Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice
Status
Not open for further replies.
1 - 20 of 45 Posts

· Registered
Joined
·
130 Posts
Discussion Starter · #1 ·
I ran all my antispyware as usual on a Sunday Morning, 9.00am, and quickly got two icons on my desktop which I deleted.
11.00 ran all spyware removal tool again:Spybot, Ad-aware and Trend Antispyware spywareblaster is also running and found 42 more instances of spyware, where are they coming from? I am using the windows firewall that came with Sp2 is it equal to the task?

John

Logfile of HijackThis v1.99.1
Scan saved at 12:01:10, on 31/12/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\Common Files\{A4902F8C-06A7-2057-0517-02040224002c}\Update.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\WINDOWS\system32\YMANTE~1\msiexec.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\taskmgr.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\?icrosoft\??ool32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\DOCUME~1\John\LOCALS~1\Temp\Rar$EX00.424\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.orange.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Orange UK
R3 - URLSearchHook: (no name) - {60D14821-F5B5-FC64-C52B-8BCD5D1F84E7} - C:\WINDOWS\system32\xxlz.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Orange - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - C:\PROGRA~1\orange3\orange3.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {60D14821-F5B5-FC64-C52B-8BCD5D1F84E7} - C:\WINDOWS\system32\xxlz.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{34902~1\Bar888.dll
O3 - Toolbar: Orange - {4E7BD74F-2B8D-469E-A1FB-F862B587B57D} - C:\PROGRA~1\orange3\orange3.dll
O3 - Toolbar: Bar888 - {C1B4DEC2-2623-438e-9CA2-C9043AB28508} - C:\PROGRA~1\COMMON~1\{34902~1\Bar888.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\PROGRA~1\Grisoft\AVG7\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [{A4902F8C-06A7-2057-0517-02040224002c}] "C:\Program Files\Common Files\{A4902F8C-06A7-2057-0517-02040224002c}\Update.exe" mc-110-12-0000137
O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\nvchost.exe
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - HKCU\..\Run: [Srsu] "C:\WINDOWS\system32\YMANTE~1\msiexec.exe" -vt yazb
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: taskmgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: orange search - file://C:\Program Files\ORANGE3\Cache\SelectedContextSearch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O20 - Winlogon Notify: winnjj32 - winnjj32.dll (file missing)
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: COM+ Messages - Unknown owner - C:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: FireDaemon Service: ecure (ecure) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
O23 - Service: FireDaemon Service: svchost1 (svchost1) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE (file missing)
O23 - Service: FireDaemon Service: system (system) - Unknown owner - C:\WINDOWS\Temp\FireDaemon.EXE (file missing)
 

· Registered
Joined
·
4,718 Posts
Hello there and welcome to TSG's security forum.
My name is David, I will be helping you with your log today.

Just a little note here before we continue John...
Your system has been quite seriously hacked, and I don't think this machine should be trusted any more.

The problem with these infections nowadays is, it causes a lot of damage. Even if we clean the malware off your system, I can't guarantee that your system will be clean afterwards, because these infections/bundles leave a lot of leftovers behind that most scanners won't even recognise and logs won't show. Also, I can't promise you we can repair all the damage it caused... Even after cleaning the malware, you can still get errors afterwards because of the damage. Solving these is not always possible since it will be searching for a needle in a haystack to find the right cause and solution.

You are dealing with some very nasty pieces of malware...
These allow hackers to remotely control your computer, steal critical system information and Download and Execute files
I would recommend you to disconnect this PC from the Internet immediately. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation.

Though these files/services may be identified and can be killed, because of it's functionality, your PC is compromised and there is no way to be sure your computer can ever again be trusted. Many experts in the security community believe that once infected with this type of malware, the best course of action would be a reformat and reinstall of the OS.
I think I would definitely recommend that you reformat and start afresh with a PC you can trust.

Please read these for more information:

How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud?
When Should I Format, How Should I Reinstall

Let me know what you wish to do - I understand that sometimes with this kind of topic, you might wish not to reformat as you want to keep all your files and do not want the inconvenience of starting afresh, but as I said before it's a good idea to start afresh - Don't forget all your files/folders can be backed-up onto a disc/USB drive.

I'm happy to help you fix it, if you wish to do so.
Let me know what you want to do.
David
 

· Registered
Joined
·
130 Posts
Discussion Starter · #5 ·
Thanks I will read them, but would replacing the hard drive do the job, there not expensive?

There is nothing of importance on this machine it is used solely for recreation by my daughter and my grandchildren, But I shall have to watch them a lot more closely in the future..

I have reformatted the hard drive as suggested and these are the new readings:

Logfile of HijackThis v1.99.1
Scan saved at 09:25:19, on 01/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\Program Files\Messenger\msmsgs.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\john\My Documents\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.orange.co.uk
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Orange UK
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\PROGRA~1\Grisoft\AVG7\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\nvchost
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe

John
 

· Registered
Joined
·
4,718 Posts
I understand your question about the hard-drive, but if you replaced the hard-drive you would have to install the operating system back onto it. It's important to understand that the hard-drive itself isn't infected, but the operating system that is installed on it is. The hard-drive should still be perfectly functionable, you just needed to delete the old operating system that was on it and reinstall it, which is what you have done. :up:

Start HijackThis, close all open windows leaving only HijackThis running. Place a check against each of the following if still present:

O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\nvchost

Click on Fix Checked when finished and exit HijackThis.
Make sure your Internet Explorer is closed when you click Fix Checked!

Please download Combofix to your desktop.
Doubleclick combo.exe to launch the application.
Follow the prompts that will be displayed on the screen.
Don't click on the window while the fix is running, because that will cause your system to hang.
When finished, it should produce a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.

David
 

· Registered
Joined
·
130 Posts
Discussion Starter · #7 ·
Logfile of HijackThis v1.99.1
Scan saved at 13:03:56, on 01/01/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\iISystem Wiper\SystemWiper.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Orange UK
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\PROGRA~1\Grisoft\AVG7\avgregcl.exe /BOOT
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [iIWiper] C:\Program Files\iISystem Wiper\SystemWiper.exe m
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe
O23 - Service: RoxMediaDB - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe
O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCom\RoxUpnpRenderer.exe
O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Program Files\Roxio\Easy Media Creator 8\Digital Home\RoxUpnpServer.exe
O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
 

· Registered
Joined
·
130 Posts
Discussion Starter · #13 ·
john - 07-01-01 13:04:19.50 Service Pack 2
ComboFix 06.11.27 - Running from: "C:\Documents and Settings\john\My Documents\New Folder"

((((((((((((((((((((((((((((((( Files Created from 2006-12-01 to 2007-01-01 ))))))))))))))))))))))))))))))))))

2007-01-01 12:52 d-------- C:\Program Files\backups
2007-01-01 12:51 218,112 --a------ C:\Program Files\HijackThis.exe
2007-01-01 12:45 1,550 --a------ C:\WINDOWS\system32\tmp.reg
2007-01-01 12:25 46,352 --a------ C:\WINDOWS\setdebug.exe
2007-01-01 12:25 139,536 --a------ C:\WINDOWS\system32\javaee.dll
2007-01-01 12:25 113 --a------ C:\WINDOWS\system32\zonedon.reg
2007-01-01 12:25 113 --a------ C:\WINDOWS\system32\zonedoff.reg
2007-01-01 12:25 d-------- C:\Program Files\Spybot - Search & Destroy
2007-01-01 12:25 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-01-01 12:03 d-------- C:\Documents and Settings\john\Application Data\Uniblue
2007-01-01 12:01 d---s---- C:\Documents and Settings\john\UserData
2007-01-01 09:19 dr-h----- C:\Documents and Settings\john\Recent
2007-01-01 09:15 221,184 --a------ C:\WINDOWS\system32\wmpns.dll
2006-12-31 20:59 d--hs---- C:\Config.Msi
2006-12-31 20:59 d-------- C:\Program Files\MSXML 4.0
2006-12-31 20:59 d-------- C:\91bf46480c15425b5c63
2006-12-31 18:19 d-------- C:\WINDOWS\system32\PreInstall
2006-12-31 18:18 d--h----- C:\WINDOWS\$hf_mig$
2006-12-31 18:13 d-------- C:\WINDOWS\system32\SoftwareDistribution
2006-12-31 18:10 d-------- C:\WINDOWS\pss
2006-12-31 17:50 d-------- C:\Documents and Settings\john\Application Data\Macromedia
2006-12-31 17:47 278,528 --a------ C:\Program Files\Common Files\FDEUnInstaller.exe
2006-12-31 17:47 d--h----- C:\WINDOWS\msdownld.tmp
2006-12-31 17:47 d-------- C:\Program Files\orange3
2006-12-31 17:47 d-------- C:\Program Files\Orange
2006-12-31 17:47 d-------- C:\Program Files\Inventel
2006-12-31 17:46 81,920 --a------ C:\WINDOWS\system32\W32N50.dll
2006-12-31 17:46 44,544 --a------ C:\WINDOWS\system32\msxml4a.dll
2006-12-31 17:46 17,134 --a------ C:\WINDOWS\system32\PCANDIS5.sys
2006-12-31 17:45 d-------- C:\Documents and Settings\john\Application Data\Roxio
2006-12-31 17:44 d-------- C:\Documents and Settings\All Users\Application Data\InstallShield
2006-12-31 17:43 d-------- C:\Program Files\Sonic
2006-12-31 17:43 d-------- C:\Program Files\Common Files\Sonic Shared
2006-12-31 17:43 d-------- C:\Documents and Settings\All Users\Application Data\Sonic
2006-12-31 17:39 d-------- C:\Documents and Settings\All Users\Application Data\Roxio
2006-12-31 17:37 d-------- C:\Program Files\Roxio
2006-12-31 17:37 d-------- C:\Program Files\Common Files\Roxio Shared
2006-12-31 17:36 d-------- C:\WINDOWS\RegisteredPackages
2006-12-31 17:32 d-------- C:\WINDOWS\Downloaded Installations
2006-12-31 17:32 d-------- C:\Program Files\Lavasoft
2006-12-31 17:28 d-------- C:\Program Files\Common Files\Adobe Systems Shared
2006-12-31 17:28 d-------- C:\Documents and Settings\All Users\Application Data\Adobe Systems
2006-12-31 17:26 d-------- C:\Program Files\Common Files\Adobe
2006-12-31 17:21 4,928 --a------ C:\WINDOWS\system32\drivers\avg7rsw.sys
2006-12-31 17:21 343,168 --a------ C:\WINDOWS\system32\drivers\avg7core.sys
2006-12-31 17:21 18,944 --a------ C:\WINDOWS\system32\drivers\avg7rsxp.sys
2006-12-31 17:21 d-------- C:\Program Files\Grisoft
2006-12-31 17:21 d-------- C:\Documents and Settings\john\Application Data\AVG7
2006-12-31 17:21 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2006-12-31 17:21 d-------- C:\Documents and Settings\All Users\Application Data\AVG7
2006-12-31 17:17 2,977,792 --------- C:\WINDOWS\UNNMP.exe
2006-12-31 17:16 d-------- C:\Program Files\Common Files\LightScribe
2006-12-31 17:15 155,648 --a------ C:\WINDOWS\system32\NeroCheck.exe
2006-12-31 17:14 d-------- C:\Program Files\Common Files\Nero
2006-12-31 17:04 3,031,040 --------- C:\WINDOWS\UNNeroVision.exe
2006-12-31 17:04 24,064 --------- C:\WINDOWS\system32\msxml3a.dll
2006-12-31 17:03 476,320 --------- C:\WINDOWS\system32\ImagXpr7.dll
2006-12-31 17:03 471,040 --------- C:\WINDOWS\system32\ImagXRA7.dll
2006-12-31 17:03 38,912 --------- C:\WINDOWS\system32\picn20.dll
2006-12-31 17:03 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2006-12-31 17:03 262,144 --------- C:\WINDOWS\system32\ImagXR7.dll
2006-12-31 17:03 106,496 --a------ C:\WINDOWS\system32\TwnLib20.dll
2006-12-31 17:03 1,568,768 ---------
 

· Registered
Joined
·
130 Posts
Discussion Starter · #14 ·
C:\WINDOWS\system32\ImagX7.dll
2006-12-31 17:03 d-------- C:\Program Files\Common Files\Ahead
2006-12-31 17:03 d-------- C:\Program Files\Ahead
2006-12-31 17:03 d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2006-12-31 17:01 d-------- C:\Documents and Settings\john\Application Data\MyFamily.com
2006-12-31 17:00 d-------- C:\Program Files\Family Tree Maker 2006
2006-12-31 16:57 d-------- C:\Program Files\iISystem Wiper
2006-12-31 16:55 d-------- C:\Program Files\Adobe
2006-12-31 16:55 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2006-12-31 16:53 d-------- C:\WINDOWS\Cache
2006-12-31 16:43 17,920 --a------ C:\WINDOWS\system32\mdimon.dll
2006-12-31 16:41 d-------- C:\Program Files\Microsoft.NET
2006-12-31 16:41 d-------- C:\Program Files\Microsoft ActiveSync
2006-12-31 16:41 d-------- C:\Program Files\Common Files\L&H
2006-12-31 16:40 d-------- C:\Program Files\Microsoft Works
2006-12-31 16:40 d-------- C:\Program Files\Microsoft Visual Studio
2006-12-31 16:40 d-------- C:\Program Files\Common Files\DESIGNER
2006-12-31 16:39 d-------- C:\WINDOWS\SHELLNEW
2006-12-31 16:39 d-------- C:\Program Files\Microsoft Office
2006-12-31 16:36 782,336 --a------ C:\WINDOWS\system32\IlmImf.dll
2006-12-31 16:36 53,248 --a------ C:\WINDOWS\system32\pmexr.dll
2006-12-31 16:36 353,280 --a------ C:\WINDOWS\system32\pmtf2.dll
2006-12-31 16:36 238,592 --a------ C:\WINDOWS\system32\PhotomatixLib.dll
2006-12-31 16:36 216,064 --a------ C:\WINDOWS\system32\pmjp.dll
2006-12-31 16:36 212,992 --a------ C:\WINDOWS\system32\PhotomatixLib2.dll
2006-12-31 16:36 205,824 --a------ C:\WINDOWS\system32\pmtf1.dll
2006-12-31 16:36 119,568 --a------ C:\WINDOWS\system32\VB6FR.DLL
2006-12-31 16:36 110,592 --a------ C:\WINDOWS\system32\PhotomatixLib3.dll
2006-12-31 16:36 11,776 --a------ C:\WINDOWS\system32\pmbm.dll
2006-12-31 16:36 d-------- C:\Program Files\Photomatix
2006-12-31 16:35 152,064 --a------ C:\WINDOWS\nvchost.exe
2006-12-31 16:29 d-------- C:\Program Files\DVD Decrypter
2006-12-31 16:26 d-------- C:\Program Files\Java
2006-12-31 16:26 d-------- C:\Program Files\Common Files\Java
2006-12-31 16:25 d-------- C:\Program Files\CCleaner
2006-12-31 16:24 d-------- C:\WINDOWS\Samsung
2006-12-31 16:23 d--hs---- C:\RECYCLER
2006-12-31 16:21 118,784 --a------ C:\WINDOWS\system32\MSSTDFMT.DLL
2006-12-31 16:21 d-------- C:\Program Files\SpywareBlaster
2006-12-31 16:20 96,256 --a------ C:\WINDOWS\system32\Csp3osu.dll
2006-12-31 16:20 45,568 --a------ C:\WINDOWS\ScFBPPM3.DLL
2006-12-31 16:20 318,976 --a------ C:\WINDOWS\system32\Ucs32p.dll
2006-12-31 16:20 306,688 --a------ C:\WINDOWS\IsUninst.exe
2006-12-31 16:20 16,896 --a------ C:\WINDOWS\system32\Csp3utl.dll
2006-12-31 16:20 16,032 --a------ C:\WINDOWS\system32\drivers\ScFBPNT3.sys
2006-12-31 16:20 d-------- C:\Program Files\Canon
2006-12-31 16:20 d-------- C:\Documents and Settings\john\WINDOWS
2006-12-31 16:15 d-------- C:\WINDOWS\SoftwareDistribution
2006-12-31 16:15 d-------- C:\WINDOWS\Prefetch
2006-12-31 16:10 95,424 --------- C:\WINDOWS\system32\drivers\slnthal.sys
2006-12-31 16:10 940,544 --a------ C:\WINDOWS\system32\wmspdmoe.dll
2006-12-31 16:10 9,216 --------- C:\WINDOWS\system32\proxycfg.exe
2006-12-31 16:10 88,064 --------- C:\WINDOWS\system32\p2pnetsh.dll
2006-12-31 16:10 870,784 --------- C:\WINDOWS\system32\ati3d1ag.dll
2006-12-31 16:10 86,016 --------- C:\WINDOWS\system32\p2pgasvc.dll
2006-12-31 16:10 86,016 --------- C:\WINDOWS\system32\mdmxsdk.dll
2006-12-31 16:10 81,920 --------- C:\WINDOWS\system32\ieencode.dll
2006-12-31 16:10 81,408 --------- C:\WINDOWS\system32\wscsvc.dll
2006-12-31 16:10 8,192 --------- C:\WINDOWS\system32\smbinst.exe
2006-12-31 16:10 8,192 --------- C:\WINDOWS\system32\bitsprx2.dll
2006-12-31 16:10 78,464 --------- C:\WINDOWS\system32\drivers\usbvideo.sys
2006-12-31 16:10 755,200 --------- C:\WINDOWS\system32\ir50_32.dll
2006-12-31 16:10 75,776 --------- C:\WINDOWS\system32\strmfilt.dll
2006-12-31 16:10 73,832 --------- C:\WINDOWS\system32\slcoinst.dll
2006-12-31 16:10 73,796 --------- C:\WINDOWS\system32\slserv.exe
2006-12-31 16:10 73,216 --------- C:\WINDOWS\system32\drivers\atintuxx.sys
2006-12-31 16:10 71,680 --------- C:\WINDOWS\system32\blastcln.exe
2006-12-31 16:10 7,680 --------- C:\WINDOWS\system32\kbdsmsno.dll
2006-12-31 16:10 7,680 --------- C:\WINDOWS\system32\kbdsmsfi.dll
2006-12-31 16:10 7,168 --------- C:\WINDOWS\system32\kbdukx.dll
2006-12-31 16:10 7,168 --------- C:\WINDOWS\system32\kbdno1.dll
2006-12-31 16:10 7,168 --------- C:\WINDOWS\system32\kbdfi1.dll
2006-12-31 16:10 7,168 --------- C:\WINDOWS\system32\hccoin.dll
2006-12-31 16:10 7,168 --------- C:\WINDOWS\system32\bitsprx3.dll
2006-12-31 16:10 685,056 --------- C:\WINDOWS\system32\drivers\hsfcxts2.sys
2006-12-31 16:10 67,584 --------- C:\WINDOWS\system32\drivers\sdbus.sys
2006-12-31 16:10 63,663 --------- C:\WINDOWS\system32\drivers\ati1rvxx.sys
2006-12-31 16:10 63,488 --------- C:\WINDOWS\system32\drivers\atinxsxx.sys
2006-12-31 16:10 60,416 --------- C:\WINDOWS\system32\fwcfg.dll
2006-12-31 16:10 6,656 --------- C:\WINDOWS\system32\kbdinmal.dll
2006-12-31 16:10 6,656 --------- C:\WINDOWS\system32\kbdinben.dll
2006-12-31 16:10 6,144 --------- C:\WINDOWS\system32\kbdmlt48.dll
2006-12-31 16:10 6,144 --------- C:\WINDOWS\system32\kbdmlt47.dll
2006-12-31 16:10 6,144 --------- C:\WINDOWS\system32\kbdinbe1.dll
2006-12-31 16:10 6,016 --------- C:\WINDOWS\system32\drivers\smbali.sys
2006-12-31 16:10 59,648 --------- C:\WINDOWS\system32\drivers\rfcomm.sys
2006-12-31 16:10 59,392 --------- C:\WINDOWS\system32\logman.exe
2006-12-31 16:10 57,856 --------- C:\WINDOWS\system32\drivers\atinbtxx.sys
2006-12-31 16:10 56,623 --------- C:\WINDOWS\system32\drivers\ati1btxx.sys
2006-12-31 16:10 526,848 --------- C:\WINDOWS\system32\p2psvc.dll
2006-12-31 16:10 52,224 --------- C:\WINDOWS\system32\drivers\atinraxx.sys
2006-12-31 16:10 50,688 --------- C:\WINDOWS\system32\btpanui.dll
2006-12-31 16:10 50,176 --------- C:\WINDOWS\system32\xmlprovi.dll
2006-12-31 16:10 5,632 --------- C:\WINDOWS\system32\kbdmaori.dll
2006-12-31 16:10 49,152 --------- C:\WINDOWS\system32\powercfg.exe
2006-12-31 16:10 48,640 --------- C:\WINDOWS\system32\pnrpnsp.dll
2006-12-31 16:10 465,176 --a------ C:\WINDOWS\system32\wuapi.dll
2006-12-31 16:10 46,464 --------- C:\WINDOWS\system32\drivers\gagp30kx.sys
2006-12-31 16:10 452,736 --------- C:\WINDOWS\system32\drivers\mtxparhm.sys
2006-12-31 16:10 44,928 --------- C:\WINDOWS\system32\drivers\agpcpq.sys
2006-12-31 16:10 44,672 --------- C:\WINDOWS\system32\drivers\uagp35.sys
2006-12-31 16:10 44,032 --------- C:\WINDOWS\system32\twext.dll
2006-12-31 16:10 438,784 --------- C:\WINDOWS\system32\xpob2res.dll
2006-12-31 16:10 43,008 --------- C:\WINDOWS\system32\drivers\amdagp.sys
2006-12-31 16:10 42,752 --------- C:\WINDOWS\system32\drivers\alim1541.sys
2006-12-31 16:10 42,368 --------- C:\WINDOWS\system32\drivers\agp440.sys
2006-12-31 16:10 42,240 --------- C:\WINDOWS\system32\drivers\viaagp.sys
2006-12-31 16:10 413,944 --a------ C:\WINDOWS\system32\wmspdmod.dll
2006-12-31 16:10 41,240 --a------ C:\WINDOWS\system32\wups.dll
2006-12-31 16:10 404,990 --------- C:\WINDOWS\system32\drivers\slntamr.sys
2006-12-31 16:10 4,274,816
 

· Registered
Joined
·
130 Posts
Discussion Starter · #15 ·
C:\WINDOWS\system32\nv4_disp.dll
2006-12-31 16:10 4,255 --------- C:\WINDOWS\system32\drivers\adv01nt5.dll
2006-12-31 16:10 397,056 --------- C:\WINDOWS\system32\s3gnb.dll
2006-12-31 16:10 384,512 --------- C:\WINDOWS\system32\mp4sdmod.dll
2006-12-31 16:10 38,016 --------- C:\WINDOWS\system32\drivers\bthmodem.sys
2006-12-31 16:10 377,984 --------- C:\WINDOWS\system32\ati2dvaa.dll
2006-12-31 16:10 36,463 --------- C:\WINDOWS\system32\drivers\ati1tuxx.sys
2006-12-31 16:10 36,096 --------- C:\WINDOWS\system32\drivers\intelppm.sys
2006-12-31 16:10 35,456 --------- C:\WINDOWS\system32\drivers\bthprint.sys
2006-12-31 16:10 34,735 --------- C:\WINDOWS\system32\drivers\ati1xsxx.sys
2006-12-31 16:10 338,432 --------- C:\WINDOWS\system32\ir41_qcx.dll
2006-12-31 16:10 327,040 --------- C:\WINDOWS\system32\drivers\ati2mtaa.sys
2006-12-31 16:10 32,866 --------- C:\WINDOWS\system32\slrundll.exe
2006-12-31 16:10 32,866 --------- C:\WINDOWS\slrundll.exe
2006-12-31 16:10 32,768 --------- C:\WINDOWS\system32\ativtmxx.dll
2006-12-31 16:10 32,285 --------- C:\WINDOWS\system32\hsfcisp2.dll
2006-12-31 16:10 312,320 --------- C:\WINDOWS\system32\p2pgraph.dll
2006-12-31 16:10 310,272 --------- C:\WINDOWS\system32\mp43dmod.dll
2006-12-31 16:10 31,744 --------- C:\WINDOWS\system32\drivers\atinxbxx.sys
2006-12-31 16:10 30,671 --------- C:\WINDOWS\system32\drivers\ati1raxx.sys
2006-12-31 16:10 30,208 --------- C:\WINDOWS\system32\bthserv.dll
2006-12-31 16:10 30,080 --------- C:\WINDOWS\system32\drivers\rndismpx.sys
2006-12-31 16:10 3,967 --------- C:\WINDOWS\system32\drivers\adv02nt5.dll
2006-12-31 16:10 3,901 --------- C:\WINDOWS\system32\drivers\siint5.dll
2006-12-31 16:10 3,775 --------- C:\WINDOWS\system32\drivers\adv11nt5.dll
2006-12-31 16:10 3,711 --------- C:\WINDOWS\system32\drivers\adv09nt5.dll
2006-12-31 16:10 3,647 --------- C:\WINDOWS\system32\drivers\adv07nt5.dll
2006-12-31 16:10 3,615 --------- C:\WINDOWS\system32\drivers\adv05nt5.dll
2006-12-31 16:10 3,135 --------- C:\WINDOWS\system32\drivers\adv08nt5.dll
2006-12-31 16:10 29,455 --------- C:\WINDOWS\system32\drivers\ati1xbxx.sys
2006-12-31 16:10 29,184 --------- C:\WINDOWS\system32\sdhcinst.dll
2006-12-31 16:10 29,056 --------- C:\WINDOWS\system32\drivers\ip6fw.sys
2006-12-31 16:10 286,792 --------- C:\WINDOWS\system32\slextspk.dll
2006-12-31 16:10 28,672 --------- C:\WINDOWS\system32\drivers\atinsnxx.sys
2006-12-31 16:10 274,304 --------- C:\WINDOWS\system32\drivers\bthport.sys
2006-12-31 16:10 262,784 --------- C:\WINDOWS\system32\drivers\http.sys
2006-12-31 16:10 26,624 --------- C:\WINDOWS\system32\drivers\usbehci.sys
2006-12-31 16:10 26,367 --------- C:\WINDOWS\system32\drivers\ati1snxx.sys
2006-12-31 16:10 25,600 --------- C:\WINDOWS\system32\drivers\hidbth.sys
2006-12-31 16:10 25,471 --------- C:\WINDOWS\system32\drivers\watv10nt.sys
2006-12-31 16:10 25,471 --------- C:\WINDOWS\system32\drivers\atv04nt5.dll
2006-12-31 16:10 25,088 --a------ C:\WINDOWS\system32\MsPMSNSv.dll
2006-12-31 16:10 24,576 --------- C:\WINDOWS\system32\httpapi.dll
2006-12-31 16:10 233,472 --------- C:\WINDOWS\system32\wmpdxm.dll
2006-12-31 16:10 23,040 --a------ C:\WINDOWS\system32\fltmc.exe
2006-12-31 16:10 220,032 --------- C:\WINDOWS\system32\drivers\hsfbs2s2.sys
2006-12-31 16:10 22,271 --------- C:\WINDOWS\system32\drivers\watv06nt.sys
2006-12-31 16:10 21,343 --------- C:\WINDOWS\system32\drivers\ati1ttxx.sys
2006-12-31 16:10 21,183 --------- C:\WINDOWS\system32\drivers\atv01nt5.dll
2006-12-31 16:10 200,192 --------- C:\WINDOWS\system32\ir50_qc.dll
2006-12-31 16:10 20,992 --------- C:\WINDOWS\system32\bthci.dll
2006-12-31 16:10 2,113,536
 

· Registered
Joined
·
130 Posts
Discussion Starter · #16 ·
C:\WINDOWS\system32\dxdiagn.dll
2006-12-31 16:10 194,328 --a------ C:\WINDOWS\system32\wuaueng1.dll
2006-12-31 16:10 193,024 --------- C:\WINDOWS\system32\fsquirt.exe
2006-12-31 16:10 188,508 --------- C:\WINDOWS\system32\slgen.dll
2006-12-31 16:10 183,808 --------- C:\WINDOWS\system32\ir50_qcx.dll
2006-12-31 16:10 180,360 --------- C:\WINDOWS\system32\drivers\ntmtlfax.sys
2006-12-31 16:10 18,944 --------- C:\WINDOWS\system32\drivers\bthusb.sys
2006-12-31 16:10 173,536 --a------ C:\WINDOWS\system32\wuweb.dll
2006-12-31 16:10 172,312 --a------ C:\WINDOWS\system32\wuauclt1.exe
2006-12-31 16:10 17,408 --------- C:\WINDOWS\system32\winshfhc.dll
2006-12-31 16:10 17,279 --------- C:\WINDOWS\system32\drivers\atv10nt5.dll
2006-12-31 16:10 17,024 --------- C:\WINDOWS\system32\drivers\bthenum.sys
2006-12-31 16:10 168,448 --------- C:\WINDOWS\system32\wmerror.dll
2006-12-31 16:10 166,912 --------- C:\WINDOWS\system32\drivers\s3gnbm.sys
2006-12-31 16:10 16,896 --a------ C:\WINDOWS\system32\fltlib.dll
2006-12-31 16:10 150,016 --a------ C:\WINDOWS\system32\wmidx.dll
2006-12-31 16:10 15,872 --------- C:\WINDOWS\system32\w3ssl.dll
2006-12-31 16:10 15,488 --------- C:\WINDOWS\system32\drivers\mssmbios.sys
2006-12-31 16:10 15,423 --------- C:\WINDOWS\system32\drivers\ch7xxnt5.dll
2006-12-31 16:10 15,104 --------- C:\WINDOWS\system32\drivers\hidir.sys
2006-12-31 16:10 14,336 --------- C:\WINDOWS\system32\drivers\atinpdxx.sys
2006-12-31 16:10 14,336 --------- C:\WINDOWS\system32\auditusr.exe
2006-12-31 16:10 14,143 --------- C:\WINDOWS\system32\drivers\atv06nt5.dll
2006-12-31 16:10 13,824 --------- C:\WINDOWS\system32\wscntfy.exe
2006-12-31 16:10 13,824 --------- C:\WINDOWS\system32\drivers\atinttxx.sys
2006-12-31 16:10 13,824 --------- C:\WINDOWS\system32\drivers\atinmdxx.sys
2006-12-31 16:10 13,824 --------- C:\WINDOWS\system32\cmsetacl.dll
2006-12-31 16:10 13,776 --------- C:\WINDOWS\system32\drivers\recagent.sys
2006-12-31 16:10 13,568 --------- C:\WINDOWS\system32\drivers\wacompen.sys
2006-12-31 16:10 13,240 --------- C:\WINDOWS\system32\drivers\slwdmsup.sys
2006-12-31 16:10 129,536 --------- C:\WINDOWS\system32\xmlprov.dll
2006-12-31 16:10 129,535 --------- C:\WINDOWS\system32\drivers\slnt7554.sys
2006-12-31 16:10 128,896 --------- C:\WINDOWS\system32\drivers\fltmgr.sys
2006-12-31 16:10 127,256 --a------ C:\WINDOWS\system32\wucltui.dll
2006-12-31 16:10 126,686 --------- C:\WINDOWS\system32\drivers\mtlmnt5.sys
2006-12-31 16:10 120,320 --------- C:\WINDOWS\system32\ir41_qc.dll
2006-12-31 16:10 12,672 --------- C:\WINDOWS\system32\drivers\usb8023x.sys
2006-12-31 16:10 12,672 --------- C:\WINDOWS\system32\drivers\mutohpen.sys
2006-12-31 16:10 12,047 --------- C:\WINDOWS\system32\drivers\ati1pdxx.sys
2006-12-31 16:10 118,784 --------- C:\WINDOWS\system32\msdadiag.dll
2006-12-31 16:10 116,224 --------- C:\WINDOWS\system32\p2p.dll
2006-12-31 16:10 114,688 --------- C:\WINDOWS\system32\wmpasf.dll
2006-12-31 16:10 11,935 --------- C:\WINDOWS\system32\drivers\wadv11nt.sys
2006-12-31 16:10 11,871 --------- C:\WINDOWS\system32\drivers\wadv09nt.sys
2006-12-31 16:10 11,868 --------- C:\WINDOWS\system32\drivers\mdmxsdk.sys
2006-12-31 16:10 11,807 --------- C:\WINDOWS\system32\drivers\wadv07nt.sys
2006-12-31 16:10 11,615 --------- C:\WINDOWS\system32\drivers\ati1mdxx.sys
2006-12-31 16:10 11,359 --------- C:\WINDOWS\system32\drivers\atv02nt5.dll
2006-12-31 16:10 11,325 --------- C:\WINDOWS\system32\drivers\vchnt5.dll
2006-12-31 16:10 11,295 --------- C:\WINDOWS\system32\drivers\wadv08nt.sys
2006-12-31 16:10 11,136 --------- C:\WINDOWS\system32\drivers\sffdisk.sys
2006-12-31 16:10 108,032 --------- C:\WINDOWS\system32\wshbth.dll
2006-12-31 16:10 104,960 --------- C:\WINDOWS\system32\drivers\atinrvxx.sys
2006-12-31 16:10 100,992 --------- C:\WINDOWS\system32\drivers\bthpan.sys
2006-12-31 16:10 10,240 --------- C:\WINDOWS\system32\drivers\sffp_sd.sys
2006-12-31 16:10 1,897,408 --------- C:\WINDOWS\system32\drivers\nv4_mini.sys
2006-12-31 16:10 1,737,856 --------- C:\WINDOWS\system32\mtxparhd.dll
2006-12-31 16:10 1,689,088 --------- C:\WINDOWS\system32\d3d9.dll
2006-12-31 16:10 1,309,184 --------- C:\WINDOWS\system32\drivers\mtlstrm.sys
2006-12-31 16:10 1,119,744 --a------ C:\WINDOWS\system32\wmsdmoe2.dll
2006-12-31 16:10 1,041,536 --------- C:\WINDOWS\system32\drivers\hsfdpsp2.sys
2006-12-31 16:10 1,003,008 --a------ C:\WINDOWS\system32\wmvdmoe2.dll
2006-12-31 16:10 d--------
 

· Registered
Joined
·
130 Posts
Discussion Starter · #17 ·
C:\WINDOWS\provisioning
2006-12-31 16:10 d-------- C:\WINDOWS\peernet
2006-12-31 16:08 d-------- C:\WINDOWS\ServicePackFiles
2006-12-31 16:07 2,897,920 --------- C:\WINDOWS\system32\xpsp2res.dll
2006-12-31 16:05 22,752 --a------ C:\WINDOWS\system32\spupdsvc.exe
2006-12-31 16:05 d-------- C:\WINDOWS\system32\ReinstallBackups
2006-12-31 16:03 d-------- C:\WINDOWS\EHome
2006-12-31 15:59 765,952 -ra------ C:\WINDOWS\system\crlds3d.dll
2006-12-31 15:59 712,704 -ra------ C:\WINDOWS\system32\Audio3D.dll
2006-12-31 15:59 712,704 -ra------ C:\WINDOWS\system32\a3d.dll
2006-12-31 15:59 60,288 --a------ C:\WINDOWS\system32\drivers\drmk.sys
2006-12-31 15:59 48,640 --a------ C:\WINDOWS\system32\drivers\stream.sys
2006-12-31 15:59 4,096 --a------ C:\WINDOWS\system32\ksuser.dll
2006-12-31 15:59 377,358 -ra------ C:\WINDOWS\system32\drivers\cmaudio.sys
2006-12-31 15:59 32,768 -ra------ C:\WINDOWS\system32\cmnprop.dll
2006-12-31 15:59 145,792 --a------ C:\WINDOWS\system32\drivers\portcls.sys
2006-12-31 15:59 140,928 --a------ C:\WINDOWS\system32\drivers\ks.sys
2006-12-31 15:59 139,264 -ra------ C:\WINDOWS\cmuninst.exe
2006-12-31 15:59 1,818,624 -ra------ C:\WINDOWS\mixer.exe
2006-12-31 15:59 d-------- C:\Program Files\C-Media
2006-12-31 15:55 d---s---- C:\WINDOWS\system32\Microsoft
2006-12-31 15:54 516,096 --------- C:\WINDOWS\system32\ati2sgag.exe
2006-12-31 15:54 294,912 -ra------ C:\WINDOWS\system32\atiiiexx.dll
2006-12-31 15:54 135,168 -ra------ C:\WINDOWS\system32\ATIDEMGR.dll
2006-12-31 15:54 d--h----- C:\Program Files\InstallShield Installation Information
2006-12-31 15:54 d-------- C:\Program Files\Common Files\InstallShield
2006-12-31 15:53 d--hs---- C:\WINDOWS\Installer
2006-12-31 15:53 d--h----- C:\Program Files\Uninstall Information
2006-12-31 15:52 dr-h----- C:\Documents and Settings\john\SendTo
2006-12-31 15:52 dr-h----- C:\Documents and Settings\john\Application Data\.
2006-12-31 15:52 dr-h----- C:\Documents and Settings\john\Application Data
2006-12-31 15:52 dr------- C:\Documents and Settings\john\Start Menu
2006-12-31 15:52 dr------- C:\Documents and Settings\john\My Documents
2006-12-31 15:52 dr------- C:\Documents and Settings\john\Favorites
2006-12-31 15:52 d--h----- C:\Documents and Settings\john\Templates
2006-12-31 15:52 d--h----- C:\Documents and Settings\john\PrintHood
2006-12-31 15:52 d--h----- C:\Documents and Settings\john\NetHood
2006-12-31 15:52 d--h----- C:\Documents and Settings\john\Local Settings
2006-12-31 15:52 d---s---- C:\Documents and Settings\john\Cookies
2006-12-31 15:52 d---s---- C:\Documents and Settings\john\Application Data\Microsoft
2006-12-31 15:52 d-------- C:\Documents and Settings\john\Desktop
2006-12-31 15:52 d-------- C:\Documents and Settings\john\Application Data\Identities
2006-12-31 15:52 d-------- C:\Documents and Settings\john\Application Data\..
2006-12-31 15:52 d-------- C:\Documents and Settings\john\..
2006-12-31 15:52 d-------- C:\Documents and Settings\john\.
2006-12-31 15:51 d--hs---- C:\System Volume Information
2006-12-31 15:48 112,128 --a------ C:\WINDOWS\system32\mapi32.dll
2006-12-31 15:48 0 -rahs---- C:\MSDOS.SYS
2006-12-31 15:48 0 -rahs---- C:\IO.SYS
2006-12-31 15:48 0 --a------ C:\CONFIG.SYS
2006-12-31 15:48 0 --a------ C:\AUTOEXEC.BAT
2006-12-31 15:48 d-------- C:\WINDOWS\system32\xircom
2006-12-31 15:48 d-------- C:\Program Files\xerox
2006-12-31 15:48 d-------- C:\Program Files\microsoft frontpage
2006-12-31 15:47 dr------- C:\WINDOWS\Offline Web Pages
2006-12-31 15:47 d--hs---- C:\Documents and Settings\All Users\DRM
2006-12-31 15:47 d---s---- C:\WINDOWS\Downloaded Program Files
2006-12-31 15:46 81,920 --a------ C:\WINDOWS\system32\isign32.dll
2006-12-31 15:46 73,728 --a------ C:\WINDOWS\system32\icwdial.dll
2006-12-31 15:46 65,536 --a------ C:\WINDOWS\system32\icwphbk.dll
2006-12-31 15:46 64,512 --a------ C:\WINDOWS\system32\acctres.dll
2006-12-31 15:46 48,128 --a------ C:\WINDOWS\system32\inetres.dll
2006-12-31 15:46 45,568 --a------ C:\WINDOWS\system32\safrslv.dll
2006-12-31 15:46 43,520 --a------ C:\WINDOWS\system32\safrcdlg.dll
2006-12-31 15:46 43,520 --a------ C:\WINDOWS\system32\racpldlg.dll
2006-12-31 15:46 32,768 --a------ C:\WINDOWS\system32\mnmsrvc.exe
2006-12-31 15:46 32,768 --a------ C:\WINDOWS\system32\isrdbg32.dll
2006-12-31 15:46 29,696 --a------ C:\WINDOWS\system32\safrdm.dll
2006-12-31 15:46 274,432 --a------ C:\WINDOWS\system32\inetcfg.dll
2006-12-31 15:46 16,384 --a------ C:\WINDOWS\system32\icfgnt5.dll
2006-12-31 15:46 12,288 --a------ C:\WINDOWS\system32\nmevtmsg.dll
2006-12-31 15:46 11,264 --a------ C:\WINDOWS\system32\atrace.dll
2006-12-31 15:46 d---s---- C:\WINDOWS\Tasks
2006-12-31 15:46 d-------- C:\WINDOWS\system32\Macromed
2006-12-31 15:46 d-------- C:\WINDOWS\system32\DirectX
2006-12-31 15:46 d-------- C:\WINDOWS\srchasst
2006-12-31 15:46 d-------- C:\Program Files\Common Files\Services
2006-12-31 15:46 d-------- C:\Program Files\Common Files\MSSoap
2006-12-31 15:45 81,920 --a------ C:\WINDOWS\system32\ils.dll
2006-12-31 15:45 73,472 --a------ C:\WINDOWS\system32\drivers\sr.sys
2006-12-31 15:45 69,632 --a------ C:\WINDOWS\system32\msconf.dll
2006-12-31 15:45 679,424 --a------ C:\WINDOWS\system32\inetcomm.dll
2006-12-31 15:45 67,584 --a------ C:\WINDOWS\system32\srclient.dll
2006-12-31 15:45 382,464 --a------ C:\WINDOWS\system32\qmgr.dll
2006-12-31 15:45 34,560 --a------ C:\WINDOWS\system32\mnmdd.dll
2006-12-31 15:45 28,672 --a------ C:\WINDOWS\system32\nmmkcert.dll
2006-12-31 15:45 274,944 --a------ C:\WINDOWS\system32\mstask.dll
2006-12-31 15:45 252,928 --a------ C:\WINDOWS\system32\msoeacct.dll
2006-12-31 15:45 239,104 --a------ C:\WINDOWS\system32\srrstr.dll
2006-12-31 15:45 190,976 --a------ C:\WINDOWS\system32\schedsvc.dll
2006-12-31 15:45 18,944 --a------ C:\WINDOWS\system32\qmgrprxy.dll
2006-12-31 15:45 170,496 --a------ C:\WINDOWS\system32\srsvc.dll
2006-12-31 15:45 12,288 --a------ C:\WINDOWS\system32\mstinit.exe
2006-12-31 15:45 105,984 --a------ C:\WINDOWS\system32\msoert2.dll
2006-12-31 15:45 d-------- C:\WINDOWS\system32\Restore
2006-12-31 15:45 d-------- C:\WINDOWS\Registration
2006-12-31 15:45 d-------- C:\WINDOWS\PCHealth
2006-12-31 15:45 d-------- C:\Program Files\Outlook Express
2006-12-31 15:45 d-------- C:\Program Files\NetMeeting
2006-12-31 15:45 d-------- C:\Program Files\Movie Maker
2006-12-31 15:45 d-------- C:\Program Files\Internet Explorer
2006-12-31 15:45 d-------- C:\Program Files\ComPlus Applications
2006-12-31 15:45 d-------- C:\Program Files\Common Files\System
2006-12-31 15:44 97,792 --a------ C:\WINDOWS\system32\comrepl.dll
2006-12-31 15:44 956,416 --a------ C:\WINDOWS\system32\msdtctm.dll
2006-12-31 15:44 91,136 --a------ C:\WINDOWS\system32\mtxoci.dll
2006-12-31 15:44 9,728 --a------ C:\WINDOWS\system32\reset.exe
2006-12-31 15:44 85,504 --a------ C:\WINDOWS\system32\catsrvps.dll
2006-12-31 15:44 80,384 --a------ C:\WINDOWS\system32\charmap.exe
2006-12-31 15:44 73,216 --a------ C:\WINDOWS\system32\avwav.dll
2006-12-31 15:44 67,072 --a------ C:\WINDOWS\system32\rdshost.exe
2006-12-31 15:44 605,696 --a------ C:\WINDOWS\system32\getuname.dll
2006-12-31 15:44 60,416 --a------ C:\WINDOWS\system32\colbact.dll
2006-12-31 15:44 6,144 --a------ C:\WINDOWS\system32\msdtc.exe
2006-12-31 15:44 58,880 --a------ C:\WINDOWS\system32\msdtclog.dll
2006-12-31 15:44 56,832 --a------ C:\WINDOWS\system32\sol.exe
2006-12-31 15:44 55,296 --a------ C:\WINDOWS\system32\freecell.exe
2006-12-31 15:44 540,160 --a------ C:\WINDOWS\system32\comuid.dll
2006-12-31 15:44 54,272 --a------ C:\WINDOWS\system32\stclient.dll
2006-12-31 15:44 5,632 --a------ C:\WINDOWS\system32\write.exe
2006-12-31 15:44 5,120 --a------ C:\WINDOWS\system32\dcomcnfg.exe
2006-12-31 15:44 498,688 --a------ C:\WINDOWS\system32\clbcatq.dll
2006-12-31 15:44 44,544 --a------ C:\WINDOWS\system32\hticons.dll
2006-12-31 15:44 4,096 --a------ C:\WINDOWS\system32\rdpcfgex.dll
2006-12-31 15:44 4,096 --a------ C:\WINDOWS\system32\mtxex.dll
2006-12-31 15:44 35,328 --a------ C:\WINDOWS\system32\winchat.exe
2006-12-31 15:44 347,136 --a------ C:\WINDOWS\system32\hypertrm.dll
2006-12-31 15:44 33,792 --a------ C:\WINDOWS\system32\regini.exe
2006-12-31 15:44 25,600 --a------ C:\WINDOWS\system32\comaddin.dll
2006-12-31 15:44 25,088 --a------ C:\WINDOWS\system32\mtxlegih.dll
2006-12-31 15:44 227,840 --a------ C:\WINDOWS\system32\avtapi.dll
2006-12-31 15:44 225,792 --a------ C:\WINDOWS\system32\catsrv.dll
2006-12-31 15:44 22,016 --a------ C:\WINDOWS\system32\qwinsta.exe
2006-12-31 15:44 21,896 --a------ C:\WINDOWS\system32\drivers\tdtcp.sys
2006-12-31 15:44 20,992 --a------ C:\WINDOWS\system32\msg.exe
2006-12-31 15:44 20,480 --a------ C:\WINDOWS\system32\qprocess.exe
2006-12-31 15:44 20,480 --a------ C:\WINDOWS\system32\mtxdm.dll
2006-12-31 15:44 183,808 --a------ C:\WINDOWS\system32\accwiz.exe
2006-12-31 15:44 161,280 --a------ C:\WINDOWS\system32\msdtcuiu.dll
2006-12-31 15:44 16,896 --a------ C:\WINDOWS\system32\tsshutdn.exe
2006-12-31 15:44 16,896 --a------ C:\WINDOWS\system32\qappsrv.exe
2006-12-31 15:44 16,384 --a------ C:\WINDOWS\system32\tskill.exe
2006-12-31 15:44 16,384 --a------ C:\WINDOWS\system32\avmeter.dll
2006-12-31 15:44 15,872 --a------ C:\WINDOWS\system32\rwinsta.exe
2006-12-31 15:44 15,872 --a------ C:\WINDOWS\system32\cdmodem.dll
2006-12-31 15:44 15,360 --a------ C:\WINDOWS\system32\logoff.exe
2006-12-31 15:44 147,456 --a------ C:\WINDOWS\system32\comsnap.dll
2006-12-31 15:44 14,848 --a------ C:\WINDOWS\system32\tsdiscon.exe
2006-12-31 15:44 14,848 --a------ C:\WINDOWS\system32\tscon.exe
2006-12-31 15:44 14,848 --a------ C:\WINDOWS\system32\shadow.exe
2006-12-31 15:44 138,752 --a------ C:\WINDOWS\system32\sndvol32.exe
2006-12-31 15:44 131,584 --a------ C:\WINDOWS\system32\sndrec32.exe
2006-12-31 15:44 126,976 --a------ C:\WINDOWS\system32\mshearts.exe
2006-12-31 15:44 12,040 --a------ C:\WINDOWS\system32\drivers\tdpipe.sys
2006-12-31 15:44 119,808 --a------ C:\WINDOWS\system32\winmine.exe
2006-12-31 15:44 114,688 --a------ C:\WINDOWS\system32\calc.exe
2006-12-31 15:44 110,080 --a------ C:\WINDOWS\system32\clbcatex.dll
2006-12-31 15:44 11,776 --a------ C:\WINDOWS\system32\xolehlp.dll
2006-12-31 15:44 1,161 --a------ C:\WINDOWS\system32\usrlogon.cmd
2006-12-31 15:44 d--h----- C:\Program Files\WindowsUpdate
2006-12-31 15:44 d-------- C:\Program Files\Windows Media Player
2006-12-31 15:44 d-------- C:\Program Files\Online Services
2006-12-31 15:44 d-------- C:\Program Files\MSN Gaming Zone
2006-12-31 15:44 d-------- C:\Program Files\Messenger
2006-12-31 15:43 93,696 --a------ C:\WINDOWS\system32\tscfgwmi.dll
2006-12-31 15:43 87,176 --a------ C:\WINDOWS\system32\rdpwsx.dll
2006-12-31 15:43 655,360 --a------ C:\WINDOWS\system32\mstscax.dll
2006-12-31 15:43 625,152 --a------ C:\WINDOWS\system32\catsrvut.dll
2006-12-31 15:43 62,464 --a------ C:\WINDOWS\system32\rdpclip.exe
2006-12-31 15:43 60,416 --a------ C:\WINDOWS\system32\remotepg.dll
2006-12-31 15:43 6,656 --a------ C:\WINDOWS\system32\wuauserv.dll
2006-12-31 15:43 58,880 --a------ C:\WINDOWS\system32\licwmi.dll
2006-12-31 15:43 56,320 --a------ C:\WINDOWS\system32\servdeps.dll
2006-12-31 15:43 538,624 --a------ C:\WINDOWS\system32\spider.exe
2006-12-31 15:43 44,544 --a------ C:\WINDOWS\system32\tscupgrd.exe
2006-12-31 15:43 426,496 --a------ C:\WINDOWS\system32\msdtcprx.dll
2006-12-31 15:43 407,552 --a------ C:\WINDOWS\system32\mstsc.exe
2006-12-31 15:43 40,840 --a------ C:\WINDOWS\system32\drivers\termdd.sys
2006-12-31 15:43 38,912 --a------ C:\WINDOWS\system32\cfgbkend.dll
2006-12-31 15:43 343,040 --a------ C:\WINDOWS\system32\mspaint.exe
2006-12-31 15:43 295,424 --a------ C:\WINDOWS\system32\termsrv.dll
2006-12-31 15:43 196,864 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2006-12-31 15:43 19,968 --a------ C:\WINDOWS\system32\rdpsnd.dll
2006-12-31 15:43 185,344 --a------ C:\WINDOWS\system32\cmprops.dll
2006-12-31 15:43 17,408 --a------ C:\WINDOWS\system32\mmfutil.dll
2006-12-31 15:43 147,968 --a------ C:\WINDOWS\system32\rdchost.dll
2006-12-31 15:43 140,800 --a------ C:\WINDOWS\system32\sessmgr.exe
2006-12-31 15:43 139,528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys
2006-12-31 15:43 13,824 --a------ C:\WINDOWS\system32\rdsaddin.exe
2006-12-31 15:43 124,184 --a------ C:\WINDOWS\system32\wuauclt.exe
2006-12-31 15:43 123,392 --a------ C:\WINDOWS\system32\mplay32.exe
2006-12-31 15:43 11,264 --a------ C:\WINDOWS\system32\icaapi.dll
2006-12-31 15:43 102,912 --a------ C:\WINDOWS\system32\clipbrd.exe
2006-12-31 15:43 1,343,768
 

· Registered
Joined
·
130 Posts
Discussion Starter · #18 ·
C:\WINDOWS\system32\wuaueng.dll
2006-12-31 15:43 1,267,200 --a------ C:\WINDOWS\system32\comsvcs.dll
2006-12-31 15:43 d-------- C:\WINDOWS\system32\MsDtc
2006-12-31 15:43 d-------- C:\WINDOWS\system32\Com
2006-12-31 15:43 d-------- C:\Program Files\Windows NT
2006-12-31 15:43 d-------- C:\Program Files\MSN
2006-12-31 15:42 82,944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys
2006-12-31 15:42 7,552 --a------ C:\WINDOWS\system32\drivers\mskssrv.sys
2006-12-31 15:42 60,800 --a------ C:\WINDOWS\system32\drivers\sysaudio.sys
2006-12-31 15:42 6,400 --a------ C:\WINDOWS\system32\drivers\splitter.sys
2006-12-31 15:42 54,272 --a------ C:\WINDOWS\system32\drivers\swmidi.sys
2006-12-31 15:42 52,864 --a------ C:\WINDOWS\system32\drivers\dmusic.sys
2006-12-31 15:42 5,376 --a------ C:\WINDOWS\system32\drivers\mspclock.sys
2006-12-31 15:42 4,992 --a------ C:\WINDOWS\system32\drivers\mspqm.sys
2006-12-31 15:42 3,072 --a------ C:\WINDOWS\system32\drivers\audstub.sys
2006-12-31 15:42 2,944 --a------ C:\WINDOWS\system32\drivers\drmkaud.sys
2006-12-31 15:42 172,416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys
2006-12-31 15:42 142,464 --a------ C:\WINDOWS\system32\drivers\aec.sys
2006-12-31 15:41 9,759 --a------ C:\WINDOWS\system32\HSF_INST.dll
2006-12-31 15:41 73,279 --a------ C:\WINDOWS\system32\drivers\HSF_SPKP.sys
2006-12-31 15:41 67,167 --a------ C:\WINDOWS\system32\drivers\HSF_BSC2.sys
2006-12-31 15:41 57,472 --a------ C:\WINDOWS\system32\drivers\redbook.sys
2006-12-31 15:41 57,471 --a------ C:\WINDOWS\system32\drivers\HSF_SAMP.sys
2006-12-31 15:41 542,879 --a------ C:\WINDOWS\system32\drivers\HSF_MSFT.sys
2006-12-31 15:41 50,751 --a------ C:\WINDOWS\system32\drivers\HSF_TONE.sys
2006-12-31 15:41 488,383 --a------ C:\WINDOWS\system32\drivers\HSF_V124.sys
2006-12-31 15:41 44,863 --a------ C:\WINDOWS\system32\drivers\HSF_SOAR.sys
2006-12-31 15:41 391,199 --a------ C:\WINDOWS\system32\drivers\HSF_K56K.sys
2006-12-31 15:41 289,887 --a------ C:\WINDOWS\system32\drivers\HSF_FALL.sys
2006-12-31 15:41 199,711 --a------ C:\WINDOWS\system32\drivers\HSF_FAXX.sys
2006-12-31 15:41 150,239 --a------ C:\WINDOWS\system32\drivers\HSF_AMOS.sys
2006-12-31 15:41 115,807 --a------ C:\WINDOWS\system32\drivers\HSF_FSKS.sys
2006-12-31 15:41 10,624 --a------ C:\WINDOWS\system32\drivers\gameenum.sys
2006-12-31 15:40 74,240 --a------ C:\WINDOWS\system32\usbui.dll
2006-12-31 15:40 41,088 --a------ C:\WINDOWS\system32\drivers\sisagp.sys
2006-12-31 15:38 9,936 --a------ C:\WINDOWS\system\LZEXPAND.DLL
2006-12-31 15:38 9,008 --a------ C:\WINDOWS\system\VER.DLL
2006-12-31 15:38 85,020 --a------ C:\WINDOWS\system32\dgsetup.dll
2006-12-31 15:38 82,944 --a------ C:\WINDOWS\system\OLECLI.DLL
2006-12-31 15:38 8,704 --a------ C:\WINDOWS\system32\batt.dll
2006-12-31 15:38 8,192 -ra------ C:\WINDOWS\system32\kbdhept.dll
2006-12-31 15:38 74,752 --a------ C:\WINDOWS\system32\storprop.dll
2006-12-31 15:38 7,168 -ra------ C:\WINDOWS\system32\kbdcz.dll
2006-12-31 15:38 69,584 --a------ C:\WINDOWS\system\AVICAP.DLL
2006-12-31 15:38 69,120 --a------ C:\WINDOWS\notepad.exe
2006-12-31 15:38 68,768 --a------ C:\WINDOWS\system\mmsystem.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdycl.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdsl1.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdsl.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdpl.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdhu.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdhela3.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdcz2.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdcz1.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\kbdcr.dll
2006-12-31 15:38 6,656 -ra------ C:\WINDOWS\system32\KBDAL.DLL
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdtuq.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdtuf.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdlv1.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdlv.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdhela2.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdgkl.dll
2006-12-31 15:38 6,144 -ra------ C:\WINDOWS\system32\kbdest.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdycc.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbduzb.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdur.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdtat.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdru1.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdru.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdro.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdpl1.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdmon.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdlt1.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdlt.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdkyr.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdkaz.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdhu1.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdhe319.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdhe220.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdhe.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdbu.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdblr.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdazel.dll
2006-12-31 15:38 5,632 -ra------ C:\WINDOWS\system32\kbdaze.dll
2006-12-31 15:38 5,120 --a------ C:\WINDOWS\system\SHELL.DLL
2006-12-31 15:38 32,816 --a------ C:\WINDOWS\system\COMMDLG.DLL
2006-12-31 15:38 24,661 --a------ C:\WINDOWS\system32\spxcoins.dll
2006-12-31 15:38 24,064 --a------ C:\WINDOWS\system\OLESVR.DLL
2006-12-31 15:38 19,200 --a------ C:\WINDOWS\system\TAPI.DLL
2006-12-31 15:38 176,157 --a------ C:\WINDOWS\system32\dgrpsetu.dll
2006-12-31 15:38 15,360 --a------ C:\WINDOWS\TASKMAN.EXE
2006-12-31 15:38 13,312 --a------ C:\WINDOWS\system32\irclass.dll
2006-12-31 15:38 126,912 --a------ C:\WINDOWS\system\MSVIDEO.DLL
2006-12-31 15:38 11,264 --a------ C:\WINDOWS\system32\drivers\irenum.sys
2006-12-31 15:38 109,456 --a------ C:\WINDOWS\system\AVIFILE.DLL
2006-12-31 15:38 103,424 --a------ C:\WINDOWS\system32\EqnClass.Dll
2006-12-31 15:38 dr------- C:\Program Files\Common Files\..
2006-12-31 15:38 dr------- C:\Program Files\.
2006-12-31 15:38 dr------- C:\Program Files
2006-12-31 15:38 dr------- C:\Documents and Settings\All Users\Start Menu
2006-12-31 15:38 dr------- C:\Documents and Settings\All Users\Documents
2006-12-31 15:38 d-ahs---- C:\Program Files\..
2006-12-31 15:38 d--h----- C:\Documents and Settings\All Users\Templates
2006-12-31 15:38 d-------- C:\WINDOWS\system32\CatRoot2
2006-12-31 15:38 d-------- C:\WINDOWS\system32\CatRoot
2006-12-31 15:38 d-------- C:\Program Files\Common Files\SpeechEngines
2006-12-31 15:38 d-------- C:\Program Files\Common Files\ODBC
2006-12-31 15:38 d-------- C:\Program Files\Common Files\Microsoft Shared
2006-12-31 15:38 d-------- C:\Program Files\Common Files\.
2006-12-31 15:38 d-------- C:\Program Files\Common Files
2006-12-31 15:38 d-------- C:\Documents and Settings\All Users\Favorites
2006-12-31 15:38 d-------- C:\Documents and Settings\All Users\Desktop
2006-12-31 15:37 dr-h----- C:\Documents and Settings\All Users\Application Data\.
2006-12-31 15:37 dr-h----- C:\Documents and Settings\All Users\Application Data
2006-12-31 15:37 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2006-12-31 15:37 d-------- C:\Documents and Settings\All Users\Application Data\..
2006-12-31 15:37 d-------- C:\Documents and Settings\All Users\..
2006-12-31 15:37 d-------- C:\Documents and Settings\All Users\.
2006-12-31 15:37 d-------- C:\Documents and Settings
2006-12-31 15:36 d-------- C:\THEME
2006-12-31 15:36 d-------- C:\DRIVERS
2006-12-31 15:32 dr-hsc--- C:\WINDOWS\system32\dllcache
2006-12-31 15:32 dr--s---- C:\WINDOWS\Fonts
2006-12-31 15:32 dr------- C:\WINDOWS\Web
2006-12-31 15:32 d-ahs---- C:\WINDOWS\..
2006-12-31 15:32 d--h----- C:\WINDOWS\inf
2006-12-31 15:32 d-------- C:\WINDOWS\WinSxS
2006-12-31 15:32 d-------- C:\WINDOWS\twain_32
2006-12-31 15:32 d-------- C:\WINDOWS\Temp
2006-12-31 15:32 d-------- C:\WINDOWS\system32\wins
2006-12-31 15:32 d-------- C:\WINDOWS\system32\wbem
2006-12-31 15:32 d-------- C:\WINDOWS\system32\usmt
2006-12-31 15:32 d-------- C:\WINDOWS\system32\spool
2006-12-31 15:32 d-------- C:\WINDOWS\system32\ShellExt
2006-12-31 15:32 d-------- C:\WINDOWS\system32\Setup
2006-12-31 15:32 d-------- C:\WINDOWS\system32\ras
2006-12-31 15:32 d-------- C:\WINDOWS\system32\oobe
2006-12-31 15:32 d-------- C:\WINDOWS\system32\npp
2006-12-31 15:32 d-------- C:\WINDOWS\system32\mui
2006-12-31 15:32 d-------- C:\WINDOWS\system32\inetsrv
2006-12-31 15:32 d-------- C:\WINDOWS\system32\IME
2006-12-31 15:32 d-------- C:\WINDOWS\system32\icsxml
2006-12-31 15:32 d-------- C:\WINDOWS\system32\ias
2006-12-31 15:32 d-------- C:\WINDOWS\system32\export
2006-12-31 15:32 d-------- C:\WINDOWS\system32\drivers\etc
2006-12-31 15:32 d-------- C:\WINDOWS\system32\drivers\disdn
2006-12-31 15:32 d-------- C:\WINDOWS\system32\drivers\..
2006-12-31 15:32 d-------- C:\WINDOWS\system32\drivers\.
2006-12-31 15:32 d-------- C:\WINDOWS\system32\drivers
2006-12-31 15:32 d-------- C:\WINDOWS\system32\dhcp
2006-12-31 15:32 d-------- C:\WINDOWS\system32\config
2006-12-31 15:32 d-------- C:\WINDOWS\system32\3com_dmi
2006-12-31 15:32 d-------- C:\WINDOWS\system32\3076
2006-12-31 15:32 d-------- C:\WINDOWS\system32\2052
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1054
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1042
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1041
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1037
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1033
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1031
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1028
2006-12-31 15:32 d-------- C:\WINDOWS\system32\1025
2006-12-31 15:32 d-------- C:\WINDOWS\system32\..
2006-12-31 15:32 d-------- C:\WINDOWS\system32\.
2006-12-31 15:32 d-------- C:\WINDOWS\system32
2006-12-31 15:32 d-------- C:\WINDOWS\system\..
2006-12-31 15:32 d-------- C:\WINDOWS\system\.
2006-12-31 15:32 d-------- C:\WINDOWS\system
2006-12-31 15:32 d-------- C:\WINDOWS\security
2006-12-31 15:32 d-------- C:\WINDOWS\Resources
2006-12-31 15:32 d-------- C:\WINDOWS\repair
2006-12-31 15:32 d-------- C:\WINDOWS\mui
2006-12-31 15:32 d-------- C:\WINDOWS\msapps
2006-12-31 15:32 d-------- C:\WINDOWS\msagent
2006-12-31 15:32 d-------- C:\WINDOWS\Media
2006-12-31 15:32 d-------- C:\WINDOWS\java
2006-12-31 15:32 d-------- C:\WINDOWS\ime
2006-12-31 15:32 d-------- C:\WINDOWS\Help
2006-12-31 15:32 d-------- C:\WINDOWS\Driver Cache
2006-12-31 15:32 d-------- C:\WINDOWS\Debug
2006-12-31 15:32 d-------- C:\WINDOWS\Cursors
2006-12-31 15:32 d-------- C:\WINDOWS\Connection Wizard
2006-12-31 15:32 d-------- C:\WINDOWS\Config
2006-12-31 15:32 d-------- C:\WINDOWS\AppPatch
2006-12-31 15:32 d-------- C:\WINDOWS\addins
2006-12-31 15:32 d-------- C:\WINDOWS\.
2006-12-31 15:32 d-------- C:\WINDOWS
 

· Registered
Joined
·
130 Posts
Discussion Starter · #19 ·
And to finish

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))

(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe"
"iIWiper"="C:\\Program Files\\iISystem Wiper\\SystemWiper.exe m"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"AVG7_CC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgcc.exe /STARTUP"
"AVG7_EMC"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgemc.exe"
"AVG7_RegCleaner"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgregcl.exe /BOOT"
@=""

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000000

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"
"AVG7_Run"="C:\\PROGRA~1\\Grisoft\\AVG7\\avgw.exe /RUNONCE"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"dontdisplaylastusername"=dword:00000000
"legalnoticecaption"=""
"legalnoticetext"=""
"shutdownwithoutlogon"=dword:00000001
"undockwithoutlogon"=dword:00000001

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload]
"PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}"
"CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}"
"WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}"
"SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="Mixer"
"hkey"="HKLM"
"command"="Mixer.exe /startup"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="NeroCheck"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="DrgToDsc"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Roxio\\Easy Media Creator 8\\Drag to Disc\\DrgToDsc.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxWatchTray]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="RoxWatchTray"
"hkey"="HKLM"
"command"="\"C:\\Program Files\\Common Files\\Roxio Shared\\SharedCOM8\\RoxWatchTray.exe\""
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="SOUNDMAN"
"hkey"="HKLM"
"command"="SOUNDMAN.EXE"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="jusched"
"hkey"="HKLM"
"command"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"inimapping"="0"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winlogon]
"key"="SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Run"
"item"="nvchost"
"hkey"="HKLM"
"command"="C:\\WINDOWS\\nvchost"
"inimapping"="0"
 

· Registered
Joined
·
4,718 Posts
Ok, let's continue..thanks for splitting up the logs.
It looks as though you reformatted quite recently..

Open hijackthis, click 'config' (bottom right) Choose the tab 'misc Tools' on top.
Choose 'delete a file on reboot'. In the field, copy and paste the filepath a few lines below.
Click open. Hijackthis will tell you that this file will be deleted on next reboot and if you want to reboot now.
When asked if you want to reboot now, say Yes.:
C:\WINDOWS\nvchost.exe

After the reboot navigate and see if this is present:
C:\WINDOWS\nvchost <--if this folder is present delete it.

Please open notepad and and copy and paste next bold in it:
(don't forget to copy and paste REGEDIT4)
REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\winlogon]
Save this as "fix.reg" Choose to save as *all files and place it on your desktop.
It should look like this:
Doubleclick on it and when it asks you if you want to merge the contents to the registry, click yes/ok.

Download and save Blacklight to your desktop.
Double-click blbeta.exe then accept the agreement.
Click on scan then click next,
You'll see a list of all items found.
Do not choose for rename yet! I want to see the log first; legitimate items can also be present.
There is a log on your desktop with the name fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
Post the contents of the log in your next reply.
Also post a new HJT log.
 
1 - 20 of 45 Posts
Status
Not open for further replies.
Top