Okay, I did all the things you needed me to do. Here are all the logs:
Combofix:
ComboFix 09-03-29.02 - Kevin 2009-03-29 19:07:36.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.751.254 [GMT -5:00]
Running from: c:\documents and settings\Kevin\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Kevin\Desktop\CFScript.txt
AV: Symantec AntiVirus Corporate Edition *On-access scanning disabled* (Updated)
FW: Symantec Client Firewall *enabled*
* Created a new restore point
FILE ::
c:\windows\system32\XDva202.sys
c:\windows\system32\XDva219.sys
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_XDVA202
-------\Legacy_XDVA219
-------\Service_XDva202
-------\Service_XDva219
((((((((((((((((((((((((( Files Created from 2009-02-28 to 2009-03-30 )))))))))))))))))))))))))))))))
.
2009-03-27 21:28 . 2009-03-27 21:28 <DIR> d--hsc--- c:\documents and settings\NetworkService\IETldCache
2009-03-25 18:50 . 2009-03-25 18:50 <DIR> d--hsc--- c:\documents and settings\LocalService\IETldCache
2009-03-25 18:45 . 2009-03-25 18:45 <DIR> d----c--- c:\windows\system32\config\systemprofile\Application Data\SACore
2009-03-25 18:45 . 2009-03-25 18:45 <DIR> d--hsc--- c:\documents and settings\Kevin\IECompatCache
2009-03-25 18:38 . 2009-03-25 18:38 <DIR> d--hsc--- c:\documents and settings\Kevin\PrivacIE
2009-03-25 18:29 . 2009-03-25 18:29 <DIR> d--hsc--- c:\documents and settings\Kevin\IETldCache
2009-03-25 16:35 . 2009-03-25 16:35 <DIR> d----c--- c:\windows\ie8updates
2009-03-25 16:33 . 2009-03-25 16:33 1,374 --a--c--- c:\windows\imsins.BAK
2009-03-25 16:29 . 2009-03-25 16:33 <DIR> d--h-c--- c:\windows\ie8
2009-03-25 16:22 . 2009-02-27 23:55 105,984 -----c--- c:\windows\system32\dllcache\iecompat.dll
2009-03-24 20:51 . 2009-03-24 20:56 <DIR> d----c--- c:\documents and settings\NetworkService\Application Data\HPAppData
2009-03-24 19:41 . 2009-03-24 19:43 <DIR> d----c--- C:\SigmaTel Audio drivers
2009-03-24 19:22 . 2009-03-24 19:24 <DIR> d----c--- C:\cabs
2009-03-24 18:37 . 2009-03-24 18:37 410,984 --a--c--- c:\windows\system32\deploytk.dll
2009-03-24 18:37 . 2009-03-24 18:37 73,728 --a--c--- c:\windows\system32\javacpl.cpl
2009-03-24 18:36 . 2009-03-24 18:36 <DIR> d----c--- c:\program files\Java
2009-03-23 21:42 . 2009-03-23 22:26 <DIR> d----c--- C:\RootRepeal
2009-03-22 11:06 . 2009-03-22 11:06 <DIR> d----c--- c:\windows\system32\NtmsData
2009-03-21 23:30 . 2009-03-21 23:30 <DIR> d----c--- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-21 23:25 . 2009-03-22 15:58 <DIR> d----c--- c:\program files\SUPERAntiSpyware
2009-03-21 23:25 . 2009-03-21 23:25 <DIR> d----c--- c:\documents and settings\Kevin\Application Data\SUPERAntiSpyware.com
2009-03-20 19:02 . 2009-03-20 19:02 <DIR> d----c--- c:\program files\Trend Micro
2009-03-20 18:26 . 2009-03-20 18:26 <DIR> d----c--- c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-03-20 17:33 . 2009-03-20 18:11 <DIR> d----c--- c:\documents and settings\All Users\Application Data\SecTaskMan
2009-03-19 19:38 . 2009-03-24 20:37 <DIR> d----c--- C:\QUARANTINE
2009-03-19 19:12 . 2009-03-19 19:12 <DIR> d----c--- c:\program files\Common Files\Cisco Systems
2009-03-18 21:49 . 2009-03-18 21:49 <DIR> d----c--- c:\program files\AVG
2009-03-18 21:42 . 2009-02-11 10:19 15,504 --a--c--- c:\windows\system32\drivers\mbam.sys
2009-03-18 21:41 . 2009-03-20 19:39 <DIR> d----c--- c:\program files\Malwarebytes' Anti-Malware
2009-03-18 21:41 . 2009-02-11 10:19 38,496 --a--c--- c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-16 16:58 . 2009-03-16 16:58 <DIR> d----c--- c:\program files\gpotato
2009-03-16 15:29 . 2009-03-16 16:09 <DIR> d----c--- c:\documents and settings\Kevin\Application Data\IGN_DLM
2009-03-15 17:31 . 2009-03-25 18:50 54,156 --ah-c--- c:\windows\QTFont.qfn
2009-03-15 17:31 . 2009-03-15 17:32 1,409 --a--c--- c:\windows\QTFont.for
2009-03-10 19:25 . 2009-03-10 19:25 <DIR> d--h-c--- C:\C_DILLA
2009-03-10 19:25 . 2009-03-10 19:25 112,128 -r-h-c--- c:\windows\CdaC14BA.DLL
2009-03-10 19:25 . 2009-03-10 19:25 39,936 --a--c--- c:\windows\system32\drivers\CDAC11BA.EXE
2009-03-10 19:25 . 2009-03-10 19:25 30,720 -r-h-c--- c:\windows\CdaC13BA.EXE
2009-03-10 19:25 . 2009-03-10 19:25 8,864 --a--c--- c:\windows\system32\drivers\CDAC15BA.SYS
2009-03-10 18:26 . 2009-03-17 18:38 <DIR> d----c--- c:\program files\Steam
2009-03-09 23:28 . 2009-03-09 23:28 <DIR> d----c--- c:\program files\Audacity
2009-03-09 23:14 . 2009-03-16 17:47 <DIR> d----c--- c:\program files\Windows Audio Recorder Professional
2009-03-08 14:22 . 2009-03-08 14:22 49,152 -----c--- c:\windows\system32\msrating.dll.mui
2009-03-08 14:22 . 2009-03-08 14:22 2,560 -----c--- c:\windows\system32\mshta.exe.mui
2009-03-08 14:21 . 2009-03-08 14:21 4,096 -----c--- c:\windows\system32\ie4uinit.exe.mui
2009-03-08 14:20 . 2009-03-08 14:20 81,920 -----c--- c:\windows\system32\iedkcs32.dll.mui
2009-02-12 22:20 . 2009-02-12 22:20 5,630 -----c--- c:\windows\system32\IE8Eula.rtf
2009-02-11 19:52 . 2009-02-11 19:52 <DIR> d----c--- c:\windows\SQLTools9_KB960089_ENU
2009-02-11 19:51 . 2009-02-11 19:51 <DIR> d----c--- c:\windows\SQL9_KB960089_ENU
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-30 00:11 --------- dc----w c:\program files\Common Files\Symantec Shared
2009-03-30 00:05 --------- dc----w c:\documents and settings\Kevin\Application Data\HPAppData
2009-03-29 02:07 --------- dc----w c:\program files\McAfee
2009-03-29 02:07 --------- dc----w c:\program files\Common Files\McAfee
2009-03-29 02:07 --------- dc----w c:\documents and settings\All Users\Application Data\McAfee
2009-03-29 01:31 --------- dc----w c:\documents and settings\All Users\Application Data\Google Updater
2009-03-25 00:31 --------- dc-h--w c:\program files\InstallShield Installation Information
2009-03-24 02:26 --------- dc----w c:\program files\CCleaner
2009-03-23 00:13 --------- dc----w c:\documents and settings\NetworkService\Application Data\SACore
2009-03-21 00:07 --------- dc----w c:\program files\Common Files\Wise Installation Wizard
2009-03-19 12:15 --------- dc----w c:\documents and settings\Lingyan\Application Data\HPAppData
2009-03-17 23:38 --------- dc----w c:\program files\DocSmartzPro
2009-03-16 22:40 --------- dc----w c:\program files\GRETECH
2009-03-15 23:43 --------- dc----w c:\program files\Google
2009-03-11 20:27 --------- dc----w c:\documents and settings\All Users\Application Data\Microsoft Help
2009-03-11 00:25 --------- dc----w c:\documents and settings\Kevin\Application Data\ArcSoft
2009-03-07 17:14 --------- dc----w c:\documents and settings\LocalService\Application Data\SACore
2009-02-28 23:44 34 -c--a-w c:\documents and settings\Kevin\jagex_runescape_preferences.dat
2009-02-28 00:12 --------- dc----w c:\program files\GemFighter
2009-02-27 04:52 --------- dc----w c:\program files\Microsoft SQL Server
2009-02-27 01:16 --------- dc----w c:\program files\Microsoft Silverlight
2007-08-04 03:42 544 -c--a-w c:\documents and settings\Xuefeng\Application Data\wklnhst.dat
2007-07-05 17:07 3,034 -c--a-w c:\documents and settings\Kevin\Application Data\wklnhst.dat
2007-04-08 04:29 1,086 -c--a-w c:\documents and settings\Lingyan\Application Data\wklnhst.dat
2006-04-14 18:37 774,144 -c--a-w c:\program files\RngInterstitial.dll
2006-04-02 01:57 32 -c--a-r c:\documents and settings\All Users\hash.dat
2003-08-27 21:19 36,963 -c--a-r c:\program files\Common Files\SM1updtr.dll
2008-05-29 17:38 32,768 -csha-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\MSHist012008052920080530\index.dat
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of c:\documents and settings\All Users\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F} ----
---- Directory of c:\documents and settings\All Users\Application Data\SecTaskMan ----
2009-03-20 17:34 9967 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_4A6835266B6B11946A8E3281C9F3D251.dll
2009-03-20 17:34 98 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_A997F1139ECFE9D45B2DBC8B58B904BB.dll
2009-03-20 17:34 974 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_96649B8A45686214DB820D2D14C2ED6D.dll
2009-03-20 17:34 934 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_B0B35DEDC76B4424EAA66DDFC3821DFE
2009-03-20 17:34 916 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_34053A86A55C7324889C73EEC136DE17.dll
2009-03-20 17:34 907 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_b25099274a207264182f8181add555d0.dll
2009-03-20 17:34 891 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_A76A12931BA584E449447C8141FC0372.dll
2009-03-20 17:34 88 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EB940C659E972054EB7A79453A6EF0B9.dll
2009-03-20 17:34 832 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DDE7F2BCF1D91C3409CFF425AE1E271A
2009-03-20 17:34 810 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_7DDFFFA258DE09A4C825D59ABECDB9F8
2009-03-20 17:34 797 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_68AB67CA7DA73301B7449A0000000010
2009-03-20 17:34 783 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_68AB67CA7DA73301B7449A0000000010.dll
2009-03-20 17:34 780 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_AA75334BD6A349D45BE6344CD4905E84
2009-03-20 17:34 75 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_89C44F9E6B8BF084FAB74EA2A0644F3E.dll
2009-03-20 17:34 74 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610005.dll
2009-03-20 17:34 74 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610003.dll
2009-03-20 17:34 74 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610002.dll
2009-03-20 17:34 74 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610001.dll
2009-03-20 17:34 706 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_96649B8A45686214DB820D2D14C2ED6D
2009-03-20 17:34 679 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DB990CF2B9CABE3308C93D231E2BC704
2009-03-20 17:34 679 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_ADE3EF6381C0ED8439B49D68F2287A8A
2009-03-20 17:34 670 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_983B05722D2A359499AC721C2F8A6EDF
2009-03-20 17:34 662 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EC2DFDB492364E248910B9D3F1017DB9
2009-03-20 17:34 653 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_2A5C838123BA5414581CBBB9D8AF42DC
2009-03-20 17:34 650 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_4A6C98315694CEA41957805BA401AF84
2009-03-20 17:34 639 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_57FA4D4407865F14191866E20A55701E
2009-03-20 17:34 629 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8663020007180A44EB446B23AFD487F0
2009-03-20 17:34 620 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_681411AE0AE2DDD4B8B959F4025CDA88
2009-03-20 17:34 614 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EE3C5F35DE50038499B4052B0F5DF0EC
2009-03-20 17:34 5984 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0E8BA73496BF22242B086AF4D32E5219
2009-03-20 17:34 594 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_6529CD9AF907AEB43BD9F4119D5058AA
2009-03-20 17:34 59 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8663020007180A44EB446B23AFD487F0.dll
2009-03-20 17:34 582 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_71C2D678E362DF347A2E4324E8282F93
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610005
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610003
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610002
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D610001
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D511001
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D511000
2009-03-20 17:34 571 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D510009
2009-03-20 17:34 567 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D6C57B87C35EC424FB38B436DBA46628
2009-03-20 17:34 561 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A1A2DB22FA2E064AA3C8E3288E43B60
2009-03-20 17:34 554 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D9BD4ABD15EE44944A9189BAF121948C
2009-03-20 17:34 550 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_34053A86A55C7324889C73EEC136DE17
2009-03-20 17:34 545 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_2D504C6FD05C01D48BE9372A331AD447
2009-03-20 17:34 545 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1B6FFD204561C114D8B7DF0625FE10F6
2009-03-20 17:34 542 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_3ECDCD77DED23F261845507E5474D270
2009-03-20 17:34 540 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_89C44F9E6B8BF084FAB74EA2A0644F3E
2009-03-20 17:34 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DDA39468D428E8B4DB27C8D5DC5CA217
2009-03-20 17:34 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_C98364860CAB473408E81B028FA65F7D
2009-03-20 17:34 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F841731866D117AB7000B0D410205
2009-03-20 17:34 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_6030E61781384634B8F8C04C9E73B6CA
2009-03-20 17:34 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_568774731F3A2774DA34AACFB6FC9FF9
2009-03-20 17:34 537 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_96F67BA0167EAFC49B0B1A09B6E4E9B4
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EB940C659E972054EB7A79453A6EF0B9
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D7314F9862C648A4DB8BE2A5B47BE100
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_b25099274a207264182f8181add555d0
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_B000DB45EB0A4C6499C3CAFE1212E6A8
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_A997F1139ECFE9D45B2DBC8B58B904BB
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_A76A12931BA584E449447C8141FC0372
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_9F2FDFE0D6387BE43AD230B83D1FBFA2
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_93BAD29AC2E44034A96BCB446EB8552E
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_90A2CC5A3D9ECE9429D33078B4DBC4C2
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_56A968A049C8C7F45A7C79D2C3C8DEE9
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_526DF528D86F7F44E9C4ABF96C7B1732
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_4A6835266B6B11946A8E3281C9F3D251
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_20DD3B9F3B0B9E24680530D0FFD031D3
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1F3B805BA42A0C233B0158879691FE82
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1881ED2242D918945BCCCEE7F9F2D425
2009-03-20 17:34 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_17400AB28230347339DBAF1833357A38
2009-03-20 17:34 498 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EC2DFDB492364E248910B9D3F1017DB9.dll
2009-03-20 17:34 42 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D511001.dll
2009-03-20 17:34 42 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D511000.dll
2009-03-20 17:34 42 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F842331866D117AB7000B0D510009.dll
2009-03-20 17:34 41 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_56A968A049C8C7F45A7C79D2C3C8DEE9.dll
2009-03-20 17:34 40 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_96F67BA0167EAFC49B0B1A09B6E4E9B4.dll
2009-03-20 17:34 3743 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_2A5C838123BA5414581CBBB9D8AF42DC.dll
2009-03-20 17:34 3257 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DDE7F2BCF1D91C3409CFF425AE1E271A.dll
2009-03-20 17:34 31 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1881ED2242D918945BCCCEE7F9F2D425.dll
2009-03-20 17:34 3090 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_BCEC896027091B74EA1A49AC5390988B.dll
2009-03-20 17:34 2979 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_7DDFFFA258DE09A4C825D59ABECDB9F8.dll
2009-03-20 17:34 2756 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_983B05722D2A359499AC721C2F8A6EDF.dll
2009-03-20 17:34 270 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_29FE602138E29584CABC02843CBCD76A.dll
2009-03-20 17:34 27 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_C98364860CAB473408E81B028FA65F7D.dll
2009-03-20 17:34 27 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_90A2CC5A3D9ECE9429D33078B4DBC4C2.dll
2009-03-20 17:34 2697 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_AA75334BD6A349D45BE6344CD4905E84.dll
2009-03-20 17:34 2680 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DB990CF2B9CABE3308C93D231E2BC704.dll
2009-03-20 17:34 266 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_B0B35DEDC76B4424EAA66DDFC3821DFE.dll
2009-03-20 17:34 26 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_9F2FDFE0D6387BE43AD230B83D1FBFA2.dll
2009-03-20 17:34 2586 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_12345db
2009-03-20 17:34 2546 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_57FA4D4407865F14191866E20A55701E.dll
2009-03-20 17:34 24817 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0E8BA73496BF22242B086AF4D32E5219.dll
2009-03-20 17:34 218 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D9BD4ABD15EE44944A9189BAF121948C.dll
2009-03-20 17:34 202 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_71C2D678E362DF347A2E4324E8282F93.dll
2009-03-20 17:34 1945 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_4A6C98315694CEA41957805BA401AF84.dll
2009-03-20 17:34 186 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A1A2DB22FA2E064AA3C8E3288E43B60.dll
2009-03-20 17:34 179 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_2D504C6FD05C01D48BE9372A331AD447.dll
2009-03-20 17:34 1725 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_ADE3EF6381C0ED8439B49D68F2287A8A.dll
2009-03-20 17:34 170 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_20DD3B9F3B0B9E24680530D0FFD031D3.dll
2009-03-20 17:34 1553 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_6529CD9AF907AEB43BD9F4119D5058AA.dll
2009-03-20 17:34 152 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_DDA39468D428E8B4DB27C8D5DC5CA217.dll
2009-03-20 17:34 152 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_568774731F3A2774DA34AACFB6FC9FF9.dll
2009-03-20 17:34 1475 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_30ECB7411F0CF9C41875A6986B2D9D37.dll
2009-03-20 17:34 1447 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_EE3C5F35DE50038499B4052B0F5DF0EC.dll
2009-03-20 17:34 1344 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_BCEC896027091B74EA1A49AC5390988B
2009-03-20 17:34 1245 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_30ECB7411F0CF9C41875A6986B2D9D37
2009-03-20 17:34 121 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_6030E61781384634B8F8C04C9E73B6CA.dll
2009-03-20 17:34 1180 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1B6FFD204561C114D8B7DF0625FE10F6.dll
2009-03-20 17:34 1116 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_681411AE0AE2DDD4B8B959F4025CDA88.dll
2009-03-20 17:34 110 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D6C57B87C35EC424FB38B436DBA46628.dll
2009-03-20 17:34 1064 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_29FE602138E29584CABC02843CBCD76A
2009-03-20 17:34 10181 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_12341rg
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_D7314F9862C648A4DB8BE2A5B47BE100.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_B000DB45EB0A4C6499C3CAFE1212E6A8.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_93BAD29AC2E44034A96BCB446EB8552E.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_8A0F841731866D117AB7000B0D410205.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_526DF528D86F7F44E9C4ABF96C7B1732.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_3ECDCD77DED23F261845507E5474D270.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_1F3B805BA42A0C233B0158879691FE82.dll
2009-03-20 17:34 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_17400AB28230347339DBAF1833357A38.dll
2009-03-20 17:33 92 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109610090400000000000F01FEC.dll
2009-03-20 17:33 804 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_07525D5E1FE567544A43C6DC2962F8F0.dll
2009-03-20 17:33 76 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_07CAE84500EEDD1109C8000565084666.dll
2009-03-20 17:33 74 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109B10090400000000000F01FEC.dll
2009-03-20 17:33 726 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0DEF1459F7230FD4B869FE75FE26F291
2009-03-20 17:33 656 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109440090400000000000F01FEC
2009-03-20 17:33 629 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00006FCA9B229EC4896DC2FC53B9CA70
2009-03-20 17:33 60 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109910090400000000000F01FEC.dll
2009-03-20 17:33 581 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_07CAE84500EEDD1109C8000565084666
2009-03-20 17:33 556 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_07525D5E1FE567544A43C6DC2962F8F0
2009-03-20 17:33 551 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109E60090400000000000F01FEC
2009-03-20 17:33 539 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0E23E40C6140D434FA9B96967D309AFE
2009-03-20 17:33 537 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_000021091A0090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0B79C053C7D38EE4AB9A00CB3B5D2472
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_060135C6BF4869F4F83392FD206023BE
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F100C0400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F100A0C00000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F10090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109C20090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109B10090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109AB0090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109A10090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109910090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109810090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109711090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109610090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109511090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109510090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109411090400000000000F01FEC
2009-03-20 17:33 522 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109010090400000000000F01FEC
2009-03-20 17:33 51 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_000021091A0090400000000000F01FEC.dll
2009-03-20 17:33 37 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109AB0090400000000000F01FEC.dll
2009-03-20 17:33 3653 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_060135C6BF4869F4F83392FD206023BE.dll
2009-03-20 17:33 254 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0DEF1459F7230FD4B869FE75FE26F291.dll
2009-03-20 17:33 1861 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109030000000000000000F01FEC
2009-03-20 17:33 180 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109A10090400000000000F01FEC.dll
2009-03-20 17:33 176 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F100A0C00000000000F01FEC.dll
2009-03-20 17:33 160 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F100C0400000000000F01FEC.dll
2009-03-20 17:33 152 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0E23E40C6140D434FA9B96967D309AFE.dll
2009-03-20 17:33 1509 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109440090400000000000F01FEC.dll
2009-03-20 17:33 1423 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00006FCA9B229EC4896DC2FC53B9CA70.dll
2009-03-20 17:33 142 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109F10090400000000000F01FEC.dll
2009-03-20 17:33 13708 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109030000000000000000F01FEC.dll
2009-03-20 17:33 1115 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109E60090400000000000F01FEC.dll
2009-03-20 17:33 108 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_0B79C053C7D38EE4AB9A00CB3B5D2472.dll
2009-03-20 17:33 108 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109810090400000000000F01FEC.dll
2009-03-20 17:33 108 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109010090400000000000F01FEC.dll
2009-03-20 17:33 107 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109510090400000000000F01FEC.dll
2009-03-20 17:33 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109C20090400000000000F01FEC.dll
2009-03-20 17:33 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109711090400000000000F01FEC.dll
2009-03-20 17:33 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109511090400000000000F01FEC.dll
2009-03-20 17:33 10 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\icn_00002109411090400000000000F01FEC.dll
2008-04-13 19:11 706048 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\_enviewlist.dll
2008-04-13 19:11 617472 --a--c--- c:\documents and settings\All Users\Application Data\SecTaskMan\_entreelist.dll
((((((((((((((((((((((((((((( SnapShot@2009-03-24_18.23.19.95 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-21 01:02:28 163,328 -c--a-w c:\windows\ERDNT\subs\ERDNT.EXE
+ 2006-10-17 18:01:08 71,680 -c--a-w c:\windows\ie8\admparse.dll
+ 2008-12-20 23:15:11 124,928 -c--a-w c:\windows\ie8\advpack.dll
+ 2008-04-14 00:11:51 35,328 -c--a-w c:\windows\ie8\corpol.dll
+ 2008-12-20 23:15:12 347,136 -c--a-w c:\windows\ie8\dxtmsft.dll
+ 2008-12-20 23:15:13 214,528 -c--a-w c:\windows\ie8\dxtrans.dll
+ 2006-10-17 17:44:36 60,416 -c--a-w c:\windows\ie8\hmmapi.dll
+ 2008-12-20 23:15:13 63,488 -c--a-w c:\windows\ie8\icardie.dll
+ 2008-12-19 09:10:15 70,656 -c--a-w c:\windows\ie8\ie4uinit.exe
+ 2008-12-20 23:15:14 153,088 -c--a-w c:\windows\ie8\ieakeng.dll
+ 2008-12-20 23:15:14 230,400 -c--a-w c:\windows\ie8\ieaksie.dll
+ 2008-12-19 05:23:56 161,792 -c--a-w c:\windows\ie8\ieakui.dll
+ 2007-04-17 09:28:12 2,455,488 -c--a-w c:\windows\ie8\ieapfltr.dat
+ 2008-12-20 23:15:15 383,488 -c--a-w c:\windows\ie8\ieapfltr.dll
+ 2008-12-20 23:15:16 384,512 -c--a-w c:\windows\ie8\iedkcs32.dll
+ 2008-04-14 00:11:54 81,920 -c--a-w c:\windows\ie8\ieencode.dll
+ 2008-04-14 00:11:54 81,920 -c--a-w c:\windows\ie8\ieencode.dll.000
+ 2008-12-20 23:15:21 6,066,688 -c--a-w c:\windows\ie8\ieframe.dll
+ 2006-10-17 18:33:40 191,488 -c--a-w c:\windows\ie8\iepeers.dll
+ 2006-10-17 18:33:40 287,744 -c--a-w c:\windows\ie8\ieproxy.dll
+ 2008-12-20 23:15:21 44,544 -c--a-w c:\windows\ie8\iernonce.dll
+ 2008-12-20 23:15:22 267,776 -c--a-w c:\windows\ie8\iertutil.dll
+ 2006-10-17 18:01:06 55,296 -c--a-w c:\windows\ie8\iesetup.dll
+ 2006-10-17 18:33:40 180,736 -c--a-w c:\windows\ie8\ieui.dll
+ 2008-12-19 05:25:25 634,024 -c--a-w c:\windows\ie8\iexplore.exe
+ 2006-10-17 17:57:58 36,352 -c--a-w c:\windows\ie8\imgutil.dll
+ 2006-10-17 18:00:54 92,672 -c--a-w c:\windows\ie8\inseng.dll
+ 2008-05-09 10:53:39 512,000 -c--a-w c:\windows\ie8\jscript.dll
+ 2008-12-20 23:15:23 27,648 -c--a-w c:\windows\ie8\jsproxy.dll
+ 2006-10-17 18:05:10 40,960 -c--a-w c:\windows\ie8\licmgr10.dll
+ 2008-12-20 23:15:23 459,264 -c--a-w c:\windows\ie8\msfeeds.dll
+ 2008-12-20 23:15:24 52,224 -c--a-w c:\windows\ie8\msfeedsbs.dll
+ 2006-10-17 17:58:32 12,288 -c--a-w c:\windows\ie8\msfeedssync.exe
+ 2006-10-17 17:56:10 45,568 -c--a-w c:\windows\ie8\mshta.exe
+ 2009-01-17 03:35:14 3,594,752 -c--a-w c:\windows\ie8\mshtml.dll
+ 2008-12-20 23:15:30 477,696 -c--a-w c:\windows\ie8\mshtmled.dll
+ 2006-10-17 17:28:56 48,128 -c--a-w c:\windows\ie8\mshtmler.dll
+ 2006-10-17 18:33:40 156,160 -c--a-w c:\windows\ie8\msls31.dll
+ 2008-12-20 23:15:31 193,024 -c--a-w c:\windows\ie8\msrating.dll
+ 2008-12-20 23:15:32 671,232 -c--a-w c:\windows\ie8\mstime.dll
+ 2008-12-20 23:15:38 102,912 -c--a-w c:\windows\ie8\occache.dll
+ 2008-12-20 23:15:38 44,544 -c--a-w c:\windows\ie8\pngfilt.dll
+ 2006-09-06 22:43:16 213,216 -c--a-w c:\windows\ie8\spuninst.exe
+ 2009-03-08 19:23:50 58,464 -c--a-w c:\windows\ie8\spuninst\iecustom.dll
+ 2009-01-07 23:20:58 231,456 -c--a-w c:\windows\ie8\spuninst\spuninst.exe
+ 2009-01-07 23:21:02 382,496 -c--a-w c:\windows\ie8\spuninst\updspapi.dll
+ 2008-12-20 23:15:39 105,984 -c--a-w c:\windows\ie8\url.dll
+ 2008-12-20 23:15:40 1,160,192 -c--a-w c:\windows\ie8\urlmon.dll
+ 2008-05-09 10:53:40 430,080 -c--a-w c:\windows\ie8\vbscript.dll
+ 2007-07-12 23:31:54 765,952 -c--a-w c:\windows\ie8\vgx.dll
+ 2008-12-20 23:15:40 233,472 -c--a-w c:\windows\ie8\webcheck.dll
+ 2006-10-17 18:05:58 206,336 -c--a-w c:\windows\ie8\winfxdocobj.exe
+ 2008-12-20 23:15:41 826,368 -c--a-w c:\windows\ie8\wininet.dll
+ 2009-03-08 09:35:04 2,048 -c----w c:\windows\ie8updates\KB968220-IE8\iecompat.dll
+ 2007-11-30 12:39:22 231,288 -c----w c:\windows\ie8updates\KB968220-IE8\spuninst\spuninst.exe
+ 2007-11-30 12:39:22 382,840 -c----w c:\windows\ie8updates\KB968220-IE8\spuninst\updspapi.dll
- 2006-10-17 18:01:08 71,680 -c--a-w c:\windows\system32\admparse.dll
+ 2009-03-08 09:32:56 72,704 -c--a-w c:\windows\system32\admparse.dll
- 2008-12-20 23:15:11 124,928 -c--a-w c:\windows\system32\advpack.dll
+ 2009-03-08 09:32:48 128,512 -c--a-w c:\windows\system32\advpack.dll
- 2009-03-24 23:04:49 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2009-03-30 00:15:48 16,384 -c--a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2009-03-24 23:04:49 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2009-03-30 00:15:48 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2009-03-24 23:04:49 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2009-03-30 00:15:48 32,768 -c--a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-14 00:11:51 35,328 -c--a-w c:\windows\system32\corpol.dll
+ 2009-03-08 09:33:40 18,944 -c--a-w c:\windows\system32\corpol.dll
- 2006-10-17 18:01:08 71,680 -c--a-w c:\windows\system32\dllcache\admparse.dll
+ 2009-03-08 09:32:56 72,704 -c--a-w c:\windows\system32\dllcache\admparse.dll
- 2008-12-20 23:15:11 124,928 -c--a-w c:\windows\system32\dllcache\advpack.dll
+ 2009-03-08 09:32:48 128,512 -c--a-w c:\windows\system32\dllcache\advpack.dll
+ 2009-01-07 23:20:52 1,022,976 -c----w c:\windows\system32\dllcache\browseui.dll
- 2008-04-14 00:11:51 35,328 -c--a-w c:\windows\system32\dllcache\corpol.dll
+ 2009-03-08 09:33:40 18,944 -c--a-w c:\windows\system32\dllcache\corpol.dll
- 2008-12-20 23:15:12 347,136 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
+ 2009-03-08 09:31:44 348,160 -c--a-w c:\windows\system32\dllcache\dxtmsft.dll
- 2008-12-20 23:15:13 214,528 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
+ 2009-03-08 09:31:38 216,064 -c--a-w c:\windows\system32\dllcache\dxtrans.dll
- 2006-10-17 17:44:36 60,416 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
+ 2009-03-08 09:24:28 68,608 -c--a-w c:\windows\system32\dllcache\hmmapi.dll
- 2008-12-20 23:15:13 63,488 -c--a-w c:\windows\system32\dllcache\icardie.dll
+ 2009-03-08 09:31:52 59,904 -c--a-w c:\windows\system32\dllcache\icardie.dll
- 2008-12-19 09:10:15 70,656 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
+ 2009-03-08 09:32:54 173,056 -c--a-w c:\windows\system32\dllcache\ie4uinit.exe
- 2008-12-20 23:15:14 153,088 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
+ 2009-03-08 09:33:02 125,952 -c--a-w c:\windows\system32\dllcache\ieakeng.dll
- 2008-12-20 23:15:14 230,400 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
+ 2009-03-08 09:33:08 229,376 -c--a-w c:\windows\system32\dllcache\ieaksie.dll
- 2008-12-19 05:23:56 161,792 -c--a-w c:\windows\system32\dllcache\ieakui.dll
+ 2009-03-08 09:32:52 163,840 -c--a-w c:\windows\system32\dllcache\ieakui.dll
- 2007-04-17 09:28:12 2,455,488 -c--a-w c:\windows\system32\dllcache\ieapfltr.dat
+ 2009-02-07 02:07:58 3,698,584 -c--a-w c:\windows\system32\dllcache\ieapfltr.dat
- 2008-12-20 23:15:15 383,488 -c--a-w c:\windows\system32\dllcache\ieapfltr.dll
+ 2009-03-08 09:11:12 445,952 -c--a-w c:\windows\system32\dllcache\ieapfltr.dll
- 2008-12-20 23:15:16 384,512 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
+ 2009-03-08 19:09:26 391,536 -c--a-w c:\windows\system32\dllcache\iedkcs32.dll
- 2008-12-20 23:15:21 6,066,688 -c--a-w c:\windows\system32\dllcache\ieframe.dll
+ 2009-03-08 09:39:48 11,063,808 -c--a-w c:\windows\system32\dllcache\ieframe.dll
- 2006-10-17 18:33:40 191,488 -c--a-w c:\windows\system32\dllcache\iepeers.dll
+ 2009-03-08 09:31:56 183,808 -c--a-w c:\windows\system32\dllcache\iepeers.dll
- 2008-12-20 23:15:21 44,544 -c--a-w c:\windows\system32\dllcache\iernonce.dll
+ 2009-03-08 09:32:50 55,808 -c--a-w c:\windows\system32\dllcache\iernonce.dll
- 2008-12-20 23:15:22 267,776 -c--a-w c:\windows\system32\dllcache\iertutil.dll
+ 2009-03-08 09:32:22 1,985,024 -c--a-w c:\windows\system32\dllcache\iertutil.dll
- 2006-10-17 18:01:06 55,296 -c--a-w c:\windows\system32\dllcache\iesetup.dll
+ 2009-03-08 09:32:50 71,680 -c--a-w c:\windows\system32\dllcache\iesetup.dll
- 2008-12-19 05:25:25 634,024 -c--a-w c:\windows\system32\dllcache\iexplore.exe
+ 2009-03-08 19:09:26 638,816 -c--a-w c:\windows\system32\dllcache\iexplore.exe
- 2006-10-17 17:57:58 36,352 -c--a-w c:\windows\system32\dllcache\imgutil.dll
+ 2009-03-08 09:31:38 34,816 -c--a-w c:\windows\system32\dllcache\imgutil.dll
- 2006-10-17 18:00:54 92,672 -c--a-w c:\windows\system32\dllcache\inseng.dll
+ 2009-03-08 09:32:46 94,720 -c--a-w c:\windows\system32\dllcache\inseng.dll
- 2008-05-09 10:53:39 512,000 -c--a-w c:\windows\system32\dllcache\jscript.dll
+ 2009-03-08 09:33:16 726,528 -c--a-w c:\windows\system32\dllcache\jscript.dll
- 2008-12-20 23:15:23 27,648 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
+ 2009-03-08 09:33:26 25,600 -c--a-w c:\windows\system32\dllcache\jsproxy.dll
- 2006-10-17 18:05:10 40,960 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
+ 2009-03-08 09:34:30 43,008 -c--a-w c:\windows\system32\dllcache\licmgr10.dll
- 2008-12-20 23:15:23 459,264 -c--a-w c:\windows\system32\dllcache\msfeeds.dll
+ 2009-03-08 09:32:26 594,432 -c--a-w c:\windows\system32\dllcache\msfeeds.dll
- 2008-12-20 23:15:24 52,224 -c--a-w c:\windows\system32\dllcache\msfeedsbs.dll
+ 2009-03-08 09:31:52 55,296 -c--a-w c:\windows\system32\dllcache\msfeedsbs.dll
- 2006-10-17 17:56:10 45,568 -c--a-w c:\windows\system32\dllcache\mshta.exe
+ 2009-03-08 09:31:02 45,568 -c--a-w c:\windows\system32\dllcache\mshta.exe
- 2009-01-17 03:35:14 3,594,752 -c--a-w c:\windows\system32\dllcache\mshtml.dll
+ 2009-03-08 09:41:16 5,937,152 -c--a-w c:\windows\system32\dllcache\mshtml.dll
- 2008-12-20 23:15:30 477,696 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
+ 2009-03-08 09:31:26 66,560 -c--a-w c:\windows\system32\dllcache\mshtmled.dll
- 2006-10-17 17:28:56 48,128 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
+ 2009-03-08 09:31:18 48,128 -c--a-w c:\windows\system32\dllcache\mshtmler.dll
- 2006-10-17 18:33:40 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll
+ 2009-03-08 09:22:38 156,160 -c--a-w c:\windows\system32\dllcache\msls31.dll
- 2008-12-20 23:15:31 193,024 -c--a-w c:\windows\system32\dllcache\msrating.dll
+ 2009-03-08 09:34:18 193,536 -c--a-w c:\windows\system32\dllcache\msrating.dll
- 2008-12-20 23:15:32 671,232 -c--a-w c:\windows\system32\dllcache\mstime.dll
+ 2009-03-08 09:32:04 611,840 -c--a-w c:\windows\system32\dllcache\mstime.dll
- 2008-12-20 23:15:38 102,912 -c--a-w c:\windows\system32\dllcache\occache.dll
+ 2009-03-08 09:34:18 109,568 -c--a-w c:\windows\system32\dllcache\occache.dll
- 2008-12-20 23:15:38 44,544 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
+ 2009-03-08 09:31:36 46,592 -c--a-w c:\windows\system32\dllcache\pngfilt.dll
- 2008-04-13 19:19:41 146,048 -c--a-w c:\windows\system32\dllcache\portcls.sys
+ 2008-04-13 19:19:42 146,048 -c--a-w c:\windows\system32\dllcache\portcls.sys
+ 2009-01-07 23:20:52 1,497,088 -c----w c:\windows\system32\dllcache\shdocvw.dll
+ 2009-01-07 23:20:52 474,112 -c----w c:\windows\system32\dllcache\shlwapi.dll
+ 2009-01-07 23:20:54 134,144 -c----w c:\windows\system32\dllcache\sqmapi.dll
- 2008-04-13 18:45:15 49,408 -c--a-w c:\windows\system32\dllcache\stream.sys
+ 2008-04-13 18:45:16 49,408 -c--a-w c:\windows\system32\dllcache\stream.sys
- 2008-12-20 23:15:39 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
+ 2009-03-08 09:34:28 105,984 -c--a-w c:\windows\system32\dllcache\url.dll
- 2008-12-20 23:15:40 1,160,192 -c--a-w c:\windows\system32\dllcache\urlmon.dll
+ 2009-03-08 09:34:56 1,206,784 -c--a-w c:\windows\system32\dllcache\urlmon.dll
- 2008-05-09 10:53:40 430,080 -c--a-w c:\windows\system32\dllcache\vbscript.dll
+ 2009-03-08 09:33:06 420,352 -c--a-w c:\windows\system32\dllcache\vbscript.dll
- 2007-07-12 23:31:54 765,952 -c--a-w c:\windows\system32\dllcache\vgx.dll
+ 2009-03-08 09:33:48 759,296 -c--a-w c:\windows\system32\dllcache\VGX.dll
- 2008-12-20 23:15:40 233,472 -c--a-w c:\windows\system32\dllcache\webcheck.dll
+ 2009-03-08 09:34:48 236,544 -c--a-w c:\windows\system32\dllcache\webcheck.dll
- 2008-12-20 23:15:41 826,368 -c--a-w c:\windows\system32\dllcache\wininet.dll
+ 2009-03-08 09:34:58 914,944 -c--a-w c:\windows\system32\dllcache\wininet.dll
- 2008-04-13 19:19:41 146,048 -c--a-w c:\windows\system32\drivers\portcls.sys
+ 2008-04-13 19:19:42 146,048 -c--a-w c:\windows\system32\drivers\portcls.sys
- 2003-07-18 00:19:32 230,416 -c--a-w c:\windows\system32\drivers\stac97.sys
+ 2003-07-17 22:19:32 230,416 -c--a-w c:\windows\system32\drivers\stac97.sys
- 2008-04-13 18:45:15 49,408 -c--a-w c:\windows\system32\drivers\stream.sys
+ 2008-04-13 18:45:16 49,408 -c--a-w c:\windows\system32\drivers\stream.sys
- 2008-12-20 23:15:12 347,136 -c--a-w c:\windows\system32\dxtmsft.dll
+ 2009-03-08 09:31:44 348,160 -c--a-w c:\windows\system32\dxtmsft.dll
- 2008-12-20 23:15:13 214,528 -c--a-w c:\windows\system32\dxtrans.dll
+ 2009-03-08 09:31:38 216,064 -c--a-w c:\windows\system32\dxtrans.dll
- 2008-12-20 23:15:13 63,488 -c--a-w c:\windows\system32\icardie.dll
+ 2009-03-08 09:31:52 59,904 -c--a-w c:\windows\system32\icardie.dll
- 2008-01-11 16:35:16 26,112 -c--a-w c:\windows\system32\idndl.dll
+ 2009-01-07 23:20:36 26,112 -c--a-w c:\windows\system32\idndl.dll
- 2008-12-19 09:10:15 70,656 -c--a-w c:\windows\system32\ie4uinit.exe
+ 2009-03-08 09:32:54 173,056 -c--a-w c:\windows\system32\ie4uinit.exe
- 2008-12-20 23:15:14 153,088 -c--a-w c:\windows\system32\ieakeng.dll
+ 2009-03-08 09:33:02 125,952 -c--a-w c:\windows\system32\ieakeng.dll
- 2008-12-20 23:15:14 230,400 -c--a-w c:\windows\system32\ieaksie.dll
+ 2009-03-08 09:33:08 229,376 -c--a-w c:\windows\system32\ieaksie.dll
- 2008-12-19 05:23:56 161,792 -c--a-w c:\windows\system32\ieakui.dll
+ 2009-03-08 09:32:52 163,840 -c--a-w c:\windows\system32\ieakui.dll
- 2007-04-17 09:28:12 2,455,488 -c--a-w c:\windows\system32\ieapfltr.dat
+ 2009-02-07 02:07:58 3,698,584 -c--a-w c:\windows\system32\ieapfltr.dat
- 2008-12-20 23:15:15 383,488 -c--a-w c:\windows\system32\ieapfltr.dll
+ 2009-03-08 09:11:12 445,952 -c--a-w c:\windows\system32\ieapfltr.dll
- 2008-12-20 23:15:16 384,512 -c--a-w c:\windows\system32\iedkcs32.dll
+ 2009-03-08 19:09:26 391,536 -c--a-w c:\windows\system32\iedkcs32.dll
- 2008-12-20 23:15:21 6,066,688 -c--a-w c:\windows\system32\ieframe.dll
+ 2009-03-08 09:39:48 11,063,808 -c--a-w c:\windows\system32\ieframe.dll
- 2006-10-17 18:33:40 191,488 -c--a-w c:\windows\system32\iepeers.dll
+ 2009-03-08 09:31:56 183,808 -c--a-w c:\windows\system32\iepeers.dll
- 2008-12-20 23:15:21 44,544 -c--a-w c:\windows\system32\iernonce.dll
+ 2009-03-08 09:32:50 55,808 -c--a-w c:\windows\system32\iernonce.dll
- 2008-12-20 23:15:22 267,776 -c--a-w c:\windows\system32\iertutil.dll
+ 2009-03-08 09:32:22 1,985,024 -c--a-w c:\windows\system32\iertutil.dll
- 2006-10-17 18:01:06 55,296 -c--a-w c:\windows\system32\iesetup.dll
+ 2009-03-08 09:32:50 71,680 -c--a-w c:\windows\system32\iesetup.dll
- 2008-03-04 00:51:46 36,864 -c--a-w c:\windows\system32\ieudinit.exe
+ 2009-03-08 09:32:52 36,864 -c--a-w c:\windows\system32\ieudinit.exe
- 2006-10-17 18:33:40 180,736 -c--a-w c:\windows\system32\ieui.dll
+ 2009-03-08 09:22:46 164,352 -c--a-w c:\windows\system32\ieui.dll
- 2006-10-17 17:57:58 36,352 -c--a-w c:\windows\system32\imgutil.dll
+ 2009-03-08 09:31:38 34,816 -c--a-w c:\windows\system32\imgutil.dll
- 2006-10-17 18:00:54 92,672 -c--a-w c:\windows\system32\inseng.dll
+ 2009-03-08 09:32:46 94,720 -c--a-w c:\windows\system32\inseng.dll
+ 2009-03-24 23:37:09 144,792 -c--a-w c:\windows\system32\java.exe
+ 2009-03-24 23:37:10 144,792 -c--a-w c:\windows\system32\javaw.exe
+ 2009-03-24 23:37:10 148,888 -c--a-w c:\windows\system32\javaws.exe
- 2008-05-09 10:53:39 512,000 -c--a-w c:\windows\system32\jscript.dll
+ 2009-03-08 09:33:16 726,528 -c--a-w c:\windows\system32\jscript.dll
- 2008-12-20 23:15:23 27,648 -c--a-w c:\windows\system32\jsproxy.dll
+ 2009-03-08 09:33:26 25,600 -c--a-w c:\windows\system32\jsproxy.dll
- 2006-10-17 18:05:10 40,960 -c--a-w c:\windows\system32\licmgr10.dll
+ 2009-03-08 09:34:30 43,008 -c--a-w c:\windows\system32\licmgr10.dll
+ 2009-02-03 02:07:18 240,544 -c--a-r c:\windows\system32\Macromed\Flash\FlashUtil10b.exe
- 2008-11-27 18:39:15 89,102 -c--a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
+ 2009-03-27 01:34:09 89,102 -c--a-w c:\windows\system32\Macromed\Flash\uninstall_activeX.exe
- 2008-05-29 23:35:12 17,486,968 -c--a-w c:\windows\system32\MRT.exe
+ 2009-02-25 17:55:00 24,768,960 -c--a-w c:\windows\system32\MRT.exe
+ 2009-01-07 23:20:18 265,720 -c--a-w c:\windows\system32\msdbg2.dll
- 2008-12-20 23:15:23 459,264 -c--a-w c:\windows\system32\msfeeds.dll
+ 2009-03-08 09:32:26 594,432 -c--a-w c:\windows\system32\msfeeds.dll
- 2008-12-20 23:15:24 52,224 -c--a-w c:\windows\system32\msfeedsbs.dll
+ 2009-03-08 09:31:52 55,296 -c--a-w c:\windows\system32\msfeedsbs.dll
- 2006-10-17 17:58:32 12,288 -c--a-w c:\windows\system32\msfeedssync.exe
+ 2009-03-08 09:31:54 13,312 -c--a-w c:\windows\system32\msfeedssync.exe
- 2006-10-17 17:56:10 45,568 -c--a-w c:\windows\system32\mshta.exe
+ 2009-03-08 09:31:02 45,568 -c--a-w c:\windows\system32\mshta.exe
- 2009-01-17 03:35:14 3,594,752 -c--a-w c:\windows\system32\mshtml.dll
+ 2009-03-08 09:41:16 5,937,152 -c--a-w c:\windows\system32\mshtml.dll
- 2008-12-20 23:15:30 477,696 -c--a-w c:\windows\system32\mshtmled.dll
+ 2009-03-08 09:31:26 66,560 -c--a-w c:\windows\system32\mshtmled.dll
- 2006-10-17 17:28:56 48,128 -c--a-w c:\windows\system32\mshtmler.dll
+ 2009-03-08 09:31:18 48,128 -c--a-w c:\windows\system32\mshtmler.dll
- 2006-10-17 18:33:40 156,160 ----a-w c:\windows\system32\msls31.dll
+ 2009-03-08 09:22:38 156,160 -c--a-w c:\windows\system32\msls31.dll
- 2008-12-20 23:15:31 193,024 -c--a-w c:\windows\system32\msrating.dll
+ 2009-03-08 09:34:18 193,536 -c--a-w c:\windows\system32\msrating.dll
- 2008-12-20 23:15:32 671,232 -c--a-w c:\windows\system32\mstime.dll
+ 2009-03-08 09:32:04 611,840 -c--a-w c:\windows\system32\mstime.dll
- 2008-01-11 16:35:16 24,576 -c--a-w c:\windows\system32\nlsdl.dll
+ 2009-01-07 23:20:38 24,576 -c--a-w c:\windows\system32\nlsdl.dll
- 2008-01-11 16:35:16 23,552 ----a-w c:\windows\system32\normaliz.dll
+ 2009-01-07 23:20:36 23,552 -c--a-w c:\windows\system32\normaliz.dll
- 2008-12-20 23:15:38 102,912 -c--a-w c:\windows\system32\occache.dll
+ 2009-03-08 09:34:18 109,568 -c--a-w c:\windows\system32\occache.dll
- 2008-12-20 23:15:38 44,544 -c--a-w c:\windows\system32\pngfilt.dll
+ 2009-03-08 09:31:36 46,592 -c--a-w c:\windows\system32\pngfilt.dll
+ 2008-04-13 18:45:14 60,160 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\drmk.sys
+ 2008-04-13 19:16:36 141,056 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\ks.sys
+ 2008-04-14 00:11:56 4,096 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\ksuser.dll
+ 2008-04-13 19:19:41 146,048 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\portcls.sys
+ 2008-04-13 18:45:15 49,408 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\stream.sys
+ 2008-04-14 00:12:45 23,552 -c--a-w c:\windows\system32\ReinstallBackups\
0001\DriverFiles\i386\wdmaud.drv
- 2007-11-30 11:18:51 17,272 -c----w c:\windows\system32\spmsg.dll
+ 2009-01-07 23:20:58 16,928 -c----w c:\windows\system32\spmsg.dll
- 2007-08-11 01:46:18 26,488 -c--a-w c:\windows\system32\spupdsvc.exe
+ 2009-01-07 23:21:00 26,144 -c--a-w c:\windows\system32\spupdsvc.exe
- 2008-12-20 23:15:39 105,984 -c--a-w c:\windows\system32\url.dll
+ 2009-03-08 09:34:28 105,984 -c--a-w c:\windows\system32\url.dll
- 2008-12-20 23:15:40 1,160,192 -c--a-w c:\windows\system32\urlmon.dll
+ 2009-03-08 09:34:56 1,206,784 -c--a-w c:\windows\system32\urlmon.dll
- 2008-05-09 10:53:40 430,080 -c--a-w c:\windows\system32\vbscript.dll
+ 2009-03-08 09:33:06 420,352 -c--a-w c:\windows\system32\vbscript.dll
- 2008-12-20 23:15:40 233,472 -c--a-w c:\windows\system32\webcheck.dll
+ 2009-03-08 09:34:48 236,544 -c--a-w c:\windows\system32\webcheck.dll
- 2006-10-17 18:05:58 206,336 -c--a-w c:\windows\system32\winfxdocobj.exe
+ 2009-03-08 09:34:48 208,384 -c--a-w c:\windows\system32\WinFXDocObj.exe
- 2008-12-20 23:15:41 826,368 -c--a-w c:\windows\system32\wininet.dll
+ 2009-03-08 09:34:58 914,944 -c--a-w c:\windows\system32\wininet.dll
- 2008-04-14 00:12:11 121,856 -c--a-w c:\windows\system32\xmllite.dll
+ 2009-01-07 23:21:04 121,856 -c--a-w c:\windows\system32\xmllite.dll
+ 2009-03-30 00:15:31 16,384 -c--atw c:\windows\Temp\Perflib_Perfdata_554.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TOSCDSPD"="c:\program files\TOSHIBA\TOSCDSPD\toscdspd.exe" [2003-09-05 65536]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-02-13 486856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-02 68856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Google Update"="c:\documents and settings\Kevin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-03-14 133104]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\3f433860-24d7-4b8a-a13a-28ad996250b3.exe" [2009-02-17 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"00THotkey"="c:\windows\system32\
00THotkey.exe" [2004-06-28 19:24 258048]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2003-10-30 192512]
"SigmaTel StacMon"="c:\program files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe" [2003-08-03 86073]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2003-09-26 184320]
"PadTouch"="c:\program files\TOSHIBA\Touch and Launch\PadExe.exe" [2004-02-03 1089589]
"SmoothView"="c:\program files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe" [2004-03-02 135168]
"TouchED"="c:\program files\TOSHIBA\TouchED\TouchED.Exe" [2003-01-21 126976]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2004-07-20 122939]
"Pinger"="c:\toshiba\ivp\ism\pinger.exe" [2005-03-17 151552]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" [2005-06-06 57344]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-09-24 185632]
"PrinTray"="c:\windows\System32\spool\DRIVERS\W32X86\3\printray.exe" [2002-03-29 36864]
"LXCICATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCItime.dll" [2006-11-21 106496]
"lxcimon.exe"="c:\program files\Lexmark 7300 Series\lxcimon.exe" [2007-02-01 205744]
"EzPrint"="c:\program files\Lexmark 7300 Series\ezprint.exe" [2007-02-01 103344]
"WrtMon.exe"="c:\windows\system32\spool\drivers\w32x86\3\WrtMon.exe" [2006-09-20 20480]
"Symantec PIF AlertEng"="c:\program files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2007-11-28 583048]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-03-28 413696]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2006-07-19 52896]
"vptray"="c:\progra~1\Symantec Client Security\Symantec AntiVirus\\vptray.exe" [2006-09-27 125168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2006-02-07 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2006-02-07 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2006-02-07 118784]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"googletalk"="c:\program files\Google\Google Talk\googletalk.exe" [2007-01-01 3739648]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-11-10 136512]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-24 148888]
"000StTHK"="000StTHK.exe" [2001-06-23 22:28 24576 c:\windows\system32\
000StTHK.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-02-20 c:\windows\agrsmmsg.exe]
"TFNF5"="TFNF5.exe" [2003-12-02 c:\windows\system32\TFNF5.exe]
"TPSMain"="TPSMain.exe" [2004-06-01 c:\windows\system32\TPSMain.exe]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-08-24 437160]
c:\documents and settings\Kevin\Start Menu\Programs\Startup\
Google Talk, Labs Edition.lnk - c:\documents and settings\Kevin\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe [2008-06-24 94704]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoResolveTrack"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Real\\RealPlayer\\realplay.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\lxcipswx.exe"=
"c:\\WINDOWS\\system32\\lxcicoms.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\WINDOWS\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"=
"c:\\TOSHIBA\\IVP\\ISM\\pinger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"c:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"c:\nexon\Combat Arms\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\nexon\Combat Arms\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
"c:\\Nexon\\Combat Arms\\NMService.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Documents and Settings\\Kevin\\Local Settings\\Application Data\\Google\\Google Talk, Labs Edition\\GoogleTalkLabsEdition.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"135:TCP"= 135:TCP:*:Disabled:TCP Port 135
"5000:TCP"= 5000:TCP:*:Disabled:TCP Port 5000
"5001:TCP"= 5001:TCP:*:Disabled:TCP Port 5001
"5002:TCP"= 5002:TCP:*:Disabled:TCP Port 5002
"5003:TCP"= 5003:TCP:*:Disabled:TCP Port 5003
"5004:TCP"= 5004:TCP:*:Disabled:TCP Port 5004
"5005:TCP"= 5005:TCP:*:Disabled:TCP Port 5005
"5006:TCP"= 5006:TCP:*:Disabled:TCP Port 5006
"5007:TCP"= 5007:TCP:*:Disabled:TCP Port 5007
"5008:TCP"= 5008:TCP:*:Disabled:TCP Port 5008
"5009:TCP"= 5009:TCP:*:Disabled:TCP Port 5009
"5010:TCP"= 5010:TCP:*:Disabled:TCP Port 5010
"5011:TCP"= 5011:TCP:*:Disabled:TCP Port 5011
"5012:TCP"= 5012:TCP:*:Disabled:TCP Port 5012
"5013:TCP"= 5013:TCP:*:Disabled:TCP Port 5013
"5014:TCP"= 5014:TCP:*:Disabled:TCP Port 5014
"5015:TCP"= 5015:TCP:*:Disabled:TCP Port 5015
"5016:TCP"= 5016:TCP:*:Disabled:TCP Port 5016
"5017:TCP"= 5017:TCP:*:Disabled:TCP Port 5017
"5018:TCP"= 5018:TCP:*:Disabled:TCP Port 5018
"5019:TCP"= 5019:TCP:*:Disabled:TCP Port 5019
"5020:TCP"= 5020:TCP:*:Disabled:TCP Port 5020
"3724:TCP"= 3724:TCP:*:Disabled:Blizzard Downloader
"6112:TCP"= 6112:TCP:*:Disabled:Blizzard Downloader
"1723:TCP"= 1723:TCP:*:Disabled:@xpsp2res.dll,-22015
"1701:UDP"= 1701:UDP:*:Disabled:@xpsp2res.dll,-22016
"500:UDP"= 500:UDP:*:Disabled:@xpsp2res.dll,-22017
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 lxci_device;lxci_device;c:\windows\system32\lxcicoms.exe -service --> c:\windows\system32\lxcicoms.exe -service [?]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2008-09-23 210216]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2009-03-06 101936]
R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
S2 gupdate1c99ab2c8cd0c90;Google Update Service (gupdate1c99ab2c8cd0c90);c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 133104]
S3 getPlus® Helper;getPlus® Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2009-01-07 33752]
S3 SavRoam;SAVRoam;c:\program files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2006-09-27 116464]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;c:\program files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2006-12-02 2805000]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-03-28 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2009-03-30 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-23 20:47]
2009-03-30 c:\windows\Tasks\GoogleUpdateTaskMachine.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-03-01 16:14]
2009-03-29 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2089434811-2407156730-932803837-1007.job
- c:\documents and settings\Kevin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-03-14 23:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
Trusted Zone: gonintendo.com
Trusted Zone: gonintendo.com\www
Trusted Zone: microsoft.com\*.update
Trusted Zone: windowsupdate.com\download
DPF: {7606693A-C18D-4567-AF85-6194FF70761E} - hxxp://app.ipop.co.kr/gom/GomWeb.cab
DPF: {87A638DE-396F-40FD-A2F8-01B56072F553} - hxxp://download.gemfighter.com/launcher/gemx2.cab
FF - ProfilePath - c:\documents and settings\Kevin\Application Data\Mozilla\Firefox\Profiles\f0g1wfjg.default\
FF - prefs.js: browser.search.defaulturl - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FF - prefs.js: browser.startup.homepage - www.yahoo.com
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Kevin\Local Settings\Application Data\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Google\Google Updater\2.4.1536.6592\npCIDetect13.dll
FF - plugin: c:\program files\Google\Update\1.2.141.5\npGoogleOneClick7.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - plugin: c:\program files\Unity\WebPlayer\loader\npUnity3D32.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1375 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-29 19:17:14
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCICATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(736)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\acs.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\ccProxy.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
c:\program files\Common Files\Symantec Shared\SNDSrvc.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Lavasoft\Ad-Aware 2007\aawservice.exe
c:\windows\system32\LEXBCES.EXE
c:\windows\system32\LEXPPS.EXE
c:\windows\system32\drivers\CDAC11BA.EXE
c:\program files\Toshiba\ConfigFree\CFSvcs.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\lxcicoms.exe
c:\program files\McAfee\Common Framework\FrameworkService.exe
c:\program files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
c:\program files\McAfee\Common Framework\naPrdMgr.exe
c:\program files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
c:\nexon\Mabinogi\npkcmsvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\toshiba\IVP\swupdate\swupdtmr.exe
c:\program files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
c:\program files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\TPSBattM.exe
c:\windows\system32\spool\drivers\w32x86\3\WrtProc.exe
c:\program files\Apoint2K\ApntEx.exe
c:\program files\McAfee\Common Framework\McTray.exe
c:\windows\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2009-03-29 19:22:20 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-30 00:22:15
ComboFix2.txt 2009-03-24 23:25:45
Pre-Run: 11,616,247,808 bytes free
Post-Run: 11,589,689,344 bytes free
780
Kapersky:
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
Monday, March 30, 2009
Operating System: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner 7 version: 7.0.25.0
Program database last update: Monday, March 30, 2009 23:44:34
Records in database: 1988079
--------------------------------------------------------------------------------
Scan settings:
Scan using the following database: extended
Scan archives: yes
Scan mail databases: yes
Scan area - My Computer:
C:\
D:\
Scan statistics:
Files scanned: 120267
Threat name: 1
Infected objects: 1
Suspicious objects: 0
Duration of the scan: 03:35:38
File name / Threat name / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\system32\drivers\gaopdxfoxktpqyoduyruotbffwvkowwhhsjlkn.sys.vir Infected: Trojan.Win32.Tdss.szg 1
The selected area was scanned.
HJT:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:39:22 PM, on 3/30/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ACS.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\system32\drivers\CDAC11BA.EXE
C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxcicoms.exe
C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
C:\Program Files\McAfee\Common Framework\FrameworkService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Nexon\Mabinogi\npkcmsvc.exe
C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\00THotkey.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\TFNF5.exe
C:\WINDOWS\system32\TPSMain.exe
C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\system32\TPSBattM.exe
C:\Program Files\Lexmark 7300 Series\lxcimon.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
C:\Program Files\QuickTime\QTTask.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtProc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\McAfee\Common Framework\udaterui.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Kevin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\McAfee\Common Framework\McTray.exe
C:\Program Files\SUPERAntiSpyware\3f433860-24d7-4b8a-a13a-28ad996250b3.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_clipbook.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\Google\Google Talk\googletalk.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [00THotkey] C:\WINDOWS\system32\00THotkey.exe
O4 - HKLM\..\Run: [000StTHK] 000StTHK.exe
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SigmaTel StacMon] C:\Program Files\SigmaTel\SigmaTel AC97 Audio Drivers\stacmon.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [TFNF5] TFNF5.exe
O4 - HKLM\..\Run: [TPSMain] TPSMain.exe
O4 - HKLM\..\Run: [PadTouch] C:\Program Files\TOSHIBA\Touch and Launch\PadExe.exe
O4 - HKLM\..\Run: [SmoothView] C:\Program Files\TOSHIBA\TOSHIBA Zooming Utility\SmoothView.exe
O4 - HKLM\..\Run: [TouchED] C:\Program Files\TOSHIBA\TouchED\TouchED.Exe
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Pinger] c:\toshiba\ivp\ism\pinger.exe /run
O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe"
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PrinTray] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\printray.exe
O4 - HKLM\..\Run: [LXCICATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCItime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [lxcimon.exe] "C:\Program Files\Lexmark 7300 Series\lxcimon.exe"
O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7300 Series\ezprint.exe"
O4 - HKLM\..\Run: [WrtMon.exe] C:\WINDOWS\system32\spool\drivers\w32x86\3\WrtMon.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\Symantec Client Security\Symantec AntiVirus\\vptray.exe
O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [googletalk] C:\Program Files\Google\Google Talk\googletalk.exe /autostart
O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Program Files\McAfee\Common Framework\udaterui.exe" /StartedFromRunKey
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Kevin\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\3f433860-24d7-4b8a-a13a-28ad996250b3.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Google Talk, Labs Edition.lnk = C:\Documents and Settings\Kevin\Local Settings\Application Data\Google\Google Talk, Labs Edition\GoogleTalkLabsEdition.exe
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.toshibadirect.com/dpdstart
O15 - Trusted Zone:
http://www.gonintendo.comO15 - Trusted Zone: http://*.gonintendo.com
O15 - Trusted Zone:
http://download.windowsupdate.comO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} -
http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.8.110.cabO16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) -
http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.1.cabO16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} -
http://download.mcafee.com/molbin/shared/m...90/mcinsctl.cabO16 - DPF: {7606693A-C18D-4567-AF85-6194FF70761E} -
http://app.ipop.co.kr/gom/GomWeb.cabO16 - DPF: {87A638DE-396F-40FD-A2F8-01B56072F553} (Launcher Class) -
http://download.gemfighter.com/launcher/gemx2.cabO16 - DPF: {C4925E65-7A1E-11D2-8BB4-00A0C9CC72C3} -
http://a532.g.akamai.net/f/532/6712/4h/pla...0/Installer.exeO16 - DPF: {CF40ACC5-E1BB-4AFF-AC72-04C2F616BCA7} (get_atlcom Class) -
http://wwwimages.adobe.com/www.adobe.com/p...obat/nos/gp.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} -
http://a532.g.akamai.net/f/532/6712/5m/vir...l/installer.exeO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\siteadvisor\mcieplg.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\ACS.exe
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ConfigFree Service (CFSvcs) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: getPlus® Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c99ab2c8cd0c90) (gupdate1c99ab2c8cd0c90) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: IS Service (ISSVC) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\ISSVC.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LiveUpdate\LuComServer_3_1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe
O23 - Service: lxci_device - - C:\WINDOWS\system32\lxcicoms.exe
O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Program Files\McAfee\SiteAdvisor\McSACore.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Program Files\McAfee\Common Framework\FrameworkService.exe
O23 - Service: npkcmsvc - INCA Internet Co., Ltd. - C:\Nexon\Mabinogi\npkcmsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
--
End of file - 16917 bytes