ComboFix 08-06-01.6 - R Omar 2008-06-04 15:10:46.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.645 [GMT -5:00]
Running from: C:\Documents and Settings\R Omar\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\R Omar\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\WINDOWS\444.470
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll-uninst.exe
C:\WINDOWS\system32\g78.exe
C:\WINDOWS\system32\ocntnkdm.exe
C:\WINDOWS\system32\ssqrRigE.dll
C:\WINDOWS\system32\vbpdtvdp.exe
C:\WINDOWS\system32\winpfz33.sys
E:\Start.exe
F:\Start.exe
G:\Start.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\R Omar\lsass.exe
C:\WINDOWS\444.470
C:\WINDOWS\system32\_000003_.tmp.dll
C:\WINDOWS\system32\_000006_.tmp.dll
C:\WINDOWS\system32\_000007_.tmp.dll
C:\WINDOWS\system32\_000008_.tmp.dll
C:\WINDOWS\system32\_000011_.tmp.dll
C:\WINDOWS\system32\_000012_.tmp.dll
C:\WINDOWS\system32\_000013_.tmp.dll
C:\WINDOWS\system32\_000019_.tmp.dll
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll-uninst.exe
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll
C:\WINDOWS\system32\6026c
C:\WINDOWS\system32\6026c\wsDRV3.exe
C:\WINDOWS\system32\a053
C:\WINDOWS\system32\a053\updatdll95.exe
C:\WINDOWS\system32\Dev3
C:\WINDOWS\system32\Dev3\moolckr.exe
C:\WINDOWS\system32\EgiRrqss.ini
C:\WINDOWS\system32\EgiRrqss.ini2
C:\WINDOWS\system32\g78.exe
C:\WINDOWS\system32\ocntnkdm.exe
C:\WINDOWS\system32\ssqrRigE.dll
C:\WINDOWS\system32\sTMP
C:\WINDOWS\system32\sTMP\lutdtx2.exe
C:\WINDOWS\system32\vbpdtvdp.exe
C:\WINDOWS\system32\Vco1
C:\WINDOWS\system32\Vco1\hdpars11.exe
C:\WINDOWS\system32\winpfz33.sys
C:\WINDOWS\UiBPbWFy
C:\WINDOWS\x.exe
C:\WINDOWS\y.exe
.
((((((((((((((((((((((((( Files Created from 2008-05-04 to 2008-06-04 )))))))))))))))))))))))))))))))
.
2008-06-02 20:04 . 2008-06-03 19:33 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-06-02 14:50 . 2008-06-02 14:50 <DIR> d-------- C:\Deckard
2008-06-02 14:26 . 2008-06-02 14:26 <DIR> d-------- C:\WINDOWS\ERUNT
2008-06-02 14:11 . 2008-06-02 14:43 <DIR> d-------- C:\SDFix
2008-06-02 04:19 . 2008-06-02 04:19 <DIR> d-------- C:\Program Files\CCleaner
2008-06-02 04:16 . 2008-06-02 14:41 <DIR> d-------- C:\Temp
2008-05-24 06:25 . 2008-05-31 14:29 <DIR> d-------- C:\Program Files\FriendBlasterPro
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-25 09:05 --------- d-----w C:\Program Files\McAfee
2008-04-28 16:13 --------- d-----w C:\Program Files\Xilisoft
2006-12-25 14:15 22 --sha-w C:\WINDOWS\SMINST\HPCD.sys
2007-11-13 08:31 12,208 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( snapshot@2008-06-03_19.49.20.53 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-06-04 00:45:36 2,048 --s-a-w C:\WINDOWS\bootstat.dat
+ 2008-06-04 20:14:22 2,048 --s-a-w C:\WINDOWS\bootstat.dat
- 2008-06-04 00:34:09 56,124 ----a-w C:\WINDOWS\system32\perfc009.dat
+ 2008-06-04 20:12:20 56,124 ----a-w C:\WINDOWS\system32\perfc009.dat
- 2008-06-04 00:34:09 391,638 ----a-w C:\WINDOWS\system32\perfh009.dat
+ 2008-06-04 20:12:20 391,638 ----a-w C:\WINDOWS\system32\perfh009.dat
.
((((((((((((((((((((((((((((((((((((((( System Restore )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2006-03-15 23:00 25600 C:\Documents and Settings\LocalService\Application Data\Microsoft\UPnP Device Host\upnphost\udhisapi.dll
2006-03-15 23:00 25600 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036151.dll
2006-03-15 23:00 25600 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038082.dll
C:\Documents and Settings\R Omar\lsass.exe
2008-05-17 01:40 86016 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036662.exe
C:\Documents and Settings\R Omar\services.exe
2008-06-02 04:15 15360 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036663.exe
2008-03-24 23:50 554008 C:\Program Files\Common Files\Microsoft Shared\DAO\dao360.dll
2006-03-15 23:00 561179 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036064.dll
2008-06-04 15:17 510668 C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcrst.dll
2008-05-24 09:29 510668 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP322\A0035999.dll
2008-06-04 15:10 510668 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038078.dll
2008-05-25 23:48 1777664 C:\Program Files\FriendBlasterPro\FriendBlasterPro.exe
2008-01-30 17:57 429568 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036202.exe
2006-07-29 01:22 51712 C:\Program Files\FriendBlasterPro\GetDiskSerial.dll
2006-07-29 01:22 51712 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036206.dll
2008-05-25 23:47 695578 C:\Program Files\FriendBlasterPro\unins000.exe
2008-05-24 05:35 695578 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036209.exe
2008-02-15 04:07 18432 C:\Program Files\Internet Explorer\iedw.exe
2007-12-06 05:05 18432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036098.exe
2008-04-05 21:11 689472 C:\Program Files\McAfee\MSC\oem\108\mccobres.dll
2008-02-05 02:33 566592 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036125.dll
C:\Program Files\Network Monitor\netmon.exe
2006-01-04 18:09 94208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036661.exe
C:\SDFix\attrib.exe
2006-03-15 23:00 11264 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036879.exe
C:\SDFix\backupreg\AppInit_DLLs.reg
2008-06-02 14:26 624 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036848.reg
C:\SDFix\backupreg\bat_shell_open.reg
2008-06-02 14:26 204 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036849.reg
C:\SDFix\backupreg\BHO.reg
2008-06-02 14:26 8844 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036850.reg
C:\SDFix\backupreg\com_shell_open.reg
2008-06-02 14:26 204 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036851.reg
C:\SDFix\backupreg\ControlPanel_Load.reg
2008-06-02 14:26 9560 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036852.reg
C:\SDFix\backupreg\Drivers32.reg
2008-06-02 14:26 3562 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036853.reg
C:\SDFix\backupreg\exe_shell_open.reg
2008-06-02 14:26 204 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036854.reg
C:\SDFix\backupreg\HKCU_SOFTWARE_Policy.reg
2008-06-02 14:26 3118 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036857.reg
C:\SDFix\backupreg\HKCU_WINDOWS_Policy.reg
2008-06-02 14:26 690 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036858.reg
C:\SDFix\backupreg\HKCURun.reg
2008-06-02 14:26 486 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036855.reg
C:\SDFix\backupreg\HKCURunServices.reg
2008-06-02 14:26 74 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036856.reg
C:\SDFix\backupreg\HKLM_SOFTWARE_Policy.reg
2008-06-02 14:26 113534 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036861.reg
C:\SDFix\backupreg\HKLM_WINDOWS_Policy.reg
2008-06-02 14:26 3156 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036862.reg
C:\SDFix\backupreg\HKLMRun.reg
2008-06-02 14:26 5804 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036859.reg
C:\SDFix\backupreg\HKLMRunServices.reg
2008-06-02 14:26 74 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036860.reg
C:\SDFix\backupreg\hta_shell_open.reg
2008-06-02 14:26 270 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036863.reg
C:\SDFix\backupreg\IEDesktop.reg
2008-06-02 14:26 4474 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036864.reg
C:\SDFix\backupreg\IEMain.reg
2008-06-02 14:26 3332 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036865.reg
C:\SDFix\backupreg\Installed_Components.reg
2008-06-02 14:26 36254 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036866.reg
C:\SDFix\backupreg\pif_shell_open.reg
2008-06-02 14:26 204 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036867.reg
C:\SDFix\backupreg\reg_shell_open.reg
2008-06-02 14:26 230 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036868.reg
C:\SDFix\backupreg\SecurityProviders.reg
2008-06-02 14:26 8002 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036869.reg
C:\SDFix\backupreg\SharedTaskScheduler.reg
2008-06-02 14:26 546 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036870.reg
C:\SDFix\backupreg\ShellServiceObjectDelayLoad.reg
2008-06-02 14:26 816 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036871.reg
C:\SDFix\backupreg\SubSystems.reg
2008-06-02 14:26 5282 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036872.reg
C:\SDFix\backupreg\txt_shell_open.reg
2008-06-02 14:26 668 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036873.reg
C:\SDFix\backupreg\Winlogon.reg
2008-06-02 14:26 29168 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036874.reg
C:\SDFix\backupreg\WinlogonNotify.reg
2008-06-02 14:26 12638 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036875.reg
C:\SDFix\backups\accesss.exe
2008-06-02 04:31 15104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036729.exe
C:\SDFix\backups\asappsrv.dll
2005-08-02 16:46 187904 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036828.dll
C:\SDFix\backups\atmtd.dll
2008-06-02 04:16 687592 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036829.dll
C:\SDFix\backups\avpcc.dll
2008-06-02 04:31 20224 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036733.dll
C:\SDFix\backups\byXPijkI.dll
2008-06-02 04:16 69632 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036830.dll
C:\SDFix\backups\clrssn.exe
2008-06-02 04:31 12288 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036735.exe
C:\SDFix\backups\command.exe
2005-08-02 16:58 293888 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036831.exe
C:\SDFix\backups\cpan.dll
2008-06-02 04:31 25088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036737.dll
C:\SDFix\backups\ctfmon32.exe
2008-06-02 04:31 29952 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036739.exe
C:\SDFix\backups\ctrlpan.dll
2008-06-02 04:31 10752 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036741.dll
C:\SDFix\backups\directx32.exe
2008-06-02 04:31 21504 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036743.exe
C:\SDFix\backups\dnsrelay.dll
2008-06-02 04:31 19968 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036745.dll
C:\SDFix\backups\editpad.exe
2008-06-02 04:31 32512 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036747.exe
C:\SDFix\backups\explore.exe
2008-06-02 04:31 15872 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036749.exe
C:\SDFix\backups\explorer32.exe
2008-06-02 04:31 14592 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036751.exe
C:\SDFix\backups\funniest.exe
2008-06-02 04:31 23552 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036753.exe
C:\SDFix\backups\funny.exe
2008-06-02 04:31 20480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036755.exe
C:\SDFix\backups\gfmnaaa.dll
2008-06-02 04:31 15104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036757.dll
C:\SDFix\backups\helpcvs.exe
2008-06-02 04:31 26112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036759.exe
C:\SDFix\backups\iedll.exe
2008-06-02 04:31 26880 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036761.exe
C:\SDFix\backups\iexplorer.exe
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036763.exe
C:\SDFix\backups\inetinf.exe
2008-06-02 04:31 23040 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036765.exe
C:\SDFix\backups\internet.exe
2008-06-02 04:31 26624 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036767.exe
C:\SDFix\backups\loader.exe
2008-06-02 04:31 9472 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036769.exe
C:\SDFix\backups\lsass.exe
2008-05-17 01:40 86016 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036835.exe
C:\SDFix\backups\mrofinu1000106.exe
2008-06-02 04:16 41984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036836.exe
C:\SDFix\backups\mrofinu1188.exe
2008-06-02 04:16 41984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036837.exe
C:\SDFix\backups\msconfd.dll
2008-06-02 04:31 17920 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036771.dll
C:\SDFix\backups\msspi.dll
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036773.dll
C:\SDFix\backups\mssys.exe
2008-06-02 04:31 11520 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036775.exe
C:\SDFix\backups\msupdate.exe
2008-06-02 04:31 20736 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036777.exe
C:\SDFix\backups\mswsc10.dll
2008-06-02 04:31 20224 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036779.dll
C:\SDFix\backups\mswsc20.dll
2008-06-02 04:31 25088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036781.dll
C:\SDFix\backups\mtwirl32.dll
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036783.dll
C:\SDFix\backups\netmon.exe
2006-01-04 18:09 94208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036839.exe
C:\SDFix\backups\notepad32.exe
2008-06-02 04:31 9984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036785.exe
C:\SDFix\backups\o21jvqIV.vbs
2005-07-29 16:24 472 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036840.vbs
C:\SDFix\backups\olehelp.exe
2008-06-02 04:31 12544 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036787.exe
C:\SDFix\backups\qttasks.exe
2008-06-02 04:31 18432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036789.exe
C:\SDFix\backups\quicken.exe
2008-06-02 04:31 19968 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036791.exe
C:\SDFix\backups\RepairRun09.reg
2008-06-02 14:28 104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036841.reg
C:\SDFix\backups\RepairVundo.reg
2008-06-02 14:27 310 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036842.reg
C:\SDFix\backups\rundll16.exe
2008-06-02 04:31 13312 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036793.exe
C:\SDFix\backups\rwwnw64d.exe
2008-06-02 04:16 49155 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036843.exe
C:\SDFix\backups\searchword.dll
2008-06-02 04:31 13056 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036795.dll
C:\SDFix\backups\services.exe
2008-06-02 04:15 15360 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036844.exe
C:\SDFix\backups\sistem.exe
2008-06-02 04:31 8448 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036797.exe
C:\SDFix\backups\svchost32.exe
2008-06-02 04:31 17920 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036799.exe
C:\SDFix\backups\svcinit.exe
2008-06-02 04:31 30976 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036801.exe
C:\SDFix\backups\systeem.exe
2008-06-02 04:31 10240 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036803.exe
C:\SDFix\backups\systemcritical.exe
2008-06-02 04:31 30208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036805.exe
C:\SDFix\backups\time.exe
2008-06-02 04:31 32256 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036807.exe
C:\SDFix\backups\uninstall_nmon.vbs
2006-01-03 17:45 1989 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036845.vbs
C:\SDFix\backups\users32.exe
2008-06-02 04:31 30720 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036809.exe
C:\SDFix\backups\vntiho182328.exe
2008-05-20 16:13 32768 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036846.exe
C:\SDFix\backups\waol.exe
2008-06-02 04:31 8448 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036811.exe
C:\SDFix\backups\win32e.exe
2008-06-02 04:31 22784 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036813.exe
C:\SDFix\backups\win64.exe
2008-06-02 04:31 22272 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036815.exe
C:\SDFix\backups\winajbm.dll
2008-06-02 04:31 22272 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036817.dll
C:\SDFix\backups\window.exe
2008-06-02 04:31 16896 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036819.exe
C:\SDFix\backups\winmgnt.exe
2008-06-02 04:31 29440 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036821.exe
C:\SDFix\backups\x.exe
2008-06-02 04:31 9728 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036725.exe
C:\SDFix\backups\xplugin.dll
2008-06-02 04:31 31232 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036823.dll
C:\SDFix\backups\y.exe
2008-06-02 04:31 11776 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036727.exe
C:\SDFix\dummy.exe
2008-06-01 19:12 6656 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036876.exe
C:\SDFix\find.exe
2006-03-15 23:00 9216 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036877.exe
C:\SDFix\findstr.exe
2006-03-15 23:00 27136 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036878.exe
C:\SDFix\regedit.exe
2006-03-15 23:00 146432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036880.exe
C:\SDFix\RepairRun09.reg
2008-06-02 14:28 104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036881.reg
C:\SDFix\RepairVundo1.reg
2008-06-02 14:27 310 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036882.reg
C:\SDFix\userinfix.reg
2008-06-02 14:30 141 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036883.reg
C:\WINDOWS\_000004_.tmp.dll
2008-02-28 11:48 11284 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036076.dll
2008-02-28 18:49 10578 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036120.dll
C:\WINDOWS\_000005_.tmp.dll
2008-03-03 02:39 11990 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036066.dll
2007-12-18 21:32 11990 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036071.dll
C:\WINDOWS\_000020_.tmp.dll
2008-03-27 23:33 15505 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036047.dll
C:\WINDOWS\_000047_.tmp.dll
2008-03-01 05:32 24290 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036082.dll
2008-06-02 14:41 8448 C:\WINDOWS\accesss.exe
2008-06-02 04:31 15104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036666.exe
2008-06-02 14:32 22016 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036730.exe
2008-06-02 14:41 12288 C:\WINDOWS\avpcc.dll
2008-06-02 04:31 20224 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036668.dll
2008-06-02 14:32 15360 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036734.dll
2008-06-02 14:41 18688 C:\WINDOWS\clrssn.exe
2008-06-02 04:31 12288 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036669.exe
2008-06-02 14:32 20736 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036736.exe
2008-06-02 14:41 18944 C:\WINDOWS\cpan.dll
2008-06-02 04:31 25088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036670.dll
2008-06-02 14:32 25088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036738.dll
2008-06-02 14:41 10496 C:\WINDOWS\ctfmon32.exe
2008-06-02 04:31 29952 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036671.exe
2008-06-02 14:32 24064 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036740.exe
2008-06-02 14:41 16896 C:\WINDOWS\ctrlpan.dll
2008-06-02 04:31 10752 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036672.dll
2008-06-02 14:32 13568 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036742.dll
2008-06-02 14:41 30464 C:\WINDOWS\directx32.exe
2008-06-02 04:31 21504 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036673.exe
2008-06-02 14:32 32512 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036744.exe
2008-06-02 14:41 24832 C:\WINDOWS\dnsrelay.dll
2008-06-02 04:31 19968 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036674.dll
2008-06-02 14:32 32256 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036746.dll
2008-06-02 14:41 10240 C:\WINDOWS\editpad.exe
2008-06-02 04:31 32512 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036675.exe
2008-06-02 14:32 13824 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036748.exe
C:\WINDOWS\explore.exe
2008-06-02 04:31 15872 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036676.exe
2008-06-02 14:41 29696 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037949.exe
2008-06-02 14:41 19968 C:\WINDOWS\explorer32.exe
2008-06-02 04:31 14592 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036677.exe
2008-06-02 14:32 23040 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036752.exe
2008-06-02 14:41 27392 C:\WINDOWS\funniest.exe
2008-06-02 04:31 23552 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036678.exe
2008-06-02 14:32 10240 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036754.exe
2008-06-02 14:41 14336 C:\WINDOWS\funny.exe
2008-06-02 04:31 20480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036679.exe
2008-06-02 14:32 18944 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036756.exe
2008-06-02 14:41 25856 C:\WINDOWS\gfmnaaa.dll
2008-06-02 04:31 15104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036680.dll
2008-06-02 14:32 15616 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036758.dll
2008-06-02 14:41 23296 C:\WINDOWS\helpcvs.exe
2008-06-02 04:31 26112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036681.exe
2008-06-02 14:32 28928 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036760.exe
2008-06-02 14:41 27136 C:\WINDOWS\iedll.exe
2008-06-02 04:31 26880 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036682.exe
2008-06-02 14:32 12288 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036762.exe
C:\WINDOWS\iexplorer.exe
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036683.exe
2008-06-02 14:41 22784 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037950.exe
2008-06-02 14:41 18944 C:\WINDOWS\inetinf.exe
2008-06-02 04:31 23040 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036684.exe
2008-06-02 14:32 23552 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036766.exe
C:\WINDOWS\inf\_000000_.tmp.dll
2007-07-06 07:55 705 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036046.dll
2008-03-01 03:25 705 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036119.dll
2008-06-02 14:41 26880 C:\WINDOWS\internet.exe
2008-06-02 04:31 26624 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036685.exe
2008-06-02 14:32 16640 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036768.exe
C:\WINDOWS\lfn.exe
2008-06-02 04:16 89049 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037951.exe
2008-06-02 14:41 28672 C:\WINDOWS\loader.exe
2008-06-02 04:31 9472 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036686.exe
2008-06-02 14:32 31744 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036770.exe
C:\WINDOWS\mrofinu1000106.exe
2008-06-02 04:16 41984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036659.exe
C:\WINDOWS\mrofinu1188.exe
2008-06-02 04:16 41984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036660.exe
2008-06-02 14:41 31488 C:\WINDOWS\msconfd.dll
2008-06-02 04:31 17920 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036687.dll
2008-06-02 14:32 18432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036772.dll
2008-06-02 14:41 19200 C:\WINDOWS\msspi.dll
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036688.dll
2008-06-02 14:32 17408 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036774.dll
2008-06-02 14:41 28416 C:\WINDOWS\mssys.exe
2008-06-02 04:31 11520 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036689.exe
2008-06-02 14:32 10496 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036776.exe
2008-06-02 14:41 19200 C:\WINDOWS\msupdate.exe
2008-06-02 04:31 20736 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036690.exe
2008-06-02 14:32 28160 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036778.exe
2008-06-02 14:41 24576 C:\WINDOWS\mswsc10.dll
2008-06-02 04:31 20224 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036691.dll
2008-06-02 14:32 25344 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036780.dll
2008-06-02 14:41 24320 C:\WINDOWS\mswsc20.dll
2008-06-02 04:31 25088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036692.dll
2008-06-02 14:32 25600 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036782.dll
2008-06-02 14:41 12032 C:\WINDOWS\mtwirl32.dll
2008-06-02 04:31 8704 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036693.dll
2008-06-02 14:32 10240 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036784.dll
2008-06-02 14:41 8192 C:\WINDOWS\notepad32.exe
2008-06-02 04:31 9984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036694.exe
2008-06-02 14:32 24320 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036786.exe
2008-06-02 14:41 25344 C:\WINDOWS\olehelp.exe
2008-06-02 04:31 12544 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036695.exe
2008-06-02 14:32 20992 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036788.exe
2008-06-02 14:41 24576 C:\WINDOWS\qttasks.exe
2008-06-02 04:31 18432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036696.exe
2008-06-02 14:32 20736 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036790.exe
2008-06-02 14:41 13312 C:\WINDOWS\quicken.exe
2008-06-02 04:31 19968 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036697.exe
2008-06-02 14:32 29952 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036792.exe
2008-06-02 14:41 18944 C:\WINDOWS\rundll16.exe
2008-06-02 04:31 13312 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036698.exe
2008-06-02 14:32 28672 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036794.exe
2008-06-02 14:41 10240 C:\WINDOWS\searchword.dll
2008-06-02 04:31 13056 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036699.dll
2008-06-02 14:32 17664 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036796.dll
2008-06-02 14:41 19712 C:\WINDOWS\sistem.exe
2008-06-02 04:31 8448 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036700.exe
2008-06-02 14:32 11264 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036798.exe
2008-06-02 14:41 28928 C:\WINDOWS\svchost32.exe
2008-06-02 04:31 17920 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036701.exe
2008-06-02 14:32 9472 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036800.exe
2008-06-02 14:41 28672 C:\WINDOWS\svcinit.exe
2008-06-02 04:31 30976 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036702.exe
2008-06-02 14:32 8448 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036802.exe
2008-06-02 14:41 16640 C:\WINDOWS\systeem.exe
2008-06-02 04:31 10240 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036703.exe
2008-06-02 14:32 16640 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036804.exe
C:\WINDOWS\system32\_{43451195-72b1-a114-59ec-29f7755ebdb3}.dll
2008-05-05 11:24 330752 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036629.dll
C:\WINDOWS\system32\_000003_.tmp.dll
2006-03-15 23:00 96768 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038059.dll
C:\WINDOWS\system32\_000005_.tmp.dll
2007-03-08 08:47 1843584 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036130.dll
C:\WINDOWS\system32\_000006_.tmp.dll
2006-03-15 23:00 983552 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038060.dll
C:\WINDOWS\system32\_000007_.tmp.dll
2006-03-15 23:00 611328 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038061.dll
C:\WINDOWS\system32\_000008_.tmp.dll
2006-03-15 23:00 1835904 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038062.dll
C:\WINDOWS\system32\_000011_.tmp.dll
2006-03-15 23:00 111104 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038063.dll
C:\WINDOWS\system32\_000012_.tmp.dll
2006-03-15 23:00 132096 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038064.dll
C:\WINDOWS\system32\_000013_.tmp.dll
2006-03-15 23:00 721920 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038065.dll
C:\WINDOWS\system32\_000019_.tmp.dll
2005-04-28 22:31 37888 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038066.dll
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll-uninst.exe
2008-06-02 04:34 63918 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038049.exe
C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll
2008-05-27 08:47 371200 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038048.dll
C:\WINDOWS\system32\6026c\wsDRV3.exe
2008-05-05 11:16 127488 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038043.exe
C:\WINDOWS\system32\a053\updatdll95.exe
2008-06-01 12:13 37900 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038044.exe
C:\WINDOWS\system32\atmtd.dll
2008-06-02 04:16 687592 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036705.dll
2008-02-16 04:32 1024000 C:\WINDOWS\system32\browseui.dll
2007-12-06 19:44 1024000 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036097.dll
2007-12-06 19:44 1024000 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036136.dll
C:\WINDOWS\system32\byXPijkI.dll
2008-06-02 04:16 69632 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036652.dll
2008-02-16 04:32 151040 C:\WINDOWS\system32\cdfview.dll
2007-12-06 19:44 151040 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036096.dll
2008-02-16 04:32 1054208 C:\WINDOWS\system32\danim.dll
2007-12-06 19:44 1054208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036095.dll
C:\WINDOWS\system32\Dev3\moolckr.exe
2008-04-22 22:49 49152 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038045.exe
2008-02-16 04:32 1024000 C:\WINDOWS\system32\dllcache\browseui.dll
2007-12-06 19:44 1024000 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036118.dll
2008-02-16 04:32 151040 C:\WINDOWS\system32\dllcache\cdfview.dll
2007-12-06 19:44 151040 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036117.dll
2008-02-16 04:32 1054208 C:\WINDOWS\system32\dllcache\danim.dll
2007-12-06 19:44 1054208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036116.dll
2008-02-20 00:32 148992 C:\WINDOWS\system32\dllcache\dnsapi.dll
2006-06-26 12:37 148480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036069.dll
2008-02-16 04:32 357888 C:\WINDOWS\system32\dllcache\dxtmsft.dll
2007-12-06 19:44 357888 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036115.dll
2008-02-16 04:32 205312 C:\WINDOWS\system32\dllcache\dxtrans.dll
2007-12-06 19:44 205824 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036114.dll
2008-02-16 04:32 55808 C:\WINDOWS\system32\dllcache\extmgr.dll
2007-12-06 19:44 55808 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036113.dll
2008-02-20 01:51 282624 C:\WINDOWS\system32\dllcache\gdi32.dll
2007-06-19 08:31 282112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036077.dll
2008-02-15 04:07 18432 C:\WINDOWS\system32\dllcache\iedw.exe
2007-12-06 05:05 18432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036112.exe
2008-02-16 04:32 251904 C:\WINDOWS\system32\dllcache\iepeers.dll
2007-12-06 19:44 251904 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036111.dll
2008-02-16 04:32 96256 C:\WINDOWS\system32\dllcache\inseng.dll
2007-12-06 19:44 96256 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036110.dll
2007-12-18 09:40 450560 C:\WINDOWS\system32\dllcache\jscript.dll
2007-11-14 02:26 450560 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036074.dll
2008-02-16 04:32 16384 C:\WINDOWS\system32\dllcache\jsproxy.dll
2007-12-06 19:44 16384 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036109.dll
2008-02-16 04:32 3066880 C:\WINDOWS\system32\dllcache\mshtml.dll
2007-12-06 19:44 3066368 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036108.dll
2008-02-16 04:32 449024 C:\WINDOWS\system32\dllcache\mshtmled.dll
2007-12-06 19:44 449024 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036107.dll
2008-02-16 04:32 146432 C:\WINDOWS\system32\dllcache\msrating.dll
2007-12-06 19:44 146432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036106.dll
2008-02-16 04:32 532480 C:\WINDOWS\system32\dllcache\mstime.dll
2007-12-06 19:44 532480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036105.dll
2008-02-16 04:32 39424 C:\WINDOWS\system32\dllcache\pngfilt.dll
2007-12-06 19:44 39424 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036104.dll
2008-02-16 04:32 1499136 C:\WINDOWS\system32\dllcache\shdocvw.dll
2007-12-06 19:44 1499136 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036103.dll
2008-02-16 04:32 474112 C:\WINDOWS\system32\dllcache\shlwapi.dll
2007-12-06 19:44 474112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036102.dll
2008-02-16 04:32 618496 C:\WINDOWS\system32\dllcache\urlmon.dll
2007-12-06 19:44 617984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036101.dll
2008-03-19 04:47 1845248 C:\WINDOWS\system32\dllcache\win32k.sys
2007-03-08 08:47 1843584 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036080.sys
2008-02-16 04:32 666112 C:\WINDOWS\system32\dllcache\wininet.dll
2007-12-06 19:44 666112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036100.dll
2008-02-20 00:32 148992 C:\WINDOWS\system32\dnsapi.dll
2006-06-26 12:37 148480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036068.dll
2006-06-26 12:37 148480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036127.dll
2008-02-20 00:32 45568 C:\WINDOWS\system32\dnsrslvr.dll
2006-03-15 23:00 45568 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036067.dll
2006-03-15 23:00 45568 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036126.dll
C:\WINDOWS\system32\drivers\mqacc.sys
2008-06-02 04:16 86144 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036827.sys
2008-02-16 04:32 357888 C:\WINDOWS\system32\dxtmsft.dll
2007-12-06 19:44 357888 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036094.dll
2008-02-16 04:32 205312 C:\WINDOWS\system32\dxtrans.dll
2007-12-06 19:44 205824 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036093.dll
2008-02-16 04:32 55808 C:\WINDOWS\system32\extmgr.dll
2007-12-06 19:44 55808 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036099.dll
C:\WINDOWS\system32\g78.exe
2008-06-02 04:26 401974 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038050.exe
2008-02-20 01:51 282624 C:\WINDOWS\system32\gdi32.dll
2007-06-19 08:31 282112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036129.dll
2008-02-16 04:32 251904 C:\WINDOWS\system32\iepeers.dll
2007-12-06 19:44 251904 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036092.dll
2008-02-16 04:32 96256 C:\WINDOWS\system32\inseng.dll
2007-12-06 19:44 96256 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036091.dll
2007-12-18 09:40 450560 C:\WINDOWS\system32\jscript.dll
2007-11-14 02:26 450560 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036073.dll
2007-11-14 02:26 450560 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036128.dll
2008-02-16 04:32 16384 C:\WINDOWS\system32\jsproxy.dll
2007-12-06 19:44 16384 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036090.dll
C:\WINDOWS\system32\mmwehtdb.dll
2008-06-03 04:32 114688 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037953.dll
2008-05-09 14:35 16863864 C:\WINDOWS\system32\MRT.exe
2008-03-05 08:30 19148408 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036045.exe
2008-03-24 23:50 518944 C:\WINDOWS\system32\msexch40.dll
2006-03-15 23:00 512029 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036063.dll
2008-03-24 23:50 326432 C:\WINDOWS\system32\msexcl40.dll
2006-03-15 23:00 319517 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036062.dll
2008-02-16 04:32 3066880 C:\WINDOWS\system32\mshtml.dll
2007-12-06 19:44 3066368 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036135.dll
2008-02-16 04:32 449024 C:\WINDOWS\system32\mshtmled.dll
2007-12-06 19:44 449024 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036089.dll
2008-03-24 23:50 1516568 C:\WINDOWS\system32\msjet40.dll
2006-03-15 23:00 1507356 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036061.dll
2008-03-24 23:50 355112 C:\WINDOWS\system32\msjetoledb40.dll
2006-03-15 23:00 358976 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036060.dll
2008-03-27 03:12 151583 C:\WINDOWS\system32\msjint40.dll
2006-03-15 23:00 151583 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036059.dll
2008-03-24 23:50 60192 C:\WINDOWS\system32\msjter40.dll
2006-03-15 23:00 53279 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036058.dll
2008-03-24 23:50 248608 C:\WINDOWS\system32\msjtes40.dll
2006-03-15 23:00 241693 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036057.dll
2008-03-24 23:50 219936 C:\WINDOWS\system32\msltus40.dll
2006-03-15 23:00 213023 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036056.dll
2008-03-24 23:50 355104 C:\WINDOWS\system32\mspbde40.dll
2006-03-15 23:00 348189 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036055.dll
2008-02-16 04:32 146432 C:\WINDOWS\system32\msrating.dll
2007-12-06 19:44 146432 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036088.dll
2008-03-24 23:50 432928 C:\WINDOWS\system32\msrd2x40.dll
2006-03-15 23:00 421919 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036054.dll
2008-03-24 23:50 322336 C:\WINDOWS\system32\msrd3x40.dll
2006-03-15 23:00 315423 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036053.dll
2008-03-24 23:50 559904 C:\WINDOWS\system32\msrepl40.dll
2006-03-15 23:00 552989 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036052.dll
2008-03-24 23:50 264992 C:\WINDOWS\system32\mstext40.dll
2006-03-15 23:00 258077 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036051.dll
2008-02-16 04:32 532480 C:\WINDOWS\system32\mstime.dll
2007-12-06 19:44 532480 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036087.dll
2008-03-24 23:50 838432 C:\WINDOWS\system32\mswdat10.dll
2006-03-15 23:00 831519 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036050.dll
2008-03-24 23:50 621344 C:\WINDOWS\system32\mswstr10.dll
2006-03-15 23:00 614429 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036049.dll
2008-03-24 23:50 355104 C:\WINDOWS\system32\msxbde40.dll
2006-03-15 23:00 348189 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036048.dll
C:\WINDOWS\system32\ocntnkdm.exe
2008-06-02 04:26 200773 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038051.exe
2008-02-16 04:32 39424 C:\WINDOWS\system32\pngfilt.dll
2007-12-06 19:44 39424 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036086.dll
C:\WINDOWS\system32\qtopafyn.dll
2008-06-03 04:23 103424 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037954.dll
C:\WINDOWS\system32\rikhlpqu.dll
2008-06-03 04:26 89088 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037955.dll
C:\WINDOWS\system32\rwwnw64d.exe
2008-06-02 04:16 49155 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036708.exe
2008-02-16 04:32 1499136 C:\WINDOWS\system32\shdocvw.dll
2007-12-06 19:44 1499136 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036134.dll
2008-02-16 04:32 474112 C:\WINDOWS\system32\shlwapi.dll
2007-12-06 19:44 474112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036085.dll
2007-12-06 19:44 474112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036133.dll
C:\WINDOWS\system32\ssqrRigE.dll
2008-06-02 04:21 275456 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038052.dll
C:\WINDOWS\system32\sTMP\lutdtx2.exe
2008-05-30 03:33 8790 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038046.exe
2008-02-16 04:32 618496 C:\WINDOWS\system32\urlmon.dll
2007-12-06 19:44 617984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036084.dll
2007-12-06 19:44 617984 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036132.dll
C:\WINDOWS\system32\vbpdtvdp.exe
2008-06-02 04:16 89049 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038053.exe
2007-12-18 09:40 417792 C:\WINDOWS\system32\vbscript.dll
2006-03-15 23:00 417792 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036072.dll
C:\WINDOWS\system32\Vco1\hdpars11.exe
2007-08-14 16:22 25105 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038047.exe
C:\WINDOWS\system32\vntiho18\vntiho182328.exe
2008-05-20 16:13 32768 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036656.exe
2008-02-16 04:32 666112 C:\WINDOWS\system32\wininet.dll
2007-12-06 19:44 666112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036083.dll
2007-12-06 19:44 666112 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036131.dll
C:\WINDOWS\system32\winpfz33.sys
2008-06-02 04:26 860 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038054.sys
2008-02-15 04:06 351744 C:\WINDOWS\system32\xpsp3res.dll
2007-12-06 04:38 350720 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP323\A0036137.dll
C:\WINDOWS\system32\ycinhinf.exe
2008-06-03 04:35 2560 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP333\A0037956.exe
2008-06-02 14:41 21248 C:\WINDOWS\systemcritical.exe
2008-06-02 04:31 30208 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036704.exe
2008-06-02 14:32 24576 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036806.exe
2008-06-02 14:41 30464 C:\WINDOWS\time.exe
2008-06-02 04:31 32256 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036710.exe
2008-06-02 14:32 28416 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036808.exe
C:\WINDOWS\UiBPbWFy\asappsrv.dll
2005-08-02 16:46 187904 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036653.dll
C:\WINDOWS\UiBPbWFy\command.exe
2005-08-02 16:58 293888 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036654.exe
C:\WINDOWS\UiBPbWFy\o21jvqIV.vbs
2005-07-29 16:24 472 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036655.vbs
C:\WINDOWS\uninstall_nmon.vbs
2006-01-03 17:45 1989 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036711.vbs
2008-06-02 14:41 11008 C:\WINDOWS\users32.exe
2008-06-02 04:31 30720 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036712.exe
2008-06-02 14:32 13312 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036810.exe
2008-06-02 14:41 21504 C:\WINDOWS\waol.exe
2008-06-02 04:31 8448 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036713.exe
2008-06-02 14:32 8960 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036812.exe
2008-06-02 14:41 18432 C:\WINDOWS\win32e.exe
2008-06-02 04:31 22784 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036714.exe
2008-06-02 14:32 27392 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036814.exe
2008-06-02 14:41 11776 C:\WINDOWS\win64.exe
2008-06-02 04:31 22272 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036715.exe
2008-06-02 14:32 14080 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036816.exe
2008-06-02 14:41 12288 C:\WINDOWS\winajbm.dll
2008-06-02 04:31 22272 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036716.dll
2008-06-02 14:32 9216 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036818.dll
2008-06-02 14:41 9984 C:\WINDOWS\window.exe
2008-06-02 04:31 16896 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036717.exe
2008-06-02 14:32 31744 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036820.exe
2008-06-02 14:41 19968 C:\WINDOWS\winmgnt.exe
2008-06-02 04:31 29440 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036718.exe
2008-06-02 14:32 9728 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036822.exe
C:\WINDOWS\x.exe
2008-06-02 04:31 9728 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036657.exe
2008-06-02 14:41 26624 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038057.exe
2008-06-02 14:41 14336 C:\WINDOWS\xplugin.dll
2008-06-02 04:31 31232 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036719.dll
2008-06-02 14:32 26624 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036824.dll
C:\WINDOWS\y.exe
2008-06-02 04:31 11776 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP331\A0036658.exe
2008-06-02 14:41 12288 {3A579F61-82CF-4117-919A-DB7B394CD5BC}\RP335\A0038058.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [ ]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-10-18 21:05 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-08-05 23:56 64512]
"hpWirelessAssistant"="C:\Program Files\hpq\HP Wireless Assistant\HP Wireless Assistant.exe" [2006-05-04 00:58 458752]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 23:03 36975]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-08-18 03:00 7585792]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2006-08-18 03:00 86016]
"nwiz"="nwiz.exe" [2006-08-18 03:00 1617920 C:\WINDOWS\system32\nwiz.exe]
"MsmqIntCert"="regsvr32 /s mqrt.dll" []
"High Definition Audio Property Page Shortcut"="CHDAudPropShortcut.exe" [2006-06-01 19:02 61952 C:\WINDOWS\system32\CHDAudPropShortcut.exe]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-04-01 00:01 761946]
"QPService"="C:\Program Files\HP\QuickPlay\QPService.exe" [2006-07-11 23:55 102400]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-17 01:11 49152]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-08-11 18:30 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 18:30 81920]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2006-06-19 13:33 163840]
"Cpqset"="C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe" [2006-05-30 18:02 40960]
"RecGuard"="C:\Windows\SMINST\RecGuard.exe" [2005-10-11 12:23 1187840]
"H2O"="C:\Program Files\SyncroSoft\Pos\H2O\cledx.exe" [2005-11-01 01:00 307200]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-03-12 18:30 517768]
"{2fa0b3b1-cc68-ca3a-5242-f7a2074f24c8}"="C:\WINDOWS\system32\{43451195-72b1-a114-59ec-29f7755ebdb3}.dll" [ ]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 00:05:26 29696]
HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2005-09-24 11:39:30 73728]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"midi2"= KORGUMDD.DRV
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\WINDOWS\\system32\\mqsvc.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
R3 CLEDX;Team H2O CLEDX service;C:\WINDOWS\system32\DRIVERS\cledx.sys [2005-05-09 21:08]
R3 nvsmu;nvsmu;C:\WINDOWS\system32\DRIVERS\nvsmu.sys [2006-03-05 18:49]
S3 5U870CAP_VID_1262&PID_25FD;HP Pavilion Webcam ;C:\WINDOWS\system32\Drivers\5U870CAP.sys [2006-06-06 15:39]
S3 KORGUMDS;KORG USB-MIDI Driver for Windows XP;C:\WINDOWS\system32\Drivers\KORGUMDS.SYS [2004-07-12 02:05]
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-06-04 15:15:08
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
Cpqset = C:\Program Files\Hewlett-Packard\Default Settings\cpqset.exe????????????<?@? ??? Y??????Y?@?????<?@
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\WINDOWS\system32\msdtc.exe
C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\Program Files\Common Files\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\McAfee\MSC\mcpromgr.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\mqsvc.exe
C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
C:\WINDOWS\system32\mqtgsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
C:\PROGRA~1\McAfee.com\Agent\mcagent.exe
C:\PROGRA~1\McAfee\MSC\mcuimgr.exe
.
**************************************************************************
.
Completion time: 2008-06-04 15:17:54 - machine was rebooted
ComboFix-quarantined-files.txt 2008-06-04 20:17:51
ComboFix2.txt 2008-06-04 00:49:37
Pre-Run: 3,494,912,000 bytes free
Post-Run: 3,473,518,592 bytes free
770 --- E O F --- 2008-05-25 08:02:48