Hi Dan
The comments regarding P2P have been noted.
Have carried out all of the above and reports are as follows.
Current situation is that all pop-ups seem to have stopped.
Thanks
Colin
Combofix reportComboFix 08-03-25.1 - Colin & Kerry 2008-03-26 18:00:52.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1382 [GMT 1:00]
Running from: C:\Documents and Settings\Colin & Kerry\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Colin & Kerry\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!FILE ::
C:\Documents and Settings\All Users\Application Data\rszyjelw
C:\Documents and Settings\Colin & Kerry\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\Colin & Kerry\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\Colin & Kerry\Desktopfilemanagerclient.exe
C:\Documents and Settings\Colin & Kerry\Desktopfkwp1.5.exe
C:\Documents and Settings\Colin & Kerry\Desktopfkwp2.0.exe
C:\Documents and Settings\Colin & Kerry\Desktopfwebd.exe
C:\Documents and Settings\Colin & Kerry\DesktopFWebdEditor.exe
C:\Documents and Settings\Colin & Kerry\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\Colin & Kerry\Desktopvirii
C:\Documents and Settings\colin.LAMUELA\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\colin.LAMUELA\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfilemanagerclient.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfkwp1.5.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfkwp2.0.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfwebd.exe
C:\Documents and Settings\colin.LAMUELA\DesktopFWebdEditor.exe
C:\Documents and Settings\colin.LAMUELA\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\colin.LAMUELA\Desktopvirii
C:\Documents and Settings\colin\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\colin\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\colin\Desktopfilemanagerclient.exe
C:\Documents and Settings\colin\Desktopfkwp1.5.exe
C:\Documents and Settings\colin\Desktopfkwp2.0.exe
C:\Documents and Settings\colin\Desktopfwebd.exe
C:\Documents and Settings\colin\DesktopFWebdEditor.exe
C:\Documents and Settings\colin\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\colin\Desktopvirii
C:\WINDOWS\system32\jwlwjshu.exe
C:\WINDOWS\system32\obkdetgl.exe
C:\WINDOWS\system32\pavas.ico
C:\WINDOWS\system32\robwncfs.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Colin & Kerry\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\Colin & Kerry\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\Colin & Kerry\Desktopfilemanagerclient.exe
C:\Documents and Settings\Colin & Kerry\Desktopfkwp1.5.exe
C:\Documents and Settings\Colin & Kerry\Desktopfkwp2.0.exe
C:\Documents and Settings\Colin & Kerry\Desktopfwebd.exe
C:\Documents and Settings\Colin & Kerry\DesktopFWebdEditor.exe
C:\Documents and Settings\Colin & Kerry\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\colin.LAMUELA\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\colin.LAMUELA\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfilemanagerclient.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfkwp1.5.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfkwp2.0.exe
C:\Documents and Settings\colin.LAMUELA\Desktopfwebd.exe
C:\Documents and Settings\colin.LAMUELA\DesktopFWebdEditor.exe
C:\Documents and Settings\colin.LAMUELA\DesktopTrojan.Win32.BlackBird.exe
C:\Documents and Settings\colin\DesktopEditorFKWP1.5.exe
C:\Documents and Settings\colin\DesktopEditorFKWP2.0.exe
C:\Documents and Settings\colin\Desktopfilemanagerclient.exe
C:\Documents and Settings\colin\Desktopfkwp1.5.exe
C:\Documents and Settings\colin\Desktopfkwp2.0.exe
C:\Documents and Settings\colin\Desktopfwebd.exe
C:\Documents and Settings\colin\DesktopFWebdEditor.exe
C:\Documents and Settings\colin\DesktopTrojan.Win32.BlackBird.exe
C:\VundoFix Backups
C:\WINDOWS\system32\jwlwjshu.exe
C:\WINDOWS\system32\obkdetgl.exe
C:\WINDOWS\system32\pavas.ico
C:\WINDOWS\system32\robwncfs.exe
.
((((((((((((((((((((((((( Files Created from 2008-02-26 to 2008-03-26 )))))))))))))))))))))))))))))))
.
2008-03-25 23:48 . 2008-03-25 23:48 <DIR> d-------- C:\Program Files\CCleaner
2008-03-25 22:23 . 2008-03-26 12:42 <DIR> d-------- C:\Program Files\SUPERAntiSpyware
2008-03-25 22:23 . 2008-03-25 22:23 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\Application Data\SUPERAntiSpyware.com
2008-03-25 22:23 . 2008-03-25 22:23 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-25 21:02 . 2008-03-25 21:02 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\Application Data\Grisoft
2008-03-25 19:08 . 2008-03-25 19:08 <DIR> d-------- C:\Program Files\PC-Cleaner
2008-03-25 18:41 . 2008-03-25 18:41 <DIR> d-------- C:\Program Files\Trend Micro
2008-03-25 17:05 . 2008-03-25 17:59 <DIR> d-------- C:\Program Files\Spyware Doctor
2008-03-25 17:05 . 2008-03-25 17:05 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\Application Data\PC Tools
2008-03-25 17:05 . 2007-12-10 14:53 81,288 --a------ C:\WINDOWS\system32\drivers\iksyssec.sys
2008-03-25 17:05 . 2007-12-10 14:53 66,952 --a------ C:\WINDOWS\system32\drivers\iksysflt.sys
2008-03-25 17:05 . 2007-12-10 14:53 41,864 --a------ C:\WINDOWS\system32\drivers\ikfilesec.sys
2008-03-25 17:05 . 2007-12-10 14:53 29,576 --a------ C:\WINDOWS\system32\drivers\kcom.sys
2008-03-25 13:37 . 2008-03-26 09:51 <DIR> d-------- C:\Program Files\a-squared Free
2008-03-25 12:46 . 2008-03-26 09:51 <DIR> d-------- C:\Program Files\Windows Defender
2008-03-25 11:19 . 2008-03-25 11:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ParetoLogic Anti-Spyware
2008-03-25 08:35 . 2008-03-26 09:50 <DIR> d-------- C:\WINDOWS\system32\ActiveScan
2008-03-24 20:34 . 2008-03-24 20:34 664 --a------ C:\WINDOWS\system32\d3d9caps.dat
2008-03-24 20:24 . 2008-03-24 20:24 <DIR> d-------- C:\Documents and Settings\colin.LAMUELA\Application Data\Grisoft
2008-03-24 20:24 . 2008-03-24 20:24 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-24 20:24 . 2007-05-30 13:10 10,872 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2008-03-24 19:19 . 2008-03-24 19:19 <DIR> d-------- C:\Documents and Settings\colin.LAMUELA\Application Data\TuneUp Software
2008-03-24 18:51 . 2008-03-24 18:51 <DIR> d-------- C:\Documents and Settings\colin.LAMUELA\Desktopvirii
2008-03-24 12:17 . 2008-03-24 12:17 <DIR> d-------- C:\Documents and Settings\colin\Desktopvirii
2008-03-24 12:08 . 2008-03-24 18:40 <DIR> d-------- C:\Program Files\RogueRemover
2008-03-24 10:12 . 2008-03-24 20:35 4,754 --a------ C:\WINDOWS\system32\tmp.reg
2008-03-24 10:11 . 2007-09-05 23:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe
2008-03-24 10:11 . 2006-04-27 16:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe
2008-03-24 10:11 . 2008-03-22 15:49 86,528 --a------ C:\WINDOWS\system32\VACFix.exe
2008-03-24 10:11 . 2008-03-15 17:16 82,432 --a------ C:\WINDOWS\system32\IEDFix.exe
2008-03-24 10:11 . 2004-07-31 17:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe
2008-03-24 10:11 . 2007-10-03 23:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe
2008-03-23 21:08 . 2008-03-26 09:50 2,550 --a------ C:\WINDOWS\system32\Uninstall.ico
2008-03-23 21:08 . 2008-03-26 09:50 1,406 --a------ C:\WINDOWS\system32\Help.ico
2008-03-23 19:27 . 2008-03-23 19:29 <DIR> d-------- C:\Program Files\ShellExView
2008-03-23 19:27 . 2008-03-23 19:27 39,424 --a------ C:\WINDOWS\zipinst.exe
2008-03-23 17:17 . 2008-03-25 10:52 <DIR> d-------- C:\Program Files\Enigma Software Group
2008-03-23 16:16 . 2008-03-23 16:19 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-03-23 16:16 . 2008-03-23 16:16 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\Application Data\Spybot - Search & Destroy
2008-03-23 16:16 . 2008-03-26 00:35 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-03-23 16:16 . 2007-03-03 03:55 9,662 -rahs---- C:\WINDOWS\unins000.ico
2008-03-23 16:08 . 2008-03-25 18:25 <DIR> d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-03-23 16:03 . 2008-03-25 12:40 <DIR> d-------- C:\Program Files\Trojan Remover
2008-03-23 14:53 . 2008-03-23 14:53 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\Desktopvirii
2008-03-23 14:53 . 2008-03-25 23:04 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\rszyjelw
2008-03-23 12:45 . 2005-07-06 17:12 2,973,696 --------- C:\WINDOWS\UNNeroVision.exe
2008-03-23 12:45 . 2005-07-06 17:37 145,608 --------- C:\WINDOWS\UNNeroVision.cfg
2008-03-23 12:44 . 2008-03-23 12:44 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-23 12:44 . 2004-07-09 09:43 364,544 --------- C:\WINDOWS\system32\TwnLib4.dll
2008-03-23 12:44 . 2001-06-26 08:15 38,912 --------- C:\WINDOWS\system32\picn20.dll
2008-03-12 15:42 . 2008-03-12 15:39 102,664 --a------ C:\WINDOWS\system32\drivers\tmcomm.sys
2008-03-12 15:39 . 2008-03-25 16:28 <DIR> d-------- C:\Documents and Settings\Colin & Kerry\.housecall6.6
2008-03-08 16:57 . 2008-03-08 17:07 <DIR> d-------- C:\Program Files\Super Internet TV
2008-02-28 16:58 . 2008-03-22 19:24 <DIR> d-------- C:\Incomplete
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-03-26 16:50 --------- d-----w C:\Program Files\PeerGuardian2
2008-03-26 16:42 --------- d-----w C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-26 15:11 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\Skype
2008-03-26 15:01 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\skypePM
2008-03-26 08:51 --------- d-----w C:\Program Files\Winamp
2008-03-26 08:51 --------- d-----w C:\Program Files\TuneUp Utilities 2008
2008-03-26 08:51 --------- d-----w C:\Program Files\Norton 360
2008-03-26 08:51 --------- d-----w C:\Program Files\LogitechImageStudio
2008-03-26 08:51 --------- d-----w C:\Program Files\DU Meter
2008-03-26 08:51 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-03-26 08:50 --------- d-----w C:\Program Files\Google
2008-03-25 21:22 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-25 18:08 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-03-25 17:47 --------- d-----w C:\Program Files\Super Ad Blocker
2008-03-25 17:30 --------- d-----w C:\Program Files\Java
2008-03-25 16:05 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\uTorrent
2008-03-23 20:47 --------- d-----w C:\Program Files\MagicISO
2008-03-23 11:44 --------- d-----w C:\Program Files\Ahead
2008-03-21 16:02 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\LimeWire
2008-03-20 12:59 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\MahJong Suite
2008-03-20 11:53 --------- d-----w C:\Program Files\MP4 Converter 3
2008-03-20 11:30 --------- d-----w C:\Program Files\IsoBuster
2008-03-06 20:32 706 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.inf
2008-03-06 20:32 23,904 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.sys
2008-03-06 20:32 10,537 ----a-w C:\WINDOWS\system32\drivers\COH_Mon.cat
2008-02-21 09:08 --------- d-----w C:\Program Files\Easy Video Joiner
2008-02-20 21:37 --------- d-----w C:\Program Files\ffdshow
2008-02-20 21:18 --------- d-----w C:\Program Files\WinAVI VideoConverter
2008-02-20 21:01 --------- d-----w C:\Program Files\FairUse Wizard 2
2008-02-16 16:32 --------- d-----w C:\Program Files\DivX
2008-02-16 15:59 --------- d-----w C:\Program Files\Codec Pack - All In 1
2008-02-16 15:58 --------- d-----w C:\Program Files\Xvid
2008-02-16 13:51 --------- d-----w C:\Program Files\Common Files\AVSMedia
2008-02-16 13:45 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\AVS4YOU
2008-02-16 13:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-02-16 11:29 --------- d-----w C:\Program Files\AviSynth 2.5
2008-02-15 10:24 --------- d-----w C:\Program Files\ABBYY FineReader 6.0 Sprint
2008-02-13 13:45 --------- d-----w C:\Program Files\Cover Expert
2008-02-12 08:43 --------- d-----w C:\Documents and Settings\LocalService\Application Data\Acronis
2008-02-12 08:34 441,760 ----a-w C:\WINDOWS\system32\drivers\timntr.sys
2008-02-12 08:34 44,384 ----a-w C:\WINDOWS\system32\drivers\tifsfilt.sys
2008-02-12 08:34 129,248 ----a-w C:\WINDOWS\system32\drivers\snapman.sys
2008-02-12 08:34 --------- d-----w C:\Documents and Settings\All Users\Application Data\Acronis
2008-02-12 08:33 368,736 ----a-w C:\WINDOWS\system32\drivers\tdrpman.sys
2008-02-12 08:33 --------- d-----w C:\Program Files\Common Files\Acronis
2008-02-12 08:33 --------- d-----w C:\Program Files\Acronis
2008-02-11 19:11 --------- d-----w C:\Program Files\LimeWire
2008-02-09 16:13 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS.ORIGINAL
2008-02-09 16:13 360,064 ----a-w C:\WINDOWS\system32\drivers\TCPIP.SYS
2008-02-09 15:18 --------- d-----w C:\Program Files\Free Audio Pack
2008-02-09 11:23 --------- d-----w C:\Program Files\Common Files\Adobe
2008-02-07 15:21 --------- d-----w C:\Program Files\Portrait Professional Max 6
2008-02-07 15:21 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\Anthropics
2008-02-05 08:38 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\LEAPS
2008-02-05 08:37 --------- d-----w C:\Program Files\Pegasys Inc
2008-02-05 08:25 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\Pegasys Inc
2008-02-02 15:32 --------- d-----w C:\Program Files\SopCast
2008-02-01 20:20 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\Winamp
2008-01-28 12:13 287,488 ----a-w C:\WINDOWS\system32\drivers\RTL8187.sys
2008-01-27 08:28 --------- d-----w C:\Program Files\MSXML 4.0
2008-01-26 20:40 --------- d-----w C:\Documents and Settings\Colin & Kerry\Application Data\MAGIX
2008-01-26 20:40 --------- d-----w C:\Documents and Settings\All Users\Application Data\MAGIX
2008-01-26 20:37 --------- d-----w C:\Program Files\MAGIX
2008-01-26 20:37 --------- d-----w C:\Program Files\Common Files\MAGIX Shared
2008-01-24 20:30 737,280 ----a-w C:\WINDOWS\iun6002.exe
2008-01-24 19:00 32 ----a-w C:\Documents and Settings\All Users\Application Data\ezsid.dat
.
------- Sigcheck -------
2007-10-30 17:53 360832 64798ecfa43d78c7178375fcdd16d8c8 C:\WINDOWS\$hf_mig$\KB941644\SP2QFE\tcpip.sys
2002-08-29 01:58 332928 244a2f9816bc9b593957281ef577d976 C:\WINDOWS\$NtServicePackUninstall$\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\$NtUninstallKB941644$\tcpip.sys
2004-08-03 23:14 359040 9f4b36614a0fc234525ba224957de55c C:\WINDOWS\ServicePackFiles\i386\TCPIP.SYS
2008-02-09 17:13 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\dllcache\TCPIP.SYS
2008-02-09 17:13 360064 482ab7f9cd41702e8f856c11cfefb02d C:\WINDOWS\system32\drivers\TCPIP.SYS
.
((((((((((((((((((((((((((((( snapshot@2008-03-26_ 0.08.00.76 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-01-24 21:05:05 64,088 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
+ 2008-03-26 12:54:43 66,936 ----a-w C:\WINDOWS\assembly\GAC\Microsoft.Vbe.Interop\11.0.0.0__71e9bce111e9429c\Microsoft.Vbe.Interop.dll
- 2008-01-24 21:05:04 223,800 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2008-03-26 12:54:34 226,656 ----a-w C:\WINDOWS\assembly\GAC\office\11.0.0.0__71e9bce111e9429c\OFFICE.DLL
+ 2003-07-14 21:57:34 38,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\AUTHZAX.DLL
+ 2003-07-14 21:53:06 94,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\AW.DLL
+ 2003-07-15 02:14:28 350,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\CDLMSO.DLL
+ 2003-07-15 02:18:12 47,160 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DFUICOM.EXE
+ 2003-07-14 21:56:54 14,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DSITF.DLL
+ 2003-07-14 21:57:14 98,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\DSSM.EXE
+ 2003-08-13 01:34:38 10,073,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\EXCEL.EXE
+ 2003-08-03 09:56:16 1,146,184 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FM20.DLL
+ 2003-07-23 22:01:40 1,949,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPCUTL.DLL
+ 2003-07-14 22:36:14 186,424 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPDTC.DLL
+ 2003-07-14 21:40:12 179,768 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPERSON.DLL
+ 2003-07-14 21:40:12 165,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPLACE.DLL
+ 2003-07-25 18:00:16 1,157,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPSRVUTL.DLL
+ 2003-07-25 18:14:50 799,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\FPWEC.DLL
+ 2003-07-14 22:11:42 2,139,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\GRAPH.EXE
+ 2003-07-14 21:57:44 87,096 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\IEAWSDC.DLL
+ 2003-07-14 21:53:50 161,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\IETAG.DLL
+ 2003-06-18 16:31:44 758,784 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIGRAPH.DLL
+ 2003-06-18 16:31:10 252,928 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIINK.DLL
+ 2003-06-18 16:31:48 17,920 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIMON.DLL
+ 2003-06-18 16:31:48 18,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIPPR.DLL
+ 2003-06-18 16:31:46 35,328 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIUI.DLL
+ 2003-06-18 16:31:34 443,904 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MDIVWCTL.DLL
+ 2003-07-14 21:58:04 230,968 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSCDM.DLL
+ 2003-07-14 21:51:50 116,288 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSCONV97.DLL
+ 2002-12-17 18:08:50 359,600 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSDMENG.DLL
+ 2002-12-17 18:08:54 1,383,592 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSDMINE.DLL
+ 2003-07-14 21:51:44 87,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSENCODE.DLL
+ 2002-04-09 19:14:36 187,560 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSMDUN80.DLL
+ 2003-07-14 21:52:52 17,464 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSMH.DLL
+ 2003-08-07 23:23:16 12,172,336 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSO.DLL
+ 2003-07-14 21:57:16 120,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOAUTH.DLL
+ 2003-07-15 02:14:18 106,552 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOCF.DLL
+ 2003-07-23 21:35:26 127,032 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOCFU.DLL
+ 2003-07-14 21:52:52 27,704 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSODCW.DLL
+ 2003-07-14 21:44:06 25,144 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOEURO.DLL
+ 2003-07-14 21:52:56 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOHTMED.EXE
+ 2002-12-17 18:09:24 2,071,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOLAP80.DLL
+ 2003-07-11 01:15:48 1,292,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSONSEXT.DLL
+ 2003-07-15 02:18:52 376,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSORUN.DLL
+ 2003-07-14 21:52:54 28,224 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSTYLE.DLL
+ 2003-07-14 21:52:52 35,896 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOSV.DLL
+ 2003-07-14 21:46:16 42,040 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXEV.DLL
+ 2003-07-14 21:45:12 55,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLED.EXE
+ 2003-07-14 21:45:12 39,488 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSOXMLMF.DLL
+ 2003-06-18 16:31:24 1,033,216 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPCORE.DLL
+ 2003-06-18 16:31:50 16,384 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPGIMME.DLL
+ 2003-07-28 11:24:40 5,677,112 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPUB.EXE
+ 2003-06-19 15:05:50 364,648 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSPVIEW.EXE
+ 2003-07-14 21:52:58 41,528 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSSH.DLL
+ 2003-07-14 22:02:14 627,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORDB.EXE
+ 2003-07-14 21:56:24 124,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORE.EXE
+ 2003-07-23 21:40:00 482,872 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSTORES.DLL
+ 2003-07-14 22:00:54 145,984 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\MSWEBCAP.DLL
+ 2003-07-14 21:57:10 56,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NAME.DLL
+ 2003-07-14 21:56:52 13,888 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\NPOFFICE.DLL
+ 2008-01-24 21:05:04 223,800 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OFFICE.DLL
+ 2003-07-15 02:14:26 283,696 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OIS.EXE
+ 2003-07-15 02:14:26 828,472 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISAPP.DLL
+ 2003-07-15 02:14:26 27,192 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISCTRL.DLL
+ 2003-07-15 02:14:26 242,240 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OISGRAPH.DLL
+ 2003-07-14 22:05:24 1,054,264 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OMFC.DLL
+ 2003-08-04 12:19:34 7,330,360 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OWC10.DLL
+ 2003-08-01 14:09:04 8,086,072 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\OWC11.DLL
+ 2003-07-30 11:40:40 6,133,312 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\POWERPNT.EXE
+ 2003-07-15 02:18:54 430,136 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP4X322.DLL
+ 2003-07-15 02:18:44 93,752 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PP7X32.DLL
+ 2003-07-31 14:21:08 1,782,840 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PPTVIEW.EXE
+ 2003-07-14 21:40:26 130,104 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PRTF9.DLL
+ 2003-07-14 21:51:12 604,728 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PTXT9.DLL
+ 2003-07-14 21:50:26 551,480 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBCONV.DLL
+ 2003-07-14 21:40:16 51,256 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\PUBTRAP.DLL
+ 2003-05-08 20:54:00 77,824 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFEDIT.DLL
+ 2003-07-14 21:57:08 40,512 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\REFIEBAR.DLL
+ 2003-07-14 21:57:08 58,944 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SEQCHK10.DLL
+ 2003-07-14 21:53:14 11,848 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\SMARTTAGINSTALL.EXE
+ 2003-08-03 09:52:32 2,808,376 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\STSLIST.DLL
+ 2003-07-03 14:19:36 2,502,656 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\VBE6.DLL
+ 2008-01-24 21:05:05 64,088 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\VBIDEPIA.DLL
+ 2003-08-06 12:24:20 12,037,688 ----a-r C:\WINDOWS\Installer\$PatchCache$\Managed\9040110900063D11C8EF10054038389C\11.0.5614\WINWORD.EXE
- 2008-03-24 18:20:56 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2008-03-26 12:55:07 593,920 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2008-03-24 18:20:56 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2008-03-26 12:55:07 12,288 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2008-03-24 18:20:56 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2008-03-26 12:55:07 86,016 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2008-03-24 18:20:56 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2008-03-26 12:55:07 135,168 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
- 2008-03-24 18:20:56 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2008-03-26 12:55:07 11,264 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
- 2008-03-24 18:20:56 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2008-03-26 12:55:07 27,136 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2008-03-24 18:20:56 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2008-03-26 12:55:07 4,096 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
- 2008-03-24 18:20:56 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
+ 2008-03-26 12:55:07 794,624 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2008-03-24 18:20:56 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2008-03-26 12:55:07 249,856 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2008-03-24 18:20:56 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
+ 2008-03-26 12:55:07 61,440 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2008-03-24 18:20:56 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2008-03-26 12:55:07 23,040 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
- 2008-03-24 18:20:56 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2008-03-26 12:55:07 286,720 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
- 2008-03-24 18:20:56 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
+ 2008-03-26 12:55:07 409,600 ----a-r C:\WINDOWS\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2008-03-25 21:23:12 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
+ 2008-03-26 08:45:15 29,696 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF11.exe
- 2008-03-25 21:23:12 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
+ 2008-03-26 08:45:15 18,944 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF13.exe
- 2008-03-25 21:23:12 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2008-03-26 08:45:15 65,024 ----a-r C:\WINDOWS\Installer\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}\IconCDDCBBF15.exe
+ 2008-03-26 12:56:25 3,174 ----a-w C:\WINDOWS\SoftwareDistribution\EventCache\{9C929DBC-7237-4316-A472-FFA2F61D2C47}.bin
- 2003-08-03 09:56:16 1,146,184 ----a-w C:\WINDOWS\system32\FM20.DLL
+ 2007-06-06 09:53:34 1,195,888 ----a-w C:\WINDOWS\system32\FM20.DLL
- 2003-07-14 21:57:04 32,584 ----a-w C:\WINDOWS\system32\FM20ENU.DLL
+ 2007-03-22 18:17:04 35,440 ----a-w C:\WINDOWS\system32\FM20ENU.DLL
- 2008-02-17 06:50:13 192,976 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
+ 2008-03-26 12:57:40 192,976 ----a-w C:\WINDOWS\system32\FNTCACHE.DAT
- 2003-06-18 16:31:48 17,920 ----a-w C:\WINDOWS\system32\mdimon.dll
+ 2007-04-09 12:23:54 28,040 ----a-w C:\WINDOWS\system32\mdimon.dll
- 2003-06-18 16:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
+ 2007-04-09 12:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdigraph.dll
- 2003-06-18 16:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
+ 2007-04-09 12:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\3\mdiui.dll
- 2003-06-18 16:31:44 758,784 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
+ 2007-04-09 12:24:04 758,664 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdigraph.dll
- 2003-06-18 16:31:46 35,328 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
+ 2007-04-09 12:23:58 46,472 ----a-w C:\WINDOWS\system32\spool\drivers\w32x86\mdiui.dll
- 2003-06-18 16:31:48 18,944 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
+ 2007-04-09 12:23:54 28,552 ----a-w C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:56 15360]
"DU Meter"="C:\Program Files\DU Meter\DUMeter.exe" [2007-10-17 20:23 979968]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-24 15:44 68856]
"PeerGuardian"="C:\Program Files\PeerGuardian2\pg2.exe" [2005-09-18 18:40 1421824]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2007-02-27 11:39 1310720]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 14:34 868352]
"SoundMAX"="C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" [2006-07-13 07:12 729088]
"JMB36X IDE Setup"="C:\WINDOWS\RaidTool\xInsIDE.exe" [2007-03-20 07:36 36864]
"36X Raid Configurer"="C:\WINDOWS\System32\xRaidSetup.exe" [2007-03-21 09:23 1953792]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50 155648]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 06:59 115816]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-04-12 16:44 8429568]
"nwiz"="nwiz.exe" [2007-04-12 16:44 1626112 C:\WINDOWS\system32\nwiz.exe]
"NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-04-12 16:44 81920]
"LVCOMS"="C:\Program Files\Common Files\Logitech\QCDriver3\LVCOMS.EXE" [2002-12-10 17:54 127022]
"LogitechGalleryRepair"="C:\Program Files\LogitechImageStudio\ISStart.exe" [2002-12-10 18:32 155648]
"LogitechImageStudioTray"="C:\Program Files\LogitechImageStudio\LogiTray.exe" [2002-12-10 18:31 61440]
"OODefragTray"="C:\WINDOWS\system32\oodtray.exe" [2007-05-11 02:08 2512392]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2004-11-02 20:24 32768]
"WinampAgent"="C:\Program Files\Winamp\winampa.exe" [2007-10-10 06:28 36352]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792]
"TrueImageMonitor.exe"="C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe" [2007-09-14 02:52 2595480]
"AcronisTimounterMonitor"="C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe" [2007-09-14 03:02 905056]
"Acronis Scheduler2 Service"="C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe" [2007-09-14 02:55 140568]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [2008-01-29 17:38 583048]
"AAWTray"="C:\Program Files\Lavasoft\Ad-Aware 2007\AAWTray.exe" [2007-08-08 15:53 88024]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2006-11-03 18:20 866584]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 04:25 144784]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2004-08-04 00:56 15360]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WUAppSetup"="C:\Program Files\Common Files\logishrd\WUApp32.exe" [2007-02-03 10:23 430080]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2006-12-20 12:55 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 2007-02-27 11:39 282624 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\uTorrent\\utorrent.exe"=
"C:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\WINDOWS\system32\DRIVERS\tdrpman.sys [2008-02-12 09:33]
R2 DUMeterSvc;DU Meter Service;C:\Program Files\DU Meter\DUMeterSvc.exe [2007-10-15 15:19]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-09-14 04:01]
R2 UxTuneUp;TuneUp Theme Extension;C:\WINDOWS\System32\svchost.exe [2004-08-04 00:56]
R3 genmcmnUSB;USB Scroll Mouse Driver;C:\WINDOWS\system32\DRIVERS\gflmouhid.sys [2004-04-19 15:01]
S1 SABKUTIL;SABKUTIL;C:\Program Files\Super Ad Blocker\SABKUTIL.sys []
S3 PhilCam8116;Logitech QuickCam Pro 3000(PID_08B0);C:\WINDOWS\system32\DRIVERS\CamDrL21.sys [2002-12-10 17:53]
S3 RTLWUSB;Realtek RTL8187 Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter;C:\WINDOWS\system32\DRIVERS\RTL8187.sys [2008-01-28 13:13]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service;C:\WINDOWS\System32\TuneUpDefragService.exe [2008-01-25 13:33]
S3 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 16:00]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
*Newly Created Service* - COMHOST
.
Contents of the 'Scheduled Tasks' folder
"2008-03-25 10:19:06 C:\WINDOWS\Tasks\Pareto UNS.job"
- C:\Program Files\Common Files\ParetoLogic\UUS\UUS.dll\Pareto_Update.exe
.
**************************************************************************
catchme 0.3.1344 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-03-26 18:04:20
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\DUMeterSvc]
"ImagePath"="C:\Program Files\DU Meter\DUMeterSvc.exe /startedbyscm:E1F6D4BE-40E33354-DUMeterService"
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\system32\RUNDLL32.EXE
.
**************************************************************************
.
Completion time: 2008-03-26 18:06:18 - machine was rebooted
ComboFix-quarantined-files.txt 2008-03-26 17:06:16
ComboFix2.txt 2008-03-25 23:08:13
.
2008-03-12 08:22:32 --- E O F ---
Malwarebytes ReportMalwarebytes' Anti-Malware 1.09
Database version: 549
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 86876
Time elapsed: 23 minute(s), 21 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 10
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\PC-Cleaner (Rogue.PC-Cleaner) -> Quarantined and deleted successfully.
C:\WINDOWS\system32smp (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\system32\obkdetgl.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\system32\robwncfs.exe.vir (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP110\A0030463.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP110\A0030464.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP110\A0030465.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP110\A0030466.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP113\A0030857.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP113\A0030859.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\Web\def.htm (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32smp\msrc.exe (Fake.Dropped.Malware) -> Quarantined and deleted successfully.
Kaspersky Report KASPERSKY ONLINE SCANNER REPORT
Wednesday, March 26, 2008 7:51:39 PM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 26/03/2008
Kaspersky Anti-Virus database records: 664730
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
C:\
D:\
E:\
F:\
Scan Statistics:
Total number of scanned objects: 58203
Number of viruses found: 4
Number of infected objects: 28
Number of suspicious objects: 0
Duration of the scan process: 00:45:26
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\Common Client\settings.dat Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBConfig.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDebug.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBDetect.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBNotify.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBRefr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetCfg2.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetDev.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetLoc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBSetUsr.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBStHash.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\BBValid.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPPolicy.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStart.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SPBBC\SPStop.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtErEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\3327387B.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtETmp\E2C1AF83.TMP Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtMoEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtNvEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtScEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtTxFEvt.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Symantec\SRTSP\SrtViEvt.log Object is locked skipped
C:\Documents and Settings\colin\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\colin\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\colin\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\Colin & Kerry\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\History\History.IE5\MSHist012008032620080327\index.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Temp\~DFDB73.tmp Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Temp\~DFDB8E.tmp Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\Colin & Kerry\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\Colin & Kerry\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\colin.LAMUELA\Desktop\SmitfraudFix.exe/data.rar/SmitfraudFix/Reboot.exe Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\colin.LAMUELA\Desktop\SmitfraudFix.exe/data.rar Infected: not-a-virus:RiskTool.Win32.Reboot.f skipped
C:\Documents and Settings\colin.LAMUELA\Desktop\SmitfraudFix.exe RarSFX: infected - 2 skipped
C:\Documents and Settings\LocalService\Application Data\Acronis\TrueImageHome\Logs\603BBB9F-02AB-4873-8178-F10407434D19.log Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Hagel Technologies\DU Meter\DUMeter.sqb Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAD.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWADMT.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.dat Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\coShared\WA\1.5\NCOWAS.ldb Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\EENGINE\EPERSIST.DAT Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDALRT.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDCON.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDDBG.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDFW.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDIDS.log Object is locked skipped
C:\Program Files\Common Files\Symantec Shared\SNDSYS.log Object is locked skipped
C:\Program Files\Norton 360\Log\AutoProtect.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVContext.log Object is locked skipped
C:\Program Files\Norton 360\Log\AVManual.log Object is locked skipped
C:\Program Files\Norton 360\Log\Backup.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetPageViewHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetSearchHistory.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUInternetTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\CUWindowsTempFiles.log Object is locked skipped
C:\Program Files\Norton 360\Log\EmailScan.log Object is locked skipped
C:\Program Files\Norton 360\Log\InternetSecurity.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIntrusionPrevented.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISIOTraffic.log Object is locked skipped
C:\Program Files\Norton 360\Log\ISNewNetwork.log Object is locked skipped
C:\Program Files\Norton 360\Log\LiveUpdate.log Object is locked skipped
C:\Program Files\Norton 360\Log\NCO.log Object is locked skipped
C:\Program Files\Norton 360\Log\VABrowserSettings.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAIPAddresses.log Object is locked skipped
C:\Program Files\Norton 360\Log\VAWeakPasswords.log Object is locked skipped
C:\Program Files\Norton 360\Log\WDFScanner.log Object is locked skipped
C:\Program Files\PeerGuardian2\history.db Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{F8295CD4-041F-4125-8E90-DBC20C4CB6C2}\RP113\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{9C929DBC-7237-4316-A472-FFA2F61D2C47}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\Sti_Trace.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\TEMP\JET824.tmp Object is locked skipped
C:\WINDOWS\TEMP\JET8C0.tmp Object is locked skipped
C:\WINDOWS\wiadebug.log Object is locked skipped
C:\WINDOWS\wiaservc.log Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009287.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009287.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009287.exe/WISE0020.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009287.exe WiseSFX: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009287.exe WiseSFXDropper: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009288.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009288.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009288.exe/WISE0020.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009288.exe WiseSFX: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009288.exe WiseSFXDropper: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009308.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009308.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009308.exe/WISE0020.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009308.exe WiseSFX: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009379.exe/WISE0014.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009379.exe/WISE0017.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP53\A0009379.exe WiseSFX: infected - 2 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP56\A0010103.exe/WISE0016.BIN Infected: not-a-virus:AdWare.Win32.OneStep.c skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP56\A0010103.exe/WISE0019.BIN Infected: not-a-virus:AdWare.Win32.Relevant.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP56\A0010103.exe/WISE0020.BIN Infected: not-a-virus:AdTool.Win32.WhenU.a skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP56\A0010103.exe WiseSFX: infected - 3 skipped
D:\System Volume Information\_restore{7CC75D25-3185-4C73-88AD-16FB45024A7A}\RP56\A0010103.exe WiseSFXDropper: infected - 3 skipped
Scan process completed.