ComboFix 09-03-18.01 - Becky 2009-03-19 11:37:10.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1535.1092 [GMT -4:00]
Running from: c:\documents and settings\Becky\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Becky\Desktop\CFScript.txt
AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated)
* Created a new restore point
FILE ::
C:\found.000
c:\windows\system32\nfr.assembly
c:\windows\t55ft2807f44.dat
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Becky\Desktop\notepad.exe
C:\found.000
c:\found.000\file0000.chk
c:\windows\9g234sdfdfgjf23\
c:\windows\system32\nfr.assembly
c:\windows\system32\nfr.gpref\
c:\windows\t55ft2807f44.dat
.
((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))
.
2009-03-18 19:09 . 2009-03-18 19:09 410,984 --a------ c:\windows\system32\deploytk.dll
2009-03-18 18:42 . 2009-03-18 18:42 <DIR> d-------- c:\documents and settings\Becky\Application Data\Malwarebytes
2009-03-18 18:42 . 2009-02-11 10:19 15,504 --a------ c:\windows\system32\drivers\mbam.sys
2009-03-18 18:41 . 2009-03-18 18:42 <DIR> d-------- c:\program files\Malwarebytes' Anti-Malware
2009-03-18 18:41 . 2009-03-18 18:41 <DIR> d-------- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-03-18 18:41 . 2009-02-11 10:19 38,496 --a------ c:\windows\system32\drivers\mbamswissarmy.sys
2009-03-18 15:11 . 2009-03-18 15:11 <DIR> d-------- c:\program files\SUPERAntiSpyware
2009-03-18 15:11 . 2009-03-18 15:11 <DIR> d-------- c:\program files\Common Files\Wise Installation Wizard
2009-03-18 15:11 . 2009-03-18 15:11 <DIR> d-------- c:\documents and settings\Becky\Application Data\SUPERAntiSpyware.com
2009-03-18 15:04 . 2009-03-18 15:04 <DIR> d-------- c:\program files\CCleaner
2009-03-17 15:50 . 2008-04-13 20:12 116,224 --a--c--- c:\windows\system32\dllcache\xrxwiadr.dll
2009-03-17 15:50 . 2001-08-17 22:37 99,865 --a--c--- c:\windows\system32\dllcache\xlog.exe
2009-03-17 15:50 . 2001-08-17 22:37 27,648 --a--c--- c:\windows\system32\dllcache\xrxftplt.exe
2009-03-17 15:50 . 2001-08-17 22:36 23,040 --a--c--- c:\windows\system32\dllcache\xrxwbtmp.dll
2009-03-17 15:50 . 2004-08-03 22:29 19,455 --a--c--- c:\windows\system32\dllcache\wvchntxx.sys
2009-03-17 15:50 . 2008-04-13 20:12 18,944 --a--c--- c:\windows\system32\dllcache\xrxscnui.dll
2009-03-17 15:50 . 2001-08-17 12:11 16,970 --a--c--- c:\windows\system32\dllcache\xem336n5.sys
2009-03-17 15:50 . 2004-08-03 22:29 12,063 --a--c--- c:\windows\system32\dllcache\wsiintxx.sys
2009-03-17 15:50 . 2008-04-13 14:36 8,832 --a--c--- c:\windows\system32\dllcache\wmiacpi.sys
2009-03-17 15:50 . 2008-04-13 20:12 8,192 --a--c--- c:\windows\system32\dllcache\wshirda.dll
2009-03-17 15:50 . 2001-08-17 22:37 4,608 --a--c--- c:\windows\system32\dllcache\xrxflnch.exe
2009-03-17 15:48 . 2001-08-17 22:36 525,568 --a--c--- c:\windows\system32\dllcache\tridxp.dll
2009-03-17 15:47 . 2001-08-17 22:36 495,616 --a--c--- c:\windows\system32\dllcache\sblfx.dll
2009-03-17 15:46 . 2001-08-17 13:28 899,146 --a--c--- c:\windows\system32\dllcache\r2mdkxga.sys
2009-03-17 15:45 . 2001-08-17 12:50 198,144 --a--c--- c:\windows\system32\dllcache\nv3.sys
2009-03-17 15:44 . 2001-08-17 13:28 802,683 --a--c--- c:\windows\system32\dllcache\ltsm.sys
2009-03-17 15:43 . 2008-04-13 20:11 702,845 --a--c--- c:\windows\system32\dllcache\i81xdnt5.dll
2009-03-17 15:42 . 2001-08-17 14:56 1,733,120 --a--c--- c:\windows\system32\dllcache\g400d.dll
2009-03-17 15:41 . 2001-08-17 12:14 952,007 --a--c--- c:\windows\system32\dllcache\diwan.sys
2009-03-17 15:40 . 2001-08-17 12:13 980,034 --a--c--- c:\windows\system32\dllcache\cicap.sys
2009-03-17 15:33 . 2001-08-17 13:28 871,388 --a--c--- c:\windows\system32\dllcache\bcmdm.sys
2009-03-17 15:32 . 2001-08-17 14:55 382,592 --a--c--- c:\windows\system32\dllcache\atidrab.dll
2009-03-17 15:31 . 2001-08-17 12:19 747,392 --a--c--- c:\windows\system32\dllcache\adm8830.sys
2009-03-17 15:30 . 2001-08-17 13:28 762,780 --a--c--- c:\windows\system32\dllcache\3cwmcru.sys
2009-03-17 15:30 . 2001-08-17 14:55 689,216 --a--c--- c:\windows\system32\dllcache\3dfxvs.dll
2009-03-17 15:30 . 2001-08-17 14:56 66,048 --a--c--- c:\windows\system32\dllcache\s3legacy.dll
2009-03-17 15:30 . 2008-04-13 14:46 53,376 --a--c--- c:\windows\system32\dllcache\1394bus.sys
2009-03-17 15:30 . 2001-08-17 14:06 11,264 --a--c--- c:\windows\system32\dllcache\1394vdbg.sys
2009-03-17 00:05 . 2009-03-17 00:05 0 --a------ c:\windows\system32\nfr.gpref
2009-03-16 23:50 . 2009-03-16 23:50 1 --a------ c:\windows\9g234sdfdfgjf23
2009-03-11 21:16 . 2009-03-11 21:16 <DIR> d-------- c:\documents and settings\David\Application Data\AVGTOOLBAR
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-03-19 15:29 --------- d-----w c:\documents and settings\user pc\Application Data\WTablet
2009-03-18 23:12 --------- d-----w c:\program files\Java
2009-03-18 19:00 --------- d-----w c:\program files\Lavasoft
2009-03-18 19:00 --------- d-----w c:\documents and settings\All Users\Application Data\Lavasoft
2009-03-17 16:21 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2009-03-17 09:26 --------- d-----w c:\documents and settings\user pc\Application Data\uTorrent
2009-03-15 21:35 138,624 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-03-15 04:15 --------- d-----w c:\documents and settings\user pc\Application Data\DVD Flick
2009-03-15 01:38 --------- d-----w c:\documents and settings\user pc\Application Data\dvdcss
2009-03-07 17:20 --------- d-----w c:\program files\Ahead
2009-02-26 18:41 --------- d-----w c:\documents and settings\user pc\Application Data\ZoomBrowser EX
2009-02-26 18:41 --------- d-----w c:\documents and settings\user pc\Application Data\CameraWindowDC
2009-02-25 15:41 --------- d-----w c:\documents and settings\user pc\Application Data\AVGTOOLBAR
2009-02-12 16:12 --------- d-----w c:\program files\Google
2009-02-11 02:24 34 ----a-w c:\documents and settings\user pc\jagex_runescape_preferences.dat
2009-02-10 04:35 --------- d-----w c:\documents and settings\Leanne\Application Data\AVGTOOLBAR
2009-02-10 04:19 --------- d-----w c:\documents and settings\Leanne\Application Data\vlc
2009-02-09 03:08 --------- d-----w c:\documents and settings\Leanne\Application Data\Apple Computer
2009-02-09 02:56 --------- d-----w c:\documents and settings\Leanne\Application Data\WTablet
2009-02-09 02:56 --------- d-----w c:\documents and settings\Leanne\Application Data\Network Associates
2009-02-09 02:42 --------- d-----w c:\documents and settings\Becky\Application Data\AVGTOOLBAR
2009-02-09 02:38 --------- d-----w c:\documents and settings\Becky\Application Data\vlc
2009-02-05 18:37 --------- d-----w c:\documents and settings\user pc\Application Data\vlc
2009-02-05 18:16 --------- d-----w c:\program files\VideoLAN
2009-02-03 19:16 --------- d-----w c:\program files\Improvisation
2009-01-27 15:56 325,128 ----a-w c:\windows\system32\drivers\avgldx86.sys
2009-01-27 15:55 107,272 ----a-w c:\windows\system32\drivers\avgtdix.sys
2009-01-25 05:54 --------- d-----w c:\documents and settings\user pc\Application Data\Any Video Converter
2009-01-24 22:06 --------- d-----w c:\program files\AVG
2009-01-24 21:59 0 ---ha-w c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2009-01-24 21:59 0 ---ha-w c:\windows\system32\drivers\Msft_Kernel_NuidFltr_01005.Wdf
2009-01-24 20:56 --------- d-----w c:\documents and settings\All Users\Application Data\nView_Profiles
2008-09-27 02:22 24 ----a-w c:\documents and settings\David\jagex_runescape_preferences.dat
.
((((((((((((((((((((((((((((( SnapShot@2009-03-19_ 0.53.12.29 )))))))))))))))))))))))))))))))))))))))))
.
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\admxprox.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\admxprox.dll
- 2002-08-29 12:00:00 49,664 -c--a-w c:\windows\system32\dllcache\adrot.dll
+ 2004-08-04 01:07:00 49,664 -c--a-w c:\windows\system32\dllcache\adrot.dll
- 2002-08-29 12:00:00 10,240 -c--a-w c:\windows\system32\dllcache\aspperf.dll
+ 2004-08-04 01:07:00 10,240 -c--a-w c:\windows\system32\dllcache\aspperf.dll
- 2002-08-29 12:00:00 29,184 -c--a-w c:\windows\system32\dllcache\asptxn.dll
+ 2004-08-04 01:07:00 29,184 -c--a-w c:\windows\system32\dllcache\asptxn.dll
- 2002-08-29 12:00:00 9,216 -c--a-w c:\windows\system32\dllcache\authfilt.dll
+ 2004-08-04 01:07:00 9,216 -c--a-w c:\windows\system32\dllcache\authfilt.dll
- 2002-08-29 12:00:00 45,568 -c--a-w c:\windows\system32\dllcache\browscap.dll
+ 2004-08-04 01:07:00 45,568 -c--a-w c:\windows\system32\dllcache\browscap.dll
- 2002-08-29 12:00:00 6,656 -c--a-w c:\windows\system32\dllcache\c_is2022.dll
+ 2004-08-04 01:07:00 6,656 -c--a-w c:\windows\system32\dllcache\c_is2022.dll
- 2002-08-29 12:00:00 10,752 -c--a-w c:\windows\system32\dllcache\c_iscii.dll
+ 2004-08-04 01:07:00 10,752 -c--a-w c:\windows\system32\dllcache\c_iscii.dll
- 2002-08-29 12:00:00 54,528 -c--a-w c:\windows\system32\dllcache\cap7146.sys
+ 2004-08-04 01:07:00 54,528 -c--a-w c:\windows\system32\dllcache\cap7146.sys
- 2002-08-29 12:00:00 9,728 -c--a-w c:\windows\system32\dllcache\change.exe
+ 2004-08-04 01:07:00 9,728 -c--a-w c:\windows\system32\dllcache\change.exe
- 2002-08-29 12:00:00 13,312 -c--a-w c:\windows\system32\dllcache\chglogon.exe
+ 2004-08-04 01:07:00 13,312 -c--a-w c:\windows\system32\dllcache\chglogon.exe
- 2002-08-29 12:00:00 15,872 -c--a-w c:\windows\system32\dllcache\chgport.exe
+ 2004-08-04 01:07:00 15,872 -c--a-w c:\windows\system32\dllcache\chgport.exe
- 2002-08-29 12:00:00 14,336 -c--a-w c:\windows\system32\dllcache\chgusr.exe
+ 2004-08-04 01:07:00 14,336 -c--a-w c:\windows\system32\dllcache\chgusr.exe
- 2002-08-29 12:00:00 1,677,824 -c--a-w c:\windows\system32\dllcache\chsbrkr.dll
+ 2004-08-04 01:07:00 1,677,824 -c--a-w c:\windows\system32\dllcache\chsbrkr.dll
- 2002-08-29 12:00:00 838,144 -c--a-w c:\windows\system32\dllcache\chtbrkr.dll
+ 2004-08-04 01:07:00 838,144 -c--a-w c:\windows\system32\dllcache\chtbrkr.dll
- 2002-08-29 12:00:00 33,792 -c--a-w c:\windows\system32\dllcache\controt.dll
+ 2004-08-04 01:07:00 33,792 -c--a-w c:\windows\system32\dllcache\controt.dll
- 2002-08-29 12:00:00 56,320 -c--a-w c:\windows\system32\dllcache\convlog.exe
+ 2004-08-04 01:07:00 56,320 -c--a-w c:\windows\system32\dllcache\convlog.exe
- 2002-08-29 12:00:00 20,480 -c--a-w c:\windows\system32\dllcache\counters.dll
+ 2004-08-04 01:07:00 20,480 -c--a-w c:\windows\system32\dllcache\counters.dll
- 2002-08-29 12:00:00 18,944 -c--a-w c:\windows\system32\dllcache\cprofile.exe
+ 2004-08-04 01:07:00 18,944 -c--a-w c:\windows\system32\dllcache\cprofile.exe
- 2002-08-29 12:00:00 31,744 -c--a-w c:\windows\system32\dllcache\esucmd.dll
+ 2004-08-04 01:07:00 31,744 -c--a-w c:\windows\system32\dllcache\esucmd.dll
- 2002-08-29 12:00:00 57,856 -c--a-w c:\windows\system32\dllcache\esuimgd.dll
+ 2004-08-04 01:07:00 57,856 -c--a-w c:\windows\system32\dllcache\esuimgd.dll
- 2002-08-29 12:00:00 45,056 -c--a-w c:\windows\system32\dllcache\esunid.dll
+ 2004-08-04 01:07:00 45,056 -c--a-w c:\windows\system32\dllcache\esunid.dll
- 2002-08-29 12:00:00 25,856 -c--a-w c:\windows\system32\dllcache\et4000.sys
+ 2004-08-04 01:07:00 25,856 -c--a-w c:\windows\system32\dllcache\et4000.sys
- 2002-08-29 12:00:00 14,848 -c--a-w c:\windows\system32\dllcache\flattemp.exe
+ 2004-08-04 01:07:00 14,848 -c--a-w c:\windows\system32\dllcache\flattemp.exe
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\ftlx041e.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\ftlx041e.dll
- 2002-08-29 12:00:00 7,680 -c--a-w c:\windows\system32\dllcache\ftpctrs2.dll
+ 2004-08-04 01:07:00 7,680 -c--a-w c:\windows\system32\dllcache\ftpctrs2.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\ftpsapi2.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\ftpsapi2.dll
- 2002-08-29 12:00:00 111,104 -c--a-w c:\windows\system32\dllcache\fxscfgwz.dll
+ 2004-08-04 01:07:00 111,104 -c--a-w c:\windows\system32\dllcache\fxscfgwz.dll
- 2002-08-29 12:00:00 132,608 -c--a-w c:\windows\system32\dllcache\fxsclntr.dll
+ 2004-08-04 01:07:00 132,608 -c--a-w c:\windows\system32\dllcache\fxsclntr.dll
- 2002-08-29 12:00:00 31,744 -c--a-w c:\windows\system32\dllcache\fxsroute.dll
+ 2004-08-04 01:07:00 31,744 -c--a-w c:\windows\system32\dllcache\fxsroute.dll
- 2002-08-29 12:00:00 11,264 -c--a-w c:\windows\system32\dllcache\fxssend.exe
+ 2004-08-04 01:07:00 11,264 -c--a-w c:\windows\system32\dllcache\fxssend.exe
- 2002-08-29 12:00:00 36,864 -c--a-w c:\windows\system32\dllcache\hanjadic.dll
+ 2004-08-04 01:07:00 36,864 -c--a-w c:\windows\system32\dllcache\hanjadic.dll
- 2002-08-29 12:00:00 10,096,640 -c--a-w c:\windows\system32\dllcache\hwxcht.dll
+ 2004-08-04 01:07:00 10,096,640 -c--a-w c:\windows\system32\dllcache\hwxcht.dll
- 2002-08-29 12:00:00 10,129,408 -c--a-w c:\windows\system32\dllcache\hwxkor.dll
+ 2004-08-04 01:07:00 10,129,408 -c--a-w c:\windows\system32\dllcache\hwxkor.dll
- 2002-08-29 12:00:00 60,928 -c--a-w c:\windows\system32\dllcache\iisclex4.dll
+ 2004-08-04 01:07:00 60,928 -c--a-w c:\windows\system32\dllcache\iisclex4.dll
- 2002-08-29 12:00:00 19,456 -c--a-w c:\windows\system32\dllcache\iiscrmap.dll
+ 2004-08-04 01:07:00 19,456 -c--a-w c:\windows\system32\dllcache\iiscrmap.dll
- 2002-08-29 12:00:00 3,584 -c--a-w c:\windows\system32\dllcache\iismui.dll
+ 2004-08-04 01:07:00 3,584 -c--a-w c:\windows\system32\dllcache\iismui.dll
- 2002-08-29 12:00:00 14,336 -c--a-w c:\windows\system32\dllcache\iisreset.exe
+ 2004-08-04 01:07:00 14,336 -c--a-w c:\windows\system32\dllcache\iisreset.exe
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\iisrstap.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\iisrstap.dll
- 2002-08-29 12:00:00 6,656 -c--a-w c:\windows\system32\dllcache\iissync.exe
+ 2004-08-04 01:07:00 6,656 -c--a-w c:\windows\system32\dllcache\iissync.exe
- 2002-08-29 12:00:00 169,984 -c--a-w c:\windows\system32\dllcache\iisui.dll
+ 2004-08-04 01:07:00 169,984 -c--a-w c:\windows\system32\dllcache\iisui.dll
- 2002-08-29 12:00:00 44,032 -c--a-w c:\windows\system32\dllcache\imekrmig.exe
+ 2004-08-04 01:07:00 44,032 -c--a-w c:\windows\system32\dllcache\imekrmig.exe
- 2002-08-29 12:00:00 102,463 -c--a-w c:\windows\system32\dllcache\imepadsm.dll
+ 2004-08-04 01:07:00 102,463 -c--a-w c:\windows\system32\dllcache\imepadsm.dll
- 2002-08-29 12:00:00 311,359 -c--a-w c:\windows\system32\dllcache\imepadsv.exe
+ 2004-08-04 01:07:00 311,359 -c--a-w c:\windows\system32\dllcache\imepadsv.exe
- 2002-08-29 12:00:00 57,398 -c--a-w c:\windows\system32\dllcache\imjpdadm.exe
+ 2004-08-04 01:07:00 57,398 -c--a-w c:\windows\system32\dllcache\imjpdadm.exe
- 2002-08-29 12:00:00 45,109 -c--a-w c:\windows\system32\dllcache\imjpuex.exe
+ 2004-08-04 01:07:00 45,109 -c--a-w c:\windows\system32\dllcache\imjpuex.exe
- 2002-08-29 12:00:00 59,904 -c--a-w c:\windows\system32\dllcache\imkrinst.exe
+ 2004-08-04 01:07:00 59,904 -c--a-w c:\windows\system32\dllcache\imkrinst.exe
- 2002-08-29 12:00:00 471,102 -c--a-w c:\windows\system32\dllcache\imskdic.dll
+ 2004-08-04 01:07:00 471,102 -c--a-w c:\windows\system32\dllcache\imskdic.dll
- 2002-08-29 12:00:00 7,680 -c--a-w c:\windows\system32\dllcache\inetmgr.exe
+ 2004-08-04 01:07:00 7,680 -c--a-w c:\windows\system32\dllcache\inetmgr.exe
- 2002-08-29 12:00:00 19,968 -c--a-w c:\windows\system32\dllcache\inetsloc.dll
+ 2004-08-04 01:07:00 19,968 -c--a-w c:\windows\system32\dllcache\inetsloc.dll
- 2002-08-29 12:00:00 8,704 -c--a-w c:\windows\system32\dllcache\infoctrs.dll
+ 2004-08-04 01:07:00 8,704 -c--a-w c:\windows\system32\dllcache\infoctrs.dll
- 2002-08-29 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\isapips.dll
+ 2004-08-04 01:07:00 7,168 -c--a-w c:\windows\system32\dllcache\isapips.dll
- 2002-08-29 12:00:00 9,216 -c--a-w c:\windows\system32\dllcache\iwrps.dll
+ 2004-08-04 01:07:00 9,216 -c--a-w c:\windows\system32\dllcache\iwrps.dll
- 2002-08-29 12:00:00 18,432 -c--a-w c:\windows\system32\dllcache\jupiw.dll
+ 2004-08-04 01:07:00 18,432 -c--a-w c:\windows\system32\dllcache\jupiw.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbd101a.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\kbd101a.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda1.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda1.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda2.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda2.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda3.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbda3.dll
- 2002-08-29 12:00:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdarme.dll
+ 2004-08-04 01:07:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdarme.dll
- 2002-08-29 12:00:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdarmw.dll
+ 2004-08-04 01:07:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdarmw.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbddiv1.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbddiv1.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbddiv2.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbddiv2.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdfa.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdfa.dll
- 2002-08-29 12:00:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdgeo.dll
+ 2004-08-04 01:07:00 5,120 -c--a-w c:\windows\system32\dllcache\kbdgeo.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdheb.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdheb.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdindev.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdindev.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinguj.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinguj.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinhin.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinhin.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinkan.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinkan.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinmar.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdinmar.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdinpun.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdinpun.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdintam.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdintam.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdintel.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdintel.dll
- 2002-08-29 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\kbdnec95.dll
+ 2004-08-04 01:07:00 7,168 -c--a-w c:\windows\system32\dllcache\kbdnec95.dll
- 2002-08-29 12:00:00 9,216 -c--a-w c:\windows\system32\dllcache\kbdnecat.dll
+ 2004-08-04 01:07:00 9,216 -c--a-w c:\windows\system32\dllcache\kbdnecat.dll
- 2002-08-29 12:00:00 7,680 -c--a-w c:\windows\system32\dllcache\kbdnecnt.dll
+ 2004-08-04 01:07:00 7,680 -c--a-w c:\windows\system32\dllcache\kbdnecnt.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdsyr1.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdsyr1.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdsyr2.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdsyr2.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdth0.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdth0.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdth1.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdth1.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdth2.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdth2.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdth3.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\kbdth3.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdurdu.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdurdu.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdusa.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdusa.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdvntc.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\kbdvntc.dll
- 2002-08-29 12:00:00 70,656 -c--a-w c:\windows\system32\dllcache\korwbrkr.dll
+ 2004-08-04 01:07:00 70,656 -c--a-w c:\windows\system32\dllcache\korwbrkr.dll
- 2002-08-29 12:00:00 22,016 -c--a-w c:\windows\system32\dllcache\logscrpt.dll
+ 2004-08-04 01:07:00 22,016 -c--a-w c:\windows\system32\dllcache\logscrpt.dll
- 2002-08-29 12:00:00 26,624 -c--a-w c:\windows\system32\dllcache\mdsync.dll
+ 2004-08-04 01:07:00 26,624 -c--a-w c:\windows\system32\dllcache\mdsync.dll
- 2002-08-29 12:00:00 92,032 -c--a-w c:\windows\system32\dllcache\mga.dll
+ 2004-08-04 01:07:00 92,032 -c--a-w c:\windows\system32\dllcache\mga.dll
- 2002-08-29 12:00:00 92,416 -c--a-w c:\windows\system32\dllcache\mga.sys
+ 2004-08-04 01:07:00 92,416 -c--a-w c:\windows\system32\dllcache\mga.sys
- 2002-08-29 12:00:00 34,304 -c--a-w c:\windows\system32\dllcache\migisol.exe
+ 2004-08-04 01:07:00 34,304 -c--a-w c:\windows\system32\dllcache\migisol.exe
- 2002-08-29 12:00:00 98,304 -c--a-w c:\windows\system32\dllcache\msir3jp.dll
+ 2004-08-04 01:07:00 98,304 -c--a-w c:\windows\system32\dllcache\msir3jp.dll
- 2002-08-29 12:00:00 229,439 -c--a-w c:\windows\system32\dllcache\multibox.dll
+ 2004-08-04 01:07:00 229,439 -c--a-w c:\windows\system32\dllcache\multibox.dll
- 2002-08-29 12:00:00 53,248 -c--a-w c:\windows\system32\dllcache\nextlink.dll
+ 2004-08-04 01:07:00 53,248 -c--a-w c:\windows\system32\dllcache\nextlink.dll
- 2002-08-29 12:00:00 36,927 -c--a-w c:\windows\system32\dllcache\padrs411.dll
+ 2004-08-04 01:07:00 36,927 -c--a-w c:\windows\system32\dllcache\padrs411.dll
- 2002-08-29 12:00:00 14,336 -c--a-w c:\windows\system32\dllcache\padrs412.dll
+ 2004-08-04 01:07:00 14,336 -c--a-w c:\windows\system32\dllcache\padrs412.dll
- 2002-08-29 12:00:00 31,744 -c--a-w c:\windows\system32\dllcache\pagecnt.dll
+ 2004-08-04 01:07:00 31,744 -c--a-w c:\windows\system32\dllcache\pagecnt.dll
- 2002-08-29 12:00:00 20,992 -c--a-w c:\windows\system32\dllcache\permchk.dll
+ 2004-08-04 01:07:00 20,992 -c--a-w c:\windows\system32\dllcache\permchk.dll
- 2002-08-29 12:00:00 6,144 -c--a-w c:\windows\system32\dllcache\pmxgl.dll
+ 2004-08-04 01:07:00 6,144 -c--a-w c:\windows\system32\dllcache\pmxgl.dll
- 2002-08-29 12:00:00 11,264 -c--a-w c:\windows\system32\dllcache\pmxmcro.dll
+ 2004-08-04 01:07:00 11,264 -c--a-w c:\windows\system32\dllcache\pmxmcro.dll
- 2002-08-29 12:00:00 131,584 -c--a-w c:\windows\system32\dllcache\pmxviceo.dll
+ 2004-08-04 01:07:00 131,584 -c--a-w c:\windows\system32\dllcache\pmxviceo.dll
- 2002-08-29 12:00:00 9,728 -c--a-w c:\windows\system32\dllcache\query.exe
+ 2004-08-04 01:07:00 9,728 -c--a-w c:\windows\system32\dllcache\query.exe
- 2002-08-29 12:00:00 16,384 -c--a-w c:\windows\system32\dllcache\quser.exe
+ 2004-08-04 01:07:00 16,384 -c--a-w c:\windows\system32\dllcache\quser.exe
- 2002-08-29 12:00:00 14,848 -c--a-w c:\windows\system32\dllcache\register.exe
+ 2004-08-04 01:07:00 14,848 -c--a-w c:\windows\system32\dllcache\register.exe
- 2002-08-29 12:00:00 79,872 -c--a-w c:\windows\system32\dllcache\rwia001.dll
+ 2004-08-04 01:07:00 79,872 -c--a-w c:\windows\system32\dllcache\rwia001.dll
- 2002-08-29 12:00:00 79,872 -c--a-w c:\windows\system32\dllcache\rwia330.dll
+ 2004-08-04 01:07:00 79,872 -c--a-w c:\windows\system32\dllcache\rwia330.dll
- 2002-08-29 12:00:00 18,944 -c--a-w c:\windows\system32\dllcache\simptcp.dll
+ 2004-08-04 01:07:00 18,944 -c--a-w c:\windows\system32\dllcache\simptcp.dll
- 2002-08-29 12:00:00 25,088 -c--a-w c:\windows\system32\dllcache\sm59w.dll
+ 2004-08-04 01:07:00 25,088 -c--a-w c:\windows\system32\dllcache\sm59w.dll
- 2002-08-29 12:00:00 30,208 -c--a-w c:\windows\system32\dllcache\sm81w.dll
+ 2004-08-04 01:07:00 30,208 -c--a-w c:\windows\system32\dllcache\sm81w.dll
- 2002-08-29 12:00:00 30,208 -c--a-w c:\windows\system32\dllcache\sm87w.dll
+ 2004-08-04 01:07:00 30,208 -c--a-w c:\windows\system32\dllcache\sm87w.dll
- 2002-08-29 12:00:00 26,112 -c--a-w c:\windows\system32\dllcache\sm89w.dll
+ 2004-08-04 01:07:00 26,112 -c--a-w c:\windows\system32\dllcache\sm89w.dll
- 2002-08-29 12:00:00 26,112 -c--a-w c:\windows\system32\dllcache\sm8aw.dll
+ 2004-08-04 01:07:00 26,112 -c--a-w c:\windows\system32\dllcache\sm8aw.dll
- 2002-08-29 12:00:00 29,184 -c--a-w c:\windows\system32\dllcache\sm8cw.dll
+ 2004-08-04 01:07:00 29,184 -c--a-w c:\windows\system32\dllcache\sm8cw.dll
- 2002-08-29 12:00:00 26,112 -c--a-w c:\windows\system32\dllcache\sm8dw.dll
+ 2004-08-04 01:07:00 26,112 -c--a-w c:\windows\system32\dllcache\sm8dw.dll
- 2002-08-29 12:00:00 26,112 -c--a-w c:\windows\system32\dllcache\sm90w.dll
+ 2004-08-04 01:07:00 26,112 -c--a-w c:\windows\system32\dllcache\sm90w.dll
- 2002-08-29 12:00:00 26,624 -c--a-w c:\windows\system32\dllcache\sm92w.dll
+ 2004-08-04 01:07:00 26,624 -c--a-w c:\windows\system32\dllcache\sm92w.dll
- 2002-08-29 12:00:00 26,624 -c--a-w c:\windows\system32\dllcache\sm93w.dll
+ 2004-08-04 01:07:00 26,624 -c--a-w c:\windows\system32\dllcache\sm93w.dll
- 2002-08-29 12:00:00 38,912 -c--a-w c:\windows\system32\dllcache\sm9aw.dll
+ 2004-08-04 01:07:00 38,912 -c--a-w c:\windows\system32\dllcache\sm9aw.dll
- 2002-08-29 12:00:00 31,744 -c--a-w c:\windows\system32\dllcache\sma3w.dll
+ 2004-08-04 01:07:00 31,744 -c--a-w c:\windows\system32\dllcache\sma3w.dll
- 2002-08-29 12:00:00 31,744 -c--a-w c:\windows\system32\dllcache\smb6w.dll
+ 2004-08-04 01:07:00 31,744 -c--a-w c:\windows\system32\dllcache\smb6w.dll
- 2002-08-29 12:00:00 15,872 -c--a-w c:\windows\system32\dllcache\smierrsm.dll
+ 2004-08-04 01:07:00 15,872 -c--a-w c:\windows\system32\dllcache\smierrsm.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\smierrsy.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\smierrsy.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\smimsgif.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\smimsgif.dll
- 2002-08-29 12:00:00 10,240 -c--a-w c:\windows\system32\dllcache\snmpstup.dll
+ 2004-08-04 01:07:00 10,240 -c--a-w c:\windows\system32\dllcache\snmpstup.dll
- 2002-08-29 12:00:00 143,422 -c--a-w c:\windows\system32\dllcache\softkey.dll
+ 2004-08-04 01:07:00 143,422 -c--a-w c:\windows\system32\dllcache\softkey.dll
- 2002-08-29 12:00:00 101,376 -c--a-w c:\windows\system32\dllcache\srusbusd.dll
+ 2004-08-04 01:07:00 101,376 -c--a-w c:\windows\system32\dllcache\srusbusd.dll
- 2002-08-29 12:00:00 16,896 -c--a-w c:\windows\system32\dllcache\status.dll
+ 2004-08-04 01:07:00 16,896 -c--a-w c:\windows\system32\dllcache\status.dll
- 2002-08-29 12:00:00 13,192 -c--a-w c:\windows\system32\dllcache\tdasync.sys
+ 2004-08-04 01:07:00 13,192 -c--a-w c:\windows\system32\dllcache\tdasync.sys
- 2002-08-29 12:00:00 21,896 -c--a-w c:\windows\system32\dllcache\tdipx.sys
+ 2004-08-04 01:07:00 21,896 -c--a-w c:\windows\system32\dllcache\tdipx.sys
- 2002-08-29 12:00:00 19,464 -c--a-w c:\windows\system32\dllcache\tdspx.sys
+ 2004-08-04 01:07:00 19,464 -c--a-w c:\windows\system32\dllcache\tdspx.sys
- 2002-08-29 12:00:00 185,344 -c--a-w c:\windows\system32\dllcache\thawbrkr.dll
+ 2004-08-04 01:07:00 185,344 -c--a-w c:\windows\system32\dllcache\thawbrkr.dll
- 2002-08-29 12:00:00 14,336 -c--a-w c:\windows\system32\dllcache\tsprof.exe
+ 2004-08-04 01:07:00 14,336 -c--a-w c:\windows\system32\dllcache\tsprof.exe
- 2002-08-29 12:00:00 48,256 -c--a-w c:\windows\system32\dllcache\w32.dll
+ 2004-08-04 01:07:00 48,256 -c--a-w c:\windows\system32\dllcache\w32.dll
- 2002-08-29 12:00:00 4,608 -c--a-w c:\windows\system32\dllcache\w3ctrs51.dll
+ 2004-08-04 01:07:00 4,608 -c--a-w c:\windows\system32\dllcache\w3ctrs51.dll
- 2002-08-29 12:00:00 73,728 -c--a-w c:\windows\system32\dllcache\w3ext.dll
+ 2004-08-04 01:07:00 73,728 -c--a-w c:\windows\system32\dllcache\w3ext.dll
- 2002-08-29 12:00:00 5,632 -c--a-w c:\windows\system32\dllcache\w3svapi.dll
+ 2004-08-04 01:07:00 5,632 -c--a-w c:\windows\system32\dllcache\w3svapi.dll
- 2002-08-29 12:00:00 9,216 -c--a-w c:\windows\system32\dllcache\wamps51.dll
+ 2004-08-04 01:07:00 9,216 -c--a-w c:\windows\system32\dllcache\wamps51.dll
- 2002-08-29 12:00:00 7,168 -c--a-w c:\windows\system32\dllcache\wamregps.dll
+ 2004-08-04 01:07:00 7,168 -c--a-w c:\windows\system32\dllcache\wamregps.dll
- 2002-08-29 12:00:00 41,600 -c--a-w c:\windows\system32\dllcache\weitekp9.dll
+ 2004-08-04 01:07:00 41,600 -c--a-w c:\windows\system32\dllcache\weitekp9.dll
- 2002-08-29 12:00:00 31,232 -c--a-w c:\windows\system32\dllcache\weitekp9.sys
+ 2004-08-04 01:07:00 31,232 -c--a-w c:\windows\system32\dllcache\weitekp9.sys
+ 2009-03-19 15:41:43 16,384 ----atw c:\windows\temp\Perflib_Perfdata_6f0.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-04-04 68856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2007-03-31 180269]
"McAfeeFireTray"="c:\progra~1\NETWOR~1\MCAFEE~1\Firetray.exe" [2005-04-12 655420]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2006-07-07 576320]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2006-07-07 600896]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-05-03 13529088]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-03-30 267048]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-01-27 1601304]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-18 148888]
"NvMediaCenter"="NvMCTray.dll" [2008-05-03 c:\windows\system32\nvmctray.dll]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
2008-12-22 11:05 356352 c:\program files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-01-27 11:56 10520 c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=c:\windows\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=c:\windows\pss\Microsoft Office.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Works Calendar Reminders.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Microsoft Works Calendar Reminders.lnk
backup=c:\windows\pss\Microsoft Works Calendar Reminders.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Personal Coach.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Personal Coach.lnk
backup=c:\windows\pss\Personal Coach.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTZDetec.exe]
--a------ 2007-12-18 15:20 401408 c:\documents and settings\user pc\Desktop\David\Creative Media Lite\CTZDetec.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-03-30 10:36 267048 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-03-28 23:37 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-04-04 19:00 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
--a------ 2008-05-03 06:46 1630208 c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2009-01-24 325128]
R1 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2009-01-24 107272]
R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2009-02-17 8944]
R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2009-02-17 55024]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2009-01-24 903960]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2009-01-24 298264]
S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2009-02-17 7408]
.
Contents of the 'Scheduled Tasks' folder
2009-03-18 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 17:57]
2009-03-17 c:\windows\Tasks\Uniblue SpyEraser Nag.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
2007-09-04 c:\windows\Tasks\Uniblue SpyEraser.job
- c:\program files\Uniblue\SpyEraser\SpyEraser.exe []
.
.
------- Supplementary Scan -------
.
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
FF - ProfilePath - c:\documents and settings\Becky\Application Data\Mozilla\Firefox\Profiles\v0zlm1jn.default\
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmusicn.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-03-19 11:42:12
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E}\1.0]
@DACL=(02 0000)
@="HtmldocPlugin 1.0 Type Library"
[HKEY_LOCAL_MACHINE\software\PortraitDisplays\DisplayTune\MGJ74D0C06550]
@DACL=(02 0000)
"Analog 0.700,0.300Caps"="vcp(02 04 05 06 08 0E 10 12 14(01 05 08 0B) 16 18 1A 1E 20 30 3E 52 60(01 03) 68 AC AE B2 B6 C0 C6 C8 C9 CA D6(01 04) DF FA FB FC FD FE AA(01 04)) vcp_p2(37 38 39 3B) type(LCD) mccs_ver(2.0) asset_eep(64) mpu(0.04)"
[HKEY_LOCAL_MACHINE\System\ControlSet003\Enum\HID\Vid_045e&Pid_00f9&MI_01&Col02\7&36e0efb9&0&0001\LogConf]
@DACL=(02 0000)
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(648)
c:\program files\SUPERAntiSpyware\SASWINLO.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\CTSVCCDA.EXE
c:\program files\Creative\Shared Files\CTDevSrv.exe
c:\progra~1\NETWOR~1\MCAFEE~1\FireSvc.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\PnkBstrA.exe
c:\windows\system32\PnkBstrB.exe
c:\program files\AVG\AVG8\avgrsx.exe
c:\progra~1\AVG\AVG8\avgnsx.exe
c:\windows\system32\Tablet.exe
c:\windows\wanmpsvc.exe
c:\windows\system32\WTablet\TabUserW.exe
c:\windows\system32\Tablet.exe
c:\program files\AVG\AVG8\avgcsrvx.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\rundll32.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2009-03-19 11:45:02 - machine was rebooted
ComboFix-quarantined-files.txt 2009-03-19 15:44:58
ComboFix2.txt 2009-03-19 04:54:14
Pre-Run: 32,409,468,928 bytes free
Post-Run: 32,390,303,744 bytes free
Current=3 Default=3 Failed=1 LastKnownGood=4 Sets=1,2,3,4
534 --- E O F --- 2009-03-13 22:12:01