new log
ComboFix 09-09-23.02 - Bonnie 09/23/2009 16:00.2.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.2559.1754 [GMT -7:00]
Running from: c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\My Documents\Downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\My Documents\Downloads\CFScript.txt
AV: CA Anti-Virus *On-access scanning disabled* (Updated) {17CFD1EA-56CF-40B5-A06B-BD3A27397C93}
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\Logs\2009-09-18 18-50-370.log
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\filelist.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-0.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-1.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-10.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-100.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-101.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-102.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-103.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-104.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-105.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-106.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-107.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-108.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-109.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-11.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-110.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-111.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-112.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-113.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-114.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-115.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-116.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-117.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-118.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-119.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-12.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-120.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-121.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-122.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-123.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-124.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-125.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-126.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-127.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-128.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-129.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-13.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-130.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-131.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-132.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-133.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-134.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-135.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-136.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-137.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-138.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-139.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-14.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-140.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-141.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-142.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-143.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-144.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-145.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-146.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-15.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-16.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-17.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-18.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-19.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-2.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-20.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-21.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-22.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-23.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-24.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-25.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-26.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-27.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-28.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-29.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-3.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-30.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-31.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-32.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-33.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-34.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-35.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-36.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-37.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-38.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-39.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-4.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-40.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-41.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-42.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-43.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-44.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-45.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-46.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-47.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-48.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-49.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-5.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-50.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-51.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-52.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-53.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-54.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-55.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-56.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-57.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-58.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-59.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-6.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-60.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-61.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-62.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-63.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-64.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-65.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-66.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-67.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-68.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-69.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-7.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-70.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-71.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-72.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-73.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-74.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-75.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-76.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-77.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-78.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-79.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-8.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-80.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-81.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-82.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-83.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-84.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-85.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-86.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-87.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-88.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-89.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-9.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-90.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-91.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-92.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-93.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-94.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-95.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-96.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-97.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-98.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\QuarantineW\2009-09-18 18-52-490\regb-99.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\Results\Evidence.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\Results\Junk.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\Results\Registry.db
c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Reg Tool\Results\Update.db
c:\program files\Reg Tool
c:\program files\Reg Tool\PW\general.html
c:\program files\Reg Tool\PW\optimizations.html
c:\program files\Reg Tool\PW\privacy.html
c:\program files\Reg Tool\PW\scheduler.html
c:\program files\Reg Tool\PW\startup.html
c:\program files\Reg Tool\PW\wizard.css
.
((((((((((((((((((((((((( Files Created from 2009-08-23 to 2009-09-23 )))))))))))))))))))))))))))))))
.
2009-09-23 14:44 . 2009-09-23 14:44 -------- d-sh--w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\PrivacIE
2009-09-22 21:02 . 2009-09-22 21:02 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Malwarebytes
2009-09-22 21:02 . 2009-09-10 21:54 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-22 21:02 . 2009-09-22 21:02 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-09-22 21:02 . 2009-09-10 21:53 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-22 21:02 . 2009-09-22 21:02 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-09-22 16:53 . 2009-09-22 16:53 -------- d-----w- C:\rsit
2009-09-19 20:48 . 2009-09-19 20:48 -------- dc----w- c:\documents and settings\All Users.WINDOWS\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-09-19 20:42 . 2008-07-06 12:06 89088 -c----w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-09-19 20:42 . 2008-07-06 12:06 575488 -c----w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-09-19 20:42 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-09-19 20:42 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-09-19 20:42 . 2008-07-06 10:50 597504 -c----w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-09-19 20:42 . 2009-09-19 20:43 -------- d-----w- C:\234563fc4a7886848891d2c7
2009-09-19 20:42 . 2008-07-06 12:06 1676288 -c----w- c:\windows\system32\dllcache\xpssvcs.dll
2009-09-19 20:42 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-09-19 20:30 . 2009-09-19 20:30 -------- d-----r- C:\AHCache
2009-09-19 01:59 . 2009-09-19 01:59 -------- d-----w- c:\program files\Trend Micro
2009-09-18 21:00 . 2001-08-17 20:56 7552 -c--a-w- c:\windows\system32\dllcache\sonypvu1.sys
2009-09-18 21:00 . 2001-08-17 20:56 7552 ----a-w- c:\windows\system32\drivers\SONYPVU1.SYS
2009-09-17 03:15 . 2009-09-20 14:24 -------- d---a-w- c:\documents and settings\All Users.WINDOWS\Application Data\TEMP
2009-09-17 03:14 . 2009-09-17 03:14 -------- d-----w- c:\program files\Common Files\Oberon Media
2009-09-17 03:14 . 2009-09-17 03:14 -------- d-----w- c:\program files\IncrediGames
2009-09-17 01:49 . 2009-09-17 01:48 880560 ----a-w- c:\windows\system32\drivers\vetefile.sys
2009-09-17 01:49 . 2009-09-17 01:48 108368 ----a-w- c:\windows\system32\drivers\veteboot.sys
2009-09-17 01:46 . 2007-08-20 20:38 32264 ----a-w- c:\windows\system32\drivers\vetmonnt.sys
2009-09-17 01:46 . 2007-08-20 20:38 21512 ----a-w- c:\windows\system32\drivers\vetfddnt.sys
2009-09-17 01:46 . 2007-08-20 20:38 26376 ----a-w- c:\windows\system32\drivers\vet-filt.sys
2009-09-17 01:46 . 2007-08-20 20:38 21128 ----a-w- c:\windows\system32\drivers\vet-rec.sys
2009-09-17 01:46 . 2007-08-20 20:37 75016 ----a-w- c:\windows\system32\isafprod.dll
2009-09-17 01:46 . 2007-08-20 20:37 99592 ----a-w- c:\windows\system32\isafeif.dll
2009-09-17 01:46 . 2007-08-20 20:26 79424 ----a-w- c:\windows\system32\vetredir.dll
2009-09-17 01:46 . 2009-09-17 01:49 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\CA
2009-09-17 01:44 . 2009-09-17 01:44 -------- d-----w- c:\documents and settings\BONNIE~1~BON\LOCALS~1
2009-09-17 01:44 . 2009-09-17 01:44 -------- d-----w- c:\documents and settings\BONNIE~1~BON
2009-09-16 23:54 . 2009-08-07 08:48 100352 -c----w- c:\windows\system32\dllcache\iecompat.dll
2009-09-16 23:52 . 2009-07-20 01:48 11067392 -c----w- c:\windows\system32\dllcache\ieframe.dll
2009-09-16 23:52 . 2009-07-03 17:09 12800 -c----w- c:\windows\system32\dllcache\xpshims.dll
2009-09-16 23:52 . 2009-07-03 17:09 594432 -c----w- c:\windows\system32\dllcache\msfeeds.dll
2009-09-16 23:52 . 2009-07-03 17:09 55296 -c----w- c:\windows\system32\dllcache\msfeedsbs.dll
2009-09-16 23:52 . 2009-07-03 17:09 1985536 -c----w- c:\windows\system32\dllcache\iertutil.dll
2009-09-16 23:52 . 2009-07-03 17:09 246272 -c----w- c:\windows\system32\dllcache\ieproxy.dll
2009-09-13 10:01 . 2009-09-13 10:01 -------- d-----w- c:\program files\MSXML 4.0
2009-09-12 22:48 . 2008-06-13 11:05 272128 -c----w- c:\windows\system32\dllcache\bthport.sys
2009-09-12 22:46 . 2008-10-24 11:21 455296 -c----w- c:\windows\system32\dllcache\mrxsmb.sys
2009-09-12 22:46 . 2008-12-11 10:57 333952 -c----w- c:\windows\system32\dllcache\srv.sys
2009-09-12 22:46 . 2008-05-01 14:33 331776 -c----w- c:\windows\system32\dllcache\msadce.dll
2009-09-12 22:46 . 2009-07-10 13:27 1315328 -c----w- c:\windows\system32\dllcache\msoe.dll
2009-09-12 22:46 . 2008-04-11 19:04 691712 -c----w- c:\windows\system32\dllcache\inetcomm.dll
2009-09-12 22:46 . 2009-06-10 16:19 2066432 -c----w- c:\windows\system32\dllcache\mstscax.dll
2009-09-12 22:46 . 2008-10-03 10:02 247326 -c----w- c:\windows\system32\dllcache\strmdll.dll
2009-09-12 22:46 . 2008-10-15 16:34 337408 -c----w- c:\windows\system32\dllcache\netapi32.dll
2009-09-12 22:45 . 2008-05-03 11:55 2560 ------w- c:\windows\system32\xpsp4res.dll
2009-09-12 22:45 . 2008-04-21 12:08 215552 -c----w- c:\windows\system32\dllcache\wordpad.exe
2009-09-12 16:21 . 2009-09-20 00:55 58432 ----a-w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-12 09:38 . 2008-04-14 12:42 11264 ------w- c:\windows\system32\spnpinst.exe
2009-09-12 09:38 . 2004-08-02 21:20 4569 ------w- c:\windows\system32\secupd.dat
2009-09-11 01:14 . 2009-09-11 01:14 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\Identities
2009-09-10 02:50 . 2008-04-14 00:11 1082368 ----a-w- c:\windows\system32\esent.dll
2009-09-08 23:18 . 2009-09-08 23:18 0 ----a-w- c:\windows\nsreg.dat
2009-09-08 23:18 . 2009-09-08 23:18 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\Mozilla
2009-09-08 21:22 . 2009-09-08 21:22 -------- d-s---w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\UserData
2009-09-08 16:57 . 2009-09-08 16:57 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\Yahoo
2009-09-08 16:21 . 2009-09-15 21:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo! Companion
2009-09-08 16:21 . 2009-09-08 16:22 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Yahoo!
2009-09-08 16:21 . 2009-09-08 16:57 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Yahoo!
2009-09-08 16:15 . 2009-09-08 16:15 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\IM
2009-09-08 16:14 . 2009-09-08 16:17 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\IM
2009-09-08 16:14 . 2009-09-08 16:14 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\IncrediMail
2009-09-08 15:49 . 2009-01-08 01:21 26144 ----a-w- c:\windows\system32\spupdsvc.exe
2009-09-08 15:48 . 2008-12-16 12:30 354304 ----a-w- c:\windows\system32\winhttp.dll
2009-09-08 15:48 . 2008-04-14 00:12 18944 ----a-w- c:\windows\system32\qmgrprxy.dll
2009-09-08 15:48 . 2008-04-14 00:11 8192 ------w- c:\windows\system32\bitsprx2.dll
2009-09-08 15:48 . 2008-04-14 00:11 7168 ------w- c:\windows\system32\bitsprx3.dll
2009-09-08 15:45 . 2008-10-16 21:13 202776 ----a-w- c:\windows\system32\wuweb.dll
2009-09-08 15:45 . 2008-10-16 21:12 323608 ----a-w- c:\windows\system32\wucltui.dll
2009-09-08 15:45 . 2008-10-16 21:12 561688 ----a-w- c:\windows\system32\wuapi.dll
2009-09-08 15:45 . 2008-10-16 21:08 34328 ----a-w- c:\windows\system32\wups.dll
2009-09-08 15:45 . 2008-04-14 00:12 165888 ----a-w- c:\windows\system32\wuauclt1.exe
2009-09-08 15:45 . 2008-04-14 00:12 183296 ----a-w- c:\windows\system32\wuaueng1.dll
2009-09-08 15:29 . 2009-09-08 15:29 -------- d-----w- c:\program files\Broadcom
2009-09-08 01:52 . 2003-07-16 20:51 41600 -c--a-w- c:\windows\system32\dllcache\weitekp9.dll
2009-09-08 01:52 . 2003-07-16 20:51 31232 -c--a-w- c:\windows\system32\dllcache\weitekp9.sys
2009-09-08 01:50 . 2008-04-14 00:09 198656 -c--a-w- c:\windows\system32\dllcache\cintime.dll
2009-09-08 01:47 . 2003-07-16 20:48 40960 -c--a-w- c:\windows\system32\dllcache\trialoc.dll
2009-09-08 01:47 . 2003-07-16 20:30 73728 -c--a-w- c:\windows\system32\dllcache\icwtutor.exe
2009-09-08 01:47 . 2003-07-16 20:30 61440 -c--a-w- c:\windows\system32\dllcache\icwres.dll
2009-09-08 01:46 . 2008-04-14 00:12 39936 ----a-w- c:\windows\system32\wbem\snmpthrd.dll
2009-09-08 01:46 . 2008-04-14 00:12 259072 ----a-w- c:\windows\system32\wbem\snmpcl.dll
2009-09-08 01:37 . 2003-07-16 20:46 24661 -c--a-w- c:\windows\system32\dllcache\spxcoins.dll
2009-09-08 01:37 . 2003-07-16 20:46 24661 ----a-w- c:\windows\system32\spxcoins.dll
2009-09-08 01:37 . 2003-07-16 20:30 13312 -c--a-w- c:\windows\system32\dllcache\irclass.dll
2009-09-08 01:37 . 2003-07-16 20:30 13312 ----a-w- c:\windows\system32\irclass.dll
2009-09-08 01:30 . 2009-09-08 01:30 -------- d-----w- C:\$WIN_NT$.~BT
2009-09-07 21:55 . 2009-09-22 23:00 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000002-00000000-00000003-00001102-00000004-10031102}.dat
2009-09-07 21:55 . 2009-09-22 23:00 288 ----a-w- c:\windows\system32\DVCState-{00000002-00000000-00000003-00001102-00000004-10031102}.dat
2009-09-07 21:54 . 2009-09-07 21:54 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Creative
2009-09-07 21:53 . 2009-09-07 21:53 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Jasc Software Inc
2009-09-07 21:48 . 2009-09-07 21:48 184 ----a-w- c:\windows\system32\e000001.dat
2009-09-07 21:48 . 2003-03-05 19:19 15840 ----a-w- c:\windows\system32\pfmodnt.sys
2009-09-07 21:48 . 2003-01-15 18:41 77824 ----a-w- c:\windows\system32\ctdvda32.dll
2009-09-07 21:48 . 2003-01-27 23:32 831600 ----a-w- c:\windows\system32\Ctaa1.dat
2009-09-07 21:48 . 2001-05-28 20:47 12288 ----a-w- c:\windows\system32\AHQCpURes.dll
2009-09-07 21:47 . 2001-03-30 09:00 62976 ----a-w- c:\windows\system32\CTDetres.dll
2009-09-07 21:47 . 1999-12-13 08:01 44032 ----a-w- c:\windows\system32\CTSVCCDA.EXE
2009-09-07 21:47 . 1999-11-18 08:00 25088 ----a-w- c:\windows\system32\CTSVCCTL.EXE
2009-09-07 21:47 . 2002-02-20 09:00 331776 ----a-w- c:\windows\system32\CTMEDENG.DLL
2009-09-07 21:47 . 2000-04-20 08:00 24576 ----a-w- c:\windows\system32\CTMERes.DLL
2009-09-07 21:03 . 2009-09-10 22:45 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Local Settings\Application Data\ApplicationHistory
2009-09-07 20:33 . 2003-08-28 23:58 4272 ----a-r- c:\windows\system32\drivers\bvrp_pci.sys
2009-09-07 20:08 . 2002-01-09 00:00 176128 ----a-w- c:\windows\system32\RcdScan.dll
2009-09-07 20:08 . 2000-03-23 19:50 446464 ----a-r- c:\windows\system32\hhactivex.dll
2009-09-07 20:08 . 1998-06-18 06:00 89360 ----a-w- c:\windows\system32\VB5DB.DLL
2009-09-07 20:08 . 2001-08-22 15:42 13632 ----a-w- c:\windows\system32\drivers\omci.sys
2009-09-07 19:38 . 2009-09-07 19:38 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\MSN6
2009-09-07 19:38 . 2009-09-07 19:38 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\MSN6
2009-09-07 19:23 . 2003-03-21 22:56 24576 ----a-w- c:\windows\system32\xpsp1hfm.exe
2009-09-07 19:21 . 2009-09-19 03:34 -------- d-sh--w- c:\documents and settings\All Users.WINDOWS\DRM
2009-09-07 12:16 . 2001-08-17 13:59 3072 ----a-w- c:\windows\system32\drivers\audstub.sys
2009-09-07 12:16 . 2008-04-13 18:47 25856 ----a-w- c:\windows\system32\drivers\usbprint.sys
2009-09-07 12:16 . 2001-08-17 13:57 16128 ----a-w- c:\windows\system32\drivers\MODEMCSA.sys
2009-09-07 12:16 . 2008-04-13 18:40 57600 ----a-w- c:\windows\system32\drivers\redbook.sys
2009-09-07 12:16 . 2001-08-17 13:46 6400 ----a-w- c:\windows\system32\drivers\enum1394.sys
2009-09-07 12:15 . 2001-08-17 13:28 871388 ----a-w- c:\windows\system32\drivers\BCMDM.sys
2009-09-07 12:08 . 2009-09-07 19:24 -------- d--h--w- c:\documents and settings\Default User.WINDOWS
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k7
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k6
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k5
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k4
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k3
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k2
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k1
2009-09-22 23:00 . 2009-09-17 00:00 64 ----a-w- c:\windows\system32\drivers\kmxcfg.u2k0
2009-09-18 21:01 . 2009-09-17 00:01 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Road Runner
2009-09-17 03:14 . 2005-08-10 14:36 -------- d-----w- c:\program files\Oberon Media
2009-09-17 00:29 . 2009-09-17 00:29 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Road Runner
2009-09-17 00:29 . 2009-09-17 00:01 -------- d-----w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Simple Star
2009-09-17 00:27 . 2007-03-04 23:53 -------- d-----w- c:\program files\Common Files\Simple Star Shared
2009-09-17 00:27 . 2009-09-17 00:26 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Simple Star Shared
2009-09-17 00:26 . 2007-03-04 23:53 -------- d-----w- c:\program files\Road Runner
2009-09-17 00:26 . 2009-09-17 00:26 -------- d-----w- c:\documents and settings\All Users.WINDOWS\Application Data\Simple Star
2009-09-16 23:57 . 2009-09-12 16:21 2376 ----a-w- c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\wklnhst.dat
2009-09-12 16:05 . 2004-02-21 16:22 -------- d-----w- c:\program files\Microsoft Picture It! 9
2009-09-12 16:03 . 2004-02-21 16:22 -------- d-----w- c:\program files\Microsoft Streets and Trips
2009-09-12 16:02 . 2004-02-21 16:21 -------- d-----w- c:\program files\Microsoft Money
2009-09-12 15:58 . 2004-02-21 16:20 -------- d-----w- c:\program files\Microsoft Works
2009-09-08 16:22 . 2004-02-25 20:07 -------- d-----w- c:\program files\Yahoo!
2009-09-08 16:15 . 2004-04-24 13:33 -------- d-----w- c:\program files\IncrediMail
2009-09-08 01:47 . 2009-09-07 19:20 23348 ----a-w- c:\windows\system32\emptyregdb.dat
2009-09-07 22:01 . 2004-02-21 16:14 -------- d-----w- c:\program files\Modem Helper
2009-09-07 21:44 . 2004-02-21 16:14 -------- d-----w- c:\program files\Common Files\SureThing Shared
2009-09-07 21:44 . 2004-02-21 16:14 -------- d-----w- c:\program files\Sonic
2009-09-05 17:35 . 2004-02-21 16:07 -------- d-----w- c:\program files\Java
2009-08-31 15:18 . 2004-03-02 21:22 32022 ----a-w- c:\documents and settings\Bonnie\Application Data\wklnhst.dat
2009-08-23 04:04 . 2009-06-16 02:02 -------- d-----w- c:\documents and settings\Bonnie\Application Data\Cabos
2009-08-16 23:55 . 2009-08-16 23:55 -------- d-----w- c:\program files\FriendFinder
2009-08-12 11:22 . 2008-03-27 13:38 -------- d-----w- c:\program files\Safari
2009-08-11 19:16 . 2009-08-11 19:16 -------- d-----w- c:\program files\Common Files\TSCUninstall
2009-08-09 17:59 . 2009-08-09 17:59 -------- d-----w- c:\program files\Profile Pimp
2009-08-09 17:59 . 2009-08-09 17:59 -------- d-----w- c:\program files\Free Offers from Freeze.com
2009-08-05 12:35 . 2009-08-05 12:34 -------- d-----w- c:\program files\iTunes
2009-08-05 12:34 . 2009-08-05 12:34 -------- d-----w- c:\program files\iPod
2009-08-05 12:34 . 2007-07-05 21:15 -------- d-----w- c:\program files\Common Files\Apple
2009-08-05 09:01 . 2003-07-16 20:37 204800 ----a-w- c:\windows\system32\mswebdvd.dll
2009-08-02 02:22 . 2009-06-27 23:25 -------- d-----w- c:\documents and settings\Bonnie\Application Data\Image Zone Express
2009-07-29 04:37 . 2005-10-17 21:29 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-07-29 04:37 . 2003-07-16 20:28 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-07-17 19:01 . 2003-07-16 20:24 58880 ----a-w- c:\windows\system32\atl.dll
2009-07-12 19:21 . 2004-08-04 07:56 233472 ------w- c:\windows\system32\wmpdxm.dll
2009-07-03 17:09 . 2006-06-23 18:33 915456 ------w- c:\windows\system32\wininet.dll
2007-03-07 20:09 . 2007-03-07 20:09 1009205 ----a-w- c:\program files\DVD Decrypter.rar
2007-03-07 20:09 . 2007-03-07 20:09 1168 ----a-w- c:\program files\DVD Shrink.rar
2007-03-07 20:09 . 2007-03-07 20:09 4594 ----a-w- c:\program files\DVD Wizard PRO.rar
2007-03-07 20:08 . 2007-03-07 20:08 270 ----a-w- c:\program files\Dvd-to-dvdr.rar
2007-03-07 20:06 . 2007-03-07 20:06 5166979 ----a-w- c:\program files\Dvd-cloner.rar
2007-03-07 20:02 . 2007-03-07 20:02 155292 ----a-w- c:\program files\Blaze Media Pro.rar
2007-03-07 20:01 . 2007-03-07 20:01 201 ----a-w- c:\program files\Mozilla Firefox.rar
2007-03-07 19:57 . 2007-03-07 19:57 448669 ----a-w- c:\program files\Trojan Guarder Gold Version.rar
2005-11-12 14:12 . 2005-11-12 14:00 504965506 ----a-w- c:\program files\Jasc Software Inc.rar
2005-06-07 11:08 . 2005-06-07 11:08 774144 ----a-w- c:\program files\RngInterstitial.dll
2005-01-24 16:01 . 2005-01-24 16:01 20279785 ----a-w- c:\program files\CyberLink.PowerEncoder.MPEG4.AVC.Edition.v1.0.Merry.Xmas-ROR.rar
2005-01-24 15:41 . 2005-01-24 15:41 10618 ----a-w- c:\program files\winrar3.42reg.htm
2004-12-06 01:21 . 2004-12-06 01:21 394775 ----a-w- c:\program files\1clickcombosetup.exe
2004-10-30 05:00 . 2005-03-24 15:13 34397 ----a-w- c:\program files\PictureSorter.zip
2004-06-14 14:40 . 2004-06-14 14:40 22251292 ----a-w- c:\program files\systemmechanicpro.exe
2004-05-25 16:27 . 2004-05-25 16:27 7272960 ----a-w- c:\program files\avg6688fu_free.exe
2004-05-19 04:16 . 2004-05-19 04:16 484 ----a-w- c:\program files\file_id.diz
2004-05-19 04:16 . 2004-05-19 04:16 8251 ----a-w- c:\program files\eithel.nfo
2004-03-03 01:42 . 2004-03-03 01:42 4361 ----a-r- c:\program files\e-Lunatic.diz
2001-05-09 12:11 . 2001-05-09 12:11 31 ----a-w- c:\program files\Install-KPTGoo.txt
1999-08-18 17:42 . 1999-08-18 17:42 3704689 ----a-r- c:\program files\KPTGOO.EXE
.
((((((((((((((((((((((((((((( SnapShot@2009-09-22_23.01.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-09-17 01:47 . 2009-09-23 19:02 10134 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\ARPPRODUCTICON.exe
- 2009-09-17 01:47 . 2009-09-22 12:44 10134 c:\windows\Installer\{BDBAAB1B-B364-465E-931D-4E2E2F0E609A}\ARPPRODUCTICON.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"="c:\program files\IncrediMail\bin\IncMail.exe" [2009-08-10 251264]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-05-27 4351216]
"Search Protection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"MoneyAgent"="c:\program files\Microsoft Money\System\mnyexpr.exe" [2003-06-18 200704]
"Road Runner PhotoShow Media Manager"="c:\progra~1\ROADRU~2\PHOTOS~1\data\Xtras\mssysmgr.exe" [2008-05-09 361976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2009-02-23 111856]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2009-09-17 177392]
"QOELOADER"="c:\program files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe" [2009-09-17 14088]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2009-09-17 230664]
"cafwc"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2009-09-22 1193200]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2009-09-22 173296]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2009-09-22 259312]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\SYSTEM32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\SYSTEM32\CTASIO.DLL [2003-02-20 110592]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\documents and settings\Bonnie\Start Menu\Programs\Startup\
WKCALREM.LNK - c:\program files\Common Files\Microsoft Shared\Works Shared\WkCalRem.exe [2003-12-5 24651]
c:\documents and settings\All Users.WINDOWS\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 20:30 79368 ----a-w- c:\windows\SYSTEM32\UmxWNP.dll
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\IncrediMail\\bin\\IncMail.exe"=
"c:\\Program Files\\IncrediMail\\bin\\ImApp.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
R0 KmxStart;KmxStart;c:\windows\SYSTEM32\DRIVERS\KmxStart.sys [6/24/2008 7:08 PM 93712]
R1 KmxAgent;KmxAgent;c:\windows\SYSTEM32\DRIVERS\KmxAgent.sys [6/24/2008 7:08 PM 63504]
R1 KmxFile;KmxFile;c:\windows\SYSTEM32\DRIVERS\KmxFile.sys [6/24/2008 7:08 PM 45584]
R1 KmxFw;KmxFw;c:\windows\SYSTEM32\DRIVERS\KmxFw.sys [6/24/2008 7:08 PM 115216]
R2 KmxCF;KmxCF;c:\windows\SYSTEM32\DRIVERS\KmxCF.sys [6/24/2008 7:08 PM 134648]
R2 KmxSbx;KmxSbx;c:\windows\SYSTEM32\DRIVERS\KmxSbx.sys [6/24/2008 7:08 PM 66576]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [10/18/2007 7:24 AM 801296]
R3 KmxCfg;KmxCfg;c:\windows\SYSTEM32\DRIVERS\KmxCfg.sys [6/24/2008 7:08 PM 88816]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [8/16/2007 6:10 PM 189704]
S2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [10/18/2007 7:24 AM 1010192]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2009-09-17 c:\windows\Tasks\CAAntiSpywareScan_Daily as Bonnie at 6 46 PM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2007-08-17 01:10]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://mystart.incredigames.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*
http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*
http://www.yahoo.com
LSP: c:\windows\system32\VetRedir.dll
FF - ProfilePath - c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Mozilla\Firefox\Profiles\1w7ph4cv.default\
FF - prefs.js: browser.search.selectedEngine - MyStart Search
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://mystart.incredigames.com/?loc=FF_Incredigame_AddressBar&search=
FF - plugin: c:\documents and settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Mozilla\Firefox\Profiles\1w7ph4cv.default\extensions\{E2883E8F-472F-4fb0-9522-AC9BF37916A7}\plugins\np_gp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
- - - - ORPHANS REMOVED - - - -
HKLM-RunOnce-<NO NAME> - (no file)
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-09-23 16:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32]
@="c:\\WINDOWS\\System32\\Macromed\\Flash\\FlashUtil10c.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}]
@Denied: (A 2) (Everyone)
@="IFlashBroker3"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(688)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
- - - - - - - > 'lsass.exe'(744)
c:\windows\system32\VetRedir.dll
c:\windows\system32\ISafeIf.dll
.
Completion time: 2009-09-23 16:11
ComboFix-quarantined-files.txt 2009-09-23 23:11
ComboFix2.txt 2009-09-22 23:07
Pre-Run: 157,333,204,992 bytes free
Post-Run: 157,312,360,448 bytes free
495 --- E O F --- 2009-09-20 10:08