Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

i think i have the worst virus in the us core.cache.dsk cant toss it&#


  • Please log in to reply

#1
aonick

aonick

    Member

  • Member
  • PipPip
  • 16 posts
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:18:41 AM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\SUPERAntiSpyware.exe
C:\WINDOWS\system32\MSIEXEC.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 2018 bytes
  • 0

Advertisements


#2
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
System Report
*************

Run on Sun 01/20/2008 at 05:25 AM

Microsoft Windows XP [Version 5.1.2600]

Current user is an administrator

Running Processes:

\SystemRoot\System32\smss.exe [624]
\??\C:\WINDOWS\system32\csrss.exe [672]
\??\C:\WINDOWS\system32\winlogon.exe [696]
C:\WINDOWS\system32\services.exe [740]
C:\WINDOWS\system32\lsass.exe [752]
C:\WINDOWS\system32\svchost.exe [924]
C:\WINDOWS\system32\svchost.exe [972]
C:\WINDOWS\System32\svchost.exe [1012]
C:\WINDOWS\System32\svchost.exe [1108]
C:\WINDOWS\System32\svchost.exe [1160]
C:\WINDOWS\system32\spoolsv.exe [1524]
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe [1648]
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe [1724]
C:\WINDOWS\System32\nvsvc32.exe [1892]
C:\WINDOWS\System32\svchost.exe [1960]
C:\WINDOWS\system32\wdfmgr.exe [2040]
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe [264]
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe [372]
C:\WINDOWS\System32\alg.exe [1372]
C:\WINDOWS\System32\svchost.exe [2440]
C:\WINDOWS\system32\ctfmon.exe [572]
C:\WINDOWS\explorer.exe [3236]
C:\Program Files\Mozilla Firefox\firefox.exe [1956]
C:\Program Files\Internet Explorer\IEXPLORE.EXE [3352]
C:\WINDOWS\System32\wbem\wmiprvse.exe [2216]


Drivers - Running:

SERVICE_NAME: ACPI
SERVICE_NAME: AegisP
SERVICE_NAME: AFD
SERVICE_NAME: Arp1394
SERVICE_NAME: atapi
SERVICE_NAME: audstub
SERVICE_NAME: Avg7Core
SERVICE_NAME: Avg7RsW
SERVICE_NAME: Avg7RsXP
SERVICE_NAME: AvgClean
SERVICE_NAME: Beep
SERVICE_NAME: catchme
SERVICE_NAME: Cdrom
SERVICE_NAME: Disk
SERVICE_NAME: dmio
SERVICE_NAME: dmload
SERVICE_NAME: Fips
SERVICE_NAME: FltMgr
SERVICE_NAME: Ftdisk
SERVICE_NAME: Gpc
SERVICE_NAME: HDAudBus
SERVICE_NAME: hidusb
SERVICE_NAME: HTTP
SERVICE_NAME: i8042prt
SERVICE_NAME: Imapi
SERVICE_NAME: IntcAzAudAddService
SERVICE_NAME: IpNat
SERVICE_NAME: IPSec
SERVICE_NAME: isapnp
SERVICE_NAME: Kbdclass
SERVICE_NAME: kmixer
SERVICE_NAME: KSecDD
SERVICE_NAME: mnmdd
SERVICE_NAME: Mouclass
SERVICE_NAME: mouhid
SERVICE_NAME: MountMgr
SERVICE_NAME: MRxDAV
SERVICE_NAME: MRxSmb
SERVICE_NAME: Msfs
SERVICE_NAME: mssmbios
SERVICE_NAME: Mup
SERVICE_NAME: NDIS
SERVICE_NAME: NdisTapi
SERVICE_NAME: Ndisuio
SERVICE_NAME: NdisWan
SERVICE_NAME: NDProxy
SERVICE_NAME: NetBIOS
SERVICE_NAME: NetBT
SERVICE_NAME: NIC1394
SERVICE_NAME: Npfs
SERVICE_NAME: Ntfs
SERVICE_NAME: Null
SERVICE_NAME: nv
SERVICE_NAME: ohci1394
SERVICE_NAME: PartMgr
SERVICE_NAME: PCI
SERVICE_NAME: PCIIde
SERVICE_NAME: PptpMiniport
SERVICE_NAME: PQNTDrv
SERVICE_NAME: Processor
SERVICE_NAME: PSched
SERVICE_NAME: Ptilink
SERVICE_NAME: PxHelp20
SERVICE_NAME: RasAcd
SERVICE_NAME: Rasl2tp
SERVICE_NAME: RasPppoe
SERVICE_NAME: Raspti
SERVICE_NAME: Rdbss
SERVICE_NAME: RDPCDD
SERVICE_NAME: rdpdr
SERVICE_NAME: redbook
SERVICE_NAME: sr
SERVICE_NAME: Srv
SERVICE_NAME: swenum
SERVICE_NAME: sysaudio
SERVICE_NAME: Tcpip
SERVICE_NAME: TermDD
SERVICE_NAME: Udfs
SERVICE_NAME: Update
SERVICE_NAME: usbcamdd
SERVICE_NAME: usbhub
SERVICE_NAME: usbohci
SERVICE_NAME: VgaSave
SERVICE_NAME: VolSnap
SERVICE_NAME: Wanarp
SERVICE_NAME: wdmaud
SERVICE_NAME: WUSB54GPV4SRV
SERVICE_NAME: GTNDIS5


Drivers - Stopped:

SERVICE_NAME: Abiosdsk
SERVICE_NAME: abp480n5
SERVICE_NAME: ACPIEC
SERVICE_NAME: adpu160m
SERVICE_NAME: aec
SERVICE_NAME: Aha154x
SERVICE_NAME: aic78u2
SERVICE_NAME: aic78xx
SERVICE_NAME: AliIde
SERVICE_NAME: amsint
SERVICE_NAME: asc
SERVICE_NAME: asc3350p
SERVICE_NAME: asc3550
SERVICE_NAME: AsyncMac
SERVICE_NAME: Atdisk
SERVICE_NAME: Atmarpc
SERVICE_NAME: cbidf2k
SERVICE_NAME: cd20xrnt
SERVICE_NAME: Cdaudio
SERVICE_NAME: Cdfs
SERVICE_NAME: Changer
SERVICE_NAME: CmdIde
SERVICE_NAME: Cpqarray
SERVICE_NAME: dac960nt
SERVICE_NAME: dmboot
SERVICE_NAME: DMusic
SERVICE_NAME: dpti2o
SERVICE_NAME: drmkaud
SERVICE_NAME: Fastfat
SERVICE_NAME: Fdc
SERVICE_NAME: Flpydisk
SERVICE_NAME: hpn
SERVICE_NAME: hpt3xx
SERVICE_NAME: i2omgmt
SERVICE_NAME: i2omp
SERVICE_NAME: IKFileSec
SERVICE_NAME: IKSysFlt
SERVICE_NAME: IKSysSec
SERVICE_NAME: ini910u
SERVICE_NAME: IntelIde
SERVICE_NAME: ip6fw
SERVICE_NAME: IpFilterDriver
SERVICE_NAME: IpInIp
SERVICE_NAME: IRENUM
SERVICE_NAME: lbrtfdc
SERVICE_NAME: Modem
SERVICE_NAME: mraid35x
SERVICE_NAME: MSKSSRV
SERVICE_NAME: MSPCLOCK
SERVICE_NAME: MSPQM
SERVICE_NAME: NwlnkFlt
SERVICE_NAME: NwlnkFwd
SERVICE_NAME: Parport
SERVICE_NAME: ParVdm
SERVICE_NAME: PCIDump
SERVICE_NAME: Pcmcia
SERVICE_NAME: PDCOMP
SERVICE_NAME: PDFRAME
SERVICE_NAME: PDRELI
SERVICE_NAME: PDRFRAME
SERVICE_NAME: perc2
SERVICE_NAME: perc2hib
SERVICE_NAME: ql1080
SERVICE_NAME: Ql10wnt
SERVICE_NAME: ql12160
SERVICE_NAME: ql1240
SERVICE_NAME: ql1280
SERVICE_NAME: RDPWD
SERVICE_NAME: Secdrv
SERVICE_NAME: Serial
SERVICE_NAME: Sfloppy
SERVICE_NAME: Simbad
SERVICE_NAME: Sparrow
SERVICE_NAME: splitter
SERVICE_NAME: swmidi
SERVICE_NAME: symc810
SERVICE_NAME: symc8xx
SERVICE_NAME: sym_hi
SERVICE_NAME: sym_u3
SERVICE_NAME: TDPIPE
SERVICE_NAME: TDTCP
SERVICE_NAME: TosIde
SERVICE_NAME: ultra
SERVICE_NAME: usbscan
SERVICE_NAME: ViaIde
SERVICE_NAME: WDICA


Services - Running:

SERVICE_NAME: ALG
SERVICE_NAME: AudioSrv
SERVICE_NAME: Avg7Alrt
SERVICE_NAME: Avg7UpdSvc
SERVICE_NAME: Browser
SERVICE_NAME: CryptSvc
SERVICE_NAME: DcomLaunch
SERVICE_NAME: Dhcp
SERVICE_NAME: dmserver
SERVICE_NAME: Dnscache
SERVICE_NAME: ERSvc
SERVICE_NAME: Eventlog
SERVICE_NAME: EventSystem
SERVICE_NAME: FastUserSwitchingCompatibility
SERVICE_NAME: helpsvc
SERVICE_NAME: HTTPFilter
SERVICE_NAME: lanmanserver
SERVICE_NAME: lanmanworkstation
SERVICE_NAME: LmHosts
SERVICE_NAME: Netman
SERVICE_NAME: Nla
SERVICE_NAME: NVSvc
SERVICE_NAME: PlugPlay
SERVICE_NAME: PolicyAgent
SERVICE_NAME: ProtectedStorage
SERVICE_NAME: RasMan
SERVICE_NAME: RemoteRegistry
SERVICE_NAME: RpcSs
SERVICE_NAME: SamSs
SERVICE_NAME: Schedule
SERVICE_NAME: seclogon
SERVICE_NAME: SENS
SERVICE_NAME: SharedAccess
SERVICE_NAME: ShellHWDetection
SERVICE_NAME: Spooler
SERVICE_NAME: srservice
SERVICE_NAME: SSDPSRV
SERVICE_NAME: stisvc
SERVICE_NAME: TapiSrv
SERVICE_NAME: TermService
SERVICE_NAME: Themes
SERVICE_NAME: TrkWks
SERVICE_NAME: UMWdf
SERVICE_NAME: W32Time
SERVICE_NAME: WebClient
SERVICE_NAME: winmgmt
SERVICE_NAME: wscsvc
SERVICE_NAME: wuauserv
SERVICE_NAME: WUSB54Gv42SVC


Services - Stopped:

SERVICE_NAME: Alerter
SERVICE_NAME: AppMgmt
SERVICE_NAME: BITS
SERVICE_NAME: cisvc
SERVICE_NAME: ClipSrv
SERVICE_NAME: COMSysApp
SERVICE_NAME: dmadmin
SERVICE_NAME: HidServ
SERVICE_NAME: ImapiService
SERVICE_NAME: Messenger
SERVICE_NAME: mnmsrvc
SERVICE_NAME: MSDTC
SERVICE_NAME: MSIServer
SERVICE_NAME: NetDDE
SERVICE_NAME: NetDDEdsdm
SERVICE_NAME: Netlogon
SERVICE_NAME: NtLmSsp
SERVICE_NAME: NtmsSvc
SERVICE_NAME: RasAuto
SERVICE_NAME: RDSessMgr
SERVICE_NAME: RemoteAccess
SERVICE_NAME: RpcLocator
SERVICE_NAME: RSVP
SERVICE_NAME: SCardSvr
SERVICE_NAME: sdAuxService
SERVICE_NAME: sdCoreService
SERVICE_NAME: SwPrv
SERVICE_NAME: SysmonLog
SERVICE_NAME: TlntSvr
SERVICE_NAME: upnphost
SERVICE_NAME: UPS
SERVICE_NAME: Viewpoint Manager Service
SERVICE_NAME: VSS
SERVICE_NAME: WmdmPmSN
SERVICE_NAME: Wmi
SERVICE_NAME: WmiApSrv
SERVICE_NAME: WZCSVC
SERVICE_NAME: xmlprov


Files Created/Modified - 60 Days :


C:\

Jan 7 2008 7:02:38a 0 A.... "C:\AUTOEXEC.BAT"
Jan 7 2008 8:14:30a 211 A.SHR "C:\boot.ini"
Jan 20 2008 4:57:00a 13,003 A.... "C:\ComboFix.txt"
Jan 7 2008 7:02:38a 0 A.... "C:\CONFIG.SYS"
Jan 7 2008 8:22:48a 433 A.... "C:\InstallHelper.log"
Jan 7 2008 7:02:38a 0 A.SHR "C:\IO.SYS"
Jan 7 2008 5:36:04p 472 A..H. "C:\IPH.PH"
Jan 7 2008 7:02:38a 0 A.SHR "C:\MSDOS.SYS"
Jan 7 2008 8:12:26a 47,564 A.SHR "C:\NTDETECT.COM"
Jan 7 2008 8:12:26a 250,032 A.SHR "C:\ntldr"
Jan 20 2008 4:56:12a 2,145,386,496 A.SH. "C:\pagefile.sys"
Jan 20 2008 5:10:30a 2,244 A.... "C:\rapport.txt"


C:\WINDOWS\

Jan 20 2008 4:56:18a 0 A.... "C:\WINDOWS\0.log"
Jan 20 2008 4:56:14a 2,048 A.S.. "C:\WINDOWS\bootstat.dat"
Jan 7 2008 7:02:38a 0 A.... "C:\WINDOWS\control.ini"
Jan 7 2008 8:06:14a 315,392 A.... "C:\WINDOWS\HideWin.exe"
Jan 7 2008 7:41:36a 1,158 A.... "C:\WINDOWS\mozver.dat"
Jan 7 2008 7:16:42a 0 A.... "C:\WINDOWS\nsreg.dat"
Jan 7 2008 7:02:32a 4,161 A.... "C:\WINDOWS\ODBCINST.INI"
Jan 20 2008 4:55:00a 466 A.... "C:\WINDOWS\SchedLgU.Txt"
Jan 20 2008 5:10:18a 120 A.... "C:\WINDOWS\setupact.log"
Jan 20 2008 4:56:26a 733 A.... "C:\WINDOWS\setupapi.log"
Jan 20 2008 5:08:10a 0 A.... "C:\WINDOWS\setuperr.log"
Jan 20 2008 4:37:32a 0 A.... "C:\WINDOWS\Sti_Trace.log"
Jan 20 2008 4:56:26a 227 A.... "C:\WINDOWS\system.ini"
Jan 7 2008 7:50:22a 36 A.... "C:\WINDOWS\tmp.html"
Jan 7 2008 7:00:12a 36 A.... "C:\WINDOWS\vb.ini"
Jan 7 2008 7:00:12a 37 A.... "C:\WINDOWS\vbaddin.ini"
Jan 20 2008 4:56:16a 159 A.... "C:\WINDOWS\wiadebug.log"
Jan 20 2008 4:56:16a 49 A.... "C:\WINDOWS\wiaservc.log"
Jan 7 2008 8:14:30a 519 A.... "C:\WINDOWS\win.ini"
Jan 20 2008 4:57:04a 10,674 A.... "C:\WINDOWS\WindowsUpdate.log"
Jan 7 2008 7:01:58a 749 A..HR "C:\WINDOWS\WindowsShell.Manifest"
Jan 20 2008 3:27:26a 773 A.... "C:\WINDOWS\wininit.ini"
Jan 8 2008 10:23:18a 316,640 A.... "C:\WINDOWS\WMSysPr9.prx"
Jan 7 2008 7:02:36a 299,552 A.... "C:\WINDOWS\WMSysPrx.prx"
Jan 7 2008 7:02:10a 2,421 ..... "C:\WINDOWS\$NtServicePackUninstall$\dataspec.xml"
Jan 7 2008 8:11:06a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00001"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00005"
Jan 7 2008 8:11:08a 12,288 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00018"
Jan 7 2008 8:11:08a 36,864 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00020"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00021"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00070"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00071"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00072"
Jan 7 2008 8:11:08a 16,384 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00073"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00139"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00140"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00172"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00173"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00174"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00178"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00179"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00180"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00181"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00182"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00183"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00184"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00185"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00186"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00196"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00197"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00198"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00199"
Jan 7 2008 8:11:08a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00200"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00201"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00202"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00212"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00213"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00214"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00215"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00216"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00217"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00218"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00219"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00220"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00221"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00222"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00223"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00224"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00225"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00226"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00227"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00228"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00229"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00230"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00231"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00232"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00233"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00234"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00235"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00236"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00237"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00238"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00239"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00240"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00241"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00242"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00243"
Jan 7 2008 8:11:10a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00245"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00247"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00250"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00251"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00252"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00253"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00264"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00265"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00266"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00267"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00268"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00269"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00270"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00271"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00272"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00273"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00274"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00275"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00276"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00277"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00278"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00279"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00280"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00281"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00282"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00283"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00284"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00285"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00286"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00287"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00288"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00289"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00290"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00291"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00292"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00293"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00294"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00299"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00301"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00303"
Jan 7 2008 8:11:12a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00305"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00307"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00309"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00311"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00313"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00315"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00316"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00317"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00318"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00319"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00320"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00321"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00322"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00323"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00324"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00325"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00326"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00327"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00328"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00329"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00330"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00331"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00332"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00333"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00334"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00335"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00336"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00337"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00338"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00339"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00340"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00341"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00342"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00343"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00344"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00345"
Jan 7 2008 8:11:14a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00346"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00347"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00348"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00349"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00350"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00351"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00352"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00353"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00355"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00357"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00358"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00359"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00360"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00364"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00367"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00368"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00373"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00374"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00375"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00499"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00500"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00501"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00502"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00503"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00504"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00505"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00506"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00507"
Jan 7 2008 8:11:16a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00508"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00509"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00510"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00511"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00512"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00513"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00514"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00515"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00516"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00517"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00518"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00519"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00520"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00521"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00522"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00523"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00524"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00525"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00526"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00527"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00528"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00529"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00530"
Jan 7 2008 8:11:18a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00531"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00532"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00533"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00534"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00535"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00536"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00537"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00538"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00539"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00540"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00541"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00542"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00543"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00544"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00545"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00546"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00547"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00548"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00549"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00550"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00551"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00552"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00553"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00554"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00555"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00556"
Jan 7 2008 8:11:20a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00557"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00558"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00559"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00560"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00561"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00562"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00563"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00564"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00565"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00566"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00567"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00568"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00569"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00570"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00571"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00572"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00573"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00574"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00575"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00576"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00577"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00578"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00579"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00580"
Jan 7 2008 8:11:22a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00581"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00582"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00583"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00584"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00585"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00586"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00587"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00588"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00589"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00590"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00591"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00592"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00593"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00594"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00595"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00596"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00597"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00598"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00599"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00600"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00601"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00602"
Jan 7 2008 8:11:24a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00603"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00604"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00605"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00606"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00607"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00608"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00609"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00610"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00611"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00612"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00613"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00614"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00615"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00616"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00617"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00618"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00619"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00620"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00621"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00622"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00623"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00624"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00625"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00626"
Jan 7 2008 8:11:26a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00627"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00628"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00629"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00630"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00631"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00632"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00633"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00634"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00635"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00636"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00637"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00638"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00639"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00640"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00641"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00642"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00643"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00644"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00645"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00646"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00647"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00660"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00661"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00698"
Jan 7 2008 8:11:28a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00699"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00700"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00701"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00702"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00703"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00704"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00705"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00706"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00707"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00708"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00709"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00710"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00711"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00712"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00713"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00714"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00715"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00716"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00717"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00718"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00719"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00720"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00721"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00722"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00723"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00724"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00726"
Jan 7 2008 8:11:30a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00808"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00809"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00812"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00813"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00814"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00815"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00850"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00851"
Jan 7 2008 8:11:32a 16,384 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00852"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00853"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00854"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00855"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00856"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00857"
Jan 7 2008 8:11:32a 94,208 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00858"
Jan 7 2008 8:11:32a 147,456 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00859"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00860"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00864"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00865"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00866"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00867"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00868"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00869"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00876"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00896"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00897"
Jan 7 2008 8:11:32a 28,672 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00903"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00904"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00917"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00920"
Jan 7 2008 8:11:32a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00921"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00923"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00924"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00925"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00926"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00927"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00928"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg00931"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01396"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01397"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01399"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01402"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01403"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01408"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01414"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01428"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01439"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01440"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01441"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01442"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01443"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01444"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01445"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01446"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01447"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01448"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01449"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01450"
Jan 7 2008 8:11:34a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01451"
Jan 7 2008 8:11:36a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01452"
Jan 7 2008 8:11:36a 8,192 A.... "C:\WINDOWS\$NtServicePackUninstall$\reg01453"
Jan 7 2008 8:11:36a 8,192 A.... "C:\WINDOWS\$NtServicePackUninst
  • 0

#3
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
SDFix: Version 1.129

Run by Administrator on Sun 01/20/2008 at 04:13 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

Trojan Files Found:



Could Not Remove C:\WINDOWS\system32\drivers\core.cache.dsk



Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 04:37:49
Windows 5.1.2600 Service Pack 2 NTFS

detected NTDLL code modification:
ZwClose

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\USB\Vid_13b1&Pid_000d\5&13addb57&0&6]
"LocationInformation"="Wireless-G USB Network Adapter"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:0000099e
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}]
"NTEContextList"=str(7):""

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\\Program Files\\uTorrent\\uTorrent.exe"="C:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:µTorrent"
"C:\\kav\\kav7\\setup.exe"="C:\\kav\\kav7\\setup.exe:*:Enabled:Kaspersky Anti-Virus 7.0 Setup"
"C:\\Program Files\\LimeWire\\LimeWire.exe"="C:\\Program Files\\LimeWire\\LimeWire.exe:*:Enabled:LimeWire"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------
C:\WINDOWS\system32\drivers\core.cache.dsk Found

File Backups: - C:\SDFix\backups\backups.zip

Files with Hidden Attributes:


Finished!
  • 0

#4
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
SDFix: Version 1.129

Run by Administrator on Sun 01/20/2008 at 05:37 AM

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:


Restoring Windows Registry Values
Restoring Windows Default Hosts File

Rebooting...


Normal Mode:
Checking Files:

No Trojan Files Found






Removing Temp Files...

ADS Check:

C:\WINDOWS
No streams found.

C:\WINDOWS\system32
No streams found.

C:\WINDOWS\system32\svchost.exe
No streams found.

C:\WINDOWS\system32\ntoskrnl.exe
No streams found.



Final Check:

catchme 0.3.1344.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-01-20 05:40:28
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden services & system hive ...

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Epoch]
"Epoch"=dword:00002ce0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}]
"DhcpServer"="255.255.255.255"
"Lease"=dword:00000e10
"LeaseObtainedTime"=dword:47933324
"T1"=dword:47933a2c
"T2"=dword:47933f72
"LeaseTerminatesTime"=dword:47934134
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}\Parameters\Tcpip]
"DhcpIPAddress"="0.0.0.0"
"DhcpSubnetMask"="255.0.0.0"
"DhcpServer"="255.255.255.255"
"Lease"=dword:00000e10
"LeaseObtainedTime"=dword:47933324
"T1"=dword:47933a2c
"T2"=dword:47933f72
"LeaseTerminatesTime"=dword:47934134

scanning hidden registry entries ...

scanning hidden files ...

scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0


Remaining Services:
------------------



Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

Remaining Files:
---------------


Files with Hidden Attributes:


Finished!
  • 0

#5
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
wow no one knows what this is!!
  • 0

#6
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
Deckard's System Scanner v20071014.68
Run by Administrator on 2008-01-20 11:09:50
Computer is in Normal Mode.
--------------------------------------------------------------------------------

-- System Restore --------------------------------------------------------------

Successfully created a Deckard's System Scanner Restore Point.


-- Last 4 Restore Point(s) --
4: 2008-01-20 17:09:52 UTC - RP4 - Deckard's System Scanner Restore Point
3: 2008-01-20 11:47:46 UTC - RP3 - Software Distribution Service 3.0
2: 2008-01-20 10:53:55 UTC - RP2 - ComboFix created restore point
1: 2008-01-20 10:53:10 UTC - RP1 - System Checkpoint


Backed up registry hives.
Performed disk cleanup.



-- HijackThis (run as Administrator.exe) ---------------------------------------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:10:01 AM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\CCleaner\CCleaner.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Documents and Settings\Administrator\Desktop\dss.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Administrator.exe

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
O23 - Service: WUSB54Gv42SVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

--
End of file - 2285 bytes

-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------

backup-20080115-140124-137 O4 - HKCU\..\RunOnce: [SpybotDeletingB913] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
backup-20080115-140124-154 O4 - HKLM\..\RunOnce: [SpybotDeletingC906] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
backup-20080115-140124-216 O4 - HKCU\..\RunOnce: [SpybotDeletingD8277] cmd /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
backup-20080115-140124-222 O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080115-140124-225 O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
backup-20080115-140124-256 O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
backup-20080115-140124-370 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
backup-20080115-140124-374 O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
backup-20080115-140124-408 O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
backup-20080115-140124-429 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080115-140124-468 O2 - BHO: (no name) - {95ACA637-65AC-3355-8B29-3AE600860CE5} - C:\WINDOWS\system32\utv.dll (file missing)
backup-20080115-140124-483 O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
backup-20080115-140124-485 O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
backup-20080115-140124-551 O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
backup-20080115-140124-609 O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
backup-20080115-140124-622 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
backup-20080115-140124-654 R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080115-140124-714 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
backup-20080115-140124-832 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
backup-20080115-140124-843 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
backup-20080115-140124-913 O4 - HKLM\..\RunOnce: [SpybotDeletingA4634] command /c del "C:\WINDOWS\system32\drivers\core.cache.dsk"
backup-20080115-140124-921 O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
backup-20080115-140124-959 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080115-140124-988 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
backup-20080115-140125-131 O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
backup-20080115-140125-160 O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
backup-20080115-140125-227 O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} - http://www.nvidia.co...iaSmartScan.cab
backup-20080115-140125-322 O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
backup-20080115-140125-334 O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
backup-20080115-140125-352 O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft....k/?linkid=39204
backup-20080115-140125-440 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080115-140125-461 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080115-140125-467 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080115-140125-504 O20 - Winlogon Notify: pmnnnno - pmnnnno.dll (file missing)
backup-20080115-140125-629 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080115-140125-824 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080115-140125-864 O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
backup-20080115-140125-873 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (file missing)
backup-20080115-140141-142 O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
backup-20080115-140141-200 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080115-140141-403 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080115-140141-512 O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
backup-20080115-140141-755 O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
backup-20080115-140141-809 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080116-035328-149 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080116-035328-160 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080116-035328-243 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080116-035328-335 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080116-035328-940 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080116-035747-170 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080116-035747-301 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080116-035747-892 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080116-035747-949 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080116-035759-462 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080116-035759-639 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080116-035759-729 O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
backup-20080116-091818-838 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080116-091818-892 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080117-233629-244 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080117-233629-276 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080117-233629-454 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080117-233629-464 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080117-233629-543 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
backup-20080117-233629-639 O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files\Evidence Eliminator\ee.exe /m
backup-20080117-233629-742 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
backup-20080117-233629-891 O4 - HKLM\..\Run: [ISTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"
backup-20080120-042919-928 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080120-045330-132 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
backup-20080120-045330-238 O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\pctsSvc.exe
backup-20080120-045330-285 O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
backup-20080120-045330-548 O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
backup-20080120-045330-634 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
backup-20080120-045330-666 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
backup-20080120-045330-794 O4 - HKCU\..\Run: [HijackThis startup scan] C:\Program Files\Trend Micro\HijackThis\HijackThis.exe /startupscan
backup-20080120-045330-801 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080120-045330-809 O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Program Files\Spyware Doctor\pctsAuxs.exe
backup-20080120-045330-843 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
backup-20080120-045330-854 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
backup-20080120-045330-933 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft....k/?LinkId=54843
backup-20080120-045330-937 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =

-- File Associations -----------------------------------------------------------

All associations okay.


-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------

R1 PQNTDrv - c:\windows\system32\drivers\pqntdrv.sys <Not Verified; PowerQuest Corporation; PowerQuest product>
R1 usbcamdd - c:\windows\system32\drivers\usbcamdd.sys
R3 GTNDIS5 (GTNDIS5 NDIS Protocol Driver) - c:\windows\system32\gtndis5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>

S3 catchme - c:\docume~1\admini~1\locals~1\temp\catchme.sys (file missing)


-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------

S4 Viewpoint Manager Service - "c:\program files\viewpoint\common\viewpointservice.exe" <Not Verified; Viewpoint Corporation; Viewpoint Manager>


-- Device Manager: Disabled ----------------------------------------------------

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: SM Bus Controller
Device ID: PCI\VEN_10DE&DEV_03EB&SUBSYS_2A61103C&REV_A2\3&2411E6FE&0&09
Manufacturer:
Name: SM Bus Controller
PNP Device ID: PCI\VEN_10DE&DEV_03EB&SUBSYS_2A61103C&REV_A2\3&2411E6FE&0&09
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Universal Serial Bus (USB) Controller
Device ID: PCI\VEN_10DE&DEV_03F2&SUBSYS_2A61103C&REV_A3\3&2411E6FE&0&11
Manufacturer:
Name: Universal Serial Bus (USB) Controller
PNP Device ID: PCI\VEN_10DE&DEV_03F2&SUBSYS_2A61103C&REV_A3\3&2411E6FE&0&11
Service:

Class GUID: {4D36E97E-E325-11CE-BFC1-08002BE10318}
Description: Other PCI Bridge Device
Device ID: PCI\VEN_10DE&DEV_03EF&SUBSYS_2A61103C&REV_A2\3&2411E6FE&0&38
Manufacturer:
Name: Other PCI Bridge Device
PNP Device ID: PCI\VEN_10DE&DEV_03EF&SUBSYS_2A61103C&REV_A2\3&2411E6FE&0&38
Service:


-- Scheduled Tasks -------------------------------------------------------------

2008-01-20 10:56:21 464 --a------ C:\WINDOWS\Tasks\XoftSpySE 2.job
2008-01-20 04:59:49 378 --a------ C:\WINDOWS\Tasks\XoftSpySE.job


-- Files created between 2007-12-20 and 2008-01-20 -----------------------------

2008-01-20 05:51:14 0 d-------- C:\Documents and Settings\LocalService\Application Data\Adobe
2008-01-20 05:51:12 0 dr------- C:\Documents and Settings\LocalService\Favorites
2008-01-20 05:07:20 1286 --a------ C:\WINDOWS\system32\tmp.reg
2008-01-20 05:06:42 25600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-01-20 05:06:42 289144 --a------ C:\WINDOWS\system32\VCCLSID.exe <Not Verified; S!Ri; >
2008-01-20 05:06:42 288417 --a------ C:\WINDOWS\system32\SrchSTS.exe <Not Verified; S!Ri; SrchSTS>
2008-01-20 05:06:42 53248 --a------ C:\WINDOWS\system32\Process.exe <Not Verified; http://www.beyondlogic.org; Command Line Process Utility>
2008-01-20 05:06:42 81920 --a------ C:\WINDOWS\system32\IEDFix.exe <Not Verified; S!Ri.URZ; IEDFix>
2008-01-20 05:06:42 51200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-01-20 04:59:47 0 d-------- C:\Program Files\XoftSpySE
2008-01-20 04:27:51 0 dr-h----- C:\Documents and Settings\Administrator\Recent
2008-01-20 04:12:41 0 d-------- C:\WINDOWS\ERUNT
2008-01-20 02:07:25 0 dr-h----- C:\$VAULT$.AVG
2008-01-16 08:34:03 0 d-------- C:\Program Files\Spyware Doctor
2008-01-16 08:34:03 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-01-16 08:23:06 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-01-16 08:17:55 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-01-16 03:57:02 0 d--hs---- C:\WINDOWS\CSC
2008-01-16 00:00:18 0 d-------- C:\WINDOWS\system32\LogFiles
2008-01-15 14:05:53 0 d-------- C:\Documents and Settings\Administrator\.housecall6.6
2008-01-15 14:05:27 0 d-------- C:\WINDOWS\Sun
2008-01-15 14:05:27 0 d-------- C:\Documents and Settings\Administrator\Application Data\Sun
2008-01-15 14:00:24 0 d-------- C:\Program Files\Trend Micro
2008-01-15 13:45:00 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2008-01-15 02:44:36 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-01-15 02:44:33 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-01-15 02:44:20 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-01-15 02:14:19 0 d-------- C:\Documents and Settings\All Users\Application Data\Avg7
2008-01-15 01:40:15 86144 --a------ C:\WINDOWS\system32\drivers\usbcamdd.sys
2008-01-15 01:31:46 0 d-------- C:\Program Files\Symantec
2008-01-15 01:21:07 0 d-------- C:\Documents and Settings\Administrator\Application Data\Help
2008-01-15 00:54:57 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinBatch
2008-01-14 17:32:52 0 d-------- C:\WINDOWS\network diagnostic
2008-01-14 17:30:35 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-01-14 11:50:43 0 d-------- C:\ebay
2008-01-14 02:00:16 0 d-------- C:\WINDOWS\system32\PreInstall
2008-01-14 02:00:15 0 d--h----- C:\WINDOWS\$hf_mig$
2008-01-14 01:56:37 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-01-14 01:19:09 0 d-------- C:\Documents and Settings\Administrator\WINDOWS
2008-01-13 22:36:09 0 d-------- C:\Program Files\Safer Networking
2008-01-13 22:33:06 0 d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-13 21:15:45 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-01-13 21:15:40 0 d-------- C:\Program Files\Common Files\Adobe
2008-01-10 09:54:26 180224 --a------ C:\WINDOWS\system32\xvidvfw.dll
2008-01-10 09:54:26 765952 --a------ C:\WINDOWS\system32\xvidcore.dll
2008-01-10 09:54:26 0 d-------- C:\Program Files\Xvid
2008-01-10 09:43:23 0 d-------- C:\Documents and Settings\Administrator\Application Data\vlc
2008-01-10 09:31:28 0 d-------- C:\Program Files\VideoLAN
2008-01-10 03:06:42 0 d-------- C:\Documents and Settings\Administrator\Application Data\DivX
2008-01-10 03:05:59 0 d-------- C:\Program Files\DivX
2008-01-09 21:25:46 0 d--hs---- C:\Documents and Settings\Administrator\UserData
2008-01-08 10:23:59 0 d-------- C:\Program Files\DFX
2008-01-08 10:23:09 0 d-------- C:\WINDOWS\RegisteredPackages
2008-01-08 10:22:50 0 d-------- C:\Program Files\Winamp
2008-01-07 17:36:09 0 d-------- C:\Documents and Settings\Administrator\Application Data\acccore
2008-01-07 17:35:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Viewpoint
2008-01-07 17:35:54 0 d-------- C:\Program Files\Viewpoint
2008-01-07 17:35:51 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL OCP
2008-01-07 17:35:50 0 d-------- C:\Documents and Settings\All Users\Application Data\AOL
2008-01-07 17:35:38 0 d-------- C:\Program Files\Common Files\AOL
2008-01-07 17:35:35 0 d-------- C:\Program Files\AIM6
2008-01-07 08:50:29 0 d-------- C:\partys
2008-01-07 08:22:34 0 d-------- C:\Program Files\eBay
2008-01-07 08:22:34 0 d-------- C:\Documents and Settings\All Users\eBay
2008-01-07 08:22:00 0 d-------- C:\WINDOWS\system32\Lang
2008-01-07 08:20:28 49152 --a------ C:\WINDOWS\system32\ChCfg.exe
2008-01-07 08:20:16 0 d-------- C:\WINDOWS\system32\RTCOM
2008-01-07 08:19:45 0 d-------- C:\Program Files\Realtek
2008-01-07 08:19:42 520192 --a------ C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-01-07 08:19:04 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-01-07 08:18:46 0 d-------- C:\Documents and Settings\LocalService\Start Menu
2008-01-07 08:18:05 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-01-07 08:17:57 0 d-------- C:\WINDOWS\Prefetch
2008-01-07 08:14:02 0 d-------- C:\WINDOWS\peernet
2008-01-07 08:14:01 0 d-------- C:\WINDOWS\provisioning
2008-01-07 08:13:23 0 d-------- C:\WINDOWS\ServicePackFiles
2008-01-07 08:11:48 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-01-07 08:10:29 0 d-------- C:\WINDOWS\EHome
2008-01-07 08:06:12 315392 --a------ C:\WINDOWS\HideWin.exe <Not Verified; Realtek Semiconductor Corp.; HD Audio Hide windows program>
2008-01-07 07:54:47 0 d-------- C:\mp3
2008-01-07 07:54:47 0 d-------- C:\Incomplete
2008-01-07 07:54:37 0 d-------- C:\Documents and Settings\Administrator\Incomplete
2008-01-07 07:54:22 0 d-------- C:\Documents and Settings\Administrator\Application Data\LimeWire
2008-01-07 07:54:18 0 d-------- C:\Program Files\Yahoo!
2008-01-07 07:54:14 0 d-------- C:\Program Files\CCleaner
2008-01-07 07:52:24 0 d-------- C:\Program Files\Java
2008-01-07 07:52:05 0 d-------- C:\Program Files\Common Files\Java
2008-01-07 07:51:37 0 d-------- C:\Program Files\LimeWire
2008-01-07 07:50:31 40960 --a------ C:\WINDOWS\system32\eetransx.exe <Not Verified; evidence-eliminator.com; Evidence Eliminator ™>
2008-01-07 07:50:31 61440 --a------ C:\WINDOWS\system32\Eeshellx.dll <Not Verified; evidence-eliminator.com; Evidence Eliminator ™>
2008-01-07 07:50:31 118784 --a------ C:\WINDOWS\system32\EEGenFn1.dll <Not Verified; Robin Hood Software Ltd; EEGenfn1>
2008-01-07 07:50:30 368912 --a------ C:\WINDOWS\system32\vbar332.dll <Not Verified; Microsoft Corporation; Microsoft Visual Basic for Applications>
2008-01-07 07:50:30 0 d-------- C:\Program Files\Evidence Eliminator
2008-01-07 07:49:27 0 d-------- C:\Documents and Settings\Administrator\Application Data\WinRAR
2008-01-07 07:41:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-01-07 07:41:39 0 d-------- C:\Documents and Settings\Administrator\Application Data\Adobe
2008-01-07 07:41:35 1158 --a------ C:\WINDOWS\mozver.dat
2008-01-07 07:37:02 0 d-------- C:\WINDOWS\nview
2008-01-07 07:30:38 0 d-------- C:\Program Files\uTorrent
2008-01-07 07:30:37 0 d-------- C:\Documents and Settings\Administrator\Application Data\uTorrent
2008-01-07 07:16:41 0 --a------ C:\WINDOWS\nsreg.dat
2008-01-07 07:16:40 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-01-07 07:10:44 0 d-------- C:\WINDOWS\win98
2008-01-07 07:10:18 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-01-07 07:10:00 94208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2008-01-07 07:10:00 15872 --a------ C:\WINDOWS\system32\GTNDIS5.sys <Not Verified; Printing Communications Assoc., Inc. (PCAUSA); PCAUSA Rawether for Windows>
2008-01-07 07:09:58 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-07 07:09:56 0 d-------- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor
2008-01-07 07:09:55 0 d-------- C:\Program Files\Common Files\InstallShield
2008-01-07 07:06:24 0 d--hs---- C:\WINDOWS\Installer
2008-01-07 07:06:22 0 d-------- C:\Documents and Settings\Administrator\Application Data\Identities
2008-01-07 07:06:16 0 dr------- C:\Documents and Settings\Administrator\Favorites
2008-01-07 07:06:16 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-01-07 07:06:16 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-01-07 07:06:16 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-01-07 07:06:15 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-01-07 07:06:15 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-01-07 07:06:15 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-01-07 07:06:15 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-01-07 07:06:15 1572864 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-01-07 07:06:15 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-01-07 07:06:15 0 dr------- C:\Documents and Settings\Administrator\My Documents
2008-01-07 07:06:15 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-01-07 07:06:12 0 d--hs---- C:\System Volume Information
2008-01-07 07:06:11 233472 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-01-07 07:06:11 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-01-07 07:06:11 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-01-07 07:06:11 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-01-07 07:06:11 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-01-07 07:06:11 233472 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-01-07 07:06:11 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-01-07 07:06:11 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-01-07 07:06:11 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-01-07 07:06:11 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-01-07 07:02:51 0 d-------- C:\WINDOWS\system32\xircom
2008-01-07 07:02:51 0 d-------- C:\Program Files\microsoft frontpage
2008-01-07 07:02:42 233472 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-01-07 07:02:37 0 -rahs---- C:\MSDOS.SYS
2008-01-07 07:02:37 0 -rahs---- C:\IO.SYS
2008-01-07 07:02:37 0 --a------ C:\CONFIG.SYS
2008-01-07 07:02:37 0 --a------ C:\AUTOEXEC.BAT
2008-01-07 07:02:04 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-01-07 07:01:59 0 dr------- C:\WINDOWS\Offline Web Pages
2008-01-07 07:01:59 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-01-07 07:01:44 0 d-------- C:\WINDOWS\srchasst
2008-01-07 07:01:38 0 d-------- C:\WINDOWS\system32\DirectX
2008-01-07 07:01:37 0 d-------- C:\WINDOWS\system32\Macromed
2008-01-07 07:01:26 0 d-------- C:\Program Files\Movie Maker
2008-01-07 07:01:00 0 d-------- C:\WINDOWS\system32\Restore
2008-01-07 07:00:54 0 d-------- C:\WINDOWS\PCHEALTH
2008-01-07 07:00:48 0 d---s---- C:\WINDOWS\Tasks
2008-01-07 07:00:45 0 d-------- C:\Program Files\Common Files\MSSoap
2008-01-07 07:00:22 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-01-07 07:00:08 0 d-------- C:\WINDOWS\Registration
2008-01-07 07:00:02 0 d--h----- C:\Program Files\WindowsUpdate
2008-01-07 07:00:02 0 d-------- C:\Program Files\Online Services
2008-01-07 06:59:56 0 d-------- C:\Program Files\Messenger
2008-01-07 06:59:48 0 d-------- C:\Program Files\MSN Gaming Zone
2008-01-07 06:59:38 0 d-------- C:\Program Files\Windows NT
2008-01-07 06:59:26 0 d-------- C:\WINDOWS\system32\MsDtc
2008-01-07 06:59:24 0 d-------- C:\WINDOWS\system32\Com
2008-01-07 06:56:13 0 d-------- C:\Program Files\Common Files\ODBC
2008-01-07 06:56:11 0 dr------- C:\Program Files
2008-01-07 06:56:11 0 d-------- C:\Program Files\Common Files
2008-01-07 06:56:11 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-01-07 06:55:50 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-01-07 06:55:50 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-01-07 06:55:50 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-01-07 06:55:50 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-01-07 06:55:50 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-01-07 06:55:50 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-01-07 06:55:50 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-01-07 06:55:50 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-01-07 06:55:50 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-01-07 06:55:50 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-01-07 06:55:50 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-01-07 06:55:50 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-01-07 06:55:50 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-01-07 06:55:50 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-01-07 06:55:50 0 dr------- C:\Documents and Settings\All Users\Documents
2008-01-07 06:55:50 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-01-07 06:55:42 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-01-07 06:55:42 0 d-------- C:\WINDOWS\system32\CatRoot
2008-01-07 06:55:37 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-01-07 06:55:37 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-01-07 06:55:37 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-01-07 06:55:37 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-01-07 06:55:25 0 d-------- C:\Documents and Settings
2008-01-07 06:52:13 0 d-------- C:\WINDOWS
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\WinSxS
2008-01-07 06:52:13 0 dr------- C:\WINDOWS\Web
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\twain_32
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\wins
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\wbem
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\usmt
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\spool
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\ShellExt
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\Setup
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\ras
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\oobe
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\npp
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\mui
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\inetsrv
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\IME
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\icsxml
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\ias
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\export
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\drivers
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-01-07 06:52:13 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\dhcp
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\config
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\3076
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\2052
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1054
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1042
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1041
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1037
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1033
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1031
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1028
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system32\1025
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\system
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\security
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Resources
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\repair
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\mui
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\msapps
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\msagent
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Media
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\java
2008-01-07 06:52:13 0 d--h----- C:\WINDOWS\inf
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\ime
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Help
2008-01-07 06:52:13 0 dr--s---- C:\WINDOWS\Fonts
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Driver Cache
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Debug
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Cursors
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Connection Wizard
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\Config
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\AppPatch
2008-01-07 06:52:13 0 d-------- C:\WINDOWS\addins
2008-01-04 15:58:50 3596288 --a------ C:\WINDOWS\system32\qt-dx331.dll
2008-01-04 15:57:22 196608 --a------ C:\WINDOWS\system32\dtu100.dll <Not Verified; DivX, Inc.; DivX, Inc. dtu100>
2008-01-04 15:57:22 81920 --a------ C:\WINDOWS\system32\dpl100.dll <Not Verified; DivX, Inc.; DivX, Inc. dpl100>
2008-01-04 15:57:12 823296 --a------ C:\WINDOWS\system32\divx_xx07.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-04 15:57:10 802816 --a------ C:\WINDOWS\system32\divx_xx11.dll <Not Verified; DivX, Inc.; DivX?>
2008-01-04 15:57:10 823296 --a------ C:\WINDOWS\system32\divx_xx0c.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-04 15:57:10 682496 --a------ C:\WINDOWS\system32\DivX.dll <Not Verified; DivX, Inc.; DivX®>
2008-01-04 15:56:24 12288 --a------ C:\WINDOWS\system32\DivXWMPExtType.dll


-- Find3M Report ---------------------------------------------------------------

2008-01-07 06:55:50 62 --ahs---- C:\Documents and Settings\Administrator\Application Data\desktop.ini
2007-12-19 13:59:04 1044480 -ra------ C:\WINDOWS\system32\roboex32.dll <Not Verified; eHelp Corporation.; RoboHELP for WinHelp 9.2>
2007-12-19 13:59:04 49152 -ra------ C:\WINDOWS\system32\inetwh32.dll <Not Verified; Blue Sky Software Corporation.; Blue Sky Software - INETWH32>


-- Registry Dump ---------------------------------------------------------------

*Note* empty entries & legit default entries are not shown


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [10/04/2007 11:14 AM]

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HijackThis startup scan"="C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" [01/15/2008 02:00 PM]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [08/03/2004 06:56 PM]

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoLowDiskSpaceChecks"=1 (0x1)

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\vds]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"




-- End of Deckard's System Scanner: finished at 2008-01-20 11:10:57 ------------
  • 0

#7
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
rrrrrrr
  • 0

#8
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
wow no one knows!
  • 0

#9
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
http://www.kaspersky...kavwebscan.html
  • 0

#10
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
nothing works!!!
  • 0

#11
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
ffffff
  • 0

#12
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
SmitFraudFix v2.274

Scan done at 3:17:27.93, Wed 01/23/2008
Run from C:\Program Files\Mozilla Firefox\SmitfraudFix
OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT
The filesystem type is NTFS
Fix run in normal mode

»»»»»»»»»»»»»»»»»»»»»»»» Process

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54Gv42.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\LimeWire\LimeWire.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Grisoft\AVG7\avgwa.dat
C:\Program Files\Spyware Doctor\pctsAuxs.exe
C:\Program Files\Spyware Doctor\pctsSvc.exe
C:\Program Files\Spyware Doctor\pctsTray.exe
C:\WINDOWS\system32\cmd.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

»»»»»»»»»»»»»»»»»»»»»»»» hosts

hosts file corrupted !

127.0.0.1 legal-at-spybot.info
127.0.0.1 www.legal-at-spybot.info

»»»»»»»»»»»»»»»»»»»»»»»» C:\


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32


»»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator


»»»»»»»»»»»»»»»»»»»»»»»» C:\Documents and Settings\Administrator\Application Data


»»»»»»»»»»»»»»»»»»»»»»»» Start Menu


»»»»»»»»»»»»»»»»»»»»»»»» C:\DOCUME~1\ADMINI~1\FAVORI~1


»»»»»»»»»»»»»»»»»»»»»»»» Desktop


»»»»»»»»»»»»»»»»»»»»»»»» C:\Program Files


»»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys


»»»»»»»»»»»»»»»»»»»»»»»» Desktop Components



»»»»»»»»»»»»»»»»»»»»»»»» IEDFix
!!!Attention, following keys are not inevitably infected!!!

IEDFix.exe by S!Ri


»»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler
!!!Attention, following keys are not inevitably infected!!!

SrchSTS.exe by S!Ri
Search SharedTaskScheduler's .dll


»»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=""


»»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System
!!!Attention, following keys are not inevitably infected!!!

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]


»»»»»»»»»»»»»»»»»»»»»»»» Rustock



»»»»»»»»»»»»»»»»»»»»»»»» DNS

Description: Linksys Wireless-G USB Network Adapter #2 - Packet Scheduler Miniport
DNS Server Search Order: 68.105.28.12
DNS Server Search Order: 68.105.29.12
DNS Server Search Order: 68.105.28.11

HKLM\SYSTEM\CCS\Services\Tcpip\..\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11
HKLM\SYSTEM\CS1\Services\Tcpip\..\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11
HKLM\SYSTEM\CS3\Services\Tcpip\..\{F34FD3A0-F0DC-49B4-B9B8-B32841DFBED3}: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11
HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11
HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11
HKLM\SYSTEM\CS3\Services\Tcpip\Parameters: DhcpNameServer=68.105.28.12 68.105.29.12 68.105.28.11


»»»»»»»»»»»»»»»»»»»»»»»» Scanning for wininet.dll infection


»»»»»»»»»»»»»»»»»»»»»»»» End
  • 0

#13
aonick

aonick

    Member

  • Topic Starter
  • Member
  • PipPip
  • 16 posts
this thing is puttin me up the fin wall!
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP