[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-01-15 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f816e9-20c0-11db-a73d-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{148a67e6-98fa-11dd-81ac-001676673357}]
shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a001031-20b3-11db-b386-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88636a5e-20bc-11db-b389-00038a000015}]
shell\1\command - .\RECYCLER\RECYCLER\autorun.exe
shell\2\command - .\RECYCLER\RECYCLER\autorun.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3f14450-98ea-11dd-81a8-001676673357}]
shell\AutoRun\command - H:\LaunchU3.exe -a
======List of files/folders created in the last 1 months======
2008-12-06 16:57:23 ----D---- C:\rsit
2008-12-06 16:53:59 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-12-06 16:53:47 ----D---- C:\Program Files\AVG
2008-12-05 20:37:08 ----D---- C:\Program Files\Symantec
2008-12-05 20:37:03 ----D---- C:\WINDOWS\Sun
2008-12-05 20:36:37 ----D---- C:\Config.Msi
2008-12-05 19:41:15 ----D---- C:\!KillBox
2008-12-05 13:40:03 ----D---- C:\Program Files\Trend Micro
2008-12-05 13:24:26 ----D---- C:\WINDOWS\pss
2008-12-05 13:04:21 ----D---- C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-12-05 13:04:08 ----D---- C:\Program Files\Lavasoft
2008-12-05 12:50:14 ----D---- C:\Documents and Settings\Owner\Application Data\MSNInstaller
2008-12-05 12:42:34 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
2008-12-04 22:05:29 ----D---- C:\Documents and Settings\Owner\Application Data\Sun
2008-12-04 21:05:41 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-04 15:56:02 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-12-04 15:55:25 ----D---- C:\Program Files\Mozilla Firefox
2008-12-03 21:45:45 ----D---- C:\Documents and Settings\Owner\Application Data\Help
2008-12-03 20:47:27 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-03 16:47:10 ----A---- C:\LOG3.tmp
2008-12-03 09:43:11 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-03 09:41:58 ----D---- C:\Program Files\WebMediaViewer
2008-11-22 12:17:47 ----D---- C:\Program Files\Perfect World Entertainment
2008-11-22 12:16:12 ----A---- C:\WINDOWS\system32\unicows.dll
2008-11-22 12:01:10 ----D---- C:\PW_International
2008-11-20 00:37:20 ----D---- C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-11-19 00:32:10 ----A---- C:\LOG2E.tmp
2008-11-12 00:11:41 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 00:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-12 00:11:25 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-11-12 00:11:23 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
BigFix.lnk - C:\Program Files\BigFix\bigfix.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2006-01-15 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Application Loader"
"C:\Program Files\Common Files\AOL\ACS\AOLDial.exe"="C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe"="C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:*:Enabled:AOL"
"C:\Program Files\America Online 9.0\waol.exe"="C:\Program Files\America Online 9.0\waol.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe:*:Enabled:AOLTsMon"
"C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe"="C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exe:*:Enabled:AOLTopSpeed"
"C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe"="C:\Program Files\Common Files\AOL\1154365368\EE\AOLServiceHost.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\System Information\sinf.exe"="C:\Program Files\Common Files\AOL\System Information\sinf.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\AOLSP Scheduler.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe"="C:\Program Files\Common Files\AOL\AOL Spyware Protection\asp.exe:*:Enabled:AOL"
"C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe"="C:\Program Files\Common Files\AolCoach\en_en\player\AOLNySEV.exe:*:Enabled:AOL"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\D]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09f816e9-20c0-11db-a73d-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{148a67e6-98fa-11dd-81ac-001676673357}]
shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5a001031-20b3-11db-b386-806d6172696f}]
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Info.exe folder.htt 480 480
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{88636a5e-20bc-11db-b389-00038a000015}]
shell\1\command - .\RECYCLER\RECYCLER\autorun.exe
shell\2\command - .\RECYCLER\RECYCLER\autorun.exe
shell\AutoRun\command - C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL .\RECYCLER\RECYCLER\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a3f14450-98ea-11dd-81a8-001676673357}]
shell\AutoRun\command - H:\LaunchU3.exe -a
======List of files/folders created in the last 1 months======
2008-12-06 16:57:23 ----D---- C:\rsit
2008-12-06 16:53:59 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-12-06 16:53:47 ----D---- C:\Program Files\AVG
2008-12-05 20:37:08 ----D---- C:\Program Files\Symantec
2008-12-05 20:37:03 ----D---- C:\WINDOWS\Sun
2008-12-05 20:36:37 ----D---- C:\Config.Msi
2008-12-05 19:41:15 ----D---- C:\!KillBox
2008-12-05 13:40:03 ----D---- C:\Program Files\Trend Micro
2008-12-05 13:24:26 ----D---- C:\WINDOWS\pss
2008-12-05 13:04:21 ----D---- C:\Documents and Settings\Owner\Application Data\Lavasoft
2008-12-05 13:04:08 ----D---- C:\Program Files\Lavasoft
2008-12-05 12:50:14 ----D---- C:\Documents and Settings\Owner\Application Data\MSNInstaller
2008-12-05 12:42:34 ----D---- C:\Documents and Settings\All Users\Application Data\Avg8
2008-12-04 22:05:29 ----D---- C:\Documents and Settings\Owner\Application Data\Sun
2008-12-04 21:05:41 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-04 15:56:02 ----D---- C:\Documents and Settings\Owner\Application Data\Mozilla
2008-12-04 15:55:25 ----D---- C:\Program Files\Mozilla Firefox
2008-12-03 21:45:45 ----D---- C:\Documents and Settings\Owner\Application Data\Help
2008-12-03 20:47:27 ----A---- C:\WINDOWS\ntbtlog.txt
2008-12-03 16:47:10 ----A---- C:\LOG3.tmp
2008-12-03 09:43:11 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-03 09:41:58 ----D---- C:\Program Files\WebMediaViewer
2008-11-22 12:17:47 ----D---- C:\Program Files\Perfect World Entertainment
2008-11-22 12:16:12 ----A---- C:\WINDOWS\system32\unicows.dll
2008-11-22 12:01:10 ----D---- C:\PW_International
2008-11-20 00:37:20 ----D---- C:\Documents and Settings\Owner\Application Data\GetRightToGo
2008-11-19 00:32:10 ----A---- C:\LOG2E.tmp
2008-11-12 00:11:41 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-12 00:11:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2008-11-12 00:11:25 ----N---- C:\WINDOWS\system32\spmsg.dll
2008-11-12 00:11:23 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$