c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Messaging.dll
+ 2004-07-15 19:31 . 2004-07-15 19:31 372736 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Management.dll
+ 2004-07-15 19:28 . 2004-07-15 19:28 241664 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.EnterpriseServices.dll
+ 2004-07-15 19:28 . 2004-07-15 19:28 466944 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Drawing.dll
+ 2004-07-15 19:31 . 2004-07-15 19:31 303104 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.OracleClient.dll
+ 2004-07-15 05:35 . 2004-07-15 05:35 319488 c:\windows\Microsoft.NET\Framework\v1.1.4322\SOS.dll
+ 2003-02-21 00:09 . 2003-02-21 00:09 122880 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusres.dll
+ 2003-02-21 00:09 . 2003-02-21 00:09 253952 c:\windows\Microsoft.NET\Framework\v1.1.4322\shfusion.dll
+ 2004-08-10 21:20 . 2004-08-10 21:20 106496 c:\windows\Microsoft.NET\Framework\v1.1.4322\netfxupdate.exe
+ 2003-02-21 09:42 . 2003-02-21 09:42 348160 c:\windows\Microsoft.NET\Framework\v1.1.4322\msvcr71.dll
+ 2004-07-15 05:33 . 2004-07-15 05:33 143360 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorrc.dll
+ 2003-02-20 23:43 . 2003-02-20 23:43 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscormmc.dll
+ 2004-07-15 05:33 . 2004-07-15 05:33 102400 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorld.dll
+ 2004-07-15 05:25 . 2004-07-15 05:25 315392 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorjit.dll
+ 2004-07-15 05:32 . 2004-07-15 05:32 233472 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscordbi.dll
+ 2004-07-15 19:28 . 2004-07-15 19:28 299008 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.VisualBasic.dll
+ 2004-07-15 19:28 . 2004-07-15 19:28 720896 c:\windows\Microsoft.NET\Framework\v1.1.4322\Microsoft.JScript.dll
+ 2004-07-15 05:35 . 2004-07-15 05:35 196608 c:\windows\Microsoft.NET\Framework\v1.1.4322\ilasm.exe
+ 2004-07-15 05:24 . 2004-07-15 05:24 282624 c:\windows\Microsoft.NET\Framework\v1.1.4322\fusion.dll
+ 2003-02-21 00:16 . 2003-02-21 00:16 798720 c:\windows\Microsoft.NET\Framework\v1.1.4322\EventLogMessages.dll
+ 2003-02-21 15:21 . 2003-02-21 15:21 524288 c:\windows\Microsoft.NET\Framework\v1.1.4322\diasymreader.dll
+ 2004-07-15 16:23 . 2004-07-15 16:23 626688 c:\windows\Microsoft.NET\Framework\v1.1.4322\cscomp.dll
+ 2002-07-29 16:11 . 2002-07-29 16:11 219136 c:\windows\Microsoft.NET\Framework\v1.1.4322\c_g18030.dll
+ 2004-07-15 06:49 . 2004-07-15 06:49 258048 c:\windows\Microsoft.NET\Framework\v1.1.4322\aspnet_isapi.dll
+ 2003-02-21 10:04 . 2003-02-21 10:04 155648 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\Vsavb7rtUI.dll
+ 2003-02-21 08:02 . 2003-02-21 08:02 131072 c:\windows\Microsoft.NET\Framework\v1.1.4322\1033\vbc7ui.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 155648 c:\windows\assembly\NativeImages1_v1.1.4322\VJSharpCodeProvider\7.0.5000.0_ _b03f5f7f11d50a3a_7d65f3fa\VJSharpCodeProvider.dll
+ 2009-10-16 22:22 . 2009-10-16 22:22 835584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f 5f7f11d50a3a_1fb499de\System.Drawing.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 192512 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing.Design\1.0.5000. 0__b03f5f7f11d50a3a_1a142122\System.Drawing.Design.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 118784 c:\windows\assembly\NativeImages1_v1.1.4322\CustomMarshalers\1.0.5000.0__b0 3f5f7f11d50a3a_b88f7ad3\CustomMarshalers.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 573440 c:\windows\assembly\GAC\System.Web.Services\1.0.5000.0__b03f5f7f11d50a3a\Sy stem.Web.Services.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 819200 c:\windows\assembly\GAC\System.Web.Mobile\1.0.5000.0__b03f5f7f11d50a3a\Syst em.Web.Mobile.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 126976 c:\windows\assembly\GAC\System.ServiceProcess\1.0.5000.0__b03f5f7f11d50a3a\ System.ServiceProcess.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 131072 c:\windows\assembly\GAC\System.Runtime.Serialization.Formatters.Soap\1.0.50 00.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 323584 c:\windows\assembly\GAC\System.Runtime.Remoting\1.0.5000.0__b77a5c561934e08 9\System.Runtime.Remoting.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 241664 c:\windows\assembly\GAC\System.Messaging\1.0.5000.0__b03f5f7f11d50a3a\Syste m.Messaging.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 372736 c:\windows\assembly\GAC\System.Management\1.0.5000.0__b03f5f7f11d50a3a\Syst em.Management.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 241664 c:\windows\assembly\GAC\System.EnterpriseServices\1.0.5000.0__b03f5f7f11d50 a3a\System.EnterpriseServices.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 466944 c:\windows\assembly\GAC\System.Drawing\1.0.5000.0__b03f5f7f11d50a3a\System. Drawing.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 303104 c:\windows\assembly\GAC\System.Data.OracleClient\1.0.5000.0__b77a5c561934e0 89\System.Data.OracleClient.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 299008 c:\windows\assembly\GAC\Microsoft.VisualBasic\7.0.5000.0__b03f5f7f11d50a3a\ Microsoft.VisualBasic.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 720896 c:\windows\assembly\GAC\Microsoft.JScript\7.0.5000.0__b03f5f7f11d50a3a\Micr osoft.JScript.dll
- 2003-03-19 12:12 . 2006-08-29 21:11 1047552 c:\windows\system32\MFC71u.dll
+ 2003-03-19 02:12 . 2003-03-19 02:12 1047552 c:\windows\system32\mfc71u.dll
- 2003-03-19 12:20 . 2003-03-19 18:19 1060864 c:\windows\system32\MFC71.DLL
+ 2003-03-19 02:20 . 2003-03-19 02:20 1060864 c:\windows\system32\mfc71.dll
+ 2004-07-15 13:15 . 2004-07-15 13:15 1032192 c:\windows\Microsoft.NET\Framework\v1.1.4322\VsaVb7rt.dll
+ 2004-07-15 19:29 . 2004-07-15 19:29 1339392 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.XML.dll
+ 2004-07-15 19:32 . 2004-07-15 19:32 2052096 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Windows.Forms.dll
+ 2004-07-15 19:29 . 2004-07-15 19:29 1257472 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Web.dll
+ 2004-07-15 19:31 . 2004-07-15 19:31 1224704 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.dll
+ 2004-07-15 19:29 . 2004-07-15 19:29 1703936 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Design.dll
+ 2004-07-15 19:32 . 2004-07-15 19:32 1294336 c:\windows\Microsoft.NET\Framework\v1.1.4322\System.Data.dll
+ 2004-07-15 05:28 . 2004-07-15 05:28 2502656 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorwks.dll
+ 2004-07-15 05:26 . 2004-07-15 05:26 2510848 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorsvr.dll
+ 2004-07-15 19:29 . 2004-07-15 19:29 2138112 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorlib.dll
+ 2003-02-21 12:25 . 2003-02-21 12:25 1564672 c:\windows\Microsoft.NET\Framework\v1.1.4322\mscorcfg.dll
+ 2009-10-15 23:53 . 2009-10-15 23:53 3449344 c:\windows\Installer\246c7f.msi
+ 2009-10-16 22:23 . 2009-10-16 22:23 4460544 c:\windows\assembly\NativeImages1_v1.1.4322\vjslib\1.0.5000.0__b03f5f7f11d5 0a3a_74812f89\vjslib.dll
+ 2009-10-16 22:21 . 2009-10-16 22:21 1953792 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934 e089_dad918fc\System.dll
+ 2009-10-16 22:23 . 2009-10-16 22:23 4763648 c:\windows\assembly\NativeImages1_v1.1.4322\System\1.0.5000.0__b77a5c561934 e089_6fb4f161\System.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 5505024 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c56 1934e089_d3233fa6\System.Xml.dll
+ 2009-10-16 22:22 . 2009-10-16 22:22 2088960 c:\windows\assembly\NativeImages1_v1.1.4322\System.Xml\1.0.5000.0__b77a5c56 1934e089_31e12a38\System.Xml.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 7880704 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0 __b77a5c561934e089_ef42400b\System.Windows.Forms.dll
+ 2009-10-16 22:22 . 2009-10-16 22:22 3014656 c:\windows\assembly\NativeImages1_v1.1.4322\System.Windows.Forms\1.0.5000.0 __b77a5c561934e089_7013f721\System.Windows.Forms.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 2244608 c:\windows\assembly\NativeImages1_v1.1.4322\System.Drawing\1.0.5000.0__b03f 5f7f11d50a3a_9406dcc5\System.Drawing.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 3395584 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5 f7f11d50a3a_db0c0a67\System.Design.dll
+ 2009-10-16 22:22 . 2009-10-16 22:22 1466368 c:\windows\assembly\NativeImages1_v1.1.4322\System.Design\1.0.5000.0__b03f5 f7f11d50a3a_b93892d8\System.Design.dll
+ 2009-10-16 22:22 . 2009-10-16 22:22 3379200 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c5619 34e089_e7763660\mscorlib.dll
+ 2009-10-16 22:24 . 2009-10-16 22:24 8880128 c:\windows\assembly\NativeImages1_v1.1.4322\mscorlib\1.0.5000.0__b77a5c5619 34e089_48352167\mscorlib.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 1224704 c:\windows\assembly\GAC\System\1.0.5000.0__b77a5c561934e089\System.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 1339392 c:\windows\assembly\GAC\System.Xml\1.0.5000.0__b77a5c561934e089\System.XML. dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 2052096 c:\windows\assembly\GAC\System.Windows.Forms\1.0.5000.0__b77a5c561934e089\S ystem.Windows.Forms.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 1257472 c:\windows\assembly\GAC\System.Web\1.0.5000.0__b03f5f7f11d50a3a\System.Web. dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 1703936 c:\windows\assembly\GAC\System.Design\1.0.5000.0__b03f5f7f11d50a3a\System.D esign.dll
+ 2009-10-16 22:20 . 2009-10-16 22:20 1294336 c:\windows\assembly\GAC\System.Data\1.0.5000.0__b77a5c561934e089\System.Dat a.dll
+ 2009-10-15 23:52 . 2009-10-15 23:52 1564672 c:\windows\assembly\GAC\mscorcfg\1.0.5000.0__b03f5f7f11d50a3a\mscorcfg.dll
+ 2009-10-16 22:18 . 2009-10-16 22:18 19210240 c:\windows\Installer\279de8a.msp
+ 2009-10-16 22:25 . 2009-10-16 22:25 12156928 c:\windows\assembly\NativeImages1_v1.1.4322\vjslib\1.0.5000.0__b03f5f7f11d5 0a3a_7f1ca069\vjslib.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"SkinClock"="c:\program files\Atomic Alarm Clock\AtomicAlarmClock.exe" [2009-04-27 1742848]
"ares"="c:\program files\Ares\Ares.exe" [2009-02-03 1004544]
"H/PC Connection Agent"="c:\program files\Microsoft ActiveSync\wcescomm.exe" [2006-11-13 1289000]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-09-05 417792]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-09-09 305440]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2008-10-17 51048]
c:\documents and settings\Administrator.HOME\Start Menu\Programs\Startup\
AutoTBar.exe [2003-9-30 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LBTWlgn]
2008-05-02 08:42 72208 ----a-w- c:\program files\Common Files\Logitech\Bluetooth\LBTWLgn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2003-02-21 01:50 40960 ----a-w- c:\program files\Softex\OmniPass\OPXPGina.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoa dGroup]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=c:\windows\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Google Updater.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Google Updater.lnk
backup=c:\windows\pss\Google Updater.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=c:\windows\pss\Logitech SetPoint.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^BitTorrent.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\BitTorrent.lnk
backup=c:\windows\pss\BitTorrent.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^eFax 4.4.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\eFax 4.4.lnk
backup=c:\windows\pss\eFax 4.4.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Gmote Server.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Gmote Server.lnk
backup=c:\windows\pss\Gmote Server.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^MLB.TV NexDef Plug-in.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\MLB.TV NexDef Plug-in.lnk
backup=c:\windows\pss\MLB.TV NexDef Plug-in.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Owner^Start Menu^Programs^Startup^Stardock ObjectDock.lnk]
path=c:\documents and settings\Owner\Start Menu\Programs\Startup\Stardock ObjectDock.lnk
backup=c:\windows\pss\Stardock ObjectDock.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"STOPzilla Local Service"=2 (0x2)
"avg8wd"=2 (0x2)
"StyleXPService"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Auth orizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\kdx\\khost.exe"=
"c:\program files\Microsoft ActiveSync\rapimgr.exe"= c:\program files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager
"c:\program files\Microsoft ActiveSync\wcescomm.exe"= c:\program files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager
"c:\\Program Files\\AOL 9.1\\waol.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\program files\Microsoft ActiveSync\WCESMgr.exe"= c:\program files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Ares\\Ares.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Java\\jre1.6.0_07\\bin\\javaw.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\Glob allyOpenPorts\List]
"26675:TCP"= 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"9420:TCP"= 9420:TCP:*Disabled:Akamai NetSession Interface
"5000:UDP"= 5000:UDP:*Disabled:Akamai NetSession Interface
"3139:TCP"= 3139:TCP:*Disabled:Akamai NetSession Interface
"2755:TCP"= 2755:TCP:*Disabled:Akamai NetSession Interface
"2860:TCP"= 2860:TCP:*Disabled:Akamai NetSession Interface
"2892:TCP"= 2892:TCP:*Disabled:Akamai NetSession Interface
"2928:TCP"= 2928:TCP:*Disabled:Akamai NetSession Interface
"1576:TCP"= 1576:TCP:*Disabled:Akamai NetSession Interface
"1634:TCP"= 1634:TCP:*Disabled:Akamai NetSession Interface
"1649:TCP"= 1649:TCP:*Disabled:Akamai NetSession Interface
"1774:TCP"= 1774:TCP:*Disabled:Akamai NetSession Interface
"3327:TCP"= 3327:TCP:*Disabled:Akamai NetSession Interface
"3397:TCP"= 3397:TCP:*Disabled:Akamai NetSession Interface
"1218:TCP"= 1218:TCP:*Disabled:Akamai NetSession Interface
"4705:TCP"= 4705:TCP:*Disabled:Akamai NetSession Interface
"4945:TCP"= 4945:TCP:*Disabled:Akamai NetSession Interface
"3657:TCP"= 3657:TCP:*Disabled:Akamai NetSession Interface
"3696:TCP"= 3696:TCP:*Disabled:Akamai NetSession Interface
"1069:TCP"= 1069:TCP:*Disabled:Akamai NetSession Interface
"3451:TCP"= 3451:TCP:*Disabled:Akamai NetSession Interface
"2332:TCP"= 2332:TCP:*Disabled:Akamai NetSession Interface
"4668:TCP"= 4668:TCP:*Disabled:Akamai NetSession Interface
"4716:TCP"= 4716:TCP:*Disabled:Akamai NetSession Interface
"1208:TCP"= 1208:TCP:*Disabled:Akamai NetSession Interface
"2531:TCP"= 2531:TCP:*Disabled:Akamai NetSession Interface
"2593:TCP"= 2593:TCP:*Disabled:Akamai NetSession Interface
"4549:TCP"= 4549:TCP:*Disabled:Akamai NetSession Interface
"4036:TCP"= 4036:TCP:*Disabled:Akamai NetSession Interface
"4512:TCP"= 4512:TCP:*Disabled:Akamai NetSession Interface
"3993:TCP"= 3993:TCP:*Disabled:Akamai NetSession Interface
"4012:TCP"= 4012:TCP:*Disabled:Akamai NetSession Interface
"4125:TCP"= 4125:TCP:*Disabled:Akamai NetSession Interface
"2441:TCP"= 2441:TCP:*Disabled:Akamai NetSession Interface
"1180:TCP"= 1180:TCP:*Disabled:Akamai NetSession Interface
"3717:TCP"= 3717:TCP:*Disabled:Akamai NetSession Interface
"1721:TCP"= 1721:TCP:*Disabled:Akamai NetSession Interface
"3260:TCP"= 3260:TCP:*Disabled:Akamai NetSession Interface
"4435:TCP"= 4435:TCP:*Disabled:Akamai NetSession Interface
"4759:TCP"= 4759:TCP:*Disabled:Akamai NetSession Interface
"1252:TCP"= 1252:TCP:*Disabled:Akamai NetSession Interface
"2274:TCP"= 2274:TCP:*Disabled:Akamai NetSession Interface
"3636:TCP"= 3636:TCP:*Disabled:Akamai NetSession Interface
"2616:TCP"= 2616:TCP:*Disabled:Akamai NetSession Interface
"2829:TCP"= 2829:TCP:*Disabled:Akamai NetSession Interface
"2098:TCP"= 2098:TCP:*Disabled:Akamai NetSession Interface
"3553:TCP"= 3553:TCP:*Disabled:Akamai NetSession Interface
"3801:TCP"= 3801:TCP:*Disabled:Akamai NetSession Interface
"4767:TCP"= 4767:TCP:*Disabled:Akamai NetSession Interface
"4782:TCP"= 4782:TCP:*Disabled:Akamai NetSession Interface
"4821:TCP"= 4821:TCP:*Disabled:Akamai NetSession Interface
"1348:TCP"= 1348:TCP:*Disabled:Akamai NetSession Interface
"3309:TCP"= 3309:TCP:*Disabled:Akamai NetSession Interface
"4523:TCP"= 4523:TCP:*Disabled:Akamai NetSession Interface
"3648:TCP"= 3648:TCP:*Disabled:Akamai NetSession Interface
"4634:TCP"= 4634:TCP:*Disabled:Akamai NetSession Interface
S3 COH_Mon;COH_Mon;c:\windows\system32\drivers\COH_Mon.sys [1/12/2008 9:32 PM 23888]
S3 P1370Aud;Creative WebCam Audio Control;c:\windows\system32\drivers\P1370Aud.sys [2/15/2009 12:51 AM 93056]
S3 P1370Aul;PD1370 Lower Filter Driver;c:\windows\system32\drivers\P1370Aul.sys [2/15/2009 12:51 AM 4992]
S3 P1370Vfx;P1370Vfx;c:\windows\system32\drivers\P1370Vfx.sys [2/15/2009 12:51 AM 6272]
S3 P1370VID;Live! Cam Voice;c:\windows\system32\drivers\P1370Vid.sys [2/15/2009 12:51 AM 297792]
S3 SCR3xx USB Smart Card Reader;SCR3xx USB Smart Card Reader;c:\windows\system32\drivers\SCR3XX2K.sys [6/2/2008 12:02 PM 47488]
S3 usbvm328;HP Camera;c:\windows\system32\drivers\usbvm326.sys [8/31/2007 9:00 PM 219648]
S3 vmfilter323;VC0326 filter service for Serome;c:\windows\system32\drivers\vmfilter323.sys [8/31/2007 9:15 PM 475264]
S4 Nuliecnt;Nuliecnt; [x]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - COMHOST
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
Akamai REG_MULTI_SZ Akamai
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{A509B1FF-37FF-4bFF-8CFF-4F3A747040FF}]
c:\windows\system32\rundll32.exe c:\windows\system32\advpack.dll,LaunchINFSectionEx c:\program files\Internet Explorer\clrtour.inf,DefaultInstall.ResetTour,,12
.
Contents of the 'Scheduled Tasks' folder
2009-10-10 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 17:34]
2008-12-27 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\program files\Microsoft IntelliType Pro\itype.exe [2008-06-10 19:56]
2009-10-14 c:\windows\Tasks\Norton Security Scan for Owner.job
- c:\program files\Norton Security Scan\Nss.exe [2008-09-19 10:18]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.yahoo.com
uDefault_Search_URL = hxxp://srch-us10.hpwis.com/
mStart Page = hxxp://www.yahoo.com
mSearch Bar = hxxp://www.yahoo.com/search/ie.html
uInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride = *.local
IE: &AIM Search - c:\program files\AIM Toolbar\AIMBar.dll/aimsearch.htm
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: turbotax.com
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
DPF: RaptisoftGameLoader - hxxp://www.miniclip.com/hamsterball/raptisoftgameloader.cab
FF - ProfilePath - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\e4wuvfee.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1641676&SearchSource=3&q=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - prefs.js: keyword.URL - hxxp://search.conduit.com/ResultsExt.aspx?q=&ctid=CT1641676&SearchSource=2
FF - component: c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\e4wuvfee.default\extensions\{9ee802e8-c931-47ab-b570-aa8f791598ca}\components\FFExternalAlert.dll
FF - component: c:\program files\Mozilla Firefox\components\coFFPlgn.dll
FF - component: c:\program files\Mozilla Firefox\components\FFComm.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrec ordext.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\kSolo\npAVX.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npmozax.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npracplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npunagi2.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npvirtools.dll
FF - plugin: c:\program files\Opera\program\plugins\npdivx32.dll
FF - plugin: c:\program files\Opera\program\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Real\RealArcade\Plugins\Mozilla\npracplug.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-10-16 17:49
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(944)
c:\program files\common files\logitech\bluetooth\LBTWlgn.dll
c:\program files\Softex\OmniPass\opxpgina.dll
c:\program files\common files\logitech\bluetooth\LBTServ.dll
.
Completion time: 2009-10-16 17:57
ComboFix-quarantined-files.txt 2009-10-16 22:56
ComboFix2.txt 2009-10-15 23:34
ComboFix3.txt 2009-10-15 02:52
ComboFix4.txt 2009-10-13 05:02
ComboFix5.txt 2009-10-16 22:33
Pre-Run: 42,879,279,104 bytes free
Post-Run: 42,932,015,104 bytes free
522 --- E O F --- 2009-10-16 22:21