ComboFix 09-07-19.04 - Liam 26/07/2009 18:59.2.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.44.1033.18.1982.1220 [GMT 1:00]
Running from: c:\users\Liam\Desktop\ComboFix.exe
Command switches used :: c:\users\Liam\Desktop\CFScript.txt
SP: AdwareAlert *disabled* (Updated) {0C87582F-EF6F-462B-8409-4995FF854620}
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\BitTorrent
c:\program files\BitTorrent\BitTorrentIE.2.dll
c:\program files\BitTorrent\uninst.exe
c:\users\Liam\AppData\Roaming\BitTorrent
c:\users\Liam\AppData\Roaming\BitTorrent\02-Crack The Skye.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\2009 - Common Dreads.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\9.0 Live.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Act A Fool.mp3.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Act A Fool.mp3.2.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Act A Fool.mp3.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Adrenalin_2_2009.TS.ELEKTRI4KA.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\alfie boe - onward.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\American Pie 1.2.3.4.5.6[1999-2007]XviD.NeRoZ.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\American Pie 1.2.3.4.5.6[1999-2007]XviD.NeRoZ.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Arctic Monkeys - Favourite Worst Nightmare 2007 (full album).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Atreyu-Lead_Sails_Paper_Anchor-2007-C4.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Atreyu-Lead_Sails_Paper_Anchor-2007-C4.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Avenged Sevenfold Discography [MP3-320] [h33t] [Louder Than Love].torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Avenged Sevenfold Live in the LBC.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\bittorrent.lng
c:\users\Liam\AppData\Roaming\BitTorrent\Boat Trip Unrated 2002 DvDrip[Eng]-greenbud1969.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Bring Me The Horizon - Suicide Season.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Bullet For My Valentine - Hearts Burst Into Fire (2008) [Mp3][
www.zonatorrent.com].torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Call of duty 4 [PC-DVD] [English] [
www.topetorrent.com].iso.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Cancer Bats - Hail Destroyer.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Coheed And Cambria.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\DevilDriver - Pray For Villains (2009).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\DevilDriver.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\dht.dat
c:\users\Liam\AppData\Roaming\BitTorrent\dht.dat.old
c:\users\Liam\AppData\Roaming\BitTorrent\Dream Theater Discography.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Duffy - Rockferry [2008][CD+2 SkidVid_XviD+Cov]192Kbps.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\DvD Santa 5.8.4 Full + Crack.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Dvd Santa v 4.5 Blackcat.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\DVDSanta v4.50 Cracked.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\DvdSanta_4.5.rar.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family Guy - Season 5.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family Guy - Season 7.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family Guy Season 4 - Complete.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family Guy Season 6.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family Guy Seasons 1-7.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E01.PDTV.XviD-ETACH.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E02.READNFO.PDTV.XviD-SYS.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E03.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E04.PDTV.XviD-2HD.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E05.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E06.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E07.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E08.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E09.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E10.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Family.Guy.S07E11.PDTV.XviD-LOL.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Fear Factory.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Five Finger Death Punch.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Gojira Discography.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Guitar Hero World Tour Soundtrack 192kbs+.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Helter Skelter Vs Raindance Present Rave Nation The Anthems [3CD] [2007] [320kbps] (elmarko99).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Helter Skelter Vs Raindance Rave Nation 3cd's (widgetzone.co.uk).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Heroes - Season 1 - DVD-rip.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Heroes Season 1 Complete-Xvid-MFG.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\inbetweeners.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Indestructible.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Indestructible.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Invaders_Must_Die.mp3.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Invaders_Must_Die.mp3.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Jack Johnson.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Jack_Johnson-Sleep_Through_The_Static-(Deluxe_Edition)-2CD-2008-EON.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Kings Of Leon - Only By The Night[2008][MP3@320kbps]-antecho.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Knowing.DVDRip.XviD-DiAMOND.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Knowing.DVDRip.XviD-DiAMOND.2.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Knowing.DVDRip.XviD-DiAMOND.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\KoRn.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Lamb Of God-Wrath.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Lamb_of_God-New_American_Gospel-(Reissue)-2006-BUTT.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Lil Jon Ft. Three 6 Mafia- Act A Fool.mp3.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Lil Jon Ft. Three 6 Mafia- Act A Fool.mp3.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Linkin Park - Minutes To Midnight [2007][CD+SkidVid+Cov].torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head - The Blackening.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head - The Blackening.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head - Through the Ashes of Empires [2003] - Zz.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.2.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.3.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.4.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.5.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.6.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.7.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Machine Head.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mastodon.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Metallica - Discography 1983-2008 (19 Albums, 23 CDs).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Meteora.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission Impossible 2.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission Impossible III(2006)DVDrip(AC3-5.1)- keltz.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission Impossible(1996)DVDrip(AC3-5.1)- keltz.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission Impossible(1996)DVDrip(AC3-5.1)- keltz.2.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission Impossible(1996)DVDrip(AC3-5.1)- keltz.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission.Impossible.2.DVDRip.XviD-W.A.L.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Mission.Impossible.2.DVDRip.XviD-W.A.L.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Nightwish- Dark Passion Play.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Office 2007.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\OFFICE07_ENTERPRISE.iso.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Onward.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Pendulum-In_Silico-2008-DV8.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Portable Microsoft Office 2007 Enterprise.exe.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Quarantine.2008.DvDRip-FxM.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Queen discography (MP3@320Kbps).1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Queen discography (MP3@320Kbps).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Queen.Sheer Heart Attack.1974.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\resume.dat
c:\users\Liam\AppData\Roaming\BitTorrent\resume.dat.old
c:\users\Liam\AppData\Roaming\BitTorrent\roadrunner united-the concert.avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\rss.dat
c:\users\Liam\AppData\Roaming\BitTorrent\rss.dat.old
c:\users\Liam\AppData\Roaming\BitTorrent\Saw.5[2008][Unrated.Edition]DvDrip-aXXo.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\settings.dat
c:\users\Liam\AppData\Roaming\BitTorrent\settings.dat.old
c:\users\Liam\AppData\Roaming\BitTorrent\Shooter[2007]DvDrip[Eng]-aXXo.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Slipknot-Vol_3-(The_Subliminal_Verses)-2004-RNS.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\SLIPKNOT - DISCOGRAPHY [CHANNEL NEO].1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\SLIPKNOT - DISCOGRAPHY [CHANNEL NEO].torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Slipknot - Vol 3 (The Subliminal Verses) - 2004.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Slipknot.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Sniper [1993]DVDRip[Xvid AC3[2ch]-RoCK&BlueLadyRG..avi.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Sniper.DVDRip.Xvid.1993-tots.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Static-X - discography (6 studio albums).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Stone Sour - 2002 - Stone Sour.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Stone_Sour-Come_What(Ever)_May-(Special_Edition)-2007-uF.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Sylosis - Conclusion of an Age (2008).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The All Star Sessions.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The Hoosiers - The Trick To Life.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The Script - We Cry.mp3.1.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The Script - We Cry.mp3.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The Sniper[2009]DVDrip[Zho]+Eng hardsub -alwaysontop.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\The.Script.The Script.2008.320kbps.mp3.nikita.rar.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Transformers[2007]DvDrip[Eng]-aXXo.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Transporter.3[2008]DvDrip-aXXo.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Trivium - Shogun [Special Edition (2008)].torrent
c:\users\Liam\AppData\Roaming\BitTorrent\U2 - Discography [VBR-Extreme] {iMog}.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\VA - Ministry Of Sound Anthems (1991-2008) [Mp3][
www.zonatorrent.com].rar.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\VA.-.Ministry.Of.Sound.Saturday.Night.Club.Classics.3CDs.(2009).Dance.LanzamientosMp3.es.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Valkyrie[2008]DvDrip[Eng]-FXG.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Vol 3 (The Subliminal Verses).torrent
c:\users\Liam\AppData\Roaming\BitTorrent\Vol. 3- The Subliminal Verses.torrent
c:\users\Liam\AppData\Roaming\BitTorrent\xXx State of the Union [2005]DVDRip[Xvid AC3[5.1]-RoCK&BlueLadyRG.avi.torrent
c:\users\Liam\AppData\Roaming\LimeWire
c:\users\Liam\AppData\Roaming\LimeWire\bugs.data
c:\users\Liam\AppData\Roaming\LimeWire\certificate\limewire.keystore
c:\users\Liam\AppData\Roaming\LimeWire\createtimes.cache
c:\users\Liam\AppData\Roaming\LimeWire\downloads.dat
c:\users\Liam\AppData\Roaming\LimeWire\fileurns.bak
c:\users\Liam\AppData\Roaming\LimeWire\fileurns.cache
c:\users\Liam\AppData\Roaming\LimeWire\filters.props
c:\users\Liam\AppData\Roaming\LimeWire\gnutella.net
c:\users\Liam\AppData\Roaming\LimeWire\installation.props
c:\users\Liam\AppData\Roaming\LimeWire\library.dat
c:\users\Liam\AppData\Roaming\LimeWire\limewire.props
c:\users\Liam\AppData\Roaming\LimeWire\mojito.props
c:\users\Liam\AppData\Roaming\LimeWire\promotion\promodb.backup
c:\users\Liam\AppData\Roaming\LimeWire\promotion\promodb.data
c:\users\Liam\AppData\Roaming\LimeWire\promotion\promodb.properties
c:\users\Liam\AppData\Roaming\LimeWire\promotion\promodb.script
c:\users\Liam\AppData\Roaming\LimeWire\questions.props
c:\users\Liam\AppData\Roaming\LimeWire\responses.cache
c:\users\Liam\AppData\Roaming\LimeWire\simpp.xml
c:\users\Liam\AppData\Roaming\LimeWire\spam.dat
c:\users\Liam\AppData\Roaming\LimeWire\tables.props
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme.lwtp
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\01_star.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\02_star.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\03_star.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\04_star.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\05_star.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\chat.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\forward_dn.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\forward_up.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\kill.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\kill_on.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\pause_dn.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\pause_up.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\play_dn.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\play_up.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\question.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\rewind_dn.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\rewind_up.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\stop_dn.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\stop_up.gif
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\theme.txt
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\version.txt
c:\users\Liam\AppData\Roaming\LimeWire\themes\windows_theme\warning.gif
c:\users\Liam\AppData\Roaming\LimeWire\ttrees.cache
c:\users\Liam\AppData\Roaming\LimeWire\ttroot.cache
c:\users\Liam\AppData\Roaming\LimeWire\version.xml
c:\users\Liam\AppData\Roaming\LimeWire\versions.props
c:\users\Liam\AppData\Roaming\LimeWire\xml\data\audio.sxml2
.
((((((((((((((((((((((((( Files Created from 2009-06-26 to 2009-07-26 )))))))))))))))))))))))))))))))
.
2009-07-26 09:23 . 2009-07-13 08:00 87888 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\NAVENG.SYS
2009-07-26 09:23 . 2009-07-13 08:00 875728 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\NAVEX15.SYS
2009-07-26 09:23 . 2009-04-04 09:04 177520 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\NAVENG32.DLL
2009-07-26 09:23 . 2009-04-04 09:04 1181040 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\NAVEX32A.DLL
2009-07-26 09:23 . 2009-04-04 09:04 371248 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\EECTRL.SYS
2009-07-26 09:23 . 2009-04-04 09:04 259368 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\ECMSVR32.DLL
2009-07-26 09:23 . 2009-04-04 09:04 2414128 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\CCERASER.DLL
2009-07-26 09:23 . 2009-04-04 09:04 101936 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20090725.020\ERASER.SYS
2009-07-24 22:22 . 2009-07-26 17:46 -------- d-----w- c:\program files\Spybot - Search & Destroy
2009-07-24 22:22 . 2009-07-24 22:25 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2009-07-21 14:05 . 2009-06-15 15:24 156672 ----a-w- c:\windows\system32\t2embed.dll
2009-07-21 14:05 . 2009-06-15 15:20 72704 ----a-w- c:\windows\system32\fontsub.dll
2009-07-21 14:05 . 2009-06-15 12:52 289792 ----a-w- c:\windows\system32\atmfd.dll
2009-07-21 14:05 . 2009-06-15 15:20 10240 ----a-w- c:\windows\system32\dciman32.dll
2009-07-19 21:58 . 2009-07-19 21:58 -------- d-----w- c:\users\Liam\AppData\Roaming\Malwarebytes
2009-07-19 21:58 . 2009-07-13 12:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-19 21:58 . 2009-07-19 21:58 -------- d-----w- c:\programdata\Malwarebytes
2009-07-19 21:58 . 2009-07-19 21:58 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-07-19 21:58 . 2009-07-13 12:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-19 15:01 . 2009-07-19 15:02 -------- d-----w- C:\rsit
2009-07-17 18:22 . 2009-07-11 19:34 276344 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSXpx86.sys
2009-07-17 18:22 . 2009-07-11 19:34 293424 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSvix86.sys
2009-07-17 18:22 . 2009-07-11 19:34 533880 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\Scxpx86.dll
2009-07-17 18:22 . 2009-07-11 19:34 451960 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSxpx86.dll
2009-07-17 18:22 . 2009-07-11 19:34 397360 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSviA64.sys
2009-07-16 19:57 . 2009-07-16 19:57 -------- d-----w- c:\program files\iPod
2009-07-16 19:57 . 2009-07-16 19:57 -------- d-----w- c:\program files\iTunes
2009-07-16 19:52 . 2009-07-16 19:52 75040 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.2.1.6\SetupAdmin.exe
2009-07-16 13:49 . 2009-07-16 13:49 -------- d-----w- c:\program files\Trend Micro
2009-07-15 21:59 . 2009-07-15 21:59 -------- d-----w- c:\program files\PFPortChecker
2009-07-15 10:38 . 2009-07-11 19:34 276344 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSXpx86.sys
2009-07-15 10:38 . 2009-07-11 19:34 293424 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSvix86.sys
2009-07-15 10:38 . 2009-07-11 19:34 533880 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\Scxpx86.dll
2009-07-15 10:38 . 2009-07-11 19:34 451960 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSxpx86.dll
2009-07-15 10:38 . 2009-07-11 19:34 397360 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090712.001\IDSviA64.sys
2009-07-14 22:49 . 2009-07-14 22:49 -------- d-----w- c:\program files\ERUNT
2009-07-11 19:34 . 2009-07-11 19:34 276344 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSXpx86.sys
2009-07-11 19:34 . 2009-07-11 19:34 293424 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSvix86.sys
2009-07-11 19:34 . 2009-07-11 19:34 533880 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\Scxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 451960 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSxpx86.dll
2009-07-11 19:34 . 2009-07-11 19:34 397360 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\BinHub\IDSviA64.sys
2009-07-02 22:32 . 2009-07-02 22:34 -------- d-----w- c:\users\Liam\AppData\Roaming\fretsonfire
2009-07-02 22:32 . 2009-07-02 22:32 -------- d-----w- c:\program files\Frets on Fire
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-26 18:11 . 2008-01-28 18:39 -------- d-----w- c:\programdata\Kontiki
2009-07-26 17:47 . 2009-06-04 20:51 142112 ----a-w- c:\programdata\nvModes.dat
2009-07-26 17:47 . 2008-10-18 20:20 -------- d-----w- c:\program files\SpeedBit Video Accelerator
2009-07-26 01:56 . 2009-07-26 01:56 1317 ----a-w- c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\tmpa39.tmp\cur.scr
2009-07-24 17:22 . 2008-03-09 20:19 -------- d-----w- c:\program files\Microsoft Silverlight
2009-07-22 02:07 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2009-07-22 02:07 . 2007-11-01 13:08 -------- d-----w- c:\programdata\Microsoft Help
2009-07-20 11:14 . 2008-11-03 14:40 -------- d-----w- c:\program files\Applications
2009-07-18 12:35 . 2009-02-09 19:55 1 ----a-w- c:\users\Liam\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-18 12:13 . 2007-12-25 18:15 -------- d-----w- c:\program files\Steam
2009-07-18 12:01 . 2007-12-25 18:15 -------- d-----w- c:\program files\Common Files\Steam
2009-07-16 19:57 . 2008-05-06 18:26 -------- d-----w- c:\program files\Common Files\Apple
2009-07-15 19:04 . 2009-04-16 14:28 -------- d-----w- c:\users\Liam\AppData\Roaming\Spotify
2009-06-24 13:04 . 2008-12-08 18:41 -------- d-----w- c:\program files\dvdSanta
2009-06-21 16:57 . 2009-06-21 16:49 -------- d-----w- c:\users\Liam\AppData\Roaming\ImgBurn
2009-06-21 14:07 . 2009-06-21 14:06 -------- d-----w- c:\program files\ImgBurn
2009-06-18 10:26 . 2007-12-25 07:53 131528 ----a-w- c:\users\Liam\AppData\Local\GDIPFONTCACHEV1.DAT
2009-06-11 21:52 . 2009-06-11 21:52 1915520 ----a-w- c:\users\Liam\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\fpupdateax\fpupdateax.exe
2009-06-10 02:15 . 2007-11-01 13:06 -------- d-----w- c:\program files\Microsoft Works
2009-06-09 17:47 . 2009-06-09 17:47 -------- d-----w- c:\program files\Broadcom
2009-06-09 17:28 . 2008-03-11 16:40 10134 ----a-r- c:\users\Liam\AppData\Roaming\Microsoft\Installer\{CAE7D1D9-3794-4169-B4DD-964ADBC534EE}\ARPPRODUCTICON.exe
2009-06-05 08:02 . 2008-03-10 16:46 -------- d-----w- c:\programdata\NVIDIA
2009-06-04 18:21 . 2007-12-25 10:50 142112 ----a-w- c:\users\Liam\AppData\Roaming\nvModes.dat
2009-06-04 16:38 . 2008-01-14 21:04 -------- d-----w- c:\program files\Avanquest update
2009-06-02 20:58 . 2009-06-02 20:57 -------- d-----w- c:\program files\QuickTime
2009-05-29 15:40 . 2009-05-29 15:40 -------- d-----w- c:\program files\AGEIA Technologies
2009-05-29 15:38 . 2008-04-14 16:52 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-29 15:38 . 2009-05-29 15:38 -------- d-----w- c:\program files\OpenAL
2009-05-29 15:38 . 2009-05-29 15:38 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-05-29 15:38 . 2009-05-29 15:38 110592 ----a-w- c:\windows\system32\OpenAL32.dll
2009-05-29 12:36 . 2009-05-29 12:36 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 12:36 . 2009-05-29 12:36 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-04-30 12:37 . 2009-06-13 19:49 293376 ----a-w- c:\windows\system32\psisdecd.dll
2009-04-30 12:37 . 2009-06-13 19:49 428544 ----a-w- c:\windows\system32\EncDec.dll
2009-06-14 19:47 . 2009-05-24 11:46 134648 ----a-w- c:\program files\mozilla firefox\components\brwsrcmp.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-07-20_11.54.43 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-07-21 14:05 . 2009-06-15 14:58 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 14:58 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 14:58 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\dciman32.dll
+ 2009-07-21 14:05 . 2009-06-15 12:45 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmlib.dll
+ 2009-07-21 14:05 . 2009-06-15 14:52 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 14:52 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 14:51 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\dciman32.dll
+ 2009-07-21 14:05 . 2009-04-11 06:28 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmlib.dll
+ 2009-07-21 14:05 . 2009-06-15 15:22 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 15:19 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\dciman32.dll
+ 2009-07-21 14:05 . 2009-06-15 15:19 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmlib.dll
+ 2008-06-05 16:53 . 2008-01-19 07:34 23552 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 15:20 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 15:20 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\dciman32.dll
+ 2006-11-02 08:38 . 2006-11-02 09:46 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmlib.dll
+ 2009-07-21 14:05 . 2009-06-15 15:04 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 15:03 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 15:02 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\dciman32.dll
+ 2009-07-21 14:05 . 2009-06-15 15:02 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmlib.dll
+ 2009-07-21 14:05 . 2009-06-15 15:23 24064 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\lpk.dll
+ 2009-07-21 14:05 . 2009-06-15 15:22 72704 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\fontsub.dll
+ 2009-07-21 14:05 . 2009-06-15 15:21 10240 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\dciman32.dll
+ 2009-07-21 14:05 . 2009-06-15 15:20 34304 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmlib.dll
+ 2007-11-01 12:07 . 2009-07-26 17:49 66486 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2006-11-02 13:05 . 2009-07-26 17:49 96788 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2007-12-25 07:45 . 2009-07-26 17:49 17144 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-372054243-2330875446-1311136529-1000_UserData.bin
- 2007-12-25 07:39 . 2009-07-20 11:21 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-25 07:39 . 2009-07-26 17:47 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-12-25 07:39 . 2009-07-26 17:47 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-12-25 07:39 . 2009-07-20 11:21 65536 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-12-25 07:39 . 2009-07-26 17:47 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-12-25 07:39 . 2009-07-20 11:21 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-05-14 02:05 . 2009-06-14 09:49 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 35088 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 18704 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 20240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-11-03 12:13 . 2009-06-10 02:17 35088 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-11-03 12:13 . 2009-07-22 02:07 35088 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-11-03 12:13 . 2009-06-10 02:17 18704 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-11-03 12:13 . 2009-07-22 02:07 18704 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-11-03 12:13 . 2009-06-10 02:17 20240 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-11-03 12:13 . 2009-07-22 02:07 20240 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\cagicon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 35088 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\oisicon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 18704 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\mspicons.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 20240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\cagicon.exe
+ 2006-10-26 20:09 . 2006-10-26 20:09 48448 c:\windows\Installer\$PatchCache$\Managed\00002119030000000000000000F01FEC\12.0.4518\PUBTRAP.DLL
+ 2009-07-26 17:46 . 2009-07-26 17:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-07-20 11:18 . 2009-07-20 11:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-07-26 17:46 . 2009-07-26 17:46 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-07-20 11:18 . 2009-07-20 11:18 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-21 14:05 . 2009-06-15 12:45 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.22152_none_ac0f1dd570f10812\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 12:42 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6002.18051_none_ab8480c057d44ef1\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 12:56 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.22450_none_aa26ab5973cc8040\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 12:52 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6001.18272_none_a9896d645abd4ddf\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 12:53 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.21067_none_a83c750976a7f2bc\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 13:03 289792 c:\windows\winsxs\x86_microsoft-windows-gdi_31bf3856ad364e35_6.0.6000.16870_none_a7a12e2a5d988a40\atmfd.dll
+ 2009-07-21 14:05 . 2009-06-15 15:00 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.22152_none_b7fc28a4355e72c9\t2embed.dll
+ 2009-07-21 14:05 . 2009-06-15 14:53 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6002.18051_none_b7718b8f1c41b9a8\t2embed.dll
+ 2009-07-21 14:05 . 2009-06-15 15:26 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.22450_none_b613b6283839eaf7\t2embed.dll
+ 2009-07-21 14:05 . 2009-06-15 15:24 156672 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6001.18272_none_b57678331f2ab896\t2embed.dll
+ 2009-07-21 14:05 . 2009-06-15 15:09 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.21067_none_b4297fd83b155d73\t2embed.dll
+ 2009-07-21 14:05 . 2009-06-15 15:29 156160 c:\windows\winsxs\x86_microsoft-windows-font-embedding_31bf3856ad364e35_6.0.6000.16870_none_b38e38f92205f4f7\t2embed.dll
+ 2008-06-05 21:42 . 2009-07-26 17:39 542440 c:\windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2006-11-02 12:47 . 2009-07-22 02:14 452472 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2009-06-21 19:27 452472 c:\windows\System32\FNTCACHE.DAT
- 2009-05-14 02:05 . 2009-06-14 09:49 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 888080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 272648 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 922384 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 845584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\outicon.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 217864 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 184080 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 159504 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2008-11-03 12:13 . 2009-07-22 02:07 272648 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\pubs.exe
- 2008-11-03 12:13 . 2009-06-10 02:17 272648 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\pubs.exe
- 2008-11-03 12:13 . 2009-06-10 02:17 217864 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\misc.exe
+ 2008-11-03 12:13 . 2009-07-22 02:07 217864 c:\windows\Installer\{91120000-0019-0000-0000-0000000FF1CE}\misc.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 888080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\wordicon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 272648 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pubs.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 922384 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\pptico.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 845584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\outicon.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 217864 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\misc.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 184080 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\joticon.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 159504 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\inficon.exe
+ 2009-07-21 14:05 . 2009-06-17 08:02 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22160_none_f4b74f0181eee730\OESpamFilter.dat
+ 2009-07-21 14:05 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18056_none_f43e83de68c3c37f\OESpamFilter.dat
+ 2009-07-21 14:05 . 2009-06-17 07:30 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22459_none_f2e4af9f84b85a2a\OESpamFilter.dat
+ 2009-07-21 14:05 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18278_none_f24470cc6babdbc4\OESpamFilter.dat
+ 2009-07-21 14:05 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21074_none_f0e3a5eb87a6b883\OESpamFilter.dat
+ 2009-07-21 14:05 . 2009-06-17 07:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16876_none_f05c31926e871825\OESpamFilter.dat
- 2006-11-02 10:22 . 2009-06-14 13:51 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2006-11-02 10:22 . 2009-07-22 02:26 6553600 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2009-05-26 17:54 . 2009-05-26 17:54 4192768 c:\windows\Installer\85257f2.msp
+ 2009-07-02 15:23 . 2009-07-02 15:23 5027328 c:\windows\Installer\85257c1.msp
- 2009-05-14 02:05 . 2009-06-14 09:49 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 1172240 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-05-14 02:05 . 2009-07-22 02:06 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2009-05-14 02:05 . 2009-06-14 09:49 1165584 c:\windows\Installer\{91120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 1172240 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-03-03 20:02 . 2009-07-22 02:06 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
- 2008-03-03 20:02 . 2009-06-14 09:50 1165584 c:\windows\Installer\{90120000-0030-0000-0000-0000000FF1CE}\accicons.exe
+ 2006-11-02 10:24 . 2009-07-07 15:10 24539592 c:\windows\System32\mrt.exe
+ 2009-07-23 02:01 . 2009-07-23 02:01 15706112 c:\windows\Installer\51af650.msp
+ 2009-05-01 17:15 . 2009-07-22 02:05 124668293 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-02-22 39408]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-03-28 1045800]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-03-29 176128]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-03-06 180224]
"HP Health Check Scheduler"="c:\program files\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [2007-03-12 50696]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 472776]
"WAWifiMessage"="c:\program files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 317128]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-04-23 1032640]
"SynTPStart"="c:\program files\Synaptics\SynTP\SynTPStart.exe" [2007-09-15 102400]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-08 136600]
"PAC7302_Monitor"="c:\windows\PixArt\PAC7302\Monitor.exe" [2006-11-03 319488]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-12-04 13556256]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2008-12-04 92704]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-07-13 292128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"Launcher"="c:\windows\SMINST\launcher.exe" [2006-11-08 44128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
@="FSFilter Activity Monitor"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Liam^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{2F9854F3-AC38-4486-AE5C-E87A73EA7415}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{3678B8CA-D23D-4F12-8A9D-9F5B84014CDB}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{CCA5CED6-67CF-47B1-ADB1-FB73210513FC}"= c:\program files\HP\QuickPlay\QP.exe:Quick Play
"{A93F5935-1EF5-4F1C-BACF-6EE8E5A5CD76}"= c:\program files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{01A55B4E-7193-471A-8CD5-FA83CB343826}"= UDP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{0009A439-7B0C-4D67-9471-7BF1DFB6B3C6}"= TCP:c:\program files\Kontiki\KService.exe

elivery Manager Service
"{460D55FE-BF87-41B1-AEEE-68695FADDE16}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{0E6030B2-45FB-46D4-91FE-CDB9555E59C6}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{6F6A0710-0A41-4A05-A285-C8B60A7CA368}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{92E805AA-A9D9-40E1-940C-C8B446E5BEC7}"= UDP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{DF7F33BC-3F59-44AB-8EDF-80453A39BDBF}"= TCP:c:\windows\System32\PnkBstrA.exe

nkBstrA
"{DBAE5092-94E6-47F1-9119-3A66B996EB85}"= UDP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{A1837AA8-D4F6-4122-9D76-56FAA7DF3591}"= TCP:c:\windows\System32\PnkBstrB.exe

nkBstrB
"{D89ECC13-9D1F-4BD6-ACB4-1F06CB85914F}"= UDP:c:\program files\WarRock\WRLauncher.exe:War Rock
"{0E424058-9EDB-4466-B534-5271F41B2B55}"= TCP:c:\program files\WarRock\WRLauncher.exe:War Rock
"{BC54951D-9808-495B-A6F5-7771BA75F84D}"= UDP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo
"{D2A148E4-07EE-420C-96CC-C9678D0D90ED}"= TCP:c:\program files\Ventrilo\Ventrilo.exe:Ventrilo
"TCP Query User{111C1AB7-E027-40A4-BF1C-66FAB6C1C9EE}c:\\program files\\warrock\\system\\warrock.exe"= UDP:c:\program files\warrock\system\warrock.exe:WarRock
"UDP Query User{669747FB-67ED-47E3-B233-7B23F7ED24EC}c:\\program files\\warrock\\system\\warrock.exe"= TCP:c:\program files\warrock\system\warrock.exe:WarRock
"{2C495F18-67A6-4C26-8D12-223DBD6AF326}"= UDP:c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{225135D3-5018-4970-9B9F-17128305B0C3}"= TCP:c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{DB7E5DCE-0816-4B04-8E6D-942A304972F9}"= UDP:c:\program files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{E6167A23-54B3-4103-9E6B-6B95B09F73F1}"= TCP:c:\program files\SpeedBit Video Accelerator\VideoAcceleratorEngine.exe:VideoAcceleratorService
"{BE92A758-4D3A-44F2-B538-2267EB7F424E}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{318C4DBD-1F0C-4002-B642-96E99D79A887}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager
"{7CD14C86-47D5-45D6-B171-17F3CEEFD37D}"= UDP:c:\program files\WarRock\WRUpdater.exe:WRUpdater
"{DA700DF3-B65D-44C5-B281-3BF637692A96}"= TCP:c:\program files\WarRock\WRUpdater.exe:WRUpdater
"{C54F5CCB-CA4D-4F6E-9DD1-E8684D2ADC3F}"= UDP:5340:warrock1
"{A9EF007B-2403-40AF-B5C1-13AA261F92C0}"= UDP:5350:warrock2
"{538359DD-3E0A-4DF8-AA87-2751ED2EF9B0}"= TCP:5340:warrock1-
"{08541AD8-ED52-48C8-9176-1D35E26EA28B}"= TCP:5350:warrock2-
"TCP Query User{98AD21F9-523D-482E-BFD5-6ACA750F5E2E}c:\\ijji\\english\\u_gunz.exe"= UDP:c:\ijji\english\u_gunz.exe:<ijji Downloader>
"UDP Query User{6A1AED19-77BE-44B7-A8B4-92ECBE534771}c:\\ijji\\english\\u_gunz.exe"= TCP:c:\ijji\english\u_gunz.exe:<ijji Downloader>
"TCP Query User{3BCDA863-BDC0-411B-A567-3AC9E8934917}c:\\program files\\ijji\\gunz\\gunz.exe"= UDP:c:\program files\ijji\gunz\gunz.exe:Gunz
"UDP Query User{10E65A74-22BD-4795-87C2-F4B4BDEFEFCF}c:\\program files\\ijji\\gunz\\gunz.exe"= TCP:c:\program files\ijji\gunz\gunz.exe:Gunz
"TCP Query User{11238811-1357-4351-9841-32F47A46BF83}c:\\program files\\steam\\steamapps\\boom_headshot92\\counter-strike source\\hl2.exe"= UDP:c:\program files\steam\steamapps\boom_headshot92\counter-strike source\hl2.exe:hl2
"UDP Query User{FA6553BC-615F-41FA-85F0-60D6CB3C6BB7}c:\\program files\\steam\\steamapps\\boom_headshot92\\counter-strike source\\hl2.exe"= TCP:c:\program files\steam\steamapps\boom_headshot92\counter-strike source\hl2.exe:hl2
"TCP Query User{5690BF13-1631-4704-ACBA-990CF0B82211}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{2A0BEABB-0427-47F4-A1C5-2418E77F0DDA}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{FEAC0024-48C2-42D1-B5FB-FCBDAF8B2754}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{A4F1DA50-3489-452F-8753-84D1C8714A55}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{88EADD12-4ED1-4E1E-96EB-CF6CD1D35DF5}c:\\program files\\sopcast\\sopcast.exe"= UDP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"UDP Query User{3C2FA847-4030-478A-B57B-43FB596CFBEE}c:\\program files\\sopcast\\sopcast.exe"= TCP:c:\program files\sopcast\sopcast.exe:SopCast Main Application
"TCP Query User{28F5AFBF-7CA7-46EA-9630-E0C6356FFB7F}c:\\program files\\tvuplayer\\tvuplayer.exe"= UDP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"UDP Query User{EB303942-F161-44B7-AB4D-EBEC4A53423C}c:\\program files\\tvuplayer\\tvuplayer.exe"= TCP:c:\program files\tvuplayer\tvuplayer.exe:TVUPlayer Component
"TCP Query User{5F432A92-3206-4A13-966B-FE45D601B2CB}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe

elivery Manager
"UDP Query User{56427B38-0ECA-4FA5-9400-7073972B91B0}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe

elivery Manager
"TCP Query User{965766B2-CC02-446D-8FEB-2C211DAF15F9}c:\\program files\\xfire\\xfire.exe"= UDP:c:\program files\xfire\xfire.exe:Xfire
"UDP Query User{FE5A61D7-95E9-4C72-ABD8-48A145968E50}c:\\program files\\xfire\\xfire.exe"= TCP:c:\program files\xfire\xfire.exe:Xfire
"{903FA4B5-8717-49EE-A947-B7E5038EF053}"= UDP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{1E695FAB-33AA-4853-A5FE-0F5992C68482}"= TCP:c:\nexon\Combat Arms\NMService.exe:Nexon Messenger Core
"{3F435204-0C0A-4C86-897A-BED348706E24}"= UDP:c:\program files\Outspark\Blackshot\System\BlackShot.exe:BlackShot
"{D3CAC5B2-3FF1-4C2F-A580-C1A2526D072B}"= TCP:c:\program files\Outspark\Blackshot\System\BlackShot.exe:BlackShot
"{B8245A3D-3115-448C-9C70-CEBC006C47E2}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{9221FB9B-AC0A-46EA-B389-E17A8C3F6DDA}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{F364E0D4-1637-4E85-B707-23962E28FA16}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{B99D147D-ACF1-4718-966F-40AC5E3C8CC8}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{058BA2B7-1A84-476C-B0DE-52452ED89294}c:\\program files\\sopcast\\adv\\sopadver.exe"= UDP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"UDP Query User{68B1F231-7BF7-4F31-B594-EC99AB1FB6A5}c:\\program files\\sopcast\\adv\\sopadver.exe"= TCP:c:\program files\sopcast\adv\sopadver.exe:SopCast Adver
"TCP Query User{7570F2E7-7D97-4C28-BF08-514646117380}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{32DDAAD6-E56C-420B-9E63-15CFA991762A}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"{66BD5FED-547A-4B78-9138-BA26E03799A7}"= UDP:c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"{98E14509-25A2-44ED-B808-906783D23615}"= TCP:c:\program files\SpeedBit Video Accelerator\VideoAccelerator.exe:VideoAccelerator
"TCP Query User{EA3B91C1-741B-4186-A4C8-98E7E76CB3FE}c:\\program files\\kontiki\\khost.exe"= UDP:c:\program files\kontiki\khost.exe

elivery Manager
"UDP Query User{8034258D-17BF-43BB-8EAE-6C96F5475F84}c:\\program files\\kontiki\\khost.exe"= TCP:c:\program files\kontiki\khost.exe

elivery Manager
"{722BA519-F706-439F-835D-AD6449E74D42}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{66B0D315-0C4D-4DA2-8920-1640ED788825}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B59346AC-ADA9-4975-867B-1687B09670C8}"= UDP:c:\program files\Spotify\spotify.exe:Spotify
"{A3CBC77E-40D1-46FF-8816-C50BF545A8F2}"= TCP:c:\program files\Spotify\spotify.exe:Spotify
"{B9D2DA88-9278-4E30-A8C3-88C533597028}"= UDP:c:\program files\Steam\steamapps\common\unreal tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{317CCB46-2E7C-4E6D-BF4A-C79B5B315786}"= TCP:c:\program files\Steam\steamapps\common\unreal tournament 3\Binaries\UT3.exe:Unreal Tournament 3
"{7F53FD7B-1336-4AB1-8093-B2FF9D8502FE}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{D3312698-DAF5-49A0-8A53-67F8FCADEAD7}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{07FF5332-54CB-4830-9F3C-761E63C79501}"= UDP:c:\program files\Spotify\spotify.exe:Spotify
"{4F368DEC-85B7-4430-8347-C99FF5317029}"= TCP:c:\program files\Spotify\spotify.exe:Spotify
"{5DBA1D18-0C5D-4AC9-AC76-E8B88F2E4997}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{482208A3-AFEE-4858-AF50-D6E9D743DA18}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\Nexon\\Combat Arms\\CombatArms.exe"= c:\nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe
"c:\\Nexon\\Combat Arms\\Engine.exe"= c:\nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe
R0 SymEFA;Symantec Extended File Attributes;c:\windows\System32\drivers\NIS\1005000.087\SymEFA.sys [24/03/2009 22:03 310320]
R1 BHDrvx86;Symantec Heuristics Driver;c:\windows\System32\drivers\NIS\1005000.087\BHDrvx86.sys [24/03/2009 22:03 258608]
R1 ccHP;Symantec Hash Provider;c:\windows\System32\drivers\NIS\1005000.087\cchpx86.sys [24/03/2009 22:02 482352]
R1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\IPSDefs\20090715.003\IDSvix86.sys [17/07/2009 19:22 293424]
R2 Norton Internet Security;Norton Internet Security;c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe [24/03/2009 22:02 115560]
R2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [24/07/2009 23:23 1153368]
R2 VideoAcceleratorService;VideoAcceleratorService;c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm --> c:\progra~1\SPEEDB~1\VideoAcceleratorService.exe -start -scm [?]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [09/04/2009 15:42 101936]
R3 SYMNDISV;Symantec Network Filter Driver;c:\windows\System32\drivers\NIS\1005000.087\symndisv.sys [24/03/2009 22:03 39984]
S3 MotDev;Motorola Inc. USB Device;c:\windows\System32\drivers\motodrv.sys [10/10/2007 18:41 42112]
S3 PAC7302;PLEOMAX PWC-2100 Pleo Chat Cam;c:\windows\System32\drivers\PAC7302.SYS [10/09/2007 09:50 457984]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.co.uk/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=73&bd=Pavilion&pf=laptop
uInternet Settings,ProxyOverride = localhost
IE: &ieSpell Options - c:\program files\ieSpell\iespell.dll/SPELLOPTION.HTM
IE: Check &Spelling - c:\program files\ieSpell\iespell.dll/SPELLCHECK.HTM
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Lookup on Merriam Webster - file://c:\program files\ieSpell\Merriam Webster.HTM
IE: Lookup on Wikipedia - file://c:\program files\ieSpell\wikipedia.HTM
FF - ProfilePath - c:\users\Liam\AppData\Roaming\Mozilla\Firefox\Profiles\p9wrxmke.default\
FF - prefs.js: browser.startup.homepage -
www.soccermanager.com
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\coFFPlgn\components\coFFPlgn.dll
FF - component: c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\IPSFFPlgn\components\IPSFFPl.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npbittorrent.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-26 19:10
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\Norton Internet Security]
"ImagePath"="\"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\ccSvcHst.exe\" /s \"Norton Internet Security\" /m \"c:\program files\Norton Internet Security\Norton Internet Security\Engine\16.5.0.135\diMaster.dll\" /prefetch:1"
.
Completion time: 2009-07-26 19:22
ComboFix-quarantined-files.txt 2009-07-26 18:22
ComboFix2.txt 2009-07-20 12:00
Pre-Run: 750,268,416 bytes free
Post-Run: 4,061,335,552 bytes free
606 --- E O F --- 2009-07-23 02:01
My computer is running much better and I no longer get redirected from google
