Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Cannot Remove Malware Popups From Laptop


  • Please log in to reply

#1
whizzer38

whizzer38

    Member

  • Member
  • PipPip
  • 14 posts
Hello Experts,
My laptop has been plagued by numerous malware/spyware popups and I can not get rid of them. URLs include, amaena.com, systemdoctor.com, and drivecleaner.com I've ran my Norton, spybot search and destroy, and tried VundoFix and they keep coming back. I've also tried a system restore point from a earlier date and it comes back with restore incomplete. Here is my HJT log: Thanks in advance.

Logfile of HijackThis v1.99.1
Scan saved at 11:52:16 PM, on 11/2/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\PROG#OLC\WINZIP\winzip32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\unzipped\hijackthis[1]\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../US/install.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma..../bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec....rl/SymAData.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Fix-It Task Manager - Unknown owner - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe (file missing)
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • 0

Advertisements


#2
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Welcome whizzer38! :whistling:

I will be helping you under the guidance of one of our expert coaches.

Please give me a little time to get back to you with instructions.

Thanks
Jamie
  • 0

#3
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey whizzer38

Submit Samples:

You have a file/s of interest to us. It would help the detection rates of the tools we use by getting hold of samples of these infections.

Please download File Submitter by Grinler. I suggest you save the file where it is easy to locate i.e. the root of the drive (C:\submitter.exe).

Create a right-click option:

1. Navigate to this folder in Windows Explorer: C:\Documents and Settings\username\SendTo
2. Right-click inside the folder and select New > Shortcut.
3. Enter the location of the item: C:\submitter.exe (or wherever you saved it)
4. Name the shortcut: Submit Malware
5. The select Finish.

Configure the tool:

1. Navigate to the tool in Windows Explorer: C:\submitter.exe (or wherever you saved it)
2. Double-click the file to open it.
3. The put a check in these boxes:

VirusTotal
Advanced
BleepingComputer.com


4. Then click Save and OK the confirmation window.
5. Then click Exit to close the tool.

Upload Samples:

1. Locate this file/s in Windows Explorer:

C:\PROG#OLC\WINZIP\winzip32.exe

2. For each file you need to right-click and select Send To > Submit Malware (or whatever you named the shortcut)
3. Copy/paste the results of the scan in your next reply.

Please download ATF Cleaner by Atribune.
This program is for XP and Windows 2000 onlyDouble-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
If you use Firefox browserClick Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browserClick Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

Kaspersky Online Scanner
Go to http://www.kaspersky.com/virusscanner

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make sure that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post with another HJT log.

  • 0

#4
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks for your help. I am currently scanning My Computer with Kaspersky and will paste the results of the scan and a new HJT log once it finishes. I downloaded ATF Cleaner and ran the program. I submitted the sample and this is the results of the file you wanted to see:

Antivirus Version Update Result
AntiVir 7.2.0.37 11.03.2006 no virus found
Authentium 4.93.8 11.04.2006 no virus found
Avast 4.7.892.0 11.03.2006 no virus found
AVG 386 11.03.2006 no virus found
BitDefender 7.2 11.04.2006 no virus found
CAT-QuickHeal 8.00 11.04.2006 no virus found
ClamAV devel-20060426 11.04.2006 no virus found
DrWeb 4.33 11.03.2006 no virus found
eTrust-InoculateIT 23.73.45 11.03.2006 no virus found
eTrust-Vet 30.3.3176 11.03.2006 no virus found
Ewido 4.0 11.04.2006 no virus found
Fortinet 2.82.0.0 11.04.2006 no virus found
F-Prot 3.16f 11.04.2006 no virus found
F-Prot4 4.2.1.29 11.04.2006 no virus found
Ikarus 0.2.65.0 11.03.2006 no virus found
Kaspersky 4.0.2.24 11.04.2006 no virus found
McAfee 4888 11.03.2006 no virus found
Microsoft 1.1609 11.04.2006 no virus found
NOD32v2 1.1853 11.03.2006 no virus found
Norman 5.80.02 11.03.2006 no virus found
Panda 9.0.0.4 11.04.2006 no virus found
Sophos 4.10.0 10.26.2006 no virus found
TheHacker 6.0.1.112 11.03.2006 no virus found
UNA 1.83 11.03.2006 no virus found
VBA32 3.11.1 11.03.2006 no virus found
VirusBuster 4.3.15:9 11.04.2006 no virus found
  • 0

#5
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks, here is my online scanner results and a new HJT log:

-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, November 04, 2006 3:05:30 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.83.0
Kaspersky Anti-Virus database last update: 4/11/2006
Kaspersky Anti-Virus database records: 238293
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 45669
Number of viruses found: 4
Number of infected objects: 16 / 0
Number of suspicious objects: 0
Duration of the scan process: 00:49:54

Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Confid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Content.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Privacy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\Restrict.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\WebHist.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPAppActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\HPPHomePageActivity.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\LiveUpdate\2006-11-04_Log.ALUSchedulerSvc.LiveUpdate Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\052538CD.htm Infected: Trojan-Downloader.HTML.Agent.aq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\28C25DAB.htm Infected: Trojan-Downloader.HTML.Agent.aq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\35AC7E6F.htm Infected: Trojan-Downloader.JS.Psyme.cb skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\41A307FB.htm Infected: Trojan-Downloader.HTML.Agent.aq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\52E00EE3.htm Infected: Trojan-Downloader.HTML.Agent.aq skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\57B10697.class Infected: Exploit.Java.ByteVerify skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\5D8D6825.htm Infected: Trojan-Downloader.HTML.Agent.aq skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Application Data\Symantec\PendingAlertsQueue.log Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Local Settings\History\History.IE5\MSHist012006110420061105\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Roberts\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Timothy Roberts\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Timothy Roberts\ntuser.dat.LOG Object is locked skipped
C:\gobackio.bin Object is locked skipped
C:\Program Files\Apoint\Apoint.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\Common Files\Real\Update_OB\realsched.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\Common Files\Symantec Shared\AntiSpam\Log\Spam.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsys.dll Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBConfig.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDebug.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBDetect.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBNotify.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBRefr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetCfg2.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetDev.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetLoc.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSetUsr.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMNot.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMReg.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBSMRSt.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStHash.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBStMSI.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\BBValid.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPPolicy.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStart.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SPBBC\LOGS\SPStop.log Object is locked skipped
C:\Program Files\Dell\AccessDirect\dadapp.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVApp.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVError.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\AVVirus.log Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0085NAV~.TMP Object is locked skipped
C:\Program Files\Norton Internet Security\Norton AntiVirus\Savrt\0243NAV~.TMP Object is locked skipped
C:\Program Files\QuickTime\qttask.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\REGSHAVE\REGSHAVE.EXE Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\RECYCLER\NPROTECT\NPROTECT.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP314\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{32A81F82-47E9-41C8-B5C7-3B350953D1AF}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\dla\tfswctrl.exe Infected: Trojan-Downloader.Win32.Agent.ayy skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\Temp\Perflib_Perfdata_d44.dat Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped

Scan process completed.


Logfile of HijackThis v1.99.1
Scan saved at 3:09:26 PM, on 11/4/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apoint\Apoint.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\unzipped\hijackthis_199[1]\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\dadapp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2\bin\npjpi142.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../US/install.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec....rl/SymAData.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Fix-It Task Manager - Unknown owner - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe (file missing)
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • 0

#6
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey whizzer38

Downloader.Agent.awf:

Please download FindAWF.exe

Run the tool and post the contents of the report in your next reply.
  • 0

#7
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks Jamie.
Here is the report:


Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~



25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



26450 byte files found
~~~~~~~~~~~~~



26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\APOINT\BAK

06/10/2003 10:07 PM 147,456 Apoint.exe
1 File(s) 147,456 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/01/2006 02:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 09:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK

11/07/2002 08:00 PM 294,912 atiptaxx.exe
1 File(s) 294,912 bytes

Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\DELL\ACCESS~1\BAK

03/07/2003 11:36 AM 209,800 dadapp.exe
1 File(s) 209,800 bytes

Directory of C:\PROGRA~1\SYNAPT~1\SYNTP\BAK

05/02/2003 04:15 PM 610,304 SynTPEnh.exe
05/02/2003 04:21 PM 110,592 SynTPLpr.exe
2 File(s) 720,896 bytes

Directory of C:\WINDOWS\SYSTEM32\DLA\BAK

08/13/2004 12:05 AM 122,939 tfswctrl.exe
1 File(s) 122,939 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

08/20/2006 05:30 PM 180,269 realsched.exe
1 File(s) 180,269 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

147456 Jun 10 2003 "C:\DELL\drivers\R64287\Apoint.exe"
147456 Jun 10 2003 "C:\Program Files\Apoint\bak\Apoint.exe"
147456 Jun 10 2003 "C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Apoint.exe"
28672 Oct 15 2005 "C:\WINDOWS\system32\qttask.exe"
282624 Sep 1 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
294912 Nov 7 2002 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
209800 Mar 7 2003 "C:\Program Files\Dell\AccessDirect\bak\dadapp.exe"
610304 May 2 2003 "C:\DELL\drivers\R61162\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe"
110592 May 2 2003 "C:\DELL\drivers\R61162\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPLpr.exe"
122939 Aug 13 2004 "C:\WINDOWS\system32\dla\bak\tfswctrl.exe"
122939 Aug 13 2004 "C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\tfswctrl.exe"
180269 Aug 20 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"


end of report
  • 0

#8
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey whizzer38

Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

Downloader.Agent.awf:

Please launch Notepad (Start > Run, type in: notepad)
Copy/paste all the blue text below to it:

@echo off

dir /s "C:\Program Files\Apoint\BAK" > c:\bakfile.txt
dir /s "C:\Program Files\Apoint" > c:\bakfile.txt

dir /s "C:\Program Files\ATI Technologies\ATI Control Panel\BAK" > c:\bakfile.txt
dir /s "C:\Program Files\ATI Technologies\ATI Control Panel" > c:\bakfile.txt

dir /s "C:\Program Files\Common Files\Real\Update_OB\BAK" >> c:\bakfile.txt
dir /s "C:\Program Files\Common Files\Real\Update_OB" >> c:\bakfile.txt

dir /s "C:\Program Files\Dell\AccessDirect\BAK" >> c:\bakfile.txt
dir /s "C:\Program Files\Dell\AccessDirect" >> c:\bakfile.txt

dir /s "C:\Program Files\QuickTime\BAK" >> c:\bakfile.txt
dir /s "C:\Program Files\QuickTime" >> c:\bakfile.txt

dir /s "C:\Program Files\REGSHAVE\BAK" >> c:\bakfile.txt
dir /s "C:\Program Files\REGSHAVE" >> c:\bakfile.txt

dir /s "C:\Program Files\Synaptics\SynTP\BAK" >> c:\bakfile.txt
dir /s "C:\Program Files\Synaptics\SynTP" >> c:\bakfile.txt

dir /s "C:\WINDOWS\system32\dla\BAK" >> c:\bakfile.txt
dir /s "C:\WINDOWS\system32\dla" >> c:\bakfile.txt

start notepad c:\bakfile.txt
echo Once you have pasted the contents of notepad into your thread at GeeksToGo, please
pause
delete c:\bakfiles.txt

In Notepad, go to File (upper menu bar), and select: Save as
In the Save as prompt:
Save in: Desktop
File Name: bakfile.bat
Save as Type: All files
Click: Save
Exit out of Notepad.

Next, on the Desktop, double click on bakfile.bat
>>Please provide the text created in your reply.<<

====
Also, please run the following:

1. DelDomains
http://www.mvps.org/.../DelDomains.inf
To delete all entries in the Restricted & Trusted Zone list, right click DelDomains.inf
Select: Install

2. ResetProtocolDefaults
http://www.mvps.org/...colDefaults.reg
Right click the link, save target as or save link as, and save to the Desktop.

Locate ResetProtocolDefaults.reg on the Desktop
Right-click and select: Merge
OK the prompt

Please can you then make sure Ewido is updated, run a full system scan and post back the results. We need to know that this method has been successful in killing the infector.

Please can you then post a fresh Hijackthis log.

  • 0

#9
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks. Results of batch file:
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\ATI Technologies\ATI Control Panel

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
11/07/2002 08:00 PM 26,106 atfaraxx.hlx
11/07/2002 08:00 PM 22,653 atfchsxx.hlx
11/07/2002 08:00 PM 22,755 atfchtxx.hlx
11/07/2002 08:00 PM 23,199 atfdeuxx.hlx
11/07/2002 08:00 PM 23,658 atfellxx.hlx
11/07/2002 08:00 PM 21,731 atfenuxx.hlp
11/07/2002 08:00 PM 21,731 atfenuxx.hlx
11/07/2002 08:00 PM 22,393 atfespxx.hlx
11/07/2002 08:00 PM 23,118 atffraxx.hlx
11/07/2002 08:00 PM 23,927 atfhebxx.hlx
11/07/2002 08:00 PM 46,242 atfjpnxx.hlx
11/07/2002 08:00 PM 53,704 atfkorxx.hlx
11/07/2002 08:00 PM 23,180 atfptbxx.hlx
11/07/2002 08:00 PM 23,293 atfthaxx.hlx
11/07/2002 08:00 PM 315,469 atiicdxx.dll
11/07/2002 08:00 PM 4,557 atiicdxx.sys
11/07/2002 08:00 PM 7,849 atiicdxx.vxd
11/07/2002 08:00 PM 110,592 Atiiprxx.exe
11/07/2002 08:00 PM 221,262 atipdsxx.dll
11/07/2002 08:00 PM 61,440 atiphexx.exe
11/07/2002 08:00 PM 94,208 atippaxx.dll
11/07/2002 08:00 PM 98,304 atiprbxx.exe
11/07/2002 08:00 PM 1,286,144 atipuixx.dll
11/07/2002 08:00 PM 2,365 atmaraxx.cnt
11/07/2002 08:00 PM 145,685 atmaraxx.hlx
11/07/2002 08:00 PM 2,168 atmchsxx.cnt
11/07/2002 08:00 PM 156,036 atmchsxx.hlx
11/07/2002 08:00 PM 2,202 atmchtxx.cnt
11/07/2002 08:00 PM 127,533 atmchtxx.hlx
11/07/2002 08:00 PM 3,044 atmdeuxx.cnt
11/07/2002 08:00 PM 128,163 atmdeuxx.hlx
11/07/2002 08:00 PM 2,969 atmellxx.cnt
11/07/2002 08:00 PM 127,996 atmellxx.hlx
11/07/2002 08:00 PM 2,796 atmenuxx.cnt
11/07/2002 08:00 PM 119,115 atmenuxx.hlp
11/07/2002 08:00 PM 119,115 atmenuxx.hlx
11/07/2002 08:00 PM 3,096 atmespxx.cnt
11/07/2002 08:00 PM 122,919 atmespxx.hlx
11/07/2002 08:00 PM 3,146 atmfraxx.cnt
11/07/2002 08:00 PM 126,884 atmfraxx.hlx
11/07/2002 08:00 PM 2,571 atmhebxx.cnt
11/07/2002 08:00 PM 132,031 atmhebxx.hlx
11/07/2002 08:00 PM 2,611 atmjpnxx.cnt
11/07/2002 08:00 PM 380,864 atmjpnxx.hlx
11/07/2002 08:00 PM 2,810 atmkorxx.cnt
11/07/2002 08:00 PM 397,457 atmkorxx.hlx
11/07/2002 08:00 PM 2,973 atmptbxx.cnt
11/07/2002 08:00 PM 123,422 atmptbxx.hlx
11/07/2002 08:00 PM 2,566 atmthaxx.cnt
11/07/2002 08:00 PM 305,740 atmthaxx.hlx
11/07/2002 08:00 PM 53,248 atricdxx.dft
11/07/2002 08:00 PM 53,248 atricdxx.enu
11/07/2002 08:00 PM 20,480 atriprxx.ara
11/07/2002 08:00 PM 16,384 atriprxx.chs
11/07/2002 08:00 PM 16,384 atriprxx.cht
11/07/2002 08:00 PM 20,480 atriprxx.deu
11/07/2002 08:00 PM 20,480 atriprxx.dft
11/07/2002 08:00 PM 20,480 atriprxx.ell
11/07/2002 08:00 PM 20,480 atriprxx.enu
11/07/2002 08:00 PM 20,480 atriprxx.esp
11/07/2002 08:00 PM 20,480 atriprxx.fra
11/07/2002 08:00 PM 20,480 atriprxx.heb
11/07/2002 08:00 PM 16,384 atriprxx.jpn
11/07/2002 08:00 PM 16,384 atriprxx.kor
11/07/2002 08:00 PM 20,480 atriprxx.ptb
11/07/2002 08:00 PM 20,480 atriprxx.tha
11/07/2002 08:00 PM 102,400 atrpuixx.ara
11/07/2002 08:00 PM 73,728 atrpuixx.chs
11/07/2002 08:00 PM 77,824 atrpuixx.cht
11/07/2002 08:00 PM 106,496 atrpuixx.deu
11/07/2002 08:00 PM 110,592 atrpuixx.ell
11/07/2002 08:00 PM 102,400 atrpuixx.enu
11/07/2002 08:00 PM 110,592 atrpuixx.esp
11/07/2002 08:00 PM 110,592 atrpuixx.fra
11/07/2002 08:00 PM 98,304 atrpuixx.heb
11/07/2002 08:00 PM 81,920 atrpuixx.jpn
11/07/2002 08:00 PM 81,920 atrpuixx.kor
11/07/2002 08:00 PM 106,496 atrpuixx.ptb
11/07/2002 08:00 PM 102,400 atrpuixx.tha
11/07/2002 08:00 PM 52,541 attaraxx.hlx
11/07/2002 08:00 PM 45,291 attchsxx.hlx
11/07/2002 08:00 PM 44,350 attchtxx.hlx
11/07/2002 08:00 PM 44,382 attdeuxx.hlx
11/07/2002 08:00 PM 45,293 attellxx.hlx
11/07/2002 08:00 PM 40,099 attenuxx.hlp
11/07/2002 08:00 PM 40,099 attenuxx.hlx
11/07/2002 08:00 PM 43,076 attespxx.hlx
11/07/2002 08:00 PM 44,940 attfraxx.hlx
11/07/2002 08:00 PM 46,906 atthebxx.hlx
11/07/2002 08:00 PM 121,240 attjpnxx.hlx
11/07/2002 08:00 PM 141,719 attkorxx.hlx
11/07/2002 08:00 PM 45,518 attptbxx.hlx
11/07/2002 08:00 PM 41,238 attthaxx.hlx
10/30/2006 10:12 PM <DIR> bak
10/10/2005 04:44 PM 1,722 SmartGart.lnk
94 File(s) 7,566,702 bytes

Directory of C:\Program Files\ATI Technologies\ATI Control Panel\bak

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
11/07/2002 08:00 PM 294,912 atiptaxx.exe
1 File(s) 294,912 bytes

Total Files Listed:
95 File(s) 7,861,614 bytes
5 Dir(s) 53,050,478,592 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\Common Files\Real\Update_OB\BAK

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
08/20/2006 05:30 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Total Files Listed:
1 File(s) 180,269 bytes
2 Dir(s) 53,050,486,784 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\Common Files\Real\Update_OB

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
10/30/2006 10:12 PM <DIR> bak
08/20/2006 05:30 PM 385,063 faus3270.dll
08/20/2006 05:30 PM 569,397 nprfxins.dll
08/20/2006 05:30 PM 36,909 pnmi3270.dll
08/20/2006 05:30 PM 184,366 r1puninst.exe
08/20/2006 05:30 PM 69,688 RealOneMessageCenter.exe
08/20/2006 05:31 PM 78,819 RealPlayer-log.txt
08/20/2006 05:30 PM 98,347 rnad3201.dll
08/20/2006 05:30 PM 327,719 rnms3270.dll
08/20/2006 05:30 PM 303,147 rnqu3270.dll
08/20/2006 05:30 PM 167,979 rnup3270.dll
08/20/2006 05:30 PM 53,291 rnxproc.exe
08/20/2006 05:30 PM 294,955 setu3270.dll
08/20/2006 05:30 PM <DIR> UI
08/20/2006 05:30 PM 335,917 upgr3270.dll
08/20/2006 05:30 PM 127,021 upgrdhlp.exe
14 File(s) 3,032,618 bytes

Directory of C:\Program Files\Common Files\Real\Update_OB\bak

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
08/20/2006 05:30 PM 180,269 realsched.exe
1 File(s) 180,269 bytes

Directory of C:\Program Files\Common Files\Real\Update_OB\UI

08/20/2006 05:30 PM <DIR> .
08/20/2006 05:30 PM <DIR> ..
08/20/2006 05:30 PM 32,395 ath.vs
08/20/2006 05:30 PM 7,484 default.png
08/20/2006 05:30 PM 436 default.smi
08/20/2006 05:30 PM <DIR> Images
08/20/2006 05:30 PM <DIR> loc
08/20/2006 05:30 PM 9,101 mirak.vs
08/20/2006 05:30 PM 3,215 msgoff.htm
08/20/2006 05:30 PM 55,012 msgui.vs
08/20/2006 05:30 PM 43,572 rnupgui.vs
7 File(s) 151,215 bytes

Directory of C:\Program Files\Common Files\Real\Update_OB\UI\Images

08/20/2006 05:30 PM <DIR> .
08/20/2006 05:30 PM <DIR> ..
08/20/2006 05:30 PM 741 real_logo_93x44.gif
1 File(s) 741 bytes

Directory of C:\Program Files\Common Files\Real\Update_OB\UI\loc

08/20/2006 05:30 PM <DIR> .
08/20/2006 05:30 PM <DIR> ..
08/20/2006 05:30 PM 1,039 msgdata.js
08/20/2006 05:30 PM 991 msgStyle.css
2 File(s) 2,030 bytes

Total Files Listed:
25 File(s) 3,366,873 bytes
14 Dir(s) 53,050,482,688 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\Dell\AccessDirect\BAK

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
03/07/2003 11:36 AM 209,800 dadapp.exe
1 File(s) 209,800 bytes

Total Files Listed:
1 File(s) 209,800 bytes
2 Dir(s) 53,050,482,688 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\Dell\AccessDirect

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
10/30/2002 04:08 PM 39,316 acus.bmp
10/30/2006 10:12 PM <DIR> bak
11/01/2002 03:47 PM 245,760 Browse.exe
11/01/2002 03:48 PM 279,552 dadcplx.dll
10/08/2002 12:17 PM 23,139 dadhelp.chm
11/01/2002 03:48 PM 61,440 dadkeyb.dll
11/18/2002 09:11 AM 188,416 dadtray.exe
09/18/2000 02:04 PM 35,896 DellPage.bmp
09/18/2000 02:04 PM 35,896 EMail.bmp
09/18/2000 02:04 PM 35,896 eSupport.bmp
09/18/2000 02:04 PM 35,896 H201.bmp
09/18/2000 02:04 PM 35,896 Habana1.bmp
09/18/2000 02:04 PM 156 I-ESupp.bmp
09/18/2000 02:04 PM 1,342 I-Inet.bmp
09/18/2000 02:04 PM 156 I-Next.bmp
09/18/2000 02:04 PM 154 I-P1.bmp
09/18/2000 02:04 PM 154 I-P2.bmp
09/18/2000 02:04 PM 156 I-Play.bmp
09/18/2000 02:04 PM 156 I-Prev.bmp
09/18/2000 02:04 PM 156 I-Stop.bmp
09/18/2000 02:04 PM 35,896 Internet.bmp
09/18/2000 02:04 PM 13,176 LonsDI.bmp
12/04/2001 12:47 PM 39,316 M2P3.bmp
09/18/2000 02:04 PM 35,896 Next.bmp
11/01/2002 03:47 PM 221,184 OnScDisp.exe
09/18/2000 02:04 PM 35,896 Play.bmp
09/18/2000 02:04 PM 35,896 Prev.bmp
10/10/2005 04:27 PM 30,272 Setup.lst
09/18/2000 02:04 PM 13,176 SkipBack.bmp
09/18/2000 02:04 PM 13,176 SkipFor.bmp
09/18/2000 02:04 PM 35,896 Stop.bmp
11/01/2002 03:47 PM 110,592 uninst.dll
31 File(s) 1,639,905 bytes

Directory of C:\Program Files\Dell\AccessDirect\bak

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
03/07/2003 11:36 AM 209,800 dadapp.exe
1 File(s) 209,800 bytes

Total Files Listed:
32 File(s) 1,849,705 bytes
5 Dir(s) 53,050,482,688 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\QuickTime\BAK

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
09/01/2006 02:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Total Files Listed:
1 File(s) 282,624 bytes
2 Dir(s) 53,050,482,688 bytes free
Volume in drive C has no label.
Volume Serial Number is 9CDC-9FB9

Directory of C:\Program Files\QuickTime

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
10/30/2006 10:12 PM <DIR> bak
09/01/2006 03:16 PM 483,328 PictureViewer.exe
10/09/2006 09:51 AM <DIR> PictureViewer.Resources
10/09/2006 03:53 PM <DIR> Plugins
10/09/2006 09:51 AM <DIR> PropertyPanels
10/09/2006 09:51 AM <DIR> QTComponents
09/01/2006 03:46 PM 598,016 QTInfo.exe
09/01/2006 03:46 PM 712,704 QTOControl.dll
09/01/2006 03:46 PM 675,840 QTOLibrary.dll
09/01/2006 04:26 PM 562,760 QTPlugin.ocx
10/09/2006 09:51 AM <DIR> QTSystem
09/01/2006 03:45 PM 303,104 QTUIPanelControl.dll
08/03/2006 02:51 PM 8,161 QuickTime Read Me.htm
09/01/2006 04:26 PM 5,580,360 QuickTimePlayer.exe
10/09/2006 09:51 AM <DIR> QuickTimePlayer.Resources
09/27/2005 11:13 AM 55,622 Sample.mov
09/27/2005 11:13 AM 18,663 Sample.qtif
10 File(s) 8,998,558 bytes

Directory of C:\Program Files\QuickTime\bak

10/30/2006 10:12 PM <DIR> .
10/30/2006 10:12 PM <DIR> ..
09/01/2006 02:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 59,904 PictureViewer.dll
09/01/2006 03:16 PM 25,600 PictureViewer.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
2 File(s) 85,504 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 109,056 PictureViewerLocalized.qtr
2 File(s) 136,192 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:18 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 97,280 PictureViewerLocalized.qtr
2 File(s) 124,416 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 27,136 PictureViewerLocalized.dll
09/01/2006 03:16 PM 56,832 PictureViewerLocalized.qtr
2 File(s) 83,968 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 108,544 PictureViewerLocalized.qtr
2 File(s) 135,680 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 96,768 PictureViewerLocalized.qtr
2 File(s) 123,904 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 105,984 PictureViewerLocalized.qtr
2 File(s) 133,120 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 102,912 PictureViewerLocalized.qtr
2 File(s) 130,048 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 57,344 PictureViewerLocalized.qtr
2 File(s) 84,480 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 56,832 PictureViewerLocalized.qtr
2 File(s) 83,968 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 57,344 PictureViewerLocalized.qtr
2 File(s) 84,480 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 98,816 PictureViewerLocalized.qtr
2 File(s) 125,952 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 105,472 PictureViewerLocalized.qtr
2 File(s) 132,608 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:18 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 93,184 PictureViewerLocalized.qtr
2 File(s) 120,320 bytes

Directory of C:\Program Files\QuickTime\PictureViewer.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 27,136 PictureViewerLocalized.dll
09/01/2006 03:46 PM 89,600 PictureViewerLocalized.qtr
2 File(s) 116,736 bytes

Directory of C:\Program Files\QuickTime\Plugins

10/09/2006 03:53 PM <DIR> .
10/09/2006 03:53 PM <DIR> ..
10/09/2006 03:53 PM 131,072 npqtplugin.dll
10/09/2006 03:53 PM 131,072 npqtplugin2.dll
10/09/2006 03:53 PM 131,072 npqtplugin3.dll
10/09/2006 03:53 PM 131,072 npqtplugin4.dll
10/09/2006 03:53 PM 131,072 npqtplugin5.dll
10/09/2006 03:53 PM 131,072 npqtplugin6.dll
10/09/2006 03:53 PM 131,072 npqtplugin7.dll
10/09/2006 03:53 PM 2,394 nsIQTScriptablePlugin.xpt
10/09/2006 03:53 PM 4,208 QuickTimePlugin.class
9 File(s) 924,106 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/27/2005 11:13 AM 2,282 annoanno.pdef
05/10/2006 12:52 PM 4,101 moovaudi.pdef
05/08/2006 03:33 PM 2,464 moovpres.pdef
09/01/2006 03:16 PM 69,632 PanelHelperBase.qpa
10/09/2006 09:51 AM <DIR> PanelHelperBase.Resources
05/08/2006 03:33 PM 4,164 PropertyPanels.plist
09/01/2006 03:16 PM 167,936 PropPanelHelpers.qpa
10/09/2006 09:51 AM <DIR> PropPanelHelpers.Resources
09/27/2005 11:13 AM 1,468 rsrcrsrc.pdef
09/27/2005 11:13 AM 5,036 trakaudi.pdef
05/08/2006 03:33 PM 1,109 trakhint.pdef
12/21/2005 10:45 AM 3,141 trakothr.pdef
09/27/2005 11:13 AM 4,779 trakstrm.pdef
12/21/2005 10:45 AM 8,583 trakvisl.pdef
12 File(s) 274,695 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 25,600 PanelHelperBase.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
1 File(s) 25,600 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PanelHelperBase.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 PanelHelperBaseLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 26,624 PropPanelHelpers.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
1 File(s) 26,624 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,624 PropPanelHelpersLocalized.qtr
1 File(s) 26,624 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\PropertyPanels\PropPanelHelpers.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 26,112 PropPanelHelpersLocalized.qtr
1 File(s) 26,112 bytes

Directory of C:\Program Files\QuickTime\QTComponents

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/28/2003 02:48 PM 144,896 Monochrome.qtx
10/28/2003 02:50 PM 144,896 Sepia.qtx
2 File(s) 289,792 bytes

Directory of C:\Program Files\QuickTime\QTSystem

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
12/21/2005 10:37 AM 377,040 CFCharacterSetBitmaps.bitmap
12/21/2005 10:37 AM 21,784 CFUniCharPropertyDatabase.data
12/21/2005 10:37 AM 84,868 CFUnicodeData-B.mapping
12/21/2005 10:37 AM 84,868 CFUnicodeData-L.mapping
09/01/2006 03:16 PM 237,568 CoreVideo.qtx
10/09/2006 09:51 AM <DIR> CoreVideo.Resources
09/01/2006 02:52 PM 106,496 ExportController.exe
09/01/2006 03:16 PM 37,376 ExportControllerPS.dll
03/23/2000 09:54 AM 747,008 Indeo4.qtx
12/06/2000 04:41 PM 120,320 Ir41_qc.dll
12/06/2000 04:41 PM 338,432 Ir41_qcx.dll
09/01/2006 03:46 PM 188,416 QTJava.dll
06/12/2006 08:57 AM 1,180,476 QTJava.zip
09/01/2006 03:46 PM 458,752 QTJavaNative.dll
09/01/2006 02:11 PM 307,200 QTMLClient.dll
09/01/2006 03:45 PM 1,085,440 QuickTime.cpl
09/01/2006 04:18 PM 13,263,360 QuickTime.qts
10/09/2006 09:51 AM <DIR> QuickTime.Resources
09/01/2006 03:16 PM 331,776 QuickTime3GPP.qtx
10/09/2006 09:51 AM <DIR> QuickTime3GPP.Resources
09/01/2006 03:16 PM 462,848 QuickTime3GPPAuthoring.qtx
10/09/2006 09:51 AM <DIR> QuickTime3GPPAuthoring.Resources
09/01/2006 03:16 PM 1,495,040 QuickTimeAudioSupport.qtx
10/09/2006 09:51 AM <DIR> QuickTimeAudioSupport.Resources
09/01/2006 03:16 PM 1,916,928 QuickTimeAuthoring.qtx
10/09/2006 09:51 AM <DIR> QuickTimeAuthoring.Resources
09/01/2006 03:16 PM 315,392 QuickTimeCapture.qtx
10/09/2006 09:51 AM <DIR> QuickTimeCapture.Resources
09/01/2006 04:26 PM 99,912 QuickTimeCheck.ocx
09/01/2006 03:16 PM 548,864 QuickTimeEffects.qtx
10/09/2006 09:51 AM <DIR> QuickTimeEffects.Resources
09/01/2006 03:16 PM 479,232 QuickTimeEssentials.qtx
10/09/2006 09:51 AM <DIR> QuickTimeEssentials.Resources
09/01/2006 03:16 PM 2,428,928 QuickTimeH264.qtx
10/09/2006 09:51 AM <DIR> QuickTimeH264.Resources
09/01/2006 03:16 PM 942,080 QuickTimeImage.qtx
10/09/2006 09:51 AM <DIR> QuickTimeImage.Resources
09/01/2006 03:16 PM 888,832 QuickTimeInternetExtras.qtx
10/09/2006 09:51 AM <DIR> QuickTimeInternetExtras.Resources
09/01/2006 03:16 PM 4,608 QuickTimeJavaExtras.qtx
09/01/2006 03:16 PM 434,176 QuickTimeMPEG.qtx
10/09/2006 09:51 AM <DIR> QuickTimeMPEG.Resources
09/01/2006 03:16 PM 307,200 QuickTimeMPEG4.qtx
10/09/2006 09:51 AM <DIR> QuickTimeMPEG4.Resources
09/01/2006 03:16 PM 528,384 QuickTimeMPEG4Authoring.qtx
10/09/2006 09:51 AM <DIR> QuickTimeMPEG4Authoring.Resources
09/01/2006 03:16 PM 561,152 QuickTimeMusic.qtx
10/09/2006 09:51 AM <DIR> QuickTimeMusic.Resources
09/01/2006 03:16 PM 2,000,384 QuickTimeMusicalInstruments.qtx
09/01/2006 03:16 PM 200,704 QuickTimeQD3D.qtx
10/09/2006 09:51 AM <DIR> QuickTimeQD3D.Resources
09/01/2006 03:16 PM 827,392 QuickTimeStreaming.qtx
10/09/2006 09:51 AM <DIR> QuickTimeStreaming.Resources
09/01/2006 03:16 PM 335,872 QuickTimeStreamingAuthoring.qtx
10/09/2006 09:51 AM <DIR> QuickTimeStreamingAuthoring.Resources
09/01/2006 03:16 PM 131,072 QuickTimeStreamingExtras.qtx
10/09/2006 09:51 AM <DIR> QuickTimeStreamingExtras.Resources
09/01/2006 03:09 PM 77,824 QuickTimeUpdateHelper.exe
09/01/2006 03:16 PM 757,760 QuickTimeVR.qtx
10/09/2006 09:51 AM <DIR> QuickTimeVR.Resources
09/01/2006 03:16 PM 614,400 QuickTimeVRAuthoring.qtx
10/09/2006 09:51 AM <DIR> QuickTimeVRAuthoring.Resources
09/01/2006 03:16 PM 241,664 QuickTimeWebHelper.qtx
10/09/2006 09:51 AM <DIR> QuickTimeWebHelper.Resources
41 File(s) 35,571,828 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 25,600 CoreVideo.qtr
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
1 File(s) 25,600 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\CoreVideo.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 25,088 CoreVideoLocalized.qtr
1 File(s) 25,088 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 30,720 QuickTime.dll
09/01/2006 03:16 PM 196,608 QuickTime.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
2 File(s) 227,328 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 181,248 QuickTimeLocalized.qtr
2 File(s) 217,600 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:18 AM 36,864 QuickTimeLocalized.dll
09/01/2006 03:46 PM 186,880 QuickTimeLocalized.qtr
2 File(s) 223,744 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 36,352 QuickTimeLocalized.dll
09/01/2006 03:16 PM 177,152 QuickTimeLocalized.qtr
2 File(s) 213,504 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 184,320 QuickTimeLocalized.qtr
2 File(s) 220,672 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 178,176 QuickTimeLocalized.qtr
2 File(s) 214,528 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,864 QuickTimeLocalized.dll
09/01/2006 03:46 PM 182,784 QuickTimeLocalized.qtr
2 File(s) 219,648 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 36,864 QuickTimeLocalized.dll
09/01/2006 03:46 PM 178,688 QuickTimeLocalized.qtr
2 File(s) 215,552 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 178,176 QuickTimeLocalized.qtr
2 File(s) 214,528 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 176,128 QuickTimeLocalized.qtr
2 File(s) 212,480 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:19 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 194,048 QuickTimeLocalized.qtr
2 File(s) 230,400 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 184,320 QuickTimeLocalized.qtr
2 File(s) 220,672 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 177,664 QuickTimeLocalized.qtr
2 File(s) 214,016 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:18 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 174,080 QuickTimeLocalized.qtr
2 File(s) 210,432 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
08/25/2006 10:20 AM 36,352 QuickTimeLocalized.dll
09/01/2006 03:46 PM 173,056 QuickTimeLocalized.qtr
2 File(s) 209,408 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 27,648 QuickTime3GPP.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
1 File(s) 27,648 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 31,232 QuickTime3GPPLocalized.qtr
1 File(s) 31,232 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 31,232 QuickTime3GPPLocalized.qtr
1 File(s) 31,232 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 31,232 QuickTime3GPPLocalized.qtr
1 File(s) 31,232 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\nl.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 31,232 QuickTime3GPPLocalized.qtr
1 File(s) 31,232 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\sv.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_CN.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 30,720 QuickTime3GPPLocalized.qtr
1 File(s) 30,720 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPP.Resources\zh_TW.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 31,744 QuickTime3GPPLocalized.qtr
1 File(s) 31,744 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
10/09/2006 09:51 AM <DIR> da.lproj
10/09/2006 09:51 AM <DIR> de.lproj
10/09/2006 09:51 AM <DIR> en.lproj
10/09/2006 09:51 AM <DIR> es.lproj
10/09/2006 09:51 AM <DIR> fi.lproj
10/09/2006 09:51 AM <DIR> fr.lproj
10/09/2006 09:51 AM <DIR> it.lproj
10/09/2006 09:51 AM <DIR> ja.lproj
10/09/2006 09:51 AM <DIR> ko.lproj
10/09/2006 09:51 AM <DIR> nb.lproj
10/09/2006 09:51 AM <DIR> nl.lproj
09/01/2006 03:16 PM 31,232 QuickTime3GPPAuthoring.qtr
10/09/2006 09:51 AM <DIR> sv.lproj
10/09/2006 09:51 AM <DIR> zh_CN.lproj
10/09/2006 09:51 AM <DIR> zh_TW.lproj
1 File(s) 31,232 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\da.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 38,912 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 38,912 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\de.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 38,912 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 38,912 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\en.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:16 PM 38,400 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 38,400 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\es.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 41,984 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 41,984 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fi.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 39,424 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 39,424 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\fr.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 39,936 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 39,936 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\it.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 39,424 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 39,424 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ja.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 38,912 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 38,912 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\ko.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 37,376 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 37,376 bytes

Directory of C:\Program Files\QuickTime\QTSystem\QuickTime3GPPAuthoring.Resources\nb.lproj

10/09/2006 09:51 AM <DIR> .
10/09/2006 09:51 AM <DIR> ..
09/01/2006 03:46 PM 39,424 QuickTime3GPPAuthoringLocalized.qtr
1 File(s) 39,424 bytes

Directory of C:\Program Files\Quick
  • 0

#10
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Do you need the results of the entire batch file?
Here is the scanner and HJT log:

---------------------------------------------------------
AVG Anti-Spyware - Scan Report
---------------------------------------------------------

+ Created at: 10:43:13 PM 11/6/2006

+ Scan result:



C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031795.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031796.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031797.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031798.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031799.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031800.EXE -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031801.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031802.exe -> Downloader.Agent.ayy : No action taken.
C:\System Volume Information\_restore{815F8C9D-047C-4033-9620-C49397A794DA}\RP317\A0031803.exe -> Downloader.Agent.ayy : No action taken.


::Report end

Logfile of HijackThis v1.99.1
Scan saved at 11:02:57 PM, on 11/6/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
C:\DELL\drivers\R61162\SynTPLpr.exe
C:\DELL\drivers\R61162\SynTPEnh.exe
C:\Program Files\Dell\AccessDirect\bak\dadapp.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Dell\AccessDirect\DadTray.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\unzipped\hijackthis_199[1]\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Norton Internet Security 2006 - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O2 - BHO: NAV Helper - {A8F38D8D-E480-4D52-B7A2-731BB6995FDD} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton Internet Security 2006 - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Program Files\Common Files\Symantec Shared\AdBlocking\NISShExt.dll
O3 - Toolbar: Norton AntiVirus - {C4069E3A-68F1-403E-B40E-20066696354B} - C:\Program Files\Norton Internet Security\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Apoint] C:\DELL\drivers\R64287\Apoint.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\DELL\drivers\R61162\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\DELL\drivers\R61162\SynTPEnh.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DadApp] C:\Program Files\Dell\AccessDirect\bak\dadapp.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - Global Startup: Norton GoBack.lnk = C:\Program Files\Norton SystemWorks\Norton GoBack\GBTray.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra button: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra 'Tools' menuitem: Express Cleanup - {5E638779-1818-4754-A595-EF1C63B87A56} - C:\Program Files\Norton SystemWorks\Norton Cleanup\WCQuick.lnk
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky...can_unicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.../US/install.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.syma...n/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} - http://www.symantec....rl/SymAData.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Internet Security Password Validation (ccISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPwdSvc.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet Security\comHost.exe
O23 - Service: Fix-It Task Manager - Unknown owner - C:\PROGRA~1\VCOM\Fix-It\mxtask.exe (file missing)
O23 - Service: GoBack Polling Service (GBPoll) - Symantec Corporation - C:\Program Files\Norton SystemWorks\Norton GoBack\GBPoll.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~2.EXE
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton UnErase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\NPROTECT.EXE
O23 - Service: Norton Protection Center Service (NSCService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
O23 - Service: Symantec AVScan (SAVScan) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~2\NORTON~2\SPEEDD~1\NOPDB.EXE
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: WLTRYSVC - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
  • 0

Advertisements


#11
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey whizzer38

Looks like it did the trick - just to confirm it worked I want you run the tool again.

Downloader.Agent.awf:

Please download FindAWF.exe

Run the tool and post the contents of the report in your next reply.
  • 0

#12
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Thanks. Everything looks stable now. Here is the report:



Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~



25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



26450 byte files found
~~~~~~~~~~~~~



26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\APOINT\BAK

06/10/2003 10:07 PM 147,456 Apoint.exe
1 File(s) 147,456 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/01/2006 02:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 09:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK

11/07/2002 08:00 PM 294,912 atiptaxx.exe
1 File(s) 294,912 bytes

Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\DELL\ACCESS~1\BAK

03/07/2003 11:36 AM 209,800 dadapp.exe
1 File(s) 209,800 bytes

Directory of C:\PROGRA~1\SYNAPT~1\SYNTP\BAK

05/02/2003 04:15 PM 610,304 SynTPEnh.exe
05/02/2003 04:21 PM 110,592 SynTPLpr.exe
2 File(s) 720,896 bytes

Directory of C:\WINDOWS\SYSTEM32\DLA\BAK

08/13/2004 12:05 AM 122,939 tfswctrl.exe
1 File(s) 122,939 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

08/20/2006 05:30 PM 180,269 realsched.exe
1 File(s) 180,269 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

147456 Jun 10 2003 "C:\DELL\drivers\R64287\Apoint.exe"
147456 Jun 10 2003 "C:\Program Files\Apoint\bak\Apoint.exe"
147456 Jun 10 2003 "C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Apoint.exe"
28672 Oct 15 2005 "C:\WINDOWS\system32\qttask.exe"
282624 Sep 1 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
294912 Nov 7 2002 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
209800 Mar 7 2003 "C:\Program Files\Dell\AccessDirect\bak\dadapp.exe"
610304 May 2 2003 "C:\DELL\drivers\R61162\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe"
110592 May 2 2003 "C:\DELL\drivers\R61162\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPLpr.exe"
122939 Aug 13 2004 "C:\WINDOWS\system32\dla\bak\tfswctrl.exe"
122939 Aug 13 2004 "C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\tfswctrl.exe"
180269 Aug 20 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"


end of report
  • 0

#13
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Would you suggest creating a new restore point from here and backing up my hard drive at this point? Thanks.
  • 0

#14
jamielaw

jamielaw

    Member

  • Member
  • PipPipPip
  • 350 posts
Hey whizzer38

Downloader.Agent.awf:

Please launch Notepad (Start > Run, type in: notepad)
Copy/paste all the text below to it:

if exist "C:\PROGRA~1\APOINT\Apoint.exe" 
move "C:\PROGRA~1\APOINT\BAK\Apoint.exe" "C:\PROGRA~1\APOINT"
rmdir "C:\PROGRA~1\APOINT\BAK"

if exist "C:\PROGRA~1\QUICKT~1\qttask.exe" 
move "C:\PROGRA~1\QUICKT~1\BAK\qttask.exe" "C:\PROGRA~1\QUICKT~1"
rmdir "C:\PROGRA~1\QUICKT~1\BAK"

if exist "C:\PROGRA~1\REGSHAVE\REGSHAVE.EXE" 
move "C:\PROGRA~1\REGSHAVE\BAK\REGSHAVE.EXE" "C:\PROGRA~1\REGSHAVE"
rmdir "C:\PROGRA~1\REGSHAVE\BAK"

if exist "C:\PROGRA~1\ATITEC~1\ATICON~1\atiptaxx.exe" 
move "C:\PROGRA~1\ATITEC~1\ATICON~1\BAK\atiptaxx.exe" "C:\PROGRA~1\ATITEC~1\ATICON~1"
rmdir "C:\PROGRA~1\ATITEC~1\ATICON~1\BAK"

rmdir "C:\PROGRA~1\COMMON~1\SYMANT~1\BAK"

if exist "C:\PROGRA~1\DELL\ACCESS~1\dadapp.exe" 
move "C:\PROGRA~1\DELL\ACCESS~1\BAK\dadapp.exe" "C:\PROGRA~1\DELL\ACCESS~1"
rmdir "C:\PROGRA~1\DELL\ACCESS~1\BAK"

if exist "C:\PROGRA~1\SYNAPT~1\SYNTP\SynTPEnh.exe" 
move "C:\PROGRA~1\SYNAPT~1\SYNTP\BAK\SynTPEnh.exe" "C:\PROGRA~1\SYNAPT~1\SYNTP"
rmdir "C:\PROGRA~1\SYNAPT~1\SYNTP\BAK"

if exist "C:\PROGRA~1\SYNAPT~1\SYNTP\SynTPLpr.exe" 
move "C:\PROGRA~1\SYNAPT~1\SYNTP\BAK\SynTPLpr.exe" "C:\PROGRA~1\SYNAPT~1\SYNTP"
rmdir "C:\PROGRA~1\SYNAPT~1\SYNTP\BAK"

if exist "C:\WINDOWS\SYSTEM32\DLA\tfswctrl.exe" 
move "C:\WINDOWS\SYSTEM32\DLA\BAK\tfswctrl.exe" "C:\WINDOWS\SYSTEM32\DLA"
rmdir "C:\WINDOWS\SYSTEM32\DLA\BAK"

if exist "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\realsched.exe" 
move "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK\realsched.exe" "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1"
rmdir "C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK"

del 123.bat

In Notepad, go to File (upper menu bar), and select: Save as
In the Save as prompt:
Save in: Desktop
File Name: "123.bat"
Save as Type: All files
Click: Save
Exit out of Notepad.

Next, on the Desktop, double click on bakfile.bat


====
Also, please run the following:

1. DelDomains
http://www.mvps.org/.../DelDomains.inf
To delete all entries in the Restricted & Trusted Zone list, right click DelDomains.inf
Select: Install

2. ResetProtocolDefaults
http://www.mvps.org/...colDefaults.reg
Right click the link, save target as or save link as, and save to the Desktop.

Locate ResetProtocolDefaults.reg on the Desktop
Right-click and select: Merge
OK the prompt

Please can you then run the Downloader.Agent.awf tool again (see post 11). Post the log back here.
  • 0

#15
whizzer38

whizzer38

    Member

  • Topic Starter
  • Member
  • PipPip
  • 14 posts
Batch file 123.bat did not appear to run or it may have been very fast.

Thanks again.


Find AWF report by noahdfear ©2006


21504 byte files found
~~~~~~~~~~~~~



21504 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



25600 byte files found
~~~~~~~~~~~~~



25600 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



26450 byte files found
~~~~~~~~~~~~~



26450 byte files sorted with strings
~~~~~~~~~~~~~~~~~~~~~



bak folders found
~~~~~~~~~~~


Directory of C:\PROGRA~1\APOINT\BAK

06/10/2003 10:07 PM 147,456 Apoint.exe
1 File(s) 147,456 bytes

Directory of C:\PROGRA~1\QUICKT~1\BAK

09/01/2006 02:57 PM 282,624 qttask.exe
1 File(s) 282,624 bytes

Directory of C:\PROGRA~1\REGSHAVE\BAK

02/04/2002 09:32 PM 53,248 REGSHAVE.EXE
1 File(s) 53,248 bytes

Directory of C:\PROGRA~1\ATITEC~1\ATICON~1\BAK

11/07/2002 08:00 PM 294,912 atiptaxx.exe
1 File(s) 294,912 bytes

Directory of C:\PROGRA~1\COMMON~1\SYMANT~1\BAK

0 File(s) 0 bytes

Directory of C:\PROGRA~1\DELL\ACCESS~1\BAK

03/07/2003 11:36 AM 209,800 dadapp.exe
1 File(s) 209,800 bytes

Directory of C:\PROGRA~1\SYNAPT~1\SYNTP\BAK

05/02/2003 04:15 PM 610,304 SynTPEnh.exe
05/02/2003 04:21 PM 110,592 SynTPLpr.exe
2 File(s) 720,896 bytes

Directory of C:\WINDOWS\SYSTEM32\DLA\BAK

08/13/2004 12:05 AM 122,939 tfswctrl.exe
1 File(s) 122,939 bytes

Directory of C:\PROGRA~1\COMMON~1\REAL\UPDATE~1\BAK

08/20/2006 05:30 PM 180,269 realsched.exe
1 File(s) 180,269 bytes


Duplicate files of bak directory contents
~~~~~~~~~~~~~~~~~~~~~~~

147456 Jun 10 2003 "C:\DELL\drivers\R64287\Apoint.exe"
147456 Jun 10 2003 "C:\Program Files\Apoint\bak\Apoint.exe"
147456 Jun 10 2003 "C:\WINDOWS\system32\ReinstallBackups\0001\DriverFiles\Apoint.exe"
28672 Oct 15 2005 "C:\WINDOWS\system32\qttask.exe"
282624 Sep 1 2006 "C:\Program Files\QuickTime\bak\qttask.exe"
53248 Feb 4 2002 "C:\Program Files\REGSHAVE\bak\REGSHAVE.EXE"
294912 Nov 7 2002 "C:\Program Files\ATI Technologies\ATI Control Panel\bak\atiptaxx.exe"
209800 Mar 7 2003 "C:\Program Files\Dell\AccessDirect\bak\dadapp.exe"
610304 May 2 2003 "C:\DELL\drivers\R61162\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPEnh.exe"
610304 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPEnh.exe"
110592 May 2 2003 "C:\DELL\drivers\R61162\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\bak\SynTPLpr.exe"
110592 May 2 2003 "C:\Program Files\Synaptics\SynTP\Media\SynTPLpr.exe"
122939 Aug 13 2004 "C:\WINDOWS\system32\dla\bak\tfswctrl.exe"
122939 Aug 13 2004 "C:\Program Files\Sonic\Sonic Solutions Product CD\DLA\install\tfswctrl.exe"
180269 Aug 20 2006 "C:\Program Files\Common Files\Real\Update_OB\bak\realsched.exe"


end of report
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP