redirect URLs and ComboFix log
The redirects seem to be (to my naive eye based on the Firefox history file) either Google ads or aggregator sites. Below is a sample (to the best I could assess from the History file) followed by the ComboFix log.
I will be out of town for a couple of days and won't be able to reply. Just didn't want you to think I was ignoring any reply. I will check again on Friday.
http://google.ad.sgdoubleclick.net/...ww.mayoclinic.com/health/folliculitis/DS00512
http://www.cpcadnet.com/track/ok/
http://www.cpcadnet.com/track/?b=14...mRpPXd3dy5vZmZlcnNmaW5kZXIuYml6Jm1jZj0x&pos=0
http://68.169.92.53/click.php?c=eNo...CwL3VJtMQkSSKqEIQlRYaJJMgMEp6nEc9iQqL4H0aDTCA
http://www.weather.com/search/enhan...1,1000,1,9,5,11,13,19,20&from=hdr_localsearch
http://google.ad.sgdoubleclick.net/...ww.mayoclinic.com/health/folliculitis/DS00512
http://68.169.92.53/click.php?c=eNo...Og0EzLdMFGRADWcAqBZBPCKUWYSp4ijakSE5rxf2mV9NY
ComboFix 11-07-26.03 - Garrett 07/26/2011 19:53:17.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1007.415 [GMT -7:00]
Running from: c:\documents and settings\Garrett\Desktop\ComboFix.exe
AV: VirusScan Enterprise + AntiSpyware Enterprise *Disabled/Updated* {918A2B0B-2C60-4016-A4AB-E868DEABF7F0}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\documents and settings\Garrett\WINDOWS
c:\documents and settings\Jen\My Documents\~WRL0004.tmp
c:\documents and settings\Jen\My Documents\~WRL0023.tmp
c:\documents and settings\Jen\My Documents\~WRL0034.tmp
c:\documents and settings\Jen\My Documents\~WRL0049.tmp
c:\documents and settings\Jen\My Documents\~WRL0127.tmp
c:\documents and settings\Jen\My Documents\~WRL0147.tmp
c:\documents and settings\Jen\My Documents\~WRL0149.tmp
c:\documents and settings\Jen\My Documents\~WRL0176.tmp
c:\documents and settings\Jen\My Documents\~WRL0220.tmp
c:\documents and settings\Jen\My Documents\~WRL0298.tmp
c:\documents and settings\Jen\My Documents\~WRL0334.tmp
c:\documents and settings\Jen\My Documents\~WRL0347.tmp
c:\documents and settings\Jen\My Documents\~WRL0358.tmp
c:\documents and settings\Jen\My Documents\~WRL0411.tmp
c:\documents and settings\Jen\My Documents\~WRL0507.tmp
c:\documents and settings\Jen\My Documents\~WRL0509.tmp
c:\documents and settings\Jen\My Documents\~WRL0611.tmp
c:\documents and settings\Jen\My Documents\~WRL0770.tmp
c:\documents and settings\Jen\My Documents\~WRL0773.tmp
c:\documents and settings\Jen\My Documents\~WRL0791.tmp
c:\documents and settings\Jen\My Documents\~WRL0797.tmp
c:\documents and settings\Jen\My Documents\~WRL0812.tmp
c:\documents and settings\Jen\My Documents\~WRL0840.tmp
c:\documents and settings\Jen\My Documents\~WRL0899.tmp
c:\documents and settings\Jen\My Documents\~WRL0909.tmp
c:\documents and settings\Jen\My Documents\~WRL0937.tmp
c:\documents and settings\Jen\My Documents\~WRL0991.tmp
c:\documents and settings\Jen\My Documents\~WRL1107.tmp
c:\documents and settings\Jen\My Documents\~WRL1152.tmp
c:\documents and settings\Jen\My Documents\~WRL1157.tmp
c:\documents and settings\Jen\My Documents\~WRL1226.tmp
c:\documents and settings\Jen\My Documents\~WRL1269.tmp
c:\documents and settings\Jen\My Documents\~WRL1327.tmp
c:\documents and settings\Jen\My Documents\~WRL1358.tmp
c:\documents and settings\Jen\My Documents\~WRL1361.tmp
c:\documents and settings\Jen\My Documents\~WRL1420.tmp
c:\documents and settings\Jen\My Documents\~WRL1535.tmp
c:\documents and settings\Jen\My Documents\~WRL1612.tmp
c:\documents and settings\Jen\My Documents\~WRL1673.tmp
c:\documents and settings\Jen\My Documents\~WRL1713.tmp
c:\documents and settings\Jen\My Documents\~WRL1720.tmp
c:\documents and settings\Jen\My Documents\~WRL1737.tmp
c:\documents and settings\Jen\My Documents\~WRL1770.tmp
c:\documents and settings\Jen\My Documents\~WRL1851.tmp
c:\documents and settings\Jen\My Documents\~WRL1909.tmp
c:\documents and settings\Jen\My Documents\~WRL1941.tmp
c:\documents and settings\Jen\My Documents\~WRL1968.tmp
c:\documents and settings\Jen\My Documents\~WRL2138.tmp
c:\documents and settings\Jen\My Documents\~WRL2145.tmp
c:\documents and settings\Jen\My Documents\~WRL2195.tmp
c:\documents and settings\Jen\My Documents\~WRL2204.tmp
c:\documents and settings\Jen\My Documents\~WRL2228.tmp
c:\documents and settings\Jen\My Documents\~WRL2315.tmp
c:\documents and settings\Jen\My Documents\~WRL2512.tmp
c:\documents and settings\Jen\My Documents\~WRL2546.tmp
c:\documents and settings\Jen\My Documents\~WRL2566.tmp
c:\documents and settings\Jen\My Documents\~WRL2590.tmp
c:\documents and settings\Jen\My Documents\~WRL2650.tmp
c:\documents and settings\Jen\My Documents\~WRL2662.tmp
c:\documents and settings\Jen\My Documents\~WRL2665.tmp
c:\documents and settings\Jen\My Documents\~WRL2713.tmp
c:\documents and settings\Jen\My Documents\~WRL2779.tmp
c:\documents and settings\Jen\My Documents\~WRL2801.tmp
c:\documents and settings\Jen\My Documents\~WRL2842.tmp
c:\documents and settings\Jen\My Documents\~WRL2910.tmp
c:\documents and settings\Jen\My Documents\~WRL2970.tmp
c:\documents and settings\Jen\My Documents\~WRL3043.tmp
c:\documents and settings\Jen\My Documents\~WRL3085.tmp
c:\documents and settings\Jen\My Documents\~WRL3199.tmp
c:\documents and settings\Jen\My Documents\~WRL3227.tmp
c:\documents and settings\Jen\My Documents\~WRL3367.tmp
c:\documents and settings\Jen\My Documents\~WRL3499.tmp
c:\documents and settings\Jen\My Documents\~WRL3568.tmp
c:\documents and settings\Jen\My Documents\~WRL3629.tmp
c:\documents and settings\Jen\My Documents\~WRL3636.tmp
c:\documents and settings\Jen\My Documents\~WRL3648.tmp
c:\documents and settings\Jen\My Documents\~WRL3668.tmp
c:\documents and settings\Jen\My Documents\~WRL3815.tmp
c:\documents and settings\Jen\My Documents\~WRL3816.tmp
c:\documents and settings\Jen\My Documents\~WRL3862.tmp
c:\documents and settings\Jen\My Documents\~WRL3891.tmp
c:\documents and settings\Jen\My Documents\~WRL3938.tmp
c:\documents and settings\Jen\My Documents\~WRL3954.tmp
c:\documents and settings\Jen\My Documents\~WRL3996.tmp
c:\documents and settings\Jen\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2011-06-27 to 2011-07-27 )))))))))))))))))))))))))))))))
.
.
2011-07-26 04:49 . 2011-07-26 04:49 -------- d-----w- c:\program files\ESET
2011-07-22 15:37 . 2011-07-22 15:37 -------- d-----w- C:\_OTL
2011-07-20 02:09 . 2011-07-20 02:09 -------- d-----w- c:\documents and settings\Garrett\Local Settings\Application Data\PackageAware
2011-07-19 15:11 . 2011-07-19 15:11 -------- d-----w- c:\documents and settings\Garrett\Application Data\Malwarebytes
2011-07-19 15:09 . 2011-07-07 02:52 41272 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-07-19 15:09 . 2011-07-19 15:09 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-07-19 15:09 . 2011-07-07 02:52 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-07-19 15:09 . 2011-07-19 15:09 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2011-07-15 18:22 . 2011-07-15 18:22 -------- d-----w- c:\documents and settings\Garrett\Local Settings\Application Data\Temp
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-07-12 03:56 . 2011-06-12 01:32 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-06-10 15:30 . 2011-06-10 15:30 0 ----a-w- c:\documents and settings\Jen\Local Settings\Application Data\Awopaziguquxuzay.bin
2008-09-29 15:07 . 2010-10-19 00:39 22576 ----a-w- c:\program files\mozilla firefox\components\Scriptff.dll
.
.
((((((((((((((((((((((((((((( SnapShot@2010-08-28_21.17.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-11-07 09:19 . 2007-11-07 09:19 54272 c:\windows\WinSxS\x86_Microsoft.VC90.OpenMP_1fc8b3b9a1e18e3b_9.0.21022.8_x-ww_ecc42bd1\vcomp90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 62976 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90rus.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46080 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90kor.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 46592 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90jpn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 64512 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90ita.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66048 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90fra.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esp.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 65024 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90esn.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 56832 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90enu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 66560 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90deu.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 39936 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90cht.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 38912 c:\windows\WinSxS\x86_Microsoft.VC90.MFCLOC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_b0db7d03\mfc90chs.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90u.dll
+ 2008-07-29 13:07 . 2008-07-29 13:07 59904 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfcm90.dll
+ 2009-07-12 03:41 . 2009-07-12 03:41 97280 c:\windows\WinSxS\x86_Microsoft.VC80.ATL_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_473666fd\ATL80.dll
+ 2011-07-24 22:26 . 2011-07-24 22:26 16384 c:\windows\Temp\Perflib_Perfdata_714.dat
+ 2011-02-23 04:05 . 2011-02-23 04:05 60808 c:\windows\system32\S32EVNT1.DLL
+ 2010-12-07 04:02 . 2010-04-20 03:47 41984 c:\windows\system32\ReinstallBackups\0014\DriverFiles\usbaapl.sys
+ 2010-09-12 03:06 . 2010-04-20 03:47 41984 c:\windows\system32\ReinstallBackups\0009\DriverFiles\usbaapl.sys
- 2001-08-23 12:00 . 2010-08-24 03:07 71592 c:\windows\system32\perfc009.dat
+ 2001-08-23 12:00 . 2011-06-12 01:21 71592 c:\windows\system32\perfc009.dat
+ 2010-03-16 16:10 . 2010-09-12 18:31 60724 c:\windows\system32\mlfcache.dat
+ 2010-10-19 00:39 . 2008-09-29 15:07 67904 c:\windows\system32\mfevtps.exe
+ 2008-09-29 15:07 . 2008-09-29 15:07 19480 c:\windows\system32\mfeotlk.dll
- 2010-05-18 23:35 . 2010-05-18 23:35 75040 c:\windows\system32\jdns_sd.dll
+ 2010-10-07 19:23 . 2010-10-07 19:23 75040 c:\windows\system32\jdns_sd.dll
+ 2011-04-09 21:20 . 2011-02-18 23:36 41984 c:\windows\system32\DRVSTORE\usbaapl_05A32DBD3911A2EF4222EF5BE7BB535FAB37D6C4\usbaapl.sys
+ 2011-04-09 21:20 . 2010-04-20 03:29 18432 c:\windows\system32\DRVSTORE\netaapl_8A27A03003759CB01567E831096473C330131D64\netaapl.sys
+ 2010-12-10 16:06 . 2010-01-20 22:18 33792 c:\windows\system32\DRVSTORE\leapfrog-0_B30D43972967E3C09B8E635B22BC13082452FEEA\i386\btblan.sys
- 2008-06-12 02:26 . 2010-04-20 03:47 41984 c:\windows\system32\drivers\usbaapl.sys
+ 2008-06-12 02:26 . 2011-02-18 23:36 41984 c:\windows\system32\drivers\usbaapl.sys
+ 2010-08-07 14:57 . 2005-08-15 22:46 68226 c:\windows\system32\drivers\StMp3Rec.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 62704 c:\windows\system32\drivers\mfetdik.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 64432 c:\windows\system32\drivers\mferkdet.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 42424 c:\windows\system32\drivers\mfebopk.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 90360 c:\windows\system32\drivers\mfeavfk.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 74648 c:\windows\system32\drivers\mfeapfk.sys
+ 2010-10-07 19:23 . 2010-10-07 19:23 91424 c:\windows\system32\dnssd.dll
- 2010-05-18 23:35 . 2010-05-18 23:35 91424 c:\windows\system32\dnssd.dll
+ 2011-07-24 02:23 . 2011-07-25 03:24 32768 c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2003-11-24 22:05 . 2010-08-14 20:07 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2003-11-24 22:05 . 2011-07-25 03:24 32768 c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2003-11-24 22:05 . 2010-08-14 20:07 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2010-09-05 03:55 . 2011-07-25 03:24 16384 c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2011-06-02 03:22 . 2011-06-02 03:22 21504 c:\windows\Installer\ac00961.msi
+ 2010-09-12 03:07 . 2010-09-12 03:07 27136 c:\windows\Installer\{C41300B9-185D-475E-BFEC-39EF732F19B1}\AppleSoftwareUpdateIco.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\ShortcutOGL_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\ShortcutDX_EB071909B9884F8CBF3D6115D4ADEE5E.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\googleearth.exe1_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\googleearth.exe_F6A848FB884248E6A4CDCBDCF41F6A74.exe
+ 2011-05-25 19:25 . 2011-05-25 19:25 65536 c:\windows\Installer\{B3FED300-806C-11E0-A0D0-B8AC6F97B88E}\ARPPRODUCTICON.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 23558 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
+ 2008-05-19 23:20 . 2011-07-17 18:09 23558 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\SC_Designer_PFM.70DBED24_B579_40CB_AB0B_F1221A3E9EC5.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 25214 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Distiller.exe
+ 2008-05-19 23:20 . 2011-07-17 18:09 25214 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Distiller.exe
+ 2010-10-19 00:37 . 2010-10-19 00:37 10134 c:\windows\Installer\{A638557B-1F13-40A0-9627-C892FBCA6960}\ARPPRODUCTICON.exe
+ 2010-05-19 18:13 . 2011-06-26 13:53 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
- 2010-05-19 18:13 . 2010-08-20 14:34 40960 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\wrdvicon.exe
+ 2011-06-26 13:57 . 2011-06-26 13:57 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2010-08-20 14:26 . 2010-08-20 14:26 34632 c:\windows\Installer\{90120000-0020-0409-0000-0000000FF1CE}\O12ConvIcon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 23040 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\unbndico.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 61440 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pubs.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 27136 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\oisicon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 11264 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\mspicons.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 86016 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\inficon.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 12288 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\cagicon.exe
+ 2010-06-09 15:40 . 2011-06-26 13:57 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-06-09 15:40 . 2010-06-09 15:40 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2010-09-23 18:15 . 2010-09-23 18:15 25214 c:\windows\Installer\{4286E640-B5FB-11DF-AC4B-005056C00008}\UNINST_Uninstall_G_F6A848FB884248E6A4CDCBDCF41F6A74_1.exe
+ 2008-05-19 23:20 . 2011-07-17 18:09 7278 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_ELEMENTS_DT.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 7278 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_ELEMENTS_DT.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 4096 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\opwicon.exe
+ 2009-08-12 06:54 . 2009-08-12 06:54 653120 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcr90.dll
+ 2009-08-12 06:54 . 2009-08-12 06:54 569664 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcp90.dll
+ 2009-08-12 06:54 . 2009-08-12 06:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_d495ac4e\msvcm90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 655872 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcr90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 572928 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcp90.dll
+ 2008-07-29 10:54 . 2008-07-29 10:54 225280 c:\windows\WinSxS\x86_Microsoft.VC90.CRT_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_6f74963e\msvcm90.dll
+ 2009-07-12 07:02 . 2009-07-12 07:02 159032 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.4148_x-ww_353599c2\atl90.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 161784 c:\windows\WinSxS\x86_Microsoft.VC90.ATL_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_d01483b2\atl90.dll
+ 2001-08-23 12:00 . 2011-06-12 01:21 443062 c:\windows\system32\perfh009.dat
- 2001-08-23 12:00 . 2010-08-24 03:07 443062 c:\windows\system32\perfh009.dat
+ 2011-06-18 20:57 . 2011-06-18 20:59 240288 c:\windows\system32\Macromed\Flash\FlashUtil10t_Plugin.exe
+ 2011-07-12 03:56 . 2011-07-12 03:56 240288 c:\windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.exe
+ 2011-07-12 03:56 . 2011-07-12 03:56 321184 c:\windows\system32\Macromed\Flash\FlashUtil10t_ActiveX.dll
+ 2003-11-24 16:26 . 2011-03-20 22:30 298048 c:\windows\system32\FNTCACHE.DAT
- 2003-11-24 16:26 . 2010-06-09 19:38 298048 c:\windows\system32\FNTCACHE.DAT
+ 2011-02-23 04:05 . 2011-02-23 04:05 126512 c:\windows\system32\drivers\SYMEVENT.SYS
+ 2011-03-30 22:25 . 2010-07-13 01:20 154672 c:\windows\system32\drivers\NSM\0201000.034\symrdrs.sys
+ 2011-03-30 22:25 . 2010-07-13 01:20 181296 c:\windows\system32\drivers\NSM\0201000.034\symrdr.sys
+ 2010-10-19 00:39 . 2008-09-29 15:07 340592 c:\windows\system32\drivers\mfehidk.sys
+ 2010-10-07 19:23 . 2010-10-07 19:23 107808 c:\windows\system32\dns-sd.exe
- 2010-05-18 23:35 . 2010-05-18 23:35 107808 c:\windows\system32\dns-sd.exe
+ 2010-08-29 15:57 . 2011-03-06 19:08 472808 c:\windows\system32\deployJava1.dll
+ 2011-02-23 04:04 . 2011-02-23 04:04 735232 c:\windows\Installer\b4b9cd3.msi
+ 2010-11-24 17:15 . 2010-11-24 17:15 450048 c:\windows\Installer\89af6.msi
+ 2011-03-06 19:13 . 2011-03-06 19:13 390144 c:\windows\Installer\2322d32e.msi
+ 2011-03-06 18:59 . 2011-03-06 18:59 533504 c:\windows\Installer\2322d0ae.msi
+ 2011-05-29 14:32 . 2011-05-29 14:32 195584 c:\windows\Installer\22557f52.msi
+ 2011-05-07 23:28 . 2011-05-07 23:28 228352 c:\windows\Installer\1f176d9b.msi
+ 2011-04-09 21:18 . 2011-04-09 21:18 811520 c:\windows\Installer\1eac173e.msi
+ 2010-12-10 16:09 . 2010-12-10 16:09 513024 c:\windows\Installer\1835a52b.msi
+ 2008-05-19 23:20 . 2011-07-17 18:09 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_Standard.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_Standard.exe
+ 2008-05-19 23:20 . 2011-07-17 18:09 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_3D.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat_3D.exe
+ 2008-05-19 23:20 . 2011-07-17 18:09 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
- 2008-05-19 23:20 . 2010-06-09 15:23 295606 c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000003}\_SC_Acrobat.exe
- 2010-05-19 18:13 . 2010-08-20 14:34 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2010-05-19 18:13 . 2011-06-26 13:53 135168 c:\windows\Installer\{90850409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 409600 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\xlicons.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 286720 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\wordicon.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 249856 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\pptico.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 794624 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\outicon.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 135168 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\misc.exe
+ 2003-11-27 14:34 . 2011-06-26 13:54 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
- 2003-11-27 14:34 . 2010-08-20 14:27 593920 c:\windows\Installer\{90110409-6000-11D3-8CFE-0150048383C9}\accicons.exe
+ 2011-04-09 21:29 . 2011-04-09 21:29 380928 c:\windows\Installer\{2A697B53-0DE3-42DA-B41D-C3F804B1C538}\iTunesIco.exe
+ 2011-07-26 04:13 . 2011-07-26 04:13 286720 c:\windows\ERDNT\AutoBackup\7-25-2011\Users\00000002\UsrClass.dat
+ 2011-07-26 04:13 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-25-2011\ERDNT.EXE
+ 2011-07-22 15:34 . 2011-07-22 15:34 286720 c:\windows\ERDNT\AutoBackup\7-22-2011\Users\00000002\UsrClass.dat
+ 2011-07-22 15:34 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-22-2011\ERDNT.EXE
+ 2011-07-02 19:19 . 2011-07-02 19:19 286720 c:\windows\ERDNT\AutoBackup\7-2-2011\Users\00000002\UsrClass.dat
+ 2011-07-02 19:19 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-2-2011\ERDNT.EXE
+ 2011-07-19 23:04 . 2011-07-19 23:04 286720 c:\windows\ERDNT\AutoBackup\7-19-2011\Users\00000002\UsrClass.dat
+ 2011-07-19 23:04 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-19-2011\ERDNT.EXE
+ 2011-07-19 01:26 . 2011-07-19 01:26 286720 c:\windows\ERDNT\AutoBackup\7-18-2011\Users\00000002\UsrClass.dat
+ 2011-07-19 01:26 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-18-2011\ERDNT.EXE
+ 2011-07-17 17:54 . 2011-07-17 17:54 286720 c:\windows\ERDNT\AutoBackup\7-17-2011\Users\00000002\UsrClass.dat
+ 2011-07-17 17:54 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-17-2011\ERDNT.EXE
+ 2011-07-13 15:24 . 2011-07-13 15:24 286720 c:\windows\ERDNT\AutoBackup\7-13-2011\Users\00000002\UsrClass.dat
+ 2011-07-13 15:24 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-13-2011\ERDNT.EXE
+ 2011-07-12 03:55 . 2011-07-12 03:55 286720 c:\windows\ERDNT\AutoBackup\7-11-2011\Users\00000002\UsrClass.dat
+ 2011-07-12 03:55 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\7-11-2011\ERDNT.EXE
+ 2011-06-18 19:29 . 2011-06-18 19:29 286720 c:\windows\ERDNT\AutoBackup\6-18-2011\Users\00000002\UsrClass.dat
+ 2011-06-18 19:29 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\6-18-2011\ERDNT.EXE
+ 2011-06-13 20:40 . 2011-06-13 20:40 286720 c:\windows\ERDNT\AutoBackup\6-13-2011\Users\00000002\UsrClass.dat
+ 2011-06-13 20:40 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\6-13-2011\ERDNT.EXE
+ 2011-06-12 01:29 . 2011-06-12 01:29 286720 c:\windows\ERDNT\AutoBackup\6-11-2011\Users\00000002\UsrClass.dat
+ 2011-06-12 01:29 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\6-11-2011\ERDNT.EXE
+ 2011-06-10 22:41 . 2011-06-10 22:41 286720 c:\windows\ERDNT\AutoBackup\6-10-2011\Users\00000002\UsrClass.dat
+ 2011-06-10 22:41 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\6-10-2011\ERDNT.EXE
+ 2011-05-07 23:26 . 2011-05-07 23:26 286720 c:\windows\ERDNT\AutoBackup\5-7-2011\Users\00000002\UsrClass.dat
+ 2011-05-07 23:26 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\5-7-2011\ERDNT.EXE
+ 2011-05-21 20:07 . 2011-05-21 20:07 286720 c:\windows\ERDNT\AutoBackup\5-21-2011\Users\00000002\UsrClass.dat
+ 2011-05-21 20:07 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\5-21-2011\ERDNT.EXE
+ 2011-04-09 20:55 . 2011-04-09 20:55 286720 c:\windows\ERDNT\AutoBackup\4-9-2011\Users\00000002\UsrClass.dat
+ 2011-04-09 20:55 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\4-9-2011\ERDNT.EXE
+ 2011-04-03 23:04 . 2011-04-03 23:04 286720 c:\windows\ERDNT\AutoBackup\4-3-2011\Users\00000002\UsrClass.dat
+ 2011-04-03 23:04 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\4-3-2011\ERDNT.EXE
+ 2011-04-23 00:44 . 2011-04-23 00:44 286720 c:\windows\ERDNT\AutoBackup\4-22-2011\Users\00000002\UsrClass.dat
+ 2011-04-23 00:44 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\4-22-2011\ERDNT.EXE
+ 2011-03-06 18:54 . 2011-03-06 18:54 286720 c:\windows\ERDNT\AutoBackup\3-6-2011\Users\00000002\UsrClass.dat
+ 2011-03-06 18:54 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\3-6-2011\ERDNT.EXE
+ 2011-03-11 02:33 . 2011-03-11 02:33 286720 c:\windows\ERDNT\AutoBackup\3-10-2011\Users\00000002\UsrClass.dat
+ 2011-03-11 02:33 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\3-10-2011\ERDNT.EXE
+ 2011-02-05 18:42 . 2011-02-05 18:42 286720 c:\windows\ERDNT\AutoBackup\2-5-2011\Users\00000002\UsrClass.dat
+ 2011-02-05 18:42 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\2-5-2011\ERDNT.EXE
+ 2011-02-27 20:17 . 2011-02-27 20:17 286720 c:\windows\ERDNT\AutoBackup\2-27-2011\Users\00000002\UsrClass.dat
+ 2011-02-27 20:17 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\2-27-2011\ERDNT.EXE
+ 2011-02-23 03:58 . 2011-02-23 03:58 286720 c:\windows\ERDNT\AutoBackup\2-22-2011\Users\00000002\UsrClass.dat
+ 2011-02-23 03:58 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\2-22-2011\ERDNT.EXE
+ 2010-12-07 03:03 . 2010-12-07 03:03 286720 c:\windows\ERDNT\AutoBackup\12-6-2010\Users\00000002\UsrClass.dat
+ 2010-12-07 03:03 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\12-6-2010\ERDNT.EXE
+ 2010-12-31 22:34 . 2010-12-31 22:34 286720 c:\windows\ERDNT\AutoBackup\12-31-2010\Users\00000002\UsrClass.dat
+ 2010-12-31 22:34 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\12-31-2010\ERDNT.EXE
+ 2010-12-10 16:01 . 2010-12-10 16:01 286720 c:\windows\ERDNT\AutoBackup\12-10-2010\Users\00000002\UsrClass.dat
+ 2010-12-10 16:01 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\12-10-2010\ERDNT.EXE
+ 2011-01-08 21:59 . 2011-01-08 21:59 286720 c:\windows\ERDNT\AutoBackup\1-8-2011\Users\00000002\UsrClass.dat
+ 2011-01-08 21:59 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\1-8-2011\ERDNT.EXE
+ 2011-01-07 17:35 . 2011-01-07 17:35 286720 c:\windows\ERDNT\AutoBackup\1-7-2011\Users\00000002\UsrClass.dat
+ 2011-01-07 17:35 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\1-7-2011\ERDNT.EXE
+ 2011-01-06 18:09 . 2011-01-06 18:09 286720 c:\windows\ERDNT\AutoBackup\1-6-2011\Users\00000002\UsrClass.dat
+ 2011-01-06 18:09 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\1-6-2011\ERDNT.EXE
+ 2011-01-30 20:36 . 2011-01-30 20:36 286720 c:\windows\ERDNT\AutoBackup\1-30-2011\Users\00000002\UsrClass.dat
+ 2011-01-30 20:36 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\1-30-2011\ERDNT.EXE
+ 2011-01-11 18:13 . 2011-01-11 18:13 286720 c:\windows\ERDNT\AutoBackup\1-11-2011\Users\00000002\UsrClass.dat
+ 2011-01-11 18:13 . 2005-10-20 19:02 163328 c:\windows\ERDNT\AutoBackup\1-11-2011\ERDNT.EXE
+ 2011-06-18 19:35 . 2005-10-20 19:02 163328 c:\windows\ERDNT\6-18-2011\ERDNT.EXE
+ 2008-07-29 15:05 . 2008-07-29 15:05 3783672 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90u.dll
+ 2008-07-29 15:05 . 2008-07-29 15:05 3768312 c:\windows\WinSxS\x86_Microsoft.VC90.MFC_1fc8b3b9a1e18e3b_9.0.30729.1_x-ww_405b0943\mfc90.dll
+ 2009-03-19 14:21 . 2011-02-18 23:36 4184352 c:\windows\system32\usbaaplrc.dll
+ 2010-12-07 04:02 . 2010-04-20 03:47 3062048 c:\windows\system32\ReinstallBackups\0014\DriverFiles\usbaaplrc.dll
+ 2010-09-12 03:06 . 2010-04-20 03:47 3062048 c:\windows\system32\ReinstallBackups\0009\DriverFiles\usbaaplrc.dll
+ 2010-01-27 01:07 . 2011-06-18 20:59 6271136 c:\windows\system32\Macromed\Flash\NPSWF32.dll
+ 2011-04-09 21:20 . 2011-02-18 23:36 4184352 c:\windows\system32\DRVSTORE\usbaapl_05A32DBD3911A2EF4222EF5BE7BB535FAB37D6C4\usbaaplrc.dll
+ 2011-04-09 21:20 . 2010-04-20 03:29 1461992 c:\windows\system32\DRVSTORE\netaapl_8A27A03003759CB01567E831096473C330131D64\wdfcoinstaller01009.dll
+ 2011-05-25 19:25 . 2011-05-25 19:25 1529344 c:\windows\Installer\ec5f93f.msi
+ 2010-10-19 00:40 . 2010-10-19 00:40 4069376 c:\windows\Installer\e10179.msi
+ 2010-10-19 00:37 . 2010-10-19 00:37 1414656 c:\windows\Installer\e10175.msi
+ 2010-08-14 00:59 . 2010-08-14 00:59 8182272 c:\windows\Installer\83fb34d3.msp
+ 2010-08-14 01:02 . 2010-08-14 01:02 2545664 c:\windows\Installer\83fb34ca.msp
+ 2010-09-02 19:28 . 2010-09-02 19:28 3749376 c:\windows\Installer\83fb34b6.msp
+ 2010-10-04 23:32 . 2010-10-04 23:32 5517824 c:\windows\Installer\83fb34ac.msp
+ 2010-09-17 14:04 . 2010-09-17 14:04 9401856 c:\windows\Installer\6482df9.msp
+ 2010-08-20 20:50 . 2010-08-20 20:50 5518848 c:\windows\Installer\2e2158e1.msp
+ 2010-08-04 22:12 . 2010-08-04 22:12 1004544 c:\windows\Installer\2e2158cb.msp
+ 2010-08-26 00:06 . 2010-08-26 00:06 6479360 c:\windows\Installer\2e2158c3.msp
+ 2010-09-12 03:07 . 2010-09-12 03:07 1554944 c:\windows\Installer\25aa0e93.msi
+ 2010-12-06 23:02 . 2010-12-06 23:02 5518848 c:\windows\Installer\22ce64ce.msp
+ 2011-04-27 18:14 . 2011-04-27 18:14 5520384 c:\windows\Installer\22557f67.msp
+ 2011-04-29 19:30 . 2011-04-29 19:30 1197056 c:\windows\Installer\22557f4b.msp
+ 2011-04-29 19:28 . 2011-04-29 19:28 1995264 c:\windows\Installer\22402a8f.msp
+ 2011-05-21 00:31 . 2011-05-21 00:31 5518848 c:\windows\Installer\22402a7b.msp
+ 2011-05-18 01:28 . 2011-05-18 01:28 6862848 c:\windows\Installer\22402a65.msp
+ 2011-04-29 19:33 . 2011-04-29 19:33 8173568 c:\windows\Installer\22402a5b.msp
+ 2011-04-09 21:29 . 2011-04-09 21:29 5448704 c:\windows\Installer\1eac2059.msi
+ 2011-04-09 21:20 . 2011-04-09 21:20 3085312 c:\windows\Installer\1eac17b3.msi
+ 2011-04-09 21:19 . 2011-04-09 21:19 1984000 c:\windows\Installer\1eac1768.msi
+ 2010-11-21 06:34 . 2010-11-21 06:34 1198080 c:\windows\Installer\1a2743b5.msp
+ 2011-03-18 03:01 . 2011-03-18 03:01 9563648 c:\windows\Installer\1a2743ac.msp
+ 2011-01-12 00:50 . 2011-01-12 00:50 8177152 c:\windows\Installer\1a2743a3.msp
+ 2011-01-07 17:45 . 2011-01-07 17:45 1710592 c:\windows\Installer\186e652c.msi
+ 2011-01-07 17:44 . 2011-01-07 17:44 9472000 c:\windows\Installer\186e650e.msi
+ 2010-12-10 16:06 . 2010-12-10 16:06 8136192 c:\windows\Installer\1835a517.msi
+ 2010-08-13 20:01 . 2010-08-13 20:01 9225216 c:\windows\Installer\14b391ec.msp
+ 2009-08-17 22:32 . 2009-08-17 22:32 1787728 c:\windows\Installer\$PatchCache$\Managed\00002109020090400000000000F01FEC\12.0.6514\PPCNV.DLL
+ 2011-07-26 04:13 . 2011-07-26 04:13 7368704 c:\windows\ERDNT\AutoBackup\7-25-2011\Users\00000001\NTUSER.DAT
+ 2011-07-22 15:34 . 2011-07-22 15:34 7368704 c:\windows\ERDNT\AutoBackup\7-22-2011\Users\00000001\NTUSER.DAT
+ 2011-07-02 19:19 . 2011-07-02 19:19 7368704 c:\windows\ERDNT\AutoBackup\7-2-2011\Users\00000001\NTUSER.DAT
+ 2011-07-19 23:04 . 2011-07-19 23:04 7385088 c:\windows\ERDNT\AutoBackup\7-19-2011\Users\00000001\NTUSER.DAT
+ 2011-07-19 01:26 . 2011-07-19 01:26 7385088 c:\windows\ERDNT\AutoBackup\7-18-2011\Users\00000001\NTUSER.DAT
+ 2011-07-17 17:54 . 2011-07-17 17:54 7385088 c:\windows\ERDNT\AutoBackup\7-17-2011\Users\00000001\NTUSER.DAT
+ 2011-07-13 15:24 . 2011-07-13 15:24 7385088 c:\windows\ERDNT\AutoBackup\7-13-2011\Users\00000001\NTUSER.DAT
+ 2011-07-12 03:55 . 2011-07-12 03:55 7368704 c:\windows\ERDNT\AutoBackup\7-11-2011\Users\00000001\NTUSER.DAT
+ 2011-06-18 19:29 . 2011-06-18 19:29 7368704 c:\windows\ERDNT\AutoBackup\6-18-2011\Users\00000001\NTUSER.DAT
+ 2011-06-13 20:40 . 2011-06-13 20:40 7368704 c:\windows\ERDNT\AutoBackup\6-13-2011\Users\00000001\NTUSER.DAT
+ 2011-06-12 01:29 . 2011-06-12 01:29 7352320 c:\windows\ERDNT\AutoBackup\6-11-2011\Users\00000001\NTUSER.DAT
+ 2011-06-10 22:41 . 2011-06-10 22:41 7352320 c:\windows\ERDNT\AutoBackup\6-10-2011\Users\00000001\NTUSER.DAT
+ 2011-05-07 23:26 . 2011-05-07 23:26 7344128 c:\windows\ERDNT\AutoBackup\5-7-2011\Users\00000001\NTUSER.DAT
+ 2011-05-21 20:07 . 2011-05-21 20:07 7352320 c:\windows\ERDNT\AutoBackup\5-21-2011\Users\00000001\NTUSER.DAT
+ 2011-04-09 20:55 . 2011-04-09 20:55 7344128 c:\windows\ERDNT\AutoBackup\4-9-2011\Users\00000001\NTUSER.DAT
+ 2011-04-03 23:04 . 2011-04-03 23:04 7344128 c:\windows\ERDNT\AutoBackup\4-3-2011\Users\00000001\NTUSER.DAT
+ 2011-04-23 00:44 . 2011-04-23 00:44 7344128 c:\windows\ERDNT\AutoBackup\4-22-2011\Users\00000001\NTUSER.DAT
+ 2011-03-06 18:53 . 2011-03-06 18:54 7327744 c:\windows\ERDNT\AutoBackup\3-6-2011\Users\00000001\NTUSER.DAT
+ 2011-03-11 02:33 . 2011-03-11 02:33 7344128 c:\windows\ERDNT\AutoBackup\3-10-2011\Users\00000001\NTUSER.DAT
+ 2011-02-05 18:42 . 2011-02-05 18:42 7327744 c:\windows\ERDNT\AutoBackup\2-5-2011\Users\00000001\NTUSER.DAT
+ 2011-02-27 20:17 . 2011-02-27 20:17 7327744 c:\windows\ERDNT\AutoBackup\2-27-2011\Users\00000001\NTUSER.DAT
+ 2011-02-23 03:58 . 2011-02-23 03:58 7327744 c:\windows\ERDNT\AutoBackup\2-22-2011\Users\00000001\NTUSER.DAT
+ 2010-12-07 03:03 . 2010-12-07 03:03 7299072 c:\windows\ERDNT\AutoBackup\12-6-2010\Users\00000001\NTUSER.DAT
+ 2010-12-31 22:34 . 2010-12-31 22:34 7327744 c:\windows\ERDNT\AutoBackup\12-31-2010\Users\00000001\NTUSER.DAT
+ 2010-12-10 16:01 . 2010-12-10 16:01 7315456 c:\windows\ERDNT\AutoBackup\12-10-2010\Users\00000001\NTUSER.DAT
+ 2011-01-08 21:59 . 2011-01-08 21:59 7327744 c:\windows\ERDNT\AutoBackup\1-8-2011\Users\00000001\NTUSER.DAT
+ 2011-01-07 17:35 . 2011-01-07 17:35 7327744 c:\windows\ERDNT\AutoBackup\1-7-2011\Users\00000001\NTUSER.DAT
+ 2011-01-06 18:09 . 2011-01-06 18:09 7327744 c:\windows\ERDNT\AutoBackup\1-6-2011\Users\00000001\NTUSER.DAT
+ 2011-01-30 20:36 . 2011-01-30 20:36 7327744 c:\windows\ERDNT\AutoBackup\1-30-2011\Users\00000001\NTUSER.DAT
+ 2011-01-11 18:13 . 2011-01-11 18:13 7327744 c:\windows\ERDNT\AutoBackup\1-11-2011\Users\00000001\NTUSER.DAT
+ 2005-07-01 16:54 . 2011-07-15 18:13 49089992 c:\windows\system32\MRT.exe
+ 2010-10-16 17:30 . 2010-10-16 17:30 20303872 c:\windows\Installer\83fb34c2.msp
+ 2010-10-15 00:57 . 2010-10-15 00:57 11189248 c:\windows\Installer\6482df0.msp
+ 2010-09-21 02:20 . 2010-09-21 02:20 20303872 c:\windows\Installer\2e2158ba.msp
+ 2005-08-08 21:25 . 2005-08-08 21:25 97385984 c:\windows\Installer\22557f69.msp
+ 2011-06-26 13:54 . 2011-06-26 13:54 20333056 c:\windows\Installer\22402a87.msp
+ 2011-01-22 07:56 . 2011-01-22 07:56 43396608 c:\windows\Installer\1d5285.msp
+ 2011-06-01 08:59 . 2011-06-01 08:59 44644864 c:\windows\Installer\1ac04566.msp
+ 2011-04-23 00:57 . 2011-04-23 00:57 20314624 c:\windows\Installer\1a2743cb.msp
+ 2011-02-24 16:38 . 2011-02-24 16:38 10984448 c:\windows\Installer\1a2743bf.msp
+ 2011-01-07 18:13 . 2011-01-07 18:13 20304384 c:\windows\Installer\186e6dea.msp
+ 2010-09-24 06:55 . 2010-09-24 06:55 43589632 c:\windows\Installer\18604bdc.msp
+ 2010-06-17 08:50 . 2010-06-17 08:50 42970624 c:\windows\Installer\14b391ed.msp
+ 2007-07-27 17:03 . 2007-07-27 17:03 119977472 c:\windows\Installer\186e6ddb.msp
+ 2007-07-27 16:03 . 2007-07-27 16:03 119977472 c:\windows\Installer\17b0c29d.msp
+ 2007-07-27 16:03 . 2007-07-27 16:03 119977472 c:\windows\Installer\14e9bb0d.msp
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WeatherEye"="c:\program files\TheWeatherNetwork\WeatherEye\WeatherEye.exe" [2006-10-04 4792512]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]
"OpenDNS Updater"="c:\program files\OpenDNS Updater\OpenDNSUpdater.exe" [2010-06-16 839680]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"LXCRCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll" [2005-12-01 65536]
"Acrobat Assistant 8.0"="f:\adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2011-05-27 624056]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
"McAfeeUpdaterUI"="c:\program files\McAfee\Common Framework\udaterui.exe" [2008-03-14 136512]
"ShStatEXE"="c:\program files\McAfee\VirusScan Enterprise\SHSTAT.EXE" [2008-09-29 124240]
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe" [2010-11-19 193880]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-03-07 421160]
"Malwarebytes' Anti-Malware"="c:\program files\Malwarebytes' Anti-Malware\mbamgui.exe" [2011-07-07 449584]
.
c:\documents and settings\Garrett\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
.
c:\documents and settings\Jen\Start Menu\Programs\Startup\
Dropbox.lnk - c:\documents and settings\Garrett\Application Data\Dropbox\bin\Dropbox.exe [N/A]
Logitech Touch Mouse Server.lnk - c:\program files\Logitech Touch Mouse Server\iTouch-Server-Win.exe [2009-10-23 228352]
OpenOffice.org 2.2.lnk - c:\program files\OpenOffice.org 2.2\program\quickstart.exe [2007-2-2 393216]
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\McAfeeEngineService]
@="Service"
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^eFax 4.4.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\eFax 4.4.lnk
backup=c:\windows\pss\eFax 4.4.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HappyFish.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\HappyFish.lnk
backup=c:\windows\pss\HappyFish.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=c:\windows\pss\InterVideo WinCinema Manager.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^LaunchU3.exe.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\LaunchU3.exe.lnk
backup=c:\windows\pss\LaunchU3.exe.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^qtopiatray.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\qtopiatray.lnk
backup=c:\windows\pss\qtopiatray.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^VPN Client.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\VPN Client.lnk
backup=c:\windows\pss\VPN Client.lnkCommon Startup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Garrett^Start Menu^Programs^Startup^MLB.TV NexDef Plug-in.lnk]
path=c:\documents and settings\Garrett\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk
backup=c:\windows\pss\MLB.TV NexDef Plug-in.lnkStartup
.
[HKLM\~\startupfolder\C:^Documents and Settings^Garrett^Start Menu^Programs^Startup^OpenOffice.org 1.9.79.lnk]
path=c:\documents and settings\Garrett\Start Menu\Programs\Startup\OpenOffice.org 1.9.79.lnk
backup=c:\windows\pss\OpenOffice.org 1.9.79.lnkStartup
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Orb]
2008-04-01 01:54 507904 ----a-w- c:\program files\Winamp Remote\bin\OrbTray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-11-30 01:38 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
.
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ctfmon.exe"=c:\windows\system32\ctfmon.exe
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" /background
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"eFax 4.4"="c:\program files\eFax Messenger 4.4\J2GDllCmd.exe" /R
"EzPrint"="c:\program files\Lexmark 2400 Series\ezprint.exe"
"FaxCenterServer"="c:\program files\Lexmark Fax Solutions\fm3032.exe" /s
"InCD"=c:\program files\Ahead\InCD\InCD.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"KernelFaultCheck"=%systemroot%\system32\dumprep 0 -k
"lxcrmon.exe"="c:\program files\Lexmark 2400 Series\lxcrmon.exe"
"Monitor"="c:\program files\LeapFrog\LeapFrog Connect\Monitor.exe"
"NeroCheck"=c:\windows\system32\NeroCheck.exe
"POINTER"=point32.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"ShStatEXE"="c:\program files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
"SoundMAX"="c:\program files\Analog Devices\SoundMAX\Smax4.exe" /tray
"SoundMAXPnP"=c:\program files\Analog Devices\SoundMAX\SMax4PNP.exe
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"type32"="c:\program files\Microsoft IntelliType Pro\type32.exe"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\mozilla.org\\Mozilla\\mozilla.exe"=
"c:\\Program Files\\Real\\RealOne Player\\realplay.exe"=
"c:\\Program Files\\SAS Institute\\SAS\\V8\\sas.exe"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Documents and Settings\\All Users\\Documents\\Ryerson\\ZTree\\zLeaf.exe"=
"c:\\Program Files\\Abacast\\Abaclient.exe"=
"c:\\Program Files\\Maple 9.5\\bin.win\\mserver.exe"=
"c:\\Program Files\\Maple 9.5\\jre\\bin\\java.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\WS_FTP\\WS_FTP95.exe"=
"c:\\Program Files\\Octoshape Streaming Services\\Jen\\OctoshapeClient.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Microsoft Games\\Halo\\halo.exe"=
"c:\\Program Files\\GameSpy Arcade\\Aphex.exe"=
"c:\\Documents and Settings\\Jen\\Application Data\\PowerChallenge\\PowerFootball\\PowerFootball.exe"=
"c:\\Documents and Settings\\Jen\\Application Data\\PowerChallenge\\PowerSoccer\\PowerSoccer.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\Orb.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbTray.exe"=
"c:\\Program Files\\Winamp Remote\\bin\\OrbStreamerClient.exe"=
"f:\\Opera\\opera.exe"=
"c:\\Program Files\\Logitech Touch Mouse Server\\iTouch-Server-Win.exe"=
"c:\\Documents and Settings\\Jen\\Application Data\\Dropbox\\bin\\Dropbox.exe"=
"c:\\Program Files\\Java\\jre6\\launch4j-tmp\\Stanza.exe"=
"c:\\Program Files\\McAfee\\Common Framework\\FrameworkService.exe"=
"c:\\Program Files\\LeapFrog\\LeapFrog Connect\\LeapFrogConnect.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"22:TCP"= 22:TCP:sshd
"4092:TCP"= 4092:TCP:Furthur
"80:UDP"= 80:UDP:streampad
"62515:UDP"= 62515:UDP:vpn
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
"10000:TCP"= 10000:TCP:vpn2
"1080:TCP"= 1080:TCP:hide real ip
.
R0 BsStor;InCD Storage Helper Driver;c:\windows\system32\drivers\bsstor.sys [11/25/2003 6:29 AM 9344]
R2 BsUDF;InCD UDF Driver;c:\windows\system32\drivers\bsudf.sys [11/25/2003 6:29 AM 448640]
R2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [7/19/2011 8:09 AM 366640]
R2 McAfeeEngineService;McAfee Engine Service;c:\program files\McAfee\VirusScan Enterprise\engineserver.exe [9/29/2008 8:07 AM 19456]
R2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [10/18/2010 5:39 PM 67904]
R2 NOF;Norton Online;c:\program files\Norton Online\Engine\2.1.0.23\ccsvchst.exe [3/8/2011 6:37 PM 126904]
R3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [7/19/2011 8:09 AM 22712]
R3 SYMRDR_{78CA3BF0-9C3B-40e1-B46D-38C877EF059A};Symantec Redirector - Norton Safety Minder;c:\windows\system32\drivers\NSM\0201000.034\symrdr.sys [3/30/2011 3:25 PM 181296]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2010 2:51 AM 135664]
S2 sshd;CYGWIN sshd;c:\cygwin\bin\cygrunsrv.exe [10/6/2004 6:48 AM 36864]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [8/14/2010 7:58 AM 13192]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [8/14/2010 7:58 AM 8456]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [1/1/2010 2:51 AM 135664]
S3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [10/18/2010 5:39 PM 64432]
S3 MR97310_VGA_DUAL_CAMERA;VGA Dual-Mode Camera;c:\windows\system32\drivers\mr97310v.sys [3/30/2004 12:29 PM 118106]
S3 nosGetPlusHelper;getPlus(R) Helper 3004;c:\windows\System32\svchost.exe -k nosGetPlusHelper [8/23/2001 5:00 AM 14336]
S3 sasrfcService;sasrfc Service;c:\program files\SAS Institute\SAS\V8\access\sasexe\sasrfc.exe [7/23/2004 1:22 PM 41984]
S3 slz1nd5;SL Series (NDIS);c:\windows\system32\drivers\slz1nd5.sys [2/16/2004 9:53 PM 17808]
S3 slz1unic;SL Series (WDM);c:\windows\system32\drivers\slz1unic.sys [2/16/2004 9:31 PM 69920]
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - MBAMSwissArmy
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
nosGetPlusHelper REG_MULTI_SZ nosGetPlusHelper
.
Contents of the 'Scheduled Tasks' folder
.
2011-07-27 c:\windows\Tasks\229B350D-034F-4c01-BAF2-3EA03DCAE0B9.job
- c:\program files\Norton Online\AddOns\Norton Safety Minder\Engine\2.1.0.52\tampmon.exe [2011-03-30 00:20]
.
2011-07-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 18:50]
.
2011-07-26 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-24 05:47]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-01 09:51]
.
2011-07-27 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-01-01 09:51]
.
2011-07-26 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-920026266-725345543-1006Core.job
- c:\documents and settings\Jen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 03:21]
.
2011-07-27 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1993962763-920026266-725345543-1006UA.job
- c:\documents and settings\Jen\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-07-02 03:21]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.puretracks.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: Append to existing PDF - f:\adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: LimeShop Preferences - file://c:\program files\Lime_Shop\Sy700\Tp700\scri700a.htm
TCP: DhcpNameServer = 172.16.0.1
TCP: Interfaces\{B86ED354-CEBA-4939-8601-3913BCE4086F}: NameServer = 209.226.175.223,198.235.216.134
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
DPF: {22D4879A-92DB-470D-8A83-E158797D8176} - file://e:\components\Liquid.ocx
FF - ProfilePath - c:\documents and settings\Garrett\Application Data\Mozilla\Firefox\Profiles\25gceplc.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.xfinity.com/customer/start/?cid=xfstart_tech_main
FF - prefs.js: network.proxy.type - 0
FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF - Ext: Norton Safety Minder: {6D5C8FC4-DE46-41bf-9092-93F0F78E9115} - c:\documents and settings\All Users\Application Data\Norton\{78CA3BF0-9C3B-40e1-B46D-38C877EF059A}\NSM_2.1.0.37\coFFFw
FF - Ext: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - %profile%\extensions\{20a82645-c095-46ed-80e3-08825760534b}
FF - Ext: Adobe DLM (powered by getPlus(R)): {E2883E8F-472F-4fb0-9522-AC9BF37916A7} - %profile%\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}
.
- - - - ORPHANS REMOVED - - - -
.
MSConfigStartUp-DivXUpdate - c:\program files\DivX\DivX Update\DivXUpdate.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2011-07-26 20:08
Windows 5.1.2600 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXCRCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\NOF]
"ImagePath"="\"c:\program files\Norton Online\Engine\2.1.0.23\ccSvcHst.exe\" /s \"NOF\" /m \"c:\program files\Norton Online\Engine\2.1.0.23\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(972)
c:\windows\system32\igfxdev.dll
.
Completion time: 2011-07-26 20:13:00
ComboFix-quarantined-files.txt 2011-07-27 03:12
ComboFix2.txt 2010-08-29 15:00
ComboFix3.txt 2010-08-28 21:21
.
Pre-Run: 66,241,568,768 bytes free
Post-Run: 66,960,650,240 bytes free
.
- - End Of File - - AEBE6D0B5C84529A85B81D9D0D58B634