Thanks Rorschach112! Attached are the results of your recommended next steps.
SDFix: Version 1.219 Run by Loren on Sun 08/24/2008 at 08:56 AM
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix
Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting
Checking Files :
No Trojan Files Found
Removing Temp Files
ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-24 16:34:56
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
scanning hidden registry entries ...
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0
Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"="C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe:*:Enabled:AOL Loader"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"="C:\\Program Files\\Bonjour\\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"="C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe:*:Enabled:McAfee Network Agent"
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"="C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\\Program Files\\iTunes\\iTunes.exe"="C:\\Program Files\\iTunes\\iTunes.exe:*:Enabled:iTunes"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"="C:\\Program Files\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Program Files\\MSN Messenger\\livecall.exe"="C:\\Program Files\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
Remaining Files :
Files with Hidden Attributes :
Tue 30 May 2006 61,952 ...H. --- "C:\Program Files\MSN\msnupdate!@#@.exe"
Tue 30 May 2006 308,224 ...H. --- "C:\Program Files\MSN\txsrvc.dll"
Tue 30 May 2006 302,592 ...H. --- "C:\Program Files\MSN\unicows.dll"
Thu 15 May 2003 73,728 A..H. --- "C:\WINDOWS\SYSTEM32\IETie.dll"
Sun 24 Jul 2005 4,348 A.SH. --- "C:\Documents and Settings\All Users\DRM\DRMv1.bak"
Sun 8 Jul 2007 49,152 ...H. --- "C:\Documents and Settings\Bridget\My Documents\~WRL2161.tmp"
Sun 8 Jul 2007 24,064 ...H. --- "C:\Documents and Settings\Bridget\My Documents\~WRL2314.tmp"
Sun 8 Jul 2007 24,576 ...H. --- "C:\Documents and Settings\Bridget\My Documents\~WRL3948.tmp"
Sun 8 Jul 2007 24,064 ...H. --- "C:\Documents and Settings\Bridget\My Documents\~WRL3984.tmp"
Sat 8 Dec 2007 25,088 ...H. --- "C:\Documents and Settings\Loren\My Documents\~WRL0101.tmp"
Tue 4 Dec 2007 25,088 ...H. --- "C:\Documents and Settings\Loren\My Documents\~WRL2171.tmp"
Sun 6 May 2007 20,992 ...H. --- "C:\Documents and Settings\Loren\My Documents\~WRL2962.tmp"
Sun 9 Dec 2007 25,088 ...H. --- "C:\Documents and Settings\Loren\My Documents\~WRL3733.tmp"
Sun 3 Feb 2008 403 A..H. --- "C:\Program Files\InterActual\InterActual Player\iti250.tmp"
Sat 5 Apr 2008 20,487 A.SHR --- "C:\Program Files\McAfee\MQC\MRU.bak"
Sat 5 Apr 2008 265 A.SHR --- "C:\Program Files\McAfee\MQC\qcconf.bak"
Tue 25 Dec 2007 0 A.SH. --- "C:\Documents and Settings\All Users\DRM\Cache\Indiv01.tmp"
Fri 18 Jul 2008 0 A..H. --- "C:\WINDOWS\SoftwareDistribution\Download\fd0264849c01086f3c6b505dc02dbd44\BIT79.tmp"
Sun 24 Jul 2005 4,348 ...H. --- "C:\Documents and Settings\Loren\My Documents\My Music\License Backup\drmv1key.bak"
Fri 7 Oct 2005 20 A..H. --- "C:\Documents and Settings\Loren\My Documents\My Music\License Backup\drmv1lic.bak"
Sat 3 Sep 2005 400 A.SH. --- "C:\Documents and Settings\Loren\My Documents\My Music\License Backup\drmv2key.bak"
Finished!****************************
COMBOFIX LOG
ComboFix 08-08-23.03 - Loren 2008-08-24 17:02:29.2 - NTFSx86
Running from: C:\Documents and Settings\Loren\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Loren\Desktop\CFScript.txt
* Created a new restore point
* Resident AV is active
FILE ::
C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Program Files\JUSearch
C:\Program Files\JUSearch\hcmconf.ini
C:\Program Files\JUSearch\juspc.exe
C:\Program Files\JUSearch\regconf.ini
C:\Program Files\JUSearch\search.log
C:\Program Files\JUSearch\SearchEnh1.dll
C:\Program Files\JUSearch\settings.xml
C:\Program Files\JUSearch\txlog.xml
C:\Program Files\JUSearch\Uninstall.exe
.
((((((((((((((((((((((((( Files Created from 2008-07-24 to 2008-08-24 )))))))))))))))))))))))))))))))
.
2008-08-24 08:50 . 2008-08-24 08:50 <DIR> d-------- C:\WINDOWS\ERUNT
2008-08-24 08:49 . 2008-08-24 08:49 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-08-24 08:44 . 2008-08-24 16:40 <DIR> d-------- C:\SDFix
2008-08-23 09:40 . 2008-08-23 09:40 <DIR> d-------- C:\WINDOWS\Sun
2008-08-23 09:37 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\SYSTEM32\javacpl.cpl
2008-08-23 09:36 . 2008-08-23 09:37 <DIR> d-------- C:\Program Files\Java
2008-08-23 09:35 . 2008-08-23 09:35 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-23 01:54 . 2008-08-23 01:54 <DIR> d-------- C:\Program Files\ERUNT
2008-08-17 09:04 . 2008-08-17 09:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-08-17 03:06 . 2008-08-17 03:06 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-08-16 12:16 . 2008-08-16 12:16 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-08-16 12:16 . 2008-08-16 12:18 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-08-16 12:15 . 2008-08-16 12:15 <DIR> d-------- C:\Program Files\Common Files\HP
2008-08-16 12:08 . 2007-03-17 01:39 958,464 -ra------ C:\WINDOWS\SYSTEM32\hpotiop4.dll
2008-08-16 12:08 . 2007-03-17 01:39 675,840 -ra------ C:\WINDOWS\SYSTEM32\hpowiax4.dll
2008-08-16 12:08 . 2007-03-17 01:39 303,104 -ra------ C:\WINDOWS\SYSTEM32\hpovst11.dll
2008-08-16 12:07 . 2008-08-16 12:16 <DIR> d-------- C:\Program Files\HP
2008-08-16 12:04 . 2008-08-16 12:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-08-16 12:04 . 2008-08-17 09:05 139,811 --a------ C:\WINDOWS\hpoins15.dat
2008-08-16 12:04 . 2007-09-20 15:05 1,039 --------- C:\WINDOWS\hpomdl15.dat
2008-08-16 12:03 . 2007-03-30 10:29 267,864 -ra------ C:\WINDOWS\SYSTEM32\hpzids01.dll
2008-08-16 12:03 . 2007-03-28 14:01 118,272 --a------ C:\WINDOWS\SYSTEM32\hpz3l5ha.dll
2008-08-16 11:59 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\mouhid.sys
2008-08-16 11:59 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\mouhid.sys
2008-08-16 11:59 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\SYSTEM32\DRIVERS\hidusb.sys
2008-08-16 11:59 . 2001-08-17 14:02 9,600 --a------ C:\WINDOWS\SYSTEM32\DLLCACHE\hidusb.sys
2008-07-27 09:39 . 2006-10-26 19:56 32,592 --a------ C:\WINDOWS\SYSTEM32\msonpmon.dll
2008-07-27 09:36 . 2008-07-27 09:36 <DIR> d-------- C:\Program Files\Microsoft Works
2008-07-27 09:34 . 2008-07-27 09:34 <DIR> d-------- C:\Program Files\Microsoft.NET
2008-07-27 09:27 . 2008-08-23 03:22 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-24 21:45 18,688 ----a-w C:\WINDOWS\system32\drivers\USBCRFT.SYS
2008-08-23 06:59 --------- d-----w C:\Program Files\Trend Micro
2008-08-20 02:26 --------- d-----w C:\Program Files\SpywareBlaster
2008-08-17 13:56 --------- d-----w C:\Documents and Settings\Loren\Application Data\AdobeUM
2008-08-17 13:55 --------- d-----w C:\Program Files\Apple Software Update
2008-08-16 17:23 --------- d-----w C:\Program Files\Hewlett-Packard
2008-08-16 16:22 --------- d-----w C:\Program Files\iTunes
2008-08-16 16:21 --------- d-----w C:\Program Files\iPod
2008-08-16 16:14 --------- d-----w C:\Program Files\QuickTime
2008-08-10 23:02 --------- d-----w C:\Documents and Settings\Loren\Application Data\SiteAdvisor
2008-08-02 20:26 --------- d-----w C:\Documents and Settings\Bridget\Application Data\SiteAdvisor
2008-08-02 19:14 --------- d-----w C:\Documents and Settings\Wendy\Application Data\SiteAdvisor
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\SYSTEM32\es.dll
2008-07-07 20:32 253,952 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\es.dll
2008-06-24 16:23 74,240 ----a-w C:\WINDOWS\SYSTEM32\mscms.dll
2008-06-24 16:23 74,240 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mscms.dll
2008-06-24 15:57 3,592,192 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\mshtml.dll
2008-06-23 09:20 70,656 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ie4uinit.exe
2008-06-23 09:20 625,664 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\iexplore.exe
2008-06-23 09:20 13,824 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieudinit.exe
2008-06-21 05:23 161,792 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\ieakui.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\SYSTEM32\mswsock.dll
2008-06-20 17:41 245,248 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\mswsock.dll
2008-06-20 17:41 148,992 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\dnsapi.dll
2008-06-20 10:45 360,320 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip.sys
2008-06-20 10:44 138,368 ------w C:\WINDOWS\SYSTEM32\DLLCACHE\afd.sys
2008-06-20 09:52 225,920 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\tcpip6.sys
2008-06-13 13:10 272,128 ----a-w C:\WINDOWS\SYSTEM32\DLLCACHE\bthport.sys
2005-01-09 15:06 184,680 -c--a-w C:\Documents and Settings\Loren\Application Data\shb.dat
2003-01-04 22:19 207,759 -c--a-w C:\Program Files\INSTALL.LOG
.
((((((((((((((((((((((((((((( snapshot@2008-08-23_ 1.34.50.03 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-07-27 14:35:27 781,104 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2008-08-23 08:13:23 783,744 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Office.Interop.Word\12.0.0.0__71e9bce111e9429c\Microsoft.Office.Interop.Word.dll
+ 2005-10-20 17:02:28 163,328 ----a-w C:\WINDOWS\erdnt\8-23-2008\ERDNT.EXE
+ 2008-08-23 06:56:15 7,024,640 ----a-w C:\WINDOWS\erdnt\8-23-2008\Users\
00000001\ntuser.dat
+ 2008-08-23 06:56:15 135,168 ----a-w C:\WINDOWS\erdnt\8-23-2008\Users\
00000002\UsrClass.dat
+ 2008-08-07 21:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX\ERDNT.EXE
+ 2008-08-24 13:51:20 7,045,120 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000001\ntuser.dat
+ 2008-08-24 13:51:20 278,528 ----a-w C:\WINDOWS\ERUNT\SDFIX\Users\
00000002\UsrClass.dat
+ 2008-08-07 21:27:04 163,328 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\ERDNT.EXE
+ 2008-08-24 13:50:58 7,045,120 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000001\ntuser.dat
+ 2008-08-24 13:50:58 278,528 ----a-w C:\WINDOWS\ERUNT\SDFIX_First_Run\Users\
00000002\UsrClass.dat
+ 2006-10-27 00:49:48 1,011,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109010090400000000000F01FEC\12.0.4518\MSDAIPP.DLL
+ 2006-10-27 00:49:46 970,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002109010090400000000000F01FEC\12.0.4518\MSONSEXT.DLL
+ 2006-10-27 20:00:12 1,751,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACECORE.DLL
+ 2006-10-27 20:00:10 576,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEDAO.DLL
+ 2006-10-27 20:00:06 47,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEERR.DLL
+ 2006-10-27 20:00:08 191,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEES.DLL
+ 2006-10-27 01:13:34 338,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEEXCH.DLL
+ 2006-10-27 01:13:44 629,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEEXCL.DLL
+ 2006-10-27 01:13:28 207,736 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACELTS.DLL
+ 2006-10-27 01:13:32 279,352 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEODBC.DLL
+ 2006-10-27 01:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEODDBS.DLL
+ 2006-10-27 01:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEODEXL.DLL
+ 2006-10-27 01:13:08 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEODPDX.DLL
+ 2006-10-27 01:13:12 15,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEODTXT.DLL
+ 2006-10-27 20:00:06 387,960 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEOLEDB.DLL
+ 2006-10-27 01:13:38 392,048 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEPDE.DLL
+ 2006-10-27 01:13:30 260,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACER2X.DLL
+ 2006-10-27 01:13:32 289,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACER3X.DLL
+ 2006-10-27 01:13:20 56,120 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACERCLR.DLL
+ 2006-10-27 01:13:38 551,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEREP.DLL
+ 2006-10-27 01:13:30 224,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACETXT.DLL
+ 2006-10-27 01:13:34 371,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ACEXBE.DLL
+ 2006-10-27 20:41:04 399,640 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\CDLMSO.DLL
+ 2006-10-27 00:59:24 205,616 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\CLVIEW.EXE
+ 2006-10-27 01:12:52 189,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\CONTACTPICKER.DLL
+ 2006-10-27 00:48:14 439,568 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\DWDCW20.DLL
+ 2006-10-27 00:48:14 434,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\DWTRIG20.EXE
+ 2006-10-26 19:04:58 75,576 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\FORM.DLL
+ 2006-10-27 00:21:24 1,682,232 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\FPSRVUTL.DLL
+ 2006-10-27 20:09:36 983,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\FPWEC.DLL
+ 2006-10-27 01:02:12 2,526,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\GRAPH.EXE
+ 2006-10-27 01:12:52 173,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\IEAWSDC.DLL
+ 2006-10-27 20:10:10 5,281,592 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\IPEDITOR.DLL
+ 2006-10-27 00:55:10 828,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MEDCAT.DLL
+ 2006-10-26 18:58:14 117,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSCONV97.DLL
+ 2006-10-27 20:26:40 16,870,712 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSO.DLL
+ 2006-10-27 19:59:06 161,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSOCF.DLL
+ 2006-10-27 00:48:12 14,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSOCFU.DLL
+ 2006-10-27 01:12:58 428,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSODCW.DLL
+ 2006-10-27 02:13:36 26,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSOEURO.DLL
+ 2006-10-27 01:00:08 6,635,320 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSORES.DLL
+ 2006-10-26 18:56:36 436,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSORUN.DLL
+ 2006-10-27 00:50:04 672,024 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSQRY32.EXE
+ 2006-10-26 18:56:40 505,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSSOAP30.DLL
+ 2006-10-27 00:55:12 832,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSTORDB.EXE
+ 2006-10-27 00:55:06 538,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\MSTORES.DLL
+ 2006-10-27 01:12:30 65,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\NAME.DLL
+ 2006-10-27 20:14:34 14,151,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OART.DLL
+ 2006-10-27 01:06:54 232,816 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ODEPLOY.EXE
+ 2006-10-27 01:14:06 7,033,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OFFOWC.DLL
+ 2006-10-27 20:18:36 1,658,152 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OGL.DLL
+ 2006-10-27 01:00:08 274,744 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OIS.EXE
+ 2006-10-27 01:00:12 998,208 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OISAPP.DLL
+ 2006-10-27 01:00:10 285,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OISGRAPH.DLL
+ 2006-10-27 01:32:42 604,000 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONBTTNIE.DLL
+ 2006-10-27 20:39:36 687,432 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONBTTNOL.DLL
+ 2006-10-27 20:03:04 1,018,664 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONENOTE.EXE
+ 2006-10-27 01:24:54 98,632 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONENOTEM.EXE
+ 2006-10-27 01:24:50 72,504 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONFILTER.DLL
+ 2006-10-27 01:24:58 1,165,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONLIBS.DLL
+ 2006-10-27 20:03:06 6,579,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONMAIN.DLL
+ 2006-10-27 01:23:00 782,720 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\ONSYNCPC.DLL
+ 2006-10-27 01:07:04 6,536,992 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OSETUP.DLL
+ 2006-07-26 23:53:56 459,080 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\OUTLFLTR.DLL
+ 2006-10-27 02:30:44 482,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\PORTCONN.DLL
+ 2006-10-27 00:52:10 2,012,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\PPTVIEW.EXE
+ 2006-10-26 19:05:00 77,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\PSOM.DLL
+ 2006-10-27 02:13:38 38,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\REFEDIT.DLL
+ 2006-10-26 19:04:44 19,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\REVERSE.DLL
+ 2006-10-27 01:13:00 503,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\SELFCERT.EXE
+ 2006-10-27 01:06:58 439,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\SETUP.EXE
+ 2006-10-27 19:57:08 2,330,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\STSLIST.DLL
+ 2006-10-26 19:04:48 29,976 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\THOCRAPI.DLL
+ 2006-10-26 19:05:04 126,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWCUTCHR.DLL
+ 2006-10-26 19:05:02 86,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWCUTLIN.DLL
+ 2006-10-26 19:04:56 58,168 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWLAY32.DLL
+ 2006-10-26 19:04:48 27,456 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWORIENT.DLL
+ 2006-10-26 19:04:54 51,008 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWRECE.DLL
+ 2006-10-26 19:04:44 19,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWRECS.DLL
+ 2006-10-26 19:04:58 76,624 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\TWSTRUCT.DLL
+ 2006-10-27 04:00:12 1,841,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\VVIEWDWG.DLL
+ 2006-10-27 03:58:38 3,732,792 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\VVIEWER.DLL
+ 2008-07-27 14:35:27 781,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\WORDPIA.DLL
+ 2006-10-26 19:05:08 1,181,520 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\XIMAGE3B.DLL
+ 2006-10-26 19:05:08 530,760 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.4518\XPAGE3C.DLL
+ 2007-05-09 22:19:48 2,585,936 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\
00002119F20000000000000000F01FEC\12.0.6215\VBE6.DLL
- 2008-07-27 14:47:38 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
+ 2008-08-23 08:22:05 217,864 ----a-r C:\WINDOWS\Installer\{90120000-006E-0409-0000-0000000FF1CE}\misc.exe
- 2008-08-16 08:42:03 20,240 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-08-23 08:16:02 20,240 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-08-16 08:42:01 184,080 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-08-23 08:16:00 184,080 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\joticon.exe
- 2008-08-16 08:42:02 217,864 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
+ 2008-08-23 08:16:02 217,864 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\misc.exe
- 2008-08-16 08:42:03 18,704 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-08-23 08:16:03 18,704 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-08-16 08:42:03 35,088 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-08-23 08:16:03 35,088 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-08-16 08:42:02 922,384 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-08-23 08:16:01 922,384 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\pptico.exe
- 2008-08-16 08:42:03 888,080 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
+ 2008-08-23 08:16:03 888,080 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-08-16 08:42:01 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-08-23 08:15:59 1,172,240 ----a-r C:\WINDOWS\Installer\{91120000-002F-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-08-23 06:06:32 32,768 -c--a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
+ 2008-08-24 21:33:17 32,768 -c--a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
- 2008-08-23 06:06:32 32,768 -c--a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2008-08-24 21:33:17 32,768 -c--a-w C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2007-06-06 15:53:34 1,195,888 ----a-w C:\WINDOWS\SYSTEM32\FM20.DLL
+ 2007-08-23 06:03:38 1,195,888 ----a-w C:\WINDOWS\SYSTEM32\FM20.DLL
+ 2008-06-10 06:21:01 135,168 ----a-w C:\WINDOWS\SYSTEM32\java.exe
+ 2008-06-10 06:21:04 135,168 ----a-w C:\WINDOWS\SYSTEM32\javaw.exe
+ 2008-06-10 07:32:34 139,264 ----a-w C:\WINDOWS\SYSTEM32\javaws.exe
+ 2007-08-23 05:18:08 96,256 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_cbb27474\ATL80.dll
+ 2007-08-23 05:18:08 1,101,824 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80.dll
+ 2007-08-23 05:18:08 1,093,120 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfc80u.dll
+ 2007-08-23 05:18:08 69,632 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80.dll
+ 2007-08-23 05:18:08 57,856 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_3bf8fa05\mfcm80u.dll
+ 2007-08-23 05:18:08 40,960 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHS.dll
+ 2007-08-23 05:18:08 45,056 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80CHT.dll
+ 2007-08-23 05:18:08 65,536 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80DEU.dll
+ 2007-08-23 05:18:08 57,344 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ENU.dll
+ 2007-08-23 05:18:08 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ESP.dll
+ 2007-08-23 05:18:08 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80FRA.dll
+ 2007-08-23 05:18:08 61,440 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80ITA.dll
+ 2007-08-23 05:18:08 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80JPN.dll
+ 2007-08-23 05:18:08 49,152 ----a-w C:\WINDOWS\WinSxS\x86_Microsoft.VC80.MFCLOC_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_91481303\mfc80KOR.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MsnMsgr"="C:\Program Files\MSN Messenger\MsnMsgr.Exe" [2007-01-19 12:54 5674352]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" [2006-11-16 20:04 139264]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"DelayShred"="c:\program files\mcafee\mshr\ShrCL.EXE" [2007-12-04 13:32 111904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-19 08:59 155648]
"HotKeysCmds"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-19 08:59 126976]
"AdaptecDirectCD"="C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe" [2002-04-10 17:44 679936]
"DwlClient"="C:\Program Files\Common Files\Dell\EUSW\Support.exe" [2004-05-27 21:05 323584]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2003-09-13 22:36 50688]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [2006-12-19 21:37 36952]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-08-04 02:33 582992]
"NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2006-01-12 16:40 155648]
"Media Codec Update Service"="C:\Program Files\Essentials Codec Pack\update.exe" [2007-04-08 11:44 303104]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2008-03-29 02:26 185896]
"AppleSyncNotifier"="C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-22 20:42 116040]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-05-27 10:50 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-07-30 10:47 289064]
"HP Software Update"="C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2007-03-11 21:34 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"SpySweeper"="C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" [2007-03-21 14:54 5078592]
"BCMSMMSG"="BCMSMMSG.exe" [2003-08-29 04:59 122880 C:\WINDOWS\BCMSMMSG.exe]
"Dit"="Dit.exe" [2004-12-17 14:21 94208 C:\WINDOWS\Dit.exe]
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"C:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"C:\\Program Files\\MSN Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
R3 CardReaderFilter;Card Reader Filter;C:\WINDOWS\system32\Drivers\USBCRFT.SYS [2008-08-24 16:45]
S0 ppa;Iomega Parallel Port Filter Driver;C:\WINDOWS\System32\DRIVERS\ppa.sys [2001-08-17 14:53]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2004-12-11 C:\WINDOWS\Tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1102778278.job
- C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpqfrucl.exe [2003-04-06 01:52]
2008-07-15 C:\WINDOWS\Tasks\McDefragTask.job
- C:\WINDOWS\system32\defrag.exe [2004-08-04 02:56]
2008-08-01 C:\WINDOWS\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-24 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job
- C:\Program Files\SpywareBot\SpywareBot.exe []
2008-08-24 C:\WINDOWS\Tasks\SpywareBot Scheduled Scan.job
- C:\Program Files\SpywareBot []
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070209221549.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2007-03-21 14:55]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070401180509.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2007-03-21 14:55]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070401180546.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2007-03-21 14:55]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070401180553.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2007-03-21 14:55]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070401180629.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe [2007-03-21 14:55]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070509232027.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-03-21 14:54]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070509232027.job
- C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe [2007-03-21 14:54]
2008-08-24 C:\WINDOWS\Tasks\wrSpySweeper20070509232027.job
- A:\","C:\","D:\","E:\" []
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-24 17:06:23
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2008-08-24 17:23:56
ComboFix-quarantined-files.txt 2008-08-24 22:23:50
ComboFix2.txt 2008-08-23 06:38:05
Pre-Run: 26,494,115,840 bytes free
Post-Run: 26,478,620,672 bytes free
325 --- E O F --- 2008-08-23 08:22:54
During the Combofix run, I also had a Window pop-up with the following:
Windows - No Disc
Exception processing messgae c0000013 Parameters 75b6bf9c4 75b6bf9c 75b6bf9c
Is this related or should I do a separate post?
Thanks for your help!!!