ComboFix 08-05-01.3 - Mike 2008-05-04 23:05:03.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.520 [GMT -4:00]
Running from: C:\Documents and Settings\Mike\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Mike\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\imsins.BAK
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\found.001
C:\found.001\dir0000.chk\Accessibility.api
C:\found.001\dir0000.chk\AcroForm.api
C:\found.001\dir0000.chk\AcroForm\adobepdf.xdc
C:\found.001\dir0000.chk\AcroForm\PMP\AdobePDF417.pmp
C:\found.001\dir0000.chk\AcroForm\PMP\DataMatrix.pmp
C:\found.001\dir0000.chk\AcroForm\PMP\QRCode.pmp
C:\found.001\dir0000.chk\AcroSign.prc
C:\found.001\dir0000.chk\Annotations\Stamps\ENU\Dynamic.pdf
C:\found.001\dir0000.chk\Annotations\Stamps\ENU\SignHere.pdf
C:\found.001\dir0000.chk\Annotations\Stamps\ENU\StandardBusiness.pdf
C:\found.001\dir0000.chk\Annotations\Stamps\Words.pdf
C:\found.001\dir0000.chk\Annots.api
C:\found.001\dir0000.chk\Checkers.api
C:\found.001\dir0000.chk\DigSig.api
C:\found.001\dir0000.chk\DVA.api
C:\found.001\dir0000.chk\eBook.api
C:\found.001\dir0000.chk\EScript.api
C:\found.001\dir0000.chk\EWH32.api
C:\found.001\dir0000.chk\HLS.api
C:\found.001\dir0000.chk\IA32.api
C:\found.001\dir0000.chk\ImageViewer.API
C:\found.001\dir0000.chk\ImageViewer\en_US\svgrsrc.dll
C:\found.001\dir0000.chk\ImageViewer\en_US\SVGViewer.dict
C:\found.001\dir0000.chk\ImageViewer\SVGCore.DLL
C:\found.001\dir0000.chk\MakeAccessible.api
C:\found.001\dir0000.chk\Multimedia.api
C:\found.001\dir0000.chk\Multimedia\MPP\Flash.mpp
C:\found.001\dir0000.chk\Multimedia\MPP\MCIMPP.mpp
C:\found.001\dir0000.chk\Multimedia\MPP\QuickTime.mpp
C:\found.001\dir0000.chk\Multimedia\MPP\Real.mpp
C:\found.001\dir0000.chk\Multimedia\MPP\WindowsMedia.mpp
C:\found.001\dir0000.chk\PDDom.api
C:\found.001\dir0000.chk\PPKLite.api
C:\found.001\dir0000.chk\ReadOutLoud.api
C:\found.001\dir0000.chk\reflow.api
C:\found.001\dir0000.chk\SaveAsRTF.api
C:\found.001\dir0000.chk\Search.api
C:\found.001\dir0000.chk\Search5.api
C:\found.001\dir0000.chk\SendMail.api
C:\found.001\dir0000.chk\Spelling.api
C:\found.001\dir0000.chk\Updater.api
C:\found.001\dir0000.chk\weblink.api
C:\found.001\dir0001.chk\VDK10.CMP
C:\found.001\dir0001.chk\VDK10.LIC
C:\found.001\dir0001.chk\VDK10.STD
C:\found.001\dir0001.chk\VDK10.SYX
C:\found.001\dir0001.chk\VDK10.THD
C:\found.002
C:\found.002\dir0000.chk\1033\MSOSVINT.DLL
C:\found.002\dir0000.chk\1033\NSEXTINT.DLL
C:\found.002\dir0000.chk\1033\WebView\CATEGORY.HTT
C:\found.002\dir0000.chk\1033\WebView\CLASSICF.HTT
C:\found.002\dir0000.chk\1033\WebView\Images\APPR.GIF
C:\found.002\dir0000.chk\1033\WebView\Images\COUT.GIF
C:\found.002\dir0000.chk\1033\WebView\Images\PEND.GIF
C:\found.002\dir0000.chk\1033\WebView\MANAGMNT.HTT
C:\found.002\dir0000.chk\1033\WebView\SCHEMA.HTT
C:\found.002\dir0000.chk\1033\WebView\SEARCH.HTT
C:\found.002\dir0000.chk\1033\WebView\SMARTF.HTT
C:\found.002\dir0000.chk\1033\WebView\WORKSPC.HTT
C:\found.002\dir0000.chk\MSONSEXT.DLL
C:\found.002\dir0000.chk\MSOSV.DLL
C:\found.002\dir0000.chk\MSOWS409.DLL
C:\found.002\dir0000.chk\MSVCP60.DLL
C:\found.002\dir0000.chk\PKMAXCTL.DLL
C:\found.002\dir0000.chk\PKMCDO.DLL
C:\found.002\dir0000.chk\PKMCORE.DLL
C:\found.002\dir0000.chk\PKMFORMS.DLL
C:\found.002\dir0000.chk\PKMRES.DLL
C:\found.002\dir0000.chk\PKMSSTLB.DLL
C:\found.002\dir0000.chk\PKMTEMPL.DLL
C:\found.002\dir0000.chk\PKMTRACE.DLL
C:\found.002\dir0000.chk\PKMWS.DLL
C:\found.002\dir0000.chk\PROMDEMO.DLL
C:\found.002\dir0000.chk\PUBPLACE.HTT
C:\found.002\dir0000.chk\SECMGR.DLL
C:\found.002\dir0000.chk\VAIDDMGR.DLL
C:\found.002\dir0000.chk\VAIMEM.DLL
C:\found.002\dir0001.chk\acro20.lng
C:\found.002\dir0001.chk\Vdk10.lng
C:\found.002\dir0001.chk\VDK10.RSD
C:\found.002\dir0001.chk\Vdk10.rst
C:\found.002\dir0001.chk\VDK10.STC
C:\found.002\dir0001.chk\VDK10.STP
C:\found.002\dir0002.chk\ATI_Classic\ATI_Classic.uis
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbDown.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbHorz.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbLeft.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbRight.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbUp.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarThumbVert.tga
C:\found.002\dir0002.chk\ATI_Classic\ATITrackBarTrack.tga
C:\found.002\dir0002.chk\ATI_Classic\CheckboxNew.tga
C:\found.002\dir0002.chk\ATI_Classic\CloseButton.bmp
C:\found.002\dir0002.chk\ATI_Classic\CloseButton_dis.bmp
C:\found.002\dir0002.chk\ATI_Classic\ComboboxDropDownButton.tga
C:\found.002\dir0002.chk\ATI_Classic\dialog_bg.bmp
C:\found.002\dir0002.chk\ATI_Classic\ExtraImages.tga
C:\found.002\dir0002.chk\ATI_Classic\GroupBox.bmp
C:\found.002\dir0002.chk\ATI_Classic\GroupBoxHeader.bmp
C:\found.002\dir0002.chk\ATI_Classic\HelpButton.bmp
C:\found.002\dir0002.chk\ATI_Classic\ListViewHeader.bmp
C:\found.002\dir0002.chk\ATI_Classic\MaxButton.bmp
C:\found.002\dir0002.chk\ATI_Classic\mdibar.bmp
C:\found.002\dir0002.chk\ATI_Classic\MDIButtons.bmp
C:\found.002\dir0002.chk\ATI_Classic\MDIButtons.tga
C:\found.002\dir0002.chk\ATI_Classic\MenuBackground.bmp
C:\found.002\dir0002.chk\ATI_Classic\MenuItem.tga
C:\found.002\dir0002.chk\ATI_Classic\MinButton.bmp
C:\found.002\dir0002.chk\ATI_Classic\ProgressBar.bmp
C:\found.002\dir0002.chk\ATI_Classic\pulldownitemextra.tga
C:\found.002\dir0002.chk\ATI_Classic\PushButton.tga
C:\found.002\dir0002.chk\ATI_Classic\RadioButtonNew.tga
C:\found.002\dir0002.chk\ATI_Classic\Rebar.bmp
C:\found.002\dir0002.chk\ATI_Classic\RebarGripper.bmp
C:\found.002\dir0002.chk\ATI_Classic\RestoreButton.bmp
C:\found.002\dir0002.chk\ATI_Classic\ScrollBarButtons.bmp
C:\found.002\dir0002.chk\ATI_Classic\ScrollbarShaftHorz.bmp
C:\found.002\dir0002.chk\ATI_Classic\ScrollbarShaftVert.bmp
C:\found.002\dir0002.chk\ATI_Classic\ScrollbarThumbBtnHorz.bmp
C:\found.002\dir0002.chk\ATI_Classic\ScrollbarThumbBtnVert.bmp
C:\found.002\dir0002.chk\ATI_Classic\Spin.tga
C:\found.002\dir0002.chk\ATI_Classic\SpinUpDownHorizontalGlyph.tga
C:\found.002\dir0002.chk\ATI_Classic\SpinUpDownVerticalGlyph.tga
C:\found.002\dir0002.chk\ATI_Classic\StatusBar.bmp
C:\found.002\dir0002.chk\ATI_Classic\SunkEdge.bmp
C:\found.002\dir0002.chk\ATI_Classic\TabItem.tga
C:\found.002\dir0002.chk\ATI_Classic\TabPane.bmp
C:\found.002\dir0002.chk\ATI_Classic\TabsPage.bmp
C:\found.002\dir0002.chk\ATI_Classic\TexbackLeft.bmp
C:\found.002\dir0002.chk\ATI_Classic\TexbackLeft2.bmp
C:\found.002\dir0002.chk\ATI_Classic\TexbackRight.bmp
C:\found.002\dir0002.chk\ATI_Classic\textback.bmp
C:\found.002\dir0002.chk\ATI_Classic\ToolbarButton.tga
C:\found.002\dir0002.chk\ATI_Classic\TreeViewNode.bmp
C:\found.002\dir0002.chk\ATI_Classic\WindowFrameBottomUis2.bmp
C:\found.002\dir0002.chk\ATI_Classic\WindowFrameLeftUis2.bmp
C:\found.002\dir0002.chk\ATI_Classic\WindowFrameRightUis2.bmp
C:\found.002\dir0002.chk\ATI_Classic\WindowFrameTopUis2.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ATI_Crimson.uis
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbDown.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbHorz.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbLeft.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbRight.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbUp.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarThumbVert.tga
C:\found.002\dir0002.chk\ATI_Crimson\ATITrackBarTrack.tga
C:\found.002\dir0002.chk\ATI_Crimson\CheckboxNew.tga
C:\found.002\dir0002.chk\ATI_Crimson\CloseButton.bmp
C:\found.002\dir0002.chk\ATI_Crimson\CloseButton_dis.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ComboboxDropDownButton.tga
C:\found.002\dir0002.chk\ATI_Crimson\ExtraImages.tga
C:\found.002\dir0002.chk\ATI_Crimson\GroupBox.bmp
C:\found.002\dir0002.chk\ATI_Crimson\GroupBoxHeader.bmp
C:\found.002\dir0002.chk\ATI_Crimson\HelpButton.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ListViewHeader.bmp
C:\found.002\dir0002.chk\ATI_Crimson\MaxButton.bmp
C:\found.002\dir0002.chk\ATI_Crimson\mdibar.bmp
C:\found.002\dir0002.chk\ATI_Crimson\MDIButtons.bmp
C:\found.002\dir0002.chk\ATI_Crimson\MDIButtons.tga
C:\found.002\dir0002.chk\ATI_Crimson\MenuBackground.bmp
C:\found.002\dir0002.chk\ATI_Crimson\MenuItem.tga
C:\found.002\dir0002.chk\ATI_Crimson\MinButton.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ProgressBar.bmp
C:\found.002\dir0002.chk\ATI_Crimson\pulldownitemextra.tga
C:\found.002\dir0002.chk\ATI_Crimson\PushButton.tga
C:\found.002\dir0002.chk\ATI_Crimson\RadioButtonNew.tga
C:\found.002\dir0002.chk\ATI_Crimson\Rebar.bmp
C:\found.002\dir0002.chk\ATI_Crimson\RebarGripper.bmp
C:\found.002\dir0002.chk\ATI_Crimson\RestoreButton.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ScrollBarButtons.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ScrollbarShaftHorz.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ScrollbarShaftVert.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ScrollbarThumbBtnHorz.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ScrollbarThumbBtnVert.bmp
C:\found.002\dir0002.chk\ATI_Crimson\Spin.tga
C:\found.002\dir0002.chk\ATI_Crimson\SpinUpDownHorizontalGlyph.tga
C:\found.002\dir0002.chk\ATI_Crimson\SpinUpDownVerticalGlyph.tga
C:\found.002\dir0002.chk\ATI_Crimson\StatusBar.bmp
C:\found.002\dir0002.chk\ATI_Crimson\SunkEdge.bmp
C:\found.002\dir0002.chk\ATI_Crimson\TabItem.tga
C:\found.002\dir0002.chk\ATI_Crimson\TabPane.bmp
C:\found.002\dir0002.chk\ATI_Crimson\TabsPage.bmp
C:\found.002\dir0002.chk\ATI_Crimson\TexbackLeft.bmp
C:\found.002\dir0002.chk\ATI_Crimson\TexbackLeft2.bmp
C:\found.002\dir0002.chk\ATI_Crimson\TexbackRight.bmp
C:\found.002\dir0002.chk\ATI_Crimson\textback.bmp
C:\found.002\dir0002.chk\ATI_Crimson\ToolbarButton.tga
C:\found.002\dir0002.chk\ATI_Crimson\TreeViewNode.bmp
C:\found.002\dir0002.chk\ATI_Crimson\WindowFrameBottomUis2.bmp
C:\found.002\dir0002.chk\ATI_Crimson\WindowFrameLeftUis2.bmp
C:\found.002\dir0002.chk\ATI_Crimson\WindowFrameRightUis2.bmp
C:\found.002\dir0002.chk\ATI_Crimson\WindowFrameTopUis2.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\buttons.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Button.CheckBox.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Button.Radio.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Buttons.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_ComboButton.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_GroupBox.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_GroupBoxEdge.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_HeaderBar.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_HorzScroll.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_HorzScrollThumb.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_MenuBackground.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_MenuItem.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_ReBar.Grip.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Scrollbar.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_StatusBarEdges.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_SunkEdge.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Tabs.Border.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Tabs.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TaskBar.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_ToolBarBackground.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_Toolbars.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TopBorder.TextBack.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbDown.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbHorz.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbLeft.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbRight.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbUp.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.ThumbVert.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.Track.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_TrackBar.TrackVert.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_UpDown.Horz.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_UpDown.Vert.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_VertScroll.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_Quicksilver.uis_VertScrollThumb.WB4
C:\found.002\dir0002.chk\CATALYST_Quicksilver\CATALYST_QuicksilverStatusBar.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\checkbox.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\checkbox_old.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\close1.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\close1_dis.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\close2.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\close2_dis.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\ComboBox.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\ComboButton2.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\comboglyph.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\dialog_bg.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\explorer_bg.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\FrameBottom.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\FrameLeft.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\FrameRight.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\FrameTop.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\Groupbox.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\GroupBoxTop2.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\header.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\HScrollShaft.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\HScrollThumb.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\Menu.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\menubg.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\MenuFrame.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\menuitem.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\minimize2.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\radio.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\radio_old.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\Rebar.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\ScrollArrows.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\spinner-horz-glyphs.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\spinner-vert-glyphs.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\spinner.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\sysicon.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\Tab.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\TabPanel.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\textback-wb4.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\textback.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\textcap.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\toolbar_bg.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\toolbuttons.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\TrackBar-h.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\TrackBar-v.tga
C:\found.002\dir0002.chk\CATALYST_Quicksilver\TrackBarHTrack.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\TrackBarVTrack.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\VScrollShaft.bmp
C:\found.002\dir0002.chk\CATALYST_Quicksilver\VScrollThumb.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\buttons.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\CATALYST_SteelBlue.uis
C:\found.002\dir0002.chk\CATALYST_SteelBlue\checkbox.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\checkbox_old.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\close1.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\close1_dis.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\close2.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\close2_dis.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\ComboBox.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\ComboButton2.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\comboglyph.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\ControlCenterStatusBar.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\dialog_bg.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\explorer_bg.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\FrameBottom.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\FrameLeft.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\FrameRight.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\FrameTop.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\Groupbox.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\GroupBoxTop2.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\header.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\HScrollShaft.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\HScrollThumb.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\Menu.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\menubg.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\MenuFrame.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\menuitem.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\minimize2.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\radio.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\radio_old.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\Rebar.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\ScrollArrows.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\spinner-horz-glyphs.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\spinner-vert-glyphs.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\spinner.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\sysicon.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\Tab.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\TabPanel.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\textback-wb4.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\textback.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\textcap.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\toolbar_bg.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\toolbuttons.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\TrackBar-h.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\TrackBar-v.tga
C:\found.002\dir0002.chk\CATALYST_SteelBlue\TrackBarHTrack.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\TrackBarVTrack.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\VScrollShaft.bmp
C:\found.002\dir0002.chk\CATALYST_SteelBlue\VScrollThumb.bmp
C:\found.002\dir0002.chk\Skins.xml
.
((((((((((((((((((((((((( Files Created from 2008-04-05 to 2008-05-05 )))))))))))))))))))))))))))))))
.
2008-05-02 09:25 . 2008-05-02 09:27 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\SecondLife
2008-05-02 09:22 . 2008-05-02 09:28 <DIR> d-------- C:\Program Files\SecondLife
2008-04-29 18:33 . 2008-04-29 18:34 <DIR> d-------- C:\WINDOWS\ERUNT
2008-04-29 18:32 . 2008-04-29 18:32 <DIR> d-------- C:\SDFIX
2008-04-29 17:52 . 2008-04-29 17:52 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-04-29 17:51 . 2008-04-29 18:52 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-04-29 17:51 . 2008-04-29 17:51 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\SUPERAntiSpyware.com
2008-04-29 16:06 . 2008-04-29 16:06 <DIR> d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-29 16:06 . 2008-04-29 16:06 <DIR> d-------- C:\Documents and Settings\Mike\Application Data\Malwarebytes
2008-04-29 16:06 . 2008-04-29 16:06 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-29 16:05 . 2008-04-29 16:05 <DIR> d-------- C:\Program Files\Common Files\Download Manager
2008-04-29 13:03 . 2008-04-29 13:03 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-04-28 23:38 . 2008-04-30 14:16 <DIR> d--h----- C:\$AVG8.VAULT$
2008-04-28 23:34 . 2008-05-04 18:50 <DIR> d-------- C:\WINDOWS\system32\drivers\Avg
2008-04-28 23:34 . 2008-04-28 23:34 <DIR> d-------- C:\Program Files\AVG
2008-04-28 23:34 . 2008-05-03 12:21 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\avg8
2008-04-28 23:34 . 2008-04-28 23:34 96,520 --a------ C:\WINDOWS\system32\drivers\avgldx86.sys
2008-04-28 23:34 . 2008-04-28 23:34 10,520 --a------ C:\WINDOWS\system32\avgrsstx.dll
2008-04-25 04:23 . 2008-04-27 22:04 <DIR> d---s---- C:\Documents and Settings\Administrator.GETTER_ONE
2008-04-25 04:23 . 2008-05-03 19:01 1,024 --ah----- C:\Documents and Settings\Administrator.GETTER_ONE\ntuser.dat.LOG
2008-04-25 04:04 . 2008-04-25 04:04 <DIR> d-------- C:\!KillBox
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-05 02:57 --------- d-----w C:\Program Files\mIRC
2008-05-03 23:36 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-05-03 23:35 --------- d-----w C:\Program Files\Trillian
2008-05-03 07:01 --------- d-----w C:\Documents and Settings\Mike\Application Data\Azureus
2008-04-29 21:14 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-04-28 22:12 --------- d-----w C:\Program Files\Java
2008-04-20 22:26 --------- d-----w C:\Documents and Settings\Mike\Application Data\Ahead
2008-04-20 21:05 --------- d-----w C:\Program Files\World of Warcraft
2008-04-13 20:44 --------- d-----w C:\Program Files\Apophysis 2.0
2008-04-04 23:35 --------- d-----w C:\Program Files\Common Files\Ahead
2008-04-04 23:33 --------- d-----w C:\Documents and Settings\All Users\Application Data\Nero
2008-04-01 17:13 --------- d-----w C:\Documents and Settings\Mike\Application Data\Xfire
2008-03-28 23:14 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-28 23:11 --------- d-----w C:\Program Files\Nero
2008-03-28 05:52 --------- d-----w C:\Program Files\AV Vcs 5.5 DIAMOND
2008-03-27 07:54 --------- d-----w C:\Program Files\Winamp
2008-03-27 07:25 48,456 ----a-w C:\WINDOWS\system32\UninstallElectricSheep.exe
2008-03-27 00:14 --------- d-s---w C:\Program Files\Xfire
2008-03-25 10:31 --------- d-----w C:\Program Files\Steam
2008-03-20 18:00 --------- d-----w C:\Program Files\Lavasoft
2008-03-20 18:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-03-20 00:11 --------- d-----w C:\Program Files\CCleaner
2008-03-19 09:47 1,845,248 ----a-w C:\WINDOWS\system32\win32k.sys
2008-03-17 09:22 --------- d-----w C:\Documents and Settings\All Users\Application Data\Ironclad Games
2008-03-17 09:21 --------- d-----w C:\Program Files\Stardock
2008-03-17 08:16 --------- d-----w C:\Program Files\Common Files\Stardock
2008-03-13 23:05 41,296 ----a-w C:\WINDOWS\system32\xfcodec.dll
2008-03-10 14:26 --------- d-----w C:\Program Files\Azureus
2008-03-01 13:06 826,368 ----a-w C:\WINDOWS\system32\wininet.dll
2008-02-20 06:51 282,624 ----a-w C:\WINDOWS\system32\gdi32.dll
2008-02-20 05:32 45,568 ----a-w C:\WINDOWS\system32\dnsrslvr.dll
2008-02-15 20:04 141,909,560 ----a-w C:\Documents and Settings\Mike\WoW-2.3.3.7799-to-0.4.0.7897-enUS-patch.exe
2007-10-13 18:57 140,202,521 ----a-w C:\Documents and Settings\Mike\WoW-2.2.3.7359-to-0.3.0.7382-enUS-patch.exe
2007-06-12 12:25 40,836,719 ----a-w C:\Documents and Settings\Mike\WoW-2.1.1.6739-to-0.1.2.6757-enUS-patch.exe
2007-04-23 22:20 221,149,222 ----a-w C:\Documents and Settings\Mike\WoW-2.0.12.6546-to-0.1.0.6577-enUS-patch.exe
.
((((((((((((((((((((((((((((( snapshot@2008-05-03_19.06.46.57 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-01 13:17:19 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-04 22:48:39 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-05-04 22:48:53 16,384 ----atw C:\WINDOWS\Temp\Perflib_Perfdata_72c.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2006-02-28 08:00 15360]
"msnmsgr"="C:\Program Files\MSN Messenger\msnmsgr.exe" [2007-01-19 13:54 5674352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NVMixerTray"="C:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" [2004-06-03 21:51 131072]
"D-Link AirPlus G"="C:\Program Files\D-Link\AirPlus G\AirGCFG.exe" [2005-03-18 05:34 1228800]
"ANIWZCS2Service"="C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe" [2004-12-16 18:49 49152]
"DiskeeperSystray"="C:\Program Files\Executive Software\Diskeeper\DkIcon.exe" [2005-07-26 18:52 184408]
"Launch LGDCore"="C:\Program Files\Logitech\G-series Software\LGDCore.exe" [2005-08-23 09:36 1110079]
"Launch LCDMon"="C:\Program Files\Logitech\G-series Software\LCDMon.exe" [2005-08-23 09:22 188416]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
"StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 13:35 90112]
"AtiPTA"="atiptaxx.exe" [2006-02-21 21:05 344064 C:\WINDOWS\system32\atiptaxx.exe]
"AVG8_TRAY"="C:\PROGRA~1\AVG\AVG8\avgtray.exe" [2008-04-28 23:34 1177368]
"MSConfig"="C:\WINDOWS\pchealth\helpctr\Binaries\MSCONFIG.exe" [2006-02-28 08:00 158208]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.ffds"= C:\PROGRA~1\COMBIN~1\Filters\FFDShow\ff_vfw.dll
"vidc.wmv3"= C:\PROGRA~1\COMBIN~1\Filters\wmv9vcm.dll
"VIDC.XFR1"= xfcodec.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Mike^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Mike\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2007-10-10 19:51 39792 C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
-ra------ 2007-03-01 10:37 2321600 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools]
--a------ 2006-12-06 09:00 516608 C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2007-06-01 10:21 153136 C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2006-02-28 08:00 15360 C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTRegRun]
--------- 1999-10-10 13:00 41984 C:\WINDOWS\CTRegRun.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-01-19 13:54 5674352 C:\Program Files\MSN Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2007-03-01 15:57 153136 C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2007-02-21 06:42 98304 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2006-11-10 13:35 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-01-28 09:48 1266936 C:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SUPERAntiSpyware]
--------- 2007-02-27 11:39 1310720 C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
C:\PROGRA~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\mIRC\\mirc.exe"=
"C:\\Program Files\\Azureus\\Azureus.exe"=
"C:\\WINDOWS\\system32\\dpvsetup.exe"=
"C:\\WINDOWS\\system32\\rundll32.exe"=
"C:\\Program Files\\Steam\\Steam.exe"=
"C:\\Program Files\\Steam\\steamapps\\aoa_kampfer\\team fortress 2\\hl2.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Stardock\\TotalGaming\\Sins of a Solar Empire\\Sins of a Solar Empire.exe"=
"C:\\Program Files\\Steam\\steamapps\\aoa_kampfer\\counter-strike\\hl.exe"=
"C:\\WINDOWS\\system32\\ElectricSheep.scr"=
"C:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"C:\\Program Files\\SecondLife\\SLVoice.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"6000:TCP"= 6000:TCP:Host
"6000:UDP"= 6000:UDP:Host1
"6112:TCP"= 6112:TCP:host2
"6112:UDP"= 6112:UDP:Host4
R0 SI3112r;Silicon Image SiI 3112 SATARaid Controller;C:\WINDOWS\system32\DRIVERS\SI3112r.sys [2004-05-12 02:01]
R1 atitray;atitray;C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys [2006-11-30 04:05]
R1 AvgLdx86;AVG AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [2008-04-28 23:34]
R2 avg8wd;AVG8 WatchDog;C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-04-28 23:34]
R3 A3AB;D-Link AirPro 802.11a/b Wireless Adapter Service(A3AB);C:\WINDOWS\system32\DRIVERS\A3AB.sys [2005-03-22 20:17]
S3 AC2003;AC2003;C:\WINDOWS\system32\Drivers\AC2003.sys [2004-07-11 23:57]
S3 cpuz126;cpuz126;C:\DOCUME~1\Mike\LOCALS~1\Temp\cpuz.sys []
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\H]
\Shell\AutoRun\command - H:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2d123d77-c137-11db-b6d5-806d6172696f}]
\Shell\AutoRun\command - F:\Autorun.exe root.ini
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a01cc654-8c3d-11dc-aec9-001195d09dab}]
\Shell\AutoRun\command - G:\Autorun.exe /run
\Shell\Shell00\Command - G:\Autorun.exe /run
\Shell\Shell01\Command - G:\Autorun.exe /action
\Shell\Shell02\Command - G:\Autorun.exe /uninstall
.
**************************************************************************
catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-04 23:09:13
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-05-04 23:10:05
ComboFix-quarantined-files.txt 2008-05-05 03:10:01
ComboFix2.txt 2008-05-03 23:07:09
Pre-Run: 6,981,283,840 bytes free
Post-Run: 6,975,303,680 bytes free
527 --- E O F --- 2008-05-01 07:11:02