here is main.txt
Deckard's System Scanner v20070426.43
Run by Patrick Schmied on 2007-05-28 at 15:00:11
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- Last 5 Restore Point(s) --
7: 2007-05-27 00:35:31 UTC - RP121 - Scheduled Checkpoint
6: 2007-05-26 03:14:04 UTC - RP120 - Windows Update
5: 2007-05-25 16:21:01 UTC - RP119 - Scheduled Checkpoint
4: 2007-05-24 13:55:31 UTC - RP118 - Windows Defender Checkpoint
3: 2007-05-24 06:12:00 UTC - RP116 - Windows Update
-- First Restore Point --
1: 2007-05-22 15:18:25 UTC - RP114 - Scheduled Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-05-28 15:03:42
Platform: Windows Vista (6.00.6000)
MSIE: Internet Explorer (7.0.6000.16448)
Running processes:
C:\Windows\System32\taskeng.exe
C:\Windows\System32\dwm.exe
C:\Windows\explorer.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe
C:\Windows\stsystra.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\Teleca Shared\CapabilityManager.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\System32\ctfmon.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\Teleca Shared\Generic.exe
C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe
C:\Windows\System32\mobsync.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Users\Patrick Schmied\Desktop\dss.exe
C:\Windows\System32\SearchFilterHost.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {15E6AC21-3DD7-49C1-B48A-66DAFF9755B5} - C:\Windows\System32\jkhih.dll
O2 - BHO: (no name) - {4B646AFB-9341-4330-8FD1-C32485AEE619} - C:\Windows\System32\rjnpguwa.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {CD6789D8-DB78-4C6F-AE5D-B15F603775A2} - C:\Windows\System32\ctahpcee.dll
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [MSKServerExe] C:\Program Files\McAfee\SpamKiller\MSKSrvr.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [D-Link Wireless G WUA-1340] C:\Program Files\D-Link\Wireless G WUA-1340\AirGCFG.exe
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Snapfire Plus\Corel Photo Downloader.exe
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NoteBurner] C:\Program Files\NoteBurner\VTBurnerGUI.exe /silence
O4 - HKLM\..\Run: [setup] rundll32.exe "C:\Windows\system32\ltxhlxln.dll",realset
O4 - HKCU\..\Run: [Steam] C:\Program Files\Valve\Steam\\Steam.exe -silent
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [RealPlayer] "C:\Program Files\Real\RealOne Player\realplay.exe" /RunUPGToolCommandReBoot
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra 'Tools' menuitem: (no name) - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\Windows\network diagnostic\xpnetdiag.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://download.microsoft.com/downl...-40e1-a617-af65a72a0465/LegitCheckControl.cab
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) -
http://cdn.scan.onecare.live.com/resource/download/scanner/en-us/wlscctrl2.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.mail.live.com/mail/w1/resources/VistaMSNPUplden-ca.cab
O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) -
http://www.ca.com/us/securityadvisor/pestscan/pestscan.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} () -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162929413578
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
http://www.ca.com/us/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mctp - {d7b95390-b1c5-11d0-b111-0080c712fe82} - C:\Program Files\Microsoft ActiveSync\aatp.dll
O18 - Protocol: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\microsoft shared\Information Retrieval\msitss.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll
O18 - Protocol: mso-offdap11 - {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\microsoft shared\Web Components\11\OWC11.DLL
O18 - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\microsoft shared\OFFICE11\MSOXMLMF.DLL
O20 - Winlogon Notify: jkhih - C:\Windows\System32\jkhih.dll
O23 - Service: CaCCProvSP - CA, Inc. - "C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe"
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe
O23 - Service: CCProvSP - TODO: <Company name> - "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ccprovsp.exe"
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"
O23 - Service: iPod Service - Apple Inc. - "C:\Program Files\iPod\bin\iPodService.exe"
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
O23 - Service: SoundMovieServer - SoundMovieServer - "C:\Windows\system32\snmvtsvc.exe"
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe
O23 - Service: VundoFix Service (VundoFixSvc) - Atribune.org - C:\Windows\System32\VundoFixSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE %SystemRoot%\System32\bcmwltry.exe
-- HijackThis Fixed Entries (C:\Users\Patrick Schmied\Documents\HijackThis\backups\) --------------------------------------------------------------------------------
backup-20070527-235614-126 O4 - HKLM\..\Run: [setup] rundll32.exe "C:\Windows\system32\ylfephpd.dll",realset
backup-20070527-235614-201 O2 - BHO: Sideload.BHO - {B4CEB816-A720-423A-82F2-63553142634D} - mscoree.dll (file missing)
backup-20070527-235614-398 O20 - Winlogon Notify: gebcaww - C:\Windows\SYSTEM32\gebcaww.dll
backup-20070527-235614-733 O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
backup-20070527-235614-778 O2 - BHO: (no name) - {4B646AFB-9341-4330-8FD1-C32485AEE619} - C:\Windows\system32\tamvsipj.dll
backup-20070527-235614-847 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20070527-235614-867 O4 - HKLM\..\Run: [runner1] C:\Windows\retadpu1000272.exe 61A847B5BBF72813329B385475FB01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
backup-20070527-235614-932 O4 - HKLM\..\Run: [SManager] smanager.7.exe
backup-20070527-235614-972 O2 - BHO: (no name) - {40B4D1BC-1F9B-479A-8D6E-022CF3014935} - C:\Windows\system32\jkhih.dll
backup-20070527-235615-419 O20 - Winlogon Notify: jkhih - C:\Windows\system32\jkhih.dll
backup-20070527-235616-141 O20 - Winlogon Notify: winmul32 - winmul32.dll (file missing)
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 APPDRV - c:\windows\system32\drivers\appdrv.sys <Not Verified; Dell Inc; Application Driver>
R2 ANIO (ANIO Service) - \??\c:\windows\system32\anio.sys
R3 WmaCDriverV32 - c:\windows\system32\drivers\wmacdriverv32.sys <Not Verified; Windows (R) Codename Longhorn DDK provider; Windows (R) Codename Longhorn DDK driver>
S3 DSproct - \??\c:\program files\dell support\gtaction\triggers\dsproct.sys
S3 SE31bus (Sony Ericsson Device 049 Driver driver (WDM)) - c:\windows\system32\drivers\se31bus.sys <Not Verified; MCCI; Sony Ericsson Device 049 Driver>
S3 SE31mdfl (Sony Ericsson Device 049 USB WMC Modem Filter) - c:\windows\system32\drivers\se31mdfl.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB WMC Modem Filter Driver>
S3 SE31mdm (Sony Ericsson Device 049 USB WMC Modem Driver) - c:\windows\system32\drivers\se31mdm.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB WMC Data Modem>
S3 SE31mgmt (Sony Ericsson Device 049 USB WMC Device Management Drivers (WDM)) - c:\windows\system32\drivers\se31mgmt.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB WMC Device Management>
S3 se31nd5 (Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (NDIS)) - c:\windows\system32\drivers\se31nd5.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB Ethernet Emulation>
S3 SE31obex (Sony Ericsson Device 049 USB WMC OBEX Interface) - c:\windows\system32\drivers\se31obex.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB WMC OBEX Interface>
S3 se31unic (Sony Ericsson Device 049 USB Ethernet Emulation SEMC49 (WDM)) - c:\windows\system32\drivers\se31unic.sys <Not Verified; MCCI; Sony Ericsson Device 049 USB Ethernet Emulation>
S4 dac2w2k - c:\windows\system32\drivers\dac2w2k.sys <Not Verified; Mylex Corporation; Mylex Disk Array Controller Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 MSSQL$MICROSOFTSMLBIZ - "c:\program files\microsoft sql server\mssql$microsoftsmlbiz\binn\sqlservr.exe" -smicrosoftsmlbiz <Not Verified; Microsoft Corporation; Microsoft SQL Server>
R2 NICCONFIGSVC - c:\program files\dell\quickset\nicconfigsvc.exe <Not Verified; Dell Inc.; NicConfigSvc>
S2 wltrysvc (Dell Wireless WLAN Tray Service) - c:\windows\system32\wltrysvc.exe c:\windows\system32\bcmwltry.exe (file missing)
S3 SoundMovieServer - "c:\windows\system32\snmvtsvc.exe" <Not Verified; SoundMovieServer; SoundMovieServer>
S3 SQLAgent$MICROSOFTSMLBIZ - "c:\program files\microsoft sql server\mssql$microsoftsmlbiz\binn\sqlagent.exe" -i microsoftsmlbiz <Not Verified; Microsoft Corporation; Microsoft SQL Server>
S3 VundoFixSvc (VundoFix Service) - vundofixsvc.exe <Not Verified; Atribune.org; Vundofix Service>
-- Scheduled Tasks -------------------------------------------------------------
2007-05-27 22:27:24 438 --ah----- C:\Windows\Tasks\User_Feed_Synchronization-{97DFEC33-0CAF-4926-90F2-9E5919AA3724}.job
-- Files created between 2007-04-28 and 2007-05-28 -----------------------------
2007-05-28 00:14:52 132660 --a------ C:\Windows\system32\ltxhlxln.dll
2007-05-28 00:13:41 50745 --a------ C:\Windows\system32\rjnpguwa.dll
2007-05-28 00:07:15 0 d-------- C:\!KillBox
2007-05-27 23:59:10 124436 --a------ C:\Windows\system32\ctahpcee.dll
2007-05-27 23:20:59 124436 --a------ C:\Windows\system32\ictqrowc.dll
2007-05-24 19:51:48 24576 --a------ C:\Windows\system32\VundoFixSVC.exe <Not Verified; Atribune.org; Vundofix Service>
2007-05-24 17:10:03 0 d-------- C:\VundoFix Backups
2007-05-19 12:36:09 997720 ---hs---- C:\Windows\system32\hihkj.bak2
2007-05-18 16:06:18 995069 ---hs---- C:\Windows\system32\hihkj.ini2
2007-05-17 21:20:17 49204 --a------ C:\Windows\system32\fvagkdnh.dll
2007-05-17 21:12:44 998774 ---hs---- C:\Windows\system32\hihkj.bak1
2007-05-17 21:11:47 262708 ---hs---- C:\Windows\system32\opnnn.dll
2007-05-17 21:11:47 262708 ---hs---- C:\Windows\system32\jkhih.dll
2007-05-17 21:09:43 0 d-------- C:\Converted
2007-05-17 21:06:39 29206 --a------ C:\Windows\system32\gebxvvu.dll
2007-05-17 21:06:26 29206 --a------ C:\Windows\system32\gebcaww.dll
2007-05-17 20:53:48 184320 --a------ C:\Windows\system32\snmvtsvc.exe <Not Verified; SoundMovieServer; SoundMovieServer>
2007-05-17 20:53:47 22528 --a------ C:\Windows\system32\WmaCDriverV32.sys <Not Verified; Windows (R) Codename Longhorn DDK provider; Windows (R) Codename Longhorn DDK driver>
2007-05-17 20:53:47 22528 --a------ C:\Windows\system32\drivers\WmaCDriverV32.sys <Not Verified; Windows (R) Codename Longhorn DDK provider; Windows (R) Codename Longhorn DDK driver>
2007-05-17 20:53:41 0 d-------- C:\Program Files\WMAConvert
2007-05-17 20:32:04 0 d-------- C:\Temp
2007-05-17 20:27:13 286720 --a------ C:\Windows\system32\NCTWMAFile2.dll <Not Verified; NCT Company Ltd.; NCTWMAFile2 ActiveX DLL>
2007-05-17 20:27:13 143872 --a------ C:\Windows\system32\NCTWMAFile.dll <Not Verified; NCT Company; NCTWMAFile ActiveX DLL>
2007-05-17 20:27:13 168448 --a------ C:\Windows\system32\NCTAudioPlayer.dll <Not Verified; NCT Company; NCTAudioPlayer ActiveX DLL>
2007-05-17 20:27:13 573440 --a------ C:\Windows\system32\NCTAudioInformation2.dll <Not Verified; NCT Company Ltd.; NCTAudioInformation2 ActiveX DLL>
2007-05-17 20:27:12 491520 --a------ C:\Windows\system32\NCTAudioFile.dll <Not Verified; NCT Company; NCTAudioFile ActiveX DLL>
2007-05-17 20:27:11 120832 --a------ C:\Windows\system32\lame_enc.dll
2007-05-17 14:20:01 0 d-------- C:\My Downloads
2007-05-17 14:18:58 0 d-------- C:\Program Files\iMesh Applications
-- Find3M Report ---------------------------------------------------------------
2007-05-25 21:05:53 0 d-------- C:\Users\Patrick Schmied\AppData\Roaming\iMesh
2007-05-17 20:32:45 0 d-------- C:\Program Files\ImTOO
2007-05-09 03:16:41 0 d-------- C:\Program Files\Windows Mail
2007-04-15 20:45:03 0 d-------- C:\Users\Patrick Schmied\AppData\Roaming\Command & Conquer 3 Tiberium Wars
2007-04-15 13:25:54 0 dr-h----- C:\Users\Patrick Schmied\AppData\Roaming\SecuROM
2007-04-14 20:17:21 0 d-------- C:\Program Files\Electronic Arts
2007-04-14 13:26:26 0 d-------- C:\Program Files\iTunes
2007-04-14 13:26:20 0 d-------- C:\Program Files\iPod
2007-04-12 03:09:07 0 d-------- C:\Program Files\Windows Defender
2007-04-08 14:28:58 0 d-------- C:\Users\Patrick Schmied\AppData\Roaming\uTorrent
2007-04-06 14:04:39 0 d-------- C:\Program Files\LimeWire
2007-04-06 11:40:57 0 d-------- C:\Program Files\Microsoft Games
2007-04-05 17:38:53 0 d-------- C:\Program Files\OboeIE
2007-04-03 20:44:12 0 d-------- C:\Program Files\Windows Live Safety Center
2007-03-28 19:39:58 0 d-------- C:\Program Files\Dream Aquarium
2007-03-03 13:37:34 3127 --a------ C:\Windows\checkip.dat