Code:
Directory of C:\
11/09/2006 20:12 43 filelist.txt
11/09/2006 19:26 805,306,368 pagefile.sys
10/09/2006 13:55 194 boot.ini
10/09/2006 12:44 11,651,953 AVG7QT.DAT
08/08/2006 20:30 0 CONFIG.SYS
08/08/2006 20:30 0 AUTOEXEC.BAT
Directory of C:\WINDOWS\system32
10/09/2006 12:34 2,184 wpa.dbl
Directory of C:\WINDOWS\Prefetch
11/09/2006 20:12 5,428 FIND.EXE-0EC32F1E.pf
11/09/2006 20:12 14,722 CMD.EXE-087B4001.pf
11/09/2006 20:10 26,240 WINZIP32.EXE-335422C1.pf
11/09/2006 20:06 96,872 IEXPLORE.EXE-27122324.pf
11/09/2006 20:06 16,880 MSNAPPAU.EXE-07139F47.pf
11/09/2006 20:06 22,740 RUNDLL32.EXE-38471A59.pf
11/09/2006 20:05 75,466 SKYPE.EXE-30AE1A60.pf
11/09/2006 20:05 14,184 WDBTNMGR.EXE-31AFAE50.pf
11/09/2006 20:05 10,756 RUNDLL32.EXE-2F41AAED.pf
11/09/2006 20:05 14,962 RUNDLL32.EXE-14C12299.pf
11/09/2006 20:05 6,728 DSLAGENT.EXE-11E24C1A.pf
11/09/2006 20:05 11,580 JUSCHED.EXE-04D31062.pf
11/09/2006 20:05 9,650 E_S4I0F2.EXE-38412DBF.pf
11/09/2006 20:05 11,706 WINLOGON.EXE-39D8E673.pf
11/09/2006 20:04 16,206 WUAUCLT.EXE-399A8E72.pf
11/09/2006 19:46 518,738 Layout.ini
11/09/2006 19:34 9,910 SSMYST.SCR-1CCCF0DC.pf
11/09/2006 19:28 1,122,014 NTOSBOOT-B00DFAAD.pf
11/09/2006 19:23 17,134 LOGONUI.EXE-0AF22957.pf
11/09/2006 19:23 102,720 WMIPRVSE.EXE-28F301A9.pf
11/09/2006 19:17 68,176 UPDATE.EXE-0845AB52.pf
11/09/2006 19:12 67,632 UPDATE.EXE-05F883CC.pf
11/09/2006 18:48 6,338 DUMPREP.EXE-1B46F901.pf
11/09/2006 18:47 22,648 SYMNRT.EXE-05594C6F.pf
11/09/2006 18:46 5,382 ATTRIB.EXE-39EAFB02.pf
11/09/2006 18:43 49,270 MSIEXEC.EXE-2F8A8CAE.pf
11/09/2006 18:42 19,800 LSETUP.EXE-32559C46.pf
11/09/2006 18:41 5,424 VCCLNUP0.EXE-01F3DBF1.pf
11/09/2006 18:41 37,832 VCSETUP.EXE-1F28DAD9.pf
11/09/2006 18:41 11,472 IRALRSHL.EXE-1773AE0D.pf
11/09/2006 18:41 19,176 CCPWDSVC.EXE-0711D107.pf
11/09/2006 18:41 71,930 NMAIN.EXE-2BA406E0.pf
11/09/2006 18:41 9,566 SEVINST.EXE-2A7737B0.pf
11/09/2006 18:40 69,726 LUCOMS~1.EXE-02DB5950.pf
11/09/2006 18:40 10,718 SYMLCSVC.EXE-0775DAC9.pf
11/09/2006 18:40 8,452 MSI17D.TMP-3B9AC87C.pf
11/09/2006 18:40 18,276 MSI145.TMP-36E10647.pf
11/09/2006 18:39 34,870 SBSERV.EXE-32089713.pf
11/09/2006 18:39 58,968 NAVAPSVC.EXE-0156D7E2.pf
11/09/2006 18:39 10,312 SAVSCAN.EXE-2CDAEA23.pf
11/09/2006 18:38 9,320 NPROTECT.EXE-12B4D3FB.pf
11/09/2006 18:38 10,058 NOPDB.EXE-09B28FA3.pf
11/09/2006 18:38 32,400 {71E7B3F5-CFAF-4C1E-B494-528E-06397DFF.pf
11/09/2006 18:31 47,942 RUNDLL32.EXE-35BB92D4.pf
11/09/2006 18:29 50,934 SPYBOTSD.EXE-1344276B.pf
11/09/2006 18:29 11,708 UPDATE.EXE-131667C7.pf
11/09/2006 18:21 83,898 NAVW32.EXE-286920DF.pf
11/09/2006 18:20 75,412 LUCALLBACKPROXY.EXE-19ED7806.pf
11/09/2006 18:20 40,500 AUPDATE.EXE-2253CB60.pf
11/09/2006 18:19 76,334 HELPCTR.EXE-3862B6F5.pf
11/09/2006 18:19 12,396 RDSADDIN.EXE-36B76CAD.pf
11/09/2006 18:19 93,702 WINLOGON.EXE-32C57D49.pf
11/09/2006 18:19 9,940 USERINIT.EXE-30B18140.pf
11/09/2006 18:19 47,784 CSRSS.EXE-12B63473.pf
11/09/2006 18:18 61,270 OPSCAN.EXE-20B6A0BA.pf
11/09/2006 18:18 114,928 OUTLOOK.EXE-1E64345B.pf
11/09/2006 18:18 16,360 RDSHOST.EXE-38C57D5D.pf
11/09/2006 18:17 9,542 RCIMLBY.EXE-29F11D7B.pf
11/09/2006 18:16 218,710 HELPSVC.EXE-2878DDA2.pf
11/09/2006 18:16 41,276 MSMSGS.EXE-2B6052DE.pf
11/09/2006 18:11 24,704 UPDATE.EXE-278456E6.pf
11/09/2006 18:11 12,294 BITSINST.EXE-2CB4826B.pf
11/09/2006 18:11 70,908 UPDATE.EXE-2726CBE7.pf
11/09/2006 18:07 24,222 REGSVR32.EXE-25EEFE2F.pf
11/09/2006 18:04 69,116 WINWORD.EXE-29F5CB89.pf
11/09/2006 17:21 34,666 DFRGNTFS.EXE-269967DF.pf
11/09/2006 17:21 11,376 DEFRAG.EXE-273F131E.pf
11/09/2006 16:50 26,066 QW.EXE-340E9CC2.pf
11/09/2006 16:44 100,556 OUTLOOK.EXE-27D5965C.pf
11/09/2006 15:30 27,752 WCESMGR.EXE-2FB86E92.pf
10/09/2006 21:17 36,922 YUPDATER.EXE-3946FDDF.pf
10/09/2006 21:16 13,476 WMIAPSRV.EXE-1E2270A5.pf
10/09/2006 21:16 62,060 YPAGER.EXE-31587640.pf
10/09/2006 21:14 111,200 MSNMSGR.EXE-366A1A81.pf
10/09/2006 21:03 58,918 AUTOROUT.EXE-1500E64C.pf
10/09/2006 19:56 21,690 YMSGR_TRAY.EXE-256366BA.pf
10/09/2006 19:05 33,394 VCGPROXYFILEMANAGER.EXE-2CE11B52.pf
10/09/2006 19:05 12,860 CPSHELPRUNNER.EXE-22868065.pf
10/09/2006 19:05 77,672 ROXWIZARDLAUNCHER.EXE-0BFB0399.pf
10/09/2006 18:11 28,160 SESSMGR.EXE-25E7D5E1.pf
10/09/2006 18:10 12,880 CIT200.EXE-3874993E.pf
10/09/2006 18:09 27,600 CCAPP.EXE-1207B2A5.pf
10/09/2006 18:09 10,024 CTFMON.EXE-0E17969B.pf
10/09/2006 18:09 9,974 USRPRMPT.EXE-2F2D32EA.pf
10/09/2006 18:09 6,802 SNDMON.EXE-0A6C21A2.pf
10/09/2006 16:40 53,900 MSMONEY.EXE-002A94C1.pf
10/09/2006 15:44 17,958 WCESCOMM.EXE-062FDF7F.pf
10/09/2006 15:44 18,300 AVGCC.EXE-36A38F59.pf
10/09/2006 15:12 36,474 AD-AWARE.EXE-3262F7A9.pf
10/09/2006 14:28 86,246 NAVW32.EXE-365BADC3.pf
10/09/2006 13:12 62,466 ACRORD32.EXE-0781811F.pf
10/09/2006 12:49 40,950 DRWTSN32.EXE-2B4B52AC.pf
10/09/2006 12:49 54,558 DWWIN.EXE-30875ADC.pf
08/09/2006 16:45 21,940 RASAUTOU.EXE-18B88A68.pf
07/09/2006 21:03 5,878 NET.EXE-01A53C2F.pf
07/09/2006 21:03 8,310 NET1.EXE-029B9DB4.pf
07/09/2006 21:03 4,948 SC.EXE-012262AF.pf
97 File(s) 5,132,238 bytes
0 Dir(s) 62,920,204,288 bytes free
Directory of C:\WINDOWS
11/09/2006 20:12 430,087 WindowsUpdate.log
11/09/2006 19:26 0 0.log
11/09/2006 19:26 159 wiadebug.log
11/09/2006 19:26 50 wiaservc.log
11/09/2006 19:26 2,048 bootstat.dat
11/09/2006 19:25 32,444 SchedLgU.Txt
11/09/2006 19:23 50,789 svcpack.log
11/09/2006 19:20 68,516 setupapi.log
11/09/2006 18:41 5,185 SYMEVENT.LOG
11/09/2006 18:12 9,412 WGA.log
11/09/2006 18:11 2,053 comsetup.log
11/09/2006 18:11 1,247 ntdtcsetup.log
11/09/2006 18:11 7,951 iis6.log
11/09/2006 18:11 2,809 tsoc.log
11/09/2006 18:11 1,374 imsins.log
11/09/2006 18:11 5,789 KB842773.log
11/09/2006 18:11 303 msgsocm.log
11/09/2006 18:11 212 ocmsn.log
11/09/2006 18:11 2,480 ocgen.log
11/09/2006 18:11 6,182 FaxSetup.log
11/09/2006 18:11 1,904 msmqinst.log
11/09/2006 18:11 4,395 setupact.log
11/09/2006 18:11 0 setuperr.log
11/09/2006 18:02 1,840 QUICKEN.INI
11/09/2006 18:02 123 INTUIT.INI
10/09/2006 17:55 78,620 ntbtlog.txt
10/09/2006 13:55 599 win.ini
10/09/2006 13:55 227 system.ini
10/09/2006 13:52 79,360 Thumbs.db
10/09/2006 13:51 116 NeroDigital.ini
03/09/2006 16:19 3,448 urls.dat
03/09/2006 16:19 3,448 htmlcode.dat
23/08/2006 17:15 308 cina.ini
Directory of C:\WINDOWS\tasks
11/09/2006 19:26 6 SA.DAT
23/08/2001 13:00 65 desktop.ini
Directory of C:\DOCUME~1\temp\LOCALS~1\Temp
11/09/2006 20:06 408 WCESCOMM.LOG
11/09/2006 20:06 1,110 jusched.log
11/09/2006 19:23 3,784,053 SymNRT 9-11-2006 18h47m9s.log
11/09/2006 18:47 0 SPR2AC.tmp
11/09/2006 18:47 0 SPR2AB.tmp
11/09/2006 18:42 36,668 symcprop.dat
11/09/2006 18:42 291 SNDunin.log
11/09/2006 18:42 3,926,608 Norton SystemWorks 2005 9-11-2006 18h38m33s.log
11/09/2006 18:41 3,192 LSInstall.log
11/09/2006 18:39 124 SSALiveUpdate.dat
11/09/2006 18:39 124 AVRES_OPTRF_LiveUpdate.dat
11/09/2006 18:24 14,525 wcesmgr.log
11/09/2006 18:19 80,856 dat1A.tmp
11/09/2006 18:16 11,300 MPC19.tmp
11/09/2006 18:16 280 MSIf732.LOG
11/09/2006 18:16 483 outstore.log
11/09/2006 18:15 280 MSIf731.LOG
11/09/2006 18:06 280 MSIaf447.LOG
11/09/2006 18:06 280 MSIaf446.LOG
11/09/2006 18:05 280 MSI90661.LOG
11/09/2006 18:05 280 MSI90660.LOG
11/09/2006 16:44 280 MSI127a.LOG
11/09/2006 16:44 280 MSI1279.LOG
11/09/2006 16:37 280 MSI97712.LOG
11/09/2006 16:37 280 MSI97711.LOG
11/09/2006 15:24 280 MSI641b0.LOG
11/09/2006 15:24 280 MSI641af.LOG
11/09/2006 15:19 280 MSI1121c.LOG
11/09/2006 15:19 280 MSI1121b.LOG
10/09/2006 21:17 280 MSI9247d.LOG
10/09/2006 21:17 280 MSI9247c.LOG
10/09/2006 21:17 16,384 ~DFFDCC.tmp
10/09/2006 21:06 280 MSIe96b4.LOG
10/09/2006 21:06 280 MSIe96b3.LOG
10/09/2006 19:47 21,176 ukwm22.bmp
10/09/2006 19:47 21,176 ukpink.bmp
10/09/2006 19:47 14,136 ukcars.bmp
10/09/2006 19:47 21,176 ukjt.bmp
10/09/2006 19:47 7,428 peanuts.bmp
10/09/2006 19:47 8,120 doodle.bmp
10/09/2006 19:47 7,556 dilbert.bmp
10/09/2006 19:47 8,120 hearts.bmp
10/09/2006 18:11 280 MSIe5c94.LOG
10/09/2006 18:11 280 MSIe5c93.LOG
10/09/2006 18:10 280 MSId490f.LOG
10/09/2006 16:41 280 MSIe401b.LOG
10/09/2006 16:41 280 MSIe401a.LOG
10/09/2006 15:45 280 MSIa01d7.LOG
10/09/2006 15:45 280 MSIa01d6.LOG
10/09/2006 14:20 280 MSI22407.LOG
10/09/2006 14:20 280 MSI22406.LOG
10/09/2006 14:20 520 WcesView.log
10/09/2006 13:16 80,856 datC0.tmp
10/09/2006 13:05 280 MSId53ff.LOG
10/09/2006 13:05 280 MSId53fe.LOG
10/09/2006 12:34 32,768 ~DF8977.tmp
10/09/2006 12:34 16,384 ~DF5D75.tmp
02/02/2006 21:23 2,422,984 Patch_MSN_Messenger.exe
i have also spent some time removing a trojan and have removed norton. the new hi jack this log is below.