DSS LOG
Main.txt
Deckard's System Scanner v20070826.66
Run by weng on 2007-08-31 12:36:50
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 2 Restore Point(s) --
2: 2007-08-31 04:36:57 UTC - RP100 - Deckard's System Scanner Restore Point
1: 2007-08-30 23:30:54 UTC - RP99 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
System Drive D: has 1.49 GiB (less than 15%) free.-- HijackThis (run as weng.exe) ------------------------------------------------
Unable to find log (file not found); running clone.
-- HijackThis Clone ------------------------------------------------------------
Emulating logfile of HijackThis v1.99.1
Scan saved at 2007-08-31 12:37:39
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (6.00.2900.2180)
Running processes:
D:\WINDOWS\system32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
D:\WINDOWS\system32\spoolsv.exe
D:\WINDOWS\system32\ctfmon.exe
D:\WINDOWS\system32\svchost.exe
D:\Program Files\MSN Messenger\usnsvc.exe
D:\WINDOWS\system32\wscntfy.exe
D:\WINDOWS\explorer.exe
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Documents and Settings\weng.WENG-126DB86A18\Desktop\dss.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.comR1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieR1 - HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.comO2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm
O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macr...ash/swflash.cabO20 - AppInit_DLLs: wbsys.dll
O20 - Winlogon Notify: WBSrv - D:\WindowBlinds5GE\WbSrv.dll
O21 - SSODL: PostBootReminder - {7849596a-48ea-486e-8937-a2a3009f31a9} - D:\WINDOWS\system32\shell32.dll
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - D:\WINDOWS\system32\shell32.dll
O21 - SSODL: SysTray - {35CEC8A3-2BE6-11D2-8773-92E220524153} - D:\WINDOWS\system32\stobject.dll
-- HijackThis Fixed Entries (D:\PROGRA~1\HIJACK~1\backups\) --------------------
backup-20000822-112028-154 O4 - HKCU\..\Run: [SUPERAntiSpyware] D:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
backup-20000822-112028-285 O4 - HKLM\..\Run: [Storm2Set] D:\WINDOWS\system32\rundll32.exe "D:\PROGRA~1\StormII\StormSet.dll",CheckEnv
backup-20000822-112028-346 O4 - HKCU\..\Run: [BitTorrent DNA] "D:\Program Files\BitTorrent_DNA\dna.exe"
backup-20000822-112028-368 O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
backup-20000822-112028-374 O9 - Extra button: Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
backup-20000822-112028-403 O4 - HKLM\..\Run: [MSPY2002] D:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
backup-20000822-112028-421 O4 - HKLM\..\Run: [NeroFilterCheck] D:\WINDOWS\system32\NeroCheck.exe
backup-20000822-112028-424 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
backup-20000822-112028-495 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20000822-112028-531 O4 - HKLM\..\Run: [Thunder] "D:\Program Files\Thunder Network\Thunder\Thunder.exe" /s
backup-20000822-112028-537 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
backup-20000822-112028-580 O4 - HKLM\..\Run: [IMJPMIG8.1] "D:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
backup-20000822-112028-652 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm
backup-20000822-112028-670 O4 - HKLM\..\Run: [PHIME2002ASync] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
backup-20000822-112028-781 O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
backup-20000822-112028-851 O4 - HKCU\..\Run: [MsnMsgr] "D:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
backup-20000822-112028-864 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20000822-112028-869 O4 - HKLM\..\Run: [PHIME2002A] D:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
backup-20000822-112028-890 O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
backup-20000822-112028-898 O4 - HKLM\..\Run: [RAVDHMON] D:\Program Files\Internet Explorer\RAVDHMON.exe
backup-20000822-112029-396 O9 - Extra 'Tools' menuitem: Æô¶¯Ñ¸À×5 - {09BA8F6D-CB54-424B-839C-C2A6C8E6B436} - D:\Program Files\Thunder Network\Thunder\Thunder.exe
backup-20000822-112029-438 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
backup-20000822-112029-808 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - D:\Program Files\Messenger\msmsgs.exe
backup-20000822-112029-880 O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
http://www.fileplane...C_2.3.2.100.cabbackup-20000822-112030-232 O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
backup-20000822-112030-293 O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
backup-20000822-112030-325 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabbackup-20000822-112034-751 O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - D:\WINDOWS\system32\WPDShServiceObj.dll
backup-20000822-112034-975 O20 - Winlogon Notify: !SASWinLogon - D:\Program Files\SUPERAntiSpyware\SASWINLO.dll
backup-20000822-112035-203 O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
backup-20000822-112035-230 O23 - Service: SDService - Max Secure Software - D:\Program Files\Max PC Secure\MaxSpyDetector\SDService.exe
backup-20000822-112035-330 O23 - Service: NMIndexingService - Unknown owner - D:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)
backup-20070826-231141-235 O2 - BHO: (no name) - {C1626E66-C26B-C628-E1DF-CDACCFA26EE1} - D:\Program Files\Common Files\goskdl.dll
backup-20070826-231141-371 O2 - BHO: ThunderBHO - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
backup-20070826-231141-465 O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
backup-20070826-231141-529 O2 - BHO: Thunder AtOnce - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
backup-20070826-231141-600 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
backup-20070826-231141-732 O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
backup-20070826-231141-931 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm
backup-20070826-231146-141 O20 - Winlogon Notify: WBSrv - D:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
backup-20070826-231146-162 O23 - Service: 1111111 - Unknown owner - D:\WINDOWS\system32\wnipsvr.exe (file missing)
backup-20070826-231146-226 O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
backup-20070826-231146-305 O23 - Service: PDAgent - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDAgent.exe
backup-20070826-231146-497 O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
backup-20070826-231146-803 O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
backup-20070829-110641-224 O4 - HKLM\..\RunOnce: [Rav] "D:\Program Files\Rising\Rav\Update\setup.exe" /UNINSTALL /S /ONCE
backup-20070829-110641-290 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØÈ«²¿Á´½Ó - D:\Program Files\Thunder Network\Thunder\Program\getallurl.htm
backup-20070829-110641-297 O8 - Extra context menu item: ʹÓÃѸÀ×ÏÂÔØ - D:\Program Files\Thunder Network\Thunder\Program\geturl.htm
backup-20070829-110641-317 O2 - BHO: ThunderAtOnce Class - {01443AEC-0FD1-40fd-9C87-E93D1494C233} - D:\Program Files\Thunder Network\Thunder\ComDlls\TDAtOnce_Now.dll
backup-20070829-110641-402 O4 - HKLM\..\Run: [AVP] "D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"
backup-20070829-110641-491 O4 - HKCU\..\Run: [ctfmon.exe] D:\WINDOWS\system32\ctfmon.exe
backup-20070829-110641-602 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
backup-20070829-110641-628 O4 - HKCU\..\Run: [msnmsgr] "D:\Program Files\MSN Messenger\msnmsgr.exe" /background
backup-20070829-110641-650 O2 - BHO: Thunder Browser Helper - {889D2FEB-5411-4565-8998-1DD2C5261283} - D:\Program Files\Thunder Network\Thunder\ComDlls\xunleiBHO_Now.dll
backup-20070829-110641-685 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20070829-110641-781 O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll
backup-20070829-110642-310 O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
http://acs.pandasoft...free/asinst.cabbackup-20070829-110642-824 O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://wengsun1988.s...ad/MsnPUpld.cabbackup-20070829-110643-108 O23 - Service: 1111111 - - (no file)
backup-20070829-110643-110 O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - D:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
backup-20070829-110643-189 O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Unknown owner - D:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe" -r (file missing)
backup-20070829-110643-281 O20 - Winlogon Notify: WBSrv - d:\NEWFOL~1\wbsrv.dll
backup-20070829-110643-443 O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - D:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
backup-20070829-110643-458 O23 - Service: PDEngine - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDEngine.exe
backup-20070829-110643-687 O23 - Service: PDAgent - Raxco Software, Inc. - D:\Program Files\Raxco\PerfectDisk\PDAgent.exe
backup-20070829-110643-821 O20 - Winlogon Notify: klogon - D:\WINDOWS\system32\klogon.dll
-- File Associations -----------------------------------------------------------
.bat - batfile - DefaultIcon - D:\WINDOWS\system32\shell32.dll,71.inf - inffile - DefaultIcon - D:\WINDOWS\system32\shell32.dll,69.ini - inifile - DefaultIcon - D:\WINDOWS\system32\shell32.dll,69.txt - txtfile - DefaultIcon - D:\WINDOWS\system32\shell32.dll,70-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 SASDIFSV - d:\program files\superantispyware\sasdifsv.sys
R1 SASKUTIL - d:\program files\superantispyware\saskutil.sys
R3 SASENUM - d:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
R4 kl1 - d:\windows\system32\drivers\kl1.sys (file missing)
R4 klif - d:\windows\system32\drivers\klif.sys (file missing)
S0 RsAntiSpyware - d:\windows\system32\drivers\rsboot.sys (file missing)
S3 Ad-Watch Connect Filter (Ad-Watch Connect Kernel Filter) - d:\windows\system32\drivers\nsdriver.sys <Not Verified; Lavasoft AB; Ad-Watch Connections>
S3 Ad-Watch Real-Time Scanner (AW Real-Time Scanner) - d:\windows\system32\drivers\awrtpd.sys <Not Verified; Lavasoft AB; Ad-Watch Beta>
S3 Ad-Watch Registry Filter (Ad-Watch Registry Kernel Filter) - d:\windows\system32\drivers\awrtrd.sys <Not Verified; Lavasoft AB; Ad-Watch Registry Protection>
S3 ahaaha1 - d:\documents and settings\weng.weng-126db86a18\desktop\new folder (2)\ahaaha.sys (file missing)
S3 bandieng1 - d:\documents and settings\weng.weng-126db86a18\desktop\new folder (2)\bandieng.sys (file missing)
S3 catchme - d:\docume~1\weng~1.wen\locals~1\temp\catchme.sys (file missing)
S3 DADriv1 - d:\documents and settings\weng.weng-126db86a18\desktop\new folder\dak32.sys (file missing)
S3 IlvMoneyDRIVER53 - d:\documents and settings\weng.weng-126db86a18\desktop\moonlight engine lite 1055\ilvmoney1055.sys (file missing)
S3 NPF (Netgroup Packet Filter) - d:\windows\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
S3 SockHook - d:\windows\system32\drivers\sockhook.sys <Not Verified; ; SOCKHOOK Driver>
S3 TdiPbk - d:\windows\system32\drivers\tdipbk.sys <Not Verified; Vnn Networks Inc; TDIPBK Firewall>
S3 XDva008 - d:\windows\system32\xdva008.sys (file missing)
S3 zenos1 - d:\documents and settings\weng.weng-126db86a18\desktop\new folder (2)\sora.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
S4 1111111 -
S4 NMIndexingService -
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2007-08-28 14:12:10 388 --a------ D:\WINDOWS\Tasks\1-Click Maintenance.job
-- Files created between 2007-07-31 and 2007-08-31 -----------------------------
2007-08-30 16:32:35 0 d-------- D:\Program Files\DiskTrix
2007-08-30 16:25:33 0 d-------- D:\Program Files\UltraDefrag
2007-08-30 14:38:51 0 dr-h----- D:\Documents and Settings\weng.WENG-126DB86A18\Recent
2007-08-30 14:37:07 0 d-------- D:\WINDOWS\system32\ActiveScan
2007-08-29 22:04:47 0 d-------- D:\Program Files\Stardock
2007-08-29 18:31:11 0 d-------- D:\WINDOWS\LastGood
2007-08-29 11:36:47 0 d-------- D:\WindowBlinds5GE
2007-08-29 11:16:53 0 d-------- D:\Program Files\Advanced StartUp Manager
2007-08-29 09:03:42 106496 -----n--- D:\WINDOWS\system32\RavExt.dll <Not Verified; Beijing Rising Technology Co., Ltd.; Rising Antivirus Software>
2007-08-29 09:02:18 65536 -----n--- D:\WINDOWS\system32\shlhook.dll <Not Verified; Beijing Rising Technology Co., Ltd.; ??????????4.0>
2007-08-29 09:02:16 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Rising
2007-08-29 08:13:04 0 d-------- D:\Program Files\CCleaner
2007-08-28 16:04:32 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\AntiVir PersonalEdition Classic
2007-08-28 15:47:03 0 d-------- D:\Program Files\Kaspersky Lab
2007-08-28 15:47:03 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Kaspersky Lab
2007-08-28 15:46:47 3670016 --a------ D:\Documents and Settings\weng.WENG-126DB86A18\ntuser.dat
2007-08-28 15:46:47 229376 --a------ D:\Documents and Settings\LocalService.NT AUTHORITY\ntuser.dat
2007-08-28 14:37:06 151641 --a------ D:\WINDOWS\system32\xpsf1.exe
2007-08-28 14:37:06 208987 --a------ D:\WINDOWS\system32\xpsf.exe
2007-08-28 14:37:06 151634 --a------ D:\WINDOWS\system32\sson.exe
2007-08-28 14:37:06 20480 --a------ D:\WINDOWS\system32\psf.exe
2007-08-28 14:37:06 24576 --a------ D:\WINDOWS\system32\mvistasf.exe
2007-08-28 13:23:08 11138 --a------ D:\WINDOWS\msvrc20.dll
2007-08-28 13:11:55 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\RegistrySmart
2007-08-28 10:00:25 0 d-------- D:\Program Files\dp
2007-08-27 16:12:46 90112 --a------ D:\WINDOWS\unvise32.exe <Not Verified; MindVision Software; Installer VISE>
2007-08-27 11:21:51 233472 --a------ D:\WINDOWS\system32\wpcap.dll <Not Verified; CACE Technologies; WinPcap high level library>
2007-08-27 11:21:51 61440 --a------ D:\WINDOWS\system32\WanPacket.dll <Not Verified; CACE Technologies; WinPcap low level NetMon wrapper library>
2007-08-27 11:21:51 81920 --a------ D:\WINDOWS\system32\Packet.dll <Not Verified; CACE Technologies; WinPcap low level packet library>
2007-08-27 11:21:51 32512 --a------ D:\WINDOWS\system32\drivers\npf.sys <Not Verified; CACE Technologies; WinPcap Netgroup Packet Filter Driver>
2007-08-27 10:55:32 2251904 --a------ D:\WINDOWS\system32\ntoskvs1.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-26 23:48:03 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Visual Styler
2007-08-26 23:46:35 0 d-------- D:\WINDOWS\Icons
2007-08-26 22:37:25 81920 --a------ D:\WINDOWS\system32\CloseApp.exe <Not Verified; Noël Danjou; CloseApp>
2007-08-26 15:35:26 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\TuneUp Software
2007-08-26 15:34:52 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\TuneUp Software
2007-08-24 13:03:56 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Raxco
2007-08-24 13:03:18 0 d-------- D:\Program Files\Raxco
2007-08-20 20:18:15 63 --a------ D:\WINDOWS\system\SysMPS.dll
2007-08-20 20:15:21 1019904 --a------ D:\WINDOWS\system32\VchReg.dll <Not Verified; Max Secure Software; Voucher Registration>
2007-08-20 20:15:20 839680 --a------ D:\WINDOWS\system32\Evidence Killer Server.dll <Not Verified; ; Evidence Killer Server Module>
2007-08-20 20:15:18 413696 --a------ D:\WINDOWS\system32\Eraser.dll <Not Verified; -; Eraser>
2007-08-20 20:15:15 0 d-------- D:\Program Files\Max PC Secure
2007-08-20 19:58:48 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\SpywareRemover
2007-08-20 19:50:47 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2007-08-20 18:54:28 53 --a------ D:\WINDOWS\system32\ztkini.dll
2007-08-20 18:05:30 0 d-------- D:\Program Files\Common Files\Wise Installation Wizard
2007-08-16 18:34:53 60 --a------ D:\WINDOWS\system32\qhcini.dll
2007-08-16 09:59:12 50 --a------ D:\WINDOWS\system32\jhaini.dll
2007-08-14 18:35:06 54 --a------ D:\WINDOWS\system32\xyhini.dll
2007-08-14 07:26:45 53 --a------ D:\WINDOWS\system32\wlfini.dll
2007-08-14 07:26:39 48 --a------ D:\WINDOWS\system32\wdcini.dll
2007-08-12 20:17:28 53 --a------ D:\WINDOWS\system32\jzgini.dll
2007-08-12 20:16:46 94 --a------ D:\WINDOWS\system32\dhdini.dll
2007-08-12 17:09:47 106496 --a------ D:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2007-08-12 17:09:45 364544 -----n--- D:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
2007-08-12 17:09:45 471040 -----n--- D:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2007-08-12 17:09:45 262144 -----n--- D:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2007-08-12 17:09:44 1568768 -----n--- D:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2007-08-12 17:09:43 38912 -----n--- D:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2007-08-12 17:09:38 155648 --a------ D:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2007-08-12 17:09:38 0 d-------- D:\Program Files\Common Files\Ahead
2007-08-12 17:09:33 0 d-------- D:\Program Files\Ahead
2007-08-11 09:35:50 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Outspark
2007-08-11 09:33:07 0 d-------- D:\Program Files\BitTorrent_DNA
2007-08-11 09:33:07 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\BitTorrent DNA
2007-08-10 10:55:39 4682 --a------ D:\WINDOWS\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
2007-08-09 18:05:09 76037 --a------ D:\WINDOWS\War3Unin.dat
2007-08-09 18:05:08 2829 --a------ D:\WINDOWS\War3Unin.pif
2007-08-09 18:05:08 139264 --a------ D:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2007-08-09 18:00:34 0 d-------- D:\Program Files\Warcraft III
2007-08-08 21:56:49 118784 --a------ D:\WINDOWS\system32\MSSTDFMT.DLL <Not Verified; Microsoft Corporation; MSSTDFMT Object Library>
2007-08-08 21:36:36 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Apple Computer
2007-08-08 21:36:19 204800 --a------ D:\WINDOWS\system32\lsvxdec.dll <Not Verified; Espre Solutions Inc; Espre Video Codec>
2007-08-08 21:36:19 150016 --a------ D:\WINDOWS\system32\ativcr2.dll <Not Verified; ATI Technologies, Inc.; Xpression TV>
2007-08-08 21:36:18 307200 --a------ D:\WINDOWS\system32\icmw_32.dll <Not Verified; Aware Inc.; MotionWavelets by Aware>
2007-08-08 21:36:18 88464 --a------ D:\WINDOWS\system32\DECVW_32.DLL <Not Verified; VDOnet Corp.; Decvw_32.dll>
2007-08-08 21:36:17 76800 --a------ D:\WINDOWS\system32\VDODEC32.dll <Not Verified; VDOnet Corp.; Vdodec32.dll>
2007-08-08 21:36:17 155648 --a------ D:\WINDOWS\system32\avidavicodec.dll <Not Verified; Avid Technology, Inc; Avid AVI Codec Version 2.0d2>
2007-08-08 21:36:17 92672 --a------ D:\WINDOWS\system32\asusasv2.dll
2007-08-08 21:36:17 71680 --a------ D:\WINDOWS\system32\asusasv1.dll
2007-08-08 21:36:15 163840 --a------ D:\WINDOWS\system32\vmnc.dll <Not Verified; VMware, Inc.; VMware Workstation>
2007-08-08 21:36:15 40960 --a------ D:\WINDOWS\system32\frapsvid.dll <Not Verified; Beepa P/L; FRAPS>
2007-08-08 21:36:15 135168 --a------ D:\WINDOWS\system32\clrviddd.dll <Not Verified; Iterated Systems, Inc.; ClearVideo>
2007-08-08 21:36:15 312832 --a------ D:\WINDOWS\system32\CLRVIDDC.DLL <Not Verified; eMajix.com, Inc.; ClearVideo Decoder DLL>
2007-08-08 21:36:15 24064 --a------ D:\WINDOWS\system32\aasc32.dll <Not Verified; Autodesk, Inc.; Autodesk Animation Studio>
2007-08-08 21:36:11 630784 --a------ D:\WINDOWS\system32\vp7vfw.dll <Not Verified; On2.com; On2_VP70>
2007-08-08 21:36:10 438272 --a------ D:\WINDOWS\system32\vp6vfw.dll <Not Verified; On2.com; On2_VP6>
2007-08-08 21:36:05 102400 --a------ D:\WINDOWS\system32\tsccvid.dll <Not Verified; TechSmith Corporation; TechSmith Screen Capture Codec>
2007-08-08 21:16:05 0 d-------- D:\WINDOWS\BurnQuick
2007-08-08 21:15:48 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Triton Interactive
2007-08-08 20:11:28 75264 --a------ D:\WINDOWS\system32\MACDec.dll <Not Verified; Matthew T. Ashland; Monkey's Audio>
2007-08-08 18:57:27 262144 --a------ D:\WINDOWS\system32\TomsMoComp_ff.dll
2007-08-08 18:57:27 395776 --a------ D:\WINDOWS\system32\libmplayer.dll
2007-08-08 18:57:27 112640 --a------ D:\WINDOWS\system32\libmpeg2_ff.dll
2007-08-08 18:57:26 2255360 --a------ D:\WINDOWS\system32\libavcodec.dll
2007-08-08 18:57:11 0 d-------- D:\Program Files\Common Files\Download Manager
2007-08-08 18:11:39 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Ahead
2007-08-08 18:11:05 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Ahead
2007-08-08 17:28:01 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Real
2007-08-08 16:58:27 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\ppstream
2007-08-08 16:57:57 0 d-------- D:\Program Files\FlashGet
2007-08-08 16:57:38 480 --a------ D:\WINDOWS\system32\keys.dat
2007-08-08 16:57:31 0 d-------- D:\Program Files\Common Files\Real
2007-08-08 16:57:18 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Poco
2007-08-08 16:57:10 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\StromII
2007-08-08 16:56:34 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Storm
2007-08-08 16:56:31 0 d-------- D:\Program Files\StormII
2007-08-08 15:08:26 164 --a------ D:\install.dat
2007-08-08 15:08:01 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Media Player Classic
2007-08-08 15:07:49 163840 --a------ D:\WINDOWS\system32\unrar.dll
2007-08-08 15:07:46 217088 --a------ D:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2007-08-08 15:07:45 180224 --a------ D:\WINDOWS\system32\xvidvfw.dll
2007-08-08 15:07:45 761856 --a------ D:\WINDOWS\system32\xvidcore.dll
2007-08-08 15:07:44 3596288 --a------ D:\WINDOWS\system32\qt-dx331.dll
2007-08-08 15:07:44 73728 --a------ D:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2007-08-08 15:07:44 740442 --a------ D:\WINDOWS\system32\divx.dll <Not Verified; DivX, Inc.; DivX®>
2007-08-08 15:07:43 5120 --a------ D:\WINDOWS\system32\ff_vfw.dll
2007-08-08 15:07:40 0 d-------- D:\Program Files\K-Lite Codec Pack
2007-08-08 14:59:00 0 d-------- D:\WINDOWS\system32\URTTemp
2007-08-08 14:10:16 0 d-------- D:\WINDOWS\system32\VIRepair
2007-08-08 13:46:53 53248 --a----c- D:\WINDOWS\system32\ImageOle.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2007-08-08 13:46:38 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\InstallShield
2007-08-08 13:38:43 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2007-08-08 12:55:51 58 --a------ D:\WINDOWS\system32\wldini.dll
2007-08-08 12:55:48 58 --a------ D:\WINDOWS\system32\jzfini.dll
2007-08-08 12:55:46 58 --a------ D:\WINDOWS\system32\wgdini.dll
2007-08-08 12:55:45 45 --a------ D:\WINDOWS\system32\qjeini.dll
2007-08-08 12:55:42 104 --a------ D:\WINDOWS\system32\zxgini.dll
2007-08-08 12:55:30 58 --a------ D:\WINDOWS\system32\tlmini.dll
2007-08-08 12:55:29 57 --a------ D:\WINDOWS\system32\wdbini.dll
2007-08-08 12:55:27 55 --a------ D:\WINDOWS\system32\dhbini.dll
2007-08-08 12:55:22 130 --a------ D:\WINDOWS\system32\mydini.dll
2007-08-08 10:25:08 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Smart PC Solutions
2007-08-08 10:25:07 0 d-a------ D:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2007-08-07 18:23:57 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Hamachi
2007-08-06 15:28:38 0 d-------- D:\Program Files\IObit
2007-08-05 13:58:00 679936 --a------ D:\WINDOWS\system32\D3DX81ab.dll <Not Verified; Generated for JEDI. www.delphi-jedi.org; D3DX81>
2007-08-05 02:01:44 49152 --a------ D:\WINDOWS\system32\ChCfg.exe
2007-08-05 02:01:10 315392 --a------ D:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Update driver Tool>
2007-08-05 01:37:42 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\NJStar
2007-08-05 01:37:32 0 d-------- D:\Program Files\NJStar Communicator
2007-08-05 00:25:30 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Google
2007-08-05 00:24:17 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Talkback
2007-08-05 00:23:55 0 --a------ D:\WINDOWS\nsreg.dat
2007-08-05 00:23:52 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Mozilla
2007-08-05 00:01:41 187392 --a------ D:\WINDOWS\system32\JPGUtils.dll
2007-08-04 23:20:26 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\WINDOWS
2007-08-04 20:04:42 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Protexis
2007-08-04 20:04:40 80 -r-hs---- D:\WINDOWS\system32\F6C29CB1CA.dll
2007-08-04 17:03:47 19456 --a------ D:\WINDOWS\system32\drivers\TdiPbk.SYS <Not Verified; Vnn Networks Inc; TDIPBK Firewall>
2007-08-04 17:03:46 4608 --a------ D:\WINDOWS\system32\drivers\SOCKHOOK.SYS <Not Verified; ; SOCKHOOK Driver>
2007-08-04 17:01:55 452608 --a------ D:\WINDOWS\notepad.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 17:01:39 0 d--h----- D:\Documents and Settings\Default User.WINDOWS\Templates
2007-08-04 17:01:39 0 dr------- D:\Documents and Settings\Default User.WINDOWS\Start Menu
2007-08-04 17:01:39 0 dr-h----- D:\Documents and Settings\Default User.WINDOWS\SendTo
2007-08-04 17:01:39 0 d--h----- D:\Documents and Settings\Default User.WINDOWS\Recent
2007-08-04 17:01:39 0 d--h----- D:\Documents and Settings\Default User.WINDOWS\PrintHood
2007-08-04 17:01:39 0 d--h----- D:\Documents and Settings\Default User.WINDOWS\NetHood
2007-08-04 17:01:39 0 d-------- D:\Documents and Settings\Default User.WINDOWS\My Documents
2007-08-04 17:01:39 0 dr-h----- D:\Documents and Settings\Default User.WINDOWS\Local Settings
2007-08-04 17:01:39 0 d-------- D:\Documents and Settings\Default User.WINDOWS\Favorites
2007-08-04 17:01:39 0 d-------- D:\Documents and Settings\Default User.WINDOWS\Desktop
2007-08-04 17:01:39 0 d---s---- D:\Documents and Settings\Default User.WINDOWS\Cookies
2007-08-04 17:01:39 0 d--h----- D:\Documents and Settings\All Users.WINDOWS\Templates
2007-08-04 17:01:39 0 dr------- D:\Documents and Settings\All Users.WINDOWS\Start Menu
2007-08-04 17:01:39 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Favorites
2007-08-04 17:01:39 0 dr------- D:\Documents and Settings\All Users.WINDOWS\Documents
2007-08-04 17:01:39 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Desktop
2007-08-04 16:59:39 0 dr-h----- D:\Documents and Settings\Default User.WINDOWS\Application Data
2007-08-04 16:59:39 0 d---s---- D:\Documents and Settings\Default User.WINDOWS\Application Data\Microsoft
2007-08-04 16:59:39 0 dr-h----- D:\Documents and Settings\All Users.WINDOWS\Application Data
2007-08-04 16:59:39 0 d---s---- D:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2007-08-04 16:06:12 0 d-------- D:\Program Files\MTV Networks
2007-08-04 16:05:24 0 d-------- D:\WINDOWS\Downloaded Installations
2007-08-04 14:22:13 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Macromedia
2007-08-04 14:13:39 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Uniblue
2007-08-04 13:37:43 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\vlc
2007-08-04 13:17:47 2560 --a------ D:\WINDOWS\_MSRSTRT.EXE
2007-08-04 12:58:47 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\WinRAR
2007-08-04 12:31:06 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
2007-08-04 12:06:44 0 d-------- D:\Program Files\Common Files\Stardock
2007-08-04 11:15:19 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Contacts
2007-08-04 11:03:04 0 d---s---- D:\Documents and Settings\weng.WENG-126DB86A18\UserData
2007-08-04 10:33:00 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\ViStart
2007-08-04 10:14:19 111104 --a------ D:\WINDOWS\system32\uharc.exe
2007-08-04 10:14:19 19968 --a------ D:\WINDOWS\system32\reico.exe <Not Verified; Dead Knight; >
2007-08-04 10:14:19 8636 --a------ D:\WINDOWS\system32\modifype.exe
2007-08-04 09:41:50 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Styler
2007-08-04 09:37:58 0 d-------- D:\Documents and Settings\All Users.WINDOWS\Application Data\thunder_vod_cache
2007-08-04 09:37:57 1988 --a------ D:\WINDOWS\system32\cid_store.dat
2007-08-04 09:33:33 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\Identities
2007-08-04 09:33:12 0 d--h----- D:\Documents and Settings\weng.WENG-126DB86A18\Templates
2007-08-04 09:33:12 0 dr------- D:\Documents and Settings\weng.WENG-126DB86A18\Start Menu
2007-08-04 09:33:12 0 dr-h----- D:\Documents and Settings\weng.WENG-126DB86A18\SendTo
2007-08-04 09:33:12 0 d--h----- D:\Documents and Settings\weng.WENG-126DB86A18\PrintHood
2007-08-04 09:33:12 0 d--h----- D:\Documents and Settings\weng.WENG-126DB86A18\NetHood
2007-08-04 09:33:12 0 dr------- D:\Documents and Settings\weng.WENG-126DB86A18\My Documents
2007-08-04 09:33:12 0 d--h----- D:\Documents and Settings\weng.WENG-126DB86A18\Local Settings
2007-08-04 09:33:12 0 d---s---- D:\Documents and Settings\weng.WENG-126DB86A18\Favorites
2007-08-04 09:33:12 0 d-------- D:\Documents and Settings\weng.WENG-126DB86A18\Desktop
2007-08-04 09:33:12 0 d---s---- D:\Documents and Settings\weng.WENG-126DB86A18\Cookies
2007-08-04 09:33:12 0 dr-h----- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data
2007-08-04 09:32:42 0 d-------- D:\WINDOWS\system32\SoftwareDistribution
2007-08-04 09:30:54 0 d---s---- D:\Documents and Settings\LocalService.NT AUTHORITY\Cookies
2007-08-04 09:30:54 0 d-------- D:\Documents and Settings\LocalService.NT AUTHORITY\Application Data
2007-08-04 09:30:54 0 d---s---- D:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Microsoft
2007-08-04 09:30:53 0 d--h----- D:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings
2007-08-04 09:30:41 229376 --a------ D:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT
2007-08-04 09:30:41 0 d--h----- D:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings
2007-08-04 09:30:41 0 d---s---- D:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies
2007-08-04 09:30:41 0 d-------- D:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data
2007-08-04 09:30:41 0 d---s---- D:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Microsoft
2007-08-04 09:24:49 262144 --ah----- D:\Documents and Settings\Default User.WINDOWS\NTUSER.DAT
2007-08-04 09:22:25 0 d--hs---- D:\Documents and Settings\All Users.WINDOWS\DRM
2007-08-04 09:19:39 21640 --a------ D:\WINDOWS\system32\emptyregdb.dat
2007-08-04 09:18:49 0 d-------- D:\Program Files\Messenger
2007-08-04 09:18:48 1232384 --a------ D:\WINDOWS\system32\write.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:43 152064 --a------ D:\WINDOWS\system32\sndvol32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:36 504832 --a------ D:\WINDOWS\system32\WINmine.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:36 441856 --a------ D:\WINDOWS\system32\sol.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:36 465408 --a------ D:\WINDOWS\system32\charmap.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:36 117760 --a------ D:\WINDOWS\system32\calc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:35 512512 --a------ D:\WINDOWS\system32\mshearts.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:35 440320 --a------ D:\WINDOWS\system32\freecell.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:22 260096 --a------ D:\WINDOWS\system32\sndrec32.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:22 726016 --a------ D:\WINDOWS\system32\mspaint.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:21 924672 --a------ D:\WINDOWS\system32\spider.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 09:18:20 215552 --a------ D:\WINDOWS\system32\termsrv.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-03 19:37:28 22016 --a------ D:\WINDOWS\system32\drivers\ultradfg.sys <Not Verified; DASoft Development Team; UltraDefrag>
2007-08-03 19:20:48 0 dr-h----- D:\Documents and Settings\weng\Recent
2007-08-03 19:18:10 0 d-------- D:\Documents and Settings\weng\Application Data\WinPatrol
2007-08-03 19:02:17 0 d-------- D:\Program Files\Lavasoft
2007-08-03 19:02:16 0 d-------- D:\Documents and Settings\All Users\Application Data\Lavasoft
2007-08-03 18:37:42 0 d-------- D:\WINDOWS\pss
2007-08-03 10:23:46 0 d-------- D:\Program Files\Ocean Technology
2007-08-01 22:27:18 0 d-------- D:\Program Files\Common Files\DirectX
-- Find3M Report ---------------------------------------------------------------
2007-08-30 19:23:23 0 d-------- D:\Program Files\Common Files
2007-08-30 17:06:58 0 d-------- D:\Program Files\SUPERAntiSpyware
2007-08-30 17:05:56 0 d-------- D:\Program Files\MSN Messenger
2007-08-30 17:04:42 0 d-------- D:\Program Files\JkDefragGUI
2007-08-29 22:01:11 0 d--h----- D:\Program Files\InstallShield Installation Information
2007-08-29 08:17:27 0 d-------- D:\Program Files\Yahoo!
2007-08-28 10:57:43 0 d-------- D:\Program Files\Iesnap
2007-08-26 18:37:10 0 d-------- D:\Program Files\BitComet
2007-08-09 14:09:46 0 d-------- D:\Program Files\Windows Media Connect 2
2007-08-09 14:09:42 0 d-------- D:\Program Files\Sogou PXP
2007-08-09 14:09:42 0 d-------- D:\Program Files\Realtek AC97
2007-08-09 14:09:33 0 d-------- D:\Program Files\Microsoft PowerToys
2007-08-09 14:09:27 0 d-------- D:\Program Files\Google
2007-08-05 00:09:43 9726464 --a------ D:\WINDOWS\system32\logonuiX.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-08-04 17:01:39 62 --ahs---- D:\Documents and Settings\weng.WENG-126DB86A18\Application Data\desktop.ini
2007-08-03 19:37:16 0 d-------- D:\Program Files\Common Files\InstallShield
2007-07-23 09:27:24 0 d-------- D:\Program Files\SnailWeb
2007-07-12 14:22:32 0 d-------- D:\Program Files\Common Files\Adobe
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="D:\WINDOWS\system32\ctfmon.exe" [01/09/2004 08:00]
"msnmsgr"="D:\Program Files\MSN Messenger\msnmsgr.exe" [19/01/2007 12:54]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
"NoResolveSearch"=1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"LinkResolveIgnoreLinkInfo"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
D:\WINDOW~1\wbsrv.dll 22/12/2005 10:21 176128 D:\WINDOW~1\WbSrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f6895fb8-4356-11dc-8135-000d8838a80a}]
Auto\command- F:\PegeFile.pif
AutoRun\command- D:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL PegeFile.pif
*Newly Created Service* - GMER
*Newly Created Service* - ULTRADFG
-- End of Deckard's System Scanner: finished at 2007-08-31 12:40:00 ------------