Ok...i think you may be on to something
after combofix completed i tried to reenable the firewall and got an error
it said that NPF has encountered an error and should be reinstalled
so i uninstalled it immediately
rebooted
windows did not load fully or was very busy with something in the backround
i restarted again and ran spybot
it found virtumonde.generic again
i tried to include the full spybot report...
maybe there is something in the non-critical results
but it makes my post too long
you can download my full post here if interested
http://home.roadrunner.com/~digitalcongo/spybot6.txt
and just for mention...i always disable everything before running combofix...
end all processes possible...
i disconnect from the internet and disable the connection as soon as its done
hjt log is from after reboot and spybot
i reinstalled norton personal firewall 2003 after hjt
its a legit copy that came with my motherboard
soyo dragon 2 p4i875p
general things that came to my attention
internet explorer appeared on my desktop and set itself as the default browser
windows startup and shutdown default sounds came over the speakers (i have these disabled)
ComboFix 08-12-31.01 - electrochemic° 2009-01-01 16:40:31.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1613 [GMT -5:00]
Running from: c:\documents and settings\electrochemic°\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\electrochemic°\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\{D3FB4103-4A4A-4968-AA94-68E0D6F76E4C}.dat
c:\windows\system32\{8D0A2401-5F60-430C-B7E3-558C05FB2A7A}.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\{D3FB4103-4A4A-4968-AA94-68E0D6F76E4C}.dat
c:\windows\system32\{8D0A2401-5F60-430C-B7E3-558C05FB2A7A}.dat
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2009-01-01 13:56 . 2009-01-01 13:56 <DIR> d-------- c:\documents and settings\Administrator
2008-12-31 23:02 . 2008-06-02 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2008-12-31 23:01 . 2008-12-31 23:05 <DIR> d-------- c:\program files\ATI Technologies
2008-12-30 20:32 . 2008-12-30 20:35 <DIR> d-------- c:\program files\Driver Sweeper
2008-12-29 19:26 . 2008-12-31 12:04 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\skypePM
2008-12-29 19:26 . 2008-12-29 19:26 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> dr------- c:\program files\Skype
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> d-------- c:\program files\Common Files\Skype
2008-12-29 19:25 . 2008-12-31 22:37 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\Skype
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-12-29 18:17 . 2008-12-30 20:36 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\uTorrent
2008-12-29 18:16 . 2008-12-29 19:33 <DIR> d-------- c:\program files\Tremulous
2008-12-28 17:45 . 2008-12-28 17:46 <DIR> d-------- c:\program files\Aspell
2008-12-28 16:17 . 2008-12-28 16:17 <DIR> d-------- C:\_OTMoveIt
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\Malwarebytes
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 08:26 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 08:26 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-27 08:48 . 2008-12-27 08:48 <DIR> d-------- c:\program files\TrayMin
2008-12-27 08:47 . 1997-01-18 11:40 299,520 --a------ c:\windows\uninst.exe
2008-12-26 09:59 . 2008-12-26 09:59 <DIR> d-------- C:\ATI
2008-12-25 22:56 . 2008-12-25 22:56 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Softland
2008-12-25 20:08 . 2008-12-27 14:20 <DIR> d-------- c:\program files\Fighter Ace Anniversary Edition
2008-12-25 15:27 . 2008-12-25 15:27 0 --a------ c:\windows\ativpsrm.bin
2008-12-25 15:18 . 2008-12-25 15:18 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2008-12-22 06:47 . 2008-12-28 08:05 <DIR> d-------- c:\program files\Absolute Poker
2008-12-22 06:47 . 2008-12-22 06:47 <DIR> d-------- c:\program files\_uninstallation_info
2008-12-20 13:14 . 2008-12-31 22:54 153 --a------ c:\windows\wininit.ini
2008-12-20 12:06 . 2008-12-20 12:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-20 12:06 . 2008-12-20 14:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-19 10:59 . 2008-12-19 10:59 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-19 10:41 . 2008-12-19 10:41 <DIR> d-------- c:\windows\Sun
2008-12-19 10:26 . 2008-12-19 10:26 <DIR> d-------- c:\program files\Security Task Manager
2008-12-19 10:26 . 2008-12-23 15:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\SecTaskMan
2008-12-19 06:09 . 2008-12-19 06:09 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Softland
2008-12-19 06:06 . 2008-12-19 06:06 <DIR> d-------- c:\program files\Softland
2008-12-19 06:06 . 2008-12-02 12:11 20,632 --a------ c:\windows\system32\dopdfmn6.dll
2008-12-19 06:06 . 2008-12-02 12:11 18,072 --a------ c:\windows\system32\dopdfmi6.dll
2008-12-19 06:06 . 2008-10-13 15:23 7,533 --a------ c:\windows\system32\dopdf6.ctm
2008-12-19 02:14 . 2008-12-19 02:16 43 --a------ c:\windows\gswin32.ini
2008-12-16 06:30 . 2008-12-16 06:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Syscan
2008-12-13 07:06 . 2008-12-13 07:06 <DIR> d-------- c:\program files\ratDVD
2008-12-09 15:42 . 2008-12-09 15:42 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-09 07:08 . 2008-12-09 07:08 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-08 20:45 . 2008-12-08 20:45 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\OpenOffice.org
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\JRE
2008-12-08 20:43 . 2008-12-09 15:42 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-08 20:42 . 2009-01-01 16:34 <DIR> d-------- c:\program files\Java
2008-12-06 23:03 . 2008-12-06 23:03 91,632 --a------ c:\windows\system32\dsofile.dll
2008-12-06 22:53 . 2008-12-06 22:53 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\KALiNKOsoft
2008-12-06 22:48 . 2008-12-06 22:48 <DIR> d-------- c:\program files\KALiNKOsoft
2008-12-06 20:19 . 2008-12-10 02:48 <DIR> d-------- c:\program files\Sauerbraten
2008-12-05 03:18 . 2008-12-05 03:18 <DIR> d-------- c:\program files\Yahoo!
2008-12-05 03:18 . 2008-12-05 03:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 03:14 . 2008-12-05 03:14 <DIR> d-------- c:\documents and settings\default
2008-12-04 21:21 . 2008-12-04 21:24 <DIR> d-------- c:\program files\Microsoft Streets & Trips 2009
2008-12-04 21:19 . 2008-12-04 21:19 <DIR> d-------- c:\program files\MSECache
2008-12-03 19:19 . 2008-12-03 19:19 <DIR> d-------- C:\97914e1baa146da91f977c89fc7be2d0
2008-12-03 19:18 . 2008-12-03 19:19 <DIR> d-------- C:\ecc3bbfb26245cd3fd5f96eb1e
2008-12-03 17:56 . 2008-12-03 17:56 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Global
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Messenger
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\j2 Messenger 4.4 Output
2008-12-03 17:54 . 2008-12-03 17:54 0 --a------ c:\windows\system32\jConnect_4_4_Port
2008-12-03 17:53 . 2009-01-01 14:37 <DIR> d-------- c:\program files\j2 Messenger 4.4
2008-12-03 02:08 . 2008-04-13 20:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-12-03 02:08 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-01 22:42 . 2008-12-28 17:46 <DIR> d-------- c:\program files\Pidgin
2008-12-01 16:02 . 2008-04-13 14:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 21:36 --------- d-----w c:\documents and settings\electrochemic°\Application Data\.purple
2009-01-01 18:59 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-01 14:51 53,248 ----a-w c:\windows\system32\zlib.dll
2008-12-25 20:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 09:43 --------- d-----w c:\program files\Bodog Poker
2008-12-06 02:06 --------- d-----w c:\documents and settings\electrochemic°\Application Data\vlc
2008-12-02 03:41 --------- d-----w c:\program files\Common Files\GTK
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS
2008-11-29 03:20 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-29 03:18 --------- d--h--w c:\program files\Creative Installation Information
2008-11-29 03:17 --------- d-----w c:\program files\Creative
2008-11-29 03:17 --------- d-----w c:\program files\Common Files\Creative
2008-11-28 06:26 --------- d-----w c:\program files\Common Files\Adobe
2008-11-28 06:20 --------- d-----w c:\program files\Syscan
2008-11-28 06:20 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-27_11.06.19.87 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-08-26 07:24:28 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-26 07:24:30 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2009-01-01 04:04:59 10,134 ----a-r c:\windows\Installer\{0F938C41-8DDD-6C8A-A234-4B5EBA0E9932}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:12 10,134 ----a-r c:\windows\Installer\{0FDEFFDE-F20C-8AF3-828A-076CCAEDEDBA}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:27 10,134 ----a-r c:\windows\Installer\{100E3E1D-3771-8668-8064-4AD38848BBE1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:15 10,134 ----a-r c:\windows\Installer\{1283C02D-CD9C-0206-355E-02683341FD64}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:22 10,134 ----a-r c:\windows\Installer\{13043D3E-558B-7D1C-13BE-783187299F59}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:40 10,134 ----a-r c:\windows\Installer\{162AAA0F-C766-6832-3812-5E21FB1DA80C}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:32 10,134 ----a-r c:\windows\Installer\{1ED6E4D0-8DB0-A333-DEA6-188F957F5A43}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:00 10,134 ----a-r c:\windows\Installer\{1ED6E4D0-8DB0-A333-DEA6-188F957F5A43}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:32 10,134 ----a-r c:\windows\Installer\{1F8BC334-1EB1-F4D2-DBF8-97C1AA64DE6C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:18 10,134 ----a-r c:\windows\Installer\{20C5A8DE-62D2-B1C1-B60B-2106F1146F30}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:02 10,134 ----a-r c:\windows\Installer\{24CE4B41-9A9B-B7DC-01AD-E815F4F60E7C}\ARPPRODUCTICON.exe
+ 2008-12-30 00:25:32 364,726 ----a-r c:\windows\Installer\{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}\SkypeIcon.exe
+ 2009-01-01 04:05:36 10,134 ----a-r c:\windows\Installer\{25462A56-9707-749D-250C-1137754BD238}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:19 10,134 ----a-r c:\windows\Installer\{2A75E60D-3335-9D96-BA98-975BCF6760CC}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:29 10,134 ----a-r c:\windows\Installer\{2B7330BD-C032-EE14-A27A-A7998244F3D1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:49 10,134 ----a-r c:\windows\Installer\{2C5C7563-B8B4-3A2E-7C5C-8F5365ED6874}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:23 10,134 ----a-r c:\windows\Installer\{2D128229-CA51-A674-E3AA-225D15F37D98}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:08 10,134 ----a-r c:\windows\Installer\{31D3AB6C-F1AB-8C52-85B7-E30BFA88C531}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:01 10,134 ----a-r c:\windows\Installer\{395D29E5-0FAE-751C-F682-F23479A8806A}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:25 10,134 ----a-r c:\windows\Installer\{3B9E28EC-5D0E-44F4-6E82-CBDCF29CAE49}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:44 10,134 ----a-r c:\windows\Installer\{407E0CBD-D6BF-F243-6DE9-F1EEA525BA1C}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:06 10,134 ----a-r c:\windows\Installer\{407E0CBD-D6BF-F243-6DE9-F1EEA525BA1C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:54 10,134 ----a-r c:\windows\Installer\{55969DFE-C3FF-E015-256D-D70EFBAB805C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:10 10,134 ----a-r c:\windows\Installer\{59A0E0DA-E80F-D9E2-32C6-8AA559D33C8E}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:05 10,134 ----a-r c:\windows\Installer\{5AB1B545-5FB7-35D4-D09C-77D0949B2164}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:44 10,134 ----a-r c:\windows\Installer\{5EC634FA-5047-38B2-A53A-15963D9BD872}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:18 10,134 ----a-r c:\windows\Installer\{5EC634FA-5047-38B2-A53A-15963D9BD872}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:56 10,134 ----a-r c:\windows\Installer\{61125E9F-D49A-CD2D-1722-FB9D654E40F2}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:58 10,134 ----a-r c:\windows\Installer\{651AFCC8-2F1A-8132-0A33-FA5F041380BA}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:09 10,134 ----a-r c:\windows\Installer\{651AFCC8-2F1A-8132-0A33-FA5F041380BA}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:04 10,134 ----a-r c:\windows\Installer\{69EF33D7-3425-1409-0BE1-C4F3A6FB57A8}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:21 10,134 ----a-r c:\windows\Installer\{69EF33D7-3425-1409-0BE1-C4F3A6FB57A8}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:03 10,134 ----a-r c:\windows\Installer\{6BFBB953-B60F-6058-33BB-3AB2A0971FF9}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:14 10,134 ----a-r c:\windows\Installer\{6CCEE8D0-012D-AB81-E824-4415B1110669}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:14 10,134 ----a-r c:\windows\Installer\{6DF5D680-2490-BE97-CA76-E1069C8ECE7B}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:16 10,134 ----a-r c:\windows\Installer\{7510EF8C-99B9-8533-524E-BF41BDC04188}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:14 10,134 ----a-r c:\windows\Installer\{7510EF8C-99B9-8533-524E-BF41BDC04188}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:18 10,134 ----a-r c:\windows\Installer\{760DE1B8-D1C9-2DCF-8CE3-3AB7D2D974BC}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:17 10,134 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:25 10,134 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:17 9,158 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2008-12-30 19:28:25 9,158 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:04:30 10,134 ----a-r c:\windows\Installer\{774DB051-42B4-DF78-9B7F-EEA352BBC5B5}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:10 10,134 ----a-r c:\windows\Installer\{819F2F52-EAEC-0DB1-D2EE-66F48ACF43C6}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:51 10,134 ----a-r c:\windows\Installer\{92DEC792-A722-5991-2607-3EE3A4BD502B}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:08 10,134 ----a-r c:\windows\Installer\{92DEC792-A722-5991-2607-3EE3A4BD502B}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:05 10,134 ----a-r c:\windows\Installer\{96793032-8651-805A-67EF-E1759C1A8E3D}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:12 10,134 ----a-r c:\windows\Installer\{96793032-8651-805A-67EF-E1759C1A8E3D}\ARPPRODUCTICON.exe
+ 2009-01-01 04:06:00 25,214 ----a-r c:\windows\Installer\{9862B19F-4CAD-4EED-920F-2F378D84393F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:28 10,134 ----a-r c:\windows\Installer\{9E021ACC-F408-27C7-2407-587852C15364}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:39 10,134 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\ARPPRODUCTICON.exe
- 2008-12-25 20:25:43 9,158 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:05:39 9,158 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:04:51 10,134 ----a-r c:\windows\Installer\{A01028FE-68D1-E3F2-160E-9763905BF095}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:26 10,134 ----a-r c:\windows\Installer\{A0E38350-2547-161B-2D3E-C5EFD24DD70F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:36 10,134 ----a-r c:\windows\Installer\{A228A56E-8663-61A6-768E-7A55890C0013}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:11 10,134 ----a-r c:\windows\Installer\{A493EC63-3021-73EF-2097-8FC2DE857021}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:16 10,134 ----a-r c:\windows\Installer\{A4C0E536-D094-CA7E-4F7F-18043992FD36}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:13 10,134 ----a-r c:\windows\Installer\{A6BD418C-37B2-4434-9F96-23C2CAAFF11C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:32 10,134 ----a-r c:\windows\Installer\{A7ECFC98-E5D5-BBDE-C5CE-D4177E4DA573}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:04 10,134 ----a-r c:\windows\Installer\{AA09F72E-8B3D-ABDF-3FC8-650176EA3EB8}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:17 10,134 ----a-r c:\windows\Installer\{ABF68C52-0ADD-C352-5998-13D16BC3B359}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:26 10,134 ----a-r c:\windows\Installer\{B094F70F-2CC2-5062-8534-D3830FC4B018}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:58 10,134 ----a-r c:\windows\Installer\{B094F70F-2CC2-5062-8534-D3830FC4B018}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:00 10,134 ----a-r c:\windows\Installer\{BE3F26EE-F81B-4A50-8376-271F5CA84C5B}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:33 10,134 ----a-r c:\windows\Installer\{C0721ABB-9A28-A7F3-6E5A-D30550C50D26}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:34 10,134 ----a-r c:\windows\Installer\{C9F100D9-5D68-1B5B-F8C8-3632876AF990}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:00 10,134 ----a-r c:\windows\Installer\{CA42C38C-B369-B190-AD06-76D3AC95CFAC}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:51 10,134 ----a-r c:\windows\Installer\{CA42C38C-B369-B190-AD06-76D3AC95CFAC}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:21 10,134 ----a-r c:\windows\Installer\{D08027B6-F704-A2FA-EE4E-EB955E2BB591}\ARPPRODUCTICON.exe
+ 2009-01-01 04:03:56 10,134 ----a-r c:\windows\Installer\{D083BDDE-09F7-D12A-9C81-4EE4AFE3C933}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:13 10,134 ----a-r c:\windows\Installer\{D3B1C799-CB73-42DE-BA0F-2344793A095C}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:56 10,134 ----a-r c:\windows\Installer\{D3B1C799-CB73-42DE-BA0F-2344793A095C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:07 10,134 ----a-r c:\windows\Installer\{D4F7D59E-9F53-3ADC-1D4A-5A698445D538}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:38 10,134 ----a-r c:\windows\Installer\{D56625ED-7605-5B0C-70EE-B0C80F0B7B38}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:45 10,134 ----a-r c:\windows\Installer\{DFA2EACA-8915-29EE-E946-F8542AE21171}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:25 10,134 ----a-r c:\windows\Installer\{E32CE8E3-D4D3-60CE-A5FC-3EA3D0B9118C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:21 10,134 ----a-r c:\windows\Installer\{E40CFA81-9EF9-B589-34FB-94D6C801967B}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:47 10,134 ----a-r c:\windows\Installer\{E5F5743C-15C6-6F6B-F515-86C36E96464F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:23 10,134 ----a-r c:\windows\Installer\{ED425483-53D8-5F86-98DA-50834FE77F7E}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:30 10,134 ----a-r c:\windows\Installer\{F5FDCCDE-9909-02CE-ED67-0AE3905B32A1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:42 10,134 ----a-r c:\windows\Installer\{F7861EB4-0B8A-91E8-6C1C-4F99C7002E96}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:34 10,134 ----a-r c:\windows\Installer\{FC7E9E53-9A60-3E08-C909-83B00D30ADAE}\ARPPRODUCTICON.exe
- 2008-08-26 07:24:28 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
- 2008-08-26 07:24:28 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-23 12:36:14 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-26 07:24:28 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
- 2008-08-25 08:37:59 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:28 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:29 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:29 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-25 08:38:00 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
- 2008-08-23 05:56:15 635,848 -c----w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24:30 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-19 00:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 06:09:22 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 07:24:30 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 -c----w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
- 2008-04-14 00:12:07 246,814 -c--a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-26 07:24:30 105,984 -c----w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:31 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
- 2006-10-19 01:47:20 937,984 -c--a-w c:\windows\system32\dllcache\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-26 07:24:28 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 ----a-w c:\windows\system32\extmgr.dll
- 2008-08-26 07:24:28 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:37:59 70,656 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:29 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 ----a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:29 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2006-10-19 00:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-12-09 20:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2008-08-26 07:24:30 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 ----a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 ----a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 ----a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll
- 2007-07-27 15:41:40 16,760 ----a-w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ------w c:\windows\system32\spmsg.dll
- 2008-07-11 12:42:28 62,976 ----a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 ----a-w c:\windows\system32\tzchange.exe
- 2008-08-26 07:24:30 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:31 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2006-10-19 01:47:20 937,984 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-09-26 4608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Pinnacle Game Profiler"="c:\program files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" [2008-12-06 2535424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-09-21 54976]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-09-21 38592]
"SmartGuardian"="c:\program files\SOYO\HW Monitor\ITESmart.exe" [2002-05-24 163840]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Pidgin.lnk - c:\program files\Pidgin\pidgin.exe [2008-12-21 45603]
TrayMin.lnk - c:\program files\TrayMin\traymin.exe [2008-12-27 45056]
WordWeb Pro.lnk - c:\program files\WordWeb\wweb32.exe [2008-09-26 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-26 16:37 133104 c:\documents and settings\electrochemic°\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j2 4.4]
--a------ 2008-10-07 16:53 95744 c:\program files\j2 Messenger 4.4\J2GDllCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-03-11 15:24 86016 c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSnD]
-rahs---- 2008-07-07 09:42 4891472 c:\program files\Spybot - Search & Destroy\SpybotSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RegistryMechanic"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"x:\\Software Downloads\\Data.Integrity\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\DRIVERS\SI3112r.sys [2007-08-29 116264]
R2 ccPxySvc;Symantec Proxy Service;"c:\program files\Norton Personal Firewall\ccPxySvc.exe" [2002-09-21 34496]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-12-25 93696]
R3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2002-12-30 18840]
R3 iteio;iteio;\??\c:\windows\system32\drivers\iteio.sys [2008-09-25 3680]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2008-06-27 99352]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2008-06-27 555032]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 itsernum;itsernum Filter ÅX°Êµ{¦¡;c:\windows\system32\DRIVERS\itsernum.sys [2008-09-25 20133]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2008-09-27 112384]
*Newly Created Service* - ALERTER
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\electrochemic []
2008-09-26 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 08:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: fighterace.ketsujin.com
Trusted Zone: primary.ketsujin.com
Trusted Zone: update.ketsujin.com
Trusted Zone: www.ketsujin.com
Trusted Zone: www.stormofaces.com
c:\windows\Downloaded Program Files\CTSUEng.ocx - c:\windows\Downloaded Program Files\CTSUEngn.ocx
O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884}
hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
c:\windows\Downloaded Program Files\CTSUEng.inf
FF - ProfilePath - c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\
FF - prefs.js: browser.search.selectedEngine - Google Images
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 16:41:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-01 16:42:17
ComboFix-quarantined-files.txt 2009-01-01 21:42:15
ComboFix2.txt 2008-12-28 13:23:30
ComboFix3.txt 2008-12-27 22:14:49
ComboFix4.txt 2008-12-27 16:06:55
Pre-Run: 50,380,787,712 bytes free
Post-Run: 50,394,845,184 bytes free
500 --- E O F --- 2008-12-30 06:47:55
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:29:59 PM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\SOYO\HW Monitor\ITESmart.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\TrayMin\traymin.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\OSDEx\OSDEx.exe
X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
X:\TorrentialRain\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\ITESmart.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pinnacle Game Profiler] "C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" -atboottime
O4 - S-1-5-18 Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'Default user')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'Default user')
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
O4 - Global Startup: Pidgin.lnk = C:\Program Files\Pidgin\pidgin.exe
O4 - Global Startup: TrayMin.lnk = C:\Program Files\TrayMin\traymin.exe
O4 - Global Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222471195500
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - KALiNKOsoft - C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7027 bytes
after combofix completed i tried to reenable the firewall and got an error
it said that NPF has encountered an error and should be reinstalled
so i uninstalled it immediately
rebooted
windows did not load fully or was very busy with something in the backround
i restarted again and ran spybot
it found virtumonde.generic again
i tried to include the full spybot report...
maybe there is something in the non-critical results
but it makes my post too long
you can download my full post here if interested
http://home.roadrunner.com/~digitalcongo/spybot6.txt
and just for mention...i always disable everything before running combofix...
end all processes possible...
i disconnect from the internet and disable the connection as soon as its done
hjt log is from after reboot and spybot
i reinstalled norton personal firewall 2003 after hjt
its a legit copy that came with my motherboard
soyo dragon 2 p4i875p
general things that came to my attention
internet explorer appeared on my desktop and set itself as the default browser
windows startup and shutdown default sounds came over the speakers (i have these disabled)
ComboFix 08-12-31.01 - electrochemic° 2009-01-01 16:40:31.6 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2047.1613 [GMT -5:00]
Running from: c:\documents and settings\electrochemic°\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\electrochemic°\Desktop\CFScript.txt
* Created a new restore point
FILE ::
c:\windows\{D3FB4103-4A4A-4968-AA94-68E0D6F76E4C}.dat
c:\windows\system32\{8D0A2401-5F60-430C-B7E3-558C05FB2A7A}.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\windows\{D3FB4103-4A4A-4968-AA94-68E0D6F76E4C}.dat
c:\windows\system32\{8D0A2401-5F60-430C-B7E3-558C05FB2A7A}.dat
.
((((((((((((((((((((((((( Files Created from 2008-12-01 to 2009-01-01 )))))))))))))))))))))))))))))))
.
2009-01-01 13:56 . 2009-01-01 13:56 <DIR> d-------- c:\documents and settings\Administrator
2008-12-31 23:02 . 2008-06-02 21:05 593,920 --------- c:\windows\system32\ati2sgag.exe
2008-12-31 23:01 . 2008-12-31 23:05 <DIR> d-------- c:\program files\ATI Technologies
2008-12-30 20:32 . 2008-12-30 20:35 <DIR> d-------- c:\program files\Driver Sweeper
2008-12-29 19:26 . 2008-12-31 12:04 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\skypePM
2008-12-29 19:26 . 2008-12-29 19:26 56 --ah----- c:\windows\system32\ezsidmv.dat
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> dr------- c:\program files\Skype
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> d-------- c:\program files\Common Files\Skype
2008-12-29 19:25 . 2008-12-31 22:37 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\Skype
2008-12-29 19:25 . 2008-12-29 19:25 <DIR> d-------- c:\documents and settings\All Users\Application Data\Skype
2008-12-29 18:17 . 2008-12-30 20:36 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\uTorrent
2008-12-29 18:16 . 2008-12-29 19:33 <DIR> d-------- c:\program files\Tremulous
2008-12-28 17:45 . 2008-12-28 17:46 <DIR> d-------- c:\program files\Aspell
2008-12-28 16:17 . 2008-12-28 16:17 <DIR> d-------- C:\_OTMoveIt
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\Malwarebytes
2008-12-28 08:26 . 2008-12-28 08:26 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-28 08:26 . 2008-12-03 19:59 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-28 08:26 . 2008-12-03 19:59 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2008-12-27 08:48 . 2008-12-27 08:48 <DIR> d-------- c:\program files\TrayMin
2008-12-27 08:47 . 1997-01-18 11:40 299,520 --a------ c:\windows\uninst.exe
2008-12-26 09:59 . 2008-12-26 09:59 <DIR> d-------- C:\ATI
2008-12-25 22:56 . 2008-12-25 22:56 <DIR> d-------- c:\documents and settings\NetworkService\Application Data\Softland
2008-12-25 20:08 . 2008-12-27 14:20 <DIR> d-------- c:\program files\Fighter Ace Anniversary Edition
2008-12-25 15:27 . 2008-12-25 15:27 0 --a------ c:\windows\ativpsrm.bin
2008-12-25 15:18 . 2008-12-25 15:18 <DIR> d-------- c:\program files\Common Files\ATI Technologies
2008-12-22 06:47 . 2008-12-28 08:05 <DIR> d-------- c:\program files\Absolute Poker
2008-12-22 06:47 . 2008-12-22 06:47 <DIR> d-------- c:\program files\_uninstallation_info
2008-12-20 13:14 . 2008-12-31 22:54 153 --a------ c:\windows\wininit.ini
2008-12-20 12:06 . 2008-12-20 12:10 <DIR> d-------- c:\program files\Spybot - Search & Destroy
2008-12-20 12:06 . 2008-12-20 14:37 <DIR> d-------- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-12-19 10:59 . 2008-12-19 10:59 <DIR> d-------- c:\windows\system32\NtmsData
2008-12-19 10:41 . 2008-12-19 10:41 <DIR> d-------- c:\windows\Sun
2008-12-19 10:26 . 2008-12-19 10:26 <DIR> d-------- c:\program files\Security Task Manager
2008-12-19 10:26 . 2008-12-23 15:33 <DIR> d-------- c:\documents and settings\All Users\Application Data\SecTaskMan
2008-12-19 06:09 . 2008-12-19 06:09 <DIR> d-------- c:\documents and settings\LocalService\Application Data\Softland
2008-12-19 06:06 . 2008-12-19 06:06 <DIR> d-------- c:\program files\Softland
2008-12-19 06:06 . 2008-12-02 12:11 20,632 --a------ c:\windows\system32\dopdfmn6.dll
2008-12-19 06:06 . 2008-12-02 12:11 18,072 --a------ c:\windows\system32\dopdfmi6.dll
2008-12-19 06:06 . 2008-10-13 15:23 7,533 --a------ c:\windows\system32\dopdf6.ctm
2008-12-19 02:14 . 2008-12-19 02:16 43 --a------ c:\windows\gswin32.ini
2008-12-16 06:30 . 2008-12-16 06:30 <DIR> d-------- c:\documents and settings\All Users\Application Data\Syscan
2008-12-13 07:06 . 2008-12-13 07:06 <DIR> d-------- c:\program files\ratDVD
2008-12-09 15:42 . 2008-12-09 15:42 410,984 --a------ c:\windows\system32\deploytk.dll
2008-12-09 07:08 . 2008-12-09 07:08 <DIR> d-------- c:\program files\Microsoft CAPICOM 2.1.0.2
2008-12-08 20:45 . 2008-12-08 20:45 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\OpenOffice.org
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\OpenOffice.org 3
2008-12-08 20:43 . 2008-12-08 20:43 <DIR> d-------- c:\program files\JRE
2008-12-08 20:43 . 2008-12-09 15:42 73,728 --a------ c:\windows\system32\javacpl.cpl
2008-12-08 20:42 . 2009-01-01 16:34 <DIR> d-------- c:\program files\Java
2008-12-06 23:03 . 2008-12-06 23:03 91,632 --a------ c:\windows\system32\dsofile.dll
2008-12-06 22:53 . 2008-12-06 22:53 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\KALiNKOsoft
2008-12-06 22:48 . 2008-12-06 22:48 <DIR> d-------- c:\program files\KALiNKOsoft
2008-12-06 20:19 . 2008-12-10 02:48 <DIR> d-------- c:\program files\Sauerbraten
2008-12-05 03:18 . 2008-12-05 03:18 <DIR> d-------- c:\program files\Yahoo!
2008-12-05 03:18 . 2008-12-05 03:19 <DIR> d-------- c:\documents and settings\All Users\Application Data\Yahoo!
2008-12-05 03:14 . 2008-12-05 03:14 <DIR> d-------- c:\documents and settings\default
2008-12-04 21:21 . 2008-12-04 21:24 <DIR> d-------- c:\program files\Microsoft Streets & Trips 2009
2008-12-04 21:19 . 2008-12-04 21:19 <DIR> d-------- c:\program files\MSECache
2008-12-03 19:19 . 2008-12-03 19:19 <DIR> d-------- C:\97914e1baa146da91f977c89fc7be2d0
2008-12-03 19:18 . 2008-12-03 19:19 <DIR> d-------- C:\ecc3bbfb26245cd3fd5f96eb1e
2008-12-03 17:56 . 2008-12-03 17:56 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Global
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\electrochemic°\Application Data\j2 Messenger
2008-12-03 17:54 . 2008-12-03 17:54 <DIR> d-------- c:\documents and settings\All Users\Application Data\j2 Messenger 4.4 Output
2008-12-03 17:54 . 2008-12-03 17:54 0 --a------ c:\windows\system32\jConnect_4_4_Port
2008-12-03 17:53 . 2009-01-01 14:37 <DIR> d-------- c:\program files\j2 Messenger 4.4
2008-12-03 02:08 . 2008-04-13 20:12 159,232 --a------ c:\windows\system32\ptpusd.dll
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a------ c:\windows\system32\drivers\usbscan.sys
2008-12-03 02:08 . 2008-04-13 14:45 15,104 --a--c--- c:\windows\system32\dllcache\usbscan.sys
2008-12-03 02:08 . 2001-08-17 22:36 5,632 --a------ c:\windows\system32\ptpusb.dll
2008-12-01 22:42 . 2008-12-28 17:46 <DIR> d-------- c:\program files\Pidgin
2008-12-01 16:02 . 2008-04-13 14:45 26,368 --a--c--- c:\windows\system32\dllcache\usbstor.sys
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-01-01 21:36 --------- d-----w c:\documents and settings\electrochemic°\Application Data\.purple
2009-01-01 18:59 --------- d-----w c:\program files\Common Files\Symantec Shared
2009-01-01 14:51 53,248 ----a-w c:\windows\system32\zlib.dll
2008-12-25 20:19 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-11 09:43 --------- d-----w c:\program files\Bodog Poker
2008-12-06 02:06 --------- d-----w c:\documents and settings\electrochemic°\Application Data\vlc
2008-12-02 03:41 --------- d-----w c:\program files\Common Files\GTK
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS.ORIGINAL
2008-11-29 06:07 361,600 ----a-w c:\windows\system32\drivers\TCPIP.SYS
2008-11-29 03:20 --------- dcsh--w c:\program files\Common Files\WindowsLiveInstaller
2008-11-29 03:18 --------- d--h--w c:\program files\Creative Installation Information
2008-11-29 03:17 --------- d-----w c:\program files\Creative
2008-11-29 03:17 --------- d-----w c:\program files\Common Files\Creative
2008-11-28 06:26 --------- d-----w c:\program files\Common Files\Adobe
2008-11-28 06:20 --------- d-----w c:\program files\Syscan
2008-11-28 06:20 --------- d-----w c:\program files\Common Files\InstallShield
2008-10-23 12:36 286,720 ----a-w c:\windows\system32\gdi32.dll
2008-10-16 20:38 826,368 ----a-w c:\windows\system32\wininet.dll
2008-10-16 19:13 202,776 ----a-w c:\windows\system32\wuweb.dll
2008-10-16 19:13 1,809,944 ----a-w c:\windows\system32\wuaueng.dll
2008-10-16 19:12 561,688 ----a-w c:\windows\system32\wuapi.dll
2008-10-16 19:12 323,608 ----a-w c:\windows\system32\wucltui.dll
2008-10-16 19:09 92,696 ----a-w c:\windows\system32\cdm.dll
2008-10-16 19:09 51,224 ----a-w c:\windows\system32\wuauclt.exe
2008-10-16 19:09 43,544 ----a-w c:\windows\system32\wups2.dll
2008-10-16 19:08 34,328 ----a-w c:\windows\system32\wups.dll
2008-10-16 19:06 268,648 ----a-w c:\windows\system32\mucltui.dll
2008-10-16 19:06 208,744 ----a-w c:\windows\system32\muweb.dll
2008-10-03 10:02 247,326 ----a-w c:\windows\system32\strmdll.dll
.
((((((((((((((((((((((((((((( snapshot@2008-12-27_11.06.19.87 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-23 10:17:49 62,976 ----a-w c:\windows\$hf_mig$\KB955839\SP3QFE\tzchange.exe
+ 2007-11-30 12:39:22 17,272 ----a-w c:\windows\$hf_mig$\KB955839\spmsg.dll
+ 2007-11-30 12:39:22 231,288 ----a-w c:\windows\$hf_mig$\KB955839\spuninst.exe
+ 2007-11-30 12:39:22 26,488 ----a-w c:\windows\$hf_mig$\KB955839\update\spcustom.dll
+ 2007-11-30 12:39:22 755,576 ----a-w c:\windows\$hf_mig$\KB955839\update\update.exe
+ 2007-11-30 12:39:22 382,840 ----a-w c:\windows\$hf_mig$\KB955839\update\updspapi.dll
+ 2008-10-23 12:43:42 286,720 ----a-w c:\windows\$hf_mig$\KB956802\SP3QFE\gdi32.dll
+ 2008-07-08 13:02:01 17,272 ----a-w c:\windows\$hf_mig$\KB956802\spmsg.dll
+ 2008-07-08 13:02:02 231,288 ----a-w c:\windows\$hf_mig$\KB956802\spuninst.exe
+ 2008-07-08 13:02:01 26,488 ----a-w c:\windows\$hf_mig$\KB956802\update\spcustom.dll
+ 2008-07-09 07:38:29 755,576 ----a-w c:\windows\$hf_mig$\KB956802\update\update.exe
+ 2008-07-09 07:38:37 382,840 ----a-w c:\windows\$hf_mig$\KB956802\update\updspapi.dll
+ 2008-08-26 07:24:28 124,928 -c----w c:\windows\ie7updates\KB958215-IE7\advpack.dll
+ 2008-08-26 07:24:28 347,136 -c----w c:\windows\ie7updates\KB958215-IE7\dxtmsft.dll
+ 2008-08-26 07:24:28 214,528 -c----w c:\windows\ie7updates\KB958215-IE7\dxtrans.dll
+ 2008-08-26 07:24:28 133,120 -c----w c:\windows\ie7updates\KB958215-IE7\extmgr.dll
+ 2008-08-26 07:24:28 63,488 -c----w c:\windows\ie7updates\KB958215-IE7\icardie.dll
+ 2008-08-25 08:37:59 70,656 -c----w c:\windows\ie7updates\KB958215-IE7\ie4uinit.exe
+ 2008-08-26 07:24:28 153,088 -c----w c:\windows\ie7updates\KB958215-IE7\ieakeng.dll
+ 2008-08-26 07:24:28 230,400 -c----w c:\windows\ie7updates\KB958215-IE7\ieaksie.dll
+ 2008-08-23 05:54:51 161,792 -c----w c:\windows\ie7updates\KB958215-IE7\ieakui.dll
+ 2008-08-26 07:24:28 383,488 -c----w c:\windows\ie7updates\KB958215-IE7\ieapfltr.dll
+ 2008-08-26 07:24:29 384,512 -c----w c:\windows\ie7updates\KB958215-IE7\iedkcs32.dll
+ 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\ie7updates\KB958215-IE7\ieframe.dll
+ 2008-08-26 07:24:29 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\iernonce.dll
+ 2008-08-26 07:24:29 267,776 -c----w c:\windows\ie7updates\KB958215-IE7\iertutil.dll
+ 2008-08-25 08:38:00 13,824 -c----w c:\windows\ie7updates\KB958215-IE7\ieudinit.exe
+ 2008-08-23 05:56:15 635,848 -c----w c:\windows\ie7updates\KB958215-IE7\iexplore.exe
+ 2008-08-26 07:24:30 27,648 -c----w c:\windows\ie7updates\KB958215-IE7\jsproxy.dll
+ 2008-08-26 07:24:30 459,264 -c----w c:\windows\ie7updates\KB958215-IE7\msfeeds.dll
+ 2008-08-26 07:24:30 52,224 -c----w c:\windows\ie7updates\KB958215-IE7\msfeedsbs.dll
+ 2008-08-26 07:24:30 477,696 -c----w c:\windows\ie7updates\KB958215-IE7\mshtmled.dll
+ 2008-08-26 07:24:30 193,024 -c----w c:\windows\ie7updates\KB958215-IE7\msrating.dll
+ 2008-08-26 07:24:30 671,232 -c----w c:\windows\ie7updates\KB958215-IE7\mstime.dll
+ 2008-08-26 07:24:30 102,912 -c----w c:\windows\ie7updates\KB958215-IE7\occache.dll
+ 2008-08-26 07:24:30 44,544 -c----w c:\windows\ie7updates\KB958215-IE7\pngfilt.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:51 371,424 -c----w c:\windows\ie7updates\KB958215-IE7\spuninst\updspapi.dll
+ 2008-08-26 07:24:30 105,984 -c----w c:\windows\ie7updates\KB958215-IE7\url.dll
+ 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\ie7updates\KB958215-IE7\urlmon.dll
+ 2008-08-26 07:24:31 233,472 -c----w c:\windows\ie7updates\KB958215-IE7\webcheck.dll
+ 2008-08-26 07:24:31 826,368 -c----w c:\windows\ie7updates\KB958215-IE7\wininet.dll
+ 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\ie7updates\KB960714-IE7\mshtml.dll
+ 2007-03-06 01:22:39 213,216 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\spuninst.exe
+ 2007-03-06 01:23:47 371,424 -c----w c:\windows\ie7updates\KB960714-IE7\spuninst\updspapi.dll
+ 2009-01-01 04:04:59 10,134 ----a-r c:\windows\Installer\{0F938C41-8DDD-6C8A-A234-4B5EBA0E9932}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:12 10,134 ----a-r c:\windows\Installer\{0FDEFFDE-F20C-8AF3-828A-076CCAEDEDBA}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:27 10,134 ----a-r c:\windows\Installer\{100E3E1D-3771-8668-8064-4AD38848BBE1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:15 10,134 ----a-r c:\windows\Installer\{1283C02D-CD9C-0206-355E-02683341FD64}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:22 10,134 ----a-r c:\windows\Installer\{13043D3E-558B-7D1C-13BE-783187299F59}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:40 10,134 ----a-r c:\windows\Installer\{162AAA0F-C766-6832-3812-5E21FB1DA80C}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:32 10,134 ----a-r c:\windows\Installer\{1ED6E4D0-8DB0-A333-DEA6-188F957F5A43}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:00 10,134 ----a-r c:\windows\Installer\{1ED6E4D0-8DB0-A333-DEA6-188F957F5A43}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:32 10,134 ----a-r c:\windows\Installer\{1F8BC334-1EB1-F4D2-DBF8-97C1AA64DE6C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:18 10,134 ----a-r c:\windows\Installer\{20C5A8DE-62D2-B1C1-B60B-2106F1146F30}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:02 10,134 ----a-r c:\windows\Installer\{24CE4B41-9A9B-B7DC-01AD-E815F4F60E7C}\ARPPRODUCTICON.exe
+ 2008-12-30 00:25:32 364,726 ----a-r c:\windows\Installer\{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}\SkypeIcon.exe
+ 2009-01-01 04:05:36 10,134 ----a-r c:\windows\Installer\{25462A56-9707-749D-250C-1137754BD238}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:19 10,134 ----a-r c:\windows\Installer\{2A75E60D-3335-9D96-BA98-975BCF6760CC}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:29 10,134 ----a-r c:\windows\Installer\{2B7330BD-C032-EE14-A27A-A7998244F3D1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:49 10,134 ----a-r c:\windows\Installer\{2C5C7563-B8B4-3A2E-7C5C-8F5365ED6874}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:23 10,134 ----a-r c:\windows\Installer\{2D128229-CA51-A674-E3AA-225D15F37D98}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:08 10,134 ----a-r c:\windows\Installer\{31D3AB6C-F1AB-8C52-85B7-E30BFA88C531}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:01 10,134 ----a-r c:\windows\Installer\{395D29E5-0FAE-751C-F682-F23479A8806A}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:25 10,134 ----a-r c:\windows\Installer\{3B9E28EC-5D0E-44F4-6E82-CBDCF29CAE49}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:44 10,134 ----a-r c:\windows\Installer\{407E0CBD-D6BF-F243-6DE9-F1EEA525BA1C}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:06 10,134 ----a-r c:\windows\Installer\{407E0CBD-D6BF-F243-6DE9-F1EEA525BA1C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:54 10,134 ----a-r c:\windows\Installer\{55969DFE-C3FF-E015-256D-D70EFBAB805C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:10 10,134 ----a-r c:\windows\Installer\{59A0E0DA-E80F-D9E2-32C6-8AA559D33C8E}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:05 10,134 ----a-r c:\windows\Installer\{5AB1B545-5FB7-35D4-D09C-77D0949B2164}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:44 10,134 ----a-r c:\windows\Installer\{5EC634FA-5047-38B2-A53A-15963D9BD872}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:18 10,134 ----a-r c:\windows\Installer\{5EC634FA-5047-38B2-A53A-15963D9BD872}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:56 10,134 ----a-r c:\windows\Installer\{61125E9F-D49A-CD2D-1722-FB9D654E40F2}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:58 10,134 ----a-r c:\windows\Installer\{651AFCC8-2F1A-8132-0A33-FA5F041380BA}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:09 10,134 ----a-r c:\windows\Installer\{651AFCC8-2F1A-8132-0A33-FA5F041380BA}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:04 10,134 ----a-r c:\windows\Installer\{69EF33D7-3425-1409-0BE1-C4F3A6FB57A8}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:21 10,134 ----a-r c:\windows\Installer\{69EF33D7-3425-1409-0BE1-C4F3A6FB57A8}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:03 10,134 ----a-r c:\windows\Installer\{6BFBB953-B60F-6058-33BB-3AB2A0971FF9}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:14 10,134 ----a-r c:\windows\Installer\{6CCEE8D0-012D-AB81-E824-4415B1110669}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:14 10,134 ----a-r c:\windows\Installer\{6DF5D680-2490-BE97-CA76-E1069C8ECE7B}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:16 10,134 ----a-r c:\windows\Installer\{7510EF8C-99B9-8533-524E-BF41BDC04188}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:14 10,134 ----a-r c:\windows\Installer\{7510EF8C-99B9-8533-524E-BF41BDC04188}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:18 10,134 ----a-r c:\windows\Installer\{760DE1B8-D1C9-2DCF-8CE3-3AB7D2D974BC}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:17 10,134 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:25 10,134 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\ARPPRODUCTICON.exe
- 2008-12-26 15:13:17 9,158 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2008-12-30 19:28:25 9,158 ----a-r c:\windows\Installer\{773040E1-3B60-6507-C387-71F8F0A03C59}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:04:30 10,134 ----a-r c:\windows\Installer\{774DB051-42B4-DF78-9B7F-EEA352BBC5B5}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:10 10,134 ----a-r c:\windows\Installer\{819F2F52-EAEC-0DB1-D2EE-66F48ACF43C6}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:51 10,134 ----a-r c:\windows\Installer\{92DEC792-A722-5991-2607-3EE3A4BD502B}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:08 10,134 ----a-r c:\windows\Installer\{92DEC792-A722-5991-2607-3EE3A4BD502B}\ARPPRODUCTICON.exe
- 2008-12-26 15:12:05 10,134 ----a-r c:\windows\Installer\{96793032-8651-805A-67EF-E1759C1A8E3D}\ARPPRODUCTICON.exe
+ 2008-12-30 19:28:12 10,134 ----a-r c:\windows\Installer\{96793032-8651-805A-67EF-E1759C1A8E3D}\ARPPRODUCTICON.exe
+ 2009-01-01 04:06:00 25,214 ----a-r c:\windows\Installer\{9862B19F-4CAD-4EED-920F-2F378D84393F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:28 10,134 ----a-r c:\windows\Installer\{9E021ACC-F408-27C7-2407-587852C15364}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:39 10,134 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\ARPPRODUCTICON.exe
- 2008-12-25 20:25:43 9,158 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:05:39 9,158 ----a-r c:\windows\Installer\{9FABF436-2541-70C2-49D4-FF8945EAAECB}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2009-01-01 04:04:51 10,134 ----a-r c:\windows\Installer\{A01028FE-68D1-E3F2-160E-9763905BF095}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:26 10,134 ----a-r c:\windows\Installer\{A0E38350-2547-161B-2D3E-C5EFD24DD70F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:36 10,134 ----a-r c:\windows\Installer\{A228A56E-8663-61A6-768E-7A55890C0013}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:11 10,134 ----a-r c:\windows\Installer\{A493EC63-3021-73EF-2097-8FC2DE857021}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:16 10,134 ----a-r c:\windows\Installer\{A4C0E536-D094-CA7E-4F7F-18043992FD36}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:13 10,134 ----a-r c:\windows\Installer\{A6BD418C-37B2-4434-9F96-23C2CAAFF11C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:32 10,134 ----a-r c:\windows\Installer\{A7ECFC98-E5D5-BBDE-C5CE-D4177E4DA573}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:04 10,134 ----a-r c:\windows\Installer\{AA09F72E-8B3D-ABDF-3FC8-650176EA3EB8}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:17 10,134 ----a-r c:\windows\Installer\{ABF68C52-0ADD-C352-5998-13D16BC3B359}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:26 10,134 ----a-r c:\windows\Installer\{B094F70F-2CC2-5062-8534-D3830FC4B018}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:58 10,134 ----a-r c:\windows\Installer\{B094F70F-2CC2-5062-8534-D3830FC4B018}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:00 10,134 ----a-r c:\windows\Installer\{BE3F26EE-F81B-4A50-8376-271F5CA84C5B}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:33 10,134 ----a-r c:\windows\Installer\{C0721ABB-9A28-A7F3-6E5A-D30550C50D26}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:34 10,134 ----a-r c:\windows\Installer\{C9F100D9-5D68-1B5B-F8C8-3632876AF990}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:00 10,134 ----a-r c:\windows\Installer\{CA42C38C-B369-B190-AD06-76D3AC95CFAC}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:51 10,134 ----a-r c:\windows\Installer\{CA42C38C-B369-B190-AD06-76D3AC95CFAC}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:21 10,134 ----a-r c:\windows\Installer\{D08027B6-F704-A2FA-EE4E-EB955E2BB591}\ARPPRODUCTICON.exe
+ 2009-01-01 04:03:56 10,134 ----a-r c:\windows\Installer\{D083BDDE-09F7-D12A-9C81-4EE4AFE3C933}\ARPPRODUCTICON.exe
- 2008-12-26 15:11:13 10,134 ----a-r c:\windows\Installer\{D3B1C799-CB73-42DE-BA0F-2344793A095C}\ARPPRODUCTICON.exe
+ 2008-12-30 19:27:56 10,134 ----a-r c:\windows\Installer\{D3B1C799-CB73-42DE-BA0F-2344793A095C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:07 10,134 ----a-r c:\windows\Installer\{D4F7D59E-9F53-3ADC-1D4A-5A698445D538}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:38 10,134 ----a-r c:\windows\Installer\{D56625ED-7605-5B0C-70EE-B0C80F0B7B38}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:45 10,134 ----a-r c:\windows\Installer\{DFA2EACA-8915-29EE-E946-F8542AE21171}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:25 10,134 ----a-r c:\windows\Installer\{E32CE8E3-D4D3-60CE-A5FC-3EA3D0B9118C}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:21 10,134 ----a-r c:\windows\Installer\{E40CFA81-9EF9-B589-34FB-94D6C801967B}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:47 10,134 ----a-r c:\windows\Installer\{E5F5743C-15C6-6F6B-F515-86C36E96464F}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:23 10,134 ----a-r c:\windows\Installer\{ED425483-53D8-5F86-98DA-50834FE77F7E}\ARPPRODUCTICON.exe
+ 2009-01-01 04:05:30 10,134 ----a-r c:\windows\Installer\{F5FDCCDE-9909-02CE-ED67-0AE3905B32A1}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:42 10,134 ----a-r c:\windows\Installer\{F7861EB4-0B8A-91E8-6C1C-4F99C7002E96}\ARPPRODUCTICON.exe
+ 2009-01-01 04:04:34 10,134 ----a-r c:\windows\Installer\{FC7E9E53-9A60-3E08-C909-83B00D30ADAE}\ARPPRODUCTICON.exe
- 2008-08-26 07:24:28 124,928 ----a-w c:\windows\system32\advpack.dll
+ 2008-10-16 20:38:34 124,928 ----a-w c:\windows\system32\advpack.dll
- 2008-08-26 07:24:28 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
+ 2008-10-16 20:38:34 124,928 -c----w c:\windows\system32\dllcache\advpack.dll
- 2008-08-26 07:24:28 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 -c----w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 -c----w c:\windows\system32\dllcache\dxtrans.dll
- 2008-08-26 07:24:28 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-16 20:38:35 133,120 -c----w c:\windows\system32\dllcache\extmgr.dll
+ 2008-10-23 12:36:14 286,720 -c----w c:\windows\system32\dllcache\gdi32.dll
- 2008-08-26 07:24:28 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
+ 2008-10-16 20:38:35 63,488 -c----w c:\windows\system32\dllcache\icardie.dll
- 2008-08-25 08:37:59 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 -c----w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 -c----w c:\windows\system32\dllcache\ieakeng.dll
- 2008-08-26 07:24:28 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 -c----w c:\windows\system32\dllcache\ieaksie.dll
- 2008-08-23 05:54:51 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
+ 2008-10-15 07:04:53 161,792 -c----w c:\windows\system32\dllcache\ieakui.dll
- 2008-08-26 07:24:28 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 -c----w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 -c----w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 -c----w c:\windows\system32\dllcache\ieframe.dll
- 2008-08-26 07:24:29 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
+ 2008-10-16 20:38:37 44,544 -c----w c:\windows\system32\dllcache\iernonce.dll
- 2008-08-26 07:24:29 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
+ 2008-10-16 20:38:37 267,776 -c----w c:\windows\system32\dllcache\iertutil.dll
- 2008-08-25 08:38:00 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 -c----w c:\windows\system32\dllcache\ieudinit.exe
- 2008-08-23 05:56:15 635,848 -c----w c:\windows\system32\dllcache\iexplore.exe
+ 2008-10-15 07:06:26 633,632 -c----w c:\windows\system32\dllcache\iexplore.exe
- 2008-08-26 07:24:30 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 -c----w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-19 00:03:58 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
+ 2008-06-18 06:09:22 100,864 -c--a-w c:\windows\system32\dllcache\logagent.exe
- 2008-08-26 07:24:30 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 -c----w c:\windows\system32\dllcache\msfeeds.dll
- 2008-08-26 07:24:30 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 -c----w c:\windows\system32\dllcache\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 -c----w c:\windows\system32\dllcache\mshtml.dll
- 2008-08-26 07:24:30 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 -c----w c:\windows\system32\dllcache\mshtmled.dll
- 2008-08-26 07:24:30 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
+ 2008-10-16 20:38:38 193,024 -c----w c:\windows\system32\dllcache\msrating.dll
- 2008-08-26 07:24:30 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
+ 2008-10-16 20:38:39 671,232 -c----w c:\windows\system32\dllcache\mstime.dll
- 2008-08-26 07:24:30 102,912 -c----w c:\windows\system32\dllcache\occache.dll
+ 2008-10-16 20:38:39 102,912 -c----w c:\windows\system32\dllcache\occache.dll
- 2008-08-26 07:24:30 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 -c----w c:\windows\system32\dllcache\pngfilt.dll
- 2008-04-14 00:12:07 246,814 -c--a-w c:\windows\system32\dllcache\strmdll.dll
+ 2008-10-03 10:02:42 247,326 -c--a-w c:\windows\system32\dllcache\strmdll.dll
- 2008-08-26 07:24:30 105,984 -c----w c:\windows\system32\dllcache\url.dll
+ 2008-10-16 20:38:39 105,984 -c----w c:\windows\system32\dllcache\url.dll
- 2008-08-26 07:24:31 1,159,680 -c----w c:\windows\system32\dllcache\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 -c----w c:\windows\system32\dllcache\urlmon.dll
- 2008-08-26 07:24:31 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
+ 2008-10-16 20:38:39 233,472 -c----w c:\windows\system32\dllcache\webcheck.dll
- 2008-08-26 07:24:31 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
+ 2008-10-16 20:38:40 826,368 -c----w c:\windows\system32\dllcache\wininet.dll
- 2006-10-19 01:47:20 937,984 -c--a-w c:\windows\system32\dllcache\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 -c--a-w c:\windows\system32\dllcache\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 -c--a-w c:\windows\system32\dllcache\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 -c--a-w c:\windows\system32\dllcache\WMVCore.dll
- 2008-08-26 07:24:28 347,136 ----a-w c:\windows\system32\dxtmsft.dll
+ 2008-10-16 20:38:34 347,136 ----a-w c:\windows\system32\dxtmsft.dll
- 2008-08-26 07:24:28 214,528 ----a-w c:\windows\system32\dxtrans.dll
+ 2008-10-16 20:38:34 214,528 ----a-w c:\windows\system32\dxtrans.dll
- 2008-08-26 07:24:28 133,120 ----a-w c:\windows\system32\extmgr.dll
+ 2008-10-16 20:38:35 133,120 ----a-w c:\windows\system32\extmgr.dll
- 2008-08-26 07:24:28 63,488 ----a-w c:\windows\system32\icardie.dll
+ 2008-10-16 20:38:35 63,488 ----a-w c:\windows\system32\icardie.dll
- 2008-08-25 08:37:59 70,656 ----a-w c:\windows\system32\ie4uinit.exe
+ 2008-10-16 13:11:09 70,656 ----a-w c:\windows\system32\ie4uinit.exe
- 2008-08-26 07:24:28 153,088 ----a-w c:\windows\system32\ieakeng.dll
+ 2008-10-16 20:38:35 153,088 ----a-w c:\windows\system32\ieakeng.dll
- 2008-08-26 07:24:28 230,400 ----a-w c:\windows\system32\ieaksie.dll
+ 2008-10-16 20:38:35 230,400 ----a-w c:\windows\system32\ieaksie.dll
- 2008-08-23 05:54:51 161,792 ----a-w c:\windows\system32\ieakui.dll
+ 2008-10-15 07:04:53 161,792 ----a-w c:\windows\system32\ieakui.dll
- 2008-08-26 07:24:28 383,488 ----a-w c:\windows\system32\ieapfltr.dll
+ 2008-10-16 20:38:35 383,488 ----a-w c:\windows\system32\ieapfltr.dll
- 2008-08-26 07:24:29 384,512 ----a-w c:\windows\system32\iedkcs32.dll
+ 2008-10-16 20:38:35 384,512 ----a-w c:\windows\system32\iedkcs32.dll
- 2008-10-03 17:41:15 6,066,176 ----a-w c:\windows\system32\ieframe.dll
+ 2008-10-16 20:38:37 6,066,176 ----a-w c:\windows\system32\ieframe.dll
- 2008-08-26 07:24:29 44,544 ----a-w c:\windows\system32\iernonce.dll
+ 2008-10-16 20:38:37 44,544 ----a-w c:\windows\system32\iernonce.dll
- 2008-08-26 07:24:29 267,776 ----a-w c:\windows\system32\iertutil.dll
+ 2008-10-16 20:38:37 267,776 ----a-w c:\windows\system32\iertutil.dll
- 2008-08-25 08:38:00 13,824 ----a-w c:\windows\system32\ieudinit.exe
+ 2008-10-16 13:11:09 13,824 ----a-w c:\windows\system32\ieudinit.exe
- 2008-08-26 07:24:30 27,648 ----a-w c:\windows\system32\jsproxy.dll
+ 2008-10-16 20:38:37 27,648 ----a-w c:\windows\system32\jsproxy.dll
- 2006-10-19 00:03:58 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-06-18 06:09:22 100,864 ----a-w c:\windows\system32\logagent.exe
+ 2008-12-09 20:24:38 17,593,280 ----a-w c:\windows\system32\MRT.exe
- 2008-08-26 07:24:30 459,264 ----a-w c:\windows\system32\msfeeds.dll
+ 2008-10-16 20:38:37 459,264 ----a-w c:\windows\system32\msfeeds.dll
- 2008-08-26 07:24:30 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
+ 2008-10-16 20:38:37 52,224 ----a-w c:\windows\system32\msfeedsbs.dll
- 2008-08-27 08:24:32 3,593,216 ----a-w c:\windows\system32\mshtml.dll
+ 2008-12-13 06:40:02 3,593,216 ----a-w c:\windows\system32\mshtml.dll
- 2008-08-26 07:24:30 477,696 ----a-w c:\windows\system32\mshtmled.dll
+ 2008-10-16 20:38:38 477,696 ----a-w c:\windows\system32\mshtmled.dll
- 2008-08-26 07:24:30 193,024 ----a-w c:\windows\system32\msrating.dll
+ 2008-10-16 20:38:38 193,024 ----a-w c:\windows\system32\msrating.dll
- 2008-08-26 07:24:30 671,232 ----a-w c:\windows\system32\mstime.dll
+ 2008-10-16 20:38:39 671,232 ----a-w c:\windows\system32\mstime.dll
- 2008-08-26 07:24:30 102,912 ----a-w c:\windows\system32\occache.dll
+ 2008-10-16 20:38:39 102,912 ----a-w c:\windows\system32\occache.dll
- 2008-08-26 07:24:30 44,544 ----a-w c:\windows\system32\pngfilt.dll
+ 2008-10-16 20:38:39 44,544 ----a-w c:\windows\system32\pngfilt.dll
- 2007-07-27 15:41:40 16,760 ----a-w c:\windows\system32\spmsg.dll
+ 2007-11-30 12:39:22 17,272 ------w c:\windows\system32\spmsg.dll
- 2008-07-11 12:42:28 62,976 ----a-w c:\windows\system32\tzchange.exe
+ 2008-10-23 10:06:59 62,976 ----a-w c:\windows\system32\tzchange.exe
- 2008-08-26 07:24:30 105,984 ----a-w c:\windows\system32\url.dll
+ 2008-10-16 20:38:39 105,984 ----a-w c:\windows\system32\url.dll
- 2008-08-26 07:24:31 1,159,680 ----a-w c:\windows\system32\urlmon.dll
+ 2008-10-16 20:38:39 1,160,192 ----a-w c:\windows\system32\urlmon.dll
- 2008-08-26 07:24:31 233,472 ----a-w c:\windows\system32\webcheck.dll
+ 2008-10-16 20:38:39 233,472 ----a-w c:\windows\system32\webcheck.dll
- 2006-10-19 01:47:20 937,984 ----a-w c:\windows\system32\wmnetmgr.dll
+ 2008-06-18 10:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2006-10-19 01:47:22 2,450,944 ----a-w c:\windows\system32\wmvcore.dll
+ 2008-06-18 10:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AlcoholAutomount"="c:\program files\Alcohol Soft\Alcohol 120\axcmd.exe" [2008-09-26 4608]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Pinnacle Game Profiler"="c:\program files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" [2008-12-06 2535424]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2005-12-04 461584]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2002-09-21 54976]
"ccRegVfy"="c:\program files\Common Files\Symantec Shared\ccRegVfy.exe" [2002-09-21 38592]
"SmartGuardian"="c:\program files\SOYO\HW Monitor\ITESmart.exe" [2002-05-24 163840]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2008-01-21 61440]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-09 136600]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\electrochemicø\Start Menu\Programs\Startup\
Dialog Box Assistant.lnk - c:\program files\OSDEx\OSDEx.exe [2002-07-13 176128]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Pidgin.lnk - c:\program files\Pidgin\pidgin.exe [2008-12-21 45603]
TrayMin.lnk - c:\program files\TrayMin\traymin.exe [2008-12-27 45056]
WordWeb Pro.lnk - c:\program files\WordWeb\wweb32.exe [2008-09-26 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-06-12 02:38 34672 c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Update]
--a----t- 2008-09-26 16:37 133104 c:\documents and settings\electrochemic°\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\j2 4.4]
--a------ 2008-10-07 16:53 95744 c:\program files\j2 Messenger 4.4\J2GDllCmd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PRONoMgr.exe]
--a------ 2003-03-11 15:24 86016 c:\program files\Intel\NCS\PROSet\PRONoMgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSnD]
-rahs---- 2008-07-07 09:42 4891472 c:\program files\Spybot - Search & Destroy\SpybotSD.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLSetupSvc"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"RegistryMechanic"=
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UpdatesDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"x:\\Software Downloads\\Data.Integrity\\utorrent.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;c:\windows\system32\DRIVERS\SI3112r.sys [2007-08-29 116264]
R2 ccPxySvc;Symantec Proxy Service;"c:\program files\Norton Personal Firewall\ccPxySvc.exe" [2002-09-21 34496]
R3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2008-12-25 93696]
R3 ctgame;Game Port;c:\windows\system32\DRIVERS\ctgame.sys [2002-12-30 18840]
R3 iteio;iteio;\??\c:\windows\system32\drivers\iteio.sys [2008-09-25 3680]
S3 COMMONFX;COMMONFX;c:\windows\system32\drivers\COMMONFX.SYS [2008-06-27 99352]
S3 CTAUDFX;CTAUDFX;c:\windows\system32\drivers\CTAUDFX.SYS [2008-06-27 555032]
S3 CTERFXFX;CTERFXFX;c:\windows\system32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTSBLFX;CTSBLFX;c:\windows\system32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 itsernum;itsernum Filter ÅX°Êµ{¦¡;c:\windows\system32\DRIVERS\itsernum.sys [2008-09-25 20133]
S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\windows\system32\DRIVERS\wg111v2.sys [2008-09-27 112384]
*Newly Created Service* - ALERTER
.
Contents of the 'Scheduled Tasks' folder
2009-01-01 c:\windows\Tasks\GoogleUpdateTaskUser.job
- c:\documents and settings\electrochemic []
2008-09-26 c:\windows\Tasks\Symantec NetDetect.job
- c:\program files\Symantec\LiveUpdate\NDETECT.EXE [2002-08-07 08:04]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local
Trusted Zone: fighterace.ketsujin.com
Trusted Zone: primary.ketsujin.com
Trusted Zone: update.ketsujin.com
Trusted Zone: www.ketsujin.com
Trusted Zone: www.stormofaces.com
c:\windows\Downloaded Program Files\CTSUEng.ocx - c:\windows\Downloaded Program Files\CTSUEngn.ocx
O16 -: {6C269571-C6D7-4818-BCA4-32A035E8C884}
hxxp://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
c:\windows\Downloaded Program Files\CTSUEng.inf
FF - ProfilePath - c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\
FF - prefs.js: browser.search.selectedEngine - Google Images
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - component: c:\documents and settings\electrochemic°\Application Data\Mozilla\Firefox\Profiles\i7eprqrr.default\extensions\{a7c6cf7f-112c-4500-a7ea-39801a327e5f}\platform\WINNT_x86-msvc\components\ipc.dll
FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll
FF - plugin: c:\program files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-01 16:41:34
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(708)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2009-01-01 16:42:17
ComboFix-quarantined-files.txt 2009-01-01 21:42:15
ComboFix2.txt 2008-12-28 13:23:30
ComboFix3.txt 2008-12-27 22:14:49
ComboFix4.txt 2008-12-27 16:06:55
Pre-Run: 50,380,787,712 bytes free
Post-Run: 50,394,845,184 bytes free
500 --- E O F --- 2008-12-30 06:47:55
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:29:59 PM, on 1/1/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\SOYO\HW Monitor\ITESmart.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe
C:\Program Files\Pidgin\pidgin.exe
C:\Program Files\TrayMin\traymin.exe
C:\Program Files\WordWeb\wweb32.exe
C:\Program Files\OSDEx\OSDEx.exe
X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\AcroRd32Info.exe
X:\TorrentialRain\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [SmartGuardian] C:\Program Files\SOYO\HW Monitor\ITESmart.exe
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 120\axcmd.exe" /automount
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Pinnacle Game Profiler] "C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle.exe" -atboottime
O4 - S-1-5-18 Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'SYSTEM')
O4 - S-1-5-18 Startup: E-mail.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe (User 'Default user')
O4 - .DEFAULT Startup: E-mail.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe (User 'Default user')
O4 - Startup: Dialog Box Assistant.lnk = C:\Program Files\OSDEx\OSDEx.exe
O4 - Startup: E-mail.lnk = ?
O4 - Startup: Shortcut to tclock.lnk = X:\Software Downloads\Essential\tclocklight-040702-3\tclock.exe
O4 - Global Startup: Pidgin.lnk = C:\Program Files\Pidgin\pidgin.exe
O4 - Global Startup: TrayMin.lnk = C:\Program Files\TrayMin\traymin.exe
O4 - Global Startup: WordWeb Pro.lnk = C:\Program Files\WordWeb\wweb32.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Documents and Settings\electrochemic°\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (HKCU)
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1222471195500
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15106/CTPID.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
O23 - Service: PinnacleUpdate Service (PinnacleUpdateSvc) - KALiNKOsoft - C:\Program Files\KALiNKOsoft\Pinnacle Game Profiler\pinnacle_updater.exe
O23 - Service: StarWind AE Service (StarWindServiceAE) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe
--
End of file - 7027 bytes