"YOUR SYSTEM IS INFECTED" desktop+popup virus
I noticed that there was another thread on this website and someone was having the exact same problems as myself.. EXACT same. I tried to post on that thread, and it wouldn't allow me to. This is what happened:
I thought I was downloading the correct webcam drivers/software for my HP laptop, but I was sadly mistaken. My desktop is now green with the warning "YOUR SYSTEM IS INFECTED"..so on and so forth. I tried to do system restore and it tells me "application cannot be executed. the file is infected. please activate your antivirus software."
every once in awhile I get a popup that says "Attention! system detected a potential hazard (TrojanSPM/LX) on your computer that may infect executable files. You private information and PC safety is at risk. To get rid of unwanted spyware and keep your computer safe you need to update your current security software. Click OK to download official intrusion detection system (IDS software)"
from what i've tried, it seems like i'm helpless and I don't know what to do. I would really appreciate any kind of help whatsoever. please, anybody help me with this.. This is my moms laptop and I feel bad that this had to happen to her, simply because I was trying to download a driver for the webcam that was simply bogus.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:10:21 PM, on 1/17/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\lxddcoms.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\smss32.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Digsby\lib\digsby-app.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Ventrilo\Ventrilo.exe
C:\Program Files\Digsby\lib\aspell\bin\aspell.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\frank\My Documents\Downloads\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\winlogon32.exe
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [smss32.exe] C:\WINDOWS\system32\smss32.exe
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [NVIDIA nTune] "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1262481124046
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn...Detection2.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll
O20 - AppInit_DLLs: C:\WINDOWS\system32\guard32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: lxdd_device - - C:\WINDOWS\system32\lxddcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
I hope I did this right, any feedback would be greatly appreciated.
combofix LOG (part 1) too big for one msg
ComboFix 10-01-19.02 - frank 01/19/2010 16:17:42.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1983.1454 [GMT -6:00]
Running from: c:\documents and settings\frank\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Updated) {AD166499-45F9-482A-A743-FDD3350758C7}
AV: AVG Anti-Virus Free *On-access scanning disabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\frank\Application Data\inst.exe
c:\program files\Common
c:\program files\Common\VsoVprev.ax
C:\s
c:\windows\system32\11478.exe
c:\windows\system32\11538.exe
c:\windows\system32\11942.exe
c:\windows\system32\12382.exe
c:\windows\system32\14604.exe
c:\windows\system32\14771.exe
c:\windows\system32\153.exe
c:\windows\system32\15724.exe
c:\windows\system32\16827.exe
c:\windows\system32\17421.exe
c:\windows\system32\18467.exe
c:\windows\system32\1869.exe
c:\windows\system32\18716.exe
c:\windows\system32\19169.exe
c:\windows\system32\19718.exe
c:\windows\system32\19895.exe
c:\windows\system32\19912.exe
c:\windows\system32\21726.exe
c:\windows\system32\23281.exe
c:\windows\system32\24464.exe
c:\windows\system32\25667.exe
c:\windows\system32\26299.exe
c:\windows\system32\26500.exe
c:\windows\system32\26962.exe
c:\windows\system32\28145.exe
c:\windows\system32\292.exe
c:\windows\system32\29358.exe
c:\windows\system32\2995.exe
c:\windows\system32\32391.exe
c:\windows\system32\3902.exe
c:\windows\system32\4827.exe
c:\windows\system32\491.exe
c:\windows\system32\5436.exe
c:\windows\system32\5447.exe
c:\windows\system32\5705.exe
c:\windows\system32\6334.exe
c:\windows\system32\9961.exe
.
((((((((((((((((((((((((( Files Created from 2009-12-19 to 2010-01-19 )))))))))))))))))))))))))))))))
.
2010-01-19 20:00 . 2010-01-19 20:00 388096 ----a-r- c:\documents and settings\frank\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe
2010-01-19 20:00 . 2010-01-19 20:00 -------- d-----w- c:\program files\TrendMicro
2010-01-18 15:14 . 2010-01-18 15:14 52224 ----a-w- c:\documents and settings\frank\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-01-18 15:14 . 2010-01-18 15:17 117760 ----a-w- c:\documents and settings\frank\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-01-18 15:14 . 2010-01-18 15:14 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-01-18 03:28 . 2010-01-18 03:28 12464 ----a-w- c:\windows\system32\avgrsstx.dll
2010-01-18 03:28 . 2010-01-18 03:28 333192 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-01-18 03:28 . 2010-01-18 03:28 28424 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-01-18 03:28 . 2010-01-19 14:15 -------- d-----w- c:\windows\system32\drivers\Avg
2010-01-18 03:28 . 2010-01-18 03:28 360584 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-01-18 03:28 . 2010-01-18 03:28 -------- d-----w- c:\program files\AVG
2010-01-18 01:11 . 2010-01-18 01:11 -------- d-----w- c:\documents and settings\frank\Application Data\Malwarebytes
2010-01-18 01:11 . 2010-01-07 22:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-18 01:11 . 2010-01-07 22:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-18 01:11 . 2010-01-18 01:11 -------- d-----w- c:\program files\Malwarebytes
2010-01-18 00:27 . 2010-01-18 00:27 -------- d-----w- c:\windows\system32\CatRoot_bak
2010-01-17 02:42 . 2010-01-18 03:28 -------- d-----w- c:\documents and settings\All Users\Application Data\avg9
2010-01-16 09:31 . 2010-01-16 09:54 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-01-13 15:43 . 2009-11-21 15:51 471552 -c----w- c:\windows\system32\dllcache\aclayers.dll
2010-01-06 08:57 . 2010-01-06 08:57 -------- d-----w- c:\program files\AC3Filter
2010-01-05 20:27 . 2010-01-05 20:27 -------- d-sh--w- c:\documents and settings\Guest\IETldCache
2010-01-05 20:25 . 2010-01-05 20:25 -------- d-sh--w- c:\documents and settings\Marcy\IETldCache
2010-01-04 18:50 . 2010-01-04 18:50 -------- d-----w- c:\documents and settings\frank\Local Settings\Application Data\PCHealth
2010-01-04 09:10 . 2010-01-04 09:11 -------- d-----w- C:\b15ed8c1a1319963d88c
2010-01-04 08:29 . 2010-01-04 08:29 -------- d-sh--w- c:\documents and settings\frank\PrivacIE
2010-01-04 03:25 . 2010-01-04 03:25 -------- d-sh--w- c:\documents and settings\frank\IETldCache
2010-01-03 23:03 . 2009-10-29 07:45 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2010-01-03 23:03 . 2009-10-29 07:45 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2010-01-03 23:03 . 2009-10-29 07:45 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2010-01-03 23:03 . 2009-10-29 07:45 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2010-01-03 23:03 . 2009-10-29 07:45 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2010-01-03 23:03 . 2009-10-29 07:45 11069952 -c----w- c:\windows\system32\dllcache\ieframe.dll
2010-01-03 23:03 . 2010-01-05 09:01 -------- d-----w- c:\windows\ie8updates
2010-01-03 23:03 . 2009-10-02 04:44 92160 -c----w- c:\windows\system32\dllcache\iecompat.dll
2010-01-03 23:01 . 2010-01-03 23:03 -------- dc-h--w- c:\windows\ie8
2010-01-03 22:19 . 2010-01-03 22:19 -------- d-----w- c:\program files\MSXML 6.0
2010-01-03 20:08 . 2008-04-14 00:10 102912 -c----w- c:\windows\system32\dllcache\dpcdll.dll
2010-01-03 20:08 . 2008-04-14 00:09 24064 -c----w- c:\windows\system32\dllcache\pidgen.dll
2010-01-03 20:08 . 2008-04-14 00:12 10752 ------w- c:\windows\system32\smtpapi.dll
2010-01-03 20:08 . 2008-04-14 00:12 9728 ------w- c:\windows\system32\rwnh.dll
2010-01-03 20:08 . 2008-04-14 12:00 81920 ------w- c:\windows\system32\ieencode.dll
2010-01-03 20:08 . 2008-04-14 00:11 498742 -c----w- c:\windows\system32\dllcache\dxmasf.dll
2010-01-03 20:08 . 2008-04-14 12:00 87040 -c----w- c:\windows\system32\dllcache\drmstor.dll
2010-01-03 20:08 . 2008-04-14 12:00 695808 -c----w- c:\windows\system32\dllcache\drmv2clt.dll
2010-01-03 20:08 . 2008-04-14 12:00 299520 -c----w- c:\windows\system32\dllcache\drmclien.dll
2010-01-03 20:08 . 2008-04-14 00:12 294912 -c----w- c:\windows\system32\dllcache\dlimport.exe
2010-01-03 20:08 . 2008-04-14 12:00 33792 -c----w- c:\windows\system32\dllcache\custsat.dll
2010-01-03 20:08 . 2008-04-14 12:00 286720 -c----w- c:\windows\system32\dllcache\blackbox.dll
2010-01-03 20:08 . 2008-04-13 17:23 8192 -c----w- c:\windows\system32\dllcache\asferror.dll
2010-01-03 19:51 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2010-01-03 19:49 . 2008-05-08 14:02 203136 -c----w- c:\windows\system32\dllcache\rmcast.sys
2010-01-03 19:49 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2010-01-03 19:49 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2010-01-03 19:49 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2010-01-03 19:49 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2010-01-03 19:48 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2010-01-03 19:48 . 2009-06-05 07:42 655872 -c----w- c:\windows\system32\dllcache\mstscax.dll
2010-01-03 19:48 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2010-01-03 19:48 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2010-01-03 19:48 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2010-01-03 13:31 . 2010-01-03 13:31 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Mozilla
2010-01-03 13:31 . 2010-01-03 13:31 -------- d-----w- c:\documents and settings\Guest\Local Settings\Application Data\Apple Computer
2010-01-03 05:39 . 2010-01-04 06:31 -------- d-----w- c:\documents and settings\frank\Application Data\HpUpdate
2010-01-03 05:39 . 2010-01-03 05:39 -------- d-----w- c:\windows\Hewlett-Packard
2010-01-03 05:24 . 2008-04-14 12:00 221184 ----a-w- c:\windows\system32\wmpns.dll
2010-01-03 03:48 . 2010-01-03 05:21 -------- d-----w- c:\windows\system32\wbem\Repository.001
2010-01-03 03:46 . 2010-01-03 22:14 -------- d-----w- c:\windows\ServicePackFiles
2010-01-03 02:56 . 2010-01-03 02:56 10134 ----a-r- c:\documents and settings\frank\Application Data\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2010-01-03 02:56 . 2010-01-03 05:39 -------- d-----w- c:\program files\HP
2010-01-03 02:56 . 2010-01-03 02:56 -------- d-----w- c:\windows\Downloaded Installations
2010-01-03 01:56 . 2002-08-29 09:40 20480 ----a-w- c:\windows\system32\drivers\hidserv.dll
2010-01-03 01:42 . 2004-08-02 20:20 4569 ------w- c:\windows\system32\secupd.dat
2010-01-03 01:22 . 2008-04-14 00:11 1082368 ----a-w- c:\windows\system32\esent.dll
2010-01-03 01:15 . 2010-01-16 09:35 -------- d-----w- c:\windows\system32\bits
2010-01-03 01:14 . 2010-01-17 09:02 -------- d--h--w- c:\windows\$hf_mig$
2010-01-03 01:13 . 2009-08-25 09:17 354816 ----a-w- c:\windows\system32\winhttp.dll
2010-01-03 01:13 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\qmgrprxy.dll
2010-01-03 01:12 . 2009-08-07 01:24 44768 ----a-w- c:\windows\system32\wups2.dll
2010-01-03 00:57 . 2010-01-03 00:57 -------- d-----w- C:\WUTemp
2010-01-03 00:55 . 2001-08-18 04:36 8192 -c--a-w- c:\windows\system32\dllcache\tsbyuv.dll
2010-01-03 00:54 . 2008-04-14 00:11 191488 ----a-w- c:\windows\system32\iuengine.dll
2010-01-02 22:16 . 2002-08-29 12:00 5632 -c--a-w- c:\windows\system32\dllcache\kbdfa.dll
2010-01-02 22:15 . 2002-08-29 12:00 6144 -c--a-w- c:\windows\system32\dllcache\ftpsapi2.dll
2010-01-02 22:15 . 2002-08-29 12:00 5632 -c--a-w- c:\windows\system32\dllcache\iisrstap.dll
2010-01-02 22:15 . 2002-08-29 12:00 14336 -c--a-w- c:\windows\system32\dllcache\iisreset.exe
2010-01-02 22:15 . 2008-04-13 18:45 52864 ----a-w- c:\windows\system32\drivers\dmusic.sys
2010-01-02 22:15 . 2008-04-13 18:45 6272 ----a-w- c:\windows\system32\drivers\splitter.sys
2010-01-02 22:15 . 2010-01-02 22:15 -------- d-----w- c:\documents and settings\Default User\Application Data\DivX
2010-01-02 22:12 . 2008-04-14 00:12 131584 ----a-w- c:\windows\system32\sndrec32.exe
2010-01-02 22:03 . 2008-04-13 18:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2010-01-02 22:01 . 2002-08-29 12:00 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2010-01-02 22:01 . 2002-08-29 12:00 13312 ----a-w- c:\windows\system32\irclass.dll
2010-01-02 22:01 . 2002-08-29 12:00 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2010-01-02 22:01 . 2002-08-29 12:00 24661 ----a-w- c:\windows\system32\spxcoins.dll
2010-01-02 21:40 . 2008-04-14 00:13 40840 ----a-w- c:\windows\system32\drivers\termdd.sys
2010-01-02 21:40 . 2008-04-13 18:32 196224 ----a-w- c:\windows\system32\drivers\rdpdr.sys
2010-01-02 21:39 . 2008-04-13 18:54 11264 ----a-w- c:\windows\system32\drivers\irenum.sys
2010-01-02 21:39 . 2008-04-14 00:12 146432 ----a-w- c:\windows\system\winspool.drv
2010-01-02 21:39 . 2008-04-14 00:12 74752 ----a-w- c:\windows\system32\storprop.dll
2009-12-31 20:57 . 2009-12-31 20:57 286720 ------w- c:\windows\Setup1.exe
2009-12-31 20:57 . 2009-12-31 20:57 73216 ----a-w- c:\windows\ST6UNST.EXE
2009-12-31 20:47 . 2010-01-18 00:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Norton
2009-12-31 20:47 . 2009-12-31 20:47 -------- d-----w- c:\documents and settings\All Users\Application Data\Symantec
2009-12-31 20:47 . 2009-12-31 20:47 -------- d-----w- c:\documents and settings\All Users\Application Data\NortonInstaller
2009-12-31 20:44 . 2009-12-31 20:44 -------- d-----w- c:\documents and settings\All Users\Application Data\PY_Software
2009-12-31 20:29 . 2009-12-31 21:09 -------- d-----w- c:\program files\webcam2
2009-12-31 20:17 . 2008-04-14 00:12 53760 ----a-w- c:\windows\system32\vfwwdm32.dll
2009-12-31 20:17 . 2008-04-14 00:11 4096 -c--a-w- c:\windows\system32\dllcache\ksuser.dll
2009-12-31 20:17 . 2008-04-14 00:11 4096 ----a-w- c:\windows\system32\ksuser.dll
2009-12-31 20:17 . 2009-12-31 20:17 -------- d-----w- c:\documents and settings\frank\Application Data\ManyCam
2009-12-31 20:08 . 2009-12-31 21:09 -------- d-----w- c:\program files\webcam
2009-12-31 20:02 . 2009-12-31 20:03 -------- d-----w- c:\documents and settings\frank\.yawcam
2009-12-31 20:01 . 2009-12-31 21:00 -------- d-----w- c:\program files\Yawcam
2009-12-31 01:34 . 2009-12-31 01:34 -------- d-----w- c:\program files\NOS