combofix pt 1
BTW....thankyou SOOmuch for your help!
ComboFix 08-02.02.5 - Lori 2008-02-03 13:14:09.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1406 [GMT -5:00]
Running from: C:\Documents and Settings\Lori\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lori\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.
2008-01-30 21:21 . 2008-01-30 21:21 <DIR> d-------- C:\Documents and Settings\Noelle\Application Data\Talkback
2008-01-21 19:55 . 2008-02-02 10:55 7,741,472 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-21 19:55 . 2008-02-02 10:55 1,054,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-21 19:55 . 2008-02-02 10:55 105,800 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-21 19:55 . 2008-02-02 10:55 101,000 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-21 19:54 . 2008-01-21 19:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-21 19:49 . 2008-01-21 19:49 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-21 19:49 . 2008-01-21 19:49 <DIR> d-------- C:\KAV
2008-01-21 12:29 . 2008-01-21 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prism
2008-01-21 12:28 . 2005-11-15 22:16 357,632 -ra------ C:\WINDOWS\system32\drivers\2862WICB.sys
2008-01-21 12:27 . 2008-01-21 12:27 <DIR> d-------- C:\Program Files\SMC
2008-01-21 12:27 . 2008-01-21 12:27 15,781 --a------ C:\WINDOWS\system32\drivers\mdc8021x.sys
2008-01-21 12:15 . 2008-01-21 12:15 158,208 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
2008-01-21 10:51 . 2008-01-21 10:51 <DIR> d-------- C:\Documents and Settings\Bob\Application Data\HPAppData
2008-01-19 07:29 . 2008-01-23 22:31 1,357 --a------ C:\WINDOWS\wininit.ini
2008-01-19 06:30 . 2008-01-19 06:30 <DIR> d-------- C:\Documents and Settings\Bob\Application Data\Talkback
2008-01-18 16:57 . 2008-01-19 05:36 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-18 16:57 . 2008-01-19 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 16:29 . 2008-01-16 16:29 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-16 16:29 . 2008-01-16 16:29 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 15:57 . 2008-01-16 15:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-15 23:14 . 2008-01-15 23:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-01-15 23:12 . 2003-12-02 16:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-01-15 23:11 . 2008-01-15 23:11 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-01-11 23:08 . 2008-01-22 05:42 <DIR> d-------- C:\VundoFix Backups
2008-01-06 13:39 . 2008-01-06 13:39 <DIR> d-------- C:\Documents and Settings\Noelle\Application Data\HPAppData
2008-01-06 00:43 . 2008-01-06 00:43 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-05 23:56 . 2008-01-05 23:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-01-05 23:49 . 2007-03-07 23:20 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-01-05 23:48 . 2008-01-05 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-05 23:48 . 2007-03-07 23:20 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-01-05 23:45 . 2007-05-02 03:56 954,368 -ra------ C:\WINDOWS\system32\hpotiop5.dll
2008-01-05 23:45 . 2007-05-02 04:01 675,840 -ra------ C:\WINDOWS\system32\hpowiax5.dll
2008-01-05 23:45 . 2007-03-07 23:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-01-05 23:45 . 2007-03-07 23:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-01-05 23:45 . 2007-05-02 04:00 303,104 -ra------ C:\WINDOWS\system32\hpovst12.dll
2008-01-05 23:45 . 2007-03-07 23:20 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-01-05 23:25 . 2008-01-05 23:25 <DIR> d-------- C:\Documents and Settings\Lori\Application Data\HP
2008-01-05 23:19 . 2008-01-05 23:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-01-05 23:12 . 2008-01-05 23:14 146,986 --------- C:\WINDOWS\hpoins21.dat.temp
2008-01-05 23:12 . 2007-05-15 05:10 8,138 --------- C:\WINDOWS\hpomdl21.dat.temp
2008-01-05 22:49 . 2008-01-05 22:49 <DIR> d-------- C:\Documents and Settings\Lori\Application Data\HPAppData
2008-01-05 21:59 . 2008-01-05 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-01-05 21:59 . 2008-01-05 22:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-01-05 21:58 . 2008-01-05 21:58 <DIR> d-------- C:\Program Files\Common Files\HP
2008-01-05 21:57 . 2008-01-05 21:57 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-01-05 21:56 . 2008-01-05 21:56 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-01-05 21:54 . 2008-01-05 23:19 <DIR> d-------- C:\Program Files\HP
2008-01-05 21:52 . 2008-01-06 00:01 147,669 --a------ C:\WINDOWS\hpoins21.dat
2008-01-05 21:52 . 2007-05-15 05:10 8,138 --------- C:\WINDOWS\hpomdl21.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 17:06 --------- d-----w C:\Program Files\VIP Casinos
2008-02-03 15:51 22 ----a-w C:\qpmd8376.bin
2008-02-03 15:43 --------- d-----w C:\Program Files\QuickTime
2008-02-03 15:42 --------- d-----w C:\Program Files\MSN Messenger
2008-02-03 15:42 --------- d-----w C:\Program Files\iTunes
2008-02-03 15:42 --------- d-----w C:\Program Files\ESPNRunTime
2008-02-03 15:42 --------- d-----w C:\Program Files\DIGStream
2008-02-03 15:42 --------- d-----w C:\Program Files\AIM95
2008-02-03 15:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-03 09:46 --------- d-----w C:\Documents and Settings\Lori\Application Data\SiteAdvisor
2008-02-02 03:11 --------- d-----w C:\Documents and Settings\Bob\Application Data\SiteAdvisor
2008-01-31 04:17 --------- d-----w C:\Documents and Settings\Noelle\Application Data\SiteAdvisor
2008-01-21 17:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 17:15 158,208 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
2008-01-17 01:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-17 01:48 --------- d-----w C:\Documents and Settings\Lori\Application Data\McAfee
2008-01-16 21:42 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2008-01-11 03:31 --------- d-----w C:\Program Files\WhiteSmoke
2008-01-09 03:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-07 05:38 155,648 ----a-w C:\WINDOWS\system32\igfxtray .exe
2008-01-07 05:38 114,688 ----a-w C:\WINDOWS\system32\hkcmd.exe
2008-01-05 01:56 1,526,640 ----a-w C:\WINDOWS\WRSetup.dll
2008-01-05 01:34 23,920 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
2008-01-05 01:34 21,872 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2008-01-05 01:34 20,336 ----a-w C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-01-05 01:34 163,696 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2008-01-04 01:45 --------- d-----w C:\Program Files\DL_cats
2008-01-03 04:30 --------- d-----w C:\Program Files\Casino Share Flash Casino
2008-01-02 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2007-12-31 05:29 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-12-31 05:23 --------- d-----w C:\Program Files\Dell_Photo AIO Printer 962
2007-12-30 17:30 --------- d-----w C:\Program Files\Dell_ENA
2007-12-30 17:30 --------- d-----w C:\Program Files\Dell
2007-12-30 16:05 --------- d-----w C:\Program Files\KeyGen Crack
2007-12-30 01:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-30 00:38 --------- d-----w C:\Documents and Settings\Lori\Application Data\AdobeUM
2007-12-28 02:04 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-28 01:56 43,528 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-28 01:56 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2007-12-28 01:56 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2007-12-28 01:56 116,472 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-27 23:32 --------- d-----w C:\Documents and Settings\Lori\Application Data\Apple Computer
2007-12-23 00:02 --------- d-----w C:\Program Files\BatchPhoto
2007-12-23 00:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-21 04:02 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-09 21:11 --------- d-----w C:\Program Files\PhotoFiltre
2007-12-08 05:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-09 01:13 164 ----a-w C:\install.dat
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2002-05-19 05:57 944,797 ----a-w C:\Program Files\wrar300.exe
2002-05-15 04:37 473 ----a-w C:\Program Files\rarregkey.txt
2002-04-01 13:43 11,264 ----a-w C:\Program Files\readme.wri
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
2007-03-02 16:52 1298024 -ra------ C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
2007-03-02 16:52 177768 -ra------ C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-16 16:42 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"PRISMSVR.EXE"="C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2008-01-08 22:09 28672]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-01-22 05:34 582992]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-01-21 12:15 158208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-08 22:09 68856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"McWebDownlMgr"="C:\WINDOWS\TEMP\McDMTemp007 (2)\DwnldMgr.exe" [ ]
C:\Documents and Settings\Lori\Start Menu\Programs\Startup\
NaturalColorLoad.lnk - C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2006-06-25 23:05:30 155715]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-07-05 19:45:13 450560]
NaturalColorLoad.lnk - C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2006-06-25 23:05:30 155715]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-10-02 17:08:08 57344]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 00:03:20 69632]
SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk - C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2005-10-17 16:10:34 421888]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-04-24 12:13 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup
BTW....thankyou SOOmuch for your help!
ComboFix 08-02.02.5 - Lori 2008-02-03 13:14:09.3 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1406 [GMT -5:00]
Running from: C:\Documents and Settings\Lori\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Lori\Desktop\CFScript.txt
* Created a new restore point
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((( Files Created from 2008-01-03 to 2008-02-03 )))))))))))))))))))))))))))))))
.
2008-01-30 21:21 . 2008-01-30 21:21 <DIR> d-------- C:\Documents and Settings\Noelle\Application Data\Talkback
2008-01-21 19:55 . 2008-02-02 10:55 7,741,472 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-01-21 19:55 . 2008-02-02 10:55 1,054,752 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-01-21 19:55 . 2008-02-02 10:55 105,800 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-01-21 19:55 . 2008-02-02 10:55 101,000 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-01-21 19:54 . 2008-01-21 19:54 <DIR> d-------- C:\Program Files\Trend Micro
2008-01-21 19:49 . 2008-01-21 19:49 <DIR> d-------- C:\Program Files\Kaspersky Lab
2008-01-21 19:49 . 2008-01-21 19:49 <DIR> d-------- C:\KAV
2008-01-21 12:29 . 2008-01-21 12:29 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prism
2008-01-21 12:28 . 2005-11-15 22:16 357,632 -ra------ C:\WINDOWS\system32\drivers\2862WICB.sys
2008-01-21 12:27 . 2008-01-21 12:27 <DIR> d-------- C:\Program Files\SMC
2008-01-21 12:27 . 2008-01-21 12:27 15,781 --a------ C:\WINDOWS\system32\drivers\mdc8021x.sys
2008-01-21 12:15 . 2008-01-21 12:15 158,208 --a--c--- C:\WINDOWS\system32\dllcache\msconfig.exe
2008-01-21 10:51 . 2008-01-21 10:51 <DIR> d-------- C:\Documents and Settings\Bob\Application Data\HPAppData
2008-01-19 07:29 . 2008-01-23 22:31 1,357 --a------ C:\WINDOWS\wininit.ini
2008-01-19 06:30 . 2008-01-19 06:30 <DIR> d-------- C:\Documents and Settings\Bob\Application Data\Talkback
2008-01-18 16:57 . 2008-01-19 05:36 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-01-18 16:57 . 2008-01-19 12:32 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-01-16 16:29 . 2008-01-16 16:29 54,156 --ah----- C:\WINDOWS\QTFont.qfn
2008-01-16 16:29 . 2008-01-16 16:29 1,409 --a------ C:\WINDOWS\QTFont.for
2008-01-16 15:57 . 2008-01-16 15:57 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Talkback
2008-01-15 23:14 . 2008-01-15 23:14 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\Webroot
2008-01-15 23:12 . 2003-12-02 16:13 <DIR> d-------- C:\Documents and Settings\Administrator\Application Data\AdobeUM
2008-01-15 23:11 . 2008-01-15 23:11 <DIR> d-------- C:\Documents and Settings\NetworkService\Application Data\Webroot
2008-01-11 23:08 . 2008-01-22 05:42 <DIR> d-------- C:\VundoFix Backups
2008-01-06 13:39 . 2008-01-06 13:39 <DIR> d-------- C:\Documents and Settings\Noelle\Application Data\HPAppData
2008-01-06 00:43 . 2008-01-06 00:43 <DIR> d-------- C:\Program Files\MSXML 4.0
2008-01-05 23:56 . 2008-01-05 23:56 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\WEBREG
2008-01-05 23:49 . 2007-03-07 23:20 16,496 -ra------ C:\WINDOWS\system32\drivers\HPZipr12.sys
2008-01-05 23:48 . 2008-01-05 23:48 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard
2008-01-05 23:48 . 2007-03-07 23:20 49,920 -ra------ C:\WINDOWS\system32\drivers\HPZid412.sys
2008-01-05 23:45 . 2007-05-02 03:56 954,368 -ra------ C:\WINDOWS\system32\hpotiop5.dll
2008-01-05 23:45 . 2007-05-02 04:01 675,840 -ra------ C:\WINDOWS\system32\hpowiax5.dll
2008-01-05 23:45 . 2007-03-07 23:20 364,544 -ra------ C:\WINDOWS\system32\hppldcoi.dll
2008-01-05 23:45 . 2007-03-07 23:20 309,760 -ra------ C:\WINDOWS\system32\difxapi.dll
2008-01-05 23:45 . 2007-05-02 04:00 303,104 -ra------ C:\WINDOWS\system32\hpovst12.dll
2008-01-05 23:45 . 2007-03-07 23:20 21,568 -ra------ C:\WINDOWS\system32\drivers\HPZius12.sys
2008-01-05 23:25 . 2008-01-05 23:25 <DIR> d-------- C:\Documents and Settings\Lori\Application Data\HP
2008-01-05 23:19 . 2008-01-05 23:19 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY
2008-01-05 23:12 . 2008-01-05 23:14 146,986 --------- C:\WINDOWS\hpoins21.dat.temp
2008-01-05 23:12 . 2007-05-15 05:10 8,138 --------- C:\WINDOWS\hpomdl21.dat.temp
2008-01-05 22:49 . 2008-01-05 22:49 <DIR> d-------- C:\Documents and Settings\Lori\Application Data\HPAppData
2008-01-05 21:59 . 2008-01-05 21:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP Product Assistant
2008-01-05 21:59 . 2008-01-05 22:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\HP
2008-01-05 21:58 . 2008-01-05 21:58 <DIR> d-------- C:\Program Files\Common Files\HP
2008-01-05 21:57 . 2008-01-05 21:57 <DIR> d-------- C:\Program Files\Hewlett-Packard
2008-01-05 21:56 . 2008-01-05 21:56 <DIR> d-------- C:\Program Files\Common Files\Hewlett-Packard
2008-01-05 21:54 . 2008-01-05 23:19 <DIR> d-------- C:\Program Files\HP
2008-01-05 21:52 . 2008-01-06 00:01 147,669 --a------ C:\WINDOWS\hpoins21.dat
2008-01-05 21:52 . 2007-05-15 05:10 8,138 --------- C:\WINDOWS\hpomdl21.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-02-03 17:06 --------- d-----w C:\Program Files\VIP Casinos
2008-02-03 15:51 22 ----a-w C:\qpmd8376.bin
2008-02-03 15:43 --------- d-----w C:\Program Files\QuickTime
2008-02-03 15:42 --------- d-----w C:\Program Files\MSN Messenger
2008-02-03 15:42 --------- d-----w C:\Program Files\iTunes
2008-02-03 15:42 --------- d-----w C:\Program Files\ESPNRunTime
2008-02-03 15:42 --------- d-----w C:\Program Files\DIGStream
2008-02-03 15:42 --------- d-----w C:\Program Files\AIM95
2008-02-03 15:12 --------- d-----w C:\Documents and Settings\All Users\Application Data\Google Updater
2008-02-03 09:46 --------- d-----w C:\Documents and Settings\Lori\Application Data\SiteAdvisor
2008-02-02 03:11 --------- d-----w C:\Documents and Settings\Bob\Application Data\SiteAdvisor
2008-01-31 04:17 --------- d-----w C:\Documents and Settings\Noelle\Application Data\SiteAdvisor
2008-01-21 17:29 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-01-21 17:15 158,208 ----a-w C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
2008-01-17 01:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\McAfee
2008-01-17 01:48 --------- d-----w C:\Documents and Settings\Lori\Application Data\McAfee
2008-01-16 21:42 15,360 ----a-w C:\WINDOWS\system32\ctfmon.exe
2008-01-11 03:31 --------- d-----w C:\Program Files\WhiteSmoke
2008-01-09 03:50 --------- d-----w C:\Documents and Settings\All Users\Application Data\DIGStream
2008-01-07 05:38 155,648 ----a-w C:\WINDOWS\system32\igfxtray .exe
2008-01-07 05:38 114,688 ----a-w C:\WINDOWS\system32\hkcmd.exe
2008-01-05 01:56 1,526,640 ----a-w C:\WINDOWS\WRSetup.dll
2008-01-05 01:34 23,920 ----a-w C:\WINDOWS\system32\drivers\sskbfd.sys
2008-01-05 01:34 21,872 ----a-w C:\WINDOWS\system32\drivers\sshrmd.sys
2008-01-05 01:34 20,336 ----a-w C:\WINDOWS\system32\drivers\SSFS0BB9.sys
2008-01-05 01:34 163,696 ----a-w C:\WINDOWS\system32\drivers\ssidrv.sys
2008-01-04 01:45 --------- d-----w C:\Program Files\DL_cats
2008-01-03 04:30 --------- d-----w C:\Program Files\Casino Share Flash Casino
2008-01-02 23:29 --------- d-----w C:\Documents and Settings\All Users\Application Data\MGS
2007-12-31 05:29 --------- d-----w C:\Program Files\Abbyy FineReader 6.0 Sprint
2007-12-31 05:23 --------- d-----w C:\Program Files\Dell_Photo AIO Printer 962
2007-12-30 17:30 --------- d-----w C:\Program Files\Dell_ENA
2007-12-30 17:30 --------- d-----w C:\Program Files\Dell
2007-12-30 16:05 --------- d-----w C:\Program Files\KeyGen Crack
2007-12-30 01:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\espionServerData
2007-12-30 00:38 --------- d-----w C:\Documents and Settings\Lori\Application Data\AdobeUM
2007-12-28 02:04 --------- d-----w C:\Program Files\Common Files\Adobe
2007-12-28 01:56 43,528 ----a-w C:\WINDOWS\system32\drivers\pxhelp20.sys
2007-12-28 01:56 129,784 ----a-w C:\WINDOWS\system32\pxafs.dll
2007-12-28 01:56 118,520 ----a-w C:\WINDOWS\system32\pxinsi64.exe
2007-12-28 01:56 116,472 ----a-w C:\WINDOWS\system32\pxcpyi64.exe
2007-12-27 23:32 --------- d-----w C:\Documents and Settings\Lori\Application Data\Apple Computer
2007-12-23 00:02 --------- d-----w C:\Program Files\BatchPhoto
2007-12-23 00:02 --------- d-----w C:\Documents and Settings\All Users\Application Data\TEMP
2007-12-21 04:02 --------- d-----w C:\Program Files\SiteAdvisor
2007-12-09 21:11 --------- d-----w C:\Program Files\PhotoFiltre
2007-12-08 05:00 --------- d-----w C:\Documents and Settings\LocalService\Application Data\SiteAdvisor
2007-11-09 01:13 164 ----a-w C:\install.dat
2007-11-07 09:26 721,920 ----a-w C:\WINDOWS\system32\lsasrv.dll
2002-05-19 05:57 944,797 ----a-w C:\Program Files\wrar300.exe
2002-05-15 04:37 473 ----a-w C:\Program Files\rarregkey.txt
2002-04-01 13:43 11,264 ----a-w C:\Program Files\readme.wri
.
Code:
<pre>
----a-w 286,720 2008-01-11 13:47:40 C:\Program Files\QuickTime\qttask .exe
----a-w 286,720 2008-01-11 13:47:41 C:\Program Files\QuickTime\qttask .exe
----a-w 5,367,608 2008-01-23 00:48:54 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI .exe
----a-w 155,648 2008-01-07 05:38:41 C:\WINDOWS\system32\igfxtray .exe
</pre>
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}]
2007-03-02 16:52 1298024 -ra------ C:\Program Files\HP\Smart Web Printing\hpswp_printenhancer.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{053F9267-DC04-4294-A72C-58F732D338C0}]
2007-03-02 16:52 177768 -ra------ C:\Program Files\HP\Smart Web Printing\hpswp_framework.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-01-16 16:42 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6172\SiteAdv.exe" [ ]
"QuickTime Task"="C:\Program Files\QuickTime\qttask .exe" [ ]
"PRISMSVR.EXE"="C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\PRISMSVR.exe" [ ]
"Microsoft Works Update Detection"="C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe" [2008-01-08 22:09 28672]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2008-01-22 05:34 582992]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2008-01-21 12:15 158208]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-01-08 22:09 68856]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"McWebDownlMgr"="C:\WINDOWS\TEMP\McDMTemp007 (2)\DwnldMgr.exe" [ ]
C:\Documents and Settings\Lori\Start Menu\Programs\Startup\
NaturalColorLoad.lnk - C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2006-06-25 23:05:30 155715]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2007-03-11 21:26:24 210520]
Logitech SetPoint.lnk - C:\Program Files\Logitech\SetPoint\SetPoint.exe [2006-07-05 19:45:13 450560]
NaturalColorLoad.lnk - C:\Program Files\SEC\Natural Color\NaturalColorLoad.exe [2006-06-25 23:05:30 155715]
Quicken Scheduled Updates.lnk - C:\Program Files\Quicken\bagent.exe [2003-10-02 17:08:08 57344]
Service Manager.lnk - C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe [2000-08-06 00:03:20 69632]
SMC2862W-G EZ Connect g 802.11g Wireless USB Utility.lnk - C:\Program Files\SMC\SMC2862W-G EZ Connect g 2.4Ghz 802.11g Wireless USB 2.0 Adapter\SMCWGUTI.exe [2005-10-17 16:10:34 421888]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2006-04-24 12:13 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~3\GOEC62~1.DLL
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Acrobat Speed Launcher.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Acrobat Speed Launcher.lnk
backup=C:\WINDOWS\pss\Adobe Acrobat Speed Launcher.lnkCommon Startup