Deckard's System Scanner v20071014.68
Extra logfile - please post this as an attachment with your post.
--------------------------------------------------------------------------------
-- System Information ----------------------------------------------------------
Microsoft Windows XP Professional (build 2600) SP 2.0
Architecture: X86; Language: English
CPU 0: Intel® Pentium® 4 CPU 3.06GHz
CPU 1: Intel® Pentium® 4 CPU 3.06GHz
Percentage of Memory in Use: 24%
Physical Memory (total/avail): 1535.48 MiB / 1154 MiB
Pagefile Memory (total/avail): 3434.87 MiB / 3219 MiB
Virtual Memory (total/avail): 2047.88 MiB / 1911.8 MiB
A: is Removable (No Media)
C: is Fixed (NTFS) - 74.55 GiB total, 59.26 GiB free.
D: is CDROM (No Media)
E: is CDROM (No Media)
\\.\PHYSICALDRIVE0 - SAMSUNG SP8004H - 74.56 GiB - 1 partition
\PARTITION0 (bootable) - Installable File System - 74.55 GiB - C:
-- Security Center -------------------------------------------------------------
AUOptions is scheduled to auto-install.
Windows Internal Firewall is enabled.
AntivirusOverride is set.
FW: COMODO Firewall Pro v3.0 (COMODO)
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Internet Explorer\\iexplore.exe"="C:\\Program Files\\Internet Explorer\\iexplore.exe:*:Enabled:Internet Explorer"
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\Win32\\RpcDataSrv.exe:*:Enabled:SiSoftware Database Agent Service"
"C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe"="C:\\Program Files\\SiSoftware\\SiSoftware Sandra Lite XII.SP1\\RpcSandraSrv.exe:*:Enabled:SiSoftware Sandra Agent Service"
-- Environment Variables -------------------------------------------------------
ALLUSERSPROFILE=C:\Documents and Settings\All Users.WINDOWS
APPDATA=C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data
CLIENTNAME=Console
CommonProgramFiles=C:\Program Files\Common Files
COMPUTERNAME=AWATCHMA-I34GHF
ComSpec=C:\WINDOWS\system32\cmd.exe
FP_NO_HOST_CHECK=NO
HOMEDRIVE=C:
HOMEPATH=\Documents and Settings\awatchman.AWATCHMA-I34GHF
LOGONSERVER=\\AWATCHMA-I34GHF
NUMBER_OF_PROCESSORS=2
OS=Windows_NT
Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem
PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
PROCESSOR_ARCHITECTURE=x86
PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 7, GenuineIntel
PROCESSOR_LEVEL=15
PROCESSOR_REVISION=0207
ProgramFiles=C:\Program Files
PROMPT=$P$G
SAN_DIR=C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1
SESSIONNAME=Console
SystemDrive=C:
SystemRoot=C:\WINDOWS
TEMP=C:\DOCUME~1\AWATCH~1.AWA\LOCALS~1\Temp
TMP=C:\DOCUME~1\AWATCH~1.AWA\LOCALS~1\Temp
USERDOMAIN=AWATCHMA-I34GHF
USERNAME=awatchman
USERPROFILE=C:\Documents and Settings\awatchman.AWATCHMA-I34GHF
windir=C:\WINDOWS
-- User Profiles ---------------------------------------------------------------
awatchman.AWATCHMA-I34GHF
(admin)-- Add/Remove Programs ---------------------------------------------------------
--> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player ActiveX --> C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 8.1.2 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81200000003}
Belarc Advisor 7.2 --> C:\PROGRA~1\Belarc\Advisor\Uninstall.exe C:\PROGRA~1\Belarc\Advisor\INSTALL.LOG
CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe"
CleanUp! --> C:\Program Files\CleanUp!\uninstall.exe
COMODO Firewall Pro --> C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
Crawler Toolbar with Web Security Guard --> C:\PROGRA~1\Crawler\CToolbar.exe uninst
DeepBurner v1.9.0.228 --> "C:\Program Files\Astonsoft\DeepBurner\Uninstall.exe" "C:\Program Files\Astonsoft\DeepBurner\install.log" -u
DeepRipper v 1.1 --> "C:\Program Files\Astonsoft\DeepRipper\Uninstall.exe" "C:\Program Files\Astonsoft\DeepRipper\install.log"
HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows Media Format 11 SDK (KB929399) --> "C:\WINDOWS\$NtUninstallKB929399$\spuninst\spuninst.exe"
ISO Recorder --> MsiExec.exe /I{DFC6573E-124D-4026-BFA4-B433C9D3FF21}
Microsoft Compression Client Pack 1.0 for Windows XP --> "C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0 --> "C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0) --> C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Mozilla Thunderbird (2.0.0.14) --> C:\Program Files\Mozilla Thunderbird\uninstall\helper.exe
NVIDIA Windows 2000/XP Display Drivers --> rundll32.exe C:\WINDOWS\System32\nvinstnt.dll,NvUninstallNT4 nv4_disp.inf
Opera 9.27 --> MsiExec.exe /X{04DB4871-BC1D-44BF-AADB-47326365EB8C}
SiSoftware Sandra Lite XII.SP1 --> "C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\unins000.exe"
Spybot - Search & Destroy --> "C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spyware Terminator --> "C:\Program Files\Spyware Terminator\unins000.exe"
VIA Rhine-Family Fast Ethernet Adapter --> Rundll32.exe vuins32.dll,vuins32Ex $Rhine $VIA
Winamp --> "C:\Program Files\Winamp\UninstWA.exe"
Windows Media Format 11 runtime --> "C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Yahoo! Toolbar --> C:\PROGRA~1\Yahoo!\Common\unyt.exe
-- Application Event Log -------------------------------------------------------
Event Record #/Type218 / Error
Event Submitted/Written: 05/31/2008 10:03:15 AM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application thunderbird.exe, version 1.8.20080.42104, faulting module thunderbird.exe, version 1.8.20080.42104, fault address 0x001c88d7.
Processing media-specific event for [thunderbird.exe!ws!]
Event Record #/Type201 / Error
Event Submitted/Written: 05/30/2008 06:11:18 PM
Event ID/Source: 4105 / H+BEDV AntiVir
Event Description:
4
Event Record #/Type195 / Error
Event Submitted/Written: 05/30/2008 06:01:29 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application teatimer.exe, version 1.5.2.16, faulting module teatimer.exe, version 1.5.2.16, fault address 0x0006f8a8.
Processing media-specific event for [teatimer.exe!ws!]
Event Record #/Type193 / Error
Event Submitted/Written: 05/30/2008 04:32:34 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application firefox.exe, version 1.9.0.3054, faulting module xul.dll, version 1.9.0.3054, fault address 0x0006741e.
Processing media-specific event for [firefox.exe!ws!]
Event Record #/Type190 / Error
Event Submitted/Written: 05/30/2008 03:54:17 PM
Event ID/Source: 1000 / Application Error
Event Description:
Faulting application avgwdsvc.exe, version 8.0.0.100, faulting module avgcfgx.dll, version 8.0.0.86, fault address 0x0002a957.
Processing media-specific event for [avgwdsvc.exe!ws!]
-- Security Event Log ----------------------------------------------------------
No Errors/Warnings found.
-- System Event Log ------------------------------------------------------------
Event Record #/Type1900 / Error
Event Submitted/Written: 05/30/2008 06:03:35 PM
Event ID/Source: 7034 / Service Control Manager
Event Description:
The AntiVir PersonalEdition Classic Guard service terminated unexpectedly. It has done this 1 time(s).
Event Record #/Type1892 / Error
Event Submitted/Written: 05/30/2008 06:03:26 PM
Event ID/Source: 7022 / Service Control Manager
Event Description:
The AntiVir PersonalEdition Classic Guard service hung on starting.
Event Record #/Type1863 / Error
Event Submitted/Written: 05/30/2008 03:54:28 PM
Event ID/Source: 7031 / Service Control Manager
Event Description:
The AVG8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
Event Record #/Type1821 / Error
Event Submitted/Written: 05/29/2008 08:45:08 PM
Event ID/Source: 7000 / Service Control Manager
Event Description:
The Lavalys EVEREST Kernel Driver service failed to start due to the following error:
%%2
Event Record #/Type1778 / Error
Event Submitted/Written: 05/29/2008 05:43:37 PM
Event ID/Source: 7031 / Service Control Manager
Event Description:
The AVG8 WatchDog service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 0 milliseconds: Restart the service.
-- End of Deckard's System Scanner: finished at 2008-05-31 10:17:20 ------------
Deckard's System Scanner v20071014.68
Run by awatchman on 2008-05-31 10:14:35
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
52: 2008-05-31 15:14:43 UTC - RP52 - Deckard's System Scanner Restore Point
51: 2008-05-30 23:32:44 UTC - RP51 - Avira AntiVir Personal - 5/30/2008 18:32
50: 2008-05-30 23:28:56 UTC - RP50 - AntiVir PersonalEdition Classic - 5/30/2008 18:28
49: 2008-05-30 23:18:38 UTC - RP49 - AntiVir PersonalEdition Classic - 5/30/2008 18:18
48: 2008-05-30 23:15:20 UTC - RP48 - AntiVir PersonalEdition Classic - 5/30/2008 18:15
-- First Restore Point --
1: 2008-05-17 18:52:37 UTC - RP1 - System Checkpoint
Performed disk cleanup.
-- HijackThis (run as awatchman.exe) -------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:14:52 AM, on 5/31/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Comodo\Firewall\cfp.exe
C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Comodo\Firewall\cmdagent.exe
C:\Program Files\Spyware Terminator\sp_rsser.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\DOCUME~1\AWATCH~1.AWA\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe
C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\AWATCH~1.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.crawler.c...a...&tbid=60076R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch =
http://dnl.crawler.c...aspx?TbId=60076R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1CB20BF0-BBAE-40A7-93F4-6435FF3D0411} - C:\PROGRA~1\Crawler\ctbr.dll
O3 - Toolbar: &Crawler Toolbar - {4B3803EA-5230-4DC3-A7FC-33638F3D3542} - C:\PROGRA~1\Crawler\ctbr.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -h
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Program Files\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Crawler Search - tbr:iemenu
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} (F-Secure Online Scanner 3.3) -
http://support.f-sec...m/ols/fscax.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.m...ash/swflash.cabO18 - Protocol: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - C:\PROGRA~1\Crawler\ctbr.dll
O23 - Service: COMODO Firewall Pro Helper Service (cmdAgent) - Unknown owner - C:\Program Files\Comodo\Firewall\cmdagent.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite XII.SP1\RpcSandraSrv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Program Files\Spyware Terminator\sp_rsser.exe
--
End of file - 3585 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080524-191716-163 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
backup-20080524-191716-195 O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
backup-20080524-191716-284 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080524-191716-380 O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
backup-20080524-191716-549 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
backup-20080524-191716-985 O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\Comodo\Firewall\cfp.exe" -h
backup-20080525-143456-257 O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080525-191550-566 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
backup-20080525-191551-462 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\WINDOWS\System32\shdocvw.dll
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R1 BANTExt (Belarc SMBios Access) - c:\windows\system32\drivers\bantext.sys
R1 sp_rsdrv2 (Spyware Terminator Driver 2) - c:\windows\system32\drivers\sp_rsdrv2.sys
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 sp_rssrv (Spyware Terminator Realtime Shield Service) - "c:\program files\spyware terminator\sp_rsser.exe" <Not Verified; Crawler.com; Crawler Spyware Terminator>
S3 Imapi Helper - "c:\program files\alex feinman\iso recorder\imapihelper.exe" <Not Verified; Alex Feinman; ISO Recorder>
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Process Modules -------------------------------------------------------------
C:\WINDOWS\system32\winlogon.exe (pid 724)
2007-04-16 10:52:53 984576 --a------ C:\WINDOWS\system32\kernel32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-07-09 08:16:16 582656 --a------ C:\WINDOWS\system32\rpcrt4.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-03-02 13:09:29 56832 --a------ C:\WINDOWS\system32\authz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-03-08 10:36:28 577536 --a------ C:\WINDOWS\system32\user32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 01:51:05 282624 --a------ C:\WINDOWS\system32\gdi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-17 07:28:27 332288 --a------ C:\WINDOWS\system32\netapi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-10-25 22:34:01 8460288 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-09-23 13:12:50 474112 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:58 617472 --a------ C:\WINDOWS\system32\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:55 1054208 --a------ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-12-19 16:52:18 134656 --a------ C:\WINDOWS\system32\shsvcs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:48 1285120 --a------ C:\WINDOWS\system32\ole32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-10-19 08:56:32 713216 --a------ C:\WINDOWS\system32\sxs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-05-19 07:59:41 94720 --a------ C:\WINDOWS\system32\iphlpapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-12-04 13:38:13 550912 --a------ C:\WINDOWS\system32\oleaut32.dll <Not Verified; Microsoft Corporation; >
2005-07-25 23:39:43 498688 --a------ C:\WINDOWS\system32\clbcatq.dll <Not Verified; Microsoft Corporation; COM Services>
C:\WINDOWS\system32\svchost.exe (pid 944)
2007-04-16 10:52:53 984576 --a------ C:\WINDOWS\system32\kernel32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-07-09 08:16:16 582656 --a------ C:\WINDOWS\system32\rpcrt4.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-03-08 10:36:28 577536 --a------ C:\WINDOWS\system32\user32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 01:51:05 282624 --a------ C:\WINDOWS\system32\gdi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:48 1285120 --a------ C:\WINDOWS\system32\ole32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-12-04 13:38:13 550912 --a------ C:\WINDOWS\system32\oleaut32.dll <Not Verified; Microsoft Corporation; >
2007-10-25 22:34:01 8460288 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-09-23 13:12:50 474112 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:55 1054208 --a------ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:58 617472 --a------ C:\WINDOWS\system32\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:49 397824 --a------ C:\WINDOWS\system32\rpcss.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:43 498688 --a------ C:\WINDOWS\system32\clbcatq.dll <Not Verified; Microsoft Corporation; COM Services>
2005-03-02 13:09:29 56832 --a------ C:\WINDOWS\system32\authz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-17 07:28:27 332288 --a------ C:\WINDOWS\system32\netapi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
C:\WINDOWS\system32\svchost.exe (pid 1152)
2007-04-16 10:52:53 984576 --a------ C:\WINDOWS\system32\kernel32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-07-09 08:16:16 582656 --a------ C:\WINDOWS\system32\rpcrt4.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-03-08 10:36:28 577536 --a------ C:\WINDOWS\system32\user32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 01:51:05 282624 --a------ C:\WINDOWS\system32\gdi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:48 1285120 --a------ C:\WINDOWS\system32\ole32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-12-04 13:38:13 550912 --a------ C:\WINDOWS\system32\oleaut32.dll <Not Verified; Microsoft Corporation; >
2007-10-25 22:34:01 8460288 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-09-23 13:12:50 474112 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:55 1054208 --a------ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:58 617472 --a------ C:\WINDOWS\system32\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-12-19 16:52:18 134656 --a------ C:\WINDOWS\system32\shsvcs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-17 07:28:27 332288 --a------ C:\WINDOWS\system32\netapi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-05-19 07:59:41 111616 --a------ C:\WINDOWS\system32\dhcpcsvc.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 00:32:43 148992 --a------ C:\WINDOWS\system32\dnsapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-05-19 07:59:41 94720 --a------ C:\WINDOWS\system32\iphlpapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-10-20 17:20:03 1082368 --a------ C:\WINDOWS\system32\esent.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-01 08:06:31 826368 --a------ C:\WINDOWS\system32\wininet.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2008-03-01 08:06:25 267776 --a------ C:\WINDOWS\system32\iertutil.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2007-04-25 09:21:15 144896 --a------ C:\WINDOWS\system32\schannel.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:43 498688 --a------ C:\WINDOWS\system32\clbcatq.dll <Not Verified; Microsoft Corporation; COM Services>
2006-08-17 07:28:27 132096 --a------ C:\WINDOWS\system32\wkssvc.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:45 243200 --a------ C:\WINDOWS\system32\es.dll <Not Verified; Microsoft Corporation; COM Services>
2005-08-22 13:29:46 197632 --a------ C:\WINDOWS\system32\netman.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2004-12-07 14:32:34 96768 --a------ C:\WINDOWS\system32\srvsvc.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-03-02 13:09:29 56832 --a------ C:\WINDOWS\system32\authz.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-04-18 11:12:23 2854400 --a------ C:\WINDOWS\system32\msi.dll <Not Verified; Microsoft Corporation; Windows Installer - Unicode>
2006-10-19 08:56:32 713216 --a------ C:\WINDOWS\system32\sxs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:44 1267200 --a------ C:\WINDOWS\system32\comsvcs.dll <Not Verified; Microsoft Corporation; COM Services>
2005-07-25 23:39:43 60416 --a------ C:\WINDOWS\system32\colbact.dll <Not Verified; Microsoft Corporation; COM Services>
2006-03-01 14:42:42 66560 --a------ C:\WINDOWS\system32\mtxclu.dll <Not Verified; Microsoft Corporation; COM Services>
2006-06-26 12:37:10 8192 --a------ C:\WINDOWS\system32\rasadhlp.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-06-22 05:47:18 181248 --a------ C:\WINDOWS\system32\rasmans.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-08 11:27:56 249344 --a------ C:\WINDOWS\system32\tapisrv.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-06-15 12:49:30 295936 --a------ C:\WINDOWS\system32\kerberos.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-01 08:06:20 124928 --a------ C:\WINDOWS\system32\advpack.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2005-07-25 23:39:43 625152 --a------ C:\WINDOWS\system32\catsrvut.dll <Not Verified; Microsoft Corporation; COM Services>
2005-07-25 23:39:42 225792 --a------ C:\WINDOWS\system32\catsrv.dll <Not Verified; Microsoft Corporation; COM Services>
2008-03-01 08:06:30 1159680 --a------ C:\WINDOWS\system32\urlmon.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
C:\WINDOWS\explorer.exe (pid 1676)
2007-04-16 10:52:53 984576 --a------ C:\WINDOWS\system32\kernel32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-07-09 08:16:16 582656 --a------ C:\WINDOWS\system32\rpcrt4.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-09-23 13:12:50 1022976 --a------ C:\WINDOWS\system32\browseui.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-02-20 01:51:05 282624 --a------ C:\WINDOWS\system32\gdi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-03-08 10:36:28 577536 --a------ C:\WINDOWS\system32\user32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:48 1285120 --a------ C:\WINDOWS\system32\ole32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-09-23 13:12:50 474112 --a------ C:\WINDOWS\system32\shlwapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-12-04 13:38:13 550912 --a------ C:\WINDOWS\system32\oleaut32.dll <Not Verified; Microsoft Corporation; >
2006-09-23 13:12:50 1497088 --a------ C:\WINDOWS\system32\shdocvw.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-17 07:28:27 332288 --a------ C:\WINDOWS\system32\netapi32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-01 08:06:31 826368 --a------ C:\WINDOWS\system32\wininet.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2008-03-01 08:06:25 267776 --a------ C:\WINDOWS\system32\iertutil.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2007-10-25 22:34:01 8460288 --a------ C:\WINDOWS\system32\shell32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:55 1054208 --a------ C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-08-25 10:45:58 617472 --a------ C:\WINDOWS\system32\comctl32.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2005-07-25 23:39:43 498688 --a------ C:\WINDOWS\system32\clbcatq.dll <Not Verified; Microsoft Corporation; COM Services>
2008-03-01 08:06:30 1159680 --a------ C:\WINDOWS\system32\urlmon.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2005-08-31 20:41:53 19968 --a------ C:\WINDOWS\system32\linkinfo.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-03-01 08:06:24 6066176 --a------ C:\WINDOWS\system32\ieframe.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2008-03-01 08:06:30 233472 --a------ C:\WINDOWS\system32\webcheck.dll <Not Verified; Microsoft Corporation; Windows® Internet Explorer>
2008-02-26 06:59:50 294912 --a------ C:\WINDOWS\system32\msctf.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2006-05-19 07:59:41 94720 --a------ C:\WINDOWS\system32\iphlpapi.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2007-04-18 11:12:23 2854400 --a------ C:\WINDOWS\system32\msi.dll <Not Verified; Microsoft Corporation; Windows Installer - Unicode>
2006-10-19 08:56:32 713216 --a------ C:\WINDOWS\system32\sxs.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
-- Files created between 2008-04-30 and 2008-05-31 -----------------------------
2008-05-30 19:04:44 0 d-------- C:\Program Files\Crawler
2008-05-30 19:02:25 0 d-------- C:\Program Files\WinClamAVShield
2008-05-30 18:59:02 0 dr-h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Recent
2008-05-30 16:57:36 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
2008-05-30 16:37:00 141312 --a------ C:\WINDOWS\system32\drivers\sp_rsdrv2.sys
2008-05-30 16:36:59 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Spyware Terminator
2008-05-30 16:36:59 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spyware Terminator
2008-05-30 16:36:56 0 d-------- C:\Program Files\Spyware Terminator
2008-05-29 21:04:40 0 d-------- C:\Program Files\SiSoftware
2008-05-29 20:00:30 0 d-------- C:\fsaua.data
2008-05-27 18:29:39 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Adobe
2008-05-26 17:23:00 0 d-------- C:\Program Files\Alex Feinman
2008-05-26 17:16:08 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\DeepBurner
2008-05-26 17:15:33 0 d-------- C:\Program Files\Astonsoft
2008-05-25 14:24:28 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-05-24 18:31:25 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-05-24 18:31:19 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\SUPERAntiSpyware.com
2008-05-24 18:24:41 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Malwarebytes
2008-05-24 18:24:35 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-05-24 18:24:19 0 d-------- C:\Program Files\Common Files\Download Manager
2008-05-24 15:59:52 0 d-------- C:\Program Files\Trend Micro
2008-05-24 14:57:46 0 d-------- C:\Program Files\a-squared Anti-Malware
2008-05-24 14:57:06 0 d-------- C:\Program Files\a-squared Anti-Dialer
2008-05-24 14:55:49 0 d-------- C:\Program Files\a-squared Free
2008-05-24 14:28:42 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Uniblue
2008-05-19 18:41:54 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-05-19 18:35:31 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\AVGTOOLBAR
2008-05-19 18:33:00 0 d-------- C:\Program Files\AVG
2008-05-19 18:23:24 0 d-------- C:\Program Files\Winamp
2008-05-19 18:23:24 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Winamp
2008-05-18 17:23:10 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2008-05-18 12:59:02 28672 -----n--- C:\WINDOWS\system32\verclsid.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 20:57:15 0 d-------- C:\WINDOWS\system32\CatRoot_bak
2008-05-17 20:56:12 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-17 20:47:18 0 d-------- C:\WINDOWS\network diagnostic
2008-05-17 20:47:00 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-17 20:37:25 3840 --a------ C:\WINDOWS\system32\drivers\BANTExt.sys
2008-05-17 20:37:10 0 d-------- C:\Program Files\Belarc
2008-05-17 19:40:07 1160 --a------ C:\WINDOWS\mozver.dat
2008-05-17 19:29:52 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-17 19:29:52 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-17 15:53:05 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Thunderbird
2008-05-17 15:33:49 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Opera
2008-05-17 15:15:09 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Comodo
2008-05-17 15:15:08 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\comodo
2008-05-17 15:13:57 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Start Menu
2008-05-17 15:12:47 0 d-------- C:\WINDOWS\Prefetch
2008-05-17 15:12:46 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-17 15:09:11 0 d-------- C:\WINDOWS\provisioning
2008-05-17 15:09:11 0 d-------- C:\WINDOWS\peernet
2008-05-17 15:07:48 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-17 15:05:10 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-17 15:03:01 0 d-------- C:\WINDOWS\EHome
2008-05-17 14:57:47 262784 -----n--- C:\WINDOWS\system32\drivers\http.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 14:57:45 23040 --a------ C:\WINDOWS\system32\fltmc.exe <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 14:57:45 16896 --a------ C:\WINDOWS\system32\fltlib.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 14:57:45 128896 -----n--- C:\WINDOWS\system32\drivers\fltmgr.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 14:57:36 377984 -----n--- C:\WINDOWS\system32\ati2dvaa.dll <Not Verified; ATI Technologies Inc.; ATI Rage 128 Family>
2008-05-17 14:51:06 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Windows Genuine Advantage
2008-05-17 14:47:06 0 d-------- C:\WINDOWS\system32\bits
2008-05-17 14:43:41 0 --a------ C:\WINDOWS\nsreg.dat
2008-05-17 14:43:39 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Mozilla
2008-05-17 14:34:49 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-05-17 14:22:39 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-17 14:19:37 0 d--hs---- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\UserData
2008-05-17 14:12:39 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Macromedia
2008-05-17 14:12:39 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Adobe
2008-05-17 14:08:43 0 d-------- C:\WUTemp
2008-05-17 14:05:44 0 d-------- C:\WINDOWS\nview
2008-05-17 13:57:49 0 d-------- C:\WINDOWS\system32\appmgmt
2008-05-17 13:54:01 552 --a------ C:\WINDOWS\system32\d3d8caps.dat
2008-05-17 13:52:25 0 d--hs---- C:\WINDOWS\Installer
2008-05-17 13:52:22 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\Identities
2008-05-17 13:52:11 0 d--h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Templates
2008-05-17 13:52:11 0 dr------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Start Menu
2008-05-17 13:52:11 0 dr-h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\SendTo
2008-05-17 13:52:11 0 d--h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\PrintHood
2008-05-17 13:52:11 2883584 --ah----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\NTUSER.DAT
2008-05-17 13:52:11 0 d--h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\NetHood
2008-05-17 13:52:11 0 dr------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\My Documents
2008-05-17 13:52:11 0 d--h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Local Settings
2008-05-17 13:52:11 0 dr------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Favorites
2008-05-17 13:52:11 0 d-------- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Desktop
2008-05-17 13:52:11 0 d--hs---- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Cookies
2008-05-17 13:52:11 0 dr-h----- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data
2008-05-17 13:50:36 262144 --ah----- C:\Documents and Settings\NetworkService.NT AUTHORITY\NTUSER.DAT
2008-05-17 13:50:36 0 d--h----- C:\Documents and Settings\NetworkService.NT AUTHORITY\Local Settings
2008-05-17 13:50:36 0 d---s---- C:\Documents and Settings\NetworkService.NT AUTHORITY\Cookies
2008-05-17 13:50:36 0 d-------- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data
2008-05-17 13:50:36 0 d---s---- C:\Documents and Settings\NetworkService.NT AUTHORITY\Application Data\Microsoft
2008-05-17 13:50:36 262144 --ah----- C:\Documents and Settings\LocalService.NT AUTHORITY\NTUSER.DAT
2008-05-17 13:50:36 0 d--h----- C:\Documents and Settings\LocalService.NT AUTHORITY\Local Settings
2008-05-17 13:50:36 0 d--hs---- C:\Documents and Settings\LocalService.NT AUTHORITY\Cookies
2008-05-17 13:50:36 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data
2008-05-17 13:50:36 0 d---s---- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\Microsoft
2008-05-17 13:47:21 0 d-------- C:\WINDOWS\system32\xircom
2008-05-17 13:47:06 221184 ---h----- C:\Documents and Settings\Default User.WINDOWS\NTUSER.DAT
2008-05-17 13:46:04 0 d--hs---- C:\Documents and Settings\All Users.WINDOWS\DRM
2008-05-17 13:45:53 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-17 13:45:53 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-17 13:45:26 0 d-------- C:\WINDOWS\srchasst
2008-05-17 13:45:20 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-17 13:45:20 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-17 13:44:50 0 d-------- C:\WINDOWS\system32\Restore
2008-05-17 13:44:45 0 d-------- C:\WINDOWS\PCHEALTH
2008-05-17 13:44:43 683520 --a------ C:\WINDOWS\system32\inetcomm.dll <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 13:44:41 0 d---s---- C:\WINDOWS\Tasks
2008-05-17 13:43:59 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-17 13:43:41 0 d-------- C:\WINDOWS\Registration
2008-05-17 13:43:14 347136 --a------ C:\WINDOWS\system32\hypertrm.dll <Not Verified; Hilgraeve, Inc.; Microsoft® Windows® Operating System>
2008-05-17 13:43:06 139528 --a------ C:\WINDOWS\system32\drivers\rdpwd.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 13:43:03 11776 --a------ C:\WINDOWS\system32\xolehlp.dll <Not Verified; Microsoft Corporation; Microsoft Distributed Transaction Coordinator>
2008-05-17 13:43:03 91136 --a------ C:\WINDOWS\system32\mtxoci.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:03 161280 --a------ C:\WINDOWS\system32\msdtcuiu.dll <Not Verified; Microsoft Corporation; Microsoft Distributed Transaction Coordinator>
2008-05-17 13:43:03 956416 --a------ C:\WINDOWS\system32\msdtctm.dll <Not Verified; Microsoft Corporation; Microsoft Distributed Transaction Coordinator>
2008-05-17 13:43:03 426496 --a------ C:\WINDOWS\system32\msdtcprx.dll <Not Verified; Microsoft Corporation; Microsoft Distributed Transaction Coordinator>
2008-05-17 13:43:03 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-17 13:43:01 97792 --a------ C:\WINDOWS\system32\comrepl.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:01 0 d-------- C:\WINDOWS\system32\Com
2008-05-17 13:43:01 60416 --a------ C:\WINDOWS\system32\colbact.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:00 1267200 --a------ C:\WINDOWS\system32\comsvcs.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:00 110080 --a------ C:\WINDOWS\system32\clbcatex.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:00 625152 --a------ C:\WINDOWS\system32\catsrvut.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:43:00 225792 --a------ C:\WINDOWS\system32\catsrv.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:42:59 540160 --a------ C:\WINDOWS\system32\comuid.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 13:42:59 498688 --a------ C:\WINDOWS\system32\clbcatq.dll <Not Verified; Microsoft Corporation; COM Services>
2008-05-17 08:40:48 6400 --a------ C:\WINDOWS\system32\drivers\splitter.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 08:40:46 142464 --a------ C:\WINDOWS\system32\drivers\aec.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 08:40:39 82944 --a------ C:\WINDOWS\system32\drivers\wdmaud.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 08:40:36 172416 --a------ C:\WINDOWS\system32\drivers\kmixer.sys <Not Verified; Microsoft Corporation; Microsoft® Windows® Operating System>
2008-05-17 08:37:26 0 d--h----- C:\Documents and Settings\Default User.WINDOWS\Templates
2008-05-17 08:37:26 0 dr------- C:\Documents and Settings\Default User.WINDOWS\Start Menu
2008-05-17 08:37:26 0 dr-h----- C:\Documents and Settings\Default User.WINDOWS\SendTo
2008-05-17 08:37:26 0 d--h----- C:\Documents and Settings\Default User.WINDOWS\Recent
2008-05-17 08:37:26 0 d--h----- C:\Documents and Settings\Default User.WINDOWS\PrintHood
2008-05-17 08:37:26 0 d--h----- C:\Documents and Settings\Default User.WINDOWS\NetHood
2008-05-17 08:37:26 0 d-------- C:\Documents and Settings\Default User.WINDOWS\My Documents
2008-05-17 08:37:26 0 dr-h----- C:\Documents and Settings\Default User.WINDOWS\Local Settings
2008-05-17 08:37:26 0 d-------- C:\Documents and Settings\Default User.WINDOWS\Favorites
2008-05-17 08:37:26 0 d-------- C:\Documents and Settings\Default User.WINDOWS\Desktop
2008-05-17 08:37:26 0 d---s---- C:\Documents and Settings\Default User.WINDOWS\Cookies
2008-05-17 08:37:26 0 d--h----- C:\Documents and Settings\All Users.WINDOWS\Templates
2008-05-17 08:37:26 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Start Menu
2008-05-17 08:37:26 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Favorites
2008-05-17 08:37:26 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Documents
2008-05-17 08:37:26 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Desktop
2008-05-17 08:37:13 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-17 08:37:13 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-17 08:37:08 0 dr-h----- C:\Documents and Settings\Default User.WINDOWS\Application Data
2008-05-17 08:37:08 0 d---s---- C:\Documents and Settings\Default User.WINDOWS\Application Data\Microsoft
2008-05-17 08:37:07 0 dr-h----- C:\Documents and Settings\All Users.WINDOWS\Application Data
2008-05-17 08:37:07 0 d---s---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2008-05-17 08:30:37 0 d-------- C:\WINDOWS
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\WinSxS
2008-05-17 08:30:37 0 dr------- C:\WINDOWS\Web
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\twain_32
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\wins
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\wbem
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\usmt
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\spool
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\Setup
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\ras
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\oobe
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\npp
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\mui
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\IME
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\ias
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\export
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\drivers
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-17 08:30:37 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\config
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\3076
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\2052
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1054
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1042
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1041
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1037
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1033
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1031
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1028
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system32\1025
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\system
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\security
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Resources
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\repair
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\mui
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\msapps
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\msagent
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Media
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\java
2008-05-17 08:30:37 0 d--h----- C:\WINDOWS\inf
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\ime
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Help
2008-05-17 08:30:37 0 dr--s---- C:\WINDOWS\Fonts
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Driver Cache
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Debug
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Cursors
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\Config
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\AppPatch
2008-05-17 08:30:37 0 d-------- C:\WINDOWS\addins
2008-05-16 19:40:08 0 dr-h----- C:\Documents and Settings\awatchman\Recent
2008-05-16 18:08:20 0 d-------- C:\Documents and Settings\All Users\Application Data\PCPitstop
2008-05-16 18:06:04 0 d-------- C:\Program Files\PCPitstop
2008-05-08 18:32:12 0 d-------- C:\Program Files\YouTube Downloader
2008-05-06 18:46:19 3362816 --a------ C:\Documents and Settings\awatchman\ntuser.dat
2008-05-03 16:00:14 0 d-------- C:\Documents and Settings\awatchman\Application Data\Malwarebytes
2008-05-03 15:59:57 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-03 13:46:37 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-05-03 13:46:01 0 d-------- C:\Program Files\Trojan Remover
2008-05-03 13:44:20 0 d-------- C:\Documents and Settings\awatchman\Application Data\Simply Super Software
2008-05-01 19:26:10 0 d-------- C:\Program Files\OpenOffice.org 2.4
-- Find3M Report ---------------------------------------------------------------
2008-05-31 10:03:12 0 d-------- C:\Program Files\Mozilla Thunderbird
2008-05-25 14:24:28 0 d-------- C:\Program Files\Common Files
2008-05-19 18:14:41 0 d-------- C:\Program Files\Messenger
2008-05-17 15:07:38 0 d-------- C:\Program Files\Movie Maker
2008-05-17 15:07:30 0 d-------- C:\Program Files\Windows NT
2008-05-17 14:33:06 0 d-------- C:\Program Files\Opera
2008-05-17 14:23:02 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-17 13:58:33 0 d-------- C:\Program Files\Online Services
2008-05-17 08:37:26 62 --ahs---- C:\Documents and Settings\awatchman.AWATCHMA-I34GHF\Application Data\desktop.ini
2008-05-03 12:48:14 0 d-------- C:\Program Files\Java
2008-05-01 19:25:30 0 d-------- C:\Program Files\OpenOffice.org 2.3
2008-04-26 18:42:23 0 d-------- C:\Program Files\Common Files\xing shared
2008-04-26 18:42:19 0 d-------- C:\Program Files\Common Files\Real
2008-04-26 18:35:52 0 d-------- C:\Program Files\Windows Media Connect 2
2008-04-19 15:47:33 0 d-------- C:\Program Files\Lavasoft
2008-04-13 18:09:12 0 d-------- C:\Program Files\Avant Browser
2008-04-13 15:18:26 0 d-------- C:\Program Files\Maxthon2
2008-04-10 18:33:36 0 d-------- C:\Program Files\InterMute
2008-04-09 19:54:20 0 d-------- C:\Program Files\Opera 9(2)
2008-04-09 19:05:25 0 d-------- C:\Program Files\Real
2008-04-04 08:10:56 0 d-------- C:\Program Files\Alwil Software
2008-03-27 03:12:54 151583 --a------ C:\WINDOWS\system32\msjint40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:58 355104 --a------ C:\WINDOWS\system32\msxbde40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:58 621344 --a------ C:\WINDOWS\system32\mswstr10.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:57 838432 --a------ C:\WINDOWS\system32\mswdat10.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:55 264992 --a------ C:\WINDOWS\system32\mstext40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:52 559904 --a------ C:\WINDOWS\system32\msrepl40.dll <Not Verified; Microsoft Corporation; Microsoft® Access>
2008-03-24 23:50:49 322336 --a------ C:\WINDOWS\system32\msrd3x40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:47 432928 --a------ C:\WINDOWS\system32\msrd2x40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:45 355104 --a------ C:\WINDOWS\system32\mspbde40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:44 219936 --a------ C:\WINDOWS\system32\msltus40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:42 248608 --a------ C:\WINDOWS\system32\msjtes40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:42 60192 --a------ C:\WINDOWS\system32\msjter40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:40 355112 --a------ C:\WINDOWS\system32\msjetoledb40.dll
2008-03-24 23:50:34 1516568 --a------ C:\WINDOWS\system32\msjet40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:30 326432 --a------ C:\WINDOWS\system32\msexcl40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
2008-03-24 23:50:28 518944 --a------ C:\WINDOWS\system32\msexch40.dll <Not Verified; Microsoft Corporation; Microsoft ® Jet>
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown<