I ran Systweak Antispyware when I got it back (off loan) and got this: c:\windows\system32\devldr32.exe . Systweak will quarantine but won't eliminate the worm. The loanee told me he disabled Systweak AND Kaspersky because they kept trying to block access to the site(s) which obviously invaded this computer.
Deckard's System Scanner v20071014.68
Run by Brian Lowe on 2008-06-04 08:03:07
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
System Restore is disabled; attempting to re-enable...success.
-- Last 1 Restore Point(s) --
1: 2008-06-04 13:03:10 UTC - RP40 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as Brian Lowe.exe) ------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:03:27 AM, on 6/4/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Documents and Settings\Brian Lowe\Desktop\Deckard's System Scanner.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\Brian Lowe.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (file missing)
O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll (file missing)
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.08\RivaTuner.exe" /S
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [RMClock] "C:\Program Files\RMClock\RMClockLauncher.exe"
O4 - HKCU\..\Run: [Systweak AntiSpyware 2008] "C:\Program Files\Systweak AntiSpyware\AntiSpyware.exe" /autorun
O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1211116646937
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
--
End of file - 4084 bytes
-- HijackThis Fixed Entries (C:\PROGRA~1\TRENDM~1\HIJACK~1\backups\) -----------
backup-20080602-153451-142 O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
backup-20080602-153451-349 O2 - BHO: StumbleUpon Launcher - {145B29F4-A56B-4b90-BBAC-45784EBEBBB7} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
backup-20080602-153451-379 O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
backup-20080602-153451-704 O8 - Extra context menu item: StumbleUpon PhotoBlog It! - res://StumbleUponIEBar.dll/blogimage
backup-20080602-153451-882 O3 - Toolbar: StumbleUpon Toolbar - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files\StumbleUpon\StumbleUponIEBar.dll
backup-20080602-153451-984 O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
backup-20080602-153841-416 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
backup-20080602-153841-558 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll (file missing)
backup-20080602-154124-324 O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080602-154124-469 O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
backup-20080602-154124-564 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
backup-20080602-154124-602 O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
backup-20080602-154459-176 O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\SCIEPlgn.dll
backup-20080602-154459-324 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
backup-20080602-154459-700 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
backup-20080602-154802-479 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
backup-20080602-155245-752 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
backup-20080602-161832-136 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search
backup-20080602-161832-219 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
Live Search
backup-20080602-161832-311 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080602-161832-885 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080602-161832-915 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
backup-20080604-053339-167 O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.08\RivaTuner.exe" /S
backup-20080604-053339-228 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/micr...?1211116646937
backup-20080604-053339-249 O4 - HKCU\..\Run: [Systweak AntiSpyware 2008] "C:\Program Files\Systweak AntiSpyware\AntiSpyware.exe" /autorun
backup-20080604-053339-377 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
Live Search:
backup-20080604-053339-409 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080604-053339-413 O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
backup-20080604-053339-419 O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
backup-20080604-053339-427 O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
backup-20080604-053339-587 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
backup-20080604-053339-676 O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe"
backup-20080604-053339-750 O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
backup-20080604-053339-772 R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
Live Search:
backup-20080604-053339-850 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
Live Search:
backup-20080604-053339-857 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
backup-20080604-053339-893 O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\ie_banner_deny.htm
backup-20080604-053339-904 O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
backup-20080604-053339-974 O4 - HKCU\..\Run: [RMClock] "C:\Program Files\RMClock\RMClockLauncher.exe"
backup-20080604-053340-178 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/ge...sh/swflash.cab
backup-20080604-053340-391 O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
backup-20080604-053340-533 O23 - Service: Kaspersky Internet Security 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe
backup-20080604-053340-761 O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
-- File Associations -----------------------------------------------------------
.cpl - cplfile - shell\cplopen\command - rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.cpl - cplfile - shell\runas\command - rundll32.exe shell32.dll,Control_RunDLLAsUser "%1",%*
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R3 RivaTuner32 - c:\program files\rivatuner v2.08\rivatuner32.sys
R3 SASPROT (Systweak AntiSpyware 2008) - c:\program files\systweak antispyware\sasprot.sys
S3 catchme - c:\combofix\catchme.sys (file missing)
S3 ENTECH - c:\windows\system32\drivers\entech.sys <Not Verified; EnTech Taiwan; PowerStrip>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Scheduled Tasks -------------------------------------------------------------
2008-05-31 14:36:49 394 --a------ C:\WINDOWS\Tasks\Systweak AntiSpyware 2008.job
2008-05-31 14:36:49 420 --a------ C:\WINDOWS\Tasks\Systweak AntiSpyware 2008 Update Checker.job
-- Files created between 2008-05-04 and 2008-06-04 -----------------------------
2008-06-04 06:01:07 68096 --a------ C:\WINDOWS\zip.exe
2008-06-04 06:01:07 49152 --a------ C:\WINDOWS\VFind.exe
2008-06-04 06:01:07 212480 --a------ C:\WINDOWS\swxcacls.exe <Not Verified; SteelWerX; SteelWerX Extended Configurator ACLists>
2008-06-04 06:01:07 136704 --a------ C:\WINDOWS\swsc.exe <Not Verified; SteelWerX; SteelWerX Service Controller>
2008-06-04 06:01:07 161792 --a------ C:\WINDOWS\swreg.exe <Not Verified; SteelWerX; SteelWerX Registry Editor>
2008-06-04 06:01:07 80412 --a------ C:\WINDOWS\grep.exe
2008-06-04 06:01:07 89504 --a------ C:\WINDOWS\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-06-04 05:39:24 0 dr-h----- C:\Documents and Settings\Brian Lowe\Recent
2008-06-02 17:53:14 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\DassaultSystemes
2008-06-02 17:52:56 0 d-------- C:\Program Files\Dassault Systemes
2008-06-02 17:49:39 0 d-------- C:\Program Files\Virtual Earth 3D
2008-06-02 15:28:37 229376 --a------ C:\Documents and Settings\LocalService\ntuser.dat
2008-06-02 15:28:37 2260992 --a------ C:\Documents and Settings\Brian Lowe\ntuser.dat
2008-06-02 15:14:59 0 d-------- C:\Program Files\Trend Micro
2008-06-01 16:55:52 0 d-------- C:\WINDOWS\Sun
2008-05-29 19:13:34 0 d-------- C:\Program Files\Advanced System Optimizer
2008-05-28 15:27:03 16 --a------ C:\WINDOWS\popcinfot.dat
2008-05-28 14:32:22 0 d-------- C:\Program Files\Steam
2008-05-28 04:19:07 0 --a------ C:\WINDOWS\ativpsrm.bin
2008-05-28 03:47:17 584 -----n--- C:\WINDOWS\system32\drivers\alcxinit.dat
2008-05-28 03:46:21 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-05-28 03:00:43 0 d-------- C:\Program Files\Lavalys
2008-05-28 03:00:10 4179293 --a------ C:\Program Files\everesthome220.exe <Not Verified; Lavalys, Inc.; >
2008-05-28 02:50:40 0 d-------- C:\Program Files\RivaTuner v2.08
2008-05-28 02:27:36 0 d-------- C:\WINDOWS\system32\Futuremark
2008-05-28 02:27:36 3972 -----n--- C:\WINDOWS\system32\drivers\PciBus.sys
2008-05-28 02:27:36 21664 --a------ C:\WINDOWS\system32\drivers\Entech.sys <Not Verified; EnTech Taiwan; PowerStrip>
2008-05-28 02:27:15 0 d-------- C:\Program Files\Futuremark
2008-05-27 08:32:19 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Malwarebytes
2008-05-27 08:32:15 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-05-27 08:32:15 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-05-21 11:58:11 0 d-------- C:\Program Files\ClockGen_1.0.5.3
2008-05-21 11:54:51 0 d-------- C:\Program Files\PC Wizard 2008
2008-05-21 11:51:09 0 d-------- C:\Program Files\OpenOffice.org 2.3 Installation Files
2008-05-18 15:21:46 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-05-18 15:21:46 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-05-18 15:21:46 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-05-18 15:21:46 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-05-18 15:21:46 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-05-18 15:21:46 524288 --ah----- C:\Documents and Settings\Administrator\ntuser.dat
2008-05-18 15:21:46 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-05-18 15:21:46 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-05-18 15:21:46 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-05-18 15:21:46 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-05-18 15:21:46 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-05-18 15:21:46 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-05-18 15:21:46 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-05-18 15:21:46 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-05-18 13:34:54 0 d-------- C:\Program Files\Windows Media Connect 2
2008-05-18 13:27:36 0 d-------- C:\WINDOWS\system32\URTTemp
2008-05-18 13:20:18 0 d-------- C:\Program Files\CleanCache 3.0
2008-05-18 13:17:35 0 d-------- C:\Program Files\PConPoint
2008-05-18 09:55:33 0 d-------- C:\Program Files\CCleaner
2008-05-18 09:49:00 0 d-------- C:\Program Files\CrystalCPUID414
2008-05-18 09:24:15 561152 -----n--- C:\WINDOWS\system32\MJ12.exe <Not Verified; J. River, Inc.; Media Jukebox>
2008-05-18 09:24:15 53248 -----n--- C:\WINDOWS\system32\BBInstaller.exe <Not Verified; J. River, Inc.; J. River BuyButton Installer>
2008-05-18 09:21:40 0 d-------- C:\WINDOWS\system32\LogFiles
2008-05-18 09:21:40 0 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-05-18 09:20:29 0 d-------- C:\Program Files\J River
2008-05-18 09:20:17 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\J River
2008-05-18 09:02:36 0 d-------- C:\Program Files\RightMark Memory Analyzer
2008-05-18 09:00:28 0 d-------- C:\Program Files\OpenOffice.org 2.3
2008-05-18 08:59:12 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Sun
2008-05-18 08:55:35 0 d-------- C:\WINDOWS\Prefetch
2008-05-18 08:46:41 0 d-------- C:\WINDOWS\system32\scripting
2008-05-18 08:46:41 0 d-------- C:\WINDOWS\l2schemas
2008-05-18 08:46:40 0 d-------- C:\WINDOWS\system32\en
2008-05-18 08:46:40 0 d-------- C:\WINDOWS\system32\bits
2008-05-18 08:44:48 0 d-------- C:\WINDOWS\ServicePackFiles
2008-05-18 08:06:32 0 d-------- C:\Program Files\X-Cleaner
2008-05-18 07:49:14 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Systweak
2008-05-18 07:49:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Systweak
2008-05-18 07:49:00 0 d-------- C:\Program Files\Systweak AntiSpyware
2008-05-18 07:48:43 11264 --a------ C:\WINDOWS\system32\AntiSpyNative32.exe
2008-05-18 07:45:22 0 d-------- C:\Documents and Settings\Brian Lowe\Contacts
2008-05-18 07:45:14 0 d------c- C:\WINDOWS\system32\DRVSTORE
2008-05-18 07:44:41 0 d--hs--c- C:\Program Files\Common Files\WindowsLiveInstaller
2008-05-18 07:44:24 0 d-------- C:\Program Files\Windows Live
2008-05-18 07:44:19 0 d-------- C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-05-18 07:24:38 0 d-------- C:\Program Files\RMClock
2008-05-18 07:13:35 0 d-------- C:\Program Files\Java
2008-05-18 07:13:11 0 d-------- C:\Program Files\Common Files\Java
2008-05-18 07:07:31 0 d--h----- C:\WINDOWS\msdownld.tmp
2008-05-18 06:51:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Adobe
2008-05-18 06:50:55 0 d-------- C:\Program Files\Common Files\Adobe
2008-05-18 06:48:59 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Macromedia
2008-05-18 06:48:37 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Adobe
2008-05-18 06:48:07 0 d-------- C:\WINDOWS\system32\Adobe
2008-05-18 06:43:48 0 d-------- C:\Program Files\Microsoft Silverlight
2008-05-18 06:33:39 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\StumbleUpon
2008-05-18 06:33:35 0 d-------- C:\Program Files\StumbleUpon
2008-05-18 06:16:47 0 d-------- C:\WINDOWS\network diagnostic
2008-05-18 06:07:28 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-05-18 06:05:54 0 d--hs---- C:\Documents and Settings\Brian Lowe\UserData
2008-05-18 05:55:16 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\MSNInstaller
2008-05-18 05:50:04 0 d-------- C:\WINDOWS\system32\PreInstall
2008-05-18 05:50:02 0 d--h----- C:\WINDOWS\$hf_mig$
2008-05-18 05:45:01 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-05-18 05:41:21 0 d-------- C:\Program Files\Realtek Sound Manager
2008-05-18 05:41:19 0 d-------- C:\Program Files\AvRack
2008-05-18 05:41:15 40960 -----n--- C:\WINDOWS\system32\ChCfg.exe
2008-05-18 05:41:08 208896 -----n--- C:\WINDOWS\alcupd.exe <Not Verified; Realtek Semiconductor Corp.; Update Application for Realtek AC'97>
2008-05-18 05:41:08 139264 -----n--- C:\WINDOWS\alcrmv.exe <Not Verified; Realtek Semiconductor Corp.; Realtek AC'97 Removing Tool>
2008-05-18 05:41:08 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-05-18 05:36:57 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-05-18 05:35:54 0 d-------- C:\WINDOWS\system32\Tools
2008-05-18 05:35:48 0 d-------- C:\Program Files\Common Files\InstallShield
2008-05-18 05:24:31 96966 --a------ C:\WINDOWS\system32\drivers\klin.dat
2008-05-18 05:24:31 88774 --a------ C:\WINDOWS\system32\drivers\klick.dat
2008-05-18 05:24:12 277792 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-05-18 05:24:12 5134112 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-05-18 05:24:12 0 d-------- C:\Program Files\Kaspersky Lab
2008-05-18 05:24:12 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-05-18 05:23:40 0 d-------- C:\kav
2008-05-18 05:15:06 0 d-------- C:\Documents and Settings\Brian Lowe\Application Data\Identities
2008-05-18 05:14:59 0 d--h----- C:\Documents and Settings\Brian Lowe\Templates
2008-05-18 05:14:59 0 dr------- C:\Documents and Settings\Brian Lowe\Start Menu
2008-05-18 05:14:59 0 dr-h----- C:\Documents and Settings\Brian Lowe\SendTo
2008-05-18 05:14:59 0 d--h----- C:\Documents and Settings\Brian Lowe\PrintHood
2008-05-18 05:14:59 0 d--h----- C:\Documents and Settings\Brian Lowe\NetHood
2008-05-18 05:14:59 0 dr------- C:\Documents and Settings\Brian Lowe\My Documents
2008-05-18 05:14:59 0 d--h----- C:\Documents and Settings\Brian Lowe\Local Settings
2008-05-18 05:14:59 0 dr------- C:\Documents and Settings\Brian Lowe\Favorites
2008-05-18 05:14:59 0 d-------- C:\Documents and Settings\Brian Lowe\Desktop
2008-05-18 05:14:59 0 d--hs---- C:\Documents and Settings\Brian Lowe\Cookies
2008-05-18 05:14:59 0 dr-h----- C:\Documents and Settings\Brian Lowe\Application Data
2008-05-18 05:12:32 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-05-18 05:12:30 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-05-18 05:12:30 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-05-18 05:12:30 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-05-18 05:12:30 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-05-18 05:12:30 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-05-18 05:09:43 229376 --a------ C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-05-18 05:09:43 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-05-18 05:09:43 0 d---s---- C:\Documents and Settings\NetworkService\Cookies
2008-05-18 05:09:43 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-05-18 05:09:43 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-05-18 05:07:13 0 d-------- C:\WINDOWS\system32\xircom
2008-05-18 05:07:13 0 d-------- C:\Program Files\microsoft frontpage
2008-05-18 05:07:02 229376 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-05-18 05:06:56 0 -rahs---- C:\MSDOS.SYS
2008-05-18 05:06:56 0 -rahs---- C:\IO.SYS
2008-05-18 05:06:56 0 --a------ C:\CONFIG.SYS
2008-05-18 05:06:56 0 --a------ C:\AUTOEXEC.BAT
2008-05-18 05:06:06 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-05-18 05:05:57 0 dr------- C:\WINDOWS\Offline Web Pages
2008-05-18 05:05:57 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-05-18 05:05:48 0 d--h----- C:\Program Files\WindowsUpdate
2008-05-18 05:05:31 0 d-------- C:\WINDOWS\system32\DirectX
2008-05-18 05:05:06 0 d---s---- C:\WINDOWS\Tasks
2008-05-18 05:05:05 0 d-------- C:\Program Files\Common Files\MSSoap
2008-05-18 05:05:02 0 d-------- C:\WINDOWS\system32\Macromed
2008-05-18 05:05:02 0 d-------- C:\WINDOWS\srchasst
2008-05-18 05:04:56 0 d-------- C:\Program Files\Movie Maker
2008-05-18 05:04:50 0 d-------- C:\WINDOWS\system32\Restore
2008-05-18 05:04:19 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-05-18 05:04:03 0 d-------- C:\WINDOWS\Registration
2008-05-18 05:03:55 0 d-------- C:\Program Files\Online Services
2008-05-18 05:03:49 0 d-------- C:\Program Files\Messenger
2008-05-18 05:03:46 0 d-------- C:\Program Files\MSN Gaming Zone
2008-05-18 05:03:17 0 d-------- C:\Program Files\Windows NT
2008-05-18 05:03:15 0 d-------- C:\WINDOWS\system32\MsDtc
2008-05-18 05:03:13 0 d-------- C:\WINDOWS\system32\Com
2008-05-17 23:45:19 0 d--hs---- C:\WINDOWS\Installer
2008-05-17 23:45:18 0 d-------- C:\Program Files\Common Files\ODBC
2008-05-17 23:45:16 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-05-17 23:45:15 0 dr------- C:\Program Files
2008-05-17 23:45:15 0 d-------- C:\Program Files\Common Files
2008-05-17 23:44:54 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-05-17 23:44:54 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-05-17 23:44:54 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-05-17 23:44:54 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-05-17 23:44:54 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-05-17 23:44:54 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-05-17 23:44:54 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-05-17 23:44:54 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-05-17 23:44:54 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-05-17 23:44:54 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-05-17 23:44:54 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-05-17 23:44:54 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-05-17 23:44:54 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-05-17 23:44:54 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-05-17 23:44:54 0 dr------- C:\Documents and Settings\All Users\Documents
2008-05-17 23:44:54 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-05-17 23:44:43 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-05-17 23:44:43 0 d-------- C:\WINDOWS\system32\CatRoot
2008-05-17 23:44:37 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-05-17 23:44:37 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-05-17 23:44:37 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-05-17 23:44:37 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-05-17 23:44:17 0 d-------- C:\Documents and Settings
2008-05-17 23:44:16 0 d--hs---- C:\System Volume Information
2008-05-17 23:38:46 0 d-------- C:\WINDOWS
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\WinSxS
2008-05-17 23:38:46 0 dr------- C:\WINDOWS\Web
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\twain_32
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\wins
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\wbem
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\usmt
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\spool
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\ShellExt
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\Setup
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\ras
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\oobe
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\npp
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\mui
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\inetsrv
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\IME
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\icsxml
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\ias
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\export
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\drivers
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-05-17 23:38:46 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\dhcp
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\config
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\3076
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\2052
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1054
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1042
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1041
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1037
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1033
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1031
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1028
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system32\1025
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\system
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\security
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Resources
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\repair
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Provisioning
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\PeerNet
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\pchealth
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\mui
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\msapps
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\msagent
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Media
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\java
2008-05-17 23:38:46 0 d--h----- C:\WINDOWS\inf
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\ime
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Help
2008-05-17 23:38:46 0 dr--s---- C:\WINDOWS\Fonts
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\ehome
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Driver Cache
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Debug
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Cursors
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Connection Wizard
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\Config
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\AppPatch
2008-05-17 23:38:46 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-05-21 11:54:20 2770045 --a------ C:\Program Files\PC Wizard 2008 v1.84.exe <Not Verified; Laurent KUTIL & Franck DELATTRE; >
2008-05-18 13:20:00 1302325 --a------ C:\Program Files\CleanCache v3.5.exe <Not Verified; ButtUglySoftware; >
2008-05-18 09:48:45 575663 --a------ C:\Program Files\CrystalCPUID414.zip
2008-05-17 23:44:54 62 --ahs---- C:\Documents and Settings\Brian Lowe\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [01/11/2008 10:16 PM]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [02/22/2008 04:25 AM]
"UnlockerAssistant"="C:\Program Files\Unlocker\UnlockerAssistant.exe" [09/07/2006 12:19 PM]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.08\RivaTuner.exe" [03/10/2008 03:10 AM]
"SoundMan"="SOUNDMAN.EXE" [01/20/2005 07:04 AM C:\WINDOWS\SOUNDMAN.EXE]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 7.0\avp.exe" [02/08/2008 06:36 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [04/13/2008 07:12 PM]
"RMClock"="C:\Program Files\RMClock\RMClockLauncher.exe" [09/22/2007 08:45 PM]
"Systweak AntiSpyware 2008"="C:\Program Files\Systweak AntiSpyware\AntiSpyware.exe" [05/30/2008 03:29 PM]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\policies\system]
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\system]
"DisableChangePassword"=0 (0x0)
"DisableLockWorkstation"=0 (0x0)
"HideLegacyLogonScripts"=0 (0x0)
"HideLogoffScripts"=0 (0x0)
"RunLogonScriptSync"=1 (0x1)
"RunStartupScriptSync"=0 (0x0)
"HideStartupScripts"=0 (0x0)
"DisableRegistryTools"=0 (0x0)
"DisableTaskMgr"=0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\policies\explorer]
"NoTrayContextMenu"=0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\dimsntfy]
C:\WINDOWS\System32\dimsntfy.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"=C:\PROGRA~1\KASPER~1\KASPER~1.0\adi alhk.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\vds]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\SafeBoot\Minimal\{533C5B84-EC70-11D2-9505-00C04F79DEAF}]
@="Volume shadow copy"
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
eapsvcs eaphost
dot3svc dot3svc
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
napagent
hkmsvc
[HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\explorer\mountpoints2\{a25d710a-2490-11dd-8e42-806d6172696f}]
AutoRun\command- E:\Setup.EXE
-- End of Deckard's System Scanner: finished at 2008-06-04 08:06:01 ------------