Great!
cool! I thought I was going to have to do all that manually.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:36:34 PM, on 8/29/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\StkASv2K.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: ForceField Toolbar Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O3 - Toolbar: ForceField Toolbar - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll
O4 - HKLM\..\Run: [ULiRaid] C:\Program Files\ULI5287\ULiRaid.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DU Meter] D:\DU Meter\DUMETER.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250327666185
O18 - Protocol: mcataloguer - {FECF9894-CCCF-4DE3-B994-AEE32E70B341} - C:\Program Files\MCataloguer\MCatProt.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceField IswSvc (IswSvc) - Check Point Software Technologies - C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Syntek STK1160 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
--
End of file - 4391 bytes
ComboFix 09-08-28.06 - owner 08/29/2009 13:26.1.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1690 [GMT -4:00]
Running from: c:\documents and settings\owner\Desktop\combo-fix.exe
AV: ZoneAlarm Extreme Security Antivirus *On-access scanning disabled* (Updated) {5D467B10-818C-4CAB-9FF7-6893B5B8F3CF}
FW: ZoneAlarm Extreme Security Firewall *enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\Installer\4802907.msi
c:\windows\Installer\480290f.msi
c:\windows\Installer\4802917.msi
c:\windows\Installer\480291f.msi
c:\windows\Installer\4802927.msi
c:\windows\Installer\4802934.msi
c:\windows\Installer\480293c.msi
c:\windows\Installer\4802944.msi
c:\windows\Installer\480294c.msi
c:\windows\Installer\4802958.msi
c:\windows\Installer\4802960.msi
c:\windows\Installer\4802968.msi
c:\windows\Installer\4802970.msi
c:\windows\Installer\4802978.msi
c:\windows\Installer\4802980.msi
c:\windows\Installer\4802988.msi
c:\windows\Installer\4802990.msi
c:\windows\Installer\4802998.msi
c:\windows\Installer\48029a0.msi
c:\windows\Installer\48029a8.msi
c:\windows\Installer\48029b0.msi
c:\windows\Installer\c123c.msi
c:\windows\Installer\c1244.msi
c:\windows\Installer\c124c.msi
c:\windows\Installer\c1254.msi
c:\windows\Installer\c125c.msi
c:\windows\Installer\c1269.msi
c:\windows\Installer\c1271.msi
c:\windows\Installer\c1279.msi
c:\windows\Installer\c1281.msi
c:\windows\Installer\c128d.msi
c:\windows\Installer\c1295.msi
c:\windows\Installer\c129d.msi
c:\windows\Installer\c12a5.msi
c:\windows\Installer\c12ad.msi
c:\windows\Installer\c12b5.msi
c:\windows\Installer\c12bd.msi
c:\windows\Installer\c12c5.msi
c:\windows\Installer\c12cd.msi
c:\windows\Installer\c12d5.msi
c:\windows\Installer\c12dd.msi
c:\windows\Installer\c12e5.msi
c:\windows\system32\drivers\hjgruikdmixfqh.sys
c:\windows\system32\hjgruibqvdlllx.dll
c:\windows\system32\hjgruidmlwblto.dat
c:\windows\system32\hjgruilog.dat
c:\windows\system32\hjgruiwqkswlnt.dll
c:\windows\system32\hjgruixtqsnswu.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_hjgruipnxrjkyl
-------\Legacy_hjgruipnxrjkyl
((((((((((((((((((((((((( Files Created from 2009-07-28 to 2009-08-29 )))))))))))))))))))))))))))))))
.
2009-08-29 05:09 . 2009-08-29 05:09 -------- d-----w- c:\program files\Windows Sidebar
2009-08-29 03:56 . 2009-08-29 03:56 -------- d-----w- c:\documents and settings\owner\Application Data\DivX
2009-08-28 10:58 . 2009-08-29 12:45 -------- d-----w- c:\documents and settings\owner\Application Data\dvdcss
2009-08-28 10:55 . 2009-08-29 12:45 -------- d-----w- c:\documents and settings\owner\Application Data\vlc
2009-08-28 10:49 . 2009-08-28 10:50 18015723 ----a-w- c:\documents and settings\All Users\Application Data\vlc-1.0.1-win32.exe
2009-08-28 10:47 . 2009-08-28 10:47 -------- d-----w- c:\windows\system32\custom matrices
2009-08-28 10:47 . 2009-08-28 10:47 -------- d-----w- c:\windows\system32\C2MP
2009-08-28 10:47 . 2009-08-28 10:47 -------- d-----w- c:\windows\system32\QuickTime
2009-08-28 10:41 . 2009-08-28 10:41 -------- d-----w- c:\program files\VideoLAN
2009-08-28 05:42 . 2009-08-29 07:58 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\QuickPar
2009-08-28 05:38 . 2009-08-28 05:39 -------- d-----w- c:\program files\QuickPar
2009-08-28 04:38 . 2009-08-28 04:38 -------- d-----w- c:\program files\Trend Micro
2009-08-28 04:35 . 2009-08-28 04:36 -------- d-----w- c:\program files\ERUNT
2009-08-26 10:04 . 2009-08-26 10:04 -------- d-----w- c:\program files\Common Files\Software Update Utility
2009-08-25 01:33 . 2009-08-25 01:33 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-08-25 00:00 . 2009-08-25 00:00 -------- d-----w- c:\documents and settings\owner\Application Data\NeroDigital(TM)
2009-08-24 22:39 . 2009-08-26 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-08-24 22:39 . 2009-08-24 22:40 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-08-24 17:16 . 2009-08-24 17:16 -------- d-----w- c:\documents and settings\owner\Application Data\CyberLink
2009-08-24 17:13 . 2009-08-24 17:13 -------- d-----w- c:\documents and settings\All Users\Application Data\CyberLink
2009-08-24 17:11 . 2009-08-24 17:18 -------- d-----w- c:\program files\CyberLink
2009-08-24 17:08 . 2008-04-14 00:12 26624 ----a-w- c:\documents and settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2009-08-24 04:56 . 2009-08-24 04:56 71256 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-08-24 04:54 . 2009-08-24 04:54 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\Nero
2009-08-21 21:57 . 2009-08-21 21:57 -------- d-----w- c:\documents and settings\All Users\Application Data\FLEXnet
2009-08-21 20:35 . 2009-08-21 20:35 -------- d-----w- c:\windows\system32\XPSViewer
2009-08-21 20:35 . 2009-08-21 20:35 -------- d-----w- c:\program files\MSBuild
2009-08-21 20:35 . 2009-08-21 20:35 -------- d-----w- c:\program files\Reference Assemblies
2009-08-21 20:34 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-08-21 20:34 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-08-21 20:34 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-08-21 20:34 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-08-21 20:34 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-08-21 20:34 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-08-21 20:34 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-08-21 20:32 . 2009-08-21 20:32 -------- d-----w- c:\program files\Windows Media Connect 2
2009-08-21 20:32 . 2009-08-21 20:32 -------- d-----w- c:\windows\system32\drivers\UMDF
2009-08-21 20:25 . 2009-08-21 20:25 -------- d-sh--w- c:\documents and settings\owner\IECompatCache
2009-08-21 20:13 . 2009-08-21 20:13 -------- d-----w- c:\program files\DFX
2009-08-21 18:25 . 2009-08-23 20:43 -------- d-----w- c:\documents and settings\owner\Application Data\Nero
2009-08-21 18:22 . 2009-08-21 18:22 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-08-21 17:58 . 2009-08-29 05:08 -------- d-----w- c:\program files\Nero
2009-08-21 17:58 . 2009-08-29 05:09 -------- d-----w- c:\program files\Common Files\Nero
2009-08-21 17:58 . 2009-08-29 05:02 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero
2009-08-21 15:20 . 2009-08-21 15:20 -------- d-----w- c:\documents and settings\owner\Application Data\Earthsim
2009-08-21 15:07 . 2009-08-21 15:20 -------- d-----w- c:\documents and settings\All Users\Application Data\Earthsim
2009-08-21 14:32 . 2009-08-21 14:32 -------- d-----w- c:\program files\Common Files\Macrovision Shared
2009-08-21 14:31 . 2009-08-21 14:30 118520 ------w- c:\windows\system32\pxinsi64.exe
2009-08-21 14:31 . 2009-08-21 14:30 116472 ------w- c:\windows\system32\pxcpyi64.exe
2009-08-21 14:29 . 2009-08-21 14:29 -------- d-----w- c:\program files\MasterSplitter
2009-08-21 14:06 . 2009-04-28 20:20 129520 ------w- c:\windows\system32\pxafs.dll
2009-08-21 14:06 . 2009-08-21 21:19 -------- d-----w- c:\documents and settings\owner\Application Data\Winamp
2009-08-21 14:06 . 2009-08-21 20:13 -------- d-----w- c:\program files\Winamp
2009-08-20 15:01 . 2009-08-20 15:01 -------- d-----w- c:\program files\Agent
2009-08-20 14:36 . 2009-08-29 14:29 -------- d-----w- C:\a1 Try These
2009-08-20 11:10 . 2009-08-21 13:46 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\MCataloguer
2009-08-20 11:03 . 2009-08-20 11:03 -------- d-----w- c:\documents and settings\All Users\Application Data\HP Product Assistant
2009-08-19 12:01 . 2009-08-19 12:01 -------- d-----w- c:\program files\MSXML 4.0
2009-08-19 08:31 . 2009-08-19 08:31 -------- d-----w- c:\program files\MCataloguer
2009-08-19 08:31 . 2009-08-19 08:31 -------- d-----w- c:\program files\MSXML 6.0
2009-08-19 03:53 . 2009-08-19 03:53 -------- d-----w- c:\program files\Common Files\Sonic Shared
2009-08-19 03:52 . 2009-08-19 03:53 -------- d-----w- c:\program files\Common Files\HP
2009-08-19 03:51 . 2009-08-19 03:51 -------- d-----w- c:\program files\Hewlett-Packard
2009-08-19 03:46 . 2009-08-19 03:55 117094 ----a-w- c:\windows\hpoins11.dat
2009-08-18 19:21 . 2009-08-18 19:21 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-08-18 18:21 . 2009-08-18 18:21 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\IsolatedStorage
2009-08-18 18:21 . 2009-08-18 18:21 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\HP
2009-08-18 18:21 . 2009-08-18 18:21 128 ----a-w- c:\documents and settings\owner\Local Settings\Application Data\fusioncache.dat
2009-08-18 18:20 . 2009-08-18 18:21 -------- d-----w- c:\documents and settings\owner\Application Data\HP
2009-08-18 18:12 . 2009-08-18 18:13 94084 ----a-w- c:\windows\hpqins07.dat
2009-08-18 18:11 . 2009-08-18 18:12 94237 ----a-w- c:\windows\hpqins04.dat
2009-08-18 18:10 . 2009-08-18 18:10 -------- d-----w- c:\documents and settings\All Users\Application Data\Sonic
2009-08-18 18:08 . 2009-08-18 18:10 94215 ----a-w- c:\windows\hpqins09.dat
2009-08-18 18:07 . 2009-08-18 18:08 94107 ----a-w- c:\windows\hpqins05.dat
2009-08-18 18:05 . 2009-08-18 18:07 94115 ----a-w- c:\windows\hpqins01.dat
2009-08-18 18:03 . 2009-08-18 18:04 94083 ----a-w- c:\windows\hpqins11.dat
2009-08-18 17:52 . 2009-08-18 17:52 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-08-18 17:51 . 2006-04-13 01:04 16496 ----a-r- c:\windows\system32\drivers\HPZipr12.sys
2009-08-18 17:51 . 2006-04-13 01:04 49664 ----a-r- c:\windows\system32\drivers\HPZid412.sys
2009-08-18 17:51 . 2006-01-04 09:12 77824 ----a-r- c:\windows\system32\HPZIDS01.dll
2009-08-18 17:51 . 2006-04-10 18:03 38400 ----a-w- c:\windows\system32\hpz3l054.dll
2009-08-18 17:50 . 2008-04-13 15:45 15104 -c--a-w- c:\windows\system32\dllcache\usbscan.sys
2009-08-18 17:50 . 2008-04-13 15:45 15104 ----a-w- c:\windows\system32\drivers\usbscan.sys
2009-08-18 17:48 . 2007-08-09 07:27 73728 ----a-w- c:\windows\system32\HPZipm12.exe
2009-08-18 17:48 . 2006-03-04 01:03 282680 ----a-w- c:\windows\system32\HPZidr12.dll
2009-08-18 17:48 . 2006-03-04 01:03 65536 ----a-w- c:\windows\system32\HPZinw12.exe
2009-08-18 17:48 . 2006-03-04 01:02 204800 ----a-w- c:\windows\system32\HPZipr12.dll
2009-08-18 17:48 . 2006-03-04 01:02 94208 ----a-w- c:\windows\system32\HPZipt12.dll
2009-08-18 17:48 . 2006-03-04 01:02 57344 ----a-w- c:\windows\system32\HPZisn12.dll
2009-08-18 17:47 . 2009-08-19 03:54 -------- d-----w- c:\program files\HP
2009-08-18 17:42 . 2008-04-13 15:47 25856 -c--a-w- c:\windows\system32\dllcache\usbprint.sys
2009-08-18 17:42 . 2008-04-13 15:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-08-17 11:31 . 2009-08-21 20:32 -------- d-----w- c:\windows\system32\LogFiles
2009-08-16 12:25 . 2008-04-13 15:45 60032 -c--a-w- c:\windows\system32\dllcache\usbaudio.sys
2009-08-16 12:25 . 2008-04-13 15:45 60032 ----a-w- c:\windows\system32\drivers\USBAUDIO.sys
2009-08-16 12:25 . 2008-04-13 15:45 32128 -c--a-w- c:\windows\system32\dllcache\usbccgp.sys
2009-08-16 12:25 . 2008-04-13 15:45 32128 ----a-w- c:\windows\system32\drivers\usbccgp.sys
2009-08-16 12:21 . 2009-08-16 12:57 -------- d-----w- c:\program files\MultiViewer
2009-08-16 09:06 . 2009-08-16 09:06 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\ACD Systems
2009-08-16 09:06 . 2009-08-16 09:06 -------- d-----w- c:\documents and settings\owner\Application Data\ACD Systems
2009-08-16 09:04 . 2009-08-16 09:04 -------- d-----w- c:\documents and settings\All Users\Application Data\ACD Systems
2009-08-16 09:04 . 2009-08-20 22:32 -------- d-----w- c:\program files\Common Files\ACD Systems
2009-08-16 09:04 . 2009-08-16 09:04 -------- d-----w- c:\program files\ACD Systems
2009-08-16 09:02 . 2009-08-20 16:26 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\Downloaded Installations
2009-08-16 05:54 . 2009-08-16 05:54 -------- d-----w- c:\windows\Downloaded Installations
2009-08-16 05:51 . 2003-06-25 20:05 266360 ----a-w- c:\windows\system32\TweakUI.exe
2009-08-16 05:14 . 2009-08-16 05:14 -------- d-----w- c:\program files\SonicWallES
2009-08-16 05:12 . 2009-08-16 05:12 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\Identities
2009-08-16 04:22 . 2009-08-16 04:22 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\Google
2009-08-16 01:29 . 2009-08-29 04:35 -------- d-----r- c:\documents and settings\owner\Downloads
2009-08-15 12:43 . 2009-08-15 12:43 0 ----a-w- c:\windows\nsreg.dat
2009-08-15 12:43 . 2009-08-15 12:43 -------- d-----w- c:\documents and settings\owner\Local Settings\Application Data\Mozilla
2009-08-15 12:08 . 2009-08-15 12:08 -------- d-----w- c:\program files\ULI5287
2009-08-15 12:07 . 2005-03-10 01:01 28672 ----a-w- c:\windows\system32\unM5287.exe
2009-08-15 12:07 . 2001-11-14 04:24 35587 ----a-w- c:\windows\system32\rm5287.exe
2009-08-15 12:07 . 2005-04-06 20:54 28672 ----a-w- c:\windows\system32\UnLAN.exe
2009-08-15 12:07 . 2005-03-23 00:36 28672 ----a-w- c:\windows\system32\drivers\ULILAN51.SYS
2009-08-15 12:07 . 2001-11-14 01:24 35587 ----a-w- c:\windows\system32\rmlan.exe
2009-08-15 12:07 . 2001-11-14 01:24 34307 ----a-w- c:\windows\system32\drivers\Install.EXE
2009-08-15 12:07 . 1998-10-29 20:45 306688 ----a-w- c:\windows\IsUninst.exe
2009-08-15 12:07 . 2009-08-15 12:07 -------- d-----w- c:\windows\system32\URTTemp
2009-08-15 12:06 . 2009-08-15 12:06 -------- d-----w- c:\program files\ATI Technologies
2009-08-15 12:06 . 2009-08-24 17:11 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-08-15 12:05 . 2009-08-15 12:06 -------- d-----w- c:\program files\Common Files\InstallShield
2009-08-15 12:05 . 2004-08-14 10:56 5810 ----a-r- c:\windows\system32\drivers\ASACPI.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-29 17:31 . 2009-08-15 11:44 64361504 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-29 15:00 . 2009-08-15 11:42 144 ----a-w- c:\windows\system32\pdfl.dat
2009-08-28 03:30 . 2009-08-28 03:30 1930751 ----a-w- c:\windows\Internet Logs\tvDebug.Zip
2009-08-26 22:30 . 2009-08-15 11:46 -------- d-----w- c:\documents and settings\owner\Application Data\#ISW.FS#
2009-08-26 09:21 . 2009-08-26 09:24 2547200 ----a-w- c:\windows\Internet Logs\xDB1.tmp
2009-08-23 14:40 . 2009-08-15 09:48 18888 ----a-w- c:\documents and settings\owner\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-08-22 17:37 . 2009-08-15 11:16 -------- d-----w- c:\program files\Common Files\Adobe
2009-08-21 18:39 . 2009-08-15 11:44 854840 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-16 12:20 . 2009-08-16 12:20 -------- d-----w- c:\program files\Wireless Camera Watcher
2009-08-16 05:14 . 2009-08-15 11:46 -------- d-----w- c:\documents and settings\owner\Application Data\MailFrontier
2009-08-16 01:16 . 2009-08-15 11:42 4212 ---ha-w- c:\windows\system32\zllictbl.dat
2009-08-15 11:53 . 2009-08-15 11:53 -------- d-----w- c:\program files\microsoft frontpage
2009-08-15 11:51 . 2009-08-15 11:51 21640 ----a-w- c:\windows\system32\emptyregdb.dat
2009-08-15 11:46 . 2009-08-15 11:46 -------- d-----w- c:\documents and settings\owner\Application Data\CheckPoint
2009-08-15 11:42 . 2009-08-15 11:42 80 ----a-w- c:\windows\system32\ibfl.dat
2009-08-15 11:42 . 2009-08-15 11:42 144 ----a-w- c:\windows\system32\lkfl.dat
2009-08-15 11:42 . 2009-08-15 11:42 -------- d-----w- c:\program files\CheckPoint
2009-08-15 11:42 . 2009-08-15 11:42 -------- d-----w- c:\program files\Zone Labs
2009-08-15 11:28 . 2009-08-15 11:27 -------- d-----w- c:\program files\ASUS
2009-08-15 11:26 . 2009-08-15 11:26 -------- d-----w- c:\program files\Realtek
2009-08-15 11:25 . 2009-08-15 11:25 -------- d-----w- c:\program files\AMD
2009-08-15 11:21 . 2009-08-15 10:29 -------- d-----w- c:\program files\AGEIA Technologies
2009-08-15 11:21 . 2009-08-15 10:29 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-08-15 11:21 . 2009-08-15 11:21 -------- d-----w- c:\program files\NVIDIA Corporation
2009-08-15 11:21 . 2009-08-15 11:21 -------- d-----w- c:\documents and settings\All Users\Application Data\NVIDIA Corporation
2009-08-15 10:20 . 2009-08-15 11:52 86327 ----a-w- c:\windows\PCHEALTH\HELPCTR\OfflineCache\index.dat
2009-08-11 20:21 . 2009-08-11 20:21 87552 ----a-w- c:\windows\system32\ac3config.exe
2009-08-05 09:01 . 2009-08-15 09:24 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-04 15:58 . 2009-08-04 15:58 802603 ----a-w- c:\windows\system32\ff_x264.dll
2009-08-04 15:57 . 2009-08-04 15:57 557003 ----a-w- c:\windows\system32\libmplayer.dll
2009-08-04 13:07 . 2009-08-04 13:07 4455179 ----a-w- c:\windows\system32\libavcodec.dll
2009-07-29 23:10 . 2009-07-29 23:10 829781 ----a-w- c:\windows\system32\xvidcore.dll
2009-07-29 04:37 . 2001-08-18 12:00 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-29 04:37 . 2001-08-18 12:00 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-17 19:01 . 2001-08-18 12:00 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-14 18:54 . 2009-08-15 11:19 2189856 ----a-w- c:\windows\system32\nvcuvid.dll
2009-07-14 18:54 . 2009-08-15 11:19 1706528 ----a-w- c:\windows\system32\nvcuvenc.dll
2009-07-14 18:54 . 2009-08-15 11:19 1597690 ----a-w- c:\windows\system32\nvdata.bin
2009-07-14 18:54 . 2009-08-15 10:28 485920 ----a-w- c:\windows\system32\nvudisp.exe
2009-07-14 18:54 . 2008-07-31 12:49 10457088 ----a-w- c:\windows\system32\nvoglnt.dll
2009-07-14 18:54 . 2008-07-26 04:48 868352 ----a-w- c:\windows\system32\nvapi.dll
2009-07-14 18:54 . 2008-07-26 04:48 2002944 ----a-w- c:\windows\system32\nvcuda.dll
2009-07-14 18:54 . 2008-07-26 04:48 151552 ----a-w- c:\windows\system32\nvcodins.dll
2009-07-14 18:54 . 2008-07-26 04:48 151552 ----a-w- c:\windows\system32\nvcod.dll
2009-07-14 18:54 . 2004-08-04 07:56 5842816 ----a-w- c:\windows\system32\nv4_disp.dll
2009-07-14 18:54 . 2004-08-04 05:29 7741664 ----a-w- c:\windows\system32\drivers\nv4_mini.sys
2009-07-14 17:35 . 2009-07-14 17:35 2173472 ----a-w- c:\windows\system32\nvcplui.exe
2009-07-14 17:35 . 2009-07-14 17:35 81920 ----a-w- c:\windows\system32\nvwddi.dll
2009-07-14 17:35 . 2009-07-14 17:35 4026368 ----a-w- c:\windows\system32\nvvitvs.dll
2009-07-14 17:35 . 2009-07-14 17:35 3170304 ----a-w- c:\windows\system32\nvwss.dll
2009-07-14 17:34 . 2009-07-14 17:34 86016 ----a-w- c:\windows\system32\nvmctray.dll
2009-07-14 17:34 . 2009-07-14 17:34 4923392 ----a-w- c:\windows\system32\nvdisps.dll
2009-07-14 17:34 . 2009-07-14 17:34 3547136 ----a-w- c:\windows\system32\nvgames.dll
2009-07-14 17:34 . 2009-07-14 17:34 188416 ----a-w- c:\windows\system32\nvmccss.dll
2009-07-14 17:34 . 2009-07-14 17:34 168004 ----a-w- c:\windows\system32\nvsvc32.exe
2009-07-14 17:34 . 2009-07-14 17:34 143360 ----a-w- c:\windows\system32\nvcolor.exe
2009-07-14 17:34 . 2009-07-14 17:34 13877248 ----a-w- c:\windows\system32\nvcpl.dll
2009-07-14 17:34 . 2009-07-14 17:34 1286144 ----a-w- c:\windows\system32\nvmobls.dll
2009-07-14 17:34 . 2009-07-14 17:34 229376 ----a-w- c:\windows\system32\nvmccs.dll
2009-07-14 13:19 . 2009-07-14 13:19 425040 ----a-w- c:\windows\system32\TomsMoComp_ff.dll
2009-07-14 12:31 . 2009-07-14 12:31 146098 ----a-w- c:\windows\system32\libmpeg2_ff.dll
2009-07-14 03:43 . 2004-08-04 07:56 286208 ------w- c:\windows\system32\wmpdxm.dll
2009-07-10 11:01 . 2009-08-15 10:28 485920 ----a-w- c:\windows\system32\NVUNINST.EXE
2009-07-03 17:09 . 2001-08-18 12:00 915456 ----a-w- c:\windows\system32\wininet.dll
2009-06-26 16:50 . 2009-06-26 16:50 81920 ------w- c:\windows\system32\ieencode.dll
2009-06-25 08:25 . 2001-08-18 12:00 730112 ----a-w- c:\windows\system32\lsasrv.dll
2009-06-25 08:25 . 2001-08-18 12:00 56832 ----a-w- c:\windows\system32\secur32.dll
2009-06-25 08:25 . 2001-08-18 12:00 54272 ----a-w- c:\windows\system32\wdigest.dll
2009-06-25 08:25 . 2001-08-18 12:00 301568 ----a-w- c:\windows\system32\kerberos.dll
2009-06-25 08:25 . 2001-08-18 12:00 147456 ----a-w- c:\windows\system32\schannel.dll
2009-06-25 08:25 . 2001-08-18 12:00 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-06-24 11:18 . 2001-08-18 12:00 92928 ----a-w- c:\windows\system32\drivers\ksecdd.sys
2009-06-12 12:31 . 2001-08-18 12:00 80896 ----a-w- c:\windows\system32\tlntsess.exe
2009-06-12 12:31 . 2001-08-18 12:00 76288 ----a-w- c:\windows\system32\telnet.exe
2009-06-10 14:13 . 2001-08-18 12:00 84992 ----a-w- c:\windows\system32\avifil32.dll
2009-06-10 13:19 . 2009-08-15 11:51 2066432 ----a-w- c:\windows\system32\mstscax.dll
2009-06-10 06:14 . 2001-08-18 12:00 132096 ----a-w- c:\windows\system32\wkssvc.dll
2009-06-03 19:09 . 2009-08-15 09:24 1291264 ----a-w- c:\windows\system32\quartz.dll
2009-06-02 17:35 . 2009-06-02 17:35 328334 ----a-w- c:\windows\system32\ff_kernelDeint.dll
2009-06-02 17:15 . 2009-06-02 17:15 113152 ----a-w- c:\windows\system32\ff_unrar.dll
2009-06-02 17:15 . 2009-06-02 17:15 146944 ----a-w- c:\windows\system32\ff_tremor.dll
2009-06-02 17:15 . 2009-06-02 17:15 183296 ----a-w- c:\windows\system32\ff_samplerate.dll
2009-06-02 17:14 . 2009-06-02 17:14 178688 ----a-w- c:\windows\system32\ff_libmad.dll
2009-06-02 17:14 . 2009-06-02 17:14 486400 ----a-w- c:\windows\system32\ff_libfaad2.dll
2009-06-02 17:13 . 2009-06-02 17:13 257024 ----a-w- c:\windows\system32\ff_libdts.dll
2009-06-02 17:13 . 2009-06-02 17:13 142848 ----a-w- c:\windows\system32\ff_liba52.dll
2009-06-02 17:11 . 2009-06-02 17:11 98304 ----a-w- c:\windows\system32\ff_wmv9.dll
2009-06-02 17:11 . 2009-06-02 17:11 85504 ----a-w- c:\windows\system32\ff_vfw.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ULiRaid"="c:\program files\ULI5287\ULiRaid.exe" [2005-08-24 409600]
"ZoneAlarm Client"="c:\program files\Zone Labs\ZoneAlarm\zlclient.exe" [2009-05-29 1005960]
"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"DU Meter"="d:\du meter\DUMETER.EXE" [2001-01-22 81920]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-07-14 13877248]
"RTHDCPL"="RTHDCPL.EXE" - c:\windows\RTHDCPL.EXE [2005-07-14 14679552]
c:\documents and settings\owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
HP Photosmart Premier Fast Start.lnk - c:\program files\HP\Digital Imaging\bin\hpqthb08.exe [2006-2-10 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvCplDaemon"=RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"nwiz"=c:\program files\NVIDIA Corporation\nView\nwiz.exe /install
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
R0 m5287;m5287;c:\windows\system32\drivers\m5287.sys [12/31/1979 8:00 PM 101120]
R2 ISWKL;ForceField ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [4/17/2009 4:11 AM 21136]
R2 IswSvc;ForceField IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [4/17/2009 4:11 AM 394632]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;c:\windows\system32\drivers\ULILAN51.SYS [8/15/2009 8:07 AM 28672]
S3 icsak;icsak;c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [4/17/2009 4:11 AM 54928]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.aol.com/?ncid=toolbar
mStart Page =
Handler: mcataloguer - {FECF9894-CCCF-4DE3-B994-AEE32E70B341} - c:\program files\MCataloguer\MCatProt.dll
FF - ProfilePath - c:\documents and settings\owner\Application Data\mozilla\firefox\profiles\xevmfdd3.default\
---- FIREFOX POLICIES ----
FF - user.js: protocol-handler.warn-external.dnUpdate - falsec:\program files\Mozilla Firefox\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.cache_size", 51200);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.ogg.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.wave.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.dpi", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("geo.enabled", true);
c:\program files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-08-29 13:31
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
Completion time: 2009-08-29 13:32
ComboFix-quarantined-files.txt 2009-08-29 17:32
Pre-Run: 280,628,199,424 bytes free
Post-Run: 282,270,347,264 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /fastdetect /bootlog
431 --- E O F --- 2009-08-26 23:02