Ok, combofix log:
ComboFix 10-04-01.02 - Chris 04/03/2010 14:24:45.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2460 [GMT 11:00]
Running from: c:\documents and settings\Chris\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Chris\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Chris\Application Data\Azureus
c:\documents and settings\Chris\Application Data\Azureus\.certs
c:\documents and settings\Chris\Application Data\Azureus\.keystore
c:\documents and settings\Chris\Application Data\Azureus\.lock
c:\documents and settings\Chris\Application Data\Azureus\active\3A4A5E955BF484231A3449812AB5BE04BA635BE1.dat
c:\documents and settings\Chris\Application Data\Azureus\active\3A4A5E955BF484231A3449812AB5BE04BA635BE1.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\5550997EF1D34433E989151A41F47F7FEDCA77C2.dat
c:\documents and settings\Chris\Application Data\Azureus\active\5550997EF1D34433E989151A41F47F7FEDCA77C2.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\762E71B7659229CC03EB2318DE43E56573D2D841.dat
c:\documents and settings\Chris\Application Data\Azureus\active\762E71B7659229CC03EB2318DE43E56573D2D841.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\77D44287EE5871AF1AE7ADAE2C2F9BFBC5079109.dat
c:\documents and settings\Chris\Application Data\Azureus\active\77D44287EE5871AF1AE7ADAE2C2F9BFBC5079109.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\7F55EBCDBBA4F3E2E332CED5CFDEE43C6A0EC369.dat
c:\documents and settings\Chris\Application Data\Azureus\active\7F55EBCDBBA4F3E2E332CED5CFDEE43C6A0EC369.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\B3189A92998B61260E005AF4962A3A748E9478AD.dat
c:\documents and settings\Chris\Application Data\Azureus\active\B3189A92998B61260E005AF4962A3A748E9478AD.dat.bak
c:\documents and settings\Chris\Application Data\Azureus\active\cache.dat
c:\documents and settings\Chris\Application Data\Azureus\azureus.config
c:\documents and settings\Chris\Application Data\Azureus\azureus.config.bak
c:\documents and settings\Chris\Application Data\Azureus\azureus.statistics
c:\documents and settings\Chris\Application Data\Azureus\azureus.statistics.bak
c:\documents and settings\Chris\Application Data\Azureus\banips.config
c:\documents and settings\Chris\Application Data\Azureus\banips.config.bak
c:\documents and settings\Chris\Application Data\Azureus\cache\1191085919.ico
c:\documents and settings\Chris\Application Data\Azureus\cnetworks.config
c:\documents and settings\Chris\Application Data\Azureus\devices.config
c:\documents and settings\Chris\Application Data\Azureus\devices.config.bak
c:\documents and settings\Chris\Application Data\Azureus\dht\addresses.dat
c:\documents and settings\Chris\Application Data\Azureus\dht\contacts.dat
c:\documents and settings\Chris\Application Data\Azureus\dht\diverse.dat
c:\documents and settings\Chris\Application Data\Azureus\dht\general.dat
c:\documents and settings\Chris\Application Data\Azureus\dht\version.dat
c:\documents and settings\Chris\Application Data\Azureus\downloads.config
c:\documents and settings\Chris\Application Data\Azureus\downloads.config.bak
c:\documents and settings\Chris\Application Data\Azureus\filters.config
c:\documents and settings\Chris\Application Data\Azureus\ipfilter.cache
c:\documents and settings\Chris\Application Data\Azureus\logs\alerts_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\AutoSpeedSearchHistory_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\clientid_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\CNetworks_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\debug_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\debug_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\Devices_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\Friends_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\Friends_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\MetaSearch_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\NetStatus_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\seltrace_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\seltrace_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\Subscriptions_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\Subscriptions_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\thread_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\thread_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.ads_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.CMsgr_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.Friends_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.Friends_2.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.PMsgr_1.log
c:\documents and settings\Chris\Application Data\Azureus\logs\v3.Stream_1.log
c:\documents and settings\Chris\Application Data\Azureus\metasearch.config
c:\documents and settings\Chris\Application Data\Azureus\metasearch.config.bak
c:\documents and settings\Chris\Application Data\Azureus\net\pm_4804.dat
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.0.34.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.0.34.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.1.02.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.1.02.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.1.06.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.1.06.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.2.2.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azemp_2.2.2.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azmplay.exe
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\azmplay.exe.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\cp1250-a.raw
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\cp1250-a.raw.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\cp1250-b.raw
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\cp1250-b.raw.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\font.desc
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\font.desc.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\osd-mplayer-a.raw
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\osd-mplayer-a.raw.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\osd-mplayer-b.raw
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\osd-mplayer-b.raw.bak
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\plugin.properties
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\plugin.properties_2.0.34
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\plugin.properties_2.1.02
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\plugin.properties_2.1.06
c:\documents and settings\Chris\Application Data\Azureus\plugins\azemp\plugin.properties_2.2.2
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.17.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.21.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.21.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.23.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.23.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.jar
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\azupnpav_0.2.5.zip
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\cd.dat
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\plugin.properties
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.17
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.21
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.23
c:\documents and settings\Chris\Application Data\Azureus\plugins\azupnpav\plugin.properties_0.2.5
c:\documents and settings\Chris\Application Data\Azureus\plugins\SpeedScheduler\SpeedScheduler.log
c:\documents and settings\Chris\Application Data\Azureus\rcm.config
c:\documents and settings\Chris\Application Data\Azureus\rcm.config.bak
c:\documents and settings\Chris\Application Data\Azureus\sidebarauto.config
c:\documents and settings\Chris\Application Data\Azureus\sidebarauto.config.bak
c:\documents and settings\Chris\Application Data\Azureus\subs\0308C8DB325E0EEF8CAF.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\047969C2F30A401262F9.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\04C338277C616F094E36.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\04C5EE008E353478F7DD.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\152DDC20BCA924D06600.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\23F3760A461D59A5B8A2.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\24B8E9AC78200A71D3DA.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\271E92AFDBD73D248E67.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\3FCA4D1D4D009F8AA8A0.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\41B5BA8E964DADE2D58B.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\447229A3A371779E8871.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\494DB665D52CE930E652.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\586F25A8AC6E08E107B0.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\5CBA0BA6AAA42E09B126.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\5F78AD8919FF8EA67371.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\6BE1D2B0DEF34A121215.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\75073EF5A9EA448FA71D.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\7B00B8227291F46ACB6D.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\9167E16C9B7944056AC7.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\A4A08E81783B5A421A5F.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\A57341AB2AA7A98D5F19.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\AF734186BA1B192A332E.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\C24018DF949C34BC2E00.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\C732D6BA9C09C29B2FA3.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\C9EBC80E3E1D103634DB.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\CECEFD4AD0AE5D7B9B76.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\E67D8443DF3B6D5C02B4.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\F55CFA86DE0798F2E798.vuze
c:\documents and settings\Chris\Application Data\Azureus\subs\F697EC37C5A4D154EB6F.vuze
c:\documents and settings\Chris\Application Data\Azureus\subscriptions.config
c:\documents and settings\Chris\Application Data\Azureus\subscriptions.config.bak
c:\documents and settings\Chris\Application Data\Azureus\tables.config
c:\documents and settings\Chris\Application Data\Azureus\tables.config.bak
c:\documents and settings\Chris\Application Data\Azureus\tmp\AZU1977959552737798551.tmp
c:\documents and settings\Chris\Application Data\Azureus\tmp\AZU3619069003981407661.tmp
c:\documents and settings\Chris\Application Data\Azureus\tmp\AZU650329234779855840.tmp
c:\documents and settings\Chris\Application Data\Azureus\tmp\AZU9078131680088162812.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] [PC] Silent Hunter III v.1.4 [RIP] [dopeman].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] 7DUST.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] a716d6b7b1ce1d859362d8b23a5c313a9dcf8c91.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Arthemis.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] AUSTRALIAN HARDCORE PT. 5.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Avenged Sevenfold Discography -
MP3@320.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] BULLET FOR MY VALENTINE - 4 ALBUMS [CHANNEL NEO].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Call.of.Duty.Modern.Warfare.2.PROPER-SKIDROW.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Cellador - Enter Deception (2006) [MP3@VBR] by Rock City.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Dead Letter Circus.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Disturbed - Indestructible [2008].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Dream Theater Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Griffiths__David_-_Introduction_To_Electrodynamics_Solutions_Manual_-_With_Update.rar.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Killswitch Engage - Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Lacuna Coil Shallow Life [MP3 320][2009][IN].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] MathType 6.0b keygen.rar.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Megadeth - Mega Collection @ 320kps.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Metallica - Discography 1983-2008 (19 Albums, 23 CDs).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Metallica Discography @ 320Kbps.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Miracle_2004.4826548.TPB.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] NHL 2009.Reloaded[PCDVD][
www.TmasGames.com].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Nightwish Complete Discography 7 albums 17 singles High Quality Album Covers.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] novapdf-professional-desktop-discount-7.0-build-322.exe.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] PowerDVD9- Ultra Version-v9.0.2201.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Rage Against the Machine -Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Raxco PerfectDisk Professional 2008 Build 9.00.039.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Sakurai J.J. - Advanced Quantum Mechanics.djvu.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Sakurai_-_Modern_Quantum_Mechanics_-_Solutions_Manual.pdf.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Simpsons Seasons 1-18.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Slayer - Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Sonata Arctica - Discografia.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] The Butterfly Effect (Retail Discography).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] The Witcher Enhanced Edition.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] UltraISO Premium Edition v9.3.3.2685 Retail-SHAREGO.rar.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] VA-Absolute_Power_Metal-The_Definitive_Collection-Vol_2-6CD-2007-TMS.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Venetian Snares.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] White Skull (8 Albums).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] white skull.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] WinRAR_3.80_Professional.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] Within Temptation Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[isoHunt] WOLFRAM.RESEARCH.MATHEMATICA.V7.0-EDGEISO.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] 2010 IIHF World Junior Hockey Championship - Gold Medal Game - 400i.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] 2010 Winter Olympics ~ Mens Hockey ~ Gold Medal Game (720p) __ CTV Feed __.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] 2010 Winter Olympics ~ Mens Hockey ~ Quarter-Final ~ Game 2 (720p).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] 2010 Winter Olympics ~ Mens Hockey ~ Semi Final ~ Game 2 (720p).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match - Calgary Flames @ Detroit Red Wings - 2010_03_09 - English - HDTV.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match - Calgary Flames @ Los Angeles Kings - 2009_11_21 - English - HDTV.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match - Calgary Flames @ San Jose Sharks - 2009_12_05 - English - SD Cap.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match - Calgary Flames @ Toronto Maple Leafs - 2009_11_14 - English - SD Cap.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match - Colorado Avalanche @ Calgary Flames - 2009_11_17 - English - SD Cap.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] NHL Match Stanley Cup Game 7 - Pittsburgh Penguins @ Detroit Red Wings - 2009_06_12 - English - HDTV.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[NHLTorrents] Olympic Ice Hockey - 21.02.10 - USA v. Canada - English - SD.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\[PC] Battlestations Midway [RIP] [dopeman] [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_[isoHunt] Miracle_2004.4826548.TPB.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_[isoHunt] novapdf-professional-desktop-discount-7.0-build-322.exe.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_[isoHunt] Rage Against the Machine -Discography.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_[NHLTorrents] 2010 Winter Olympics ~ Mens Hockey ~ Gold Medal Game (720p) __ CTV Feed __.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_[NHLTorrents] 2010 Winter Olympics ~ Mens Hockey ~ Quarter-Final ~ Game 2 (720p).torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_Megadeth.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_Rina Yaguchi - Shemale sex 17 - DSV-20.wmv.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_She-Males.Invade.Italy.XXX.Evil.Angel.ROCCO.SIFFREDI.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\_Taylorbow.com siterip.rar.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU1029095814494834350.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU1223326105779813180.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU1566202890865062574.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU2124876591481504943.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU343923980154052276.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU4130567499377358052.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU4506267381712282116.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU4606405817078234796.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU5065912886380668671.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU5558831763875586242.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6321349770908870869.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6378441331882968084.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6460617679476664733.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6580637565754800426.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6945346115817352765.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU6982018743439194535.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU7054293023838041629.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU7527735817859708294.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU7766539006408337353.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU7769213122346412708.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU7964765969525782015.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU8138050356314873131.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU8257230210740961159.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\AZU947745374773133914.tmp
c:\documents and settings\Chris\Application Data\Azureus\torrents\Brandi_Belle.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\compilation.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\CUMCOMP_NotOnMyFace.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Disturbed [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\DVDfab.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Fallout_3-RELOADED [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Far_Cry_2___Razor1911_iso_windows [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Megadeth.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Partial Differential equations books [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Power_Quest_Discography_(Power_Metal)-(Demonoid.com)_ [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\PUBLIC_INVASION.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Rina Yaguchi - Shemale sex 17 - DSV-20.wmv.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\She-Males.Invade.Italy.XXX.Evil.Angel.ROCCO.SIFFREDI.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\shemale twins 800k.wmv.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Taylorbow.com siterip.rar.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\ubuntu-9.04-desktop-i386.iso.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Ultimate_Celebrity_Sex_Tape_Collection.torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\WHITE SKULL Discografia [
www.heavytorrents.org] [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\torrents\Worms2 [mininova].torrent
c:\documents and settings\Chris\Application Data\Azureus\update.log
c:\documents and settings\Chris\Application Data\Azureus\update.properties
c:\documents and settings\Chris\Application Data\Azureus\VuzeActivities.config
c:\documents and settings\Chris\Application Data\Azureus\VuzeActivities.config.bak
c:\program files\Azureus
c:\program files\Azureus\AzureusUpdater.exe
c:\program files\Azureus\plugins\autostop\autostop_2.0.2.jar
c:\program files\Azureus\plugins\autostop\autostop_2.0.2.zip
c:\program files\Azureus\plugins\autostop\README.txt
c:\program files\Azureus\plugins\autostop\src.zip
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.10.zip
c:\program files\Azureus\plugins\azupdater\azupdater_1.8.8.zip
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.10.jar
c:\program files\Azureus\plugins\azupdater\azupdaterpatcher_1.8.8.jar
c:\program files\Azureus\plugins\azupdater\Azureus2_4.2.0.8_P4.pax
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.10
c:\program files\Azureus\plugins\azupdater\plugin.properties_1.8.8
c:\program files\Azureus\plugins\azupdater\Updater.jar.bak
c:\program files\Azureus\plugins\SpeedScheduler\PausedTorrents.conf
c:\program files\Azureus\plugins\SpeedScheduler\SavedSchedules.xml
c:\program files\Azureus\plugins\SpeedScheduler\SpeedScheduler_1.6.0.jar
.
((((((((((((((((((((((((( Files Created from 2010-03-03 to 2010-04-03 )))))))))))))))))))))))))))))))
.
2010-04-02 09:46 . 2006-08-04 08:29 43904 ----a-r- c:\windows\system32\drivers\JRAID_2.sys
2010-03-25 09:16 . 2010-03-25 09:16 -------- d-----w- c:\program files\ERUNT
2010-03-25 09:12 . 2010-03-25 09:12 -------- d-----w- c:\program files\Trend Micro
2010-03-15 06:29 . 2010-03-15 06:29 -------- d-----w- c:\documents and settings\Chris\Application Data\Malwarebytes
2010-03-15 06:29 . 2010-01-07 05:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-15 06:29 . 2010-03-15 06:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2010-03-15 06:29 . 2010-03-15 06:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-15 06:29 . 2010-01-07 05:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-10 11:38 . 2010-03-10 11:38 -------- d-----w- c:\documents and settings\LocalService\Application Data\Softland
2010-03-10 11:38 . 2010-03-10 11:38 -------- d-----w- c:\documents and settings\Chris\Application Data\Softland
2010-03-10 11:37 . 2010-03-01 04:42 23368 ----a-w- c:\windows\system32\novamnp7.dll
2010-03-10 11:37 . 2010-03-01 04:42 20808 ----a-w- c:\windows\system32\novamip7.dll
2010-03-10 11:37 . 2010-02-05 03:00 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2010-03-10 11:37 . 2010-03-10 11:37 -------- d-----w- c:\program files\Softland
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-02 10:51 . 2010-02-08 11:58 -------- d-----w- c:\program files\Steam
2010-02-17 05:57 . 2010-02-17 05:57 -------- d-----w- c:\program files\Microsoft Silverlight
2010-02-11 11:17 . 2009-11-23 05:37 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-02-11 11:16 . 2009-11-23 05:37 -------- d-----w- c:\program files\AGEIA Technologies
2010-02-11 11:11 . 2009-02-23 04:21 -------- d-----w- c:\program files\Common Files\BioWare
2010-02-11 10:59 . 2010-02-11 10:51 -------- d-----w- c:\program files\Mass Effect 2
2010-02-08 10:27 . 2010-02-08 10:27 -------- d-----w- c:\program files\Devious Codeworks
2010-01-31 16:30 . 2009-10-29 14:53 603968 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2010-01-18 07:31 . 2010-01-18 07:31 22328 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys
2010-01-18 07:31 . 2010-01-18 07:31 22328 ----a-w- c:\documents and settings\Chris\Application Data\PnkBstrK.sys
2010-01-18 07:31 . 2010-01-18 07:31 22328 ----a-w- c:\documents and settings\Chris\Application Data\PnkBstrK.sys
2010-01-18 07:31 . 2010-01-18 07:31 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-01-18 07:31 . 2010-01-18 07:31 669184 ----a-w- c:\windows\system32\pbsvc.exe
2010-01-18 07:31 . 2010-01-18 07:31 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-01-14 04:06 . 2010-01-14 04:06 29480 ----a-w- c:\windows\system32\msxml3a.dll
2010-01-14 04:06 . 2010-01-14 04:06 53319 ----a-w- c:\documents and settings\All Users\Application Data\TEMP\{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}\PostBuild.exe
2010-01-14 04:06 . 2009-03-13 10:41 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-01-14 04:06 . 2009-02-27 22:53 353576 ----a-w- c:\windows\system32\msvcr71.dll
2009-06-28 10:29 . 2009-06-28 10:27 849106944 ----a-w- c:\program files\Counter-Strike 1.6 + Half-Life.iso
.
((((((((((((((((((((((((((((( SnapShot@2010-04-02_09.59.44 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-03 02:24 . 2010-04-03 02:24 16384 c:\windows\Temp\Perflib_Perfdata_6f4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUS SmartDoctor"="c:\program files\ASUS\SmartDoctor\SmartDoctor.exe" [2009-04-16 1183744]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-08-30 61440]
"F5D8051v3"="c:\program files\Belkin\F5D8051v3\Belkinwcui.exe" [2007-08-03 1630208]
"WinFast Schedule"="c:\program files\WinFast\WFTVFM\WFWIZ.exe" [2007-02-13 397312]
"iKeyWorks"="c:\progra~1\Keyboard\Ikeymain.exe" [2002-11-22 73728]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2010-03-19 2046816]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-07-16 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-10 149280]
"RemoteControl9"="c:\program files\CyberLink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336]
"PDVD9LanguageShortcut"="c:\program files\CyberLink\PowerDVD9\Language\Language.exe" [2009-04-27 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-09-01 75048]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-08-17 00:33 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2009-09-04 01:08 935288 ----a-r- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-10-02 17:08 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ASUSGamerOSD]
2008-06-26 00:51 380928 ----a-w- c:\program files\ASUS\GamerOSD\GamerOSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2009-01-06 21:06 290088 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\JMB36X Configure]
2006-06-02 08:45 385024 ------r- c:\windows\system32\JMRaidTool.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
2008-04-14 00:12 1695232 ------w- c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
2009-07-26 05:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2009-01-06 00:18 413696 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAX]
2006-04-10 17:19 729088 ----a-w- c:\program files\Analog Devices\SoundMAX\SMax4.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMAXPnP]
2006-05-01 10:07 843776 ----a-r- c:\program files\Analog Devices\Core\smax4pnp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
2009-07-16 12:01 198160 ----a-w- c:\program files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CiSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Mass Effect\\Binaries\\MassEffect.exe"=
"c:\\Program Files\\Mass Effect\\MassEffectLauncher.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx9.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Dx10.exe"=
"c:\\Program Files\\Ubisoft\\Assassin's Creed\\AssassinsCreed_Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FarCry2.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Launcher.exe"=
"c:\\Program Files\\Ubisoft\\Far Cry 2\\bin\\FC2Editor.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_online.exe"=
"c:\\Program Files\\Sierra Entertainment\\World in Conflict\\wic_ds.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\bin_ship\\DAOCharacterCreator.exe"=
"c:\\Program Files\\Dragon Age Origins Character Creator\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Rockstar Games Social Club\\RGSCLauncher.exe"=
"c:\\Program Files\\Rockstar Games\\Grand Theft Auto IV\\LaunchGTAIV.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daorigins.exe"=
"c:\\Program Files\\Dragon Age\\DAOriginsLauncher.exe"=
"c:\\Program Files\\Dragon Age\\bin_ship\\daupdatersvc.service.exe"=
"c:\\Program Files\\CyberLink\\PowerDVD9\\PowerDVD9.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\Crysis.exe"=
"c:\\Program Files\\Electronic Arts\\Crytek\\Crysis\\Bin32\\CrysisDedicatedServer.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\Program Files\\Mass Effect 2\\Binaries\\MassEffect2.exe"=
"c:\\Program Files\\Mass Effect 2\\MassEffect2Launcher.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [7/19/2009 2:01 AM 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [7/19/2009 4:42 PM 335240]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [7/19/2009 4:42 PM 108552]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [7/1/2009 5:20 PM 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [7/1/2009 5:20 PM 41424]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/01/14 15:08];c:\program files\CyberLink\PowerDVD9\000.fcl [9/1/2009 4:59 PM 87536]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [7/19/2009 4:41 PM 297752]
R2 PD91Agent;PD91Agent;c:\program files\Raxco\PerfectDisk2008\PD91Agent.exe [1/16/2008 11:52 AM 664840]
R3 WFIOCTL;WFIOCTL;c:\program files\WinFast\WFTVFM\WFIOCTL.sys [2/24/2009 5:07 PM 9446]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\Dragon Age\bin_ship\daupdatersvc.service.exe [11/23/2009 4:28 PM 25832]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [7/4/2009 1:49 AM 1029456]
S3 PD91Engine;PD91Engine;c:\program files\Raxco\PerfectDisk2008\PD91Engine.exe [1/16/2008 11:52 AM 894216]
S3 SaiK0621;SaiK0621;c:\windows\system32\drivers\SaiK0621.sys [10/22/2008 4:09 PM 106496]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [7/1/2009 5:20 PM 32016]
.
Contents of the 'Scheduled Tasks' folder
2010-03-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:01]
2010-04-02 c:\windows\Tasks\OGADaily.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
2010-04-03 c:\windows\Tasks\OGALogon.job
- c:\windows\system32\OGAVerify.exe [2008-12-31 06:04]
2010-04-03 c:\windows\Tasks\SDMsgUpdate (TE).job
- c:\progra~1\SMARTD~1\Messages\SDNotify.exe [2009-08-26 16:21]
2010-04-03 c:\windows\Tasks\WGASetup.job
- c:\windows\system32\KB905474\wgasetup.exe [2009-04-22 12:18]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
TCP: {CDC0FB5A-A492-46A2-86D0-2F1920419E28} = 198.142.0.51,203.2.75.132
FF - ProfilePath - c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\h1dqusqv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.optuszoo.com.au/
FF - component: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\h1dqusqv.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - plugin: c:\documents and settings\Chris\Application Data\Mozilla\Firefox\Profiles\h1dqusqv.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-04-03 14:30
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\{B154377D-700F-42cc-9474-23858FBDF4BD}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD9\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-854245398-287218729-839522115-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:76,82,75,63,3c,a6,f7,60,70,c8,15,64,5f,ee,71,8f,f2,70,1d,e0,08,b0,87,
9f,f3,54,bd,fb,f1,7b,66,db,77,6b,02,eb,06,00,b6,e2,65,ff,46,3a,9c,74,33,67,\
"??"=hex:69,6f,5c,46,6a,89,f9,ee,2d,48,e0,10,87,42,1e,12
[HKEY_USERS\S-1-5-21-854245398-287218729-839522115-1003\Software\SecuROM\License information*]
"datasecu"=hex:25,38,84,a0,89,79,77,c6,ce,8e,a9,71,80,06,ab,ad,6a,39,16,f7,90,
3f,7c,71,34,08,dd,1e,47,a0,82,82,4f,b0,32,72,1d,ed,e3,21,7d,04,16,f2,0d,ab,\
"rkeysecu"=hex:2f,0f,d5,3e,02,2b,06,63,b1,0b,dd,b6,71,e2,54,98
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(860)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-04-03 14:31:27
ComboFix-quarantined-files.txt 2010-04-03 03:31
ComboFix2.txt 2010-04-02 10:06
Pre-Run: 23,139,926,016 bytes free
Post-Run: 23,087,353,856 bytes free
- - End Of File - - 30B738E6C5158AD49DA5ACE1F0F38B5B
Kaspersky scan:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Sunday, April 4, 2010
Operating system: Microsoft Windows XP Professional Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Saturday, April 03, 2010 13:40:23
Records in database: 3913863
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
A:\
C:\
D:\
F:\
G:\
Scan statistics:
Objects scanned: 342023
Threats found: 9
Infected objects found: 23
Suspicious objects found: 4
Scan duration: 08:32:28
File name / Threat / Threats count
C:\Documents and Settings\Chris\Application Data\Sun\Java\Deployment\cache\6.0\49\6b800f31-43c82e50 Infected: Trojan-Downloader.Java.OpenConnection.at 1
C:\Qoobox\Quarantine\C\WINDOWS\system32\spool\prtprocs\w32x86\00001e0a.tmp.vir Infected: Trojan.Win32.Cosmu.orp 1
C:\Qoobox\Quarantine\G\AUTORUN.INF.vir Infected: Backdoor.Win32.Hupigon.cfeh 1
C:\System Volume Information\_restore{58434EB0-2DD5-4889-B814-9AE057144569}\RP388\A0085960.sys Infected: Rootkit.Win32.TDSS.u 1
G:\Backup\Documents and Settings\Chris\My Documents\Downloads\New Folder\3DSV.33\3DSV.33.zip Infected: Trojan.Win32.Agent.angb 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\death.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\death.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\death.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\longhorn.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\longhorn.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\longhorn.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\optic.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\optic.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\Documents and Settings\Chris\My Documents\My Pictures\Backgrounds\optic.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\Documents and Settings\Chris\My Documents\Stars 3 Screensaver\Stars.3.Screensaver.v2.51.00.0000.cracked.-.s0m\stars3ss.scr Suspicious: Packed.Win32.Black.d 1
G:\Backup\Documents and Settings\Chris\My Documents\Stars 3 Screensaver\Stars.3.Screensaver.v2.51.00.0000.cracked.-.s0m.zip Suspicious: Packed.Win32.Black.d 1
G:\Backup\My Pictures\Backgrounds\death.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\My Pictures\Backgrounds\death.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\My Pictures\Backgrounds\death.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\My Pictures\Backgrounds\longhorn.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\My Pictures\Backgrounds\longhorn.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\My Pictures\Backgrounds\longhorn.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\My Pictures\Backgrounds\optic.exe Infected: not-a-virus:WebToolbar.Win32.WhenU.a 1
G:\Backup\My Pictures\Backgrounds\optic.exe Infected: not-a-virus:AdWare.Win32.NewDotNet 1
G:\Backup\My Pictures\Backgrounds\optic.exe Infected: Trojan-Downloader.Win32.Small.bke 1
G:\Backup\Stars 3 Screensaver\Stars.3.Screensaver.v2.51.00.0000.cracked.-.s0m\stars3ss.scr Suspicious: Packed.Win32.Black.d 1
G:\Backup\Stars 3 Screensaver\Stars.3.Screensaver.v2.51.00.0000.cracked.-.s0m.zip Suspicious: Packed.Win32.Black.d 1
Selected area has been scanned.
DDS log:
DDS (Ver_10-03-17.01) - NTFSx86
Run by Chris at 12:42:03.85 on Sun 04/04/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3007.2223 [GMT 10:00]
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\WINDOWS\ATKKBService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\WgaTray.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\NMSAccessU.exe
C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\Belkin\F5D8051v3\Belkinwcui.exe
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\PROGRA~1\Keyboard\Ikeymain.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\CyberLink\PowerDVD9\PDVD9Serv.exe
C:\Program Files\Cyberlink\Shared Files\brs.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\ASUS\SmartDoctor\SmartDoctor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\Documents and Settings\Chris\Local Settings\temp\jkos-Chris\binaries\ScanningProcess.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Chris\Desktop\dds.com
============== Pseudo HJT Report ===============
uInternet Settings,ProxyOverride = *.local
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg8\avgssie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ASUS SmartDoctor] c:\program files\asus\smartdoctor\SmartDoctor.exe /start
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun
mRun: [F5D8051v3] c:\program files\belkin\f5d8051v3\Belkinwcui.exe
mRun: [WinFast Schedule] c:\program files\winfast\wftvfm\WFWIZ.exe
mRun: [iKeyWorks] c:\progra~1\keyboard\Ikeymain.exe
mRun: [AVG8_TRAY] c:\progra~1\avg\avg8\avgtray.exe
mRun: [TkBellExe] "c:\program files\common files\real\update_ob\realsched.exe" -osboot
mRun: [RemoteControl9] "c:\program files\cyberlink\powerdvd9\PDVD9Serv.exe"
mRun: [PDVD9LanguageShortcut] "c:\program files\cyberlink\powerdvd9\language\Language.exe"
mRun: [BDRegion] c:\program files\cyberlink\shared files\brs.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: {CDC0FB5A-A492-46A2-86D0-2F1920419E28} = 198.142.0.51,203.2.75.132
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg8\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\chris\applic~1\mozilla\firefox\profiles\h1dqusqv.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.optuszoo.com.au/
FF - component: c:\program files\avg\avg8\firefox\components\avgssff.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
============= SERVICES / DRIVERS ===============
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [2009-7-19 64160]
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-7-19 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2009-7-19 27784]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-7-19 108552]
R1 VBoxDrv;VirtualBox Service;c:\windows\system32\drivers\VBoxDrv.sys [2009-7-1 115856]
R1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\drivers\VBoxUSBMon.sys [2009-7-1 41424]
R2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/01/14 15:08:04];c:\program files\cyberlink\powerdvd9\000.fcl [2009-9-1 87536]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\avg\avg8\avgwdsvc.exe [2009-7-19 297752]
R2 PD91Agent;PD91Agent;c:\program files\raxco\perfectdisk2008\PD91Agent.exe [2008-1-16 664840]
R3 rt2870;Belkin N1 Wireless USB Adapter Driver;c:\windows\system32\drivers\rt2870.sys [2009-2-21 485248]
R3 WFIOCTL;WFIOCTL;c:\program files\winfast\wftvfm\WFIOCTL.sys [2009-2-24 9446]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files\dragon age\bin_ship\daupdatersvc.service.exe [2009-11-23 25832]
S3 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\lavasoft\ad-aware\AAWService.exe [2009-7-4 1029456]
S3 PD91Engine;PD91Engine;c:\program files\raxco\perfectdisk2008\PD91Engine.exe [2008-1-16 894216]
S3 SaiK0621;SaiK0621;c:\windows\system32\drivers\SaiK0621.sys [2008-10-22 106496]
S3 VBoxUSB;VirtualBox USB;c:\windows\system32\drivers\VBoxUSB.sys [2009-7-1 32016]
=============== Created Last 30 ================
2010-04-03 04:02:32 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-04-03 03:46:27 0 d-----w- c:\documents and settings\chris\.SunDownloadManager
2010-04-02 09:46:26 43904 ----a-r- c:\windows\system32\drivers\JRAID_2.sys
2010-04-02 09:42:55 0 d-sha-r- C:\cmdcons
2010-04-02 09:41:16 98816 ----a-w- c:\windows\sed.exe
2010-04-02 09:41:16 77312 ----a-w- c:\windows\MBR.exe
2010-04-02 09:41:16 261632 ----a-w- c:\windows\PEV.exe
2010-04-02 09:41:16 161792 ----a-w- c:\windows\SWREG.exe
2010-03-25 09:12:48 0 d-----w- c:\program files\Trend Micro
2010-03-15 06:29:17 0 d-----w- c:\docume~1\chris\applic~1\Malwarebytes
2010-03-15 06:29:13 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-15 06:29:12 0 d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2010-03-15 06:29:11 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-15 06:29:11 0 d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-10 11:38:10 0 d-----w- c:\docume~1\chris\applic~1\Softland
2010-03-10 11:37:55 7549 ----a-w- c:\windows\system32\novap7.ctm
2010-03-10 11:37:55 23368 ----a-w- c:\windows\system32\novamnp7.dll
2010-03-10 11:37:55 20808 ----a-w- c:\windows\system32\novamip7.dll
2010-03-10 11:37:51 1700352 ----a-w- c:\windows\system32\GdiPlus.dll
2010-03-10 11:37:50 0 d-----w- c:\program files\Softland
==================== Find3M ====================
2010-04-03 04:02:19 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-03-06 14:01:25 15688 ----a-w- c:\windows\system32\lsdelete.exe
2010-01-18 07:31:35 22328 ----a-w- c:\docume~1\chris\applic~1\PnkBstrK.sys
2010-01-18 07:31:22 103736 ----a-w- c:\windows\system32\PnkBstrB.exe
2010-01-18 07:31:17 669184 ----a-w- c:\windows\system32\pbsvc.exe
2010-01-18 07:31:17 66872 ----a-w- c:\windows\system32\PnkBstrA.exe
2010-01-14 04:06:31 505128 ----a-w- c:\windows\system32\msvcp71.dll
2010-01-14 04:06:31 353576 ----a-w- c:\windows\system32\msvcr71.dll
2010-01-14 04:06:31 29480 ----a-w- c:\windows\system32\msxml3a.dll
2009-06-28 10:29:06 849106944 ----a-w- c:\program files\Counter-Strike 1.6 + Half-Life.iso
2006-06-23 06:48:54 32768 ----a-r- c:\windows\inf\UpdateUSB.exe
2009-07-30 16:06:15 16384 --sha-w- c:\windows\system32\config\systemprofile\ietldcache\index.dat
2009-04-01 09:09:30 32768 --sha-w- c:\windows\system32\config\systemprofile\local settings\history\history.ie5\mshist012009040120090402\index.dat
============= FINISH: 12:42:32.25 ===============
Your help is very much appreciated
