--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0: scan report
Tuesday, April 6, 2010
Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Tuesday, April 06, 2010 08:52:57
Records in database: 3914280
--------------------------------------------------------------------------------
Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes
Scan area - My Computer:
C:\
E:\
F:\
Scan statistics:
Objects scanned: 92331
Threats found: 4
Infected objects found: 6
Suspicious objects found: 0
Scan duration: 01:38:03
File name / Threat / Threats count
C:\Qoobox\Quarantine\C\WINDOWS\sulbdr32.dll.vir Infected: Trojan-Downloader.Win32.Mufanom.naa 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP863\A0105900.exe Infected: Trojan-Spy.Win32.Zbot.aefy 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP866\A0106201.exe Infected: Packed.Win32.Krap.ae 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP869\A0106667.exe Infected: Packed.Win32.Krap.ae 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP872\A0107077.exe Infected: Trojan-Spy.Win32.Zbot.gen 1
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP893\A0109455.dll Infected: Trojan-Downloader.Win32.Mufanom.naa 1
Selected area has been scanned.
DDS (Ver_10-03-17.01) - NTFSx86
Run by JOHN CONNOLLY at 14:23:16.40 on Tue 04/06/2010
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_19
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1270.627 [GMT -4:00]
============== Running Processes ===============
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
svchost.exe
C:\Program Files\NavNT\defwatch.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\NavNT\rtvscan.exe
C:\PlusTech\WPPS\lpdServ.exe
C:\PlusTech\WPPS\lprServ.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
C:\Program Files\Common Files\Sage\ServiceHost\Sage.ServiceHost.Host.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\NavNT\vptray.exe
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\LogMeIn\x86\LMIGuardian.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\internet explorer\iexplore.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\PROGRA~1\ERIC'S~1\TELNET98.EXE
C:\Program Files\Microsoft Office\OFFICE11\EXCEL.EXE
C:\Program Files\internet explorer\iexplore.exe
C:\Documents and Settings\JOHN CONNOLLY\Desktop\dds.com
============== Pseudo HJT Report ===============
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: DriveLetterAccess: {5ca3d70e-1895-11cf-8e15-001234567890} - c:\windows\system32\dla\DLASHX_W.DLL
BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\bae\BAE.dll
BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
mRun: [igfxtray] c:\windows\system32\igfxtray.exe
mRun: [igfxhkcmd] c:\windows\system32\hkcmd.exe
mRun: [igfxpers] c:\windows\system32\igfxpers.exe
mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime
mRun: [vptray] c:\program files\navnt\vptray.exe
mRun: [Adobe Photo Downloader] "c:\program files\adobe\photoshop album starter edition\3.2\apps\apdproxy.exe"
mRun: [LogMeIn GUI] "c:\program files\logmein\x86\LogMeInSystray.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\quickb~1.lnk - c:\program files\common files\intuit\quickbooks\qbupdate\qbupdate.exe
IE: E&xport to Microsoft Excel - c:\progra~1\micros~4\office11\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~4\office11\REFIEBAR.DLL
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - {FE54FA40-D68C-11d2-98FA-00C0F0318AFE} - c:\windows\system32\Shdocvw.dll
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: acehardware-acenet.com
Trusted Zone: acehardware-aceonline.com
Trusted Zone: acehardware-eaglevision.com
Trusted Zone: acehardware-vendors.com
Trusted Zone: aceservices.com\*.imagemax
Trusted Zone: acehardware-acenet.com
Trusted Zone: acehardware-aceonline.com
Trusted Zone: acehardware-eaglevision.com
Trusted Zone: acehardware-vendors.com
Trusted Zone: aceservices.com
Trusted Zone: musicmatch.com\online
DPF: AceIESecuritySettings - hxxp://apps.acehardware-vendors.com/Controls/AceIESecuritySettings.CAB
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {3DC2E31C-371A-4BD3-9A27-CDF57CE604CF} - hxxp://moneycentral.msn.com/cabs/pmupd806.exe
DPF: {41F841C0-AE16-11D5-8817-0050DA6EF5E5} - hxxp://apps.acehardware-vendors.com/Acehardware-Vendors/Controls/Farpoint60/fpspr60.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {C903C000-9C6E-419D-A0AC-2E760BBA3764} - hxxp://apps.acehardware-vendors.com/acehardware-vendors/Controls/MCSi/McsiMenu.cab
DPF: {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_19-windows-i586.cab
DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} - hxxps://epicor.webex.com/client/T23L/support/ieatgpc.cab
TCP: {52DA9712-55A0-4028-8282-4971C2071872} = 4.2.2.2,192.168.10.46
Notify: igfxcui - igfxdev.dll
Notify: LMIinit - LMIinit.dll
Notify: NavLogon - c:\windows\system32\NavLogon.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll
================= FIREFOX ===================
FF - ProfilePath - c:\docume~1\johnco~1\applic~1\mozilla\firefox\profiles\pi2g4500.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}
---- FIREFOX POLICIES ----
c:\program files\mozilla firefox\greprefs\all.js - pref("backups.number_of_prefs_copies", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.link.open_newwindow.ui", 3); // prefs UI version
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.disable_window_open_feature.status", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("advanced.always_load_images", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.protocol-handler.external.help", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.connect.timeout", 30); // in seconds
c:\program files\mozilla firefox\greprefs\all.js - pref("network.http.request.timeout", 120); // in seconds
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN_show_punycode", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.image.imageBehavior", 0); // 0-Accept, 1-dontAcceptForeign, 2-dontUse
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.cookieBehavior", 3); // 0-Accept, 1-dontAcceptForeign, 2-dontUse, 3-p3p
c:\program files\mozilla firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
c:\program files\mozilla firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.id", "{ec8030f7-c20a-464f-9b0e-13a3a9e97384}");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.version",
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.extensions.version", "1.0");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.build_id",
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.update.autoUpdateEnabled", true); // Whether or not background app updates
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.update.url", "chrome://mozapps/locale/update/update.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.update.updatesAvailable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.update.lastUpdateDate", 0); // UTC offset when last App update was
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("app.update.performed", false); // Whether or not an update has been
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdateEnabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdate", false); // Automatically download and install
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.interval", 604800000); // Check for updates to Extensions and
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.lastUpdateDate", 0); // UTC offset when last Extension/Theme
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.severity.threshold", 5);// The number of pending Extension/Theme
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.update.count", 0); // The number of extension/theme/etc
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("update.interval", 3600000); // Check each of the above intervals
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("update.showSlidingNotification", true); // Windows-only slide-up taskbar
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("update.severity", 0);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("general.useragent.vendor", "Firefox");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("general.useragent.vendorSub",
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.update.resetHomepage", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.startup.homepage_override.1", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.turbo.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://browser/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://browser/content/searchconfig.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("update_notifications.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("update_notifications.provider.0.frequency", 7); // number of days
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.xul.error_pages.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("pfs.datasource.url", "chrome://mozapps/locale/plugins/plugins.properties");
============= SERVICES / DRIVERS ===============
R2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\logmein\x86\rainfo.sys [2007-8-3 12856]
R2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2008-3-5 46112]
R2 NAVAPEL;NAVAPEL;c:\program files\navnt\Navapel.sys [2001-9-24 9232]
R2 Norton AntiVirus Server;Norton AntiVirus Client;c:\program files\navnt\rtvscan.exe [2001-9-24 454656]
R2 PTLPDService;PTLPDService;c:\plustech\wpps\lpdServ.exe [2008-9-2 69632]
R2 PTLPRService;PTLPRService;c:\plustech\wpps\lprServ.exe [2008-9-2 61440]
R2 Sage.ServiceHost.Host;Sage Service Host;c:\program files\common files\sage\servicehost\Sage.ServiceHost.Host.exe [2007-5-30 86016]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;c:\program files\google\google desktop search\GoogleDesktop.exe [2010-1-14 30192]
S4 LMIRfsClientNP;LMIRfsClientNP; [x]
=============== Created Last 30 ================
2010-04-05 20:25:14 0 d-----w- C:\ComboFix
2010-04-05 20:20:10 73728 ----a-w- c:\windows\system32\javacpl.cpl
2010-04-05 20:12:08 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-04-05 15:27:54 0 d-sha-r- C:\cmdcons
2010-04-05 15:12:06 98816 ----a-w- c:\windows\sed.exe
2010-04-05 15:12:06 77312 ----a-w- c:\windows\MBR.exe
2010-04-05 15:12:06 261632 ----a-w- c:\windows\PEV.exe
2010-04-05 15:12:06 161792 ----a-w- c:\windows\SWREG.exe
2010-03-31 16:04:23 0 d-----w- c:\program files\Trend Micro
2010-03-10 08:43:31 3558912 ------w- c:\windows\system32\dllcache\moviemk.exe
==================== Find3M ====================
2010-02-25 15:54:36 11070976 ------w- c:\windows\system32\dllcache\ieframe.dll
2010-02-24 09:54:25 173056 ------w- c:\windows\system32\dllcache\ie4uinit.exe
2006-05-11 13:39:32 56 --sh--r- c:\windows\system32\AFCBF2ABD8.sys
2006-05-11 13:39:34 3350 --sha-w- c:\windows\system32\KGyGaAvL.sys
============= FINISH: 14:24:01.75 ===============
ComboFix 10-04-04.01 - JOHN CONNOLLY 04/05/2010 16:26:06.5.2 - x86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.1270.821 [GMT -4:00]
Running from: C:\Documents and Settings\JOHN CONNOLLY\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\JOHN CONNOLLY\Desktop\CFScript.txt
FILE ::
"c:\windows\Clegejelape.dat"
"c:\windows\Lwaha.bin"
.
((((((((((((((((((((((((( Files Created from 2010-03-05 to 2010-04-05 )))))))))))))))))))))))))))))))
.
2010-04-05 20:19:53 . 2010-04-05 20:19:53 -------- d-----w- C:\Program Files\Java
2010-04-05 20:12:19 . 2010-04-05 20:12:19 503808 ----a-w- C:\Documents and Settings\JOHN CONNOLLY\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7aca6cde-n\msvcp71.dll
2010-04-05 20:12:19 . 2010-04-05 20:12:19 499712 ----a-w- C:\Documents and Settings\JOHN CONNOLLY\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7aca6cde-n\jmc.dll
2010-04-05 20:12:19 . 2010-04-05 20:12:19 348160 ----a-w- C:\Documents and Settings\JOHN CONNOLLY\Application Data\Sun\Java\Deployment\SystemCache\6.0\54\1a209876-7aca6cde-n\msvcr71.dll
2010-04-05 20:12:15 . 2010-04-05 20:12:15 61440 ----a-w- C:\Documents and Settings\JOHN CONNOLLY\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-175fbc5a-n\decora-sse.dll
2010-04-05 20:12:15 . 2010-04-05 20:12:15 12800 ----a-w- C:\Documents and Settings\JOHN CONNOLLY\Application Data\Sun\Java\Deployment\SystemCache\6.0\17\6d0ad391-175fbc5a-n\decora-d3d.dll
2010-04-05 20:12:08 . 2010-04-05 20:19:57 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll
2010-04-05 19:55:18 . 2010-04-05 19:55:18 -------- d-----w- C:\Program Files\Common Files\Adobe AIR
2010-03-31 18:11:35 . 2010-03-31 18:11:46 -------- d-----w- C:\Program Files\ERUNT
2010-03-31 16:04:23 . 2010-03-31 16:04:23 -------- d-----w- C:\Program Files\Trend Micro
2010-03-10 08:43:31 . 2009-10-23 15:28:37 3558912 ------w- C:\WINDOWS\system32\dllcache\moviemk.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-04-05 20:20:24 . 2006-03-28 12:47:50 -------- d-----w- C:\Program Files\Common Files\Java
2010-04-05 19:53:29 . 2006-04-28 14:21:10 -------- d-----w- C:\Program Files\Common Files\Adobe
2010-03-26 16:02:42 . 2006-04-28 18:24:45 -------- d-----w- C:\Program Files\ViewChoice
2010-02-25 14:05:24 . 2008-08-20 15:23:29 -------- d-----w- C:\Program Files\Spybot - Search & Destroy
2010-02-25 14:00:12 . 2008-08-20 15:23:29 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2010-02-25 06:24:37 . 2004-08-10 17:51:29 916480 ------w- C:\WINDOWS\system32\wininet.dll
2010-01-20 14:08:44 . 2010-01-14 14:16:34 119808 ----a-w- C:\Program Files\mozilla firefox\components\GoogleDesktopMozilla.dll
2005-09-15 22:26:00 . 2006-04-27 16:38:30 41573 ----a-w- C:\Program Files\mozilla firefox\components\jar50.dll
2005-09-15 22:26:00 . 2006-04-27 16:38:31 48223 ----a-w- C:\Program Files\mozilla firefox\components\jsd3250.dll
2005-09-15 22:26:00 . 2006-04-27 16:38:30 160871 ----a-w- C:\Program Files\mozilla firefox\components\xpinstal.dll
2006-05-11 13:39:32 . 2006-05-08 19:17:57 56 --sh--r- C:\WINDOWS\system32\AFCBF2ABD8.sys
2006-05-11 13:39:34 . 2006-05-08 19:17:57 3350 --sha-w- C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((( SnapShot@2010-04-05_16.22.23 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-04-05 20:20:11 . 2010-04-05 20:20:11 16384 C:\WINDOWS\temp\Perflib_Perfdata_ca0.dat
+ 2010-04-05 19:55:31 . 2010-04-05 19:55:31 20480 C:\WINDOWS\Installer\1c0e62.msi
+ 2010-04-05 19:55:20 . 2010-04-05 19:55:20 26112 C:\WINDOWS\Installer\1c0e5d.msi
+ 2009-02-27 16:56:34 . 2009-02-27 16:56:34 16768 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\ViewerPS.dll
+ 2009-02-27 21:10:28 . 2009-02-27 21:10:28 35696 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\reader_sl.exe
+ 2009-02-27 16:08:04 . 2009-02-27 16:08:04 10752 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\piaglbreakfinder.dll
+ 2009-02-27 16:56:10 . 2009-02-27 16:56:10 79208 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\PDFPrevHndlr.dll
+ 2009-02-27 20:37:50 . 2009-02-27 20:37:50 99704 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\eula.exe
+ 2009-02-27 20:32:32 . 2009-02-27 20:32:32 26464 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\acrotextextractor.exe
+ 2009-02-27 16:18:50 . 2009-02-27 16:18:50 15216 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroRd32Info.exe
+ 2009-02-27 16:07:26 . 2009-02-27 16:07:26 75128 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\acroiehelpershim.dll
+ 2009-02-27 16:07:32 . 2009-02-27 16:07:32 61816 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroIEHelper.dll
+ 2006-12-02 02:54:32 . 2006-12-02 02:54:32 626688 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcr80.dll
+ 2006-12-02 02:54:34 . 2006-12-02 02:54:34 548864 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcp80.dll
+ 2006-12-02 02:54:32 . 2006-12-02 02:54:32 479232 C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.762_x-ww_6b128700\msvcm80.dll
+ 2010-04-05 20:20:10 . 2010-04-05 20:19:57 153376 C:\WINDOWS\system32\javaws.exe
+ 2010-04-05 20:20:10 . 2010-04-05 20:19:57 145184 C:\WINDOWS\system32\javaw.exe
+ 2010-04-05 20:20:10 . 2010-04-05 20:19:57 145184 C:\WINDOWS\system32\java.exe
+ 2010-04-05 20:20:24 . 2010-04-05 20:20:24 180224 C:\WINDOWS\Installer\361ef.msi
+ 2010-04-05 20:19:56 . 2010-04-05 20:19:56 577536 C:\WINDOWS\Installer\361ea.msi
+ 2009-02-27 16:16:46 . 2009-02-27 16:16:46 378200 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\pdfshell.dll
+ 2009-02-27 16:56:24 . 2009-02-27 16:56:24 116096 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\PDFPrevHndlrShim.exe
+ 2009-02-27 16:13:42 . 2009-02-27 16:13:42 103792 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\nppdf32.dll
+ 2009-01-18 20:05:44 . 2009-01-18 20:05:44 675840 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\JP2KLib.dll
+ 2009-02-27 16:54:04 . 2009-02-27 16:54:04 542096 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AdobeCollabSync.exe
+ 2009-02-27 16:35:10 . 2009-02-27 16:35:10 120168 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroRdIF.dll
+ 2009-02-27 21:10:32 . 2009-02-27 21:10:32 349544 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroRd32.exe
+ 2009-02-27 16:07:48 . 2009-02-27 16:07:48 660840 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroPDF.dll
+ 2009-02-27 16:50:58 . 2009-02-27 16:50:58 279952 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\acrobroker.exe
+ 2009-02-27 16:50:28 . 2009-02-27 16:50:28 251224 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\a3dutility.exe
+ 2009-02-27 16:08:44 . 2009-02-27 16:08:44 2409808 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\rt3d.dll
+ 2007-12-11 11:19:40 . 2007-12-11 11:19:40 1204224 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\Onix32.dll
+ 2009-02-27 16:39:26 . 2009-02-27 16:39:26 1302760 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\JSByteCodeWin.bin
+ 2008-12-18 20:48:34 . 2008-12-18 20:48:34 3645440 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\authplay.dll
+ 2009-02-27 20:36:06 . 2009-02-27 20:36:06 5712384 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AGM.dll
+ 2010-01-04 21:44:28 . 2010-01-04 21:44:28 27012608 C:\WINDOWS\Installer\1c0e58.msp
+ 2010-04-05 19:54:52 . 2010-04-05 19:54:52 21352448 C:\WINDOWS\Installer\1c0e57.msi
+ 2009-02-27 20:37:44 . 2009-02-27 20:37:44 20403568 C:\WINDOWS\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB7449A0100000010\9.1.0\AcroRd32.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="C:\WINDOWS\system32\igfxtray.exe" [2005-10-15 01:49:46 94208]
"igfxhkcmd"="C:\WINDOWS\system32\hkcmd.exe" [2005-10-15 01:46:34 77824]
"igfxpers"="C:\WINDOWS\system32\igfxpers.exe" [2005-10-15 01:50:30 114688]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-03-28 12:54:57 98304]
"vptray"="C:\Program Files\NavNT\vptray.exe" [2001-09-24 11:59:00 73728]
"Adobe Photo Downloader"="C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 15:09:58 63712]
"LogMeIn GUI"="C:\Program Files\LogMeIn\x86\LogMeInSystray.exe" [2007-08-03 20:09:34 63048]
"Adobe ARM"="C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 19:57:56 948672]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 09:57:28 35760]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 15:43:18 248040]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
QuickBooks Update Agent.lnk - C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe [2009-9-16 972064]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-11-15 23:46:22 87352 ----a-w- C:\WINDOWS\system32\LMIinit.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^America Online 9.0 Tray Icon.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\America Online 9.0 Tray Icon.lnk
backup=C:\WINDOWS\pss\America Online 9.0 Tray Icon.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\QuickBooks Update Agent.lnk
backup=C:\WINDOWS\pss\QuickBooks Update Agent.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
2005-09-08 10:20:00 122940 ----a-w- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DMXLauncher]
2005-10-05 08:12:00 94208 ----a-w- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Google Desktop Search]
2010-01-19 15:13:53 30192 ----a-w- C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2005-06-10 15:44:02 249856 ----a-w- C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2005-06-10 15:44:02 81920 ----a-w- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MimBoot]
2005-09-09 00:20:46 8192 ----a-w- C:\PROGRA~1\MUSICM~1\MUSICM~3\mimboot.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MMTray]
2005-09-09 00:20:46 110592 ----a-w- C:\PROGRA~1\MUSICM~1\MUSICM~3\mm_tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSKDetectorExe]
2005-08-12 20:16:44 1121792 ----a-w- C:\Program Files\McAfee\SpamKiller\MSKDetct.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QBReminderFlash]
2004-11-11 15:26:36 26112 ----a-w- C:\Program Files\Intuit\QuickBooks 2005\Atom\QBReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RealTray]
2006-03-28 12:54:42 26112 ----a-w- C:\Program Files\Real\RealPlayer\realplay.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ose"=3 (0x3)
"AOL ACS"=2 (0x2)
"WMPNetworkSvc"=3 (0x3)
"gusvc"=2 (0x2)
"GoogleDesktopManager"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Eric's Telnet98\\TELNET98.EXE"=
"C:\\Program Files\\Intuit\\QuickBooks 2007\\QBDBMgrN.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\WINDOWS\\system32\\dxdiag.exe"=
"C:\\WINDOWS\\system32\\dpnsvr.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP

xpsp2res.dll,-22009
R2 LMIInfo;LogMeIn Kernel Information Provider;C:\Program Files\LogMeIn\x86\rainfo.sys [8/3/2007 4:09:34 PM 12856]
R2 PTLPDService;PTLPDService;C:\PlusTech\WPPS\lpdServ.exe [9/2/2008 2:51:53 PM 69632]
R2 PTLPRService;PTLPRService;C:\PlusTech\WPPS\lprServ.exe [9/2/2008 2:51:53 PM 61440]
R2 Sage.ServiceHost.Host;Sage Service Host;C:\Program Files\Common Files\Sage\ServiceHost\Sage.ServiceHost.Host.exe [5/30/2007 1:55:48 PM 86016]
S3 GoogleDesktopManager-110309-193829;Google Desktop Manager 5.9.911.3589;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [1/14/2010 10:16:22 AM 30192]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - JAVAQUICKSTARTERSERVICE
.
.
------- Supplementary Scan -------
.
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
Trusted Zone: acehardware-acenet.com
Trusted Zone: acehardware-aceonline.com
Trusted Zone: acehardware-eaglevision.com
Trusted Zone: acehardware-vendors.com
Trusted Zone: aceservices.com\*.imagemax
Trusted Zone: acehardware-acenet.com
Trusted Zone: acehardware-aceonline.com
Trusted Zone: acehardware-eaglevision.com
Trusted Zone: acehardware-vendors.com
Trusted Zone: aceservices.com
Trusted Zone: musicmatch.com\online
TCP: {52DA9712-55A0-4028-8282-4971C2071872} = 4.2.2.2,192.168.10.46
DPF: AceIESecuritySettings - hxxp://apps.acehardware-vendors.com/Controls/AceIESecuritySettings.CAB
DPF: {41F841C0-AE16-11D5-8817-0050DA6EF5E5} - hxxp://apps.acehardware-vendors.com/Acehardware-Vendors/Controls/Farpoint60/fpspr60.cab
DPF: {C903C000-9C6E-419D-A0AC-2E760BBA3764} - hxxp://apps.acehardware-vendors.com/acehardware-vendors/Controls/MCSi/McsiMenu.cab
FF - ProfilePath - C:\Documents and Settings\JOHN CONNOLLY\Application Data\Mozilla\Firefox\Profiles\pi2g4500.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - component: C:\Program Files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("backups.number_of_prefs_copies", 1);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("browser.link.open_newwindow.ui", 3); // prefs UI version
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.closed", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.document", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.frames", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.history", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.length", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.opener", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.parent", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.self", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.top", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("capability.policy.default.Window.window", "allAccess");
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("dom.disable_window_open_feature.status", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("advanced.always_load_images", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.protocol-handler.external.help", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.http.connect.timeout", 30); // in seconds
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.http.request.timeout", 120); // in seconds
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.IDN_show_punycode", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.image.imageBehavior", 0); // 0-Accept, 1-dontAcceptForeign, 2-dontUse
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.cookieBehavior", 3); // 0-Accept, 1-dontAcceptForeign, 2-dontUse, 3-p3p
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.cookie.p3plevel", 1); // 0=low, 1=medium, 2=high, 3=custom
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.enablePad", false); // Allow client to do proxy autodiscovery
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.id", "{ec8030f7-c20a-464f-9b0e-13a3a9e97384}");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.version",
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.extensions.version", "1.0");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.build_id",
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.autoUpdateEnabled", true); // Whether or not background app updates
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.url", "chrome://mozapps/locale/update/update.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.updatesAvailable", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.lastUpdateDate", 0); // UTC offset when last App update was
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("app.update.performed", false); // Whether or not an update has been
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdateEnabled", true);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.autoUpdate", false); // Automatically download and install
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.interval", 604800000); // Check for updates to Extensions and
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.lastUpdateDate", 0); // UTC offset when last Extension/Theme
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.severity.threshold", 5);// The number of pending Extension/Theme
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.update.count", 0); // The number of extension/theme/etc
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.interval", 3600000); // Check each of the above intervals
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.showSlidingNotification", true); // Windows-only slide-up taskbar
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("update.severity", 0);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("general.useragent.vendor", "Firefox");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("general.useragent.vendorSub",
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.update.resetHomepage", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.startup.homepage_override.1", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.turbo.enabled", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.default", "chrome://browser/content/searchconfig.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.search.param.Google.1.custom", "chrome://browser/content/searchconfig.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("update_notifications.enabled", true);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("update_notifications.provider.0.frequency", 7); // number of days
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.xul.error_pages.enabled", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("pfs.datasource.url", "chrome://mozapps/locale/plugins/plugins.properties");
.
- - - - ORPHANS REMOVED - - - -
MSConfigStartUp-SunJavaUpdateSched - C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe