newwyorkbound
New member
- 2008-04-14 00:12:08 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
+ 2004-08-04 19:00:00 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
- 2008-04-14 00:12:08 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
+ 2004-08-04 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
- 2008-04-14 00:12:08 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
+ 2004-08-04 19:00:00 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
- 2008-04-14 00:12:08 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
+ 2004-08-04 19:00:00 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
- 2008-04-14 00:12:08 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll
+ 2004-08-04 19:00:00 530,944 ----a-w c:\windows\system32\wbem\wbemcore.dll
- 2008-04-14 00:12:08 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
+ 2004-08-04 19:00:00 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
- 2008-04-14 00:12:08 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
+ 2004-08-04 19:00:00 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
- 2008-04-14 00:12:08 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
+ 2004-08-04 19:00:00 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
- 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
+ 2004-08-04 19:00:00 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
- 2008-04-14 00:12:08 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
+ 2004-08-04 19:00:00 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
- 2008-04-14 00:12:39 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
+ 2004-08-04 19:00:00 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
- 2008-04-14 00:12:08 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
+ 2004-08-04 19:00:00 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
- 2008-04-14 00:12:40 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
+ 2004-08-04 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
- 2008-04-13 17:10:20 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
+ 2004-08-04 19:00:00 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
- 2008-04-14 00:12:09 88,576 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
+ 2004-08-04 19:00:00 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
- 2008-04-14 00:12:40 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
+ 2004-08-04 19:00:00 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
- 2008-04-14 00:12:09 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
+ 2004-08-04 19:00:00 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
- 2008-04-14 00:12:09 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
+ 2004-08-04 19:00:00 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
- 2008-04-14 00:12:09 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
+ 2004-08-04 19:00:00 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
- 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
+ 2004-08-04 19:00:00 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
- 2008-04-14 00:12:09 61,952 ----a-w c:\windows\system32\wbem\wmipiprt.dll
+ 2004-08-04 19:00:00 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll
- 2008-04-14 00:12:09 62,464 ----a-w c:\windows\system32\wbem\wmipjobj.dll
+ 2004-08-04 19:00:00 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll
- 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
+ 2004-08-04 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
- 2008-04-14 00:12:09 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-04 19:00:00 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
- 2008-04-14 00:12:40 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-04 19:00:00 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
- 2008-04-14 00:12:09 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
+ 2004-08-04 19:00:00 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
- 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
+ 2004-08-04 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
- 2008-04-14 00:12:09 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
+ 2004-08-04 19:00:00 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
- 2008-04-14 00:12:08 49,152 ----a-w c:\windows\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 ----a-w c:\windows\system32\wdigest.dll
- 2008-04-14 00:12:45 23,552 ----a-w c:\windows\system32\wdmaud.drv
+ 2004-08-04 08:56:58 23,552 ----a-w c:\windows\system32\wdmaud.drv
- 2008-04-14 00:12:08 68,096 ----a-w c:\windows\system32\webclnt.dll
+ 2006-01-04 03:35:05 68,096 ----a-w c:\windows\system32\webclnt.dll
- 2008-04-14 00:12:08 135,680 ----a-w c:\windows\system32\webvw.dll
+ 2004-08-04 19:00:00 135,680 ----a-w c:\windows\system32\webvw.dll
- 2008-04-14 00:12:39 65,024 ----a-w c:\windows\system32\wextract.exe
+ 2004-08-04 19:00:00 65,536 ----a-w c:\windows\system32\wextract.exe
- 2008-04-14 00:12:39 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
+ 2004-08-04 19:00:00 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
- 2008-04-14 00:12:08 463,360 ----a-w c:\windows\system32\wiadefui.dll
+ 2004-08-04 19:00:00 463,360 ----a-w c:\windows\system32\wiadefui.dll
- 2008-04-14 00:12:08 124,416 ----a-w c:\windows\system32\wiadss.dll
+ 2004-08-04 19:00:00 124,416 ----a-w c:\windows\system32\wiadss.dll
- 2008-04-14 00:12:08 75,776 ----a-w c:\windows\system32\wiascr.dll
+ 2004-08-04 19:00:00 75,776 ----a-w c:\windows\system32\wiascr.dll
- 2008-04-14 00:12:08 333,824 ----a-w c:\windows\system32\wiaservc.dll
+ 2006-12-19 18:16:47 333,824 ----a-w c:\windows\system32\wiaservc.dll
- 2008-04-14 00:12:08 589,312 ----a-w c:\windows\system32\wiashext.dll
+ 2004-08-04 19:00:00 589,312 ----a-w c:\windows\system32\wiashext.dll
- 2008-04-14 00:12:08 111,104 ----a-w c:\windows\system32\wiavideo.dll
+ 2004-08-04 19:00:00 111,104 ----a-w c:\windows\system32\wiavideo.dll
- 2008-09-15 12:12:56 1,846,400 ----a-w c:\windows\system32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\system32\win32k.sys
- 2008-04-14 00:12:08 102,400 ----a-w c:\windows\system32\win32spl.dll
+ 2004-08-04 19:00:00 101,888 ----a-w c:\windows\system32\win32spl.dll
- 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll
+ 2004-08-04 19:00:00 937,984 ----a-w c:\windows\system32\winbrand.dll
- 2008-04-14 00:12:08 354,304 ----a-w c:\windows\system32\winhttp.dll
+ 2004-08-04 19:00:00 351,232 ----a-w c:\windows\system32\winhttp.dll
- 2008-04-14 00:12:09 32,256 ----a-w c:\windows\system32\winipsec.dll
+ 2004-08-04 19:00:00 32,768 ----a-w c:\windows\system32\winipsec.dll
- 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\winlogon.exe
+ 2004-08-04 19:00:00 502,272 ----a-w c:\windows\system32\winlogon.exe
- 2008-04-14 00:12:09 176,128 ----a-w c:\windows\system32\winmm.dll
+ 2004-08-04 19:00:00 176,128 ----a-w c:\windows\system32\winmm.dll
- 2008-04-14 00:11:11 756,224 ----a-w c:\windows\system32\winntbbu.dll
+ 2004-08-04 19:00:00 764,928 ----a-w c:\windows\system32\winntbbu.dll
- 2008-04-14 00:12:09 16,896 ----a-w c:\windows\system32\winrnr.dll
+ 2004-08-04 19:00:00 16,896 ----a-w c:\windows\system32\winrnr.dll
- 2008-04-14 00:12:09 99,328 ----a-w c:\windows\system32\winscard.dll
+ 2004-08-04 19:00:00 99,328 ----a-w c:\windows\system32\winscard.dll
- 2008-04-14 00:12:09 17,408 ----a-w c:\windows\system32\winshfhc.dll
+ 2004-08-04 19:00:00 17,408 ----a-w c:\windows\system32\winshfhc.dll
- 2008-04-14 00:12:45 146,432 ----a-w c:\windows\system32\winspool.drv
+ 2004-08-04 19:00:00 146,432 ----a-w c:\windows\system32\winspool.drv
- 2008-04-14 00:12:09 293,376 ----a-w c:\windows\system32\winsrv.dll
+ 2007-03-17 13:43:01 292,864 ----a-w c:\windows\system32\winsrv.dll
- 2008-04-14 00:12:09 53,760 ----a-w c:\windows\system32\winsta.dll
+ 2004-08-04 19:00:00 53,760 ----a-w c:\windows\system32\winsta.dll
- 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\wintrust.dll
+ 2004-08-04 19:00:00 176,640 ----a-w c:\windows\system32\wintrust.dll
- 2008-04-14 00:12:40 5,632 ----a-w c:\windows\system32\winver.exe
+ 2004-08-04 19:00:00 5,632 ----a-w c:\windows\system32\winver.exe
- 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2006-08-17 12:28:27 132,096 ----a-w c:\windows\system32\wkssvc.dll
- 2008-04-14 00:12:09 172,032 ----a-w c:\windows\system32\wldap32.dll
+ 2004-08-04 19:00:00 172,032 ----a-w c:\windows\system32\wldap32.dll
- 2008-04-14 00:12:09 92,672 ----a-w c:\windows\system32\wlnotify.dll
+ 2004-08-04 19:00:00 92,672 ----a-w c:\windows\system32\wlnotify.dll
- 2008-04-14 00:11:15 5,632 ----a-w c:\windows\system32\wmi.dll
+ 2004-08-04 19:00:00 5,632 ----a-w c:\windows\system32\wmi.dll
- 2008-04-14 00:12:09 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
+ 2004-08-04 19:00:00 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
- 2008-04-14 00:12:10 303,616 ----a-w c:\windows\system32\wmstream.dll
+ 2004-08-04 19:00:00 303,616 ----a-w c:\windows\system32\wmstream.dll
- 2008-04-14 00:12:10 264,192 ----a-w c:\windows\system32\wow32.dll
+ 2004-08-04 19:00:00 264,192 ----a-w c:\windows\system32\wow32.dll
- 2008-04-14 00:12:40 32,256 ----a-w c:\windows\system32\wpabaln.exe
+ 2004-08-04 19:00:00 32,256 ----a-w c:\windows\system32\wpabaln.exe
- 2008-04-14 00:12:41 11,264 ----a-w c:\windows\system32\wpnpinst.exe
+ 2004-08-04 19:00:00 32,256 ----a-w c:\windows\system32\wpnpinst.exe
- 2008-04-14 00:12:10 82,432 ----a-w c:\windows\system32\ws2_32.dll
+ 2004-08-04 19:00:00 82,944 ----a-w c:\windows\system32\ws2_32.dll
- 2008-04-14 00:12:10 19,968 ----a-w c:\windows\system32\ws2help.dll
+ 2004-08-04 19:00:00 19,968 ----a-w c:\windows\system32\ws2help.dll
- 2008-04-14 00:12:41 13,824 ----a-w c:\windows\system32\wscntfy.exe
+ 2004-08-04 19:00:00 13,824 ----a-w c:\windows\system32\wscntfy.exe
- 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe
+ 2004-08-04 19:00:00 114,688 ----a-w c:\windows\system32\wscript.exe
- 2008-04-14 00:12:10 80,896 ----a-w c:\windows\system32\wscsvc.dll
+ 2004-08-04 19:00:00 81,408 ----a-w c:\windows\system32\wscsvc.dll
- 2008-04-14 00:12:10 108,032 ----a-w c:\windows\system32\wshbth.dll
+ 2004-08-04 19:00:00 108,032 ----a-w c:\windows\system32\wshbth.dll
- 2008-04-14 00:12:10 36,864 ----a-w c:\windows\system32\wshcon.dll
+ 2004-08-04 19:00:00 28,672 ----a-w c:\windows\system32\wshcon.dll
- 2008-05-09 10:53:40 90,112 ----a-w c:\windows\system32\wshext.dll
+ 2004-08-04 19:00:00 65,536 ----a-w c:\windows\system32\wshext.dll
- 2008-04-14 00:12:10 14,336 ----a-w c:\windows\system32\wship6.dll
+ 2004-08-04 19:00:00 14,336 ----a-w c:\windows\system32\wship6.dll
- 2008-04-14 00:12:10 11,264 ----a-w c:\windows\system32\wshrm.dll
+ 2004-08-04 19:00:00 11,776 ----a-w c:\windows\system32\wshrm.dll
- 2008-04-14 00:12:10 19,456 ----a-w c:\windows\system32\wshtcpip.dll
+ 2004-08-04 19:00:00 19,968 ----a-w c:\windows\system32\wshtcpip.dll
- 2008-04-14 00:12:10 41,984 ----a-w c:\windows\system32\wsnmp32.dll
+ 2004-08-04 19:00:00 42,496 ----a-w c:\windows\system32\wsnmp32.dll
- 2008-04-14 00:12:10 22,528 ----a-w c:\windows\system32\wsock32.dll
+ 2004-08-04 19:00:00 22,528 ----a-w c:\windows\system32\wsock32.dll
- 2008-04-14 00:12:10 50,688 ----a-w c:\windows\system32\wstdecod.dll
+ 2004-08-04 19:00:00 50,688 ----a-w c:\windows\system32\wstdecod.dll
- 2008-04-14 00:12:10 18,432 ----a-w c:\windows\system32\wtsapi32.dll
+ 2004-08-04 19:00:00 18,432 ----a-w c:\windows\system32\wtsapi32.dll
- 2008-04-14 00:12:41 165,888 ----a-w c:\windows\system32\wuauclt1.exe
+ 2004-08-04 19:00:00 165,888 ----a-w c:\windows\system32\wuauclt1.exe
- 2008-04-14 00:12:11 183,296 ----a-w c:\windows\system32\wuaueng1.dll
+ 2004-08-04 19:00:00 183,296 ----a-w c:\windows\system32\wuaueng1.dll
- 2008-04-14 00:12:11 6,656 ----a-w c:\windows\system32\wuauserv.dll
+ 2004-08-04 19:00:00 6,656 ----a-w c:\windows\system32\wuauserv.dll
- 2008-04-14 00:12:11 383,488 ----a-w c:\windows\system32\wzcdlg.dll
+ 2004-08-04 19:00:00 378,368 ----a-w c:\windows\system32\wzcdlg.dll
- 2008-04-14 00:12:11 52,736 ----a-w c:\windows\system32\wzcsapi.dll
+ 2004-08-04 19:00:00 51,712 ----a-w c:\windows\system32\wzcsapi.dll
- 2008-04-14 00:12:11 483,840 ----a-w c:\windows\system32\wzcsvc.dll
+ 2004-08-04 19:00:00 359,936 ----a-w c:\windows\system32\wzcsvc.dll
- 2008-04-14 00:12:11 91,648 ----a-w c:\windows\system32\xactsrv.dll
+ 2004-08-04 19:00:00 91,648 ----a-w c:\windows\system32\xactsrv.dll
- 2008-04-14 00:12:41 30,720 ----a-w c:\windows\system32\xcopy.exe
+ 2004-08-04 19:00:00 30,720 ----a-w c:\windows\system32\xcopy.exe
- 2008-04-14 00:12:11 121,856 ----a-w c:\windows\system32\xmllite.dll
+ 2006-07-14 15:51:51 121,856 ----a-w c:\windows\system32\xmllite.dll
- 2008-04-14 00:12:11 129,024 ----a-w c:\windows\system32\xmlprov.dll
+ 2004-08-04 19:00:00 129,536 ----a-w c:\windows\system32\xmlprov.dll
- 2008-04-14 00:12:11 50,176 ----a-w c:\windows\system32\xmlprovi.dll
+ 2004-08-04 19:00:00 50,176 ----a-w c:\windows\system32\xmlprovi.dll
- 2008-04-14 00:12:11 11,776 ----a-w c:\windows\system32\xolehlp.dll
+ 2006-03-01 19:42:42 11,776 ----a-w c:\windows\system32\xolehlp.dll
- 2008-04-13 17:39:29 438,784 ----a-w c:\windows\system32\xpob2res.dll
+ 2004-08-04 19:00:00 438,784 ----a-w c:\windows\system32\xpob2res.dll
- 2008-04-13 17:39:22 187,392 ----a-w c:\windows\system32\xpsp1res.dll
+ 2004-08-04 19:00:00 187,392 ----a-w c:\windows\system32\xpsp1res.dll
- 2008-04-13 17:39:24 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
+ 2004-08-04 19:00:00 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
- 2008-04-13 17:39:26 689,152 ----a-w c:\windows\system32\xpsp3res.dll
+ 2007-10-29 10:04:03 350,720 ----a-w c:\windows\system32\xpsp3res.dll
- 2008-04-14 00:12:11 338,432 ----a-w c:\windows\system32\zipfldr.dll
+ 2004-08-04 19:00:00 337,920 ----a-w c:\windows\system32\zipfldr.dll
+ 2009-01-28 07:35:10 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_8d8.dat
- 2008-04-14 00:12:07 50,688 ----a-w c:\windows\twain_32.dll
+ 2004-08-04 19:00:00 50,688 ----a-w c:\windows\twain_32.dll
- 2008-04-14 00:12:39 283,648 ----a-w c:\windows\winhlp32.exe
+ 2004-08-04 19:00:00 283,648 ----a-w c:\windows\winhlp32.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-23 68856]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2008-10-16 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-08-28 147456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe [2007-12-07 28672]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MostFun.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MostFun.lnk
backup=c:\windows\pss\MostFun.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-01-03 11:15 50528 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2005-04-29 00:05 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-11-21 17:38 52840 c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 14:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-06-20 22:36 1207080 c:\progra~1\MI3AA1~1\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lost Beachs screen saver]
--a------ 2002-02-06 17:09 370176 c:\program files\Lost Beachs\screen saver\TaskTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 14:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2002-09-14 02:42 212992 c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 23:24 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-11-23 01:38 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2008-02-19 12:01 104080 c:\progra~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-11-05 05:47 688218 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-11-05 05:47 98394 c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
--a------ 2007-03-14 19:49 125632 c:\progra~1\SYMANT~1\VPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-10-16 20:57 4347120 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-03 99376]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2004-12-15 200192]
R4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-27 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Bejeweled%202/Images/stg_drm.ocx
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yl65l58j.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.portal.radford.edu/MyRU.php
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yl65l58j.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-28 02:33:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop4]
"Name"="oemDesktop4"
"DisplayName"="NotepadSync"
"Param1"="\\EXTRAS\\DESKTOP\\NotePadSync\\NotePadSync.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000000
"State"=dword:0000000b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Cisco Systems\Clean Access Agent\CCAAgent.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-01-28 2:39:28 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-01-28 07:38:28
ComboFix2.txt 2009-01-24 09:18:00
Pre-Run: 93,931,364,352 bytes free
Post-Run: 94,008,369,152 bytes free
3953 --- E O F --- 2009-01-28 07:25:30
+ 2004-08-04 19:00:00 131,584 ----a-w c:\windows\system32\wbem\viewprov.dll
- 2008-04-14 00:12:08 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
+ 2004-08-04 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wbemcntl.dll
- 2008-04-14 00:12:08 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
+ 2004-08-04 19:00:00 214,528 ----a-w c:\windows\system32\wbem\wbemcomn.dll
- 2008-04-14 00:12:08 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
+ 2004-08-04 19:00:00 71,680 ----a-w c:\windows\system32\wbem\wbemcons.dll
- 2008-04-14 00:12:08 531,456 ----a-w c:\windows\system32\wbem\wbemcore.dll
+ 2004-08-04 19:00:00 530,944 ----a-w c:\windows\system32\wbem\wbemcore.dll
- 2008-04-14 00:12:08 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
+ 2004-08-04 19:00:00 178,176 ----a-w c:\windows\system32\wbem\wbemdisp.dll
- 2008-04-14 00:12:08 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
+ 2004-08-04 19:00:00 273,920 ----a-w c:\windows\system32\wbem\wbemess.dll
- 2008-04-14 00:12:08 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
+ 2004-08-04 19:00:00 43,008 ----a-w c:\windows\system32\wbem\wbemperf.dll
- 2008-04-14 00:12:08 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
+ 2004-08-04 19:00:00 18,944 ----a-w c:\windows\system32\wbem\wbemprox.dll
- 2008-04-14 00:12:08 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
+ 2004-08-04 19:00:00 43,520 ----a-w c:\windows\system32\wbem\wbemsvc.dll
- 2008-04-14 00:12:39 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
+ 2004-08-04 19:00:00 116,224 ----a-w c:\windows\system32\wbem\wbemtest.exe
- 2008-04-14 00:12:08 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
+ 2004-08-04 19:00:00 197,120 ----a-w c:\windows\system32\wbem\wbemupgd.dll
- 2008-04-14 00:12:40 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
+ 2004-08-04 19:00:00 196,608 ----a-w c:\windows\system32\wbem\wmiadap.exe
- 2008-04-13 17:10:20 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
+ 2004-08-04 19:00:00 6,656 ----a-w c:\windows\system32\wbem\wmiapres.dll
- 2008-04-14 00:12:09 88,576 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
+ 2004-08-04 19:00:00 89,088 ----a-w c:\windows\system32\wbem\wmiaprpl.dll
- 2008-04-14 00:12:40 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
+ 2004-08-04 19:00:00 126,464 ----a-w c:\windows\system32\wbem\wmiapsrv.exe
- 2008-04-14 00:12:09 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
+ 2004-08-04 19:00:00 60,928 ----a-w c:\windows\system32\wbem\wmicookr.dll
- 2008-04-14 00:12:09 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
+ 2004-08-04 19:00:00 140,800 ----a-w c:\windows\system32\wbem\wmidcprv.dll
- 2008-04-14 00:12:09 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
+ 2004-08-04 19:00:00 156,672 ----a-w c:\windows\system32\wbem\wmipcima.dll
- 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
+ 2004-08-04 19:00:00 132,096 ----a-w c:\windows\system32\wbem\wmipdskq.dll
- 2008-04-14 00:12:09 61,952 ----a-w c:\windows\system32\wbem\wmipiprt.dll
+ 2004-08-04 19:00:00 62,464 ----a-w c:\windows\system32\wbem\wmipiprt.dll
- 2008-04-14 00:12:09 62,464 ----a-w c:\windows\system32\wbem\wmipjobj.dll
+ 2004-08-04 19:00:00 62,976 ----a-w c:\windows\system32\wbem\wmipjobj.dll
- 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
+ 2004-08-04 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmiprov.dll
- 2008-04-14 00:12:09 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
+ 2004-08-04 19:00:00 437,248 ----a-w c:\windows\system32\wbem\wmiprvsd.dll
- 2008-04-14 00:12:40 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
+ 2004-08-04 19:00:00 218,112 ----a-w c:\windows\system32\wbem\wmiprvse.exe
- 2008-04-14 00:12:09 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
+ 2004-08-04 19:00:00 41,472 ----a-w c:\windows\system32\wbem\wmipsess.dll
- 2008-04-14 00:12:09 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
+ 2004-08-04 19:00:00 144,896 ----a-w c:\windows\system32\wbem\wmisvc.dll
- 2008-04-14 00:12:09 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
+ 2004-08-04 19:00:00 95,232 ----a-w c:\windows\system32\wbem\wmiutils.dll
- 2008-04-14 00:12:08 49,152 ----a-w c:\windows\system32\wdigest.dll
+ 2006-03-24 04:37:50 49,152 ----a-w c:\windows\system32\wdigest.dll
- 2008-04-14 00:12:45 23,552 ----a-w c:\windows\system32\wdmaud.drv
+ 2004-08-04 08:56:58 23,552 ----a-w c:\windows\system32\wdmaud.drv
- 2008-04-14 00:12:08 68,096 ----a-w c:\windows\system32\webclnt.dll
+ 2006-01-04 03:35:05 68,096 ----a-w c:\windows\system32\webclnt.dll
- 2008-04-14 00:12:08 135,680 ----a-w c:\windows\system32\webvw.dll
+ 2004-08-04 19:00:00 135,680 ----a-w c:\windows\system32\webvw.dll
- 2008-04-14 00:12:39 65,024 ----a-w c:\windows\system32\wextract.exe
+ 2004-08-04 19:00:00 65,536 ----a-w c:\windows\system32\wextract.exe
- 2008-04-14 00:12:39 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
+ 2004-08-04 19:00:00 433,664 ----a-w c:\windows\system32\wiaacmgr.exe
- 2008-04-14 00:12:08 463,360 ----a-w c:\windows\system32\wiadefui.dll
+ 2004-08-04 19:00:00 463,360 ----a-w c:\windows\system32\wiadefui.dll
- 2008-04-14 00:12:08 124,416 ----a-w c:\windows\system32\wiadss.dll
+ 2004-08-04 19:00:00 124,416 ----a-w c:\windows\system32\wiadss.dll
- 2008-04-14 00:12:08 75,776 ----a-w c:\windows\system32\wiascr.dll
+ 2004-08-04 19:00:00 75,776 ----a-w c:\windows\system32\wiascr.dll
- 2008-04-14 00:12:08 333,824 ----a-w c:\windows\system32\wiaservc.dll
+ 2006-12-19 18:16:47 333,824 ----a-w c:\windows\system32\wiaservc.dll
- 2008-04-14 00:12:08 589,312 ----a-w c:\windows\system32\wiashext.dll
+ 2004-08-04 19:00:00 589,312 ----a-w c:\windows\system32\wiashext.dll
- 2008-04-14 00:12:08 111,104 ----a-w c:\windows\system32\wiavideo.dll
+ 2004-08-04 19:00:00 111,104 ----a-w c:\windows\system32\wiavideo.dll
- 2008-09-15 12:12:56 1,846,400 ----a-w c:\windows\system32\win32k.sys
+ 2008-09-15 11:57:41 1,846,016 ----a-w c:\windows\system32\win32k.sys
- 2008-04-14 00:12:08 102,400 ----a-w c:\windows\system32\win32spl.dll
+ 2004-08-04 19:00:00 101,888 ----a-w c:\windows\system32\win32spl.dll
- 2008-04-13 16:48:53 1,647,616 ----a-w c:\windows\system32\winbrand.dll
+ 2004-08-04 19:00:00 937,984 ----a-w c:\windows\system32\winbrand.dll
- 2008-04-14 00:12:08 354,304 ----a-w c:\windows\system32\winhttp.dll
+ 2004-08-04 19:00:00 351,232 ----a-w c:\windows\system32\winhttp.dll
- 2008-04-14 00:12:09 32,256 ----a-w c:\windows\system32\winipsec.dll
+ 2004-08-04 19:00:00 32,768 ----a-w c:\windows\system32\winipsec.dll
- 2008-04-14 00:12:39 507,904 ----a-w c:\windows\system32\winlogon.exe
+ 2004-08-04 19:00:00 502,272 ----a-w c:\windows\system32\winlogon.exe
- 2008-04-14 00:12:09 176,128 ----a-w c:\windows\system32\winmm.dll
+ 2004-08-04 19:00:00 176,128 ----a-w c:\windows\system32\winmm.dll
- 2008-04-14 00:11:11 756,224 ----a-w c:\windows\system32\winntbbu.dll
+ 2004-08-04 19:00:00 764,928 ----a-w c:\windows\system32\winntbbu.dll
- 2008-04-14 00:12:09 16,896 ----a-w c:\windows\system32\winrnr.dll
+ 2004-08-04 19:00:00 16,896 ----a-w c:\windows\system32\winrnr.dll
- 2008-04-14 00:12:09 99,328 ----a-w c:\windows\system32\winscard.dll
+ 2004-08-04 19:00:00 99,328 ----a-w c:\windows\system32\winscard.dll
- 2008-04-14 00:12:09 17,408 ----a-w c:\windows\system32\winshfhc.dll
+ 2004-08-04 19:00:00 17,408 ----a-w c:\windows\system32\winshfhc.dll
- 2008-04-14 00:12:45 146,432 ----a-w c:\windows\system32\winspool.drv
+ 2004-08-04 19:00:00 146,432 ----a-w c:\windows\system32\winspool.drv
- 2008-04-14 00:12:09 293,376 ----a-w c:\windows\system32\winsrv.dll
+ 2007-03-17 13:43:01 292,864 ----a-w c:\windows\system32\winsrv.dll
- 2008-04-14 00:12:09 53,760 ----a-w c:\windows\system32\winsta.dll
+ 2004-08-04 19:00:00 53,760 ----a-w c:\windows\system32\winsta.dll
- 2008-04-14 00:12:09 176,640 ----a-w c:\windows\system32\wintrust.dll
+ 2004-08-04 19:00:00 176,640 ----a-w c:\windows\system32\wintrust.dll
- 2008-04-14 00:12:40 5,632 ----a-w c:\windows\system32\winver.exe
+ 2004-08-04 19:00:00 5,632 ----a-w c:\windows\system32\winver.exe
- 2008-04-14 00:12:09 132,096 ----a-w c:\windows\system32\wkssvc.dll
+ 2006-08-17 12:28:27 132,096 ----a-w c:\windows\system32\wkssvc.dll
- 2008-04-14 00:12:09 172,032 ----a-w c:\windows\system32\wldap32.dll
+ 2004-08-04 19:00:00 172,032 ----a-w c:\windows\system32\wldap32.dll
- 2008-04-14 00:12:09 92,672 ----a-w c:\windows\system32\wlnotify.dll
+ 2004-08-04 19:00:00 92,672 ----a-w c:\windows\system32\wlnotify.dll
- 2008-04-14 00:11:15 5,632 ----a-w c:\windows\system32\wmi.dll
+ 2004-08-04 19:00:00 5,632 ----a-w c:\windows\system32\wmi.dll
- 2008-04-14 00:12:09 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
+ 2004-08-04 19:00:00 115,200 ----a-w c:\windows\system32\wmsdmoe.dll
- 2008-04-14 00:12:10 303,616 ----a-w c:\windows\system32\wmstream.dll
+ 2004-08-04 19:00:00 303,616 ----a-w c:\windows\system32\wmstream.dll
- 2008-04-14 00:12:10 264,192 ----a-w c:\windows\system32\wow32.dll
+ 2004-08-04 19:00:00 264,192 ----a-w c:\windows\system32\wow32.dll
- 2008-04-14 00:12:40 32,256 ----a-w c:\windows\system32\wpabaln.exe
+ 2004-08-04 19:00:00 32,256 ----a-w c:\windows\system32\wpabaln.exe
- 2008-04-14 00:12:41 11,264 ----a-w c:\windows\system32\wpnpinst.exe
+ 2004-08-04 19:00:00 32,256 ----a-w c:\windows\system32\wpnpinst.exe
- 2008-04-14 00:12:10 82,432 ----a-w c:\windows\system32\ws2_32.dll
+ 2004-08-04 19:00:00 82,944 ----a-w c:\windows\system32\ws2_32.dll
- 2008-04-14 00:12:10 19,968 ----a-w c:\windows\system32\ws2help.dll
+ 2004-08-04 19:00:00 19,968 ----a-w c:\windows\system32\ws2help.dll
- 2008-04-14 00:12:41 13,824 ----a-w c:\windows\system32\wscntfy.exe
+ 2004-08-04 19:00:00 13,824 ----a-w c:\windows\system32\wscntfy.exe
- 2008-05-08 11:24:44 155,648 ----a-w c:\windows\system32\wscript.exe
+ 2004-08-04 19:00:00 114,688 ----a-w c:\windows\system32\wscript.exe
- 2008-04-14 00:12:10 80,896 ----a-w c:\windows\system32\wscsvc.dll
+ 2004-08-04 19:00:00 81,408 ----a-w c:\windows\system32\wscsvc.dll
- 2008-04-14 00:12:10 108,032 ----a-w c:\windows\system32\wshbth.dll
+ 2004-08-04 19:00:00 108,032 ----a-w c:\windows\system32\wshbth.dll
- 2008-04-14 00:12:10 36,864 ----a-w c:\windows\system32\wshcon.dll
+ 2004-08-04 19:00:00 28,672 ----a-w c:\windows\system32\wshcon.dll
- 2008-05-09 10:53:40 90,112 ----a-w c:\windows\system32\wshext.dll
+ 2004-08-04 19:00:00 65,536 ----a-w c:\windows\system32\wshext.dll
- 2008-04-14 00:12:10 14,336 ----a-w c:\windows\system32\wship6.dll
+ 2004-08-04 19:00:00 14,336 ----a-w c:\windows\system32\wship6.dll
- 2008-04-14 00:12:10 11,264 ----a-w c:\windows\system32\wshrm.dll
+ 2004-08-04 19:00:00 11,776 ----a-w c:\windows\system32\wshrm.dll
- 2008-04-14 00:12:10 19,456 ----a-w c:\windows\system32\wshtcpip.dll
+ 2004-08-04 19:00:00 19,968 ----a-w c:\windows\system32\wshtcpip.dll
- 2008-04-14 00:12:10 41,984 ----a-w c:\windows\system32\wsnmp32.dll
+ 2004-08-04 19:00:00 42,496 ----a-w c:\windows\system32\wsnmp32.dll
- 2008-04-14 00:12:10 22,528 ----a-w c:\windows\system32\wsock32.dll
+ 2004-08-04 19:00:00 22,528 ----a-w c:\windows\system32\wsock32.dll
- 2008-04-14 00:12:10 50,688 ----a-w c:\windows\system32\wstdecod.dll
+ 2004-08-04 19:00:00 50,688 ----a-w c:\windows\system32\wstdecod.dll
- 2008-04-14 00:12:10 18,432 ----a-w c:\windows\system32\wtsapi32.dll
+ 2004-08-04 19:00:00 18,432 ----a-w c:\windows\system32\wtsapi32.dll
- 2008-04-14 00:12:41 165,888 ----a-w c:\windows\system32\wuauclt1.exe
+ 2004-08-04 19:00:00 165,888 ----a-w c:\windows\system32\wuauclt1.exe
- 2008-04-14 00:12:11 183,296 ----a-w c:\windows\system32\wuaueng1.dll
+ 2004-08-04 19:00:00 183,296 ----a-w c:\windows\system32\wuaueng1.dll
- 2008-04-14 00:12:11 6,656 ----a-w c:\windows\system32\wuauserv.dll
+ 2004-08-04 19:00:00 6,656 ----a-w c:\windows\system32\wuauserv.dll
- 2008-04-14 00:12:11 383,488 ----a-w c:\windows\system32\wzcdlg.dll
+ 2004-08-04 19:00:00 378,368 ----a-w c:\windows\system32\wzcdlg.dll
- 2008-04-14 00:12:11 52,736 ----a-w c:\windows\system32\wzcsapi.dll
+ 2004-08-04 19:00:00 51,712 ----a-w c:\windows\system32\wzcsapi.dll
- 2008-04-14 00:12:11 483,840 ----a-w c:\windows\system32\wzcsvc.dll
+ 2004-08-04 19:00:00 359,936 ----a-w c:\windows\system32\wzcsvc.dll
- 2008-04-14 00:12:11 91,648 ----a-w c:\windows\system32\xactsrv.dll
+ 2004-08-04 19:00:00 91,648 ----a-w c:\windows\system32\xactsrv.dll
- 2008-04-14 00:12:41 30,720 ----a-w c:\windows\system32\xcopy.exe
+ 2004-08-04 19:00:00 30,720 ----a-w c:\windows\system32\xcopy.exe
- 2008-04-14 00:12:11 121,856 ----a-w c:\windows\system32\xmllite.dll
+ 2006-07-14 15:51:51 121,856 ----a-w c:\windows\system32\xmllite.dll
- 2008-04-14 00:12:11 129,024 ----a-w c:\windows\system32\xmlprov.dll
+ 2004-08-04 19:00:00 129,536 ----a-w c:\windows\system32\xmlprov.dll
- 2008-04-14 00:12:11 50,176 ----a-w c:\windows\system32\xmlprovi.dll
+ 2004-08-04 19:00:00 50,176 ----a-w c:\windows\system32\xmlprovi.dll
- 2008-04-14 00:12:11 11,776 ----a-w c:\windows\system32\xolehlp.dll
+ 2006-03-01 19:42:42 11,776 ----a-w c:\windows\system32\xolehlp.dll
- 2008-04-13 17:39:29 438,784 ----a-w c:\windows\system32\xpob2res.dll
+ 2004-08-04 19:00:00 438,784 ----a-w c:\windows\system32\xpob2res.dll
- 2008-04-13 17:39:22 187,392 ----a-w c:\windows\system32\xpsp1res.dll
+ 2004-08-04 19:00:00 187,392 ----a-w c:\windows\system32\xpsp1res.dll
- 2008-04-13 17:39:24 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
+ 2004-08-04 19:00:00 2,897,920 ----a-w c:\windows\system32\xpsp2res.dll
- 2008-04-13 17:39:26 689,152 ----a-w c:\windows\system32\xpsp3res.dll
+ 2007-10-29 10:04:03 350,720 ----a-w c:\windows\system32\xpsp3res.dll
- 2008-04-14 00:12:11 338,432 ----a-w c:\windows\system32\zipfldr.dll
+ 2004-08-04 19:00:00 337,920 ----a-w c:\windows\system32\zipfldr.dll
+ 2009-01-28 07:35:10 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_8d8.dat
- 2008-04-14 00:12:07 50,688 ----a-w c:\windows\twain_32.dll
+ 2004-08-04 19:00:00 50,688 ----a-w c:\windows\twain_32.dll
- 2008-04-14 00:12:39 283,648 ----a-w c:\windows\winhlp32.exe
+ 2004-08-04 19:00:00 283,648 ----a-w c:\windows\winhlp32.exe
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-11-23 68856]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-06-20 1207080]
"Aim6"="c:\program files\AIM6\aim6.exe" [2008-01-03 50528]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE" [2008-10-16 4347120]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"UserFaultCheck"="c:\windows\system32\dumprep 0 -u" [X]
"YSearchProtection"="c:\program files\Yahoo!\Search Protection\SearchProtection.exe" [2008-01-10 223984]
"CanonSolutionMenu"="c:\program files\Canon\SolutionMenu\CNSLMAIN.exe" [2007-10-25 652624]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2007-09-13 1603152]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-10-01 111936]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-11-20 290088]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-09-06 413696]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
MostFun.lnk - c:\program files\MostFun\Bin\MostFun.exe [2007-08-28 147456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2008-04-23 29696]
Clean Access Agent.lnk - c:\program files\Cisco Systems\Clean Access Agent\CCAAgentLauncher.exe [2007-12-07 28672]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^BigFix.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\BigFix.lnk
backup=c:\windows\pss\BigFix.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Clean Access Agent.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Clean Access Agent.lnk
backup=c:\windows\pss\Clean Access Agent.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Install Pending Files.LNK]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Install Pending Files.LNK
backup=c:\windows\pss\Install Pending Files.LNKCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MostFun.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MostFun.lnk
backup=c:\windows\pss\MostFun.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
c:\windows\system32\dumprep 0 -u [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Aim6]
--a------ 2008-01-03 11:15 50528 c:\program files\AIM6\aim6.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIPTA]
--a------ 2005-04-29 00:05 344064 c:\program files\ATI Technologies\ATI Control Panel\atiptaxx.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
--a------ 2006-11-21 17:38 52840 c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2004-08-04 14:00 15360 c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\H/PC Connection Agent]
--a------ 2006-06-20 22:36 1207080 c:\progra~1\MI3AA1~1\wcescomm.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
--a------ 2008-11-20 13:20 290088 c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lost Beachs screen saver]
--a------ 2002-02-06 17:09 370176 c:\program files\Lost Beachs\screen saver\TaskTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
--a------ 2004-10-13 11:24 1694208 c:\program files\Messenger\msmsgs.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 14:50 155648 c:\windows\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-06 15:09 413696 c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Recguard]
--a------ 2002-09-14 02:42 212992 c:\windows\SMINST\Recguard.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
--a------ 2004-11-02 23:24 32768 c:\program files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 01:11 132496 c:\program files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2007-11-23 01:38 68856 c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Symantec NetDriver Monitor]
--a------ 2008-02-19 12:01 104080 c:\progra~1\SYMNET~1\SNDMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
--a------ 2004-11-05 05:47 688218 c:\program files\Synaptics\SynTP\SynTPEnh.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPLpr]
--a------ 2004-11-05 05:47 98394 c:\program files\Synaptics\SynTP\SynTPLpr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
-ra------ 2006-03-30 15:45 313472 c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
--a------ 2007-03-14 19:49 125632 c:\progra~1\SYMANT~1\VPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
--a------ 2008-10-16 20:57 4347120 c:\program files\Yahoo!\Messenger\YahooMessenger.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AolCoach\\en_en\\player\\AOLNySEV.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
"c:\\Program Files\\MostFun\\Bin\\MostFun.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2008-09-03 99376]
R3 HSFHWATI;HSFHWATI;c:\windows\system32\drivers\HSFHWATI.sys [2004-12-15 200192]
R4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [2007-03-14 116416]
R4 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2008-01-27 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-01-24 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 11:34]
.
- - - - ORPHANS REMOVED - - - -
Notify-dimsntfy - (no file)
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com/
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
mStart Page = hxxp://www.yahoo.com/
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uInternet Connection Wizard,ShellNext = hxxp://www.gateway.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} - file:///C:/Program%20Files/Bejeweled%202/Images/stg_drm.ocx
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yl65l58j.default\
FF - prefs.js: browser.startup.homepage - hxxps://www.portal.radford.edu/MyRU.php
FF - plugin: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\yl65l58j.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-01-28 02:33:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\ActiveSync]
"Name"="ActiveSync"
"DisplayName"="Microsoft ActiveSync"
"Param1"="ActiveSync"
"Type"="wellknown"
"Order"=dword:00000000
"State"=dword:00000020
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\IESettings]
"Name"="IESettings"
"Type"="IESettings"
"Order"=dword:00000003
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\MediaFiles]
"Name"="MediaFiles"
"Type"="MediaFiles"
"Order"=dword:00000002
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\CriticalAppInstall\NPW]
"Name"="NPW"
"Param1"="NPW"
"Type"="wellknown"
"Order"=dword:00000001
"State"=dword:0000000b
[HKEY_USERS\S-1-5-21-2266918304-2087264726-3243295965-1003\Software\Microsoft\Windows Mobile Disc\S*a*m*s*u*n*g* *B*l*a*c*k*J*a*c*k*"!\DesktopAppInstall\oemDesktop4]
"Name"="oemDesktop4"
"DisplayName"="NotepadSync"
"Param1"="\\EXTRAS\\DESKTOP\\NotePadSync\\NotePadSync.exe"
"Param2"=""
"Type"="createprocess"
"Order"=dword:00000000
"State"=dword:0000000b
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\Ati2evxx.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\ati2evxx.exe
c:\program files\Common Files\Symantec Shared\ccSetMgr.exe
c:\program files\Common Files\Symantec Shared\ccEvtMgr.exe
c:\program files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Symantec\LiveUpdate\AluSchedulerSvc.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Symantec AntiVirus\DefWatch.exe
c:\program files\Canon\IJPLM\ijplmsvc.exe
c:\windows\system32\HPZipm12.exe
c:\program files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
c:\program files\Symantec AntiVirus\Rtvscan.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\ati2evxx.exe
c:\progra~1\MI3AA1~1\rapimgr.exe
c:\program files\Cisco Systems\Clean Access Agent\CCAAgent.exe
c:\program files\iPod\bin\iPodService.exe
c:\program files\AIM6\aolsoftware.exe
c:\progra~1\Yahoo!\MESSEN~1\Ymsgr_tray.exe
c:\windows\system32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2009-01-28 2:39:28 - machine was rebooted [Owner]
ComboFix-quarantined-files.txt 2009-01-28 07:38:28
ComboFix2.txt 2009-01-24 09:18:00
Pre-Run: 93,931,364,352 bytes free
Post-Run: 94,008,369,152 bytes free
3953 --- E O F --- 2009-01-28 07:25:30