I still cant connect to the internet after running ComboFix and manually rebooting.
ComboFix 11-12-17.02 - Matt 12/17/2011 12:47:03.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3327.2677 [GMT -5:00]
Running from: c:\documents and settings\Matt\Desktop\ComboFix.exe
AV: AntiVir Desktop *Enabled/Updated* {AD166499-45F9-482A-A743-FDD3350758C7}
FW: ZoneAlarm Free Firewall *Enabled* {829BDA32-94B3-44F4-8446-F8FCFF809F8B}
* Created a new restore point
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\All Users\Application Data\TEMP
c:\documents and settings\All Users\Start Menu\Programs\Startup\hpoddt01.exe.lnk
c:\documents and settings\Matt\Application Data\0ad
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_b_2b376348.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_back_b_acede9c5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_back_f_1172e536.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_f_650392a8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_sm_b_2058e11d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\aspis_sm_f_0e33fc1c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\brontoburger_1637e35e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\bush_med_a_56d9464a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\camel_1_56c3caa3.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_civic3_5678dbdf.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_civic3_arch_7357fda4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_civic3_props_1_617ec9fb.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_civic3_props_new_d29a4c50.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_house_d_a9abd5fb.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_house_d_color_d4e90631.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_house_d_swrd_88ba9482.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_sb_mud_e9be350f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_tavern_mud_430aed82.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_tavern_props_1_bac648fd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_tavern_props_new_c8253467.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\celt_tavern_struct_48fbd2c1.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\column_doric_0776de3c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\column_doric_top_fd2585ac.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\column_fallen_b_b282195e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\column_fallen_d_661eaef4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\column_fallen_e_fcda05a5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_celt_farmstead_1ffbfb6b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_stone_medit_a_64c20099.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_struct_2x2_bb0a9d58.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_struct_4x4_847289c9.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_struct_5x5_d8b838fd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_struct_6x6_d8b838fd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\decal_struct_small_3cb6c9fd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_antlers_62f175c5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_attack_01_1c1cd99b.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_death_01_04a20dcf.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_death_02_e28936ad.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_idle_01_26d889ae.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_idle_02_6ef8cec7.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_idle_03_fba22ff9.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_idle_04_1879aa74.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_mesh_190478eb.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_run_01_11d6431c.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_walk_01_e014b932.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\deer_walk_02_adec388d.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_build_01_10388f8a.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_death_01_9a948fd7.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_dress_609f2cc5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_farm_01_b545b415.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_gather_01_80eab784.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_idle_01_0d3607ec.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_lumber_01_a864cfdc.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_mine_01_14b02b9b.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_tunic_dca55adf.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\f_walk_01_f7c584ac.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\fence_stone_a_89543ef4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\field_grain_fadd9c8b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\field_plot_fac9f879.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\floating_barrels_a4c9426a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_2x2_a_719c147b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_3x3_a_1bdee415.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_3x3_b_808cba18.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_3x3_c_07bcb9b1.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_4x4_a_6ba93c63.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_5x5_b_ac0145ab.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_6x6_a_1bdfe8c3.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\found_wall_long_a_b40ffbb7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\gazelle_horns_41bf04e2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_01_815f2478.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_02_4df80f8c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_03_d2baaa47.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_04_271cc93e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_05_2b1bea85.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_medit_06_4d19b740.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_mineral_01_83973d93.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\geo_mineral_02_c8cfdf54.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\giraffe_adult_64264132.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_boeotian_highcrest_686b0065.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_props_e407ea78.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_round_e073247b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_shields_3d291143.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_struct_77fbefa7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_tiles_short_5d802ebe.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_civic_trees_761c522a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_corral_3a9e7aea.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_corral_ceiling_0e452e5d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_corral_decal_b59afa4e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_corral_doors_a43ced9d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_corral_roof_6f314862.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_farmstead_9dfbaa20.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_farmstead_hay_967b0a56.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_farmstead_props_d0a4535c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_fishing_boat_05b4ae40.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_fortress_ca02be30.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_fortress_gate_a67feb69.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_fortress_props_4302fd72.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_fortress_shields_ec509759.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gate_c11b68b0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gate_door_96776e27.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gate_props_2cd0a223.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gym_331b65e9.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gym_props_21751360.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gym_shields_b6917978.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_gym_tiles_3576768c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_highcrest_3b50dea4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_a_c1c87ec8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_a_props_b3a40ef3.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_a_shields_11e4378f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_b_32faa4c2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_b_gables_813ae04d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_b_props_327a4459.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_b_shields_1313e4a0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_c_a821621b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_c_gables_1cb805c3.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_c_props_a5329be5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_house_c_shields_1ab32e5c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_kyrenia_8221d9d8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_mill_blocks_54728411.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_mill_c3b2551f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_mill_props_3151071b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_mill_roof_0519b4c2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_mill_wood_ee81f6dc.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_pilos_simple_ac1bd050.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_scout_tower_da657c27.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_scout_tower_f_75484344.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_scout_tower_p_39729fac.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_spartan_king_e116432f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa_base_35593db5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa_props_a_8c1e455c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa_props_b_a2a2504b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa_props_roof_131719fa.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa2_base_f95b7b3e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa2_props_new_2a950484.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa2_shields_6f8866c7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa2_tiles_8f52092d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_stoa2_trees_5cc084ea.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_a_base_6106a8a0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_a_props_7aa2dec7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_a_struct_dcd5a291.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_b_base_5a7cd0d2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_b_props_215da87d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_b_struct_3116d6e8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_c_base_5a7cd0d2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_temple_c_props_11dac8fd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_wall_med_298051bf.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_wall_tower_15d8099c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\hele_wall_tower_props_ca640cb8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\helmet_corinthian_dual_2b823299.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\helmet_thracian_4_8e093aa8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\inf_sword_ready_a_f6472116.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\inf_sword_ready_e_a4d588b4.psa
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\kyrenia_cargo_1ee304ba.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\kyrenia_sail_5aa6f0d5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\kyrenia_shield_1f567e64.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\luggage_female_back_632dd2d6.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\m_cape_long_cf7c1f75.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\m_cape_medium_bb0b9023.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\m_pants_celt_218489bb.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\m_tunic_long_7a242836.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\m_tunic_short_99946f8a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\mace_helmet_hellenistic_pilos_feathers_8263c511.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\onager_projectile_9f880bae.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_antefixes_bd83f98d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_props_6c647d27.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_roof_b8608b6b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_steps_edd30d21.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_struct_691184ae.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\parth_walls_06004604.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\pegasus_wings_3eac6d9c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\pers_tri_b302e9da.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\pers_tri_mast_41ef9bbd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\pers_tri_oars_aa44095c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\plant_desert_01_7719aae9.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\plant_desert_02_7c08abb5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\pond_lillies_large_210895ed.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\projectile-bolt_de967894.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_coolus_a_18d4672a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_coolus_c_be8c6e30.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_coolus_d_3f09c2b3.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_coolus_e_7c8376ef.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_coolus_g_542a055c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_gallicg_cent_a_7b98e234.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_qui_cb3e3880.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_qui_oars_b12ca965.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_qui_oars2_0e384079.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\rome_qui_props_0a5a0cbd.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\sarissa_b_4ed94927.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\shield_cape_0d0dcff7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\shipwreck_hull_2_c8a64ad7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\shipwreck_hull_7c12e793.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\shipwreck_sail_2_f3d0d051.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\spear_hoplite_23ccbfc4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\temple_unfinished_5b764fd5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\temple_unfinished_columns_f75c91d0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_top_a_c7353ff4.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_top_b_ae3dc341.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_top_c_8e12ac1f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_top_d_3961fb97.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_trunk_a_3dce9a1c.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_apple_trunk_b_272495ab.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_top_a_dbaff66e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_top_b_8cdaf308.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_top_c_cfc9343a.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_top_d_3c284d58.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_trunk_a_cd1fe4fc.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_trunk_b_b75438d7.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_trunk_c_447488fe.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_baobab_trunk_d_83c94450.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_large_53f03310.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_med_e9007f6b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_skinny_11f99d3f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_sm_714576e6.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_tall_e0c3e3c8.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_cypress_xlarge_e7f00551.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_pine_02_d3c86c1b.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_pine_03_7b6f987d.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_01_08871445.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_02_ea2f0dbf.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_03_9f8b7dd0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_04_8eaae39f.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_05_004e54a2.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_06_90fab0b5.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_07_6a1fe473.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\tree_senegal_08_2ad1255e.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\underbrush_01_50378327.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\underbrush_02_bcd682f0.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\wildebeest_adult_39532537.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\wildebeest_juvenile_4a0d8713.pmd
c:\documents and settings\Matt\Application Data\0ad\cache\mods\public\public.zip\wood_shuttle_36212f0f.pmd
c:\documents and settings\Matt\Application Data\0ad\config\profiles\default\settings\history
c:\documents and settings\Matt\Application Data\0ad\logs\interestinglog.html
c:\documents and settings\Matt\Application Data\0ad\logs\mainlog.html
c:\documents and settings\Matt\Application Data\0ad\logs\sim_log\1340\commands.txt
c:\documents and settings\Matt\Application Data\0ad\logs\sim_log\3384\commands.txt
c:\documents and settings\Matt\Application Data\0ad\logs\sim_log\4708\commands.txt
c:\documents and settings\Matt\Application Data\0ad\logs\sim_log\4904\commands.txt
c:\documents and settings\Matt\Application Data\0ad\logs\sim_log\5704\commands.txt
c:\documents and settings\Matt\Application Data\0ad\logs\system_info.txt
c:\documents and settings\Matt\Application Data\Adobe\plugs
c:\documents and settings\Matt\Application Data\Adobe\shed
C:\install.exe
c:\windows\$NtUninstallKB13206$
c:\windows\$NtUninstallKB13206$\1040479395
c:\windows\$NtUninstallKB13206$\292019470\@
c:\windows\$NtUninstallKB13206$\292019470\L\jvtnikve
c:\windows\CSC\d6
c:\windows\system32\Cache
.
.
((((((((((((((((((((((((( Files Created from 2011-11-17 to 2011-12-17 )))))))))))))))))))))))))))))))
.
.
2011-12-15 02:54 . 2011-12-15 02:54 -------- d-----w- c:\documents and settings\NetworkService\Application Data\Apple Computer
2011-12-13 23:12 . 2011-12-13 23:13 -------- d-----w- c:\program files\Webcam
2011-12-13 12:10 . 2001-08-23 12:00 5632 -c--a-w- c:\windows\system32\dllcache\smimsgif.dll
2011-12-13 12:10 . 2001-08-23 12:00 5632 -c--a-w- c:\windows\system32\dllcache\smierrsy.dll
2011-12-13 12:10 . 2001-08-23 12:00 5632 ----a-w- c:\windows\system32\wbem\snmp\smimsgif.dll
2011-12-13 12:10 . 2001-08-23 12:00 5632 ----a-w- c:\windows\system32\wbem\snmp\smierrsy.dll
2011-12-13 12:10 . 2001-08-23 12:00 15872 -c--a-w- c:\windows\system32\dllcache\smierrsm.dll
2011-12-13 12:10 . 2001-08-23 12:00 15872 ----a-w- c:\windows\system32\wbem\snmp\smierrsm.dll
2011-12-13 12:10 . 2001-08-23 12:00 10240 -c--a-w- c:\windows\system32\dllcache\snmpstup.dll
2011-12-13 12:10 . 2001-08-23 12:00 10240 ----a-w- c:\windows\system32\wbem\snmpstup.dll
2011-12-13 12:05 . 2001-08-23 12:00 18944 -c--a-w- c:\windows\system32\dllcache\simptcp.dll
2011-12-13 12:05 . 2001-08-23 12:00 18944 ----a-w- c:\windows\system32\simptcp.dll
2011-12-13 03:40 . 2011-12-13 03:40 -------- d-----w- c:\windows\OPTIONS
2011-12-13 02:49 . 2001-08-23 12:00 9216 -c--a-w- c:\windows\system32\dllcache\wamps51.dll
2011-12-13 02:46 . 2008-04-14 00:12 10752 ----a-w- c:\windows\system32\smtpapi.dll
2011-12-13 02:46 . 2008-04-14 00:12 9728 ----a-w- c:\windows\system32\rwnh.dll
2011-12-13 02:46 . 2011-12-13 02:50 -------- d-----w- C:\Inetpub
2011-12-13 02:27 . 2004-08-04 03:31 20992 -c--a-w- c:\windows\system32\dllcache\rtl8139.sys
2011-12-13 02:27 . 2004-08-04 03:31 20992 ----a-w- c:\windows\system32\drivers\RTL8139.sys
2011-12-04 19:09 . 2011-12-04 19:09 -------- d-----w- c:\documents and settings\Matt\Application Data\AnvSoft
2011-12-04 19:09 . 2011-12-04 19:09 -------- d-----w- c:\program files\AnvSoft
2011-12-04 18:49 . 2011-12-12 02:55 -------- d-sh--w- c:\documents and settings\Matt\Local Settings\Application Data\1167dd0e
2011-12-04 18:49 . 2011-12-04 18:49 -------- d-----w- c:\documents and settings\Matt\Application Data\Foxreal
2011-12-04 18:48 . 2011-09-06 16:07 66944 ----a-w- c:\windows\system32\drivers\thdudf.sys
2011-11-22 04:21 . 2011-11-22 04:21 -------- d-----w- c:\documents and settings\Matt\Local Settings\Application Data\VS Revo Group
2011-11-22 04:21 . 2009-12-30 16:20 27064 ----a-w- c:\windows\system32\drivers\revoflt.sys
2011-11-22 04:21 . 2011-11-22 04:21 -------- d-----w- c:\program files\VS Revo Group
2011-11-20 05:27 . 2011-11-20 05:27 -------- d-----w- c:\program files\iPod
2011-11-18 03:12 . 2011-11-18 03:12 -------- d-----w- c:\program files\Common Files\Java
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-11-20 16:51 . 2011-06-22 17:41 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-10-24 19:29 . 2011-10-24 19:29 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2011-10-24 19:29 . 2011-10-24 19:29 69632 ----a-w- c:\windows\system32\QuickTime.qts
2011-10-10 14:22 . 2009-09-11 03:20 692736 ----a-w- c:\windows\system32\inetcomm.dll
2011-10-03 10:06 . 2010-04-23 16:19 472808 ----a-w- c:\windows\system32\deployJava1.dll
2011-10-03 07:37 . 2009-09-12 05:09 73728 ----a-w- c:\windows\system32\javacpl.cpl
2011-09-28 07:06 . 2004-08-04 05:56 599040 ----a-w- c:\windows\system32\crypt32.dll
2011-09-26 15:41 . 2008-07-29 23:59 611328 ----a-w- c:\windows\system32\uiautomationcore.dll
2011-09-26 15:41 . 2001-08-23 12:00 220160 ----a-w- c:\windows\system32\oleacc.dll
2011-09-26 15:41 . 2001-08-23 12:00 20480 ----a-w- c:\windows\system32\oleaccrc.dll
2011-03-18 17:53 . 2011-04-24 20:15 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" [2008-06-24 1840424]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"MusicManager"="c:\documents and settings\Matt\Local Settings\Application Data\Programs\Google\MusicManager\MusicManager.exe" [2011-11-12 13222400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoxioEngineUtility"="c:\program files\Common Files\Roxio Shared\System\EngUtil.exe" [2003-01-13 69632]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2010-03-13 91520]
"36X Raid Configurer"="c:\windows\system32\xRaidSetup.exe" [2010-09-07 1976920]
"SSBkgdUpdate"="c:\program files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" [2006-10-25 210472]
"PaperPort PTD"="c:\program files\ScanSoft\PaperPort\pptd40nt.exe" [2008-07-10 29984]
"IndexSearch"="c:\program files\ScanSoft\PaperPort\IndexSearch.exe" [2008-07-10 46368]
"PPort11reminder"="c:\program files\ScanSoft\PaperPort\Ereg\Ereg.exe" [2007-08-31 328992]
"ControlCenter3"="c:\program files\Brother\ControlCenter3\brctrcen.exe" [2008-12-24 114688]
"BrStsMon00"="c:\program files\Browny02\Brother\BrStMonW.exe" [2010-02-09 2621440]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe" [2010-12-14 47904]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-05-05 102400]
"NeroFilterCheck"="c:\program files\Common Files\Nero\Lib\NeroCheck.exe" [2008-07-09 570664]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 10.0\Reader\Reader_sl.exe" [2011-09-05 35736]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"RTHDCPL"="RTHDCPL.EXE" [2008-12-26 18081280]
"LogMeIn Hamachi Ui"="c:\program files\LogMeIn Hamachi\hamachi-2-ui.exe" [2011-08-15 1955208]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2011-09-07 40376]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2010-09-22 640440]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2011-04-21 281768]
"APSDaemon"="c:\program files\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-09-27 59240]
"HostManager"="c:\program files\Common Files\AOL\1252996968\ee\AOLSoftware.exe" [2010-03-08 41800]
"PC Monitor Operations"="c:\program files\PC Monitor\pcmontask.exe" [2011-12-05 121152]
"ISW"="c:\program files\CheckPoint\ZAForceField\ForceField.exe" [2011-11-03 738944]
"ZoneAlarm"="c:\program files\CheckPoint\ZoneAlarm\zatray.exe" [2011-11-10 73360]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2011-06-09 254696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-11-13 421736]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2011-10-24 421888]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"RunNarrator"="Narrator.exe" [2008-04-14 53760]
"tscuninstall"="c:\windows\system32\tscupgrd.exe" [2004-08-03 44544]
.
c:\documents and settings\Matt\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
.
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2011-08-07 113024]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2009-09-03 22:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.DLL
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\!SASCORE]
@=""
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Air Mouse.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Air Mouse.lnk
backup=c:\windows\pss\Air Mouse.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Matt^Start Menu^Programs^Startup^OneNote 2010 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Matt\Start Menu\Programs\Startup\OneNote 2010 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2010 Screen Clipper and Launcher.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Matt^Start Menu^Programs^Startup^Stay On Top.lnk]
path=c:\documents and settings\Matt\Start Menu\Programs\Startup\Stay On Top.lnk
backup=c:\windows\pss\Stay On Top.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DivXUpdate]
2010-09-16 20:04 1164584 ----a-w- c:\program files\DivX\DivX Update\DivXUpdate.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
"DisableMonitoring"=dword:00000001
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Call of Duty\\CoDMP.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\acs\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1252996968\\ee\\aolsoftware.exe"=
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Common Files\\AOL\\TopSpeed\\3.0\\aoltpsd3.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\System Information\\sinf.exe"=
"c:\\Program Files\\Battlefield 2\\BF2.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\Battlefield 2\\BF2VoipServer.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Steam\\steamapps\\mattardz\\dedicated server\\hlds.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\WINDOWS\\pchealth\\helpctr\\binaries\\helpctr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\ooVoo\\ooVoo.exe"=
"c:\\Program Files\\Steam\\steamapps\\mattardz\\sourcesdk\\bin\\SDKLauncher.exe"=
"c:\\Program Files\\Steam\\steam.exe"=
"c:\\Documents and Settings\\Matt\\Local Settings\\Application Data\\0 A.D. alpha\\binaries\\system\\pyrogenesis.exe"=
"c:\\Program Files\\Firaxis Games\\Sid Meier's Civilization 4\\Civilization4.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Microsoft Games\\Project S\\Spartan.exe"=
"c:\\Documents and Settings\\Matt\\Local Settings\\Application Data\\Google\\Chrome\\Application\\chrome.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Microsoft Office\\Office14\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\ONENOTE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office14\\OUTLOOK.EXE"=
"c:\\Program Files\\Google\\Google Earth\\client\\googleearth.exe"=
"c:\\Program Files\\EA Games\\Battlefield Play4Free\\BFP4f.exe"=
"c:\\Program Files\\Air Mouse\\Air Mouse\\Air Mouse.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\bin\\SDKLauncher.exe"=
"c:\\Program Files\\Steam\\steamapps\\mattardz\\team fortress 2\\hl2.exe"=
"c:\\Documents and Settings\\Matt\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\swarm.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\alien swarm\\srcds.exe"=
"c:\\Documents and Settings\\Matt\\Application Data\\Spotify\\spotify.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\AOL Desktop 9.6\\waol.exe"=
"c:\\Program Files\\AOL Desktop 9.6\\AOLBrowser\\aolbrowser.exe"=
"c:\\Program Files\\Battlelog Web Plugins\\Sonar\\0.70.3\\SonarHost.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"67:UDP"= 67:UDP:DHCP Discovery Service
"443:TCP"= 443:TCP:*:Disabled:ooVoo TCP port 443
"443:UDP"= 443:UDP:*:Disabled:ooVoo UDP port 443
"37674:TCP"= 37674:TCP:*:Disabled:ooVoo TCP port 37674
"37674:UDP"= 37674:UDP:*:Disabled:ooVoo UDP port 37674
"37675:UDP"= 37675:UDP:*:Disabled:ooVoo UDP port 37675
"10001:TCP"= 10001:TCP:*:Disabled:ooVoo TCP port 10001
"10001:UDP"= 10001:UDP:*:Disabled:ooVoo UDP port 10001
"10002:UDP"= 10002:UDP:*:Disabled:ooVoo UDP port 10002
"37676:TCP"= 37676:TCP:*:Disabled:ooVoo TCP port 37676
"37676:UDP"= 37676:UDP:*:Disabled:ooVoo UDP port 37676
"37677:UDP"= 37677:UDP:*:Disabled:ooVoo UDP port 37677
"37675:TCP"= 37675:TCP:*:Disabled:ooVoo TCP port 37675
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management
"54925:UDP"= 54925:UDP:BrotherNetwork Scanner
"3587:TCP"= 3587:TCP:Windows Peer-to-Peer Grouping
"3540:UDP"= 3540:UDP:Peer Name Resolution Protocol (PNRP)
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings]
"AllowInboundEchoRequest"= 1 (0x1)
.
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\SASDIFSV.SYS [2/17/2010 1:25 PM 12880]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [5/10/2010 1:41 PM 67664]
R2 !SASCORE;SAS Core Service;c:\program files\SUPERAntiSpyware\SASCORE.EXE [6/29/2010 12:48 PM 116608]
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [9/12/2011 6:59 PM 136360]
R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files\LogMeIn Hamachi\hamachi-2.exe [8/15/2011 3:18 PM 1361288]
R2 Iprip;RIP Listener;c:\windows\System32\svchost.exe -k netsvcs [8/4/2004 12:56 AM 14336]
R2 ISWKL;ZoneAlarm Toolbar ISWKL;c:\program files\CheckPoint\ZAForceField\ISWKL.sys [11/3/2011 9:44 AM 27016]
R2 IswSvc;ZoneAlarm Toolbar IswSvc;c:\program files\CheckPoint\ZAForceField\ISWSVC.exe [11/3/2011 9:44 AM 497280]
R2 PC Monitor;PC Monitor;c:\program files\PC Monitor\PCMonitorSrv.exe [8/8/2011 2:59 PM 313152]
R2 thdudf;TOSHIBA UDF2.5 Reader File System Driver;c:\windows\system32\drivers\thdudf.sys [12/4/2011 1:48 PM 66944]
R3 BrYNSvc;BrYNSvc;c:\program files\Browny02\BrYNSvc.exe [2/13/2011 6:57 PM 245760]
S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [8/26/2010 7:36 PM 691696]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 12:16 PM 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/28/2009 11:03 PM 135664]
S3 Aken;Aken;c:\documents and settings\Matt\Local Settings\Application Data\0 A.D. alpha\binaries\system\aken.sys [6/17/2007 5:29 AM 3712]
S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [9/10/2009 10:43 PM 1684736]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [11/28/2009 11:03 PM 135664]
S3 icsak;icsak;\??\c:\program files\CheckPoint\ZAForceField\AK\icsak.sys --> c:\program files\CheckPoint\ZAForceField\AK\icsak.sys [?]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [9/14/2009 11:38 PM 22216]
S3 MEMSWEEP2;MEMSWEEP2;\??\c:\windows\system32\E3.tmp --> c:\windows\system32\E3.tmp [?]
S3 Microsoft SharePoint Workspace Audit Service;Microsoft SharePoint Workspace Audit Service;c:\program files\Microsoft Office\Office14\GROOVE.EXE [6/12/2011 10:15 AM 31125880]
S3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [1/9/2010 9:37 PM 4640000]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [11/21/2011 11:21 PM 27064]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [8/4/2004 12:56 AM 14336]
S3 wod0205;WeOnlyDo Network Adapter 2.5;c:\windows\system32\drivers\wod0205.sys [9/12/2011 4:54 PM 28936]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 12:16 PM 753504]
S4 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [9/14/2009 11:39 PM 366152]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc
.
Contents of the 'Scheduled Tasks' folder
.
2011-12-13 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 21:57]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-29 04:03]
.
2011-12-17 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-29 04:03]
.
2011-12-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-1659004503-725345543-1003Core.job
- c:\documents and settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-11 20:59]
.
2011-12-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-343818398-1659004503-725345543-1003UA.job
- c:\documents and settings\Matt\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-11 20:59]
.
2011-12-17 c:\windows\Tasks\User_Feed_Synchronization-{27331CC7-789B-42EB-92F7-7C7C8981C86A}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
2011-12-17 c:\windows\Tasks\User_Feed_Synchronization-{8553B989-AA05-4D87-84A6-FE85AAD0FCD4}.job
- c:\windows\system32\msfeedssync.exe [2009-03-08 08:31]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = local
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - /105
TCP: DhcpNameServer = 192.168.10.1
DPF: {7E1C8369-99C1-46BA-86C7-1BF331ADEB2B} - hxxps://www51.honeywell.com/checkbrowser/ax/CBSystemCheck.CAB
FF - ProfilePath - c:\documents and settings\Matt\Application Data\Mozilla\Firefox\Profiles\xcgcf8sm.default\
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
- - - - ORPHANS REMOVED - - - -
.
HKCU-Run-DriverMax - (no file)
HKCU-Run-DriverMax_RESTART - (no file)
MSConfigStartUp-LogMeIn Hamachi Ui - c:\program files\Hamachi\hamachi-2-ui.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-12-17 13:07
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet005\Services\MEMSWEEP2]
"ImagePath"="\??\c:\windows\system32\E3.tmp"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5
977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,00,5e,04,06,b1,7f,4b,a5,d0,2e,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839
E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,82,00,5e,04,06,b1,7f,4b,a5,d0,2e,\
.
[HKEY_USERS\S-1-5-21-343818398-1659004503-725345543-1003\Software\Microsoft\SystemCertificates\AddressBook*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(828)
c:\program files\SUPERAntiSpyware\SASWINLO.DLL
c:\windows\system32\WININET.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'lsass.exe'(892)
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
.
- - - - - - - > 'explorer.exe'(3044)
c:\windows\system32\WININET.dll
c:\program files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\progra~1\COMMON~1\MICROS~1\OFFICE14\Cultures\office.odf
c:\progra~1\MICROS~2\Office14\1033\GrooveIntlResource.dll
c:\program files\iTunes\iTunesMiniPlayer.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\en.lproj\iTunesMiniPlayerLocalized.dll
c:\program files\iTunes\iTunesMiniPlayer.Resources\iTunesMiniPlayer.dll
c:\program files\Windows Media Player\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\program files\WinSCP\DragExt.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Google\Update\1.3.21.79\GoogleCrashHandler.exe
c:\program files\Brother\ControlCenter3\brccMCtl.exe
c:\windows\RTHDCPL.EXE
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\SpywareGuard\sgbhp.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\program files\Avira\AntiVir Desktop\avguard.exe
c:\program files\Common Files\AOL\ACS\AOLAcsd.exe
c:\program files\Avira\AntiVir Desktop\avshadow.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Nero\Nero BackItUp 4\NBService.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\windows\system32\SearchIndexer.exe
c:\windows\system32\wscntfy.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\avira\antivir desktop\avcenter.exe
.
**************************************************************************
.
Completion time: 2011-12-17 13:11:47 - machine was rebooted
ComboFix-quarantined-files.txt 2011-12-17 18:11
.
Pre-Run: 93,546,213,376 bytes free
Post-Run: 93,801,197,568 bytes free
.
- - End Of File - - 25DEA0840561AD36EA08AE590BEDBC68