Yes that C:\WINDOWS\Temp\removalfile.bat is still there.
Here's the Rootkit report:
GMER 1.0.14.14205 -
http://www.gmer.netRootkit scan 2008-04-08 20:00:35
Windows 5.1.2600 Service Pack 2
---- System - GMER 1.0.14 ----
SSDT 871273B0 ZwAlertResumeThread
SSDT 87127488 ZwAlertThread
SSDT 87116D48 ZwAllocateVirtualMemory
SSDT 8708D5B0 ZwConnectPort
SSDT 87125E70 ZwCreateMutant
SSDT 87085188 ZwCreateThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwDeleteValueKey [0xF5F41350]
SSDT 87159888 ZwFreeVirtualMemory
SSDT 871269C0 ZwImpersonateAnonymousToken
SSDT 87126008 ZwImpersonateThread
SSDT 8705D790 ZwMapViewOfSection
SSDT 8711FF30 ZwOpenEvent
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwOpenProcess [0xF7F2B8AC]
SSDT 871690D8 ZwOpenProcessToken
SSDT 871551A8 ZwOpenThreadToken
SSDT 86FDFBC8 ZwQueryValueKey
SSDT 87174478 ZwResumeThread
SSDT 871543C8 ZwSetContextThread
SSDT 871568F8 ZwSetInformationProcess
SSDT 87153210 ZwSetInformationThread
SSDT \??\C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Event Library/Symantec Corporation) ZwSetValueKey [0xF5F41580]
SSDT 871E1BB0 ZwSuspendProcess
SSDT 87127898 ZwSuspendThread
SSDT \??\C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.sys ZwTerminateProcess [0xF7F2B812]
SSDT 87127AF0 ZwTerminateThread
SSDT 87157E48 ZwUnmapViewOfSection
SSDT 870D6188 ZwWriteVirtualMemory
---- Kernel code sections - GMER 1.0.14 ----
? goclkhbm.sys The system cannot find the file specified. !
---- User IAT/EAT - GMER 1.0.14 ----
IAT C:\WINDOWS\Explorer.EXE[1520] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01C72F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1520] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01C72CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1520] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01C72D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\Explorer.EXE[1520] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01C72CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Jenny Zhao\Desktop\gmer\gmer.exe[1740] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00372F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Jenny Zhao\Desktop\gmer\gmer.exe[1740] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00372CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Jenny Zhao\Desktop\gmer\gmer.exe[1740] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00372D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Documents and Settings\Jenny Zhao\Desktop\gmer\gmer.exe[1740] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00372CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [01DE2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [01DE2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [01DE2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Logitech\QuickCam\Quickcam.exe[1892] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [01DE2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003C2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003C2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003C2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe[2132] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003C2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[2604] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [008D2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[2604] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [008D2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[2604] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [008D2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\wscntfy.exe[2604] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [008D2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [003B2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [003B2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [003B2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[3384] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [003B2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AB2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AB2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AB2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4048] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AB2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AB2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AB2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AB2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[4368] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AB2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\WISPTIS.EXE[5004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00892F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\WISPTIS.EXE[5004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00892CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\WISPTIS.EXE[5004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00892D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\WISPTIS.EXE[5004] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00892CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[5972] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtCreateFile] [00AB2F30] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[5972] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [00AB2CA0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[5972] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtClose] [00AB2D00] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
IAT C:\WINDOWS\system32\rundll32.exe[5972] @ C:\WINDOWS\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [00AB2CD0] C:\Program Files\Common Files\Logishrd\LVMVFM\LVPrcInj.dll (Camera Helper Library./Logitech Inc.)
---- Devices - GMER 1.0.14 ----
AttachedDevice \FileSystem\Ntfs \Ntfs SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat fltMgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
AttachedDevice \FileSystem\Fastfat \Fat SYMEVENT.SYS (Symantec Event Library/Symantec Corporation)
---- EOF - GMER 1.0.14 ----
Here's the Autostart report:
GMER 1.0.14.14205 -
http://www.gmer.netAutostart scan 2008-04-08 20:00:50
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = C:\WINDOWS\system32\userinit.exe,
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
!SASWinLogon@DLLName = C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
NavLogon@DLLName = C:\WINDOWS\system32\NavLogon.dll
rqRKcyyy@DLLName = rqRKcyyy.dll
WgaLogon@DLLName = WgaLogon.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AVG Anti-Spyware Guard@ = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
ccEvtMgr@ = "C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe"
ccSetMgr@ = "C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe"
DefWatch@ = "C:\Program Files\Symantec AntiVirus\DefWatch.exe"
LVCOMSer@ = "C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe"
LVPrcSrv@ = "C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe"
LVSrvLauncher@ = C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe
MDM@ = "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe"
SPBBCSvc@ = "C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe"
Symantec AntiVirus@ = "C:\Program Files\Symantec AntiVirus\Rtvscan.exe"
UleadBurningHelper@ = C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@SmappC:\Program Files\Analog Devices\SoundMAX\Smtray.exe = C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
@ccApp"C:\Program Files\Common Files\Symantec Shared\ccApp.exe" = "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
@vptrayC:\PROGRA~1\SYMANT~1\VPTray.exe = C:\PROGRA~1\SYMANT~1\VPTray.exe
@LogitechCommunicationsManager"C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" = "C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
@LogitechQuickCamRibbon"C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide = "C:\Program Files\Logitech\QuickCam\Quickcam.exe" /hide
@WinFast ScheduleC:\Program Files\WinFast\WFTVFM\WFWIZ.exe = C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
@!AVG Anti-Spyware"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized = "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
@b89f240brundll32.exe "C:\WINDOWS\system32\rlkwsiyh.dll",b = rundll32.exe "C:\WINDOWS\system32\rlkwsiyh.dll",b
@BMbbac1797Rundll32.exe "C:\WINDOWS\system32\lgmpoipb.dll",s = Rundll32.exe "C:\WINDOWS\system32\lgmpoipb.dll",s
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ctfmon.exeC:\WINDOWS\system32\ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe
@MsnMsgr"C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background = "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
HKLM\Software\Classes\.scr@ = "%1" %*
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks >>>
@{57B86673-276A-48B2-BAE7-C6DBB3020EB8}C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\shellexecutehook.dll
@{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}C:\Program Files\SUPERAntiSpyware\SASSEH.DLL = C:\Program Files\SUPERAntiSpyware\SASSEH.DLL
@{BFA7416F-6EBA-43E5-B485-D32C6C78E1DB}C:\WINDOWS\system32\rqRKcyyy.dll = C:\WINDOWS\system32\rqRKcyyy.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{30D02401-6A81-11d0-8274-00C04FD5AE38} /*IE Search Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E7E4BC40-E76A-11CE-A9BB-00AA004AE837} /*Shell DocObject Viewer*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FBF23B40-E3F0-101B-8488-00AA003E56F8} /*InternetShortcut*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3C374A40-BAE4-11CF-BF7D-00AA006946EE} /*Microsoft Url History Service*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FF393560-C2A7-11CF-BFF4-444553540000} /*History*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E00-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{7BD29E01-76C1-11CF-9DD0-00A0C9034933} /*Temporary Internet Files*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{CFBFAE00-17A6-11D0-99CB-00C04FD64497} /*Microsoft Url Search Hook*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3DC7A020-0ACD-11CF-A9BB-00AA004AE837} /*The Internet*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{871C5380-42A0-1069-A2EA-08002B30309D} /*Internet Name Space*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/C:\WINDOWS\system32\extmgr.dll = C:\WINDOWS\system32\extmgr.dll
@{BDA77241-42F6-11d0-85E2-00AA001FE28C} /*LDVP Shell Extensions*/C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
@{07C45BB1-4A8C-4642-A1F5-237E7215FF66} /*IE Microsoft BrowserBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{1C1EDB47-CE22-4bbb-B608-77B48F83C823} /*IE Fade Task*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{205D7A97-F16D-4691-86EF-F3075DCCA57D} /*IE Menu Desk Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{3028902F-6374-48b2-8DC6-9725E775B926} /*IE AutoComplete*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{43886CD5-6529-41c4-A707-7B3C92C05E68} /*IE Navigation Bar*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{44C76ECD-F7FA-411c-9929-1B77BA77F524} /*IE Menu Site*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{4B78D326-D922-44f9-AF2A-07805C2A3560} /*IE Menu Band*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6038EF75-ABFC-4e59-AB6F-12D397F6568D} /*IE Microsoft History AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6B4ECC4F-16D1-4474-94AB-5A763F2A54AE} /*IE Tracking Shell Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{6CF48EF8-44CD-45d2-8832-A16EA016311B} /*IE IShellFolderBand*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{73CFD649-CD48-4fd8-A272-2070EA56526B} /*IE BandProxy*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{98FF6D4B-6387-4b0a-8FBD-C5C4BB17B4F8} /*IE MRU AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9A096BB5-9DC3-4D1C-8526-C3CBF991EA4E} /*IE RSS Feeder Folder*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{9D958C62-3954-4b44-8FAB-C4670C1DB4C2} /*IE Microsoft Shell Folder AutoComplete List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{B31C5FAE-961F-415b-BAF0-E697A5178B94} /*IE Microsoft Multiple AutoComplete List Container*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BC476F4C-D9D7-4100-8D4E-E043F6DEC409} /*Microsoft Browser Architecture*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BFAD62EE-9D54-4b2a-BF3B-76F90697BD2A} /*IE Shell Rebar BandSite*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{E6EE9AAC-F76B-4947-8260-A9F136138E11} /*IE Shell Band Site Menu*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F2CF5485-4E02-4f68-819C-B92DE9277049} /*&Links*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{F83DAC1C-9BB9-4f2b-B619-09819DA81B0E} /*IE Registry Tree Options Utility*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FAC3CBF6-8697-43d0-BAB9-DCD1FCE19D75} /*IE User Assist*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{FDE7673D-2E19-4145-8376-BBD58C4BC7BA} /*IE Custom MRU AutoCompleted List*/C:\WINDOWS\system32\ieframe.dll = C:\WINDOWS\system32\ieframe.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Web Folders*/C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL = C:\Program Files\Common Files\Microsoft Shared\Web Folders\MSONSEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL = C:\PROGRA~1\MICROS~2\Office12\OLKFSTUB.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL = C:\PROGRA~1\MICROS~2\Office12\MLSHEXT.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/C:\Program Files\Microsoft Office\Office12\msohevi.dll = C:\Program Files\Microsoft Office\Office12\msohevi.dll
@{993BE281-6695-4BA5-8A2A-7AACBFAAB69E} /*Microsoft Office Metadata Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97} /*Microsoft Office Thumbnail Handler*/C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll = C:\Program Files\Windows Live\Messenger\fsshext.8.5.1302.1018.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/C:\Program Files\WinRAR\rarext.dll = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
AVG Anti-Spyware@{8934FCEF-F5B8-468f-951F-78A921CD3920} = C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\context.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers@{CA8ACAFA-5FBB-467B-B348-90DD488DE003} = C:\Program Files\SUPERAntiSpyware\SASCTXMN.DLL
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
LDVPMenu@{BDA77241-42F6-11d0-85E2-00AA001FE28C} = C:\Program Files\Common Files\Symantec Shared\SSC\vpshell2.dll
MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = C:\Program Files\WinRAR\rarext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{0D79E2A9-BE78-4FD4-882B-E075A86DFD7D}C:\WINDOWS\system32\mlJBUNET.dll = C:\WINDOWS\system32\mlJBUNET.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
@{ed4c1fa1-5a7b-4b4e-8f03-81e0f6f61121}C:\WINDOWS\system32\advusbpa.dll = C:\WINDOWS\system32\advusbpa.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157@Start Pagehttp://go.microsoft.com/fwlink/?LinkId=69157 =
http://go.microsoft....k/?LinkId=69157@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft...p...&ar=msnhome@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
livecall@CLSID = C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-help@CLSID = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
msnim@CLSID = C:\PROGRA~1\WINDOW~4\MESSEN~1\MSGRAP~1.DLL
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\system32\wiascr.dll
---- EOF - GMER 1.0.14 ----
And here's the Filelist report:
Tue 04/08/2008 20:01:19.90
Volume in drive C has no label.
Volume Serial Number is B89F-24A4
Directory of C:\
04/08/2008 07:23 PM 5,514 avenger.txt
04/08/2008 07:23 PM 1,072,549,888 hiberfil.sys
04/08/2008 07:23 PM 1,610,612,736 pagefile.sys
04/08/2008 11:21 AM 13,600 ComboFix.txt
04/06/2008 08:42 PM 307 kaflog.txt
03/31/2008 06:20 PM 90 inf.log
03/31/2008 06:07 PM 0 IO.SYS
03/31/2008 06:07 PM 0 MSDOS.SYS
03/31/2008 06:07 PM 0 AUTOEXEC.BAT
03/31/2008 06:07 PM 0 CONFIG.SYS
03/31/2008 06:02 PM 211 boot.ini
08/03/2004 10:59 PM 250,032 ntldr
08/03/2004 10:38 PM 47,564 NTDETECT.COM
13 File(s) 2,683,479,942 bytes
0 Dir(s) 115,402,362,880 bytes free
Volume in drive C has no label.
Volume Serial Number is B89F-24A4
Directory of C:\
Volume in drive C has no label.
Volume Serial Number is B89F-24A4
Directory of C:\WINDOWS
04/08/2008 07:54 PM 250 gmer.ini
04/08/2008 07:31 PM 32,316 BMbbac1797.txt
04/08/2008 07:31 PM 22 pskt.ini
04/08/2008 07:24 PM 0 0.log
04/08/2008 07:24 PM 157 wiadebug.log
04/08/2008 07:24 PM 48 wiaservc.log
04/08/2008 07:23 PM 2,048 bootstat.dat
04/08/2008 07:23 PM 15,158 SchedLgU.Txt
04/08/2008 07:22 PM 1,424,218 WindowsUpdate.log
04/08/2008 06:20 PM 446 cookies.ini
04/08/2008 06:01 PM 488,232 setupapi.log
04/08/2008 11:21 AM 53,248 PSEXESVC.EXE
04/08/2008 11:20 AM 227 system.ini
04/07/2008 09:07 AM 364,856 ntbtlog.txt
04/06/2008 10:11 AM 1,366 gmer.bat
04/06/2008 08:34 AM 80 gmer_uninstall.cmd
04/06/2008 08:34 AM 819,200 gmer.dll
04/02/2008 06:57 PM 242 svcpack.log
04/02/2008 06:44 PM 1,859 mozver.dat
04/02/2008 05:02 PM 176,967 setupact.log
04/01/2008 04:11 PM 11,860 DPINST.LOG
04/01/2008 08:53 AM 4,267 wmsetup.log
03/31/2008 07:57 PM 0 nsreg.dat
03/31/2008 07:55 PM 316,640 WMSysPr9.prx
03/31/2008 07:28 PM 552 win.ini
03/31/2008 06:54 PM 42,060 WgaNotify.log
03/31/2008 06:54 PM 716,708 iis6.log
03/31/2008 06:54 PM 1,374 imsins.log
03/31/2008 06:54 PM 217,970 comsetup.log
03/31/2008 06:54 PM 292,287 tsoc.log
03/31/2008 06:54 PM 130,635 ntdtcsetup.log
03/31/2008 06:54 PM 34,743 ocmsn.log
03/31/2008 06:54 PM 10,950 KB938127-IE7.log
03/31/2008 06:54 PM 32,352 tabletoc.log
03/31/2008 06:54 PM 111,090 netfxocm.log
03/31/2008 06:54 PM 43,987 MedCtrOC.log
03/31/2008 06:54 PM 306,332 ocgen.log
03/31/2008 06:54 PM 31,771 msgsocm.log
03/31/2008 06:54 PM 629,801 FaxSetup.log
03/31/2008 06:54 PM 199,302 msmqinst.log
03/31/2008 06:36 PM 6,272 spupdsvc.log
03/31/2008 06:25 PM 1,374 imsins.BAK
03/31/2008 06:25 PM 83,191 KB943055.log
03/31/2008 06:25 PM 83,011 KB946026.log
03/31/2008 06:25 PM 95,035 KB944533.log
03/31/2008 06:25 PM 93,662 KB944533-IE7.log
03/31/2008 06:25 PM 65,187 updspapi.log
03/31/2008 06:25 PM 84,695 KB943485.log
03/31/2008 06:24 PM 85,630 KB942840.log
03/31/2008 06:24 PM 84,708 KB941644.log
03/31/2008 06:24 PM 75,706 KB941569.log
03/31/2008 06:24 PM 85,843 KB937894.log
03/31/2008 06:24 PM 84,642 KB944653.log
03/31/2008 06:24 PM 84,379 KB941568.log
03/31/2008 06:24 PM 96,311 KB942763.log
03/31/2008 06:24 PM 37,710 ie7_main.log
03/31/2008 06:23 PM 108,758 KB942615-IE7.log
03/31/2008 06:23 PM 93,151 ie7.log
03/31/2008 06:22 PM 38,245 IDNMitigationAPIs.log
03/31/2008 06:22 PM 37,910 NLSDownlevelMapping.log
03/31/2008 06:22 PM 39,655 KB915865.log
03/31/2008 06:21 PM 38,315 KB914440.log
03/31/2008 06:21 PM 79,442 KB943460.log
03/31/2008 06:21 PM 75,674 KB904942.log
03/31/2008 06:20 PM 525 chipset.log
03/31/2008 06:16 PM 48,691 KB936357.log
03/31/2008 06:15 PM 48,299 KB941202.log
03/31/2008 06:15 PM 38,983 KB933729.log
03/31/2008 06:15 PM 46,988 KB936021.log
03/31/2008 06:15 PM 46,759 KB938127.log
03/31/2008 06:15 PM 35,456 KB936782.log
03/31/2008 06:15 PM 47,053 KB938829.log
03/31/2008 06:15 PM 46,493 KB938828.log
03/31/2008 06:15 PM 35,466 KB925398.log
03/31/2008 06:14 PM 45,867 KB935839.log
03/31/2008 06:14 PM 45,498 KB935840.log
03/31/2008 06:14 PM 45,810 KB929123.log
03/31/2008 06:14 PM 36,727 KB927891.log
03/31/2008 06:14 PM 44,821 KB930916.log
03/31/2008 06:14 PM 45,089 KB920213.log
03/31/2008 06:14 PM 44,697 KB890046.log
03/31/2008 06:14 PM 44,839 KB932168.log
03/31/2008 06:14 PM 43,426 KB931261.log
03/31/2008 06:13 PM 44,318 KB930178.log
03/31/2008 06:13 PM 45,374 KB931784.log
03/31/2008 06:13 PM 833 OEWABLog.txt
03/31/2008 06:13 PM 44,895 KB925902.log
03/31/2008 06:13 PM 807,854 setuplog.txt
03/31/2008 06:13 PM 42,905 KB926436.log
03/31/2008 06:13 PM 43,112 KB918118.log
03/31/2008 06:13 PM 43,447 KB927779.log
03/31/2008 06:13 PM 38,270 KB924667.log
03/31/2008 06:13 PM 40,237 KB927802.log
03/31/2008 06:13 PM 40,233 KB928843.log
03/31/2008 06:13 PM 41,313 KB928255.log
03/31/2008 06:12 PM 40,020 KB926255.log
03/31/2008 06:12 PM 40,108 KB923980.log
03/31/2008 06:12 PM 39,940 KB924270.log
03/31/2008 06:12 PM 38,728 KB922819.log
03/31/2008 06:12 PM 34,477 KB923191.log
03/31/2008 06:12 PM 36,580 KB924496.log
03/31/2008 06:12 PM 36,070 KB923414.log
03/31/2008 06:12 PM 37,678 KB920872.log
03/31/2008 06:12 PM 35,927 KB920685.log
03/31/2008 06:12 PM 36,080 KB919007.log
03/31/2008 06:11 PM 36,031 KB916595.log
03/31/2008 06:11 PM 28,383 KB922582.log
03/31/2008 06:11 PM 33,948 KB920683.log
03/31/2008 06:11 PM 32,426 KB920670.log
03/31/2008 06:11 PM 32,957 KB914388.log
03/31/2008 06:11 PM 31,037 KB911280.log
03/31/2008 06:11 PM 32,884 KB913580.log
03/31/2008 06:11 PM 31,220 KB918439.log
03/31/2008 06:11 PM 31,916 KB917344.log
03/31/2008 06:11 PM 31,533 KB914389.log
03/31/2008 06:10 PM 31,657 KB908531.log
03/31/2008 06:10 PM 31,637 KB900485.log
03/31/2008 06:10 PM 30,822 KB911562.log
03/31/2008 06:10 PM 18,719 KB911564.log
03/31/2008 06:10 PM 8,192 REGLOCS.OLD
03/31/2008 06:10 PM 30,153 KB911927.log
03/31/2008 06:10 PM 29,523 KB908519.log
03/31/2008 06:10 PM 23,753 KB910437.log
03/31/2008 06:10 PM 30,450 KB900725.log
03/31/2008 06:10 PM 27,925 KB905749.log
03/31/2008 06:09 PM 27,401 KB905414.log
03/31/2008 06:09 PM 26,587 KB901017.log
03/31/2008 06:09 PM 31,752 KB902400.log
03/31/2008 06:09 PM 23,053 KB894391.log
03/31/2008 06:09 PM 21,209 KB896423.log
03/31/2008 06:09 PM 20,697 KB899587.log
03/31/2008 06:09 PM 20,197 KB899591.log
03/31/2008 06:09 PM 20,061 KB893756.log
03/31/2008 06:09 PM 20,215 KB896358.log
03/31/2008 06:09 PM 22,124 KB890859.log
03/31/2008 06:08 PM 21,324 KB901214.log
03/31/2008 06:08 PM 21,135 KB896428.log
03/31/2008 06:08 PM 21,510 KB885835.log
03/31/2008 06:08 PM 20,108 KB891781.log
03/31/2008 06:08 PM 20,019 KB887472.log
03/31/2008 06:08 PM 20,098 KB888302.log
03/31/2008 06:08 PM 19,661 KB885836.log
03/31/2008 06:08 PM 12,255 KB886185.log
03/31/2008 06:08 PM 19,649 KB873339.log
03/31/2008 06:07 PM 0 control.ini
03/31/2008 06:06 PM 4,161 ODBCINST.INI
03/31/2008 06:06 PM 749 WindowsShell.Manifest
03/31/2008 06:04 PM 1,022 sessmgr.setup.log
03/31/2008 06:04 PM 36 vb.ini
03/31/2008 06:04 PM 37 vbaddin.ini
03/31/2008 06:03 PM 133 DtcInstall.log
03/31/2008 06:02 PM 200 cmsetacl.log
03/31/2008 05:53 PM 7,880 KB892130.log
03/31/2008 05:53 PM 9,477 KB898461.log
03/31/2008 05:53 PM 9,365 KB893803v2.log
03/31/2008 05:44 PM 0 vpc32.INI
03/31/2008 01:01 PM 0 Sti_Trace.log
03/31/2008 12:59 PM 1,052 regopt.log
03/31/2008 12:58 PM 0 setuperr.log
03/03/2008 08:29 PM 761,856 gmer.exe
01/09/2008 03:01 PM 453 bdoscandellang.ini
01/09/2008 03:01 PM 53,248 bdoscandel.exe
06/13/2007 06:23 AM 1,033,216 explorer.exe
05/26/2005 07:22 PM 10,752 hh.exe
08/04/2004 12:56 AM 283,648 winhlp32.exe
08/04/2004 12:56 AM 69,120 NOTEPAD.EXE
08/04/2004 12:56 AM 146,432 regedit.exe
08/04/2004 12:56 AM 50,688 twain_32.dll
04/26/2002 12:27 PM 368,640 SynCor.exe
04/26/2002 12:27 PM 962,560 SynthCoreA.Dll
08/23/2001 08:00 AM 707 _default.pif
08/23/2001 08:00 AM 48,680 winnt.bmp
08/23/2001 08:00 AM 48,680 winnt256.bmp
08/23/2001 08:00 AM 16,730 FeatherTexture.bmp
08/23/2001 08:00 AM 80 explorer.scf
08/23/2001 08:00 AM 17,336 Gone Fishing.bmp
08/23/2001 08:00 AM 15,360 TASKMAN.EXE
08/23/2001 08:00 AM 65,954 Prairie Wind.bmp
08/23/2001 08:00 AM 94,784 twain.dll
08/23/2001 08:00 AM 26,582 Greenstone.bmp
08/23/2001 08:00 AM 49,680 twunk_16.exe
08/23/2001 08:00 AM 25,600 twunk_32.exe
08/23/2001 08:00 AM 2 desktop.ini
08/23/2001 08:00 AM 1,405 msdfmap.ini
08/23/2001 08:00 AM 65,832 Santa Fe Stucco.bmp
08/23/2001 08:00 AM 256,192 winhelp.exe
08/23/2001 08:00 AM 18,944 vmmreg32.dll
08/23/2001 08:00 AM 26,680 River Sumida.bmp
08/23/2001 08:00 AM 17,362 Rhododendron.bmp
08/23/2001 08:00 AM 17,062 Coffee Bean.bmp
08/23/2001 08:00 AM 9,522 Zapotec.bmp
08/23/2001 08:00 AM 82,944 clock.avi
08/23/2001 08:00 AM 65,978 Soap Bubbles.bmp
08/23/2001 08:00 AM 1,272 Blue Lace 16.bmp
08/31/2000 08:00 AM 49,152 VFind.exe
08/31/2000 08:00 AM 212,480 swxcacls.exe
08/31/2000 08:00 AM 161,792 swreg.exe
08/31/2000 08:00 AM 73,728 fdsv.exe
08/31/2000 08:00 AM 98,816 sed.exe
08/31/2000 08:00 AM 80,412 grep.exe
08/31/2000 08:00 AM 28,160 Nircmd.exe
08/31/2000 08:00 AM 68,096 zip.exe
08/31/2000 08:00 AM 136,704 swsc.exe
203 File(s) 17,225,667 bytes
0 Dir(s) 115,402,350,592 bytes free
Volume in drive C has no label.
Volume Serial Number is B89F-24A4
Directory of C:\WINDOWS\System32
04/08/2008 08:01 PM 263,311 TENUBJlm.ini
04/08/2008 07:59 PM 263,295 TENUBJlm.ini2
04/08/2008 07:41 PM 91,712 advusbpa.dll
04/08/2008 07:38 PM 705,369 hyiswklr.ini
04/08/2008 07:38 PM 83,520 rlkwsiyh.dll
04/08/2008 07:32 PM 3,648 qvajcqgi.dll
04/08/2008 07:30 PM 88,640 lgmpoipb.dll
04/08/2008 07:29 PM 269,824 mlJBUNET.dll
04/08/2008 07:24 PM 38,912 rqRKcyyy.dll
04/08/2008 07:22 PM 270,486 RqXGOqru.ini
04/08/2008 07:22 PM 270,470 RqXGOqru.ini2
04/08/2008 06:20 PM 705,378 pfmsjnkb.ini
04/08/2008 05:54 PM 91,712 wegjosbd.dll
04/08/2008 05:51 PM 3,648 vxpclcwk.dll
04/08/2008 05:44 PM 38,912 yayaXoMg.dll
04/08/2008 11:29 AM 3,648 vebwsuan.dll
04/06/2008 08:40 PM 16,384 restart.exe
04/06/2008 08:40 PM 53,248 process.exe
04/06/2008 08:40 PM 90,112 regdacl.exe
04/06/2008 08:40 PM 4,096 reboot.exe
04/01/2008 04:10 PM 137,256 FNTCACHE.DAT
03/31/2008 07:01 PM 4,912 lvcoinst.log
03/31/2008 06:55 PM 2,206 wpa.dbl
03/31/2008 06:37 PM 311,934 perfh009.dat
03/31/2008 06:37 PM 40,196 perfc009.dat
03/31/2008 06:37 PM 356,120 PerfStringBackup.INI
03/31/2008 06:24 PM 138,978 TZLog.log
03/31/2008 06:09 PM 386 $winnt$.inf
03/31/2008 06:07 PM 2,577 CONFIG.NT
03/31/2008 06:06 PM 16,832 amcompat.tlb
03/31/2008 06:06 PM 23,392 nscompat.tlb
03/31/2008 06:06 PM 488 WindowsLogon.manifest
03/31/2008 06:06 PM 488 logonui.exe.manifest
03/31/2008 06:06 PM 749 sapi.cpl.manifest
03/31/2008 06:06 PM 749 wuaucpl.cpl.manifest
03/31/2008 06:06 PM 749 ncpa.cpl.manifest
03/31/2008 06:06 PM 749 cdplayer.exe.manifest
03/31/2008 06:06 PM 749 nwc.cpl.manifest
03/31/2008 06:04 PM 21,640 emptyregdb.dat
03/31/2008 01:02 PM 0 h323log.txt
03/29/2008 10:47 AM 236,032 WgaTray.exe
03/21/2008 08:44 AM 1,488,688 LegitCheckControl.dll
03/20/2008 07:45 PM 200,064 WgaLogon.dll
01/11/2008 01:53 AM 44,544 pngfilt.dll
12/19/2007 07:01 PM 347,136 dxtmsft.dll
12/08/2007 11:51 AM 3,592,192 mshtml.dll
12/06/2007 10:21 PM 193,024 msrating.dll
12/06/2007 10:21 PM 671,232 mstime.dll
12/06/2007 10:21 PM 233,472 webcheck.dll
12/06/2007 10:21 PM 105,984 url.dll
12/06/2007 10:21 PM 1,159,680 urlmon.dll
12/06/2007 10:21 PM 824,832 wininet.dll
12/06/2007 10:21 PM 102,912 occache.dll
12/06/2007 10:21 PM 478,208 mshtmled.dll
12/06/2007 10:21 PM 52,224 msfeedsbs.dll
12/06/2007 10:21 PM 1,831,424 inetcpl.cpl
12/06/2007 10:21 PM 27,648 jsproxy.dll
12/06/2007 10:21 PM 459,264 msfeeds.dll
12/06/2007 10:21 PM 6,066,176 ieframe.dll
12/06/2007 10:21 PM 267,776 iertutil.dll
12/06/2007 10:21 PM 44,544 iernonce.dll
12/06/2007 10:21 PM 124,928 advpack.dll
12/06/2007 10:21 PM 383,488 ieapfltr.dll
12/06/2007 10:21 PM 63,488 icardie.dll
12/06/2007 10:21 PM 153,088 ieakeng.dll
12/06/2007 10:21 PM 230,400 ieaksie.dll
12/06/2007 10:21 PM 133,120 extmgr.dll
12/06/2007 10:21 PM 214,528 dxtrans.dll
12/06/2007 10:21 PM 384,512 iedkcs32.dll
12/06/2007 08:44 PM 474,112 shlwapi.dll
12/06/2007 08:44 PM 1,499,136 shdocvw.dll
12/06/2007 08:44 PM 1,054,208 danim.dll
12/06/2007 08:44 PM 151,040 cdfview.dll
12/06/2007 08:44 PM 1,024,000 browseui.dll
12/06/2007 07:00 AM 13,824 ieudinit.exe
12/06/2007 07:00 AM 70,656 ie4uinit.exe
12/06/2007 05:38 AM 350,720 xpsp3res.dll
12/06/2007 12:59 AM 161,792 ieakui.dll
12/04/2007 02:38 PM 550,912 oleaut32.dll
11/13/2007 07:31 AM 60,416 tzchange.exe
11/07/2007 05:26 AM 721,920 lsasrv.dll
10/29/2007 06:43 PM 1,287,680 quartz.dll
10/27/2007 06:39 PM 230,912 wmasf.dll
10/27/2007 06:37 PM 2,109,440 wmvcore.dll
10/25/2007 11:34 PM 8,460,288 shell32.dll
10/21/2007 06:51 PM 323,624 wiaaut.dll
10/21/2007 06:38 PM 516,832 capicom.dll
10/18/2007 11:31 AM 51,224 sirenacm.dll
10/11/2007 10:00 PM 465,432 LVUI2RC.dll
10/11/2007 10:00 PM 490,008 LVUI2.dll
10/11/2007 09:57 PM 195,096 lvci1150.dll
10/11/2007 09:57 PM 416,280 lvcodec2.dll
10/11/2007 09:18 PM 21,138 Repository.reg
10/11/2007 09:11 PM 59,500 lvcoinst.ini
10/11/2007 03:12 PM 1,468,968 legitcheckcontrol.dll.bak
08/21/2007 02:15 AM 683,520 inetcomm.dll
08/13/2007 07:54 PM 191,488 iepeers.dll
08/13/2007 07:54 PM 413,696 vbscript.dll
08/13/2007 07:54 PM 180,736 ieui.dll
08/13/2007 07:54 PM 156,160 msls31.dll
08/13/2007 07:45 PM 443,904 html.iec
08/13/2007 07:45 PM 78,336 ieencode.dll
08/13/2007 07:45 PM 206,336 WinFXDocObj.exe
08/13/2007 07:44 PM 40,960 licmgr10.dll
08/13/2007 07:39 PM 71,680 admparse.dll
08/13/2007 07:39 PM 55,296 iesetup.dll
08/13/2007 07:39 PM 92,672 inseng.dll
08/13/2007 07:38 PM 10,240 advpack.dll.mui
08/13/2007 07:38 PM 491,520 jscript.dll
08/13/2007 07:36 PM 12,288 msfeedssync.exe
08/13/2007 07:36 PM 36,352 imgutil.dll
08/13/2007 07:32 PM 45,568 mshta.exe
08/13/2007 07:32 PM 66,560 tdc.ocx
08/13/2007 07:06 PM 56,700 ieuinit.inf
08/13/2007 07:01 PM 48,128 mshtmler.dll
08/13/2007 06:50 PM 1,383,424 mshtml.tlb
07/30/2007 08:19 PM 203,096 wuweb.dll
07/30/2007 08:19 PM 1,712,984 wuaueng.dll
07/30/2007 08:19 PM 549,720 wuapi.dll
07/30/2007 08:19 PM 325,976 wucltui.dll
07/30/2007 08:19 PM 25,944 wuaucpl.cpl.mui
07/30/2007 08:19 PM 216,408 wuaucpl.cpl
07/30/2007 08:19 PM 92,504 cdm.dll
07/30/2007 08:19 PM 53,080 wuauclt.exe
07/30/2007 08:19 PM 43,352 wups2.dll
07/30/2007 08:19 PM 25,944 wuapi.dll.mui
07/30/2007 08:18 PM 34,136 wucltui.dll.mui
07/30/2007 08:18 PM 33,624 wups.dll
07/30/2007 08:18 PM 20,312 wuaueng.dll.mui
07/09/2007 09:09 AM 584,192 rpcrt4.dll
07/06/2007 08:46 AM 48,640 mqupgrd.dll
07/06/2007 08:46 AM 138,240 mqad.dll
07/06/2007 08:46 AM 95,744 mqsec.dll
07/06/2007 08:46 AM 47,104 mqdscli.dll
07/06/2007 08:46 AM 177,152 mqrt.dll
07/06/2007 08:46 AM 471,552 mqutil.dll
07/06/2007 08:46 AM 16,896 mqise.dll
07/06/2007 08:46 AM 660,992 mqqm.dll
06/26/2007 02:08 AM 1,104,896 msxml3.dll
06/19/2007 09:31 AM 282,112 gdi32.dll
04/30/2007 03:22 AM 4,734,976 wmp.dll
04/25/2007 10:21 AM 144,896 schannel.dll
04/18/2007 12:12 PM 2,854,400 msi.dll
04/17/2007 05:32 AM 2,455,488 ieapfltr.dat
04/16/2007 11:52 AM 984,576 kernel32.dll
03/17/2007 09:43 AM 292,864 winsrv.dll
03/08/2007 11:36 AM 40,960 mf3216.dll
03/08/2007 11:36 AM 577,536 user32.dll
03/08/2007 09:47 AM 1,843,584 win32k.sys
03/08/2007 01:10 AM 991,232 ieframe.dll.mui
02/28/2007 05:10 AM 2,180,352 ntoskrnl.exe
02/28/2007 04:38 AM 2,057,600 ntkrnlpa.exe
02/26/2007 08:20 PM 49,152 TempDel.EXE
02/05/2007 04:17 PM 185,344 upnphost.dll
01/23/2007 03:29 PM 546,304 hhctrl.ocx
12/19/2006 05:52 PM 134,656 shsvcs.dll
12/19/2006 02:16 PM 333,824 wiaservc.dll
12/10/2006 02:10 PM 14,640 spmsg.dll
11/27/2006 10:54 AM 433,152 riched20.dll
11/27/2006 10:54 AM 539,136 msftedit.dll
11/01/2006 03:17 PM 927,504 mfc40u.dll
10/26/2006 07:58 PM 30,512 mdimon.dll
10/26/2006 02:10 PM 1,190,688 FM20.DLL
10/26/2006 02:10 PM 33,088 FM20ENU.DLL
10/26/2006 01:45 PM 293,376 WISPTIS.EXE
10/26/2006 01:45 PM 207,360 INKED.DLL
10/19/2006 09:56 AM 713,216 sxs.dll
10/16/2006 12:15 PM 122,880 oledlg.dll
10/14/2006 04:13 AM 981,760 mfc42u.dll
10/13/2006 08:35 AM 64,000 nwapi32.dll
10/13/2006 08:35 AM 142,336 nwprovau.dll
10/13/2006 08:35 AM 65,536 nwwks.dll
09/27/2006 09:35 PM 83,752 pds.dll
09/27/2006 09:35 PM 46,896 msgsys.dll
09/27/2006 09:35 PM 83,752 nts.dll
09/27/2006 09:35 PM 83,696 loc32vc0.dll
09/27/2006 09:35 PM 34,600 cba.dll
09/27/2006 09:33 PM 43,760 NavLogon.dll
09/23/2006 02:12 PM 74,715 IE7Eula.rtf
09/18/2006 06:55 PM 48,816 S32EVNT1.DLL
09/06/2006 06:43 PM 22,752 spupdsvc.exe
09/01/2006 09:44 AM 8,798 icrav03.rat
09/01/2006 09:44 AM 1,988 ticrf.rat
08/25/2006 11:45 AM 617,472 comctl32.dll
08/22/2006 05:05 AM 498,742 dxmasf.dll
08/21/2006 10:52 AM 246,814 strmdll.dll
08/21/2006 08:21 AM 16,896 fltlib.dll
08/21/2006 05:14 AM 23,040 fltmc.exe
08/17/2006 08:28 AM 332,288 netapi32.dll
08/17/2006 08:28 AM 132,096 wkssvc.dll
08/16/2006 07:58 AM 100,352 6to4svc.dll
08/07/2006 05:02 PM 534,208 SymNeti.dll
08/07/2006 05:02 PM 161,472 SymRedir.dll
07/24/2006 10:50 AM 47,920 VBAME.DLL
07/24/2006 10:50 AM 39,728 SCP32.DLL
07/24/2006 10:50 AM 125,744 MSSTDFMT.DLL
07/21/2006 04:24 AM 72,704 hlink.dll
07/14/2006 11:51 AM 121,856 xmllite.dll
06/29/2006 09:05 AM 23,552 normaliz.dll
06/29/2006 09:05 AM 26,112 idndl.dll
06/28/2006 06:59 PM 24,576 nlsdl.dll
06/26/2006 01:37 PM 148,480 dnsapi.dll
06/26/2006 01:37 PM 8,192 rasadhlp.dll
06/22/2006 06:47 AM 181,248 rasmans.dll
06/22/2006 01:06 AM 1,435,648 query.dll
06/22/2006 01:06 AM 69,120 ciodm.dll
06/08/2006 01:06 PM 60,294 normnfkd.nls
06/08/2006 01:06 PM 45,794 normnfc.nls
06/08/2006 01:06 PM 59,342 normidna.nls
06/08/2006 01:06 PM 66,384 normnfkc.nls
06/08/2006 01:06 PM 39,284 normnfd.nls
06/01/2006 02:47 PM 163,840 jgdw400.dll
06/01/2006 02:47 PM 27,648 jgpl400.dll
05/19/2006 08:59 AM 111,616 dhcpcsvc.dll
05/19/2006 08:59 AM 94,720 iphlpapi.dll
03/24/2006 12:37 AM 49,152 wdigest.dll
03/16/2006 08:38 PM 28,672 verclsid.exe
03/01/2006 03:42 PM 91,136 mtxoci.dll
03/01/2006 03:42 PM 11,776 xolehlp.dll
03/01/2006 03:42 PM 161,280 msdtcuiu.dll
03/01/2006 03:42 PM 66,560 mtxclu.dll
03/01/2006 03:42 PM 956,416 msdtctm.dll
03/01/2006 03:42 PM 426,496 msdtcprx.dll
01/03/2006 11:35 PM 68,096 webclnt.dll
10/20/2005 06:20 PM 1,082,368 esent.dll
10/17/2005 05:14 PM 118,272 t2embed.dll
10/17/2005 05:14 PM 80,896 fontsub.dll
09/09/2005 09:53 PM 2,067,968 cdosys.dll
08/31/2005 09:41 PM 19,968 linkinfo.dll
08/22/2005 11:35 PM 123,392 umpnpmgr.dll
08/22/2005 02:29 PM 197,632 netman.dll
07/26/2005 12:39 AM 397,824 rpcss.dll
07/26/2005 12:39 AM 101,376 txflog.dll
07/26/2005 12:39 AM 37,888 olecnv32.dll
07/26/2005 12:39 AM 74,752 olecli32.dll
07/26/2005 12:39 AM 1,285,120 ole32.dll
07/26/2005 12:39 AM 540,160 comuid.dll
07/26/2005 12:39 AM 243,200 es.dll
07/26/2005 12:39 AM 97,792 comrepl.dll
07/26/2005 12:39 AM 1,267,200 comsvcs.dll
07/26/2005 12:39 AM 625,152 catsrvut.dll
07/26/2005 12:39 AM 110,080 clbcatex.dll
07/26/2005 12:39 AM 60,416 colbact.dll
07/26/2005 12:39 AM 498,688 clbcatq.dll
07/26/2005 12:39 AM 225,792 catsrv.dll
07/08/2005 12:27 PM 249,344