…Part 3
– Files created between 2007-04-26 and 2007-05-26 -----------------------------
2007-05-26 10:00:25 8704 --a------ C:\WINDOWS\system32\drivers\amathsifvidv.sys
2007-05-25 20:16:02 0 d–h----- C:\Documents and Settings\Administrator\Templates
2007-05-25 20:16:02 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2007-05-25 20:16:02 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2007-05-25 20:16:02 0 d–h----- C:\Documents and Settings\Administrator\Recent
2007-05-25 20:16:02 0 d–h----- C:\Documents and Settings\Administrator\PrintHood
2007-05-25 20:16:02 229376 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2007-05-25 20:16:02 0 d–h----- C:\Documents and Settings\Administrator\NetHood
2007-05-25 20:16:02 0 dr------- C:\Documents and Settings\Administrator\My Documents
2007-05-25 20:16:02 0 dr-h----- C:\Documents and Settings\Administrator\Local Settings
2007-05-25 20:16:02 0 d-------- C:\Documents and Settings\Administrator\Favorites
2007-05-25 20:16:02 0 d-------- C:\Documents and Settings\Administrator\Desktop
2007-05-25 20:16:02 0 d—s---- C:\Documents and Settings\Administrator\Cookies
2007-05-25 20:16:02 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2007-05-25 20:16:02 0 d—s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2007-05-25 18:02:51 0 d-------- C:\HiJackThis
2007-05-25 15:42:13 0 d-------- C:\Program Files\a-squared Free
2007-05-24 21:23:25 0 d-------- C:\VundoFix Backups
2007-05-24 21:09:45 0 d-------- C:\Program Files\Spyware Doctor
2007-05-24 21:09:45 0 d-------- C:\Documents and Settings\user\Application Data\PC Tools
2007-05-24 20:21:57 209526 --a------ C:\WINDOWS\system32\vrsyeutj.exe
2007-05-24 07:10:58 2 --a------ C:\752151790
2007-05-24 07:08:10 1536 --a------ C:\xxxcwainda.exe
2007-05-15 18:56:59 0 d-------- C:\MoTeC
2007-05-15 18:56:57 0 d-------- C:\Program Files\MoTeC
2007-04-27 16:21:03 0 d-------- C:\Program Files\GTR2
– Find3M Report ---------------------------------------------------------------
2007-05-26 07:29:27 0 d-------- C:\Program Files\WhatsRunning
2007-05-25 21:16:02 0 d-------- C:\Documents and Settings\user\Application Data\wsInspector
2007-05-25 17:34:53 0 d-------- C:\Documents and Settings\user\Application Data\VMware
2007-05-24 19:26:54 0 d-------- C:\Documents and Settings\user\Application Data\Simple Sudoku
2007-05-10 20:03:36 0 d-------- C:\Program Files\Simple Sudoku
2007-04-02 18:11:35 0 d-------- C:\Program Files\EA SPORTS
2007-04-01 22:11:41 0 d–h----- C:\Program Files\InstallShield Installation Information
2007-03-31 16:18:05 0 d-------- C:\Program Files\Common Files\Logitech
2007-03-31 16:17:57 0 d-------- C:\Program Files\Logitech
– Registry Dump ---------------------------------------------------------------
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{53707962-6F74-2D53-2644-206D7942484F} C:\PROGRA~1\SPYBOT~1\SDHelper.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
“avast!”=“C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe”
“NvCplDaemon”=“RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup”
“!AVG Anti-Spyware”=“"C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized”
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
“InstallVisualStyle”=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,
63,65,73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,5c,52,6f,79,61,6c,65,2e,
6d,73,73,74,79,6c,65,73,00
“InstallTheme”=hex(2):43,3a,5c,57,49,4e,44,4f,57,53,5c,52,65,73,6f,75,72,63,65,
73,5c,54,68,65,6d,65,73,5c,52,6f,79,61,6c,65,2e,74,68,65,6d,65,00
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
“DisableRegistryTools”=dword:00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
“{A00ED310-6EE3-4764-883D-F0B833AEC645}”=“”
“{57B86673-276A-48B2-BAE7-C6DBB3020EB8}”=“AVG Anti-Spyware 7.5”
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Authentication Packages REG_MULTI_SZ msv1_0\0\0
Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0
Notification Packages REG_MULTI_SZ scecli\0\0
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdauxservice
HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\sdcoreservice
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
“Auto EPSON Stylus C84 Series on VALUED-ECECF7F4”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P47 "Auto EPSON Stylus C84 Series on VALUED-ECECF7F4" /O26 "\\VALUED-ECECF7F4\Printer4" /M "Stylus C84"”
“EPSON Stylus C84 Series”=“C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I2D1.EXE /P23 "EPSON Stylus C84 Series" /O6 "USB001" /M "Stylus C84"”
“NeroFilterCheck”=“C:\WINDOWS\system32\NeroCheck.exe”
“RemoteControl”=“"C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"”
[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
HTTPFilter REG_MULTI_SZ HTTPFilter\0\0
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
WudfServiceGroup REG_MULTI_SZ WUDFSvc\0\0
newlycreated - HKEY_LOCAL_MACHINE\system\currentcontrolset\enum\root\LEGACY_RPCLOCATOR
– End of Deckard’s System Scanner: finished at 2007-05-26 at 10:38:48 ---------