1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Host File Infected Page 1

Discussion in 'Malware and Virus Removal Archive' started by Fredb38, 2008/12/30.

  1. 2008/12/30
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    [Resolved] Host File Infected Page 1

    This problem started out with Web sites being blocked. I found with everybody's help that my Host file was infected. The file was rebuilt and that problem was solved. It was suggest that I run rsit.exe and post the out come to see if I have more problems. Please find the log files listed below.
    info.txt logfile of random's system information tool 1.05 2008-12-30 22:05:59

    ======Uninstall list======

    --> "C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\setup\ccinstaller.exe" /u /silent /module= "fw "
    --> "C:\Program Files\HP Games\Bejeweled 2 Deluxe\Uninstall.exe "
    --> "C:\Program Files\HP Games\Blackhawk Striker 2\Uninstall.exe "
    --> "C:\Program Files\HP Games\Blasterball 3\Uninstall.exe "
    --> "C:\Program Files\HP Games\Boggle Supreme\Uninstall.exe "
    --> "C:\Program Files\HP Games\Bookworm Adventures\Uninstall.exe "
    --> "C:\Program Files\HP Games\Cake Mania\Uninstall.exe "
    --> "C:\Program Files\HP Games\Chessmaster Challenge\Uninstall.exe "
    --> "C:\Program Files\HP Games\Chuzzle Deluxe\Uninstall.exe "
    --> "C:\Program Files\HP Games\Crystal Maze\Uninstall.exe "
    --> "C:\Program Files\HP Games\Diner Dash - Flo on the Go\Uninstall.exe "
    --> "C:\Program Files\HP Games\Family Feud\Uninstall.exe "
    --> "C:\Program Files\HP Games\FATE\Uninstall.exe "
    --> "C:\Program Files\HP Games\Final Drive Nitro\Uninstall.exe "
    --> "C:\Program Files\HP Games\Insaniquarium Deluxe\Uninstall.exe "
    --> "C:\Program Files\HP Games\JEOPARDY\Uninstall.exe "
    --> "C:\Program Files\HP Games\Jewel Quest 2 - Tournament Edition\Uninstall.exe "
    --> "C:\Program Files\HP Games\Luxor 2\Uninstall.exe "
    --> "C:\Program Files\HP Games\Mah Jong Quest\Uninstall.exe "
    --> "C:\Program Files\HP Games\My HP Game Console\Uninstall.exe "
    --> "C:\Program Files\HP Games\Peggle\Uninstall.exe "
    --> "C:\Program Files\HP Games\Penguins!\Uninstall.exe "
    --> "C:\Program Files\HP Games\Poker Superstars 2\Uninstall.exe "
    --> "C:\Program Files\HP Games\Polar Bowler\Uninstall.exe "
    --> "C:\Program Files\HP Games\Polar Golfer Pineapple Cup\Uninstall.exe "
    --> "C:\Program Files\HP Games\Polar Golfer\Uninstall.exe "
    --> "C:\Program Files\HP Games\SpongeBob SquarePants 3D Obstacle Odyssey\Uninstall.exe "
    --> "C:\Program Files\HP Games\Super Granny 3\Uninstall.exe "
    --> "C:\Program Files\HP Games\Swarm\Uninstall.exe "
    --> "C:\Program Files\HP Games\Tank-o-Box\Uninstall.exe "
    --> "C:\Program Files\HP Games\The Treasures of Montezuma\Uninstall.exe "
    --> "C:\Program Files\HP Games\Tradewinds\Uninstall.exe "
    --> "C:\Program Files\HP Games\Wheel of Fortune\Uninstall.exe "
    32 Bit HP CIO Components Installer-->MsiExec.exe /I{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}
    Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Reader 8.1.3-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A81300000003}
    AnswerWorks 5.0 English Runtime-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}\setup.exe" -l0x9 -uninst -removeonly
    ArcSoft Print Creations - Album Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1AlbumPage
    ArcSoft Print Creations - Brochures & Flyers-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1Brochure
    ArcSoft Print Creations - Funhouse II-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1HouseFun
    ArcSoft Print Creations - Funhouse-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1Funhouse
    ArcSoft Print Creations - Greeting Card-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1GreetingCard
    ArcSoft Print Creations - Photo Book-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1PhotoBook
    ArcSoft Print Creations - Photo Calendar-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1Calendar
    ArcSoft Print Creations - Photo Prints-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1PhotoPrint
    ArcSoft Print Creations - Poster Creator-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1Poster
    ArcSoft Print Creations - Quick Photo Book-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1OneTouch
    ArcSoft Print Creations - Scrapbook-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1ScrapBook
    ArcSoft Print Creations - Slimline Card-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9 -1Slimline
    ArcSoft Print Creations-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{271C6608-69FD-4D6E-933C-4C08742AA33C}\Setup.exe" -l0x9
    Ashampoo Burning Studio 8.04--> "I:\Program Files\Ashampoo Burning Studio 8\unins000.exe "
    Ashampoo DVD Theme Pack 1-->C:\PROGRA~1\UNWISE.EXE C:\PROGRA~1\INSTALL.LOG
    Ashampoo Music Studio 3--> "I:\Program Files\Ashampoo\Ashampoo Music Studio 3\Uninstall\0230_Uninstall.EXE "
    Ashampoo Photo Commander 7.10--> "I:\Program Files\Ashampoo\Ashampoo Photo Commander 7\unins000.exe "
    AVS DVDMenu Editor 1.2.1.19--> "C:\Program Files\Common Files\AVSMedia\AVS DVDMenu Editor\unins000.exe "
    AVS Video Tools 5.6--> "I:\Program Files\VideoTools\unins000.exe "
    CA Anti-Spyware--> "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\setup\ccinstaller.exe" /u /silent /module= "pp "
    CA Anti-Virus-->C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\unvet32.exe
    CA Internet Security Suite--> "C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u
    CA Pest Patrol Realtime Protection-->MsiExec.exe /X{F05A5232-CE5E-4274-AB27-44EB8105898D}
    CA Website Inspector-->C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\CAWebsiteInspector.exe /uninstall
    ConvertXtoDVD 3.3.2.100--> "I:\Program Files\Convert X to DVD\3\unins000.exe "
    Enhanced Multimedia Keyboard Solution-->C:\HP\KBD\Install.exe /u
    FotoFusionV4-->C:\Windows\FotoFusionV4 Uninstaller.exe
    Google Gmail Notifier--> "C:\Program Files\Google\Gmail Notifier\UninstallGmail.exe "
    Hardware Diagnostic Tools-->C:\Program Files\PC-Doctor 5 for Windows\uninst.exe
    Hewlett-Packard Active Check-->MsiExec.exe /X{254C37AA-6B72-4300-84F6-98A82419187E}
    Hewlett-Packard Asset Agent for Health Check-->MsiExec.exe /X{669D4A35-146B-4314-89F1-1AC3D7B88367}
    HijackThis 2.0.2--> "C:\Program Files\trend micro\HijackThis.exe" /uninstall
    HP Active Support Library 32 bit components-->MsiExec.exe /I{6D3DB611-D5E8-4E4B-8952-0D3F549F9CC6}
    HP Active Support Library-->C:\Program Files\InstallShield Installation Information\{0A47BAFF-D4FF-4BD3-96CA-02A22EA62722}\setup.exe -runfromtemp -l0x0409
    HP Customer Experience Enhancements-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AB5E289E-76BF-4251-9F3F-9B763F681AE0}\setup.exe" -l0x9 -removeonly
    HP Customer Feedback-->MsiExec.exe /I{9DBA770F-BF73-4D39-B1DF-6035D95268FC}
    HP Customer Participation Program 8.0-->C:\Program Files\HP\Digital Imaging\ExtCapUninstall\hpzscr01.exe -datfile hpqhsc01.dat
    HP Easy Setup - Frontend-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40F7AED3-0C7D-4582-99F6-484A515C73F2}\setup.exe" -l0x9 -removeonly
    HP Imaging Device Functions 8.0-->C:\Program Files\HP\Digital Imaging\DeviceManagement\hpzscr01.exe -datfile hpqbud01.dat
    HP OCR Software 8.0-->C:\Program Files\HP\Digital Imaging\OCR\hpzscr01.exe -datfile hpqbud11.dat
    HP On-Screen Cap/Num/Scroll Lock Indicator-->C:\Windows\system32\OsdRemove.exe
    HP Photosmart Essential 3.5-->C:\Program Files\HP\Digital Imaging\PhotosmartEssential\hpzscr01.exe -datfile hpqbud13.dat
    HP Photosmart Essential-->MsiExec.exe /X{EB21A812-671B-4D08-B974-2A347F0D8F70}
    HP Photosmart.All-In-One Driver Software 8.0 .A-->C:\Program Files\HP\Digital Imaging\{282E5AB2-8E47-4571-B6FA-6B512555B557}\setup\hpzscr01.exe -datfile hposcr18.dat -onestop -showdisconnect -forcereboot
    HP Picasso Media Center Add-In-->MsiExec.exe /I{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}
    HP Product Assistant-->MsiExec.exe /I{36FDBE6E-6684-462B-AE98-9A39A1B200CC}
    HP Solution Center 8.0-->C:\Program Files\HP\Digital Imaging\eSupport\hpzscr01.exe -datfile hpqbud05.dat
    HP Total Care Advisor-->MsiExec.exe /X{0DDA7620-4F8B-43B3-8828-CA5EE292FA3B}
    HP Update-->MsiExec.exe /X{FE57DE70-95DE-4B64-9266-84DA811053DB}
    HPSSupply-->MsiExec.exe /X{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}
    ImTOO DVD Ripper Ultimate-->I:\Program Files\DVD Ripper Ultimate 5\Uninstall.exe
    IrfanView (remove only)-->I:\Program Files\IrfanView\iv_uninstall.exe
    Java(TM) SE Runtime Environment 6 Update 1-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010}
    LightScribe System Software 1.14.17.1-->MsiExec.exe /X{0E7DBD52-B097-4F2B-A7C7-F105B0D20FDB}
    LimeWire 4.18.8--> "I:\Program Files\LimeWire\uninstall.exe "
    Loan Calculator! Plus v2.5-->C:\PROGRA~1\LOANCA~1\UNWISE.EXE C:\PROGRA~1\LOANCA~1\INSTALL.LOG
    Magic DVD Copier Version 4.9 build 3--> "I:\Program Files\MagicDVDCopier\unins000.exe "
    Magic ISO Maker v5.5 (build 0272)-->I:\PROGRA~1\MagicISO\UNWISE.EXE I:\PROGRA~1\MagicISO\INSTALL.LOG
    Microsoft Office Home and Student 60 day trial-->c:\hp\bin\MSOffice\uninst2.cmd
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
    Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
    Mindful version 2--> "C:\Program Files\Felitec\Mindful 2\unins000.exe "
    Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
    muvee autoProducer 6.0-->C:\Program Files\InstallShield Installation Information\{14AF024E-2E3B-49D0-A175-D1C1A06B155A}\setup.exe -runfromtemp -l0x0009 -removeonly
    My HP Games--> "C:\Program Files\HP Games\Uninstall.exe "
    Nero 9-->C:\Program Files\Common Files\Nero\Nero ProductInstaller 4\SetupX.exe REMOVESERIALNUMBER= "9M03-01A1-PCX7-K31A-8A94-98PT-KT2E-522A "
    neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B}
    NVIDIA Drivers-->C:\Windows\system32\NVUNINST.EXE UninstallGUI
    Photo Collage Maker 1.81--> "I:\Program Files\Photo Collage Maker\unins000.exe "
    Photo Collage Platinum 2.04-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6D7FBAB1-1BD8-45F9-AC29-F872546513E6}\Setup.exe"
    Picasa 3--> "I:\Program Files\Picasa3\Uninstall.exe "
    Picture Collage Maker-->MsiExec.exe /I{FA6A9266-244B-4965-8686-87DE52B7BACD}
    ProShow Gold-->I:\Program Files\Photodex\uninst.exe
    Python 2.5-->MsiExec.exe /I{0A2C5854-557E-48C8-835A-3B9F074BDCAA}
    Quick AVI Splitter v2.0--> "I:\Program Files\Quick AVI Splitter\unins000.exe "
    Quicken 2008-->MsiExec.exe /X{3B0F52AC-EF5C-4831-B221-06C782E41280}
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
    RegCure 1.5.1.3-->I:\Program Files\RegCure\uninst.exe
    Rhapsody Player Engine-->MsiExec.exe /I{2DFF31F9-7893-4922-AF66-C9A1EB4EBB31}
    Rhapsody-->C:\PROGRA~1\Rhapsody\Unwise32.exe /A C:\PROGRA~1\Rhapsody\install.log
    Roxio Activation Module-->MsiExec.exe /I{35E1EC43-D4FC-4E4A-AAB3-20DDA27E8BB0}
    Roxio Creator Audio-->MsiExec.exe /X{83FFCFC7-88C6-41c6-8752-958A45325C82}
    Roxio Creator Basic v9-->MsiExec.exe /X{C8B0680B-CDAE-4809-9F91-387B6DE00F7C}
    Roxio Creator Copy-->MsiExec.exe /X{619CDD8A-14B6-43a1-AB6C-0F4EE48CE048}
    Roxio Creator Data-->MsiExec.exe /X{0D397393-9B50-4c52-84D5-77E344289F87}
    Roxio Creator EasyArchive-->MsiExec.exe /X{11F93B4B-48F0-4A4E-AE77-DFA96A99664B}
    Roxio Creator Tools-->MsiExec.exe /X{0394CDC8-FABD-4ed8-B104-03393876DFDF}
    Roxio Express Labeler 3-->MsiExec.exe /X{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}
    Roxio MyDVD Basic v9-->MsiExec.exe /X{938B1CD7-7C60-491E-AA90-1F1888168240}
    Seagate Manager Installer--> "C:\Program Files\InstallShield Installation Information\{71883667-71F2-48A1-AB72-28D518D8AC4A}\setup.exe" -runfromtemp -l0x0409 -removeonly
    Seagate Manager Installer-->MsiExec.exe /X{71883667-71F2-48A1-AB72-28D518D8AC4A}
    SnagIt 8-->MsiExec.exe /I{DA0BF7AB-88EB-4675-8FA1-531EAD938821}
    Snapfish Picture Mover-->MsiExec.exe /X{029B5901-1F27-4347-9923-E8ACC8F54E15}
    Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_VEN_14F1&DEV_2F20&SUBSYS_200C14F1\UIU32m.exe -U -ITrx200Cz.INF
    Spelling Dictionaries Support For Adobe Reader 8-->MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003}
    WeatherBug Gadget-->MsiExec.exe /I{209CDA54-D390-46A2-A97C-7BF61734418D}
    WinPatrol 2008-->I:\PROGRA~1\WINPAT~1\Setup.exe /remove /q0
    WinRAR--> "C:\Windows\WinRAR\uninstall.exe" "/U:I:\Program Files\WinRar\Uninstall\uninstall.xml "
    WinZip 12.0-->MsiExec.exe /X{CD95F661-A5C4-44F5-A6AA-ECDD91C240B7}
    Wondershare DVD Slideshow Builder 4.3.0 Trial Version--> "I:\Program Files\DVD Slideshow Builder\unins000.exe "
    Wondershare Photo Story Platinum trial version 3.0.0--> "I:\Program Files\Photo Story Platinum\Photo Story Platinum\unins000.exe "
    Yahoo! Search Protection-->C:\PROGRA~1\Yahoo!\SEARCH~1\UNINST~1.EXE
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\unyt.exe

    ======Hosts File======

    Message: The Application Information service entered the running state.
    Record Number: 21901
    Source Name: Service Control Manager
    Time Written: 20081231013924.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 3004
    Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
    For more information please see the following:
    Not Applicable
    Scan ID: {B6C79D9E-3FE4-4CEA-AA56-2293B8E56B41}
    User: Fred-PC\Fred
    Name: Unknown
    ID:
    Severity ID:
    Category ID:
    Path Found: file:C:\Windows\system32\drivers\etc\HOSTS
    Alert Type: Unclassified software
    Detection Type:
    Record Number: 21902
    Source Name: Microsoft-Windows-Windows Defender
    Time Written: 20081231021837.000000-000
    Event Type: Warning
    User:

    Computer Name: Fred-PC
    Event Code: 3005
    Message: Windows Defender Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software.
    For more information please see the following:
    Not Applicable
    Scan ID: {B6C79D9E-3FE4-4CEA-AA56-2293B8E56B41}
    User: Fred-PC\Fred
    Name: Unknown
    ID:
    Severity ID:
    Category ID:
    Alert Type: Unclassified software
    Action: Ignore
    Record Number: 21903
    Source Name: Microsoft-Windows-Windows Defender
    Time Written: 20081231021837.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 3004
    Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
    For more information please see the following:
    Not Applicable
    Scan ID: {0E0C6F36-52C0-4DC8-A4B7-729CDDECD353}
    User: Fred-PC\Fred
    Name: Unknown
    ID:
    Severity ID:
    Category ID:
    Path Found: file:C:\Windows\system32\drivers\etc\HOSTS
    Alert Type: Unclassified software
    Detection Type:
    Record Number: 21904
    Source Name: Microsoft-Windows-Windows Defender
    Time Written: 20081231024621.000000-000
    Event Type: Warning
    User:

    Computer Name: Fred-PC
    Event Code: 3005
    Message: Windows Defender Real-Time Protection agent has taken action to protect this machine from spyware or other potentially unwanted software.
    For more information please see the following:
    Not Applicable
    Scan ID: {0E0C6F36-52C0-4DC8-A4B7-729CDDECD353}
    User: Fred-PC\Fred
    Name: Unknown
    ID:
    Severity ID:
    Category ID:
    Alert Type: Unclassified software
    Action: Ignore
    Record Number: 21905
    Source Name: Microsoft-Windows-Windows Defender
    Time Written: 20081231024621.000000-000
    Event Type: Information
    User:

    Application event log

    Computer Name: Fred-PC
    Event Code: 88
    Message: Shell is started at session 1
    Record Number: 4728
    Source Name: UmxAgent
    Time Written: 20081231021449.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 88
    Message: explorer.exe started
    Record Number: 4729
    Source Name: UmxAgent
    Time Written: 20081231025136.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 88
    Message: explorer.exe started
    Record Number: 4730
    Source Name: UmxAgent
    Time Written: 20081231025136.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 88
    Message: Shell is started at session 1
    Record Number: 4731
    Source Name: UmxAgent
    Time Written: 20081231025136.000000-000
    Event Type: Information
    User:

    Computer Name: Fred-PC
    Event Code: 5
    Message: Unsupported service control request (see data below)
    Record Number: 4732
    Source Name: LightScribeService
    Time Written: 20081231030559.000000-000
    Event Type: Information
    User:

    Security event log

    Computer Name: Fred-PC
    Event Code: 5038
    Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys
    Record Number: 6573
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20081231030552.283051-000
    Event Type: Audit Failure
    User:

    Computer Name: Fred-PC
    Event Code: 5038
    Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys
    Record Number: 6574
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20081231030552.345451-000
    Event Type: Audit Failure
    User:

    Computer Name: Fred-PC
    Event Code: 5038
    Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys
    Record Number: 6575
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20081231030552.376651-000
    Event Type: Audit Failure
    User:

    Computer Name: Fred-PC
    Event Code: 5038
    Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys
    Record Number: 6576
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20081231030552.439051-000
    Event Type: Audit Failure
    User:

    Computer Name: Fred-PC
    Event Code: 5038
    Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume1\WINDOWS\System32\drivers\tcpip.sys
    Record Number: 6577
    Source Name: Microsoft-Windows-Security-Auditing
    Time Written: 20081231030552.470251-000
    Event Type: Audit Failure
    User:

    ======Environment variables======

    "ComSpec "=%SystemRoot%\system32\cmd.exe
    "FP_NO_HOST_CHECK "=NO
    "OS "=Windows_NT
    "Path "=C:\Program Files\Common Files\ArcSoft\Bin;%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\hp\bin\Python;c:\Program Files\Common Files\Roxio Shared\DLLShared\;c:\Program Files\Common Files\Roxio Shared\9.0\DLLShared\
    "PATHEXT "=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH;.MSC
    "PROCESSOR_ARCHITECTURE "=x86
    "TEMP "=%SystemRoot%\TEMP
    "TMP "=%SystemRoot%\TEMP
    "USERNAME "=SYSTEM
    "windir "=%SystemRoot%
    "PROCESSOR_LEVEL "=15
    "PROCESSOR_IDENTIFIER "=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
    "PROCESSOR_REVISION "=6b01
    "NUMBER_OF_PROCESSORS "=2
    "RoxioCentral "=c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\
    "PLATFORM "=HPD
    "PCBRAND "=Pavilion
    "OnlineServices "=Online Services

    -----------------EOF-----------------
    Logfile of random's system information tool 1.05 (written by random/random)
    Run by Fred at 2008-12-30 22:05:09
    Microsoft® Windows Vistaâ„¢ Home Premium Service Pack 1
    System drive C: has 250 GB (75%) free of 334 GB
    Total RAM: 3454 MB (70% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:05:55 PM, on 12/30/2008
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v7.00 (7.00.6001.18000)
    Boot mode: Normal

    Running processes:
    C:\Windows\system32\taskeng.exe
    C:\Windows\system32\Dwm.exe
    C:\Windows\Explorer.EXE
    C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
    C:\Program Files\Windows Defender\MSASCui.exe
    C:\hp\support\hpsysdrv.exe
    C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    C:\WINDOWS\RtHDVCpl.exe
    C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
    C:\Windows\system32\schtasks.exe
    C:\Program Files\Google\Gmail Notifier\gnotify.exe
    C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
    C:\Windows\system32\jusched.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe
    C:\WINDOWS\System32\rundll32.exe
    C:\Program Files\Seagate\SeagateManager\FreeAgent Status\stxmenumgr.exe
    C:\Program Files\Windows Media Player\wmpnscfg.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
    I:\Program Files\WinPatrol\WinPatrol.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\WINDOWS\ehome\ehtray.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Windows\ehome\ehmsas.exe
    C:\Program Files\Windows Sidebar\sidebar.exe
    C:\hp\kbd\kbd.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Light\CAGlobalLight.exe
    C:\Program Files\CA\CA Internet Security Suite\ccprovep.exe
    C:\Users\Fred\Downloads\RSIT.exe
    C:\Program Files\trend micro\Fred.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O2 - BHO: CA Toolbar Helper - {FBF2401B-7447-4727-BE5D-C19B2075CA84} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: CA Toolbar - {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll
    O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
    O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    O4 - HKLM\..\Run: [KBD] C:\HP\KBD\KbdStub.EXE
    O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe "
    O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    O4 - HKLM\..\Run: [HP Health Check Scheduler] c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
    O4 - HKLM\..\Run: [SunJavaUpdateReg] "C:\Windows\system32\jureg.exe "
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
    O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe "
    O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe "
    O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe "
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe "
    O4 - HKLM\..\Run: [MaxMenuMgr] "C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe "
    O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
    O4 - HKLM\..\Run: [Mindful 2] "C:\Program Files\Felitec\Mindful 2\Mindful.exe "
    O4 - HKLM\..\Run: [cafw] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
    O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
    O4 - HKLM\..\Run: [WinPatrol] I:\Program Files\WinPatrol\winpatrol.exe -expressboot
    O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
    O13 - Gopher Prefix:
    O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
    O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
    O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
    O23 - Service: Seagate Service (FreeAgentGoNext Service) - Seagate Technology LLC - C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: ScsiAccess - Unknown owner - I:\Program Files\Photodex\ScsiAccess.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
    O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
    O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
    O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
    O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
    O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

    --
    End of file - 9780 bytes

    ======Scheduled tasks folder======

    C:\Windows\tasks\CAAntiSpywareScan_Daily as Fred at 6 50 PM.job
    C:\Windows\tasks\RegCure Program Check.job
    C:\Windows\tasks\RegCure.job
    C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}]
    SnagIt Toolbar Loader - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll [2007-05-01 63048]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2007-03-20 803864]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
    Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-04-07 501400]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FBF2401B-7447-4727-BE5D-C19B2075CA84}]
    CA Toolbar Helper - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2007-03-20 803864]
    {10134636-E7AF-4AC5-A1DC-C7C44BB97D81} - CA Toolbar - C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\Toolbar\CallingIDIE.dll [2008-07-23 275896]
    {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll [2007-05-01 161352]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "Windows Defender "=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
    "hpsysdrv "=c:\hp\support\hpsysdrv.exe [2007-04-18 65536]
    "KBD "=C:\HP\KBD\KbdStub.EXE [2006-12-08 65536]
    "OsdMaestro "=C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe [2007-02-15 118784]
    "RtHDVCpl "=C:\Windows\RtHDVCpl.exe [2008-01-15 4874240]
    "HP Health Check Scheduler "=c:\Program Files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2007-05-24 71176]
    "SunJavaUpdateReg "=C:\Windows\system32\jureg.exe [2007-04-07 54936]
    "HP Software Update "=C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-12-10 49152]
    " "= []
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2} "=C:\Program Files\Google\Gmail Notifier\gnotify.exe [2005-07-15 479232]
    "cctray "=C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe [2008-12-28 247024]
    "CAVRID "=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2008-08-30 234736]
    "QOELOADER "=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe [2008-12-21 14088]
    "NvCplDaemon "=C:\Windows\system32\NvCpl.dll [2008-05-22 13539872]
    "NvMediaCenter "=C:\Windows\system32\NvMcTray.dll [2008-05-22 92704]
    "Adobe Reader Speed Launcher "=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
    "MaxMenuMgr "=C:\Program Files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe [2008-10-28 181544]
    "hpqSRMon "=C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe [2008-08-20 150016]
    "Mindful 2 "=C:\Program Files\Felitec\Mindful 2\Mindful.exe [2008-12-08 718336]
    "cafw "=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-08-28 771312]
    "capfasem "=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-08-28 173296]
    "WinPatrol "=I:\Program Files\WinPatrol\winpatrol.exe [2008-04-25 333120]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar "=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-19 1233920]
    "ehTray.exe "=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes' Anti-Malware]
    I:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /starttray []

    [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]
    C:\Program Files\Snapfish Picture Mover\SnapfishMediaDetector.exe [2007-05-07 1273856]

    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
    C:\Windows\system32\UmxWnp.Dll [2007-05-18 79368]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
    "{1869181A-9F50-4FCF-8BFF-1B8588ECB85C} "=C:\Program Files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll [2008-07-23 1377720]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername "=0
    "legalnoticecaption "=
    "legalnoticetext "=
    "shutdownwithoutlogon "=1
    "undockwithoutlogon "=1
    "EnableUIADesktopToggle "=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "EnableShellExecuteHooks "=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe "= "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink "

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
    shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\resycled\boot.com i:
    shell\Open\command - I:\resycled\boot.com i:

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dc19f21-d040-11dd-82c4-001bb9a9776f}]
    shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL I:\resycled\boot.com i:
    shell\Open\command - I:\resycled\boot.com i:

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5adc666f-cf6e-11dd-a7cd-001bb9a9776f}]
    shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\resycled\boot.com g:
    shell\Open\command - "resycled\b


    ======List of files/folders created in the last 1 months======

    2008-12-30 22:05:11 ----D---- C:\Program Files\trend micro
    2008-12-30 22:05:09 ----D---- C:\rsit
    2008-12-30 10:49:33 ----D---- C:\ProgramData\HP Product Assistant
    2008-12-28 20:29:51 ----A---- C:\Windows\wininit.ini
    2008-12-28 19:44:39 ----D---- C:\ProgramData\Spybot - Search & Destroy
    2008-12-28 14:47:17 ----D---- C:\Users\Fred\AppData\Roaming\WinPatrol
    2008-12-27 23:56:48 ----ASH---- C:\Users\Fred\AppData\Roaming\desktop.ini
    2008-12-27 15:27:41 ----D---- C:\ScreenSaver
    2008-12-27 14:51:53 ----D---- C:\ProgramData\LoanSpread
    2008-12-27 14:43:03 ----A---- C:\Windows\system32\MACHNM1.EXE
    2008-12-27 14:43:03 ----A---- C:\Windows\system32\KeyLbE32.dll
    2008-12-27 14:43:02 ----D---- C:\Program Files\Loan Calculator Plus25
    2008-12-27 09:49:04 ----D---- C:\ProgramData\vsosdk
    2008-12-26 22:28:51 ----D---- C:\Home
    2008-12-26 00:28:41 ----D---- C:\ProgramData\ArcSoft
    2008-12-26 00:28:39 ----D---- C:\Users\Fred\AppData\Roaming\Arcsoft
    2008-12-26 00:28:22 ----D---- C:\Program Files\Common Files\ArcSoft
    2008-12-26 00:28:22 ----D---- C:\Program Files\ArcSoft
    2008-12-25 22:38:02 ----AD---- C:\ProgramData\TEMP
    2008-12-25 18:30:41 ----D---- C:\external drive
    2008-12-24 21:17:19 ----D---- C:\Users\Fred\AppData\Roaming\NeroDCTemplates
    2008-12-24 20:49:58 ----D---- C:\Users\Fred\AppData\Roaming\Real
    2008-12-24 20:37:34 ----D---- C:\Users\Fred\AppData\Roaming\Roxio
    2008-12-24 20:22:39 ----D---- C:\Users\Fred\AppData\Roaming\Printer Info Cache
    2008-12-24 20:22:39 ----D---- C:\Users\Fred\AppData\Roaming\Image Zone Express
    2008-12-24 14:12:39 ----D---- C:\Program Files\Common Files\Bcgsoft
    2008-12-24 13:44:48 ----D---- C:\ProgramData\Apple Computer
    2008-12-24 13:36:50 ----D---- C:\Users\Fred\AppData\Roaming\LumaPix
    2008-12-24 13:35:21 ----A---- C:\Windows\FotoFusionV4 Uninstaller.exe
    2008-12-24 11:53:41 ----D---- C:\Users\Fred\AppData\Roaming\dvdcss
    2008-12-24 11:45:42 ----D---- C:\Program Files\QuickTime
    2008-12-24 08:19:48 ----A---- C:\Program Files\UNWISE.EXE
    2008-12-23 15:16:50 ----D---- C:\Users\Fred\AppData\Roaming\Malwarebytes
    2008-12-23 15:16:41 ----D---- C:\ProgramData\Malwarebytes
    2008-12-23 13:56:28 ----D---- C:\Users\Fred\AppData\Roaming\Photodex
    2008-12-23 13:35:59 ----D---- C:\Windows\Sun
    2008-12-23 12:03:54 ----D---- C:\Junk
    2008-12-23 11:56:09 ----A---- C:\Windows\system32\msshooks.dll
    2008-12-23 11:56:09 ----A---- C:\Windows\system32\msscb.dll
    2008-12-23 11:56:07 ----A---- C:\Windows\system32\SearchFilterHost.exe
    2008-12-23 11:56:07 ----A---- C:\Windows\system32\propdefs.dll
    2008-12-23 11:56:07 ----A---- C:\Windows\system32\mssitlb.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\wsepno.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\thawbrkr.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\srchadmin.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\rtffilt.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\propsys.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\msstrc.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\mssprxy.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\msshsq.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\mimefilt.dll
    2008-12-23 11:56:06 ----A---- C:\Windows\system32\korwbrkr.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\xmlfilter.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\tquery.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\SearchProtocolHost.exe
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\SearchIndexer.exe
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\offfilt.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\nlhtml.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\mssvp.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\mssrch.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\mssphtb.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\mssph.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\msscntrs.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\chtbrkr.dll
    2008-12-23 11:56:05 ----A---- C:\Windows\system32\chsbrkr.dll
    2008-12-23 09:08:42 ----A---- C:\Windows\system32\rpcrt4.dll
    2008-12-23 09:08:42 ----A---- C:\Windows\system32\pacerprf.dll
    2008-12-23 09:08:41 ----A---- C:\Windows\system32\wersvc.dll
    2008-12-23 09:08:41 ----A---- C:\Windows\system32\Faultrep.dll
    2008-12-23 09:08:40 ----A---- C:\Windows\system32\emdmgmt.dll
    2008-12-23 09:08:40 ----A---- C:\Windows\system32\dataclen.dll
    2008-12-23 09:08:40 ----A---- C:\Windows\system32\cdd.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\wshext.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\wscript.exe
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\vbscript.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\scrrun.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\scrobj.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\jscript.dll
    2008-12-23 09:08:39 ----A---- C:\Windows\system32\cscript.exe
    2008-12-23 01:21:57 ----A---- C:\Windows\system32\xa52376368.exe
    2008-12-23 01:21:56 ----A---- C:\Windows\system32\xa52375198.exe
    2008-12-22 23:14:17 ----A---- C:\Windows\system32\FlashUtil9e.exe
    2008-12-22 21:34:25 ----A---- C:\Windows\system32\BASSMOD.dll
    2008-12-22 20:28:17 ----D---- C:\Windows\system32\IOSUBSYS
    2008-12-22 20:00:29 ----D---- C:\ProgramData\TechSmith
    2008-12-22 20:00:25 ----D---- C:\Program Files\TechSmith
    2008-12-22 19:51:32 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-12-22 19:49:46 ----D---- C:\MAGICDVDCOPY_TEMP
    2008-12-22 19:42:36 ----D---- C:\Users\Fred\AppData\Roaming\Ashampoo
    2008-12-22 19:42:11 ----D---- C:\ProgramData\ashampoo
    2008-12-22 19:26:09 ----A---- C:\Windows\system32\sipr3260.dll
    2008-12-22 19:23:22 ----A---- C:\Users\Fred\AppData\Roaming\inst.exe
    2008-12-22 19:23:21 ----D---- C:\Users\Fred\AppData\Roaming\Vso
    2008-12-22 19:23:11 ----A---- C:\Windows\system32\Pncrt.dll
    2008-12-22 19:23:11 ----A---- C:\Windows\system32\drv43260.dll
    2008-12-22 19:23:11 ----A---- C:\Windows\system32\drv33260.dll
    2008-12-22 19:23:11 ----A---- C:\Windows\system32\drv23260.dll
    2008-12-22 19:23:11 ----A---- C:\Windows\system32\cook3260.dll
    2008-12-22 19:23:10 ----A---- C:\Windows\system32\wvc1dmod.dll
    2008-12-22 19:23:10 ----A---- C:\Windows\system32\vp7vfw.dll
    2008-12-22 19:23:10 ----A---- C:\Windows\gdiplus.dll
    2008-12-22 19:23:09 ----D---- C:\Program Files\VSO
    2008-12-22 19:18:51 ----D---- C:\Users\Fred\AppData\Roaming\AVSMedia
    2008-12-22 19:18:48 ----D---- C:\ProgramData\AVS4YOU
    2008-12-22 19:14:46 ----D---- C:\Program Files\Common Files\AVSMedia
    2008-12-22 19:14:38 ----A---- C:\Windows\system32\msxml3a.dll
    2008-12-22 19:14:38 ----A---- C:\Windows\system32\msvcr70.dll
    2008-12-22 19:14:38 ----A---- C:\Windows\system32\msvcp70.dll
    2008-12-22 19:14:38 ----A---- C:\Windows\system32\mfc70.dll
    2008-12-22 19:14:37 ----A---- C:\Windows\system32\xvidvfw.dll
    2008-12-22 19:14:37 ----A---- C:\Windows\system32\xvidcore.dll
    2008-12-22 19:14:37 ----A---- C:\Windows\system32\mpg4c32.dll
    2008-12-22 19:14:37 ----A---- C:\Windows\system32\mcdvd_32.dll
    2008-12-22 19:14:37 ----A---- C:\Windows\system32\divx.dll
    2008-12-22 18:54:32 ----D---- C:\Users\Fred\AppData\Roaming\uTorrent
    2008-12-22 17:48:51 ----D---- C:\ProgramData\LightScribe
    2008-12-22 17:48:38 ----D---- C:\Users\Fred\AppData\Roaming\Nero
    2008-12-22 17:28:17 ----A---- C:\Windows\Irremote.ini
    2008-12-22 17:08:08 ----D---- C:\Program Files\Nero
    2008-12-22 17:07:31 ----D---- C:\ProgramData\Nero
    2008-12-22 17:07:30 ----D---- C:\Program Files\Common Files\Nero
    2008-12-22 17:07:15 ----A---- C:\Windows\system32\d3dx9_30.dll
    2008-12-22 16:34:03 ----D---- C:\Users\Fred\AppData\Roaming\LimeWire
    2008-12-22 16:30:37 ----D---- C:\Users\Fred\AppData\Roaming\WinRAR
    2008-12-22 16:30:23 ----D---- C:\Windows\WinRAR
    2008-12-22 16:26:24 ----D---- C:\ProgramData\WinZip
    2008-12-22 15:34:36 ----D---- C:\ProgramData\Seagate
    2008-12-22 15:34:36 ----D---- C:\Program Files\Seagate
    2008-12-22 15:33:25 ----SHD---- C:\Windows\ftpcache
    2008-12-22 12:26:32 ----D---- C:\Program Files\Adobe
    2008-12-22 10:14:13 ----D---- C:\Program Files\Mozilla Firefox
    2008-12-22 10:00:57 ----D---- C:\ProgramData\NVIDIA
    2008-12-22 09:36:43 ----D---- C:\Users\Fred\AppData\Roaming\InstallShield
    2008-12-22 09:30:23 ----A---- C:\Windows\RTKAUDIOSERVICE.EXE
    2008-12-22 09:29:14 ----A---- C:\Windows\system32\SRSWOW.dll
    2008-12-22 09:29:14 ----A---- C:\Windows\system32\RtkPgExt.dll
    2008-12-22 09:29:14 ----A---- C:\Windows\RtlUpd.exe
    2008-12-22 09:29:13 ----A---- C:\Windows\system32\RtkCoInst.dll
    2008-12-22 09:29:13 ----A---- C:\Windows\RtHDVCpl.exe
    2008-12-22 09:24:30 ----D---- C:\Users\Fred\AppData\Roaming\WinBatch
    2008-12-22 09:06:33 ----D---- C:\PerfLogs
    2008-12-22 08:40:59 ----A---- C:\Windows\system32\onex.dll
    2008-12-22 08:40:58 ----A---- C:\Windows\system32\SLsvc.exe
    2008-12-22 08:40:50 ----A---- C:\Windows\system32\PSHED.DLL
    2008-12-22 08:40:49 ----A---- C:\Windows\system32\imagesp1.dll
    2008-12-22 08:40:47 ----A---- C:\Windows\system32\dfsr.exe
    2008-12-22 08:40:45 ----A---- C:\Windows\system32\sstpsvc.dll
    2008-12-22 08:40:45 ----A---- C:\Windows\system32\pidgenx.dll
    2008-12-22 08:40:45 ----A---- C:\Windows\system32\mstscax.dll
    2008-12-22 08:40:44 ----A---- C:\Windows\system32\WsmSvc.dll
    2008-12-22 08:40:44 ----A---- C:\Windows\system32\winrscmd.dll
    2008-12-22 08:40:43 ----A---- C:\Windows\system32\sysmain.dll
    2008-12-22 08:40:43 ----A---- C:\Windows\system32\RMActivate.exe
    2008-12-22 08:40:42 ----A---- C:\Windows\system32\VSSVC.exe
    2008-12-22 08:40:42 ----A---- C:\Windows\system32\vssapi.dll
    2008-12-22 08:40:42 ----A---- C:\Windows\system32\secproc.dll
    2008-12-22 08:40:42 ----A---- C:\Windows\system32\PresentationNative_v0300.dll
    2008-12-22 08:40:41 ----A---- C:\Windows\system32\RMActivate_isv.exe
    2008-12-22 08:40:41 ----A---- C:\Windows\system32\iesetup.dll
    2008-12-22 08:40:40 ----A---- C:\Windows\system32\secproc_isv.dll
    2008-12-22 08:40:38 ----A---- C:\Windows\system32\xpssvcs.dll
    2008-12-22 08:40:38 ----A---- C:\Windows\system32\icardres.dll
    2008-12-22 08:40:38 ----A---- C:\Windows\system32\icardagt.exe
    2008-12-22 08:40:38 ----A---- C:\Windows\system32\drmv2clt.dll
    2008-12-22 08:40:38 ----A---- C:\Windows\system32\blackbox.dll
    2008-12-22 08:40:37 ----A---- C:\Windows\system32\RacEngn.dll
    2008-12-22 08:40:36 ----A---- C:\Windows\system32\spwizimg.dll
    2008-12-22 08:40:36 ----A---- C:\Windows\system32\RMActivate_ssp_isv.exe
    2008-12-22 08:40:36 ----A---- C:\Windows\system32\RMActivate_ssp.exe
    2008-12-22 08:40:36 ----A---- C:\Windows\system32\rdpencom.dll
    2008-12-22 08:40:36 ----A---- C:\Windows\system32\MSMPEG2VDEC.DLL
    2008-12-22 08:40:35 ----A---- C:\Windows\system32\msjet40.dll
    2008-12-22 08:40:35 ----A---- C:\Windows\system32\lpremove.exe
    2008-12-22 08:40:35 ----A---- C:\Windows\bfsvc.exe
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\wevtsvc.dll
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\qmgr.dll
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\ntdll.dll
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\lsasrv.dll
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\localspl.dll
    2008-12-22 08:40:34 ----A---- C:\Windows\system32\IKEEXT.DLL
    2008-12-22 08:40:33 ----A---- C:\Windows\system32\wcncsvc.dll
    2008-12-22 08:40:33 ----A---- C:\Windows\system32\TsWpfWrp.exe
    2008-12-22 08:40:33 ----A---- C:\Windows\system32\recdisc.exe
    2008-12-22 08:40:33 ----A---- C:\Windows\system32\mscoree.dll
    2008-12-22 08:40:33 ----A---- C:\Windows\system32\kernel32.dll
    2008-12-22 08:40:32 ----A---- C:\Windows\system32\vds.exe
    2008-12-22 08:40:32 ----A---- C:\Windows\system32\CompMgmtLauncher.exe
    2008-12-22 08:40:31 ----A---- C:\Windows\system32\wmp.dll
    2008-12-22 08:40:30 ----A---- C:\Windows\system32\wcnwiz.dll
    2008-12-22 08:40:30 ----A---- C:\Windows\system32\SMBHelperClass.dll
    2008-12-22 08:40:30 ----A---- C:\Windows\system32\msvbvm60.dll
    2008-12-22 08:40:30 ----A---- C:\Windows\system32\mstsc.exe
    2008-12-22 08:40:29 ----A---- C:\Windows\system32\termsrv.dll
    2008-12-22 08:40:29 ----A---- C:\Windows\system32\msdtctm.dll
    2008-12-22 08:40:29 ----A---- C:\Windows\system32\kerberos.dll
    2008-12-22 08:40:29 ----A---- C:\Windows\system32\advapi32.dll
    2008-12-22 08:40:28 ----A---- C:\Windows\system32\mmcndmgr.dll
    2008-12-22 08:40:28 ----A---- C:\Windows\system32\IMJP10K.DLL
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\xolehlp.dll
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\Query.dll
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\MSMPEG2ADEC.DLL
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\msdtcprx.dll
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\MPSSVC.dll
    2008-12-22 08:40:27 ----A---- C:\Windows\system32\CertEnroll.dll
    2008-12-22 08:40:26 ----A---- C:\Windows\system32\WindowsAnytimeUpgradeCPL.dll
    2008-12-22 08:40:26 ----A---- C:\Windows\system32\ole32.dll
    2008-12-22 08:40:26 ----A---- C:\Windows\system32\netlogon.dll
    2008-12-22 08:40:26 ----A---- C:\Windows\system32\msvcrt.dll
    2008-12-22 08:40:25 ----A---- C:\Windows\system32\SSShim.dll
    2008-12-22 08:40:25 ----A---- C:\Windows\system32\schedsvc.dll
    2008-12-22 08:40:25 ----A---- C:\Windows\system32\nlmgp.dll
    2008-12-22 08:40:25 ----A---- C:\Windows\system32\mcupdate_GenuineIntel.dll
    2008-12-22 08:40:25 ----A---- C:\Windows\system32\DfsShlEx.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\wer.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\user32.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\shlwapi.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\sdclt.exe
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\milcore.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\IasMigPlugin.dll
    2008-12-22 08:40:24 ----A---- C:\Windows\system32\clusapi.dll
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\WSDApi.dll
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\winrsmgr.dll
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\vdsdyn.dll
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\QAGENTRT.DLL
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\mmc.exe
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\diagperf.dll
    2008-12-22 08:40:23 ----A---- C:\Windows\system32\d3d9.dll
    2008-12-22 08:40:22 ----A---- C:\Windows\system32\vdsbas.dll
    2008-12-22 08:40:22 ----A---- C:\Windows\system32\SLC.dll
    2008-12-22 08:40:22 ----A---- C:\Windows\system32\mtxclu.dll
    2008-12-22 08:40:21 ----A---- C:\Windows\system32\swprv.dll
    2008-12-22 08:40:21 ----A---- C:\Windows\system32\MSVidCtl.dll
    2008-12-22 08:40:21 ----A---- C:\Windows\system32\msi.dll
    2008-12-22 08:40:21 ----A---- C:\Windows\system32\comctl32.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\XPSSHHDR.dll
     
  2. 2008/12/30
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Host File Infected Page 2

    2008-12-22 08:40:20 ----A---- C:\Windows\system32\sbe.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\samsrv.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\msdtckrm.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\mfc42u.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\gpsvc.dll
    2008-12-22 08:40:20 ----A---- C:\Windows\system32\FWPUCLNT.DLL
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\wecutil.exe
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\usp10.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\sdengin2.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\mfc42.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\gacinstall.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\esent.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\cmipnpinstall.dll
    2008-12-22 08:40:19 ----A---- C:\Windows\system32\cmicryptinstall.dll
    2008-12-22 08:40:18 ----A---- C:\Windows\system32\WSManMigrationPlugin.dll
    2008-12-22 08:40:18 ----A---- C:\Windows\system32\mswsock.dll
    2008-12-22 08:40:18 ----A---- C:\Windows\system32\crypt32.dll
    2008-12-22 08:40:18 ----A---- C:\Windows\system32\comsvcs.dll
    2008-12-22 08:40:18 ----A---- C:\Windows\system32\certutil.exe
    2008-12-22 08:40:17 ----A---- C:\Windows\system32\wmdrmsdk.dll
    2008-12-22 08:40:17 ----A---- C:\Windows\system32\sqlceqp30.dll
    2008-12-22 08:40:17 ----A---- C:\Windows\system32\setupapi.dll
    2008-12-22 08:40:17 ----A---- C:\Windows\system32\oleaut32.dll
    2008-12-22 08:40:17 ----A---- C:\Windows\system32\FirewallAPI.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\wecsvc.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\sdohlp.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\schannel.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\p2psvc.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\msv1_0.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\lsm.exe
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\iphlpsvc.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\eapp3hst.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\bcrypt.dll
    2008-12-22 08:40:16 ----A---- C:\Windows\system32\AuxiliaryDisplayDriverLib.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\wmpmde.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\vdsutil.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\thumbcache.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\riched20.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\mcmde.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\imapi2fs.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\d3d10_1.dll
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\autofmt.exe
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\autoconv.exe
    2008-12-22 08:40:15 ----A---- C:\Windows\system32\autochk.exe
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\WinSAT.exe
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\wevtapi.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\dmvdsitf.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\d3d10_1core.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\comuid.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\comdlg32.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\browseui.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\authui.dll
    2008-12-22 08:40:14 ----A---- C:\Windows\system32\authfwcfg.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\WSDMon.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\wevtfwd.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\uexfat.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\rasmans.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\mscories.dll
    2008-12-22 08:40:13 ----A---- C:\Windows\system32\eapphost.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\wlansvc.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\whealogr.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\untfs.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\sqlcese30.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\pcaui.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\iassam.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\eappcfg.dll
    2008-12-22 08:40:12 ----A---- C:\Windows\system32\DfrgNtfs.exe
    2008-12-22 08:40:11 ----A---- C:\Windows\system32\dot3svc.dll
    2008-12-22 08:40:10 ----A---- C:\Windows\system32\rdpwsx.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\zipfldr.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\WsmAuto.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\winhttp.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\rpcss.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\rasppp.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\nlasvc.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\mssha.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\msdrm.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\evr.dll
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\dfrgui.exe
    2008-12-22 08:40:09 ----A---- C:\Windows\system32\BFE.DLL
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\WsmWmiPl.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\wmdrmdev.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\WebClnt.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\rastls.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\printui.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\ncrypt.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\msrepl40.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\dhcpcsvc6.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\ddraw.dll
    2008-12-22 08:40:08 ----A---- C:\Windows\system32\audiosrv.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\w32time.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\themecpl.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\sqlsrv32.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\QAGENT.DLL
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\objsel.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\iasnap.dll
    2008-12-22 08:40:07 ----A---- C:\Windows\system32\dbghelp.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\wmdrmnet.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\winsrv.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\WerFaultSecure.exe
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\spoolss.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\PresentationHost.exe
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\ncryptui.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\msctf.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\iprtrmgr.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\infocardapi.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\icm32.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\bcdedit.exe
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\basecsp.dll
    2008-12-22 08:40:06 ----A---- C:\Windows\system32\azroles.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\wlangpui.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\winsta.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\taskschd.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\scksp.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\netprofm.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\mstlsapi.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\hcrstco.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\dbgeng.dll
    2008-12-22 08:40:05 ----A---- C:\Windows\system32\AudioEng.dll
    2008-12-22 08:40:04 ----A---- C:\Windows\system32\winlogon.exe
    2008-12-22 08:40:04 ----A---- C:\Windows\system32\taskcomp.dll
    2008-12-22 08:40:04 ----A---- C:\Windows\system32\rsaenh.dll
    2008-12-22 08:40:04 ----A---- C:\Windows\system32\netcfgx.dll
    2008-12-22 08:40:04 ----A---- C:\Windows\system32\cdosys.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\wlansec.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\wercon.exe
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\msdtcuiu.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\mprddm.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\lpksetup.exe
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\iasrad.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\dfshim.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\certcli.dll
    2008-12-22 08:40:03 ----A---- C:\Windows\system32\apds.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\Wldap32.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\uDWM.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\tsgqec.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\shdocvw.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\eapsvc.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\certmgr.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\bcdsrv.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\AUDIOKSE.dll
    2008-12-22 08:40:02 ----A---- C:\Windows\system32\aaclient.dll
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\WMVDECOD.DLL
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\umpnpmgr.dll
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\pla.dll
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\msidcrl30.dll
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\dxgi.dll
    2008-12-22 08:40:01 ----A---- C:\Windows\system32\dnsapi.dll
    2008-12-22 08:40:00 ----A---- C:\Windows\system32\wmicmiplugin.dll
    2008-12-22 08:40:00 ----A---- C:\Windows\system32\ntprint.dll
    2008-12-22 08:40:00 ----A---- C:\Windows\system32\netshell.dll
    2008-12-22 08:40:00 ----A---- C:\Windows\system32\dot3gpui.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\wscsvc.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\wscisvif.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\winmm.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\synceng.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\shsvcs.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\services.exe
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\pnidui.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\MMDevAPI.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\cryptnet.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\comsnap.dll
    2008-12-22 08:39:59 ----A---- C:\Windows\system32\cmifw.dll
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\WMVSDECD.DLL
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\taskeng.exe
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\rasapi32.dll
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\msjtes40.dll
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\msconfig.exe
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\imapi2.dll
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\iassdo.dll
    2008-12-22 08:39:58 ----A---- C:\Windows\system32\cipher.exe
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\wkssvc.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\uxtheme.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\tdh.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\SessEnv.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\qdvd.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\msscp.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\dot3api.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\dmdskmgr.dll
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\cmd.exe
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\cbsra.exe
    2008-12-22 08:39:57 ----A---- C:\Windows\system32\AuthFWSnapin.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\WUDFx.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\wlanmsm.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\wlancfg.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\wevtutil.exe
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\srvsvc.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\rpchttp.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\rdpdd.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\mshtmled.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\msdtcVSp1res.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\localsec.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\loadperf.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\fontext.dll
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\diskpart.exe
    2008-12-22 08:39:56 ----A---- C:\Windows\system32\comres.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\wsqmcons.exe
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\WMADMOD.DLL
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\wlanpref.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\wlanapi.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\WinSATAPI.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\profprov.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\NAPMONTR.DLL
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\hnetcfg.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\dsound.dll
    2008-12-22 08:39:55 ----A---- C:\Windows\system32\avifil32.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\wsecedit.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\tracerpt.exe
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\SmartcardCredentialProvider.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\SLCommDlg.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\RDPENCDD.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\PresentationHostProxy.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\MuiUnattend.exe
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\filemgmt.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\dnsrslvr.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\dhcpcsvc.dll
    2008-12-22 08:39:54 ----A---- C:\Windows\system32\AuxiliaryDisplayCpl.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\WMSPDMOD.DLL
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\wininit.exe
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\spp.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\rasdlg.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\QSHVHOST.DLL
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\P2PGraph.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\mscorier.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\iassvcs.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\iashost.exe
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\gpresult.exe
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\dwmredir.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\dwm.exe
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\azroleui.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\system32\apphelp.dll
    2008-12-22 08:39:53 ----A---- C:\Windows\HelpPane.exe
    2008-12-22 08:39:52 ----A---- C:\Windows\system32\SLUI.exe
    2008-12-22 08:39:52 ----A---- C:\Windows\system32\mcbuilder.exe
    2008-12-22 08:39:51 ----A---- C:\Windows\system32\srrstr.dll
    2008-12-22 08:39:51 ----A---- C:\Windows\system32\spwizeng.dll
    2008-12-22 08:39:51 ----A---- C:\Windows\system32\rasmontr.dll
    2008-12-22 08:39:51 ----A---- C:\Windows\system32\lltdsvc.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\WMPEncEn.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\wecapi.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\unbcl.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\tcpmon.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\shrink.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\oleacc.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\msra.exe
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\msdri.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\IPHLPAPI.DLL
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\iashlpr.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\gpedit.dll
    2008-12-22 08:39:50 ----A---- C:\Windows\system32\brcpl.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\vsstrace.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\regsvc.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\raschap.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\PerfCenterCPL.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\ntvdm.exe
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\ipsmsnap.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\framedynos.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\fdWSD.dll
    2008-12-22 08:39:49 ----A---- C:\Windows\system32\advpack.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\wpdshext.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\wdc.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\Storprop.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\ntlanman.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\NetProjW.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\netman.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\l2nacp.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\iedkcs32.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\ieapfltr.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\framedyn.dll
    2008-12-22 08:39:48 ----A---- C:\Windows\system32\dssenh.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\WsmProv.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\WlanMM.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\WLanConn.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\tcpipcfg.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\sxs.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\profsvc.dll
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\KMSVC.DLL
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\certreq.exe
    2008-12-22 08:39:47 ----A---- C:\Windows\system32\adsnt.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\wusa.exe
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\WUDFHost.exe
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\wlanhlp.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\WerFault.exe
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\VAN.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\userenv.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\umb.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\puiobj.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\ncsi.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\IPBusEnum.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\ie4uinit.exe
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\fundisc.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\cryptui.dll
    2008-12-22 08:39:46 ----A---- C:\Windows\system32\catsrvut.dll
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\photowiz.dll
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\netid.dll
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\netcenter.dll
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\MdSched.exe
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\InkEd.dll
    2008-12-22 08:39:45 ----A---- C:\Windows\system32\dps.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\ws2_32.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\WinSCard.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\winrs.exe
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\spbcd.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\secur32.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\odbcjt32.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\ntdsapi.dll
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\NAPSTAT.EXE
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\msinfo32.exe
    2008-12-22 08:39:44 ----A---- C:\Windows\system32\ipsecsnp.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\schtasks.exe
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\RelMon.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\prnntfy.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\pdh.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\netdiagfx.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\msfeeds.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\mblctr.exe
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\iasacct.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\dmdlgs.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\dhcpsapi.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\cryptsvc.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\catsrv.dll
    2008-12-22 08:39:43 ----A---- C:\Windows\system32\activeds.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\wvc.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\winrm.vbs
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\TSpkg.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\qwave.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\FirewallControlPanel.exe
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\fdWCN.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\dot3msm.dll
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\dfrgfat.exe
    2008-12-22 08:39:42 ----A---- C:\Windows\system32\AudioSes.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\wow32.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\shsetup.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\rastapi.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\ntshrui.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\netcorehc.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\NAPHLPR.DLL
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\MSMPEG2ENC.DLL
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\msacm32.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\ifmon.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\els.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\dot3cfg.dll
    2008-12-22 08:39:41 ----A---- C:\Windows\system32\adsldp.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\wscntfy.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\stobject.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\sdrsvc.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\QUTIL.DLL
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\net1.exe
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\msdt.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\ipnathlp.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\iasrecst.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\iasdatastore.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\fdSSDP.dll
    2008-12-22 08:39:40 ----A---- C:\Windows\system32\clbcatq.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\wlgpclnt.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\wlanui.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\upnphost.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\systemcpl.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\smss.exe
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\rasman.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\P2P.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\nci.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\msftedit.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\MSAC3ENC.DLL
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\mprmsg.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\dsprop.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\Defrag.exe
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\CompatUI.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\adsldpc.dll
    2008-12-22 08:39:39 ----A---- C:\Windows\system32\ActiveContentWizard.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\Wpc.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\wdigest.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\t2embed.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\setupcl.exe
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\rascfg.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\PresentationSettings.exe
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\oleprn.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\MigAutoPlay.exe
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\loghours.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\L2SecHC.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\fde.dll
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\dxdiag.exe
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\DFDWiz.exe
    2008-12-22 08:39:38 ----A---- C:\Windows\system32\AuxiliaryDisplayServices.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\wiaservc.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\scansetting.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\rtm.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\NAPCRYPT.DLL
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\msutb.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\msihnd.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\mprdim.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\ifsutil.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\gpapi.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\devmgr.dll
    2008-12-22 08:39:37 ----A---- C:\Windows\system32\CertEnrollUI.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\wscapi.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\wlandlg.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\WinFXDocObj.exe
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\wdi.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\vssadmin.exe
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\usbmon.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\SyncCenter.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\spoolsv.exe
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\mswmdm.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\msls31.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\kdusb.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\imagehlp.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\dimsroam.dll
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\BOOTVID.DLL
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\audiodg.exe
    2008-12-22 08:39:36 ----A---- C:\Windows\system32\actxprxy.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\uudf.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\sud.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\scecli.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\SCardSvr.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\regapi.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\PresentationCFFRasterizerNative_v0300.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\newdev.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\mycomput.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\mstask.dll
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\mspaint.exe
    2008-12-22 08:39:35 ----A---- C:\Windows\system32\kdcom.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\termmgr.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\tapisrv.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\ssdpsrv.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\SLUINotify.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\samlib.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\Robocopy.exe
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\puiapi.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\mtxoci.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\input.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\inetpp.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\duser.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\cic.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\AzSqlExt.dll
    2008-12-22 08:39:34 ----A---- C:\Windows\system32\adtschema.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\WUDFPlatform.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\wisptis.exe
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\webcheck.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\verifier.exe
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\sdshext.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\netiohlp.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\msdtclog.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\msdt.exe
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\iasads.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\cscapi.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\cmdial32.dll
    2008-12-22 08:39:33 ----A---- C:\Windows\system32\authz.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\wpcsvc.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\wpccpl.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\WMPhoto.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\wintrust.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\vdsldr.exe
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\themeui.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\SndVol.exe
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\slcinst.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\rasgcw.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\pnpsetup.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\oledlg.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\ntmarta.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\mmcbase.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\icfupgd.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\icardie.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\dxtmsft.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\d3d8.dll
    2008-12-22 08:39:32 ----A---- C:\Windows\system32\clfsw32.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\wtsapi32.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\wpd_ci.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\unlodctr.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\ulib.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\syssetup.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\SnippingTool.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\slmgr.vbs
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\sethc.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\rasqec.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\pnpui.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\nslookup.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\ncobjapi.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\msrd3x40.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\mscms.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\msaatext.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\mpr.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\mlang.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\lodctr.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\iaspolcy.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\fontsub.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\extmgr.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\dxdiagn.dll
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\diskraid.exe
    2008-12-22 08:39:31 ----A---- C:\Windows\system32\accessibilitycpl.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\WSManHTTPConfig.exe
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\Utilman.exe
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\unattend.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\trkwks.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\scesrv.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\oobefldr.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\ogldrv.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\occache.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\Mcx2Svc.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\lnkstub.exe
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\cabview.dll
    2008-12-22 08:39:30 ----A---- C:\Windows\system32\cabinet.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\wpcao.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\wermgr.exe
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\sdspres.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\p2pcollab.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\msnetobj.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\iepeers.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\ieaksie.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\eappgnui.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\dfdts.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\bthci.dll
    2008-12-22 08:39:29 ----A---- C:\Windows\system32\basesrv.dll
    2008-12-22 08:39:28 ----A---- C:\Windows\system32\mmcss.dll
    2008-12-22 08:39:28 ----A---- C:\Windows\system32\dsquery.dll
    2008-12-22 08:39:28 ----A---- C:\Windows\system32\drvinst.exe
    2008-12-22 08:39:28 ----A---- C:\Windows\system32\dispdiag.exe
    2008-12-22 08:39:28 ----A---- C:\Windows\system32\DHCPQEC.DLL
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\wercplsupport.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\verifier.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\secproc_ssp_isv.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\secproc_ssp.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\RstrtMgr.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\qedit.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\mprapi.dll
    2008-12-22 08:39:27 ----A---- C:\Windows\system32\efsadu.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\xactsrv.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\WPDSp.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\WPDShServiceObj.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\WMVENCOD.DLL
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\wiascanprofiles.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\wiaaut.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\usercpl.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\setupugc.exe
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\QSVRMGMT.DLL
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\pnrpnsp.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\PNPXAssocPrx.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\PNPXAssoc.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\pngfilt.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\p2pnetsh.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\networkmap.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\msrdc.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\msoeacct.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\msdmo.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\lsass.exe
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\iscsiexe.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\icacls.exe
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\d3d10core.dll
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\consent.exe
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\conime.exe
    2008-12-22 08:39:26 ----A---- C:\Windows\system32\autoplay.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\xwizards.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\systeminfo.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\resutils.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\pcadm.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\netcfg.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\msrating.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\mfplat.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\lpk.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\findstr.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\eappprxy.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\DWWIN.EXE
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\dssec.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\drmmgrtn.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\dpapimig.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\dot3ui.dll
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\dfrgifc.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\cmdl32.exe
    2008-12-22 08:39:25 ----A---- C:\Windows\system32\alg.exe
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\txflog.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\tbssvc.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\taskkill.exe
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\powercpl.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\odbc32.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\nshhttp.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\netprof.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\msieftp.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\MFWMAAEC.DLL
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\imm32.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\iexpress.exe
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\feclient.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\dxva2.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\dwmapi.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\dbnetlib.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\d3d10.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\btpanui.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\bcdprov.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\apircl.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\system32\ActionQueue.dll
    2008-12-22 08:39:24 ----A---- C:\Windows\regedit.exe
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\WMASF.DLL
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\syncui.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\svchost.exe
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\slwmi.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\SLCExt.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\slcc.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\shwebsvc.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\RASMM.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\raserver.exe
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\provthrd.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\PnPUnattend.exe
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\olepro32.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\networkexplorer.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\MediaMetadataHandler.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\EAPQEC.DLL
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\dmocx.dll
    2008-12-22 08:39:23 ----A---- C:\Windows\system32\aclui.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\xcopy.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\wlanext.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\uxsms.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\upnp.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\UIHub.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\taskmgr.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\reg.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\QCLIPROV.DLL
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\perfts.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\netplwiz.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\NapiNSP.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\msoert2.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\msjetoledb40.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\mountvol.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\mmcshext.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\icsfiltr.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\ias.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\dskquoui.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\dnscacheugc.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\cmstp.exe
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\certprop.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\browser.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\brcplsdw.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\AuxiliaryDisplayApi.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\audiodev.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\atl.dll
    2008-12-22 08:39:22 ----A---- C:\Windows\system32\appinfo.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\WUDFSvc.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\WUDFCoinstaller.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\WMVXENCD.DLL
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\WMVSENCD.DLL
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\wmpsrcwp.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\wmpdxm.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\SysFxUI.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\SoundRecorder.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\Sens.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\SecEdit.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\rekeywiz.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\qcap.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\qasf.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\PING.EXE
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\mtstocom.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\mscandui.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\makecab.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\lsmproxy.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\inetmib1.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\ieakeng.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\httpapi.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\dsuiext.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\dmusic.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\cewmdm.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\bitsadmin.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\batt.dll
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\auditpol.exe
    2008-12-22 08:39:21 ----A---- C:\Windows\system32\adsmsext.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\xwtpw32.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\wzcdlg.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\wscmisetup.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\wpdwcn.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\WMSPDMOE.DLL
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\winrshost.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\wiashext.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\wiadefui.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\userinit.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\tasklist.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\sxstrace.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\sppnp.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\shimgvw.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\shacct.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\seclogon.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\sbeio.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\perfmon.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\p2phost.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\ndfapi.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\napipsec.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\msorcl32.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\msdadiag.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\ktmutil.exe
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\keymgr.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\HelpPaneProxy.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\dxtrans.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\dot3gpclnt.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\csrsrv.dll
    2008-12-22 08:39:20 ----A---- C:\Windows\system32\apss.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\wscproxystub.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\wpdbusenum.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\wmiprop.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\winethc.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\UIAutomationCore.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\txfw32.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\TapiMigPlugin.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\takeown.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\rasplap.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\prntvpt.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\powrprof.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\pots.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\PnPutil.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\pcasvc.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\nshipsec.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\notepad.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\netiougc.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\msimtf.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\msiexec.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\MP4SDECD.DLL
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\inseng.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\ftp.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\fmifs.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\findnetprinters.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\driverquery.exe
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\dnshc.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\d3dim700.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\cryptdll.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\colorui.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\system32\capisp.dll
    2008-12-22 08:39:19 ----A---- C:\Windows\notepad.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\WMADMOE.DLL
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\WLanHC.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\wiaacmgr.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\wextract.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\w32tm.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\version.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\unregmp2.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\UI0Detect.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\TMM.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\shrpubw.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\shgina.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\sfc_os.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\sendmail.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\runonce.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\rshx32.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\RpcPing.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\RESAMPLEDMO.DLL
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\perfnet.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\olecli32.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\nsisvc.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\net.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\msvfw32.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\MPG4DECD.DLL
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\MP43DECD.DLL
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\mdminst.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\luainstall.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\ktmw32.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\imapi.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\getmac.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\fsutil.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\fdPHost.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\dsauth.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\dimsjob.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\d3dim.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\compstui.dll
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\cmmon32.exe
    2008-12-22 08:39:18 ----A---- C:\Windows\system32\cmlua.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\wmpshell.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\tscupgrd.exe
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\sdchange.exe
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\PortableDeviceWiaCompat.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\pnpts.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\migisol.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\ipconfig.exe
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\imgutil.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\fdeploy.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\credui.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\cmutil.dll
    2008-12-22 08:39:17 ----A---- C:\Windows\system32\ACW.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\wmvdspa.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\wmidx.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\vdmredir.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\utildll.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\TSTheme.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\TpmInit.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\softkbd.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\sfc.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\remotepg.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\pdhui.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\nlaapi.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\msfeedsbs.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\modemui.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\McxDriv.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\iernonce.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\hlink.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\fwcfg.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\ExplorerFrame.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\expand.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\EncDump.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\dispci.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\dinput8.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\diantz.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\comrepl.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\colbact.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\cfgbkend.dll
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\bridgeunattend.exe
    2008-12-22 08:39:15 ----A---- C:\Windows\system32\amstream.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\wsnmp32.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\WsmCl.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\wmpcm.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\wfapigp.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\waitfor.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\vds_ps.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\tabcal.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\sti_ci.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\shutdown.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\rdrleakdiag.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\qdv.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\osblprov.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\olesvr32.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\odbccp32.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\msdtc.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\logman.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\iscsium.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\esentutl.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\dpnet.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\DpiScaling.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\dmsynth.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\COLORCNV.DLL
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\cmcfg32.dll
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\cacls.exe
    2008-12-22 08:39:14 ----A---- C:\Windows\system32\bootcfg.exe
     

  3. to hide this advert.

  4. 2008/12/30
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Host File Infected Page 3

    2008-12-22 08:39:14 ----A---- C:\Windows\system32\admparse.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\xmlprovi.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\wpnpinst.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\werdiagcontroller.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\wavemsp.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\ufat.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\ucsvc.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\TimeDateMUICallback.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\tbs.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\sxproxy.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\SLLUA.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\rgb9rast.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\RegCtrl.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\rasdiag.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\rasauto.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\prevhost.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\olethk32.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\odbctrac.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\networkitemfactory.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\netbtugc.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\mstext40.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\mshta.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\msctfui.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\mobsync.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\mfvdsp.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\licmgr10.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\itss.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\iscsiwmi.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\iscsied.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\dskquota.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\csrstub.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\cscdll.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\convert.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\bitsigd.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\AuthFWGP.dll
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\AtBroker.exe
    2008-12-22 08:39:13 ----A---- C:\Windows\system32\at.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\wpclsp.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\WINSRPC.DLL
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\winnsi.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\vss_ps.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\VIDRESZR.DLL
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\usbui.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\upnpcont.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\unattendedjoin.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\srwmi.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\setupcln.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\regini.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\RacAgent.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\odbccu32.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\odbccr32.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\ocsetup.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\nsi.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\nbtstat.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\napdsnap.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\mydocs.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\mtxlegih.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\mtxdm.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\msident.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\msdart.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\MsCtfMonitor.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\mfcsubs.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\l2gpstore.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\GuidedHelp.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\graftabl.com
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\gpupdate.exe
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\fphc.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\dsdmo.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\dot3dlg.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\dmime.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\devenum.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\cmstplua.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\cmpbk32.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\avrt.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\apilogen.dll
    2008-12-22 08:39:12 ----A---- C:\Windows\system32\amxread.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\wsock32.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\WlanMmHC.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\WindowsAnytimeUpgrade.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\wiarpc.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\wiadss.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\WavDest.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\vfwwdm32.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\TabbtnEx.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\Tabbtn.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\syskey.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\ROUTE.EXE
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\rasphone.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\psbase.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\procinst.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\odbcbcp.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\netevent.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\ndfetw.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\msxbde40.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\msexcl40.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\MP3DMOD.DLL
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\inetppui.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\extrac32.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\eventcls.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\dmscript.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\d3dxof.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\csrss.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\CertEnrollCtrl.exe
    2008-12-22 08:39:11 ----A---- C:\Windows\system32\atmfd.dll
    2008-12-22 08:39:11 ----A---- C:\Windows\fveupdate.exe
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\WsmRes.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\WSHTCPIP.DLL
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\wship6.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\wshcon.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\tcpmon.ini
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\sxsstore.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\slwga.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\setupSNK.exe
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\PlaySndSrv.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\OptionalFeatures.exe
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\Netplwiz.exe
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\msvidc32.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\mspbde40.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\msltus40.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\localui.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\lltdapi.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\LangCleanupSysprepAction.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\icsunattend.exe
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\icaapi.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\HotStartUserAgent.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\dmloader.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\credssp.dll
    2008-12-22 08:39:10 ----A---- C:\Windows\system32\ComputerDefaults.exe
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\usbperf.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\spopk.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\serialui.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\sbunattend.exe
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\odbcconf.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\NcdProp.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\msfeedssync.exe
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\ieencode.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\hbaapi.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\dmutil.dll
    2008-12-22 08:39:09 ----A---- C:\Windows\system32\cofiredm.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\vdmdbg.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\url.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\rasctrs.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\nlsbres.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\msobjs.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\midimap.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\LogonUI.exe
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\iprtprio.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\InfDefaultInstall.exe
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\hnetmon.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\esentprf.dll
    2008-12-22 08:39:08 ----A---- C:\Windows\system32\corpol.dll
    2008-12-22 08:39:07 ----A---- C:\Windows\system32\osbaseln.dll
    2008-12-22 08:39:07 ----A---- C:\Windows\system32\msmmsp.dll
    2008-12-22 08:39:07 ----A---- C:\Windows\system32\msisip.dll
    2008-12-22 08:39:07 ----A---- C:\Windows\system32\cfgmgr32.dll
    2008-12-22 08:39:06 ----A---- C:\Windows\system32\winusb.dll
    2008-12-22 08:39:06 ----A---- C:\Windows\system32\rdpcfgex.dll
    2008-12-22 08:39:06 ----A---- C:\Windows\system32\dispex.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\spwmp.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\riched32.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\Nlsdl.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\msidle.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\KBDKOR.DLL
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\KBDJPN.DLL
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\iscsilog.dll
    2008-12-22 08:39:05 ----A---- C:\Windows\system32\idndl.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\wmploc.DLL
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\vga64k.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\vga256.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\vga.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\tsddd.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\framebuf.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\dxmasf.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\dmdskres2.dll
    2008-12-22 08:39:04 ----A---- C:\Windows\system32\bootstr.dll
    2008-12-22 08:39:03 ----A---- C:\Windows\system32\spwizres.dll
    2008-12-22 08:39:03 ----A---- C:\Windows\system32\gatherWirelessInfo.vbs
    2008-12-22 08:39:03 ----A---- C:\Windows\system32\gatherWiredInfo.vbs
    2008-12-22 08:39:03 ----A---- C:\Windows\system32\f3ahvoas.dll
    2008-12-22 08:39:02 ----A---- C:\Windows\system32\fsmgmt.msc
    2008-12-22 08:39:01 ----A---- C:\Windows\system32\vsp1cln.exe
    2008-12-22 08:39:01 ----A---- C:\Windows\system32\perfmon.msc
    2008-12-22 08:38:34 ----A---- C:\Windows\system32\xmllite.dll
    2008-12-22 08:38:34 ----A---- C:\Windows\system32\wbemcomn.dll
    2008-12-22 08:38:30 ----A---- C:\Windows\system32\sqmapi.dll
    2008-12-22 08:38:30 ----A---- C:\Windows\system32\SmiInstaller.dll
    2008-12-22 08:38:30 ----A---- C:\Windows\system32\SmiEngine.dll
    2008-12-22 08:38:24 ----A---- C:\Windows\system32\wdscore.dll
    2008-12-22 08:38:24 ----A---- C:\Windows\system32\PkgMgr.exe
    2008-12-22 08:38:10 ----A---- C:\Windows\system32\mspatcha.dll
    2008-12-22 08:38:10 ----A---- C:\Windows\system32\drvstore.dll
    2008-12-22 08:38:10 ----A---- C:\Windows\system32\dpx.dll
    2008-12-22 08:38:09 ----A---- C:\Windows\system32\msdelta.dll
    2008-12-22 08:38:03 ----A---- C:\Windows\system32\kbd106.dll
    2008-12-21 18:49:57 ----D---- C:\Program Files\Common Files\Scanner
    2008-12-21 18:49:55 ----A---- C:\Windows\system32\vetredir.dll
    2008-12-21 18:49:55 ----A---- C:\Windows\system32\isafprod.dll
    2008-12-21 18:49:55 ----A---- C:\Windows\system32\isafeif.dll
    2008-12-21 18:49:47 ----D---- C:\ProgramData\CA
    2008-12-21 18:49:42 ----D---- C:\Program Files\CA
    2008-12-21 18:39:50 ----D---- C:\ProgramData\CA-SupportBridge
    2008-12-21 18:03:33 ----D---- C:\Users\Fred\AppData\Roaming\Adobe
    2008-12-21 17:35:01 ----D---- C:\Program Files\Google
    2008-12-21 15:30:27 ----D---- C:\Program Files\Felitec
    2008-12-21 13:55:13 ----D---- C:\ProgramData\WEBREG
    2008-12-21 13:53:38 ----D---- C:\Users\Fred\AppData\Roaming\HP
    2008-12-21 13:49:13 ----D---- C:\ProgramData\HPSSUPPLY
    2008-12-21 13:46:41 ----D---- C:\Program Files\Common Files\Hewlett-Packard
    2008-12-21 13:40:40 ----A---- C:\Windows\system32\hpz3l4v2.dll
    2008-12-21 13:38:38 ----A---- C:\Windows\system32\hpzids01.dll
    2008-12-21 13:38:37 ----A---- C:\Windows\system32\hpowiav1.dll
    2008-12-21 13:38:37 ----A---- C:\Windows\system32\hpovst01.dll
    2008-12-21 13:38:37 ----A---- C:\Windows\system32\hpotiop1.dll
    2008-12-21 13:19:17 ----D---- C:\Program Files\Quicken Backup
    2008-12-21 13:15:31 ----D---- C:\Program Files\Common Files\AnswerWorks 5.0
    2008-12-21 13:14:56 ----A---- C:\Windows\system32\acXMLParser.dll
    2008-12-21 13:14:55 ----A---- C:\Windows\system32\cdintf300.dll
    2008-12-21 13:14:40 ----D---- C:\Users\Fred\AppData\Roaming\Intuit
    2008-12-21 13:14:36 ----D---- C:\Program Files\Common Files\Palo Alto Software
    2008-12-21 13:14:28 ----D---- C:\Program Files\Common Files\Intuit
    2008-12-21 13:14:25 ----D---- C:\Program Files\Quicken
    2008-12-21 13:14:19 ----A---- C:\Windows\QUICKEN.INI
    2008-12-21 13:14:05 ----D---- C:\ProgramData\Intuit
    2008-12-21 12:35:40 ----D---- C:\Users\Fred\AppData\Roaming\Mozilla
    2008-12-21 11:56:59 ----A---- C:\Windows\system32\es.dll
    2008-12-21 11:56:31 ----SHD---- C:\System Volume Information
    2008-12-21 11:44:51 ----D---- C:\Users\Fred\AppData\Roaming\Yahoo!
    2008-12-21 11:44:51 ----D---- C:\ProgramData\Yahoo! Companion
    2008-12-21 11:44:24 ----A---- C:\Windows\ODBC.INI
    2008-12-21 11:44:21 ----A---- C:\Windows\system32\mdimon.dll
    2008-12-21 11:43:25 ----D---- C:\Program Files\Microsoft ActiveSync
    2008-12-21 11:42:52 ----D---- C:\Program Files\Common Files\DESIGNER
    2008-12-21 11:42:02 ----D---- C:\Windows\PCHEALTH
    2008-12-21 11:42:02 ----D---- C:\Program Files\Microsoft.NET
    2008-12-21 10:28:50 ----D---- C:\Users\Fred\AppData\Roaming\CallingID
    2008-12-21 10:23:13 ----HD---- C:\Config.msi
    2008-12-21 10:22:55 ----D---- C:\Windows\Downloaded Installations
    2008-12-21 10:22:47 ----A---- C:\caavsetupLog.txt
    2008-12-21 10:21:09 ----A---- C:\caisslog.txt
    2008-12-21 09:43:23 ----A---- C:\Windows\system32\winipsec.dll
    2008-12-21 09:43:23 ----A---- C:\Windows\system32\polstore.dll
    2008-12-21 09:43:23 ----A---- C:\Windows\system32\IPSECSVC.DLL
    2008-12-21 09:43:23 ----A---- C:\Windows\system32\FwRemoteSvr.dll
    2008-12-21 09:42:14 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
    2008-12-21 09:42:14 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
    2008-12-21 09:42:14 ----A---- C:\Windows\system32\PortableDeviceApi.dll
    2008-12-21 09:39:36 ----A---- C:\Windows\system32\psisdecd.dll
    2008-12-21 09:39:36 ----A---- C:\Windows\system32\EncDec.dll
    2008-12-21 09:38:33 ----A---- C:\Windows\system32\gdi32.dll
    2008-12-21 09:37:36 ----A---- C:\Windows\system32\mshtml.dll
    2008-12-21 09:36:27 ----A---- C:\Windows\system32\Apphlpdm.dll
    2008-12-21 09:36:25 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
    2008-12-21 09:36:25 ----A---- C:\Windows\system32\gameux.dll
    2008-12-21 09:35:55 ----A---- C:\Windows\system32\wmpeffects.dll
    2008-12-21 09:35:02 ----A---- C:\Windows\system32\msxml3r.dll
    2008-12-21 09:35:02 ----A---- C:\Windows\system32\msxml3.dll
    2008-12-21 09:34:05 ----A---- C:\Windows\system32\netapi32.dll
    2008-12-21 09:33:36 ----A---- C:\Windows\system32\tzres.dll
    2008-12-21 09:32:28 ----A---- C:\Windows\system32\shell32.dll
    2008-12-21 09:30:38 ----A---- C:\Windows\explorer.exe
    2008-12-21 09:28:56 ----A---- C:\Windows\system32\wininet.dll
    2008-12-21 09:28:56 ----A---- C:\Windows\system32\jsproxy.dll
    2008-12-21 09:28:56 ----A---- C:\Windows\system32\ieui.dll
    2008-12-21 09:28:55 ----A---- C:\Windows\system32\ieframe.dll
    2008-12-21 09:28:52 ----A---- C:\Windows\system32\urlmon.dll
    2008-12-21 09:28:52 ----A---- C:\Windows\system32\mstime.dll
    2008-12-21 09:28:51 ----A---- C:\Windows\system32\iertutil.dll
    2008-12-21 09:27:18 ----A---- C:\Windows\system32\NlsLexicons0046.dll
    2008-12-21 09:27:18 ----A---- C:\Windows\system32\NlsLexicons0045.dll
    2008-12-21 09:27:17 ----A---- C:\Windows\system32\NlsLexicons0049.dll
    2008-12-21 09:27:17 ----A---- C:\Windows\system32\NlsLexicons0047.dll
    2008-12-21 09:27:17 ----A---- C:\Windows\system32\NlsLexicons0039.dll
    2008-12-21 09:27:17 ----A---- C:\Windows\system32\NlsLexicons0021.dll
    2008-12-21 09:27:17 ----A---- C:\Windows\system32\NlsLexicons0020.dll
    2008-12-21 09:27:16 ----A---- C:\Windows\system32\NlsLexicons0026.dll
    2008-12-21 09:27:16 ----A---- C:\Windows\system32\NlsLexicons0024.dll
    2008-12-21 09:27:16 ----A---- C:\Windows\system32\NlsLexicons0022.dll
    2008-12-21 09:27:15 ----A---- C:\Windows\system32\NlsLexicons0027.dll
    2008-12-21 09:27:15 ----A---- C:\Windows\system32\NlsLexicons0013.dll
    2008-12-21 09:27:15 ----A---- C:\Windows\system32\NlsLexicons0011.dll
    2008-12-21 09:27:15 ----A---- C:\Windows\system32\NlsLexicons0010.dll
    2008-12-21 09:27:14 ----A---- C:\Windows\system32\NlsLexicons0019.dll
    2008-12-21 09:27:14 ----A---- C:\Windows\system32\NlsLexicons0018.dll
    2008-12-21 09:27:14 ----A---- C:\Windows\system32\NlsLexicons0001.dll
    2008-12-21 09:27:13 ----A---- C:\Windows\system32\NlsLexicons0007.dll
    2008-12-21 09:27:13 ----A---- C:\Windows\system32\NlsLexicons0003.dll
    2008-12-21 09:27:13 ----A---- C:\Windows\system32\NlsLexicons0002.dll
    2008-12-21 09:27:12 ----A---- C:\Windows\system32\NlsLexicons004e.dll
    2008-12-21 09:27:12 ----A---- C:\Windows\system32\NlsLexicons004c.dll
    2008-12-21 09:27:12 ----A---- C:\Windows\system32\NlsLexicons004b.dll
    2008-12-21 09:27:12 ----A---- C:\Windows\system32\NlsLexicons004a.dll
    2008-12-21 09:27:12 ----A---- C:\Windows\system32\NlsLexicons0009.dll
    2008-12-21 09:27:11 ----A---- C:\Windows\system32\NlsLexicons003e.dll
    2008-12-21 09:27:11 ----A---- C:\Windows\system32\NlsLexicons002a.dll
    2008-12-21 09:27:11 ----A---- C:\Windows\system32\NlsLexicons001b.dll
    2008-12-21 09:27:11 ----A---- C:\Windows\system32\NlsLexicons001a.dll
    2008-12-21 09:27:10 ----A---- C:\Windows\system32\NlsLexicons001d.dll
    2008-12-21 09:27:10 ----A---- C:\Windows\system32\NlsLexicons000d.dll
    2008-12-21 09:27:10 ----A---- C:\Windows\system32\NlsLexicons000c.dll
    2008-12-21 09:27:10 ----A---- C:\Windows\system32\NlsLexicons000a.dll
    2008-12-21 09:27:09 ----A---- C:\Windows\system32\NlsLexicons0414.dll
    2008-12-21 09:27:09 ----A---- C:\Windows\system32\NlsLexicons000f.dll
    2008-12-21 09:27:08 ----A---- C:\Windows\system32\NlsLexicons0416.dll
    2008-12-21 09:27:07 ----A---- C:\Windows\system32\NlsLexicons081a.dll
    2008-12-21 09:27:07 ----A---- C:\Windows\system32\NlsLexicons0816.dll
    2008-12-21 09:27:06 ----A---- C:\Windows\system32\NlsModels0011.dll
    2008-12-21 09:27:06 ----A---- C:\Windows\system32\NlsData0049.dll
    2008-12-21 09:27:06 ----A---- C:\Windows\system32\NlsData0047.dll
    2008-12-21 09:27:06 ----A---- C:\Windows\system32\NlsData0046.dll
    2008-12-21 09:27:06 ----A---- C:\Windows\system32\NlsData0045.dll
    2008-12-21 09:27:05 ----A---- C:\Windows\system32\NlsData0039.dll
    2008-12-21 09:27:05 ----A---- C:\Windows\system32\NlsData0024.dll
    2008-12-21 09:27:05 ----A---- C:\Windows\system32\NlsData0022.dll
    2008-12-21 09:27:05 ----A---- C:\Windows\system32\NlsData0021.dll
    2008-12-21 09:27:05 ----A---- C:\Windows\system32\NlsData0020.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0027.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0026.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0018.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0013.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0011.dll
    2008-12-21 09:27:04 ----A---- C:\Windows\system32\NlsData0010.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0019.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0007.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0003.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0002.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0001.dll
    2008-12-21 09:27:03 ----A---- C:\Windows\system32\NlsData0000.dll
    2008-12-21 09:27:02 ----A---- C:\Windows\system32\NlsData004c.dll
    2008-12-21 09:27:02 ----A---- C:\Windows\system32\NlsData004b.dll
    2008-12-21 09:27:02 ----A---- C:\Windows\system32\NlsData004a.dll
    2008-12-21 09:27:02 ----A---- C:\Windows\system32\NlsData0009.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData004e.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData003e.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData002a.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData001d.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData001b.dll
    2008-12-21 09:27:01 ----A---- C:\Windows\system32\NlsData001a.dll
    2008-12-21 09:27:00 ----A---- C:\Windows\system32\NlsData000f.dll
    2008-12-21 09:27:00 ----A---- C:\Windows\system32\NlsData000d.dll
    2008-12-21 09:27:00 ----A---- C:\Windows\system32\NlsData000c.dll
    2008-12-21 09:27:00 ----A---- C:\Windows\system32\NlsData000a.dll
    2008-12-21 09:26:59 ----A---- C:\Windows\system32\NlsData081a.dll
    2008-12-21 09:26:59 ----A---- C:\Windows\system32\NlsData0816.dll
    2008-12-21 09:26:59 ----A---- C:\Windows\system32\NlsData0416.dll
    2008-12-21 09:26:59 ----A---- C:\Windows\system32\NlsData0414.dll
    2008-12-21 09:26:59 ----A---- C:\Windows\system32\NaturalLanguage6.dll
    2008-12-21 09:26:58 ----A---- C:\Windows\system32\NlsLexicons0c1a.dll
    2008-12-21 09:26:58 ----A---- C:\Windows\system32\NlsData0c1a.dll
    2008-12-21 09:25:52 ----A---- C:\Windows\system32\kbd106n.dll
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\winresume.exe
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\winload.exe
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\srdelayed.exe
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\srcore.dll
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\srclient.dll
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\setbcdlocale.dll
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\rstrui.exe
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\kd1394.dll
    2008-12-21 09:25:50 ----A---- C:\Windows\system32\ci.dll
    2008-12-21 09:24:41 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
    2008-12-21 09:24:41 ----A---- C:\Windows\system32\WindowsCodecs.dll
    2008-12-21 09:24:41 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
    2008-12-21 09:23:41 ----A---- C:\Windows\system32\win32spl.dll
    2008-12-21 09:23:41 ----A---- C:\Windows\system32\printcom.dll
    2008-12-21 09:23:35 ----A---- C:\Windows\system32\wshrm.dll
    2008-12-21 09:23:13 ----A---- C:\Windows\system32\rrinstaller.exe
    2008-12-21 09:23:13 ----A---- C:\Windows\system32\mfps.dll
    2008-12-21 09:23:13 ----A---- C:\Windows\system32\mfpmp.exe
    2008-12-21 09:23:13 ----A---- C:\Windows\system32\mferror.dll
    2008-12-21 09:23:13 ----A---- C:\Windows\system32\mf.dll
    2008-12-21 09:23:12 ----A---- C:\Windows\system32\WMVCORE.DLL
    2008-12-21 09:23:12 ----A---- C:\Windows\system32\WMNetMgr.dll
    2008-12-21 09:23:12 ----A---- C:\Windows\system32\logagent.exe
    2008-12-21 09:22:56 ----A---- C:\Windows\system32\INETRES.dll
    2008-12-21 09:22:56 ----A---- C:\Windows\system32\inetcomm.dll
    2008-12-21 09:22:50 ----A---- C:\Windows\system32\connect.dll
    2008-12-21 09:22:44 ----A---- C:\Windows\system32\quartz.dll
    2008-12-21 09:21:44 ----D---- C:\Program Files\MSXML 4.0
    2008-12-21 09:21:06 ----A---- C:\Windows\system32\ntoskrnl.exe
    2008-12-21 09:21:06 ----A---- C:\Windows\system32\ntkrnlpa.exe
    2008-12-21 09:20:52 ----A---- C:\Windows\system32\msxml6r.dll
    2008-12-21 09:20:52 ----A---- C:\Windows\system32\msxml6.dll
    2008-12-21 09:11:16 ----D---- C:\Users\Fred\AppData\Roaming\Snapfish
    2008-12-21 09:10:48 ----D---- C:\Users\Fred\AppData\Roaming\Identities
    2008-12-21 09:09:44 ----D---- C:\Users\Fred\AppData\Roaming\Macromedia
    2008-12-21 09:09:16 ----D---- C:\Users\Fred\AppData\Roaming\Hewlett-Packard
    2008-12-21 09:06:32 ----SD---- C:\Users\Fred\AppData\Roaming\Microsoft
    2008-12-21 09:06:32 ----D---- C:\Users\Fred\AppData\Roaming\Media Center Programs
    2008-12-21 09:03:53 ----A---- C:\Windows\system32\wups2.dll
    2008-12-21 09:03:53 ----A---- C:\Windows\system32\wucltux.dll
    2008-12-21 09:03:53 ----A---- C:\Windows\system32\wuaueng.dll
    2008-12-21 09:03:53 ----A---- C:\Windows\system32\wuauclt.exe
    2008-12-21 09:03:41 ----A---- C:\Windows\system32\wups.dll
    2008-12-21 09:03:41 ----A---- C:\Windows\system32\wudriver.dll
    2008-12-21 09:03:41 ----A---- C:\Windows\system32\wuapi.dll
    2008-12-21 09:03:29 ----A---- C:\Windows\system32\wuwebv.dll
    2008-12-21 09:03:29 ----A---- C:\Windows\system32\wuapp.exe
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Templates
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Start Menu
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Favorites
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Documents
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Desktop
    2008-12-21 09:02:43 ----SHD---- C:\ProgramData\Application Data
    2008-12-21 09:02:43 ----SHD---- C:\Documents and Settings
    2008-12-21 09:02:21 ----D---- C:\Windows\SoftwareDistribution

    ======List of files/folders modified in the last 1 months======

    2008-12-30 22:05:34 ----D---- C:\Windows\Prefetch
    2008-12-30 22:05:11 ----RD---- C:\Program Files
    2008-12-30 22:05:01 ----D---- C:\Windows\Temp
    2008-12-30 20:03:02 ----D---- C:\Windows\System32
    2008-12-30 20:03:02 ----D---- C:\Windows\inf
    2008-12-30 20:03:02 ----A---- C:\Windows\system32\PerfStringBackup.INI
    2008-12-30 19:44:29 ----D---- C:\Windows\system32\drivers
    2008-12-30 10:49:37 ----SHD---- C:\Windows\Installer
    2008-12-30 10:49:33 ----HD---- C:\ProgramData
    2008-12-30 08:58:28 ----D---- C:\Windows\Tasks
    2008-12-30 08:58:28 ----D---- C:\Windows\system32\Tasks
    2008-12-29 10:30:25 ----D---- C:\WINDOWS
    2008-12-28 22:16:41 ----A---- C:\Windows\win.ini
    2008-12-28 22:14:19 ----D---- C:\ProgramData\HP
    2008-12-28 22:13:43 ----D---- C:\Windows\winsxs
    2008-12-28 22:12:26 ----D---- C:\Windows\twain_32
    2008-12-28 21:48:47 ----D---- C:\Windows\system32\catroot
    2008-12-28 13:59:52 ----D---- C:\Windows\system32\NDF
    2008-12-27 23:57:20 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-12-27 15:54:20 ----D---- C:\Windows\system32\catroot2
    2008-12-27 15:51:50 ----D---- C:\Program Files\Common Files
    2008-12-26 17:35:11 ----SD---- C:\ProgramData\Microsoft
    2008-12-25 23:27:11 ----RSD---- C:\Windows\Fonts
    2008-12-25 18:28:04 ----D---- C:\Windows\system32\WDI
    2008-12-24 20:50:13 ----D---- C:\Program Files\Rhapsody
    2008-12-24 20:46:42 ----D---- C:\ProgramData\Roxio
    2008-12-24 20:37:37 ----D---- C:\ProgramData\Sonic
    2008-12-24 13:20:58 ----D---- C:\Program Files\Common Files\InstallShield
    2008-12-23 16:46:09 ----D---- C:\Windows\SMINST
    2008-12-23 12:29:06 ----D---- C:\Windows\system32\LogFiles
    2008-12-23 12:15:57 ----D---- C:\Windows\rescache
    2008-12-23 11:57:27 ----D---- C:\Windows\system32\en-US
    2008-12-23 11:57:27 ----D---- C:\Windows\PolicyDefinitions
    2008-12-22 20:28:39 ----D---- C:\Program Files\Common Files\PX Storage Engine
    2008-12-22 17:06:37 ----AD---- C:\Program Files\Common Files\LightScribe
    2008-12-22 12:26:45 ----D---- C:\Program Files\Common Files\Adobe
    2008-12-22 12:26:41 ----D---- C:\ProgramData\Adobe
    2008-12-22 11:41:59 ----D---- C:\Windows\Logs
    2008-12-22 09:48:51 ----D---- C:\Windows\Microsoft.NET
    2008-12-22 09:48:28 ----RSD---- C:\Windows\assembly
    2008-12-22 09:30:03 ----D---- C:\Windows\system32\RTCOM
    2008-12-22 09:29:17 ----A---- C:\Windows\DIFxAPI.dll
    2008-12-22 09:29:13 ----D---- C:\Program Files\Realtek
    2008-12-22 09:16:52 ----SHD---- C:\Boot
    2008-12-22 09:16:25 ----ASH---- C:\Program Files\desktop.ini
    2008-12-22 09:07:13 ----D---- C:\Program Files\Windows Sidebar
    2008-12-22 09:07:13 ----D---- C:\Program Files\Windows Media Player
    2008-12-22 09:07:13 ----D---- C:\Program Files\Windows Mail
    2008-12-22 09:07:13 ----D---- C:\Program Files\Windows Collaboration
    2008-12-22 09:07:13 ----D---- C:\Program Files\Windows Calendar
    2008-12-22 09:07:13 ----D---- C:\Program Files\Movie Maker
    2008-12-22 09:07:13 ----D---- C:\Program Files\Internet Explorer
    2008-12-22 09:07:12 ----D---- C:\Program Files\Windows Photo Gallery
    2008-12-22 09:07:12 ----D---- C:\Program Files\Windows Journal
    2008-12-22 09:07:12 ----D---- C:\Program Files\Windows Defender
    2008-12-22 09:07:12 ----D---- C:\Program Files\Common Files\System
    2008-12-22 09:07:11 ----D---- C:\Windows\servicing
    2008-12-22 09:07:11 ----D---- C:\Windows\ehome
    2008-12-22 09:07:09 ----D---- C:\Windows\MSAgent
    2008-12-22 09:07:08 ----D---- C:\Windows\L2Schemas
    2008-12-22 09:07:08 ----D---- C:\Windows\IME
    2008-12-22 09:07:08 ----D---- C:\Windows\DigitalLocker
    2008-12-22 09:07:07 ----D---- C:\Windows\system32\XPSViewer
    2008-12-22 09:07:07 ----D---- C:\Windows\system32\ko-KR
    2008-12-22 09:07:07 ----D---- C:\Windows\system32\da-DK
    2008-12-22 09:07:07 ----D---- C:\Windows\system32\com
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\sysprep
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\oobe
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\migration
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\it-IT
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\el-GR
    2008-12-22 09:07:03 ----D---- C:\Windows\system32\de-DE
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\sv-SE
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\SLUI
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\setup
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\ru-RU
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\pt-PT
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\ias
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\hu-HU
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\he-IL
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\fr-FR
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\fi-FI
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\cs-CZ
    2008-12-22 09:07:02 ----D---- C:\Windows\system32\AdvancedInstallers
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\zh-TW
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\zh-CN
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\ro-RO
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\pl-PL
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\manifeststore
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\ja-JP
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\es-ES
    2008-12-22 09:07:01 ----D---- C:\Windows\system32\en
    2008-12-22 09:07:00 ----D---- C:\Windows\system32\wbem
    2008-12-22 09:07:00 ----D---- C:\Windows\system32\tr-TR
    2008-12-22 09:07:00 ----D---- C:\Windows\system32\nl-NL
    2008-12-22 09:07:00 ----D---- C:\Windows\system32\nb-NO
    2008-12-22 09:07:00 ----D---- C:\Windows\system32\ar-SA
    2008-12-22 09:06:59 ----D---- C:\Windows\system32\pt-BR
    2008-12-22 09:06:59 ----D---- C:\Windows\system32\migwiz
    2008-12-22 09:06:40 ----D---- C:\Windows\AppPatch
    2008-12-22 09:06:34 ----D---- C:\Windows\system32\Boot
    2008-12-22 09:06:34 ----D---- C:\Windows\Boot
    2008-12-22 08:50:53 ----A---- C:\Windows\system32\ifxcardm.dll
    2008-12-22 08:50:53 ----A---- C:\Windows\system32\axaltocm.dll
    2008-12-21 23:11:25 ----D---- C:\Windows\ModemLogs
    2008-12-21 22:49:49 ----HD---- C:\hp
    2008-12-21 18:42:05 ----A---- C:\Windows\SYSTEM.INI
    2008-12-21 13:49:13 ----D---- C:\Program Files\HP
    2008-12-21 13:48:45 ----D---- C:\Program Files\Common Files\HP
    2008-12-21 13:44:21 ----D---- C:\ProgramData\Hewlett-Packard
    2008-12-21 11:57:44 ----D---- C:\Windows\Panther
    2008-12-21 11:55:25 ----D---- C:\Program Files\Common Files\microsoft shared
    2008-12-21 11:54:39 ----D---- C:\Program Files\Microsoft Works
    2008-12-21 11:43:30 ----D---- C:\Windows\ShellNew
    2008-12-21 11:42:54 ----D---- C:\Program Files\Microsoft Office
    2008-12-21 11:39:28 ----D---- C:\Windows\system
    2008-12-21 10:17:14 ----D---- C:\ProgramData\Symantec
    2008-12-21 10:17:14 ----D---- C:\Program Files\Common Files\Symantec Shared
    2008-12-21 09:54:46 ----D---- C:\Windows\Debug
    2008-12-21 09:46:50 ----D---- C:\Windows\system32\ras
    2008-12-21 09:46:50 ----D---- C:\Windows\system32\icsxml
    2008-12-21 09:11:01 ----SHD---- C:\$Recycle.Bin
    2008-12-21 09:06:22 ----RD---- C:\Users
    2008-12-21 09:02:45 ----D---- C:\Windows\system32\restore
    2008-12-09 15:24:38 ----A---- C:\Windows\system32\mrt.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 KmxAgent;KmxAgent; C:\Windows\System32\DRIVERS\kmxagent.sys [2008-03-21 63504]
    R1 KmxFile;KmxFile; C:\Windows\System32\DRIVERS\KmxFile.sys [2008-03-21 45584]
    R1 KmxFilter;HIPS Core Filter Driver; C:\Windows\system32\DRIVERS\KmxFilter.sys [2008-05-30 51704]
    R1 VETEFILE;VET File Scan Engine; C:\Windows\system32\drivers\VETEFILE.sys [2008-12-21 880560]
    R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\Windows\system32\drivers\VETFDDNT.sys [2008-08-30 21488]
    R1 VET-FILT;VET File System Filter; C:\Windows\system32\drivers\VET-FILT.sys [2008-08-30 26352]
    R1 VETMONNT;VET File Monitor; C:\Windows\system32\drivers\VETMONNT.sys [2008-08-30 32240]
    R1 VET-REC;VET File System Recognizer; C:\Windows\system32\drivers\VET-REC.sys [2008-08-30 21104]
    R2 KmxCF;KmxCF; C:\Windows\System32\DRIVERS\KmxCF.sys [2008-06-04 138744]
    R2 KmxSbx;KmxSbx; C:\Windows\System32\DRIVERS\KmxSbx.sys [2008-03-21 66576]
    R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672]
    R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-10-18 8704]
    R3 Dot4;MS IEEE-1284.4 Driver; C:\Windows\system32\DRIVERS\Dot4.sys [2008-01-19 131584]
    R3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\Windows\system32\DRIVERS\Dot4Prt.sys [2008-01-19 16384]
    R3 dot4usb;MS Dot4USB Filter Dot4USB Filter; C:\Windows\system32\DRIVERS\dot4usb.sys [2008-01-19 36864]
    R3 HSF_DP;HSF_DP; C:\Windows\system32\DRIVERS\HSX_DP.sys [2008-05-08 980992]
    R3 HSXHWBS2;HSXHWBS2; C:\Windows\system32\DRIVERS\HSXHWBS2.sys [2008-05-08 266752]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-01-15 2047576]
    R3 KmxCfg;KmxCfg; C:\Windows\System32\DRIVERS\kmxcfg.sys [2008-05-30 88816]
    R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-05-03 1065384]
    R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-05-22 7465312]
    R3 pcouffin;VSO Software pcouffin; C:\Windows\System32\Drivers\pcouffin.sys [2008-12-22 47360]
    R3 Ps2;PS2; C:\Windows\system32\DRIVERS\PS2.sys [2005-12-12 19072]
    R3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328]
    R3 VETEBOOT;VET Boot Scan Engine; C:\Windows\system32\drivers\VETEBOOT.sys [2008-12-21 108368]
    R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2008-05-08 661504]
    R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
    S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
    S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
    S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
    S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
    S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
    S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
    S3 PcdrNdisuio;PCDRNDISUIO Usermode I/O Protocol; C:\Windows\system32\DRIVERS\pcdrndisuio.sys []
    S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2008-11-19 109056]
    R2 CAISafe;CAISafe; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe [2008-08-30 144696]
    R2 FreeAgentGoNext Service;Seagate Service; C:\Program Files\Seagate\SeagateManager\Sync\FreeAgentService.exe [2008-10-28 156968]
    R2 HP Health Check Service;HP Health Check Service; c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe [2007-05-24 61440]
    R2 hpqddsvc;HP CUE DeviceDiscovery Service; C:\Windows\system32\svchost.exe [2008-01-19 21504]
    R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-09-26 283912]
    R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
    R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0; C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
    R2 Net Driver HPZ12;Net Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
    R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-05-22 118784]
    R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-19 21504]
    R2 ScsiAccess;ScsiAccess; I:\Program Files\Photodex\ScsiAccess.exe [2008-12-23 181312]
    R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192]
    R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296]
    R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2008-03-19 145936]
    R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-04-15 281104]
    R2 VETMSGNT;VET Message Service; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe [2008-08-30 255216]
    R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-10-18 386560]
    R3 CaCCProvSP;CaCCProvSP; C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe [2008-12-28 214256]
    R3 hpqcxs08;hpqcxs08; C:\Windows\system32\svchost.exe [2008-01-19 21504]
    R3 PPCtlPriv;PPCtlPriv; C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-08-27 185584]
    S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-07-31 136120]
    S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
    S3 RoxMediaDB9;RoxMediaDB9; c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-05-11 887544]
    S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe [2007-05-03 74656]

    -----------------EOF-----------------
     
  5. 2008/12/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hi Fred,

    It appears you have a flash drive infection. Please download Flash_Disinfector by sUBs and save it to your desktop:

    NOTE: In the event you already have Flash_Disinfector, this is a new version that I need you to download.

    • Plug in your USB flash drive.
    • Double-click Flash_Disinfector.exe to run it.
    • Follow any prompts that may appear.
    • Your desktop will vanish for a while, and then reappear. This is normal.
    • Wait until the program has finished scanning, then please exit the program. If you use more than 1 flash drive, run the tool with each plugged in.


    Next, download ComboFix by sUBs from here, saving the file to your desktop.


    Disable realtime protection applications as they sometimes interfere with the tool. Check this link for your applicable programs.

    • Close all open programs and windows
    • Double click ComboFix.exe and follow the prompts.
    • It may reboot your computer and resume running when you logon. Wait for it to complete. When finished, it will open a log for you. Post that log in your next reply.
    Note: Do not mouseclick combofix's window while its running. That may cause it to stall
     
  6. 2008/12/30
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Can this also be a external drive as it is plugged into a usb port or is this just a flash drive.
     
  7. 2008/12/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Could be an external usb drive as well. The drives affected are G: and I:
     
  8. 2008/12/30
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Host File Infected

    I have a G drive showing as a removable drive but no i drive.

    ComboFix 08-12-30.01 - Fred 2008-12-31 0:13:20.1 - NTFSx86
    Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1033.18.3454.2300 [GMT -5:00]
    Running from: c:\users\Fred\Downloads\ComboFix.exe
    AV: CA Anti-Virus *On-access scanning enabled* (Updated)
    AV: Norton Internet Security *On-access scanning enabled* (Outdated)
    FW: Norton Internet Security *disabled*
    FW: CA Personal Firewall *disabled*
    * Created a new restore point
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    c:\program files\INSTALL.LOG
    c:\users\Fred\AppData\Roaming\inst.exe
    c:\windows\system32\hpowiav1.dll
    c:\windows\system32\mpg4c32.dll
    c:\windows\system32\Pncrt.dll
    D:\resycled
    d:\resycled\boot.com
    H:\resycled
    h:\resycled\boot.com
    I:\Autorun.inf
    I:\resycled
    i:\resycled\boot.com

    .
    ((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-31 )))))))))))))))))))))))))))))))
    .

    2008-12-30 22:05 . 2008-12-30 22:05 <DIR> d-------- C:\rsit
    2008-12-30 22:05 . 2008-12-30 22:05 <DIR> d-------- c:\program files\trend micro
    2008-12-30 10:49 . 2008-12-30 10:49 <DIR> d-------- c:\users\All Users\HP Product Assistant
    2008-12-30 10:49 . 2008-12-30 10:49 <DIR> d-------- c:\programdata\HP Product Assistant
    2008-12-28 22:02 . 2007-02-28 19:32 6,600 --a------ c:\windows\hpomdl18.dat
    2008-12-28 20:29 . 2008-12-28 20:29 116 --a------ c:\windows\wininit.ini
    2008-12-28 19:44 . 2008-12-30 19:52 <DIR> d-------- c:\users\All Users\Spybot - Search & Destroy
    2008-12-28 19:44 . 2008-12-30 19:52 <DIR> d-------- c:\programdata\Spybot - Search & Destroy
    2008-12-28 14:47 . 2008-12-28 14:47 <DIR> d-------- c:\users\Fred\AppData\Roaming\WinPatrol
    2008-12-28 14:01 . 2008-12-30 19:54 85,308 --a------ c:\windows\System32\drivers\kmxcfg.u2k0
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k7
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k6
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k5
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k4
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k3
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k2
    2008-12-28 14:01 . 2008-12-30 19:54 64 --a------ c:\windows\System32\drivers\kmxcfg.u2k1
    2008-12-27 23:56 . 2008-12-27 23:56 <DIR> dr------- c:\windows\System32\config\systemprofile\Searches
    2008-12-27 23:56 . 2008-12-27 23:56 <DIR> dr------- c:\windows\System32\config\systemprofile\Saved Games
    2008-12-27 23:56 . 2008-12-27 23:56 <DIR> dr------- c:\windows\System32\config\systemprofile\Links
    2008-12-27 15:27 . 2008-12-28 23:06 <DIR> d-------- C:\ScreenSaver
    2008-12-27 14:51 . 2008-12-27 14:54 <DIR> d-------- c:\users\All Users\LoanSpread
    2008-12-27 14:51 . 2008-12-27 14:54 <DIR> d-------- c:\programdata\LoanSpread
    2008-12-27 14:43 . 2008-12-27 14:43 <DIR> d-------- c:\program files\Loan Calculator Plus25
    2008-12-27 14:43 . 1999-06-21 16:40 86,016 --a------ c:\windows\System32\KeyLbE32.dll
    2008-12-27 14:43 . 1996-08-20 21:37 15,840 --a------ c:\windows\System32\MACHNM1.EXE
    2008-12-27 09:49 . 2008-12-27 09:49 <DIR> d-------- c:\users\All Users\vsosdk
    2008-12-27 09:49 . 2008-12-27 09:49 <DIR> d-------- c:\programdata\vsosdk
    2008-12-26 22:28 . 2008-12-26 22:28 <DIR> d-------- C:\Home
    2008-12-26 00:28 . 2008-12-28 00:15 <DIR> d-------- c:\users\Fred\AppData\Roaming\Arcsoft
    2008-12-26 00:28 . 2008-12-28 00:15 <DIR> d-------- c:\users\All Users\ArcSoft
    2008-12-26 00:28 . 2008-12-28 00:15 <DIR> d-------- c:\programdata\ArcSoft
    2008-12-26 00:28 . 2008-12-27 23:55 <DIR> d-------- c:\program files\Common Files\ArcSoft
    2008-12-26 00:28 . 2008-12-26 00:28 <DIR> d-------- c:\program files\ArcSoft
    2008-12-26 00:20 . 2007-10-25 07:49 107,026 --------- c:\windows\hpqins13.dat.temp
    2008-12-25 22:38 . 2008-12-25 22:58 <DIR> d-a------ c:\users\All Users\TEMP
    2008-12-25 22:38 . 2008-12-25 22:58 <DIR> d-a------ c:\programdata\TEMP
    2008-12-25 18:30 . 2008-12-25 18:30 <DIR> d-------- C:\external drive
    2008-12-24 21:17 . 2008-12-24 21:17 <DIR> d-------- c:\users\Fred\AppData\Roaming\NeroDCTemplates
    2008-12-24 20:37 . 2008-12-24 20:37 <DIR> d-------- c:\users\Fred\AppData\Roaming\Roxio
    2008-12-24 20:22 . 2008-12-24 20:22 <DIR> d-------- c:\users\Fred\AppData\Roaming\Printer Info Cache
    2008-12-24 20:22 . 2008-12-24 20:28 <DIR> d-------- c:\users\Fred\AppData\Roaming\Image Zone Express
    2008-12-24 20:16 . 2008-12-24 20:16 0 --ah----- c:\windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
    2008-12-24 20:12 . 2008-12-26 17:14 130,834 --------- c:\windows\hpoins18.dat.temp
    2008-12-24 20:12 . 2007-02-28 19:32 6,600 --------- c:\windows\hpomdl18.dat.temp
    2008-12-24 14:12 . 2008-12-24 14:12 <DIR> d-------- c:\program files\Common Files\Bcgsoft
    2008-12-24 13:44 . 2008-12-24 13:44 <DIR> d-------- c:\users\All Users\Apple Computer
    2008-12-24 13:44 . 2008-12-24 13:44 <DIR> d-------- c:\programdata\Apple Computer
    2008-12-24 13:36 . 2008-12-26 21:23 <DIR> d-------- c:\users\Fred\AppData\Roaming\LumaPix
    2008-12-24 13:35 . 2008-12-24 13:35 266,704 --a------ c:\windows\FotoFusionV4 Uninstaller.exe
    2008-12-24 12:56 . 2007-11-21 09:50 1,435,272 --a------ c:\windows\System32\Flash8.ocx
    2008-12-24 11:53 . 2008-12-24 11:53 <DIR> d-------- c:\users\Fred\AppData\Roaming\dvdcss
    2008-12-24 11:45 . 2008-12-24 11:45 <DIR> d-------- c:\program files\QuickTime
    2008-12-24 08:19 . 2001-09-28 18:00 243,200 --a------ c:\program files\UNWISE.EXE
    2008-12-23 15:16 . 2008-12-23 15:16 <DIR> d-------- c:\users\Fred\AppData\Roaming\Malwarebytes
    2008-12-23 15:16 . 2008-12-23 15:16 <DIR> d-------- c:\users\All Users\Malwarebytes
    2008-12-23 15:16 . 2008-12-23 15:16 <DIR> d-------- c:\programdata\Malwarebytes
    2008-12-23 13:56 . 2008-12-23 13:56 <DIR> d-------- c:\users\Fred\AppData\Roaming\Photodex
    2008-12-23 13:35 . 2008-12-23 13:35 <DIR> d-------- c:\windows\Sun
    2008-12-23 12:03 . 2008-12-30 20:39 <DIR> d-------- C:\Junk
    2008-12-23 09:08 . 2008-04-26 03:26 891,448 --a------ c:\windows\System32\drivers\tcpip.sys
    2008-12-23 01:21 . 2008-12-23 01:21 50,435,552 --a------ c:\windows\System32\xa52376368.exe
    2008-12-23 01:21 . 2008-12-23 01:21 50,435,552 --a------ c:\windows\System32\xa52375198.exe
    2008-12-22 23:45 . 2007-07-12 11:56 2,201,224 --a------ c:\windows\System32\Flash9.ocx
    2008-12-22 23:14 . 2008-06-27 10:47 2,987,392 --a------ c:\windows\System32\Flash9e.ocx
    2008-12-22 23:14 . 2008-06-27 10:47 218,496 --a------ c:\windows\System32\FlashUtil9e.exe
    2008-12-22 20:28 . 2008-12-22 20:28 <DIR> d-------- c:\windows\System32\IOSUBSYS
    2008-12-22 20:00 . 2008-12-22 20:00 <DIR> d-------- c:\users\All Users\TechSmith
    2008-12-22 20:00 . 2008-12-22 20:00 <DIR> d-------- c:\programdata\TechSmith
    2008-12-22 20:00 . 2008-12-22 20:00 <DIR> d-------- c:\program files\TechSmith
    2008-12-22 19:51 . 2008-12-22 19:51 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
    2008-12-22 19:49 . 2008-12-22 19:49 <DIR> d-------- C:\MAGICDVDCOPY_TEMP
    2008-12-22 19:42 . 2008-12-22 21:52 <DIR> d-------- c:\users\Fred\AppData\Roaming\Ashampoo
    2008-12-22 19:42 . 2008-12-22 19:42 <DIR> d-------- c:\users\All Users\ashampoo
    2008-12-22 19:42 . 2008-12-22 19:42 <DIR> d-------- c:\programdata\ashampoo
    2008-12-22 19:26 . 2002-12-10 02:20 102,439 --a------ c:\windows\System32\sipr3260.dll
    2008-12-22 19:23 . 2008-12-30 23:55 <DIR> d-------- c:\users\Fred\AppData\Roaming\Vso
    2008-12-22 19:23 . 2008-12-22 19:23 <DIR> d-------- c:\program files\VSO
    2008-12-22 19:23 . 2004-05-04 12:53 1,645,320 --a------ c:\windows\gdiplus.dll
    2008-12-22 19:23 . 2006-05-20 17:16 1,184,984 --a------ c:\windows\System32\wvc1dmod.dll
    2008-12-22 19:23 . 2006-05-11 20:21 626,688 --a------ c:\windows\System32\vp7vfw.dll
    2008-12-22 19:23 . 2006-09-29 13:24 217,127 --a------ c:\windows\System32\drv43260.dll
    2008-12-22 19:23 . 2006-09-29 13:25 208,935 --a------ c:\windows\System32\drv33260.dll
    2008-12-22 19:23 . 2006-09-29 13:26 176,165 --a------ c:\windows\System32\drv23260.dll
    2008-12-22 19:23 . 2007-03-18 21:37 65,602 --a------ c:\windows\System32\cook3260.dll
    2008-12-22 19:23 . 2008-12-22 19:23 47,360 --a------ c:\windows\System32\drivers\pcouffin.sys
    2008-12-22 19:23 . 2008-12-22 19:23 47,360 --a------ c:\users\Fred\AppData\Roaming\pcouffin.sys
    2008-12-22 19:18 . 2008-12-24 12:16 <DIR> d-------- c:\users\Fred\AppData\Roaming\AVSMedia
    2008-12-22 19:18 . 2008-12-22 19:18 <DIR> d-------- c:\users\All Users\AVS4YOU
    2008-12-22 19:18 . 2008-12-22 19:18 <DIR> d-------- c:\programdata\AVS4YOU
    2008-12-22 19:14 . 2008-12-22 19:15 <DIR> d-------- c:\program files\Common Files\AVSMedia
    2008-12-22 18:54 . 2008-12-29 21:26 <DIR> d-------- c:\users\Fred\AppData\Roaming\uTorrent
    2008-12-22 17:48 . 2008-12-22 17:58 <DIR> d-------- c:\users\Fred\AppData\Roaming\Nero
    2008-12-22 17:48 . 2008-12-22 17:48 <DIR> d-------- c:\users\All Users\LightScribe
    2008-12-22 17:48 . 2008-12-22 17:48 <DIR> d-------- c:\programdata\LightScribe
    2008-12-22 17:28 . 2008-12-22 17:28 4,767 --a------ c:\windows\Irremote.ini
    2008-12-22 17:08 . 2008-12-22 17:27 <DIR> d-------- c:\program files\Nero
    2008-12-22 17:07 . 2008-12-22 17:18 <DIR> d-------- c:\users\All Users\Nero
    2008-12-22 17:07 . 2008-12-22 17:18 <DIR> d-------- c:\programdata\Nero
    2008-12-22 17:07 . 2008-12-22 17:48 <DIR> d-------- c:\program files\Common Files\Nero
    2008-12-22 16:34 . 2008-12-22 16:39 <DIR> d-------- c:\users\Fred\AppData\Roaming\LimeWire
    2008-12-22 16:30 . 2008-12-22 16:30 <DIR> d-------- c:\windows\WinRAR
    2008-12-22 16:26 . 2008-12-22 16:28 <DIR> d-------- c:\users\All Users\WinZip
    2008-12-22 16:26 . 2008-12-22 16:28 <DIR> d-------- c:\programdata\WinZip
    2008-12-22 15:34 . 2008-12-22 15:34 <DIR> d-------- c:\users\All Users\Seagate
    2008-12-22 15:34 . 2008-12-22 15:34 <DIR> d-------- c:\programdata\Seagate
    2008-12-22 15:34 . 2008-12-22 15:34 <DIR> d-------- c:\program files\Seagate
    2008-12-22 15:33 . 2008-12-22 15:33 <DIR> d--hs---- c:\windows\ftpcache
    2008-12-22 10:00 . 2008-12-22 10:01 <DIR> d-------- c:\users\All Users\NVIDIA
    2008-12-22 10:00 . 2008-12-22 10:01 <DIR> d-------- c:\programdata\NVIDIA
    2008-12-22 09:37 . 2007-10-15 18:02 8,535 --a------ c:\windows\System32\nvide.nvu
    2008-12-22 09:36 . 2008-12-22 09:36 <DIR> d-------- c:\users\Fred\AppData\Roaming\InstallShield
    2008-12-22 09:30 . 2008-01-08 13:10 98,304 --a------ c:\windows\RTKAUDIOSERVICE.EXE
    2008-12-22 09:30 . 2007-11-14 15:18 553 --a------ c:\windows\USetup.iss
    2008-12-22 09:29 . 2008-01-15 11:26 4,874,240 --a------ c:\windows\RtHDVCpl.exe
    2008-12-22 09:29 . 2008-01-15 19:19 2,047,576 --a------ c:\windows\System32\drivers\RTKVHDA.sys
    2008-12-22 09:29 . 2007-11-07 17:31 1,191,936 --a------ c:\windows\RtlUpd.exe
    2008-12-22 09:29 . 2008-01-09 18:52 636,416 --a------ c:\windows\System32\RtkPgExt.dll
    2008-12-22 09:29 . 2007-11-13 12:35 532,480 --a------ c:\windows\System32\RTSndMgr.cpl
    2008-12-22 09:29 . 2007-07-25 09:33 135,168 --a------ c:\windows\System32\SRSWOW.dll
    2008-12-22 09:29 . 2008-01-14 16:18 29,696 --a------ c:\windows\System32\RtkCoInst.dll
    2008-12-22 09:24 . 2008-12-22 09:24 <DIR> d-------- c:\users\Fred\AppData\Roaming\WinBatch
    2008-12-22 09:06 . 2008-12-22 09:06 <DIR> d-------- C:\PerfLogs
    2008-12-22 08:39 . 2008-01-19 01:06 8,147,456 --a------ c:\windows\System32\wmploc.DLL
    2008-12-22 08:38 . 2008-01-19 02:36 704,512 --a------ c:\windows\System32\SmiEngine.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-12-29 03:14 --------- d-----w c:\programdata\HP
    2008-12-28 04:57 --------- d--h--w c:\program files\InstallShield Installation Information
    2008-12-25 01:50 --------- d-----w c:\program files\Rhapsody
    2008-12-25 01:46 --------- d-----w c:\programdata\Roxio
    2008-12-25 01:37 --------- d-----w c:\programdata\Sonic
    2008-12-24 18:20 --------- d-----w c:\program files\Common Files\InstallShield
    2008-12-23 01:28 --------- d-----w c:\program files\Common Files\PX Storage Engine
    2008-12-22 22:06 --------- d---a-w c:\program files\Common Files\LightScribe
    2008-12-22 17:26 --------- d-----w c:\program files\Common Files\Adobe
    2008-12-22 14:29 319,456 ----a-w c:\windows\DIFxAPI.dll
    2008-12-22 14:29 --------- d-----w c:\program files\Realtek
    2008-12-22 14:16 174 --sha-w c:\program files\desktop.ini
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Sidebar
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Photo Gallery
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Mail
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Journal
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Defender
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Collaboration
    2008-12-22 14:07 --------- d-----w c:\program files\Windows Calendar
    2008-12-22 13:50 82,432 ----a-w c:\windows\System32\axaltocm.dll
    2008-12-22 13:50 101,888 ----a-w c:\windows\System32\ifxcardm.dll
    2008-12-21 18:49 --------- d-----w c:\program files\HP
    2008-12-21 18:48 --------- d-----w c:\program files\Common Files\HP
    2008-12-21 18:44 --------- d-----w c:\programdata\Hewlett-Packard
    2008-12-21 16:54 --------- d-----w c:\program files\Microsoft Works
    2008-12-21 15:17 --------- d-----w c:\programdata\Symantec
    2008-12-21 15:17 --------- d-----w c:\program files\Common Files\Symantec Shared
    2008-12-21 14:36 541,696 ----a-w c:\windows\AppPatch\AcLayers.dll
    2008-12-21 14:36 52,736 ----a-w c:\windows\AppPatch\iebrshim.dll
    2008-12-21 14:36 460,288 ----a-w c:\windows\AppPatch\AcSpecfc.dll
    2008-12-21 14:36 2,560 ----a-w c:\windows\AppPatch\AcRes.dll
    2008-12-21 14:36 2,154,496 ----a-w c:\windows\AppPatch\AcGenral.dll
    2008-12-21 14:36 173,056 ----a-w c:\windows\AppPatch\AcXtrnal.dll
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Templates
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Start Menu
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Favorites
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Documents
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Desktop
    2008-12-21 14:02 --------- d-sh--w c:\programdata\Application Data
    2008-09-30 21:43 1,286,152 ----a-w c:\windows\System32\msxml4.dll
    2008-09-18 04:56 147,456 ----a-w c:\windows\System32\Faultrep.dll
    2008-09-18 04:56 125,952 ----a-w c:\windows\System32\wersvc.dll
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Sidebar "= "c:\program files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
    "ehTray.exe "= "c:\windows\ehome\ehTray.exe" [2008-01-19 125952]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "hpsysdrv "= "c:\hp\support\hpsysdrv.exe" [2007-04-18 65536]
    "KBD "= "c:\hp\KBD\KbdStub.EXE" [2006-12-08 65536]
    "OsdMaestro "= "c:\program files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe" [2007-02-15 118784]
    "HP Health Check Scheduler "= "c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-05-24 71176]
    "SunJavaUpdateReg "= "c:\windows\system32\jureg.exe" [2007-04-07 54936]
    "HP Software Update "= "c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
    "{0228e555-4f9c-4e35-a3ec-b109a192b4c2} "= "c:\program files\Google\Gmail Notifier\gnotify.exe" [2005-07-15 479232]
    "cctray "= "c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-12-28 247024]
    "CAVRID "= "c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-08-30 234736]
    "QOELOADER "= "c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-6.0.1.33\QOELoader.exe" [2008-12-21 14088]
    "NvCplDaemon "= "c:\windows\system32\NvCpl.dll" [2008-05-22 13539872]
    "NvMediaCenter "= "c:\windows\system32\NvMcTray.dll" [2008-05-22 92704]
    "Adobe Reader Speed Launcher "= "c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-10-15 39792]
    "MaxMenuMgr "= "c:\program files\Seagate\SeagateManager\FreeAgent Status\StxMenuMgr.exe" [2008-10-28 181544]
    "hpqSRMon "= "c:\program files\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-08-20 150016]
    "Mindful 2 "= "c:\program files\Felitec\Mindful 2\Mindful.exe" [2008-12-08 718336]
    "cafw "= "c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-08-28 771312]
    "capfasem "= "c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-08-28 173296]
    "WinPatrol "= "i:\program files\WinPatrol\winpatrol.exe" [2008-04-25 333120]
    "RtHDVCpl "= "RtHDVCpl.exe" [2008-01-15 c:\windows\RtHDVCpl.exe]

    c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-01-02 210520]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
    "EnableUIADesktopToggle "= 0 (0x0)

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
    "EnableShellExecuteHooks "= 1 (0x1)

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
    "{1869181A-9F50-4FCF-8BFF-1B8588ECB85C} "= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-07-23 1377720]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
    2007-05-18 14:30 79368 c:\windows\System32\UmxWNP.dll

    [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Snapfish Media Detector.lnk]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
    "LightScribe Control Panel "=c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiSpyware]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
    "DisableMonitoring "=dword:00000001

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
    "DisableMonitoring "=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
    "{B8914DBA-114E-435A-B908-1A0976F147B8} "= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{83A547B4-BF52-4D6F-88B1-B6CF3F1D2B11} "= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{2C5E35E1-5405-4EE0-8DE2-3BBAD8B22625} "= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{8D7B9122-3108-4765-B178-49B7F77F881C} "= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{4C41D456-0402-4A32-A111-5C090A755CF1} "= UDP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{80356B9A-6162-44BF-8B34-145357382F45} "= TCP:c:\program files\earthlink totalaccess\TaskPanl.exe:taskpanl
    "{11E5E373-B3D1-496A-B9E0-27B5CC101BCA} "= UDP:i:\program files\Utorrent\uTorrent.exe:µTorrent (TCP-In)
    "{0C7392F8-8167-4E9A-89EB-29FBD2BC8D1C} "= TCP:i:\program files\Utorrent\uTorrent.exe:µTorrent (UDP-In)
    "{C25016E8-1C04-48E6-A1E2-561D4D271D6B} "= c:\program files\HP\Digital Imaging\bin\hpqpse.exe:hpqpse.exe
    "{20D28C8F-535E-401C-A51D-58EAA68AB404} "= c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe:hpqphotocrm.exe
    "{3E3DE168-137A-426A-A5E9-339527BC3990} "= c:\program files\HP\Digital Imaging\bin\hpqsudi.exe:hpqsudi.exe
    "{B96BF345-9921-4DDF-9550-11EA83A89B17} "= c:\program files\HP\Digital Imaging\bin\hpqpsapp.exe:hpqpsapp.exe

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
    "EnableFirewall "= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
    "c:\\Program Files\\EarthLink TotalAccess\\TaskPanl.exe "= c:\program files\EarthLink TotalAccess\TaskPanl.exe:*:Enabled:Earthlink

    R0 KmxFw;KmxFw;c:\windows\system32\DRIVERS\kmxfw.sys [2008-03-19 103952]
    R1 KmxAgent;KmxAgent;c:\windows\system32\DRIVERS\kmxagent.sys [2008-03-21 63504]
    R1 KmxFile;KmxFile;c:\windows\system32\DRIVERS\KmxFile.sys [2008-03-21 45584]
    R1 KmxFilter;HIPS Core Filter Driver;c:\windows\system32\DRIVERS\KmxFilter.sys [2008-05-30 51704]
    R2 FreeAgentGoNext Service;Seagate Service; "c:\program files\Seagate\SeagateManager\Sync\FreeAgentService.exe" [2008-10-28 156968]
    R2 KmxCF;KmxCF;c:\windows\system32\DRIVERS\KmxCF.sys [2008-06-04 138744]
    R2 KmxSbx;KmxSbx;c:\windows\system32\DRIVERS\KmxSbx.sys [2008-03-21 66576]
    R2 Nero BackItUp Scheduler 4.0;Nero BackItUp Scheduler 4.0;c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe [2008-12-05 935208]
    R2 UmxAgent;HIPS Event Manager; "c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe" [2007-10-18 1010192]
    R2 UmxCfg;HIPS Configuration Interpreter; "c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe" [2007-10-18 801296]
    R2 UmxPol;HIPS Policy Manager; "c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe" [2008-04-15 281104]
    R3 KmxCfg;KmxCfg;c:\windows\system32\DRIVERS\kmxcfg.sys [2008-05-30 88816]
    R3 PPCtlPriv;PPCtlPriv; "c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe" [2008-12-21 185584]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
    HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
    hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
    \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL g:\resycled\boot.com g:
    \shell\Open\command - "resycled\b

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\I]
    \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL i:\resycled\boot.com i:
    \shell\Open\command - i:\resycled\boot.com i:

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dc19f21-d040-11dd-82c4-001bb9a9776f}]
    \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL i:\resycled\boot.com i:
    \shell\Open\command - i:\resycled\boot.com i:

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5adc666f-cf6e-11dd-a7cd-001bb9a9776f}]
    \shell\AutoRun\command - c:\windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL g:\resycled\boot.com g:
    \shell\Open\command - "resycled\b

    *Newly Created Service* - CATCHME
    *Newly Created Service* - PROCEXP90

    [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]
    "c:\program files\Common Files\LightScribe\LSRunOnce.exe "
    .
    Contents of the 'Scheduled Tasks' folder

    2008-12-23 c:\windows\Tasks\CAAntiSpywareScan_Daily as Fred at 6 50 PM.job
    - c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2008-08-27 18:44]

    2008-12-31 c:\windows\Tasks\RegCure Program Check.job
    - i:\program files\RegCure\RegCure.exe [2007-08-02 09:20]

    2008-12-24 c:\windows\Tasks\RegCure.job
    - i:\program files\RegCure\RegCure.exe [2007-08-02 09:20]

    2008-12-30 c:\windows\Tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
    - i:\program files\Spybot - Search & Destroy\SDUpdate.exe []
    .
    - - - - ORPHANS REMOVED - - - -

    WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
    MSConfigStartUp-Malwarebytes' Anti-Malware - i:\program files\Malwarebytes' Anti-Malware\mbamgui.exe


    .
    ------- Supplementary Scan -------
    .
    uStart Page =
    mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=74&bd=Pavilion&pf=desktop
    IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
    IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
    LSP: c:\windows\system32\VetRedir.dll
    FF - ProfilePath -
    .

    **************************************************************************

    catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2008-12-31 00:17:34
    Windows 6.0.6001 Service Pack 1 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
    AppInit_DLLs = ????????????

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    --------------------- DLLs Loaded Under Running Processes ---------------------

    - - - - - - - > 'winlogon.exe'(1184)
    c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
    c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
    c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
    .
    Completion time: 2008-12-31 0:19:34
    ComboFix-quarantined-files.txt 2008-12-31 05:19:32

    Pre-Run: 265,322,274,816 bytes free
    Post-Run: 266,439,286,784 bytes free

    351 --- E O F --- 2008-12-27 21:20:11
     
  9. 2008/12/30
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Highlight and copy the contents of the code box below.
    Code:
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\G /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\I /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{0dc19f21-d040-11dd-82c4-001bb9a9776f} /f
    reg delete HKCU\software\microsoft\windows\currentversion\explorer\mountpoints2\{5adc666f-cf6e-11dd-a7cd-001bb9a9776f} /f
    exit
    cls
    
    Click Start>Run and type cmd then hit enter to open a command window. Right click in the command window and select paste. The command window will close on it's own.


    Please upload the following files to my submission channel for analysis. Leave a link back to this topic.

    c:\windows\System32\xa52376368.exe
    c:\windows\System32\xa52375198.exe

    Thanks!


    Next, do an online scan with Kaspersky Online Scanner

    Click Accept, when prompted to download and install the program files and database of malware definitions.
    • Click Run at the Security prompt.
    • The program will then begin downloading and installing and will also update the database.
    • Please be patient as this can take several minutes.
    • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Click View scan report at the bottom.
    • Click the Save Report As... button.
    • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply.
    **Note**

    To optimize scanning time and produce a more sensible report for review:
    • Close any open programs.
    • Turn off the real-time scanner of all antivirus or antispyware programs while performing the online scan.

    Post the Kaspersky log here.
     
  10. 2008/12/31
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Still scanning a flash drive. Screen has been blank for about 10 minutes. I'm waiting for it to finish.
     
  11. 2008/12/31
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    If it hasn't finished within another 5 minutes, close the window. If there is nothing on that flash drive you need to keep, open My Computer and right click the flash drive's icon then select format. When it is complete, run Flash_Disinfector again.
     
  12. 2008/12/31
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    When you say close the window not sure what you mean. The only thing i see is a blank desktop. Nothing say the program is even running.
     
  13. 2008/12/31
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Ah, I see.
    Press Ctrl+Alt+Del to open the task manager.
    Click File>New Task (Run) and type explorer.exe then hit Enter.

    Now click the Processes tab and see if you find flash_disinfector.exe. If so, End Task on it.
     
  14. 2008/12/31
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Was not their. had to reboot to get everything back.
    Going to have to give up for the night. Work come early.
    Will try and hook up with you tomorrow night and give it another go. Thanks for the help
     
  15. 2008/12/31
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Blocked Sites

    I ran Kaspersky and all that it found I deleted. It was some old files that had a keygen in it that shows up as a virus. All were on my external drive. Forgot I even had them. These file had not been opened in many months so not sure if this is where my problem might have come from.
    So far it looks like my Host file was the only thing I found corrupt.

    KASPERSKY ONLINE SCANNER 7 REPORT
    Wednesday, December 31, 2008
    Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
    Kaspersky Online Scanner 7 version: 7.0.25.0
    Program database last update: Wednesday, December 31, 2008 11:31:29
    Records in database: 1537826
    --------------------------------------------------------------------------------

    Scan settings:
    Scan using the following database: extended
    Scan archives: yes
    Scan mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\
    F:\
    G:\
    H:\
    I:\

    Scan statistics:
    Files scanned: 177568
    Threat name: 12
    Infected objects: 17
    Suspicious objects: 0
    Duration of the scan: 03:13:11


    File name / Threat name / Threats count
    H:\Downloaded programs\Advanced Archive Password Recovery Pro 4.0 + Crack\Advanced Archive Password Recovery Pro 4.0 + Crack\setup.exe Infected: not-a-virus:pSWTool.Win32.AdvancedPR.c 1
    H:\Downloaded programs\Advanced Archive Password Recovery Pro 4.0 + Crack\Advanced Archive Password Recovery Pro 4.0 + Crack\setup.exe Infected: Trojan.Win32.Agent.xjc 1
    H:\Downloaded programs\Advanced Archive Password Recovery Pro 4.0 + Crack\Advanced Archive Password Recovery Pro 4.0 + Crack.rar Infected: not-a-virus:pSWTool.Win32.AdvancedPR.c 1
    H:\Downloaded programs\Advanced Archive Password Recovery Pro 4.0 + Crack\Advanced Archive Password Recovery Pro 4.0 + Crack.rar Infected: Trojan.Win32.Agent.xjc 1
    H:\Downloaded programs\Backup4all Professional 3.11.300\backup4all.zip Infected: not-a-virus:AdWare.Win32.Agent.zk 1
    H:\Downloaded programs\LimeWire4.20.9\LimeWireWin.exe Infected: not-a-virus:pSWTool.Win32.IEPassView.ae 1
    H:\Downloaded programs\Magic DVD Copier 4.8.0.5 Incl. Keygen\MagicDVDCopier48.exe Infected: Trojan-Downloader.MSIL.Agent.ah 1
    H:\Downloaded programs\my fantasy maker\My Fantasy Maker v5.0 + Crack\MFM50a.exe Infected: Trojan.Win32.Monder.gen 1
    H:\Downloaded programs\Password\Advanced Archive Password Recovery Pro 4.0 + Crack\setup.exe Infected: not-a-virus:pSWTool.Win32.AdvancedPR.c 1
    H:\Downloaded programs\Password\Advanced Archive Password Recovery Pro 4.0 + Crack\setup.exe Infected: Trojan.Win32.Small.xta 1
    H:\Downloaded programs\Photo Collage Platinum 2.04 with patch\PCP204\PhotoCollagePlatinum2.04.exe Infected: Trojan-Downloader.Win32.Agent.peo 1
    H:\Downloaded programs\SPLIT & EXTRACT TEXT FROM PDF FILES\a-pdf-text extractor.exe Infected: not-a-virus:Monitor.Win32.Ardamax.k 1
    H:\Downloaded programs\VSO ConvertXtoDVD v3.1.1.3\VSO ConvertXtoDVD v3.1.1.3.rar Infected: Trojan-Downloader.MSIL.Agent.bb 1
    H:\Downloaded programs\VSO ConvertXtoDVD v3.1.1.3\vsoConvertXtoDVD3_setup.exe Infected: Trojan-Downloader.MSIL.Agent.bb 1
    H:\Downloaded programs\WinAVI Video Converter 8.0 with working key\HelixSDK RM converter kit for WinAVI.exe Infected: Trojan-Downloader.Win32.Agent.pwa 1
    H:\Downloaded programs\WinAVI Video Converter 8.0 with working key\WinAVI_Video_Converter 8.0.exe Infected: Trojan-Downloader.Win32.Agent.pwa 1
    H:\Downloaded programs\Wondershare DVD Slide Show\Wondershare DVD Slideshow Builder v4.3.0 Incl Crack\DSB_trial.exe Infected: Trojan-Downloader.Win32.Agent.uks 1

    The selected area was scanned.
     
  16. 2009/01/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Looks like you're good to go. Click Start>Run and type ComboFix /u then hit Enter to uninstall ComboFix and remove the files it has quarantined. This action will also reset the System Restore points, removing any infected files there as well.
    Verify the C:\Qoobox and C:\ComboFix folders were removed, as well as the C:\ComboFix.txt file.
    You can delete any other logs that were created/saved too.

    Geri has posted some very helpful information and recommendations regarding future protection in the following link.

    http://www.windowsbbs.com/showthread.php?t=67958

    Surf safe! :)
     
  17. 2009/01/01
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Tried to run Click Start>Run and type ComboFix /u but windows says it can't find it. Should I run combofix again and then uninstall it?
     
  18. 2009/01/01
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Click Start>Run and type ComboFix /u
    Windows says it can't find it.
     
  19. 2009/01/01
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    ComboFix was previously run from c:\users\Fred\Downloads\ComboFix.exe
    Is it still there?
    If so, enter c:\users\Fred\Downloads\ComboFix.exe /u in the Run dialog.
     
  20. 2009/01/01
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Download folder is empty. Should I download again and run combofix /u
     
  21. 2009/01/01
    Fredb38

    Fredb38 Well-Known Member Thread Starter

    Joined:
    2003/05/30
    Messages:
    182
    Likes Received:
    0
    Download folder is empty
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.