wow you guys must be smart people to actually be able to make sense of these logs! here's the HJT and other log you asked for, will attach combofix next.
Deckard's System Scanner v20071014.68
Run by Daanish Rashid on 2008-02-11 12:53:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; disk is full.
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 0.07 GiB (less than 15%) free.
-- HijackThis (run as Daanish Rashid.exe) --------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56, on 2008-02-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Evolve Developmental Coaching\HypnoTutor Audio\HypnoTutorScheduler.exe
C:\WINDOWS\Explorer.EXE
c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Daanish Rashid\Local Settings\Temporary Internet Files\Content.IE5\K5U7G5EF\dss[1].exe
C:\DOCUME~1\DAANIS~1\Desktop\Daanish Rashid.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = globeandmail.com: Canada's National Newspaper
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {44709E95-7744-4123-A011-95F7B523C072} - C:\WINDOWS\system32\urqom.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {3c017d6d-b18a-3f7b-b9f4-0ea4ab90b016} - {610b09ba-4ae0-4f9b-b7f3-a81bd6d710c3} - C:\WINDOWS\system32\nmlcurof.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {771BB8CB-3DBD-4403-A0F6-8B2A42B70400} - C:\WINDOWS\system32\gebba.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9DB30F1E-538B-4395-9E49-37C1429AB459} - C:\WINDOWS\system32\khfefda.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
O4 - HKLM\..\Run: [c4ff9d44] rundll32.exe "C:\WINDOWS\system32\uwbyyueb.dll",b
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [NoteZilla] C:\Program Files\Conceptworld\NoteZilla\NoteZilla.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/ca/en/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: khfefda - khfefda.dll (file missing)
O20 - Winlogon Notify: winpcl32 - winpcl32.dll (file missing)
O21 - SSODL: PrxCheck - {fb493eaf-406b-48b9-b153-e24ea4ae3401} - C:\WINDOWS\Installer\{fb493eaf-406b-48b9-b153-e24ea4ae3401}\PrxCheck.dll (file missing)
O21 - SSODL: zip - {2655105c-5766-4797-ba96-5061ca911978} - C:\WINDOWS\Installer\{2655105c-5766-4797-ba96-5061ca911978}\zip.dll (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Training Schedule for the HypnoTutor Training Application (HypnoTutor Training Schedule) - Unknown owner - C:\Program Files\Evolve Developmental Coaching\HypnoTutor Audio\HypnoTutorScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe
O23 - Service: OracleServiceXE - Oracle Corporation - c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
O23 - Service: OracleXEClrAgent - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe
O23 - Service: OracleXETNSListener - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
--
End of file - 8506 bytes
-- HijackThis Fixed Entries (C:\DOCUME~1\DAANIS~1\Desktop\backups\) ------------
backup-20080211-014933-233 O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
backup-20080211-014933-544 O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
backup-20080211-014933-837 O4 - HKLM\..\Run: [c4ff9d44] rundll32.exe "C:\WINDOWS\system32\uwbyyueb.dll",b
backup-20080211-014933-870 O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 vkquwexg - c:\windows\system32\drivers\combo-fix.sys (file missing)
S3 LMImirr - c:\windows\system32\drivers\lmimirr.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 HypnoTutor Training Schedule (Training Schedule for the HypnoTutor Training Application) - "c:\program files\evolve developmental coaching\hypnotutor audio\hypnotutorscheduler.exe" /install /service <Not Verified; ; HypnoTutorScheduler Application>
R2 OracleServiceXE - c:\oraclexe\app\oracle\product\10.2.0\server\bin\oracle.exe xe <Not Verified; Oracle Corporation; >
R2 OracleXETNSListener - c:\oraclexe\app\oracle\product\10.2.0\server\bin\tnslsnr.exe
S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
S3 OracleMTSRecoveryService - c:\oraclexe\app\oracle\product\10.2.0\server\bin\omtsreco.exe "oraclemtsrecoveryservice" <Not Verified; Oracle Corporation; Oracle MTS Recovery Service>
S3 OracleXEClrAgent - c:\oraclexe\app\oracle\product\10.2.0\server\bin\oraclragnt.exe agent_sid=clrextproc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25
S3 SandraDataSrv (Sandra Data Service) - c:\program files\sisoftware\sisoftware sandra lite 2005.sr3\rpcdatasrv.exe <Not Verified; SiSoftware; SiSoftware Sandra 2005.SR3>
S3 SandraTheSrv (Sandra Service) - c:\program files\sisoftware\sisoftware sandra lite 2005.sr3\rpcsandrasrv.exe <Not Verified; SiSoftware; SiSoftware Sandra 2005.SR3>
S4 OracleJobSchedulerXE - c:\oraclexe\app\oracle\product\10.2.0\server\bin\extjob.exe xe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
Device ID: PCI\VEN_1317&DEV_0985&SUBSYS_05741317&REV_11\3&61AAA01&0&70
Manufacturer: Linksys
Name: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
PNP Device ID: PCI\VEN_1317&DEV_0985&SUBSYS_05741317&REV_11\3&61AAA01&0&70
Service: AN983
-- Scheduled Tasks -------------------------------------------------------------
2008-02-03 06:21:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-01-11 and 2008-02-11 -----------------------------
2008-02-11 03:38:26 0 d-------- C:\Program Files\EsetOnlineScanner
2008-02-11 03:36:36 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\HouseCall 6.6
2008-02-11 03:36:26 0 d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-02-11 02:02:03 60416 --a------ C:\WINDOWS\system32\drivers\ComboFix.sys
2008-02-11 01:38:46 0 dr-h----- C:\$VAULT$.AVG
2008-02-11 01:21:57 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\AVG7
2008-02-11 01:21:11 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2008-02-11 01:19:43 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-02-11 01:19:43 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2008-02-10 23:13:42 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-02-10 22:50:13 0 d-------- C:\cmdcons
2008-02-10 22:46:57 68096 --a------ C:\WINDOWS\system32\zip.exe
2008-02-10 22:46:57 98816 --a------ C:\WINDOWS\system32\sed.exe
2008-02-10 22:46:57 80412 --a------ C:\WINDOWS\system32\grep.exe
2008-02-10 22:46:57 73728 --a------ C:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-10 22:46:50 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-02-10 22:17:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-02-10 22:16:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-02-10 22:08:56 15 --a------ C:\WINDOWS\system32\c4ff8fca
2008-02-10 12:56:36 0 dr-h----- C:\Documents and Settings\Daanish Rashid\Recent
2008-02-09 11:51:53 691545 --a------ C:\WINDOWS\unins000.exe
2008-02-09 11:51:53 3469 --a------ C:\WINDOWS\unins000.dat
2008-02-09 11:39:56 0 d-------- C:\Program Files\SysCleaner
2008-02-09 11:35:44 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\SystemDefender
2008-02-09 11:34:27 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\errclean
2008-02-09 11:33:41 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-02-01 06:41:58 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\TechSmith
2008-02-01 06:41:29 0 d-------- C:\Program Files\TechSmith
2008-02-01 06:39:12 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 06:38:19 0 d-------- C:\Program Files\MediaMonkey
2008-02-01 06:35:17 0 d-------- C:\Program Files\IrfanView
2008-01-31 00:32:29 0 d-------- C:\Program Files\Ares
2008-01-31 00:30:36 0 d-------- C:\Program Files\WallPerformer 2.0
2008-01-31 00:30:31 0 d-------- C:\Program Files\DocPad
2008-01-31 00:30:00 0 d-------- C:\Program Files\Common Files\System-G
2008-01-30 14:36:53 0 d-------- C:\Program Files\eMule
2008-01-18 22:51:55 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Ashampoo
2008-01-18 21:53:04 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ashampoo
2008-01-18 21:50:24 0 d-------- C:\Program Files\Ashampoo
2008-01-18 21:43:35 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Obsidium
2008-01-18 21:42:40 0 d--h----- C:\Documents and Settings\All Users.WINDOWS\Application Data\{1A6E8DCF-3BC3-4C53-A3E9-CF66F0B2C556}
2008-01-18 21:41:57 0 d-------- C:\Program Files\Oront Burning Kit 2
2008-01-18 21:37:00 0 d-------- C:\Program Files\Instant CD & DVD Burner
2008-01-18 21:36:53 0 d-------- C:\Program Files\Easy MPEG AVI DIVX WMV RM to DVD
2008-01-18 18:45:58 0 d-------- C:\Program Files\GetData
2008-01-18 18:45:40 0 d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-01-14 21:07:05 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\CyberLink
2008-01-14 21:04:57 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-01-14 21:02:35 0 d-------- C:\Program Files\CyberLink
2008-01-14 00:57:09 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Conceptworld
2008-01-14 00:56:49 0 d-------- C:\Program Files\Conceptworld
2008-01-13 02:58:13 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\3M
2008-01-13 02:55:14 0 d-------- C:\Program Files\3M
2008-01-11 04:22:58 0 d-------- C:\Documents and Settings\Daanish Rashid\.housecall6.6
-- Find3M Report ---------------------------------------------------------------
2008-02-11 01:14:29 0 d-------- C:\Program Files\FastStone Image Viewer
2008-02-10 22:40:29 0 d-------- C:\Program Files\iCal v4.0 Web Calendar
2008-02-10 12:52:07 0 d-------- C:\Program Files\Opera
2008-02-10 12:37:11 0 d-------- C:\Program Files\ewido anti-spyware 4.0
2008-02-09 16:35:35 0 d-a------ C:\Program Files\Common Files
2008-02-07 14:18:15 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\uTorrent
2008-02-03 23:15:21 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\LimeWire
2008-02-03 00:56:20 0 d-------- C:\Program Files\Shareaza Lite
2008-01-30 20:52:55 0 d-------- C:\Program Files\Winamp
2008-01-30 20:52:44 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\foobar2000
2008-01-14 21:02:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-13 05:07:23 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\dvdcss
2008-01-09 23:14:53 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\GRETECH
2008-01-09 23:00:20 0 d-------- C:\Program Files\Total Video Player
2008-01-09 22:59:11 0 d-------- C:\Program Files\MP4 Video Player
2008-01-09 22:58:48 0 d-------- C:\Program Files\FLV Player
2008-01-09 22:56:30 0 d-------- C:\Program Files\GRETECH
2008-01-09 16:34:44 0 d-------- C:\Program Files\Microsoft Visual Studio .NET
2008-01-09 05:18:16 11270 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-28 19:37:18 0 d-------- C:\Program Files\Alcovarp
2007-12-28 19:03:12 0 d-------- C:\Program Files\RocketDock
2007-12-28 18:57:30 0 d-------- C:\Program Files\CrossLoop
2007-12-24 20:06:41 0 d-------- C:\Program Files\BearFlix
2007-12-24 19:47:56 0 dr-h----- C:\Documents and Settings\Daanish Rashid\Application Data\yahoo!
2007-12-20 11:36:56 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\SlimBrowser
2007-12-19 22:58:33 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Azureus
2007-12-19 16:19:42 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Ulead Systems
2007-12-19 11:25:22 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Flock
2007-12-19 11:24:58 0 d-------- C:\Program Files\Flock
2007-12-19 08:09:45 0 d-------- C:\Program Files\DivX
2007-12-19 08:08:13 0 d-------- C:\Program Files\Mozilla Thunderbird
2007-12-18 11:47:21 0 d-------- C:\Program Files\MSN Messenger
Deckard's System Scanner v20071014.68
Run by Daanish Rashid on 2008-02-11 12:53:22
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Failed to create restore point; disk is full.
Backed up registry hives.
Performed disk cleanup.
System Drive C: has 0.07 GiB (less than 15%) free.
-- HijackThis (run as Daanish Rashid.exe) --------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:56, on 2008-02-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\Program Files\Evolve Developmental Coaching\HypnoTutor Audio\HypnoTutorScheduler.exe
C:\WINDOWS\Explorer.EXE
c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Daanish Rashid\Local Settings\Temporary Internet Files\Content.IE5\K5U7G5EF\dss[1].exe
C:\DOCUME~1\DAANIS~1\Desktop\Daanish Rashid.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = globeandmail.com: Canada's National Newspaper
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {44709E95-7744-4123-A011-95F7B523C072} - C:\WINDOWS\system32\urqom.dll (file missing)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: {3c017d6d-b18a-3f7b-b9f4-0ea4ab90b016} - {610b09ba-4ae0-4f9b-b7f3-a81bd6d710c3} - C:\WINDOWS\system32\nmlcurof.dll (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: (no name) - {771BB8CB-3DBD-4403-A0F6-8B2A42B70400} - C:\WINDOWS\system32\gebba.dll (file missing)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: (no name) - {9DB30F1E-538B-4395-9E49-37C1429AB459} - C:\WINDOWS\system32\khfefda.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
O4 - HKLM\..\Run: [c4ff9d44] rundll32.exe "C:\WINDOWS\system32\uwbyyueb.dll",b
O4 - HKCU\..\Run: [LogitechSoftwareUpdate] "C:\Program Files\Logitech\Video\ManifestEngine.exe" boot
O4 - HKCU\..\Run: [NoteZilla] C:\Program Files\Conceptworld\NoteZilla\NoteZilla.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_8 -reboot 1
O4 - HKCU\..\Run: [Spoolsv] C:\WINDOWS\system32\spoolvs.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scan8/oscan8.cab
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/ca/en/securityadvisor/virusinfo/webscan.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab34246.cab
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL
O20 - Winlogon Notify: khfefda - khfefda.dll (file missing)
O20 - Winlogon Notify: winpcl32 - winpcl32.dll (file missing)
O21 - SSODL: PrxCheck - {fb493eaf-406b-48b9-b153-e24ea4ae3401} - C:\WINDOWS\Installer\{fb493eaf-406b-48b9-b153-e24ea4ae3401}\PrxCheck.dll (file missing)
O21 - SSODL: zip - {2655105c-5766-4797-ba96-5061ca911978} - C:\WINDOWS\Installer\{2655105c-5766-4797-ba96-5061ca911978}\zip.dll (file missing)
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Program Files\Ares\chatServer.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Training Schedule for the HypnoTutor Training Application (HypnoTutor Training Schedule) - Unknown owner - C:\Program Files\Evolve Developmental Coaching\HypnoTutor Audio\HypnoTutorScheduler.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: OracleMTSRecoveryService - Oracle Corporation - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\omtsreco.exe
O23 - Service: OracleServiceXE - Oracle Corporation - c:\oraclexe\app\oracle\product\10.2.0\server\bin\ORACLE.EXE
O23 - Service: OracleXEClrAgent - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\bin\OraClrAgnt.exe
O23 - Service: OracleXETNSListener - Unknown owner - C:\oraclexe\app\oracle\product\10.2.0\server\BIN\tnslsnr.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR3\RpcSandraSrv.exe
--
End of file - 8506 bytes
-- HijackThis Fixed Entries (C:\DOCUME~1\DAANIS~1\Desktop\backups\) ------------
backup-20080211-014933-233 O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
backup-20080211-014933-544 O4 - HKLM\..\Run: [ucookw] "C:\PROGRA~1\ErrClean\ucookw.exe" -start
backup-20080211-014933-837 O4 - HKLM\..\Run: [c4ff9d44] rundll32.exe "C:\WINDOWS\system32\uwbyyueb.dll",b
backup-20080211-014933-870 O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
S0 vkquwexg - c:\windows\system32\drivers\combo-fix.sys (file missing)
S3 LMImirr - c:\windows\system32\drivers\lmimirr.sys (file missing)
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
R2 HypnoTutor Training Schedule (Training Schedule for the HypnoTutor Training Application) - "c:\program files\evolve developmental coaching\hypnotutor audio\hypnotutorscheduler.exe" /install /service <Not Verified; ; HypnoTutorScheduler Application>
R2 OracleServiceXE - c:\oraclexe\app\oracle\product\10.2.0\server\bin\oracle.exe xe <Not Verified; Oracle Corporation; >
R2 OracleXETNSListener - c:\oraclexe\app\oracle\product\10.2.0\server\bin\tnslsnr.exe
S3 AresChatServer (Ares Chatroom server) - c:\program files\ares\chatserver.exe <Not Verified; Ares Development Group; Ares Chat Server>
S3 OracleMTSRecoveryService - c:\oraclexe\app\oracle\product\10.2.0\server\bin\omtsreco.exe "oraclemtsrecoveryservice" <Not Verified; Oracle Corporation; Oracle MTS Recovery Service>
S3 OracleXEClrAgent - c:\oraclexe\app\oracle\product\10.2.0\server\bin\oraclragnt.exe agent_sid=clrextproc max_dispatchers=2 tcp_dispatchers=0 max_task_threads=6 max_sessions=25
S3 SandraDataSrv (Sandra Data Service) - c:\program files\sisoftware\sisoftware sandra lite 2005.sr3\rpcdatasrv.exe <Not Verified; SiSoftware; SiSoftware Sandra 2005.SR3>
S3 SandraTheSrv (Sandra Service) - c:\program files\sisoftware\sisoftware sandra lite 2005.sr3\rpcsandrasrv.exe <Not Verified; SiSoftware; SiSoftware Sandra 2005.SR3>
S4 OracleJobSchedulerXE - c:\oraclexe\app\oracle\product\10.2.0\server\bin\extjob.exe xe
-- Device Manager: Disabled ----------------------------------------------------
Class GUID: {4D36E972-E325-11CE-BFC1-08002BE10318}
Description: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
Device ID: PCI\VEN_1317&DEV_0985&SUBSYS_05741317&REV_11\3&61AAA01&0&70
Manufacturer: Linksys
Name: Linksys LNE100TX Fast Ethernet Adapter(LNE100TX v4)
PNP Device ID: PCI\VEN_1317&DEV_0985&SUBSYS_05741317&REV_11\3&61AAA01&0&70
Service: AN983
-- Scheduled Tasks -------------------------------------------------------------
2008-02-03 06:21:01 284 --a------ C:\WINDOWS\Tasks\AppleSoftwareUpdate.job
-- Files created between 2008-01-11 and 2008-02-11 -----------------------------
2008-02-11 03:38:26 0 d-------- C:\Program Files\EsetOnlineScanner
2008-02-11 03:36:36 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\HouseCall 6.6
2008-02-11 03:36:26 0 d-------- C:\WINDOWS\system32\HouseCall 6.6
2008-02-11 02:02:03 60416 --a------ C:\WINDOWS\system32\drivers\ComboFix.sys
2008-02-11 01:38:46 0 dr-h----- C:\$VAULT$.AVG
2008-02-11 01:21:57 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\AVG7
2008-02-11 01:21:11 0 d-------- C:\Documents and Settings\LocalService.NT AUTHORITY\Application Data\AVG7
2008-02-11 01:19:43 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\Grisoft
2008-02-11 01:19:43 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg7
2008-02-10 23:13:42 0 d-------- C:\Documents and Settings\Administrator\Application Data\PC Tools
2008-02-10 22:50:13 0 d-------- C:\cmdcons
2008-02-10 22:46:57 68096 --a------ C:\WINDOWS\system32\zip.exe
2008-02-10 22:46:57 98816 --a------ C:\WINDOWS\system32\sed.exe
2008-02-10 22:46:57 80412 --a------ C:\WINDOWS\system32\grep.exe
2008-02-10 22:46:57 73728 --a------ C:\WINDOWS\system32\fdsv.exe <Not Verified; Smallfrogs Studio; >
2008-02-10 22:46:50 53248 --a------ C:\WINDOWS\PSEXESVC.EXE <Not Verified; Sysinternals; Sysinternals PsExec>
2008-02-10 22:17:17 0 d-------- C:\Documents and Settings\Administrator\Application Data\Macromedia
2008-02-10 22:16:24 0 d-------- C:\Documents and Settings\Administrator\Application Data\Mozilla
2008-02-10 22:08:56 15 --a------ C:\WINDOWS\system32\c4ff8fca
2008-02-10 12:56:36 0 dr-h----- C:\Documents and Settings\Daanish Rashid\Recent
2008-02-09 11:51:53 691545 --a------ C:\WINDOWS\unins000.exe
2008-02-09 11:51:53 3469 --a------ C:\WINDOWS\unins000.dat
2008-02-09 11:39:56 0 d-------- C:\Program Files\SysCleaner
2008-02-09 11:35:44 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\SystemDefender
2008-02-09 11:34:27 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\errclean
2008-02-09 11:33:41 0 dr------- C:\Documents and Settings\All Users.WINDOWS\Application Data\SalesMon
2008-02-01 06:41:58 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\TechSmith
2008-02-01 06:41:29 0 d-------- C:\Program Files\TechSmith
2008-02-01 06:39:12 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-02-01 06:38:19 0 d-------- C:\Program Files\MediaMonkey
2008-02-01 06:35:17 0 d-------- C:\Program Files\IrfanView
2008-01-31 00:32:29 0 d-------- C:\Program Files\Ares
2008-01-31 00:30:36 0 d-------- C:\Program Files\WallPerformer 2.0
2008-01-31 00:30:31 0 d-------- C:\Program Files\DocPad
2008-01-31 00:30:00 0 d-------- C:\Program Files\Common Files\System-G
2008-01-30 14:36:53 0 d-------- C:\Program Files\eMule
2008-01-18 22:51:55 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Ashampoo
2008-01-18 21:53:04 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\ashampoo
2008-01-18 21:50:24 0 d-------- C:\Program Files\Ashampoo
2008-01-18 21:43:35 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Obsidium
2008-01-18 21:42:40 0 d--h----- C:\Documents and Settings\All Users.WINDOWS\Application Data\{1A6E8DCF-3BC3-4C53-A3E9-CF66F0B2C556}
2008-01-18 21:41:57 0 d-------- C:\Program Files\Oront Burning Kit 2
2008-01-18 21:37:00 0 d-------- C:\Program Files\Instant CD & DVD Burner
2008-01-18 21:36:53 0 d-------- C:\Program Files\Easy MPEG AVI DIVX WMV RM to DVD
2008-01-18 18:45:58 0 d-------- C:\Program Files\GetData
2008-01-18 18:45:40 0 d-a------ C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-01-14 21:07:05 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\CyberLink
2008-01-14 21:04:57 0 d-------- C:\Documents and Settings\All Users.WINDOWS\Application Data\CyberLink
2008-01-14 21:02:35 0 d-------- C:\Program Files\CyberLink
2008-01-14 00:57:09 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Conceptworld
2008-01-14 00:56:49 0 d-------- C:\Program Files\Conceptworld
2008-01-13 02:58:13 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\3M
2008-01-13 02:55:14 0 d-------- C:\Program Files\3M
2008-01-11 04:22:58 0 d-------- C:\Documents and Settings\Daanish Rashid\.housecall6.6
-- Find3M Report ---------------------------------------------------------------
2008-02-11 01:14:29 0 d-------- C:\Program Files\FastStone Image Viewer
2008-02-10 22:40:29 0 d-------- C:\Program Files\iCal v4.0 Web Calendar
2008-02-10 12:52:07 0 d-------- C:\Program Files\Opera
2008-02-10 12:37:11 0 d-------- C:\Program Files\ewido anti-spyware 4.0
2008-02-09 16:35:35 0 d-a------ C:\Program Files\Common Files
2008-02-07 14:18:15 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\uTorrent
2008-02-03 23:15:21 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\LimeWire
2008-02-03 00:56:20 0 d-------- C:\Program Files\Shareaza Lite
2008-01-30 20:52:55 0 d-------- C:\Program Files\Winamp
2008-01-30 20:52:44 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\foobar2000
2008-01-14 21:02:41 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-01-13 05:07:23 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\dvdcss
2008-01-09 23:14:53 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\GRETECH
2008-01-09 23:00:20 0 d-------- C:\Program Files\Total Video Player
2008-01-09 22:59:11 0 d-------- C:\Program Files\MP4 Video Player
2008-01-09 22:58:48 0 d-------- C:\Program Files\FLV Player
2008-01-09 22:56:30 0 d-------- C:\Program Files\GRETECH
2008-01-09 16:34:44 0 d-------- C:\Program Files\Microsoft Visual Studio .NET
2008-01-09 05:18:16 11270 --ahs---- C:\WINDOWS\system32\KGyGaAvL.sys
2007-12-28 19:37:18 0 d-------- C:\Program Files\Alcovarp
2007-12-28 19:03:12 0 d-------- C:\Program Files\RocketDock
2007-12-28 18:57:30 0 d-------- C:\Program Files\CrossLoop
2007-12-24 20:06:41 0 d-------- C:\Program Files\BearFlix
2007-12-24 19:47:56 0 dr-h----- C:\Documents and Settings\Daanish Rashid\Application Data\yahoo!
2007-12-20 11:36:56 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\SlimBrowser
2007-12-19 22:58:33 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Azureus
2007-12-19 16:19:42 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Ulead Systems
2007-12-19 11:25:22 0 d-------- C:\Documents and Settings\Daanish Rashid\Application Data\Flock
2007-12-19 11:24:58 0 d-------- C:\Program Files\Flock
2007-12-19 08:09:45 0 d-------- C:\Program Files\DivX
2007-12-19 08:08:13 0 d-------- C:\Program Files\Mozilla Thunderbird
2007-12-18 11:47:21 0 d-------- C:\Program Files\MSN Messenger