Here are the logs, not-attached. Thanks again!
Combo Fix:
ComboFix 09-10-17.01 - Alexander Stone 10/18/2009 19:01.1.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.97 [GMT -4:00]
Running from: c:\documents and settings\Alexander Stone\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Shared
c:\program files\Shared\lib.sig
c:\windows\a3kebook.ini
c:\windows\akebook.ini
c:\windows\ANS2000.INI
c:\windows\system32\bszip.dll
c:\windows\system32\nuar.old
c:\windows\system32\skynet.dat
c:\windows\wf3.dat
c:\windows\wf4.dat
.
((((((((((((((((((((((((( Files Created from 2009-09-18 to 2009-10-18 )))))))))))))))))))))))))))))))
.
2009-10-17 22:46 . 2009-10-17 22:46 124976 ----a-w- c:\windows\system32\drivers\SYMEVENT.SYS
2009-10-17 22:46 . 2009-10-17 23:09 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-10-17 22:46 . 2009-10-17 22:46 -------- d-----w- c:\program files\Symantec
2009-10-17 22:43 . 2009-10-17 22:43 -------- d-----w- c:\windows\system32\drivers\NAV
2009-10-17 22:43 . 2009-10-17 22:43 -------- d-----w- c:\program files\Windows Sidebar
2009-10-17 22:43 . 2009-10-17 22:43 -------- d-----w- c:\program files\Norton AntiVirus
2009-10-17 22:41 . 2009-10-17 22:41 -------- d-----w- c:\program files\NortonInstaller
2009-10-17 22:41 . 2009-10-17 22:41 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-10-17 02:07 . 2009-10-17 02:07 -------- d-----w- c:\program files\iPod
2009-10-17 02:07 . 2009-10-17 02:09 -------- d-----w- c:\documents and settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-17 02:07 . 2009-10-17 02:09 -------- d-----w- c:\program files\iTunes
2009-10-17 02:04 . 2009-10-17 02:04 -------- d-----w- c:\program files\Bonjour
2009-10-17 01:58 . 2009-10-17 02:02 -------- d-----w- c:\program files\QuickTime
2009-10-16 23:06 . 2009-10-17 01:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Lavasoft
2009-10-16 02:28 . 2009-10-01 14:29 195440 ------w- c:\windows\system32\MpSigStub.exe
2009-10-16 02:24 . 2009-10-16 02:24 -------- d-----w- c:\program files\Windows Defender
2009-10-16 01:54 . 2009-10-17 22:48 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-10-16 01:36 . 2009-10-16 01:36 -------- d-----w- c:\program files\Trend Micro
2009-10-16 01:34 . 2009-10-16 01:34 -------- d-----w- c:\program files\ERUNT
2009-10-15 02:43 . 2009-10-18 13:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-10-15 02:43 . 2009-10-15 21:40 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-15 02:13 . 2009-10-15 02:13 -------- d-----w- c:\program files\VS Revo Group
2009-10-15 00:15 . 2009-10-15 00:15 -------- d-----w- c:\windows\system32\XPSViewer
2009-10-15 00:15 . 2009-10-15 00:15 -------- d-----w- c:\program files\MSBuild
2009-10-15 00:15 . 2009-10-15 00:15 -------- d-----w- c:\program files\Reference Assemblies
2009-10-15 00:13 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-15 00:13 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-10-15 00:13 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-10-15 00:13 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-15 00:13 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-10-15 00:13 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-15 00:13 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-15 00:13 . 2009-10-15 00:14 -------- d-----w- C:\34df902294fd73946e2a4370ed
2009-10-14 23:51 . 2009-07-10 13:27 1315328 ------w- c:\windows\system32\dllcache\msoe.dll
2009-10-14 23:46 . 2009-03-06 14:22 284160 ------w- c:\windows\system32\dllcache\pdh.dll
2009-10-14 23:46 . 2009-02-09 12:10 473600 ------w- c:\windows\system32\dllcache\fastprox.dll
2009-10-14 23:46 . 2009-02-09 12:10 401408 ------w- c:\windows\system32\dllcache\rpcss.dll
2009-10-14 23:46 . 2009-02-06 11:11 110592 ------w- c:\windows\system32\dllcache\services.exe
2009-10-14 23:46 . 2009-02-06 10:10 227840 ------w- c:\windows\system32\dllcache\wmiprvse.exe
2009-10-14 23:46 . 2009-06-25 08:25 730112 ------w- c:\windows\system32\dllcache\lsasrv.dll
2009-10-14 23:46 . 2009-02-09 12:10 617472 ------w- c:\windows\system32\dllcache\advapi32.dll
2009-10-14 23:46 . 2009-02-09 12:10 453120 ------w- c:\windows\system32\dllcache\wmiprvsd.dll
2009-10-14 23:46 . 2009-02-09 12:10 714752 ------w- c:\windows\system32\dllcache\ntdll.dll
2009-10-14 23:46 . 2009-08-04 15:13 2145280 ------w- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-10-14 23:46 . 2009-08-05 00:44 2189184 ------w- c:\windows\system32\dllcache\ntoskrnl.exe
2009-10-14 23:46 . 2009-08-04 14:20 2023936 ------w- c:\windows\system32\dllcache\ntkrpamp.exe
2009-10-14 23:45 . 2008-12-11 10:57 333952 ------w- c:\windows\system32\dllcache\srv.sys
2009-10-14 23:45 . 2008-10-24 11:21 455296 ------w- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-14 23:44 . 2008-10-15 16:34 337408 ------w- c:\windows\system32\dllcache\netapi32.dll
2009-10-14 23:44 . 2008-04-11 19:04 691712 ------w- c:\windows\system32\dllcache\inetcomm.dll
2009-10-14 23:43 . 2008-06-13 11:05 272128 ------w- c:\windows\system32\dllcache\bthport.sys
2009-10-14 23:43 . 2008-05-08 14:02 203136 ------w- c:\windows\system32\dllcache\rmcast.sys
2009-10-14 23:34 . 2009-10-14 23:34 -------- d-sh--w- c:\windows\system32\config\systemprofile\IETldCache
2009-10-14 21:02 . 2009-10-14 21:02 -------- d-sh--w- c:\documents and settings\NetworkService\IETldCache
2009-10-14 14:27 . 2009-10-14 14:27 -------- d-----w- c:\windows\system32\scripting
2009-10-14 14:27 . 2009-10-14 14:27 -------- d-----w- c:\windows\l2schemas
2009-10-14 14:27 . 2009-10-14 14:27 -------- d-----w- c:\windows\system32\en
2009-10-14 14:27 . 2009-10-14 14:27 -------- d-----w- c:\windows\system32\bits
2009-10-14 14:17 . 2009-10-14 14:41 -------- d-----w- c:\windows\Security
2009-10-14 14:11 . 2009-10-14 14:11 -------- d-----w- c:\windows\EHome
2009-10-14 09:36 . 2008-04-14 00:12 69120 ------w- c:\windows\system32\wlanapi.dll
2009-10-14 09:36 . 2008-04-13 18:43 14208 ------w- c:\windows\system32\drivers\wacompen.sys
2009-10-14 09:36 . 2004-08-04 02:29 25471 ------w- c:\windows\system32\drivers\watv10nt.sys
2009-10-14 09:36 . 2004-08-04 02:29 22271 ------w- c:\windows\system32\drivers\watv06nt.sys
2009-10-14 09:36 . 2004-08-04 02:29 11935 ------w- c:\windows\system32\drivers\wadv11nt.sys
2009-10-14 09:36 . 2004-08-04 02:29 11871 ------w- c:\windows\system32\drivers\wadv09nt.sys
2009-10-14 09:36 . 2004-08-04 02:29 11807 ------w- c:\windows\system32\drivers\wadv07nt.sys
2009-10-14 09:36 . 2004-08-04 02:29 11295 ------w- c:\windows\system32\drivers\wadv08nt.sys
2009-10-14 09:36 . 2008-04-14 00:12 11325 ------w- c:\windows\system32\drivers\vchnt5.dll
2009-10-14 09:36 . 2008-04-13 18:46 121984 ------w- c:\windows\system32\drivers\usbvideo.sys
2009-10-14 09:34 . 2008-04-14 00:12 176640 ------w- c:\windows\system32\napstat.exe
2009-10-14 09:33 . 2008-04-14 00:11 81920 ------w- c:\windows\system32\ieencode.dll
2009-10-14 09:32 . 2008-04-14 00:11 4255 ------w- c:\windows\system32\drivers\adv01nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3967 ------w- c:\windows\system32\drivers\adv02nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3775 ------w- c:\windows\system32\drivers\adv11nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3711 ------w- c:\windows\system32\drivers\adv09nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3647 ------w- c:\windows\system32\drivers\adv07nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3615 ------w- c:\windows\system32\drivers\adv05nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 3135 ------w- c:\windows\system32\drivers\adv08nt5.dll
2009-10-14 09:32 . 2008-04-14 00:11 136192 ------w- c:\windows\system32\aaclient.dll
2009-10-14 03:03 . 2009-10-14 03:03 -------- d-sh--w- c:\documents and settings\Alexander Stone\PrivacIE
2009-10-14 03:02 . 2009-10-14 03:02 -------- d-sh--w- c:\documents and settings\LocalService\IETldCache
2009-10-14 03:01 . 2009-10-14 03:01 -------- d-sh--w- c:\documents and settings\Alexander Stone\IETldCache
2009-10-14 02:53 . 2009-08-29 08:08 12800 ------w- c:\windows\system32\dllcache\xpshims.dll
2009-10-14 02:53 . 2009-08-29 08:08 594432 ------w- c:\windows\system32\dllcache\msfeeds.dll
2009-10-14 02:53 . 2009-08-29 08:08 55296 ------w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-14 02:53 . 2009-08-29 08:08 1985536 ------w- c:\windows\system32\dllcache\iertutil.dll
2009-10-14 02:53 . 2009-08-29 08:08 246272 ------w- c:\windows\system32\dllcache\ieproxy.dll
2009-10-14 02:53 . 2009-08-29 08:08 11069440 ------w- c:\windows\system32\dllcache\ieframe.dll
2009-10-14 02:53 . 2009-10-15 00:37 -------- d-----w- c:\windows\ie8updates
2009-10-14 02:51 . 2009-08-07 08:48 100352 ------w- c:\windows\system32\dllcache\iecompat.dll
2009-10-14 02:49 . 2009-10-14 02:51 -------- dc-h--w- c:\windows\ie8
2009-10-14 01:48 . 2009-10-14 01:48 46060 ---ha-w- c:\windows\system32\mlfcache.dat
2009-10-13 12:34 . 2009-10-14 01:19 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-10-13 12:34 . 2009-10-13 12:34 -------- d-----w- c:\documents and settings\Alexander Stone\Application Data\IObit
2009-10-13 12:31 . 2009-10-13 12:31 -------- d-----w- c:\program files\Microsoft
2009-10-13 12:31 . 2009-10-13 12:31 -------- d-----w- c:\program files\Windows Live SkyDrive
2009-10-13 02:31 . 2009-10-13 02:31 -------- d-----w- c:\program files\IObit
2009-10-13 00:43 . 2009-10-13 12:34 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-10-10 23:36 . 2009-10-16 21:18 -------- d-----w- c:\documents and settings\Alexander Stone\Tracing
2009-10-10 23:33 . 2009-10-15 01:26 -------- d-----w- c:\program files\Microsoft Silverlight
2009-10-10 23:32 . 2009-08-06 02:48 54752 ----a-w- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-10-10 23:17 . 2009-10-10 23:17 -------- d-----w- c:\program files\Microsoft Sync Framework
2009-10-10 23:15 . 2006-11-29 17:06 3426072 ----a-w- c:\windows\system32\d3dx9_32.dll
2009-10-10 23:15 . 2009-10-10 23:15 -------- d-----w- c:\program files\Microsoft SQL Server Compact Edition
2009-10-10 23:07 . 2009-10-13 12:33 -------- d-----w- c:\program files\Windows Live
2009-10-10 11:36 . 2009-10-10 11:36 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Help
2009-09-26 23:15 . 2009-09-26 23:15 -------- d-----w- c:\program files\Common Files\Windows Live
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-10-17 22:46 . 2009-10-17 22:46 805 ----a-w- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-17 22:46 . 2009-10-17 22:46 7443 ----a-w- c:\windows\system32\drivers\SYMEVENT.CAT
2009-10-17 22:46 . 2005-05-08 02:11 60808 ----a-w- c:\windows\system32\S32EVNT1.DLL
2009-10-17 02:18 . 2007-01-01 18:00 -------- d-----w- c:\documents and settings\Alexander Stone\Application Data\Apple Computer
2009-10-17 02:07 . 2008-12-21 00:00 -------- d-----w- c:\program files\Common Files\Apple
2009-10-16 01:31 . 2005-04-29 10:00 50400 ----a-w- c:\documents and settings\Alexander Stone\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-10-14 01:17 . 2007-12-16 20:02 -------- d-----w- c:\program files\Google
2009-10-13 12:34 . 2005-05-08 02:11 -------- d-----w- c:\program files\Common Files\Sym
2009-10-13 12:32 . 2007-08-31 10:10 -------- d-----w- c:\program files\Windows Live Toolbar
2009-10-13 03:48 . 2007-05-17 00:42 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-09-11 14:18 . 2004-08-10 17:51 136192 ----a-w- c:\windows\system32\msv1_0.dll
2009-09-04 21:03 . 2004-08-10 17:51 58880 ----a-w- c:\windows\system32\msasn1.dll
2009-08-29 08:08 . 2004-08-10 17:51 916480 ----a-w- c:\windows\system32\wininet.dll
2009-08-26 08:00 . 2004-08-10 17:51 247326 ----a-w- c:\windows\system32\strmdll.dll
2009-08-06 23:24 . 2004-08-10 18:02 327896 ----a-w- c:\windows\system32\wucltui.dll
2009-08-06 23:24 . 2004-08-10 18:02 209632 ----a-w- c:\windows\system32\wuweb.dll
2009-08-06 23:24 . 2005-05-26 08:16 44768 ----a-w- c:\windows\system32\wups2.dll
2009-08-06 23:24 . 2005-04-13 22:39 35552 ----a-w- c:\windows\system32\wups.dll
2009-08-06 23:24 . 2004-08-10 18:02 53472 ----a-w- c:\windows\system32\wuauclt.exe
2009-08-06 23:24 . 2004-08-10 17:50 96480 ----a-w- c:\windows\system32\cdm.dll
2009-08-06 23:23 . 2004-08-10 18:02 575704 ----a-w- c:\windows\system32\wuapi.dll
2009-08-06 23:23 . 2007-09-01 06:11 274288 ----a-w- c:\windows\system32\mucltui.dll
2009-08-06 23:23 . 2007-09-01 06:11 215920 ----a-w- c:\windows\system32\muweb.dll
2009-08-06 23:23 . 2004-08-10 18:02 1929952 ----a-w- c:\windows\system32\wuaueng.dll
2009-08-05 09:01 . 2004-08-10 17:51 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-05 00:44 . 2004-08-10 17:51 2189184 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-08-04 14:20 . 2004-08-04 03:59 2066048 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-07-29 04:37 . 2004-08-10 17:51 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2004-08-10 17:51 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-26 20:44 . 2009-07-26 20:44 48448 ----a-w- c:\windows\system32\sirenacm.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2004-10-09 155648]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2004-10-09 126976]
"SunJavaUpdateSched"="c:\program files\Java\j2re1.4.2_03\bin\jusched.exe" [2003-11-19 32881]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-12 290816]
"\\ALEX1\EPSON Stylus Photo R300 Series"="c:\windows\System32\spool\DRIVERS\W32X86\3\E_S4I2F1.EXE" [2003-06-04 99840]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2006-11-03 866584]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-21 305440]
c:\documents and settings\Alexander Stone\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Digital Line Detect.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
backup=c:\windows\pss\Digital Line Detect.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=c:\windows\pss\QuickBooks Update Agent.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\SAGENT4.EXE"=
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\WINDOWS\\system32\\logon.scr"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2002-04-11 16194]
R3 fsssvc;Windows Live Family Safety Service;c:\program files\Windows Live\Family Safety\fsssvc.exe [2009-08-06 704864]
R3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;c:\windows\system32\DRIVERS\WG511ICB.sys [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NAV\1100000.088\SYMDS.SYS [2009-08-30 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NAV\1100000.088\SYMEFA.SYS [2009-08-30 169008]
S1 BHDrvx86;BHDrvx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\BASHDefs\20090921.001\BHDrvx86.sys [2009-09-21 507440]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NAV\1100000.088\ccHPx86.sys [2009-08-24 501888]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NAV\1100000.088\Ironx86.SYS [2009-08-30 114736]
S2 fssfltr;fssfltr;c:\windows\system32\DRIVERS\fssfltr_tdi.sys [2009-08-06 54752]
S2 NAV;Norton AntiVirus;c:\program files\Norton AntiVirus\Engine\17.0.0.136\ccSvcHst.exe [2009-08-24 126392]
S2 WinDefend;Windows Defender;c:\program files\Windows Defender\MsMpEng.exe [2006-11-03 13592]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-08-29 102448]
S3 IDSxpx86;IDSxpx86;c:\documents and settings\All Users\Application Data\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_17.0.0.136\Definitions\IPSDefs\20090911.001\IDSxpx86.sys [2009-09-10 329080]
.
Contents of the 'Scheduled Tasks' folder
2009-10-14 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2009-10-18 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Windows Defender\MpCmdRun.exe [2006-11-03 23:20]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Open in new background tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/229?7338187de1364b2c94e4495a93771f87
IE: Open in new foreground tab - c:\program files\Windows Live Toolbar\Components\en-us\msntabres.dll.mui/230?7338187de1364b2c94e4495a93771f87
.
- - - - ORPHANS REMOVED - - - -
SharedTaskScheduler-{ad8a005a-2fd2-4dcc-8e7a-95c5d7c71fb2} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{543afe43-6b62-40a6-bb3e-001eb7b1b1ca} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{6c940be8-a90d-4168-ba44-8bb50d06b11e} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{749c1259-fc4e-4a30-831b-a3797c0941ec} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{ec2b3e47-3328-4128-a4b5-6b84f78a3e5d} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{8648409d-2114-4a24-933b-4c6892f6d726} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{4485730d-53c6-47f6-be14-7a4a38be227d} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{1ea3b4e3-3e36-43c7-817d-5cb1e0c87eef} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{d475fdb4-49f7-419e-8f25-a2226b12b34d} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{698c4063-4bbd-4290-8e11-9b08f6f80bba} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{b33c0604-d724-4dde-9d45-0d04da62c0ba} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{43c59feb-161c-4f6f-8d0b-0a159ab1abf5} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{2e15ce82-a4ca-47f9-ac6c-56a0dd3f06d1} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{42df5b95-c90c-40ca-884e-291594a713d3} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{382ec7eb-6e10-4945-91c9-f7ce7e833749} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{2a0fcd35-fb44-45bc-88ff-25d9f3e2ab05} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{3a01d124-ee6d-4961-aad5-5ca266c3b84d} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{050c04c5-3450-4e35-8bb6-0333c44a882f} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{bfa2b51f-4f87-473c-a44b-b7948247738a} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{57137f38-249c-49bc-98f9-2e1c48d46000} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{9e1edd6d-b891-4caf-9368-85e197fb8ba2} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{2be19818-4b77-4072-9eb1-265d77ee4f63} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{63689a13-418a-406f-acbd-ffa658b4f175} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{539827df-2f23-4d07-89e7-42ac9f123ace} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{63c5870e-b86d-4075-933c-8c5e6330178c} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{22b99929-0797-49a9-aae9-00bf50662cd5} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{ba827862-9205-4f2e-bd35-7b145444ac7b} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{a746430f-529a-4f92-a520-4688cc04d003} - c:\windows\system32\kenamezi.dll
SharedTaskScheduler-{244e7fa0-e36e-4dc7-9865-6aeef12e1eb2} - c:\windows\system32\juzutase.dll
SharedTaskScheduler-{ee72de4e-06bb-484f-81be-2cb5a124c29a} - c:\windows\system32\sorujawi.dll
SSODL-pivehapus-{ad8a005a-2fd2-4dcc-8e7a-95c5d7c71fb2} - c:\windows\system32\kenamezi.dll
SSODL-wizenetum-{543afe43-6b62-40a6-bb3e-001eb7b1b1ca} - c:\windows\system32\kenamezi.dll
SSODL-mijozokor-{6c940be8-a90d-4168-ba44-8bb50d06b11e} - c:\windows\system32\kenamezi.dll
SSODL-zivuyolep-{749c1259-fc4e-4a30-831b-a3797c0941ec} - c:\windows\system32\kenamezi.dll
SSODL-donupisaf-{ec2b3e47-3328-4128-a4b5-6b84f78a3e5d} - c:\windows\system32\kenamezi.dll
SSODL-mujohilom-{8648409d-2114-4a24-933b-4c6892f6d726} - c:\windows\system32\kenamezi.dll
SSODL-bapebalop-{4485730d-53c6-47f6-be14-7a4a38be227d} - c:\windows\system32\kenamezi.dll
SSODL-sedebazot-{1ea3b4e3-3e36-43c7-817d-5cb1e0c87eef} - c:\windows\system32\kenamezi.dll
SSODL-vuyenofoj-{d475fdb4-49f7-419e-8f25-a2226b12b34d} - c:\windows\system32\kenamezi.dll
SSODL-perayitil-{698c4063-4bbd-4290-8e11-9b08f6f80bba} - c:\windows\system32\juzutase.dll
SSODL-surojoran-{b33c0604-d724-4dde-9d45-0d04da62c0ba} - c:\windows\system32\juzutase.dll
SSODL-naturebeb-{43c59feb-161c-4f6f-8d0b-0a159ab1abf5} - c:\windows\system32\juzutase.dll
SSODL-riwakawof-{2e15ce82-a4ca-47f9-ac6c-56a0dd3f06d1} - c:\windows\system32\juzutase.dll
SSODL-dowudasez-{42df5b95-c90c-40ca-884e-291594a713d3} - c:\windows\system32\juzutase.dll
SSODL-fegoleref-{382ec7eb-6e10-4945-91c9-f7ce7e833749} - c:\windows\system32\kenamezi.dll
SSODL-gamewalez-{2a0fcd35-fb44-45bc-88ff-25d9f3e2ab05} - c:\windows\system32\juzutase.dll
SSODL-lezoyulam-{3a01d124-ee6d-4961-aad5-5ca266c3b84d} - c:\windows\system32\kenamezi.dll
SSODL-pajevabew-{050c04c5-3450-4e35-8bb6-0333c44a882f} - c:\windows\system32\kenamezi.dll
SSODL-lozuzasez-{bfa2b51f-4f87-473c-a44b-b7948247738a} - c:\windows\system32\juzutase.dll
SSODL-yigefihin-{57137f38-249c-49bc-98f9-2e1c48d46000} - c:\windows\system32\juzutase.dll
SSODL-puhatubub-{9e1edd6d-b891-4caf-9368-85e197fb8ba2} - c:\windows\system32\kenamezi.dll
SSODL-zipodinaf-{2be19818-4b77-4072-9eb1-265d77ee4f63} - c:\windows\system32\kenamezi.dll
SSODL-razokemik-{63689a13-418a-406f-acbd-ffa658b4f175} - c:\windows\system32\juzutase.dll
SSODL-tesebusoy-{539827df-2f23-4d07-89e7-42ac9f123ace} - c:\windows\system32\juzutase.dll
SSODL-bajirumew-{63c5870e-b86d-4075-933c-8c5e6330178c} - c:\windows\system32\juzutase.dll
SSODL-nukahapok-{22b99929-0797-49a9-aae9-00bf50662cd5} - c:\windows\system32\juzutase.dll
SSODL-baseliwaj-{ba827862-9205-4f2e-bd35-7b145444ac7b} - c:\windows\system32\kenamezi.dll
SSODL-zawuwikek-{a746430f-529a-4f92-a520-4688cc04d003} - c:\windows\system32\kenamezi.dll
SSODL-nebawalov-{244e7fa0-e36e-4dc7-9865-6aeef12e1eb2} - c:\windows\system32\juzutase.dll
SSODL-muyayizud-{ee72de4e-06bb-484f-81be-2cb5a124c29a} - c:\windows\system32\sorujawi.dll
Notify-WgaLogon - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-10-18 19:26
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet002\Services\NAV]
"ImagePath"="\"c:\program files\Norton AntiVirus\Engine\17.0.0.136\ccSvcHst.exe\" /s \"NAV\" /m \"c:\program files\Norton AntiVirus\Engine\17.0.0.136\diMaster.dll\" /prefetch:1"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(252)
c:\windows\system32\WININET.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\IEFRAME.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Dell\NicConfigSvc\NicConfigSvc.exe
c:\program files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
c:\windows\system32\wdfmgr.exe
c:\combofix\CF25381.exe
.
**************************************************************************
.
Completion time: 2009-10-18 19:49 - machine was rebooted
ComboFix-quarantined-files.txt 2009-10-18 23:49
Pre-Run: 9,695,080,448 bytes free
Post-Run: 10,051,964,928 bytes free
WindowsXP-KB310994-SP2-Home-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(2)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(2)\WINDOWS="Microsoft Windows XP Home Edition" /noexecute=optin /fastdetect
334 --- E O F --- 2009-10-15 01:30
==============================================================================
DDS:
DDS (Ver_09-10-13.01) - NTFSx86
Run by Alexander Stone at 19:51:37.03 on Sun 10/18/2009
Internet Explorer: 8.0.6001.18702
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.247.33 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Norton AntiVirus\Engine\17.0.0.136\ccSvcHst.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Norton AntiVirus\Engine\17.0.0.136\ccSvcHst.exe
C:\WINDOWS\explorer.exe
C:\Documents and Settings\Alexander Stone\Desktop\dds.scr
============== Pseudo HJT Report ===============
uStart Page = hxxp://google.com/
uDefault_Search_URL = hxxp://www.google.com/ie
mSearch Bar =
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 6.0\reader\activex\AcroIEHelper.dll
BHO: Symantec Intrusion Prevention: {6d53ec84-6aae-4787-aeee-f4628f01010c} - c:\program files\norton antivirus\engine\17.0.0.136\IPSBHO.DLL
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - c:\program files\windows live\toolbar\wltcore.dll
TB: &Windows Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - c:\program files\windows live\toolbar\wltcore.dll
TB: {855F3B16-6D32-4FE6-8A56-BBB695989046} - No File
TB: &Yahoo! Toolbar: {ef99bd32-c1fb-11d2-892f-0090271d4f88} -
TB: {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - No File
uRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [SunJavaUpdateSched] c:\program files\java\j2re1.4.2_03\bin\jusched.exe
mRun: [PCMService] "c:\program files\dell\media experience\PCMService.exe"
mRun: [\\ALEX1\EPSON Stylus Photo R300 Series] c:\windows\system32\spool\drivers\w32x86\3\e_s4i2f1.exe /p38 "\\alex1\EPSON Stylus Photo R300 Series" /O6 "USB003" /M "Stylus Photo R300"
mRun: [Windows Defender] "c:\program files\windows defender\MSASCui.exe" -hide
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"
StartupFolder: c:\docume~1\alexan~1\startm~1\programs\startup\erunta~1.lnk - c:\program files\erunt\AUTOBACK.EXE
IE: Add to Windows &Live Favorites -
http://favorites.live.com/quickadd.aspxIE: Open in new background tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/229?7338187de1364b2c94e4495a93771f87
IE: Open in new foreground tab - c:\program files\windows live toolbar\components\en-us\msntabres.dll.mui/230?7338187de1364b2c94e4495a93771f87
IE: {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.htmlIE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - {08B0E5C0-4FCB-11CF-AAA5-00401C608501}
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Notify: igfxcui - igfxsrvc.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SEH: Microsoft AntiMalware ShellExecuteHook: {091eb208-39dd-417d-a5dd-7e2c2d8fb9cb} - c:\progra~1\wifd1f~1\MpShHook.dll
============= SERVICES / DRIVERS ===============
R0 SymDS;Symantec Data Store;c:\windows\system32\drivers\nav\1100000.088\SymDS.sys [2009-10-17 328752]
R0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\nav\1100000.088\SymEFA.sys [2009-10-17 169008]
R1 BHDrvx86;BHDrvx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\bashdefs\20090921.001\BHDrvx86.sys [2009-9-21 507440]
R1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\nav\1100000.088\ccHPx86.sys [2009-10-17 501888]
R1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\nav\1100000.088\Ironx86.sys [2009-10-17 114736]
R2 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr_tdi.sys [2009-10-10 54752]
R2 NAV;Norton AntiVirus;c:\program files\norton antivirus\engine\17.0.0.136\ccSvcHst.exe [2009-10-17 126392]
R2 SeaPort;SeaPort;c:\program files\microsoft\search enhancement pack\seaport\SeaPort.exe [2009-5-19 240512]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\common files\symantec shared\eengine\EraserUtilRebootDrv.sys [2009-10-17 102448]
R3 IDSxpx86;IDSxpx86;c:\documents and settings\all users\application data\norton\{0c55c096-0f1d-4f28-aaa2-85ef591126e7}\nav_17.0.0.136\definitions\ipsdefs\20090911.001\IDSXpx86.sys [2009-10-17 329080]
S3 AWINDIS5;AWINDIS5 Protocol Driver;c:\windows\system32\AWINDIS5.SYS [2005-4-28 16194]
S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2009-8-5 704864]
S3 PRISM_ICB;NETGEAR WG511 Wireless LAN Driver;c:\windows\system32\drivers\wg511icb.sys --> c:\windows\system32\drivers\WG511ICB.sys [?]
=============== Created Last 30 ================
2009-10-18 18:56 <DIR> a-dshr-- C:\cmdcons
2009-10-18 18:51 236,544 a------- c:\windows\PEV.exe
2009-10-18 18:51 161,792 a------- c:\windows\SWREG.exe
2009-10-18 18:51 98,816 a------- c:\windows\sed.exe
2009-10-17 18:46 124,976 a------- c:\windows\system32\drivers\SYMEVENT.SYS
2009-10-17 18:46 7,443 a------- c:\windows\system32\drivers\SYMEVENT.CAT
2009-10-17 18:46 805 a------- c:\windows\system32\drivers\SYMEVENT.INF
2009-10-17 18:46 <DIR> --d----- c:\program files\Symantec
2009-10-17 18:46 <DIR> --d----- c:\program files\common files\Symantec Shared
2009-10-17 18:43 <DIR> --d----- c:\windows\system32\drivers\NAV
2009-10-17 18:43 <DIR> --d----- c:\program files\Norton AntiVirus
2009-10-17 18:41 <DIR> --d----- c:\program files\NortonInstaller
2009-10-17 18:41 <DIR> --d----- c:\docume~1\alluse~1\applic~1\NortonInstaller
2009-10-16 22:07 <DIR> --d----- c:\program files\iPod
2009-10-16 22:07 <DIR> --d----- c:\program files\iTunes
2009-10-16 22:07 <DIR> --d----- c:\docume~1\alluse~1\applic~1\{755AC846-7372-4AC8-8550-C52491DAA8BD}
2009-10-16 22:04 <DIR> --d----- c:\program files\Bonjour
2009-10-15 22:28 195,440 -------- c:\windows\system32\MpSigStub.exe
2009-10-15 21:54 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Norton
2009-10-15 21:36 <DIR> --d----- c:\program files\Trend Micro
2009-10-15 17:29 211 a------- c:\windows\wininit.ini
2009-10-14 22:43 <DIR> --d----- c:\program files\Spybot - Search & Destroy
2009-10-14 22:43 <DIR> --d----- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2009-10-14 22:13 <DIR> --d----- c:\program files\VS Revo Group
2009-10-14 21:34 1,089,593 -------- c:\windows\system32\dllcache\ntprint.cat
2009-10-14 20:15 <DIR> --d----- c:\windows\system32\XPSViewer
2009-10-14 20:13 117,760 -------- c:\windows\system32\prntvpt.dll
2009-10-14 20:13 89,088 -------- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-10-14 20:13 1,676,288 -------- c:\windows\system32\xpssvcs.dll
2009-10-14 20:13 1,676,288 -------- c:\windows\system32\dllcache\xpssvcs.dll
2009-10-14 20:13 597,504 -------- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-10-14 20:13 575,488 -------- c:\windows\system32\xpsshhdr.dll
2009-10-14 20:13 575,488 -------- c:\windows\system32\dllcache\xpsshhdr.dll
2009-10-14 20:13 <DIR> --d----- C:\34df902294fd73946e2a4370ed
2009-10-14 19:51 1,315,328 -------- c:\windows\system32\dllcache\msoe.dll
2009-10-14 19:45 333,952 -------- c:\windows\system32\dllcache\srv.sys
2009-10-14 19:45 455,296 -------- c:\windows\system32\dllcache\mrxsmb.sys
2009-10-14 19:44 337,408 -------- c:\windows\system32\dllcache\netapi32.dll
2009-10-14 19:44 691,712 -------- c:\windows\system32\dllcache\inetcomm.dll
2009-10-14 19:43 272,128 -------- c:\windows\system32\dllcache\bthport.sys
2009-10-14 19:43 203,136 -------- c:\windows\system32\dllcache\rmcast.sys
2009-10-14 10:27 <DIR> --d----- c:\windows\system32\scripting
2009-10-14 10:27 <DIR> --d----- c:\windows\l2schemas
2009-10-14 10:27 <DIR> --d----- c:\windows\system32\en
2009-10-14 10:27 <DIR> --d----- c:\windows\system32\bits
2009-10-14 10:19 <DIR> --d----- c:\windows\network diagnostic
2009-10-14 10:17 <DIR> --d----- c:\windows\Security
2009-10-14 10:11 <DIR> --d----- c:\windows\EHome
2009-10-14 05:36 69,120 -------- c:\windows\system32\wlanapi.dll
2009-10-14 05:36 25,471 -------- c:\windows\system32\drivers\watv10nt.sys
2009-10-14 05:36 22,271 -------- c:\windows\system32\drivers\watv06nt.sys
2009-10-14 05:36 14,208 -------- c:\windows\system32\drivers\wacompen.sys
2009-10-14 05:36 11,935 -------- c:\windows\system32\drivers\wadv11nt.sys
2009-10-14 05:36 11,871 -------- c:\windows\system32\drivers\wadv09nt.sys
2009-10-14 05:36 11,807 -------- c:\windows\system32\drivers\wadv07nt.sys
2009-10-14 05:36 11,295 -------- c:\windows\system32\drivers\wadv08nt.sys
2009-10-14 05:36 28,672 -------- c:\windows\system32\vidcap.ax
2009-10-14 05:36 11,325 -------- c:\windows\system32\drivers\vchnt5.dll
2009-10-14 05:36 121,984 -------- c:\windows\system32\drivers\usbvideo.sys
2009-10-14 05:34 193,024 -------- c:\windows\system32\napmontr.dll
2009-10-14 05:33 81,920 -------- c:\windows\system32\ieencode.dll
2009-10-14 05:32 4,255 -------- c:\windows\system32\drivers\adv01nt5.dll
2009-10-14 05:32 3,967 -------- c:\windows\system32\drivers\adv02nt5.dll
2009-10-14 05:32 3,775 -------- c:\windows\system32\drivers\adv11nt5.dll
2009-10-14 05:32 3,711 -------- c:\windows\system32\drivers\adv09nt5.dll
2009-10-14 05:32 3,647 -------- c:\windows\system32\drivers\adv07nt5.dll
2009-10-14 05:32 3,615 -------- c:\windows\system32\drivers\adv05nt5.dll
2009-10-14 05:32 3,135 -------- c:\windows\system32\drivers\adv08nt5.dll
2009-10-14 05:32 136,192 -------- c:\windows\system32\aaclient.dll
2009-10-13 23:03 <DIR> --dsh--- c:\documents and settings\alexander stone\PrivacIE
2009-10-13 23:01 <DIR> --dsh--- c:\documents and settings\alexander stone\IETldCache
2009-10-13 22:53 12,800 -------- c:\windows\system32\dllcache\xpshims.dll
2009-10-13 22:53 1,985,536 -------- c:\windows\system32\dllcache\iertutil.dll
2009-10-13 22:53 594,432 -------- c:\windows\system32\dllcache\msfeeds.dll
2009-10-13 22:53 246,272 -------- c:\windows\system32\dllcache\ieproxy.dll
2009-10-13 22:53 55,296 -------- c:\windows\system32\dllcache\msfeedsbs.dll
2009-10-13 22:53 11,069,440 -------- c:\windows\system32\dllcache\ieframe.dll
2009-10-13 22:53 <DIR> --d----- c:\windows\ie8updates
2009-10-13 22:49 <DIR> -cd-h--- c:\windows\ie8
2009-10-13 21:48 46,060 a---h--- c:\windows\system32\mlfcache.dat
2009-10-13 08:34 <DIR> --d----- c:\docume~1\alexan~1\applic~1\IObit
2009-10-13 08:31 <DIR> --d----- c:\program files\Microsoft
2009-10-13 08:31 <DIR> --d----- c:\program files\Windows Live SkyDrive
2009-10-12 22:31 <DIR> --d----- c:\program files\IObit
2009-10-10 19:36 <DIR> --d----- c:\documents and settings\alexander stone\Tracing
2009-10-10 19:32 54,752 a------- c:\windows\system32\drivers\fssfltr_tdi.sys
2009-10-10 19:15 3,426,072 a------- c:\windows\system32\d3dx9_32.dll
2009-10-10 19:15 <DIR> --d----- c:\program files\Microsoft SQL Server Compact Edition
2009-09-26 19:15 <DIR> --d----- c:\program files\common files\Windows Live
==================== Find3M ====================
2009-10-17 18:46 60,808 a------- c:\windows\system32\S32EVNT1.DLL
2009-10-14 10:32 77,859 a------- c:\windows\pchealth\helpctr\offlinecache\index.dat
2009-09-11 10:18 136,192 a------- c:\windows\system32\msv1_0.dll
2009-09-11 10:18 136,192 -------- c:\windows\system32\dllcache\msv1_0.dll
2009-09-04 17:03 58,880 a------- c:\windows\system32\msasn1.dll
2009-09-04 17:03 58,880 -------- c:\windows\system32\dllcache\msasn1.dll
2009-08-29 04:08 1,208,832 -------- c:\windows\system32\dllcache\urlmon.dll
2009-08-29 04:08 916,480 -------- c:\windows\system32\wininet.dll
2009-08-29 04:08 916,480 -------- c:\windows\system32\dllcache\wininet.dll
2009-08-29 04:08 5,940,224 -------- c:\windows\system32\dllcache\mshtml.dll
2009-08-29 04:08 206,848 -------- c:\windows\system32\dllcache\occache.dll
2009-08-29 04:08 25,600 -------- c:\windows\system32\dllcache\jsproxy.dll
2009-08-29 04:08 184,320 -------- c:\windows\system32\dllcache\iepeers.dll
2009-08-29 04:08 387,584 -------- c:\windows\system32\dllcache\iedkcs32.dll
2009-08-28 06:35 173,056 -------- c:\windows\system32\dllcache\ie4uinit.exe
2009-08-26 04:00 247,326 a------- c:\windows\system32\strmdll.dll
2009-08-26 04:00 247,326 -------- c:\windows\system32\dllcache\strmdll.dll
2009-08-07 04:48 100,352 -------- c:\windows\system32\dllcache\iecompat.dll
2009-08-06 19:24 327,896 a------- c:\windows\system32\dllcache\wucltui.dll
2009-08-06 19:24 209,632 a------- c:\windows\system32\dllcache\wuweb.dll
2009-08-06 19:24 35,552 a------- c:\windows\system32\dllcache\wups.dll
2009-08-06 19:24 53,472 a------- c:\windows\system32\dllcache\wuauclt.exe
2009-08-06 19:24 96,480 a------- c:\windows\system32\dllcache\cdm.dll
2009-08-06 19:23 575,704 a------- c:\windows\system32\dllcache\wuapi.dll
2009-08-06 19:23 1,929,952 a------- c:\windows\system32\dllcache\wuaueng.dll
2009-08-06 19:23 274,288 a------- c:\windows\system32\mucltui.dll
2009-08-06 19:23 215,920 a------- c:\windows\system32\muweb.dll
2009-08-05 05:01 204,800 a------- c:\windows\system32\mswebdvd.dll
2009-08-05 05:01 204,800 -------- c:\windows\system32\dllcache\mswebdvd.dll
2009-08-04 20:44 2,189,184 -------- c:\windows\system32\ntoskrnl.exe
2009-08-04 20:44 2,189,184 -------- c:\windows\system32\dllcache\ntoskrnl.exe
2009-08-04 11:13 2,145,280 -------- c:\windows\system32\dllcache\ntkrnlmp.exe
2009-08-04 10:20 2,023,936 -------- c:\windows\system32\dllcache\ntkrpamp.exe
2009-08-04 10:20 2,066,048 -------- c:\windows\system32\ntkrnlpa.exe
2009-08-04 10:20 2,066,048 -------- c:\windows\system32\dllcache\ntkrnlpa.exe
2009-07-29 00:37 119,808 a------- c:\windows\system32\t2embed.dll
2009-07-29 00:37 81,920 a------- c:\windows\system32\fontsub.dll
2009-07-29 00:37 119,808 -------- c:\windows\system32\dllcache\t2embed.dll
2009-07-29 00:37 81,920 -------- c:\windows\system32\dllcache\fontsub.dll
2009-07-26 16:44 48,448 a------- c:\windows\system32\sirenacm.dll
2005-05-10 06:28 0 a---h--- c:\docume~1\alluse~1\applic~1\gwseh.dat
============= FINISH: 19:53:10.84 ===============