Here you go.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uukjedxv.dll
C:\WINDOWS\system32\uukjedxv.dll NOT unregistered.
C:\WINDOWS\system32\uukjedxv.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sanykwyj.dll
C:\WINDOWS\system32\sanykwyj.dll NOT unregistered.
C:\WINDOWS\system32\sanykwyj.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\frtahwye.dll
C:\WINDOWS\system32\frtahwye.dll NOT unregistered.
C:\WINDOWS\system32\frtahwye.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\dinnrsxa.dll
C:\WINDOWS\system32\dinnrsxa.dll NOT unregistered.
C:\WINDOWS\system32\dinnrsxa.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\kikmjklr.dll
C:\WINDOWS\system32\kikmjklr.dll NOT unregistered.
C:\WINDOWS\system32\kikmjklr.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ebiewsvq.dll
C:\WINDOWS\system32\ebiewsvq.dll NOT unregistered.
C:\WINDOWS\system32\ebiewsvq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cpaqgkvk.dll
C:\WINDOWS\system32\cpaqgkvk.dll NOT unregistered.
C:\WINDOWS\system32\cpaqgkvk.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tweiubel.dll
C:\WINDOWS\system32\tweiubel.dll NOT unregistered.
C:\WINDOWS\system32\tweiubel.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\pszouwcr.dll
C:\WINDOWS\system32\pszouwcr.dll NOT unregistered.
C:\WINDOWS\system32\pszouwcr.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ewrygksz.dll
C:\WINDOWS\system32\ewrygksz.dll NOT unregistered.
C:\WINDOWS\system32\ewrygksz.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\qzoequjy.dll
C:\WINDOWS\system32\qzoequjy.dll NOT unregistered.
C:\WINDOWS\system32\qzoequjy.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\lgcymdyt.dll
C:\WINDOWS\system32\lgcymdyt.dll NOT unregistered.
C:\WINDOWS\system32\lgcymdyt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yukfedtn.dll
C:\WINDOWS\system32\yukfedtn.dll NOT unregistered.
C:\WINDOWS\system32\yukfedtn.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uknwcmgp.dll
C:\WINDOWS\system32\uknwcmgp.dll NOT unregistered.
C:\WINDOWS\system32\uknwcmgp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\bktucgor.dll
C:\WINDOWS\system32\bktucgor.dll NOT unregistered.
C:\WINDOWS\system32\bktucgor.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\exmayxld.dll
C:\WINDOWS\system32\exmayxld.dll NOT unregistered.
C:\WINDOWS\system32\exmayxld.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\xjaroaqg.dll
C:\WINDOWS\system32\xjaroaqg.dll NOT unregistered.
C:\WINDOWS\system32\xjaroaqg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\waeknqtd.dll
C:\WINDOWS\system32\waeknqtd.dll NOT unregistered.
C:\WINDOWS\system32\waeknqtd.dll moved successfully.
C:\WINDOWS\system32\vvgeowbv.exe moved successfully.
C:\WINDOWS\system32\dpqaqlqx.bin moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ounwcmgp.dll
C:\WINDOWS\system32\ounwcmgp.dll NOT unregistered.
C:\WINDOWS\system32\ounwcmgp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\eywwtmjn.dll
C:\WINDOWS\system32\eywwtmjn.dll NOT unregistered.
C:\WINDOWS\system32\eywwtmjn.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yjublvgn.dll
C:\WINDOWS\system32\yjublvgn.dll NOT unregistered.
C:\WINDOWS\system32\yjublvgn.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\nsttxcdg.dll
C:\WINDOWS\system32\nsttxcdg.dll NOT unregistered.
C:\WINDOWS\system32\nsttxcdg.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uxelxzgn.dll
C:\WINDOWS\system32\uxelxzgn.dll NOT unregistered.
C:\WINDOWS\system32\uxelxzgn.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\mugtiuko.dll
C:\WINDOWS\system32\mugtiuko.dll NOT unregistered.
C:\WINDOWS\system32\mugtiuko.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sqstqrxt.dll
C:\WINDOWS\system32\sqstqrxt.dll NOT unregistered.
C:\WINDOWS\system32\sqstqrxt.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\lkkksrqp.dll
C:\WINDOWS\system32\lkkksrqp.dll NOT unregistered.
C:\WINDOWS\system32\lkkksrqp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\gryjtdkv.dll
C:\WINDOWS\system32\gryjtdkv.dll NOT unregistered.
C:\WINDOWS\system32\gryjtdkv.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yitguiwj.dll
C:\WINDOWS\system32\yitguiwj.dll NOT unregistered.
C:\WINDOWS\system32\yitguiwj.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\kjywuspq.dll
C:\WINDOWS\system32\kjywuspq.dll NOT unregistered.
C:\WINDOWS\system32\kjywuspq.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\yepwhrbi.dll
C:\WINDOWS\system32\yepwhrbi.dll NOT unregistered.
C:\WINDOWS\system32\yepwhrbi.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ipszlrub.dll
C:\WINDOWS\system32\ipszlrub.dll NOT unregistered.
C:\WINDOWS\system32\ipszlrub.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uhypjvmd.dll
C:\WINDOWS\system32\uhypjvmd.dll NOT unregistered.
C:\WINDOWS\system32\uhypjvmd.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ckofqykq.dll
C:\WINDOWS\system32\ckofqykq.dll NOT unregistered.
C:\WINDOWS\system32\ckofqykq.dll moved successfully.
C:\WINDOWS\system32\stfv.bin moved successfully.
C:\WINDOWS\system32\acespy moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\ace16win.dll
C:\WINDOWS\system32\ace16win.dll NOT unregistered.
C:\WINDOWS\system32\ace16win.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\smkkhaxb.dll
C:\WINDOWS\system32\smkkhaxb.dll NOT unregistered.
C:\WINDOWS\system32\smkkhaxb.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\kwiqdsiu.dll
C:\WINDOWS\system32\kwiqdsiu.dll NOT unregistered.
C:\WINDOWS\system32\kwiqdsiu.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\uoigzsln.dll
C:\WINDOWS\system32\uoigzsln.dll NOT unregistered.
C:\WINDOWS\system32\uoigzsln.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\awkbwrjz.dll
C:\WINDOWS\system32\awkbwrjz.dll NOT unregistered.
C:\WINDOWS\system32\awkbwrjz.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\wkufwkcs.dll
C:\WINDOWS\system32\wkufwkcs.dll NOT unregistered.
C:\WINDOWS\system32\wkufwkcs.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\cpylhtcp.dll
C:\WINDOWS\system32\cpylhtcp.dll NOT unregistered.
C:\WINDOWS\system32\cpylhtcp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\tsngecax.dll
C:\WINDOWS\system32\tsngecax.dll NOT unregistered.
C:\WINDOWS\system32\tsngecax.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\sbgpnvej.dll
C:\WINDOWS\system32\sbgpnvej.dll NOT unregistered.
C:\WINDOWS\system32\sbgpnvej.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\talvfmxk.dll
C:\WINDOWS\system32\talvfmxk.dll NOT unregistered.
C:\WINDOWS\system32\talvfmxk.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\ocxojbvm.dll
C:\WINDOWS\system32\ocxojbvm.dll NOT unregistered.
C:\WINDOWS\system32\ocxojbvm.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\vafiimqv.dll
C:\WINDOWS\system32\vafiimqv.dll NOT unregistered.
C:\WINDOWS\system32\vafiimqv.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\neroeugp.dll
C:\WINDOWS\system32\neroeugp.dll NOT unregistered.
C:\WINDOWS\system32\neroeugp.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\scfihvxa.dll
C:\WINDOWS\system32\scfihvxa.dll NOT unregistered.
C:\WINDOWS\system32\scfihvxa.dll moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\system32\khkgcyxw.dll
C:\WINDOWS\system32\khkgcyxw.dll NOT unregistered.
C:\WINDOWS\system32\khkgcyxw.dll moved successfully.
C:\Documents and Settings\Administrator\Application Data\Adssite Advanced Toolbar moved successfully.
C:\Documents and Settings\Administrator\Application Data\internaldb41.dat moved successfully.
File/Folder C:\\WINDOWS\\system32\\vvgeowbv.exe not found.
File/Folder C:\WINDOWS\System32\llsccn.exe not found.
File/Folder C:\PROGRA~1\COMMON~1\mmou not found.
File/Folder C:\PROGRA~1\COMMON~1\ICROSO~1 not found.
File/Folder C:\WINDOWS\xload.exe not found.
Created on 11/13/2007 11:24:21
SUPERAntiSpyware
SUPERAntiSpyware Scan Log
http://www.superantispyware.comGenerated 11/13/2007 at 03:04 PM
Application Version : 3.9.1008
Core Rules Database Version : 3343
Trace Rules Database Version: 1344
Scan type : Complete Scan
Total Scan Time : 00:33:06
Memory items scanned : 374
Memory threats detected : 0
Registry items scanned : 5518
Registry threats detected : 0
File items scanned : 28008
File threats detected : 6
Trojan.Downloader-FakeRX
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000387.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000388.DLL
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000389.DLL
Trojan.Downloader-Gen/Burre
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000390.DLL
Trojan.TaskDir
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000391.DLL
Adware.WebBuying Assistant-Installer
C:\SYSTEM VOLUME INFORMATION\_RESTORE{799F3823-C297-4530-A9C5-8991F6C828B5}\RP5\A0000392.EXE
WinPFind log
WinPFind3 logfile created on: 11/13/2007 5:16:11 PM
WinPFind3U by OldTimer - Version 1.0.42 Folder = C:\Documents and Settings\Administrator\Desktop\WinPFind3u\
Microsoft Windows XP Service Pack 2 (Version = 5.1.2600)
Internet Explorer (Version = 6.0.2900.2180)
1022.99 Mb Total Physical Memory | 610.55 Mb Available Physical Memory | 59.68% Memory free
1.66 Gb Paging File | 1.43 Gb Available in Paging File | 86.42% Paging File free
Paging file location(s): C:\pagefile.sys 768 1553;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 12.72 Gb Free Space | 34.14% Space Free
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
Computer Name: WEAR
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
[Processes - Non-Microsoft Only]
applemobiledeviceservice.exe -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ]
ashdisp.exe -> %ProgramFiles%\Alwil Software\Avast4\ashDisp.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 79224 bytes | Modified Date = 9/6/2007 5:06:10 AM | Attr = ]
ashserv.exe -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 132472 bytes | Modified Date = 9/6/2007 5:06:04 AM | Attr = ]
aswupdsv.exe -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 16248 bytes | Modified Date = 9/6/2007 4:54:58 AM | Attr = ]
ipodservice.exe -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 11/2/2007 6:36:32 PM | Attr = ]
ituneshelper.exe -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 11/2/2007 6:36:42 PM | Attr = ]
nvsvc32.exe -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.9147 | Size = 155715 bytes | Modified Date = 8/11/2006 7:42:50 PM | Attr = ]
superantispyware.exe -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr = ]
winpfind3u.exe -> %UserDesktop%\WinPFind3u\WinPFind3U.exe -> OldTimer Tools [Ver = 1.0.42.0 | Size = 322560 bytes | Modified Date = 9/4/2007 10:47:26 AM | Attr = ]
wlservice.exe -> %ProgramFiles%\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe -> GEMTEKS [Ver = 1, 0, 0, 4 | Size = 41025 bytes | Modified Date = 2/6/2004 10:56:14 PM | Attr = ]
wmp54gv4.exe -> %ProgramFiles%\Linksys Wireless-G PCI Wireless Network Monitor\WMP54Gv4.exe -> Linksys [Ver = 1.0.1.8 | Size = 5238272 bytes | Modified Date = 11/16/2005 4:49:44 AM | Attr = ]
[Win32 Services - Non-Microsoft Only]
(Apple Mobile Device) Apple Mobile Device [Win32_Own | Auto | Running] -> %CommonProgramFiles%\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -> Apple, Inc. [Ver = 1, 14, 0, 0 | Size = 110592 bytes | Modified Date = 9/6/2007 12:28:18 PM | Attr = ]
(aswUpdSv) avast! iAVS4 Control Service [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\aswUpdSv.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 16248 bytes | Modified Date = 9/6/2007 4:54:58 AM | Attr = ]
(Ati HotKey Poller) Ati HotKey Poller [Win32_Own | Auto | Stopped] -> %System32%\ati2evxx.exe -> [Ver = | Size = 303104 bytes | Modified Date = 9/6/2003 8:37:00 PM | Attr = ]
(avast! Antivirus) avast! Antivirus [Win32_Own | Auto | Running] -> %ProgramFiles%\Alwil Software\Avast4\ashServ.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 132472 bytes | Modified Date = 9/6/2007 5:06:04 AM | Attr = ]
(avast! Mail Scanner) avast! Mail Scanner [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Alwil Software\Avast4\ashMaiSv.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 243064 bytes | Modified Date = 9/6/2007 5:05:42 AM | Attr = ]
(avast! Web Scanner) avast! Web Scanner [Win32_Own | On_Demand | Stopped] -> %ProgramFiles%\Alwil Software\Avast4\ashWebSv.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 345464 bytes | Modified Date = 9/6/2007 5:04:44 AM | Attr = ]
(dmadmin) Logical Disk Manager Administrative Service [Win32_Shared | Disabled | Stopped] -> %System32%\dmadmin.exe -> Microsoft Corp., Veritas Software [Ver = 2600.2180.503.0 | Size = 224768 bytes | Modified Date = 8/4/2004 1:56:48 AM | Attr = ]
(IDriverT) InstallDriver Table Manager [Win32_Own | On_Demand | Stopped] -> %CommonProgramFiles%\InstallShield\Driver\1150\Intel 32\IDriverT.exe -> Macrovision Corporation [Ver = 11.50.42618 | Size = 69632 bytes | Modified Date = 11/14/2005 1:06:04 AM | Attr = ]
(iPod Service) iPod Service [Win32_Own | On_Demand | Running] -> %ProgramFiles%\iPod\bin\iPodService.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 504104 bytes | Modified Date = 11/2/2007 6:36:32 PM | Attr = ]
(NVSvc) NVIDIA Display Driver Service [Win32_Own | Auto | Running] -> %System32%\nvsvc32.exe -> NVIDIA Corporation [Ver = 6.14.10.9147 | Size = 155715 bytes | Modified Date = 8/11/2006 7:42:50 PM | Attr = ]
(WMP54Gv4SVC) WMP54Gv4SVC [Win32_Own | Auto | Running] -> %ProgramFiles%\Linksys Wireless-G PCI Wireless Network Monitor\WLService.exe -> GEMTEKS [Ver = 1, 0, 0, 4 | Size = 41025 bytes | Modified Date = 2/6/2004 10:56:14 PM | Attr = ]
[Registry - Non-Microsoft Only]
< Run [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
ATIModeChange -> %System32%\Ati2mdxx.exe -> ATI Technologies, Inc. [Ver = 4.13.3 | Size = 28672 bytes | Modified Date = 9/4/2001 3:24:00 PM | Attr = ]
avast! -> %ProgramFiles%\Alwil Software\Avast4\ashDisp.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 79224 bytes | Modified Date = 9/6/2007 5:06:10 AM | Attr = ]
iTunesHelper -> %ProgramFiles%\iTunes\iTunesHelper.exe -> Apple Inc. [Ver = 7.5.0.20 | Size = 267048 bytes | Modified Date = 11/2/2007 6:36:42 PM | Attr = ]
NvCplDaemon -> %System32%\nvcpl.dll [RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup] -> NVIDIA Corporation [Ver = 6.14.10.9147 | Size = 7630848 bytes | Modified Date = 8/11/2006 7:43:02 PM | Attr = ]
NvMediaCenter -> %System32%\nvmctray.dll [RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit] -> NVIDIA Corporation [Ver = 6.14.10.9147 | Size = 86016 bytes | Modified Date = 8/11/2006 7:43:04 PM | Attr = ]
QuickTime Task -> %ProgramFiles%\QuickTime\QTTask.exe -> Apple Inc. [Ver = 7.3 | Size = 286720 bytes | Modified Date = 10/19/2007 8:16:26 PM | Attr = ]
< OptionalComponents [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\OptionalComponents\ ->
IMAIL -> Installed = 1 ->
MAPI -> Installed = 1 ->
MSFS -> Installed = 1 ->
< Run [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run ->
SUPERAntiSpyware -> %ProgramFiles%\SUPERAntiSpyware\SUPERAntiSpyware.exe -> SUPERAntiSpyware.com [Ver = 3, 9, 0, 1008 | Size = 1318912 bytes | Modified Date = 6/21/2007 2:06:28 PM | Attr = ]
< User Startup > -> C:\Documents and Settings\Administrator\Start Menu\Programs\Startup ->
%UserStartup%\ERUNT AutoBackup.lnk -> %ProgramFiles%\ERUNT\AUTOBACK.EXE -> [Ver = | Size = 38912 bytes | Modified Date = 10/20/2005 12:04:08 PM | Attr = ]
< ICQ Agent [HKCU] > -> HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\ ->
HKEY_CURRENT_USER\Software\Mirabilis\ICQ\Agent\Apps\ -> ->
< ShellExecuteHooks [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks ->
{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} [HKLM] -> %ProgramFiles%\SUPERAntiSpyware\SASSEH.DLL [] -> SuperAdBlocker.com [Ver = 1, 0, 0, 1008 | Size = 77824 bytes | Modified Date = 12/20/2006 1:55:48 PM | Attr = ]
< SecurityProviders [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\\SecurityProviders ->
< Winlogon settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
< Winlogon settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon ->
*UserInit* -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit ->
C:\WINDOWS\system32\vvgeowbv.exe -> %System32%\vvgeowbv.exe -> File not found
< Winlogon\Notify settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ ->
!SASWinLogon -> %ProgramFiles%\SUPERAntiSpyware\SASWINLO.dll -> SUPERAntiSpyware.com [Ver = 1, 0, 0, 1046 | Size = 294912 bytes | Modified Date = 4/19/2007 1:41:36 PM | Attr = ]
< CurrentVersion Policy Settings [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveAutoRun -> 67108863 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\\NoDriveTypeAutoRun -> 255 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{BDEADF00-C265-11D0-BCED-00A0C90AB50F} -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{6DFD7C5C-2451-11d3-A299-00C04F8EF6AF} -> 1073741857 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\NonEnum\\{0DF44EAA-FF21-4412-828E-260A8728E7F1} -> 32 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\ -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\dontdisplaylastusername -> 0 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticecaption -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\legalnoticetext -> ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\shutdownwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\\undockwithoutlogon -> 1 ->
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Uninstall\ -> ->
< CurrentVersion Policy Settings [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\ActiveDesktop\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Associations\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun -> 145 ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run\ -> ->
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\ -> ->
< HOSTS File > (27 bytes) -> C:\WINDOWS\System32\drivers\etc\Hosts ->
127.0.0.1 localhost -> ->
< Internet Explorer Settings > -> ->
HKLM: Default_Page_URL ->
http://www.microsoft...p...&ar=msnhome ->
HKLM: Main\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Local Page -> C:\windows\system32\blank.htm ->
HKLM: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: Start Page ->
http://www.microsoft...p...ER}&ar=home ->
HKLM: CustomizeSearch ->
http://ie.search.msn...st/srchcust.htm ->
HKLM: Search\\Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKLM: SearchAssistant ->
http://ie.search.msn...st/srchasst.htm ->
HKCU: Default_Search_URL ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Local Page -> C:\WINDOWS\system32\blank.htm ->
HKCU: Search Page ->
http://www.microsoft...amp;ar=iesearch ->
HKCU: Start Page -> www.google.com ->
HKCU: ProxyEnable -> 0 ->
< Trusted Sites > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ ->
msn.com [ - ] -> ->
< BHO's > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\ ->
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} [HKLM] -> %ProgramFiles%\Java\jre1.6.0_01\bin\ssv.dll [SSVHelper Class] -> Sun Microsystems, Inc. [Ver = 6.0.10.6 | Size = 501400 bytes | Modified Date = 3/14/2007 2:43:40 AM | Attr = ]
< Internet Explorer Bars [HKCU] > -> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\ ->
{32683183-48a0-441b-a342-7c2a440a9478} [HKLM] -> Reg Data - Key not found [Reg Data - Key not found] -> File not found
< Internet Explorer ToolBars [HKCU] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ ->
WebBrowser\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} [HKLM] -> Reg Data - Key not found [Yahoo! Toolbar] -> File not found
< User Agent Post Platform [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform ->
{EC5DC32E-CE23-9402-3955-16C8DE90949A} -> ->
SV1 -> ->
< DNS Name Servers [HKLM] > -> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Adapters\ ->
{07383DDD-CCCF-482A-99B7-A4AEC796F2B7} -> (Linksys Wireless-G PCI Adapter) ->
{3F570B30-6703-45BF-9935-2B609ED9EB1F} -> (Intel® PRO/1000 MT Network Connection) ->
{DA18C2FA-A7C8-4842-AC19-2004DB311B27} -> () ->
< Protocol Handlers [HKLM] > -> HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ ->
ipp -> Reg Data - Key not found -> File not found
msdaipp -> Reg Data - Key not found -> File not found
< Downloaded Program Files > -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\ ->
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} -> QuickTime Object - CodeBase =
http://www.apple.com...ex/qtplugin.cab ->
{166B1BCA-3F9C-11CF-8075-444553540000} -> Shockwave ActiveX Control - CodeBase =
http://download.macr...director/sw.cab ->
{7B19E477-0FF8-11d4-9914-005004D3B3DB} -> JavaPlugin.Object - CodeBase =
http://java.sun.com/...122_011-win.cab ->
{8AD9C840-044E-11D1-B3E9-00805F499D93} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...122_011-win.cab ->
{CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} -> Java Plug-in 1.6.0_01 - CodeBase =
http://java.sun.com/...indows-i586.cab ->
{D27CDB6E-AE6D-11CF-96B8-444553540000} -> - CodeBase =
http://fpdownload.ma...ash/swflash.cab ->
[Files/Folders - Created Within 30 days]
ComboFix -> %SystemDrive%\ComboFix -> [Folder | Created Date = 11/9/2007 3:57:50 PM | Attr = ]
qoobox -> %SystemDrive%\qoobox -> [Folder | Created Date = 11/9/2007 3:58:51 PM | Attr = ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Created Date = 11/13/2007 11:24:10 AM | Attr = ]
absolute key logger.lnk -> %SystemRoot%\absolute key logger.lnk -> [Ver = | Size = 25344 bytes | Created Date = 10/15/2007 10:16:45 PM | Attr = ]
aconti.ini -> %SystemRoot%\aconti.ini -> [Ver = | Size = 18688 bytes | Created Date = 11/9/2007 12:40:43 PM | Attr = ]
aconti.sdb -> %SystemRoot%\aconti.sdb -> [Ver = | Size = 8192 bytes | Created Date = 11/9/2007 12:40:43 PM | Attr = ]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 136192 bytes | Created Date = 11/9/2007 3:57:58 PM | Attr = ]
default.htm -> %SystemRoot%\default.htm -> [Ver = | Size = 1679 bytes | Created Date = 10/15/2007 10:16:42 PM | Attr = ]
erdnt -> %SystemRoot%\erdnt -> [Folder | Created Date = 11/9/2007 4:02:56 PM | Attr = ]
NirCmd.exe -> %SystemRoot%\NirCmd.exe -> NirSoft [Ver = 2.00 | Size = 51200 bytes | Created Date = 11/9/2007 3:57:58 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Created Date = 10/30/2007 12:48:18 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Created Date = 10/30/2007 12:48:18 PM | Attr = H ]
actskin4.ocx -> %System32%\actskin4.ocx -> [Ver = 4, 2, 7, 3 | Size = 380928 bytes | Created Date = 11/8/2007 8:29:52 AM | Attr = ]
aswBoot.exe -> %System32%\aswBoot.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 801144 bytes | Created Date = 11/8/2007 8:29:52 AM | Attr = ]
AvastSS.scr -> %System32%\AvastSS.scr -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 95608 bytes | Created Date = 11/8/2007 8:29:59 AM | Attr = ]
bflqwlsw.ini -> %System32%\bflqwlsw.ini -> [Ver = | Size = 1280502 bytes | Created Date = 11/2/2007 11:34:50 PM | Attr = HS]
dlxyamxe.ini -> %System32%\dlxyamxe.ini -> [Ver = | Size = 1201486 bytes | Created Date = 11/5/2007 11:25:56 PM | Attr = HS]
jpewocmz.ini -> %System32%\jpewocmz.ini -> [Ver = | Size = 4 bytes | Created Date = 11/2/2007 11:32:34 PM | Attr = ]
QuickTime.qts -> %System32%\QuickTime.qts -> Apple Inc. [Ver = 7.3 | Size = 49152 bytes | Created Date = 10/19/2007 8:16:46 PM | Attr = ]
QuickTimeVR.qtx -> %System32%\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.3 | Size = 65536 bytes | Created Date = 10/19/2007 8:16:46 PM | Attr = ]
shgwndxg.ini -> %System32%\shgwndxg.ini -> [Ver = | Size = 1273287 bytes | Created Date = 10/24/2007 3:46:19 PM | Attr = HS]
swxcacls.exe -> %System32%\swxcacls.exe -> SteelWerX [Ver = 1.0.1.1 | Size = 212480 bytes | Created Date = 11/9/2007 3:57:58 PM | Attr = ]
sznf.ascii -> %System32%\sznf.ascii -> [Ver = | Size = 92 bytes | Created Date = 11/9/2007 12:37:58 PM | Attr = ]
VFind.exe -> %System32%\VFind.exe -> [Ver = | Size = 49152 bytes | Created Date = 11/9/2007 3:57:58 PM | Attr = ]
wwdqqcru.ini -> %System32%\wwdqqcru.ini -> [Ver = | Size = 1242406 bytes | Created Date = 11/3/2007 12:19:48 AM | Attr = HS]
aavmker4.sys -> %System32%\drivers\aavmker4.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 26624 bytes | Created Date = 11/8/2007 8:30:01 AM | Attr = ]
aswmon.sys -> %System32%\drivers\aswmon.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 92848 bytes | Created Date = 11/8/2007 8:29:57 AM | Attr = ]
aswmon2.sys -> %System32%\drivers\aswmon2.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 94416 bytes | Created Date = 11/8/2007 8:29:57 AM | Attr = ]
aswRdr.sys -> %System32%\drivers\aswRdr.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 23152 bytes | Created Date = 11/8/2007 8:30:03 AM | Attr = ]
aswTdi.sys -> %System32%\drivers\aswTdi.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 42912 bytes | Created Date = 11/8/2007 8:30:02 AM | Attr = ]
[Files/Folders - Modified Within 90 days]
ComboFix -> %SystemDrive%\ComboFix -> [Folder | Modified Date = 11/9/2007 6:58:38 PM | Attr = ]
Config.Msi -> %SystemDrive%\Config.Msi -> [Folder | Modified Date = 11/13/2007 12:47:04 PM | Attr = HS]
dvdcopy -> %SystemDrive%\dvdcopy -> [Folder | Modified Date = 9/13/2007 1:33:56 AM | Attr = ]
Program Files -> %ProgramFiles% -> [Folder | Modified Date = 11/13/2007 11:31:34 AM | Attr = R ]
qoobox -> %SystemDrive%\qoobox -> [Folder | Modified Date = 11/9/2007 6:58:18 PM | Attr = ]
System Volume Information -> %SystemDrive%\System Volume Information -> [Folder | Modified Date = 11/9/2007 4:04:04 PM | Attr = HS]
Temp -> %SystemDrive%\Temp -> [Folder | Modified Date = 11/9/2007 4:01:32 PM | Attr = ]
WINDOWS -> %SystemRoot% -> [Folder | Modified Date = 11/13/2007 12:48:42 PM | Attr = ]
_OTMoveIt -> %SystemDrive%\_OTMoveIt -> [Folder | Modified Date = 11/13/2007 11:24:12 AM | Attr = ]
$hf_mig$ -> %SystemRoot%\$hf_mig$ -> [Folder | Modified Date = 10/10/2007 11:30:36 AM | Attr = H ]
$NtUninstallKB933360$ -> %SystemRoot%\$NtUninstallKB933360$ -> [Folder | Modified Date = 8/29/2007 2:00:22 AM | Attr = H ]
$NtUninstallKB933729$ -> %SystemRoot%\$NtUninstallKB933729$ -> [Folder | Modified Date = 10/10/2007 11:30:38 AM | Attr = H ]
$NtUninstallKB939653$ -> %SystemRoot%\$NtUninstallKB939653$ -> [Folder | Modified Date = 10/10/2007 11:30:22 AM | Attr = H ]
$NtUninstallKB941202$ -> %SystemRoot%\$NtUninstallKB941202$ -> [Folder | Modified Date = 10/10/2007 11:29:10 AM | Attr = H ]
absolute key logger.lnk -> %SystemRoot%\absolute key logger.lnk -> [Ver = | Size = 25344 bytes | Modified Date = 10/15/2007 10:16:46 PM | Attr = ]
aconti.ini -> %SystemRoot%\aconti.ini -> [Ver = | Size = 18688 bytes | Modified Date = 11/9/2007 12:40:44 PM | Attr = ]
aconti.sdb -> %SystemRoot%\aconti.sdb -> [Ver = | Size = 8192 bytes | Modified Date = 11/9/2007 12:40:44 PM | Attr = ]
bootstat.dat -> %SystemRoot%\bootstat.dat -> [Ver = | Size = 2048 bytes | Modified Date = 11/13/2007 12:47:06 PM | Attr = S]
catchme.exe -> %SystemRoot%\catchme.exe -> [Ver = | Size = 136192 bytes | Modified Date = 10/29/2007 6:56:20 PM | Attr = ]
default.htm -> %SystemRoot%\default.htm -> [Ver = | Size = 1679 bytes | Modified Date = 11/9/2007 12:39:36 PM | Attr = ]
Downloaded Program Files -> %SystemRoot%\Downloaded Program Files -> [Folder | Modified Date = 11/13/2007 12:47:02 PM | Attr = S]
erdnt -> %SystemRoot%\erdnt -> [Folder | Modified Date = 11/13/2007 12:49:04 PM | Attr = ]
Help -> %SystemRoot%\Help -> [Folder | Modified Date = 8/24/2007 5:10:08 AM | Attr = ]
imsins.BAK -> %SystemRoot%\imsins.BAK -> [Ver = | Size = 1393 bytes | Modified Date = 10/10/2007 11:30:32 AM | Attr = ]
inf -> %SystemRoot%\inf -> [Folder | Modified Date = 11/13/2007 10:41:06 AM | Attr = H ]
Installer -> %SystemRoot%\Installer -> [Folder | Modified Date = 11/13/2007 11:31:38 AM | Attr = HS]
MEMORY.DMP -> %SystemRoot%\MEMORY.DMP -> [Ver = | Size = 805306368 bytes | Modified Date = 11/8/2007 3:13:30 PM | Attr = ]
mozver.dat -> %SystemRoot%\mozver.dat -> [Ver = | Size = 3866 bytes | Modified Date = 9/15/2007 9:01:14 AM | Attr = ]
NeroDigital.ini -> %SystemRoot%\NeroDigital.ini -> [Ver = | Size = 116 bytes | Modified Date = 9/25/2007 3:25:52 PM | Attr = ]
Prefetch -> %SystemRoot%\Prefetch -> [Folder | Modified Date = 11/13/2007 5:14:12 PM | Attr = ]
QTFont.for -> %SystemRoot%\QTFont.for -> [Ver = | Size = 1409 bytes | Modified Date = 10/30/2007 12:48:20 PM | Attr = ]
QTFont.qfn -> %SystemRoot%\QTFont.qfn -> [Ver = | Size = 54156 bytes | Modified Date = 11/13/2007 12:49:16 PM | Attr = H ]
Registration -> %SystemRoot%\Registration -> [Folder | Modified Date = 9/27/2007 10:19:54 AM | Attr = ]
security -> %SystemRoot%\security -> [Folder | Modified Date = 11/8/2007 3:54:48 PM | Attr = ]
system32 -> %System32% -> [Folder | Modified Date = 11/13/2007 12:44:34 PM | Attr = HS]
Tasks -> %SystemRoot%\Tasks -> [Folder | Modified Date = 11/8/2007 8:28:18 AM | Attr = S]
Temp -> %SystemRoot%\Temp -> [Folder | Modified Date = 11/13/2007 4:51:58 PM | Attr = ]
UHJlZmVycmVkIEN1c3RvbWVy -> %SystemRoot%\UHJlZmVycmVkIEN1c3RvbWVy -> [Folder | Modified Date = 11/8/2007 8:26:30 AM | Attr = HS]
WinSxS -> %SystemRoot%\WinSxS -> [Folder | Modified Date = 9/21/2007 10:20:26 AM | Attr = ]
AppleSoftwareUpdate.job -> %SystemRoot%\tasks\AppleSoftwareUpdate.job -> [Ver = | Size = 284 bytes | Modified Date = 11/12/2007 4:30:02 PM | Attr = ]
SA.DAT -> %SystemRoot%\tasks\SA.DAT -> [Ver = | Size = 6 bytes | Modified Date = 11/13/2007 12:47:10 PM | Attr = H ]
aaamhgfv.dll -> %System32%\aaamhgfv.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
ajcsmohw.dll -> %System32%\ajcsmohw.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/6/2007 12:10:54 PM | Attr = ]
ajysmodw.dll -> %System32%\ajysmodw.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/28/2007 1:37:48 AM | Attr = ]
aswBoot.exe -> %System32%\aswBoot.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 801144 bytes | Modified Date = 9/6/2007 5:09:50 AM | Attr = ]
AvastSS.scr -> %System32%\AvastSS.scr -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 95608 bytes | Modified Date = 9/6/2007 5:00:08 AM | Attr = ]
beeisvux.dll -> %System32%\beeisvux.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:45:52 AM | Attr = ]
bflqwlsw.ini -> %System32%\bflqwlsw.ini -> [Ver = | Size = 1280502 bytes | Modified Date = 11/2/2007 11:35:06 PM | Attr = HS]
CatRoot2 -> %System32%\CatRoot2 -> [Folder | Modified Date = 11/13/2007 12:47:20 PM | Attr = ]
config -> %System32%\config -> [Folder | Modified Date = 11/9/2007 4:03:04 PM | Attr = ]
CONFIG.NT -> %System32%\CONFIG.NT -> [Ver = | Size = 2626 bytes | Modified Date = 11/8/2007 8:30:02 AM | Attr = ]
cphtgtoa.dll -> %System32%\cphtgtoa.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 11:41:34 AM | Attr = ]
din.ip -> %System32%\din.ip -> [Ver = | Size = 12 bytes | Modified Date = 11/2/2007 11:32:36 PM | Attr = ]
dirpxclm.dll -> %System32%\dirpxclm.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
dllcache -> %System32%\dllcache -> [Folder | Modified Date = 11/8/2007 9:02:20 AM | Attr = RHS]
dlxyamxe.ini -> %System32%\dlxyamxe.ini -> [Ver = | Size = 1201486 bytes | Modified Date = 11/5/2007 11:41:12 PM | Attr = HS]
driv2 -> %System32%\driv2 -> [Folder | Modified Date = 11/13/2007 12:47:02 PM | Attr = ]
drivers -> %System32%\drivers -> [Folder | Modified Date = 11/9/2007 6:55:46 PM | Attr = ]
DRVSTORE -> %System32%\DRVSTORE -> [Folder | Modified Date = 11/13/2007 10:41:24 AM | Attr = ]
ebyvzrol.dll -> %System32%\ebyvzrol.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 11:02:56 PM | Attr = ]
ehggconm.dll -> %System32%\ehggconm.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:45:52 AM | Attr = ]
eimvckoa.dll -> %System32%\eimvckoa.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 10:56:48 AM | Attr = ]
emzoequj.dll -> %System32%\emzoequj.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 11:11:36 AM | Attr = ]
euyqwroc.ini -> %System32%\euyqwroc.ini -> [Ver = | Size = 694081 bytes | Modified Date = 10/9/2007 11:11:48 AM | Attr = HS]
gdkgcuxw.dll -> %System32%\gdkgcuxw.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/1/2007 3:49:58 PM | Attr = ]
GroupPolicy -> %System32%\GroupPolicy -> [Folder | Modified Date = 10/14/2007 11:25:38 PM | Attr = H ]
hjbunskc.dll -> %System32%\hjbunskc.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:42:18 AM | Attr = ]
hkcmd.exe -> %System32%\hkcmd.exe -> Intel Corporation [Ver = 3.0.0.4342 | Size = 163840 bytes | Modified Date = 9/27/2007 10:31:50 AM | Attr = ]
hlzodkym.dll -> %System32%\hlzodkym.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 11:54:06 PM | Attr = ]
iblv.dll -> %System32%\iblv.dll -> [Ver = | Size = 69632 bytes | Modified Date = 11/5/2007 11:35:32 PM | Attr = ]
icwyngzf.dll -> %System32%\icwyngzf.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/2/2007 4:00:26 PM | Attr = ]
jhgfusqo.dll -> %System32%\jhgfusqo.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 10:31:48 AM | Attr = ]
jkmoijkl.dll -> %System32%\jkmoijkl.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
jllmjooo.dll -> %System32%\jllmjooo.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/1/2007 3:49:58 PM | Attr = ]
jpewocmz.ini -> %System32%\jpewocmz.ini -> [Ver = | Size = 4 bytes | Modified Date = 11/2/2007 11:32:36 PM | Attr = ]
keys.res -> %System32%\keys.res -> [Ver = | Size = 2354 bytes | Modified Date = 10/14/2007 11:24:54 PM | Attr = ]
kgcmhyth.dll -> %System32%\kgcmhyth.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 9:32:34 PM | Attr = ]
kuxaznps.dll -> %System32%\kuxaznps.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 1:01:42 AM | Attr = ]
kzhrgvgq.dll -> %System32%\kzhrgvgq.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:45:52 AM | Attr = ]
lfnwfcks.dll -> %System32%\lfnwfcks.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 9:32:32 PM | Attr = ]
mudjosmn.ini -> %System32%\mudjosmn.ini -> [Ver = | Size = 693841 bytes | Modified Date = 10/4/2007 9:34:02 PM | Attr = HS]
mwgmbocm.dll -> %System32%\mwgmbocm.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
mzmzrdqd.dll -> %System32%\mzmzrdqd.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/28/2007 1:37:48 AM | Attr = ]
navwanvd.ini -> %System32%\navwanvd.ini -> [Ver = | Size = 4 bytes | Modified Date = 10/14/2007 11:25:04 PM | Attr = ]
nosaizgs.dll -> %System32%\nosaizgs.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
nvapps.xml -> %System32%\nvapps.xml -> [Ver = | Size = 81191 bytes | Modified Date = 11/13/2007 12:49:00 PM | Attr = ]
oeqlkosc.dll -> %System32%\oeqlkosc.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 11:41:32 AM | Attr = ]
ogyobsjd.dll -> %System32%\ogyobsjd.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 1:01:42 AM | Attr = ]
oowvutfd.dll -> %System32%\oowvutfd.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 9:32:34 PM | Attr = ]
oqwcraku.dll -> %System32%\oqwcraku.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/6/2007 12:10:56 PM | Attr = ]
perfc009.dat -> %System32%\perfc009.dat -> [Ver = | Size = 58596 bytes | Modified Date = 11/5/2007 11:42:48 PM | Attr = ]
perfh009.dat -> %System32%\perfh009.dat -> [Ver = | Size = 392296 bytes | Modified Date = 11/5/2007 11:42:48 PM | Attr = ]
PerfStringBackup.INI -> %System32%\PerfStringBackup.INI -> [Ver = | Size = 458340 bytes | Modified Date = 11/5/2007 11:42:48 PM | Attr = ]
QuickTime.qts -> %System32%\QuickTime.qts -> Apple Inc. [Ver = 7.3 | Size = 49152 bytes | Modified Date = 10/19/2007 8:16:46 PM | Attr = ]
QuickTimeVR.qtx -> %System32%\QuickTimeVR.qtx -> Apple Inc. [Ver = 7.3 | Size = 65536 bytes | Modified Date = 10/19/2007 8:16:46 PM | Attr = ]
Restore -> %System32%\Restore -> [Folder | Modified Date = 11/9/2007 4:04:04 PM | Attr = ]
rgtmmdns.ini -> %System32%\rgtmmdns.ini -> [Ver = | Size = 693721 bytes | Modified Date = 10/24/2007 3:43:46 PM | Attr = HS]
rpojcays.dll -> %System32%\rpojcays.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 12:51:42 PM | Attr = ]
sets.res -> %System32%\sets.res -> [Ver = | Size = 399 bytes | Modified Date = 10/9/2007 11:12:16 AM | Attr = ]
sft.res -> %System32%\sft.res -> [Ver = | Size = 1943 bytes | Modified Date = 11/6/2007 7:24:30 AM | Attr = ]
shgwndxg.ini -> %System32%\shgwndxg.ini -> [Ver = | Size = 1273287 bytes | Modified Date = 11/2/2007 11:19:36 PM | Attr = HS]
smrajhpu.dll -> %System32%\smrajhpu.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/2/2007 4:00:24 PM | Attr = ]
sznf.ascii -> %System32%\sznf.ascii -> [Ver = | Size = 92 bytes | Modified Date = 11/9/2007 12:38:00 PM | Attr = ]
ueydmvtb.dll -> %System32%\ueydmvtb.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:42:18 AM | Attr = ]
uiwgvwya.dll -> %System32%\uiwgvwya.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/4/2007 11:54:02 PM | Attr = ]
utstv.bak1 -> %System32%\utstv.bak1 -> [Ver = | Size = 2133026 bytes | Modified Date = 9/28/2007 10:14:14 PM | Attr = HS]
utstv.bak2 -> %System32%\utstv.bak2 -> [Ver = | Size = 6788 bytes | Modified Date = 9/28/2007 10:14:04 AM | Attr = HS]
utstv.ini -> %System32%\utstv.ini -> [Ver = | Size = 435938 bytes | Modified Date = 11/5/2007 11:37:00 PM | Attr = HS]
vbs9 -> %System32%\vbs9 -> [Folder | Modified Date = 10/13/2007 12:45:36 PM | Attr = ]
vtxgpquc.dll -> %System32%\vtxgpquc.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:07:12 AM | Attr = ]
wgyluhdl.dll -> %System32%\wgyluhdl.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 12:30:46 PM | Attr = ]
wmypswag.dll -> %System32%\wmypswag.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 11:11:36 AM | Attr = ]
wnarlbsf.dll -> %System32%\wnarlbsf.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:37:00 AM | Attr = ]
wpa.dbl -> %System32%\wpa.dbl -> [Ver = | Size = 2206 bytes | Modified Date = 11/13/2007 12:47:08 PM | Attr = ]
wuoolibf.dll -> %System32%\wuoolibf.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/3/2007 10:42:18 AM | Attr = ]
wwdqqcru.ini -> %System32%\wwdqqcru.ini -> [Ver = | Size = 1242406 bytes | Modified Date = 11/5/2007 7:35:16 PM | Attr = HS]
wykuqnmc.ini -> %System32%\wykuqnmc.ini -> [Ver = | Size = 693412 bytes | Modified Date = 9/30/2007 7:15:58 PM | Attr = HS]
ydausspi.dll -> %System32%\ydausspi.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 11:28:26 AM | Attr = ]
zenowair.dll -> %System32%\zenowair.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/28/2007 1:37:48 AM | Attr = ]
zgnuagmx.dll -> %System32%\zgnuagmx.dll -> [Ver = | Size = 32256 bytes | Modified Date = 9/27/2007 10:31:48 AM | Attr = ]
zgnuagmx.exe -> %System32%\zgnuagmx.exe -> [Ver = | Size = 3584 bytes | Modified Date = 9/27/2007 10:31:52 AM | Attr = ]
zip1 -> %System32%\zip1 -> [Folder | Modified Date = 9/27/2007 10:26:54 AM | Attr = ]
zncrymao.dll -> %System32%\zncrymao.dll -> [Ver = | Size = 32256 bytes | Modified Date = 10/9/2007 12:51:44 PM | Attr = ]
aavmker4.sys -> %System32%\drivers\aavmker4.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 26624 bytes | Modified Date = 9/6/2007 5:00:54 AM | Attr = ]
aswmon.sys -> %System32%\drivers\aswmon.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 92848 bytes | Modified Date = 9/6/2007 5:05:26 AM | Attr = ]
aswmon2.sys -> %System32%\drivers\aswmon2.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 94416 bytes | Modified Date = 9/6/2007 5:05:10 AM | Attr = ]
aswRdr.sys -> %System32%\drivers\aswRdr.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 23152 bytes | Modified Date = 9/6/2007 5:03:02 AM | Attr = ]
aswTdi.sys -> %System32%\drivers\aswTdi.sys -> ALWIL Software [Ver = 4.7.1043.0 | Size = 42912 bytes | Modified Date = 9/6/2007 5:02:20 AM | Attr = ]
etc -> %System32%\drivers\etc -> [Folder | Modified Date = 11/9/2007 6:55:50 PM | Attr = ]
tmcomm.sys -> %System32%\drivers\tmcomm.sys -> Trend Micro Inc. [Ver = 1.6.0.1059 | Size = 102664 bytes | Modified Date = 9/27/2007 10:07:42 AM | Attr = ]
[File String Scan - Non-Microsoft Only]
File scan skipped for file %SystemRoot%\MEMORY.DMP -> File size too big (805306368 bytes) ->
UPX! , UPX0 , -> %System32%\aswBoot.exe -> ALWIL Software [Ver = 4, 7, 1043, 0 | Size = 801144 bytes | Modified Date = 9/6/2007 5:09:50 AM | Attr = ]
PEC2 , -> %System32%\dfrg.msc -> [Ver = | Size = 41397 bytes | Modified Date = 8/23/2001 6:00:00 AM | Attr = ]
PEC2 , PECompact2 , -> %System32%\DivX.dll -> DivX, Inc. [Ver = 6.2.5.34 | Size = 620180 bytes | Modified Date = 7/18/2006 5:09:26 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ffdshow.ax -> [Ver = 1.0.2.2605 | Size = 889344 bytes | Modified Date = 11/29/2005 2:51:02 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_kernelDeint.dll -> [Ver = | Size = 32256 bytes | Modified Date = 11/29/2005 2:10:46 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_liba52.dll -> [Ver = | Size = 24064 bytes | Modified Date = 11/29/2005 2:09:00 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_libdts.dll -> [Ver = | Size = 99840 bytes | Modified Date = 11/29/2005 2:09:00 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_libmad.dll -> [Ver = | Size = 67584 bytes | Modified Date = 11/29/2005 2:09:04 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_realaac.dll -> [Ver = | Size = 79872 bytes | Modified Date = 11/29/2005 2:09:54 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_samplerate.dll -> [Ver = | Size = 113152 bytes | Modified Date = 11/29/2005 2:09:06 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_theora.dll -> [Ver = | Size = 77824 bytes | Modified Date = 11/29/2005 2:09:14 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_unrar.dll -> [Ver = | Size = 29184 bytes | Modified Date = 11/29/2005 2:09:24 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_vfw.dll -> [Ver = | Size = 3584 bytes | Modified Date = 11/29/2005 2:17:16 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_wmv9.dll -> [Ver = | Size = 14848 bytes | Modified Date = 11/29/2005 2:09:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\ff_x264.dll -> [Ver = | Size = 140800 bytes | Modified Date = 11/29/2005 2:10:06 PM | Attr = ]
UPX! , UPX0 , -> %System32%\iviaudio.ax -> InterVideo Inc. [Ver = 7.0.27.191 | Size = 462848 bytes | Modified Date = 4/17/2006 7:37:08 AM | Attr = ]
UPX! , UPX0 , -> %System32%\Ivinav.ax -> InterVideo Inc. [Ver = 7.0.27.172 | Size = 601600 bytes | Modified Date = 2/14/2006 3:12:54 PM | Attr = ]
UPX! , UPX0 , -> %System32%\IVIVIDEO.ax -> InterVideo Inc. [Ver = 7.0.27.191 | Size = 1089536 bytes | Modified Date = 4/17/2006 7:37:06 AM | Attr = ]
UPX! , UPX0 , -> %System32%\LameACM.acm ->
http://www.mp3dev.org/ [Ver = 0.9.1 | Size = 185344 bytes | Modified Date = 11/29/2005 3:39:24 AM | Attr = ]
UPX! , UPX0 , -> %System32%\libavcodec.dll -> [Ver = | Size = 912896 bytes | Modified Date = 11/29/2005 2:14:42 PM | Attr = ]
UPX! , UPX0 , -> %System32%\libmpeg2_ff.dll -> [Ver = | Size = 40448 bytes | Modified Date = 11/29/2005 2:10:10 PM | Attr = ]
UPX! , UPX0 , -> %System32%\libmplayer.dll -> [Ver = | Size = 114176 bytes | Modified Date = 11/29/2005 2:11:30 PM | Attr = ]
UPX! , UPX0 , -> %System32%\MODSource.ax -> [Ver = | Size = 70144 bytes | Modified Date = 12/10/2004 5:53:58 AM | Attr = ]
UPX! , UPX0 , -> %System32%\MP3Source.ax -> [Ver = | Size = 61952 bytes | Modified Date = 12/10/2004 5:51:50 AM | Attr = ]
UPX! , UPX0 , -> %System32%\SrchSTS.exe -> S!Ri [Ver = | Size = 288417 bytes | Modified Date = 4/27/2006 4:49:00 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swreg.exe -> SteelWerX [Ver = 2.0.1.8 | Size = 279552 bytes | Modified Date = 7/22/2007 6:39:28 PM | Attr = ]
UPX! , UPX0 , -> %System32%\swsc.exe -> [Ver = | Size = 40960 bytes | Modified Date = 1/9/2006 9:36:00 AM | Attr = ]
UPX! , UPX0 , -> %System32%\TomsMoComp_ff.dll -> [Ver = | Size = 38912 bytes | Modified Date = 11/29/2005 2:09:50 PM | Attr = ]
winsync , -> %System32%\wbdbase.deu -> [Ver = | Size = 1309184 bytes | Modified Date = 8/23/2001 6:00:00 AM | Attr = ]
WSUD , UPX0 , -> %System32%\dllcache\hwxjpn.dll -> [Ver = | Size = 13463552 bytes | Modified Date = 8/23/2001 6:00:00 AM | Attr = ]
PTech , -> %System32%\drivers\mtlstrm.sys -> Smart Link [Ver = 3.80.01MC15 | Size = 1309184 bytes | Modified Date = 8/3/2004 11:41:38 PM | Attr = ]
< End of report >