1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Windows cnnot find C:/WINDOWS/WINLOGON.EXE

Discussion in 'Windows XP' started by vespo, Apr 16, 2008.

Thread Status:
Not open for further replies.
  1. vespo

    vespo Thread Starter

    Joined:
    Apr 16, 2008
    Messages:
    2
    For some unknown reason my computer has come up with an error message that says "Windows can't find C:/WINDOWS/WINLOGON.EXE, MAKE SURE THE PATH IS CORRECT...."ETC.

    I need some help to remove this message and find out why it appears everytime i start up my computer.

    This my HijackThis log and below it is the combofix log:

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:35:36, on 16/04/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.6000.16640)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
    C:\WINDOWS\system32\HPZipm12.exe
    C:\Program Files\Prevx1\PXAgent.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\Drivers\WTSRV.EXE
    C:\WINDOWS\Explorer.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\Program Files\TalkTalk\bin\sprtcmd.exe
    C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\Search Settings\SearchSettings.exe
    C:\Program Files\iTunes\iTunesHelper.exe
    C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
    C:\Program Files\Prevx1\PXConsole.exe
    C:\WINDOWS\system32\WTClient.exe
    C:\PROGRA~1\MultSlim\MMKeybd.EXE
    C:\PROGRA~1\MultSlim\KPDrv4XP.exe
    C:\WINDOWS\system32\WISPTIS.EXE
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    C:\Program Files\ClamWin\bin\ClamTray.exe
    C:\Program Files\iPod\bin\iPodService.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Program Files\MagicDisc\MagicDisc.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqimzone.exe
    C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    C:\Program Files\Zone Labs\ZoneAlarm\MailFrontier\mantispm.exe
    C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.co.uk/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.yahoo.com/
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\winlogon.exe
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
    O2 - BHO: AddTask Class - {24F06550-65E3-4D1C-8CFE-839C296B5530} - C:\Program Files\real\IEeREAD.dll
    O2 - BHO: Malicious Scripts Scanner - {55EA1964-F5E4-4D6A-B9B2-125B37655FCB} - C:\Documents and Settings\All Users\Application Data\Prevx\pxbho.dll
    O2 - BHO: AddTask Class - {6A19C29D-ED45-4483-8999-9F939C8161F2} - C:\Program Files\real\WebHook.dll
    O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
    O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O2 - BHO: Burn4Free Toolbar Helper - {D187A56B-A33F-4CBE-9D77-459FC0BAE012} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
    O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C:\Program Files\Search Settings\kb125\SearchSettings.dll
    O2 - BHO: ZoneAlarm Spy Blocker BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
    O3 - Toolbar: ZoneAlarm Spy Blocker - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll
    O3 - Toolbar: Burn4Free Toolbar - {4F11ACBB-393F-4C86-A214-FF3D0D155CC3} - C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll
    O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
    O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
    O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
    O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [SearchSettings] C:\Program Files\Search Settings\SearchSettings.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [Service] C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\Winupdate\Servicerun.exe C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\Winupdate\Service.exe
    O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    O4 - HKLM\..\Run: [RelevantKnowledge] C:\windows\system32\rlvknlg.exe -boot
    O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"
    O4 - HKLM\..\Run: [Adobe_ID0EYTHM] C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE
    O4 - HKLM\..\Run: [PrevxOne] "C:\Program Files\Prevx1\PXConsole.exe"
    O4 - HKLM\..\Run: [WTClient] WTClient.exe
    O4 - HKLM\..\Run: [MultSlim] C:\PROGRA~1\MultSlim\MMKeybd.EXE
    O4 - HKLM\..\Run: [KPDrv4XP] C:\PROGRA~1\MultSlim\KPDrv4XP.exe
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe /S
    O4 - HKCU\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
    O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Photosmart Premier Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
    O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
    O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
    O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
    O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.1.6.cab
    O17 - HKLM\System\CCS\Services\Tcpip\..\{2748F250-9351-4C8F-A858-7F83B82B09F1}: NameServer = 10.0.0.1
    O17 - HKLM\System\CS2\Services\Tcpip\..\{2748F250-9351-4C8F-A858-7F83B82B09F1}: NameServer = 10.0.0.1
    O17 - HKLM\System\CS3\Services\Tcpip\..\{2748F250-9351-4C8F-A858-7F83B82B09F1}: NameServer = 10.0.0.1
    O17 - HKLM\System\CS4\Services\Tcpip\..\{2748F250-9351-4C8F-A858-7F83B82B09F1}: NameServer = 10.0.0.1
    O17 - HKLM\System\CS5\Services\Tcpip\..\{2748F250-9351-4C8F-A858-7F83B82B09F1}: NameServer = 10.0.0.1
    O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe
    O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
    O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe (file missing)
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\drivers\w32x86\3\HPBOID.EXE
    O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Prevx Agent (PREVXAgent) - Prevx - C:\Program Files\Prevx1\PXAgent.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
    O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\System32\Drivers\WTSRV.EXE

    --
    End of file - 12972 bytes


    The other log (COMBOFIX) will be on another post as the thread is too long.
     
  2. vespo

    vespo Thread Starter

    Joined:
    Apr 16, 2008
    Messages:
    2
    tHIS REFERS BACK TO MY FIRST THREAD,THIS IS THE COMBOFIX LOG:

    ComboFix 08-04-15.4 - user 2008-04-16 14:44:02.1 - NTFSx86
    Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.2607 [GMT 1:00]
    Running from: C:\Program Files\ComboFix.exe
    * Created a new restore point
    * Resident AV is active


    WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
    .

    ((((((((((((((((((((((((( Files Created from 2008-03-16 to 2008-04-16 )))))))))))))))))))))))))))))))
    .

    2008-04-16 14:38 . 2008-04-16 14:39 1,770,196 --a------ C:\Program Files\ComboFix.exe
    2008-04-16 14:06 . 2008-04-16 14:06 <DIR> d-------- C:\Program Files\RegistrySmart
    2008-04-16 13:41 . 2008-04-16 13:41 45,056 --a------ C:\WINDOWS\system32\UTSCSI.EXE
    2008-04-16 13:40 . 2008-04-16 13:40 <DIR> d-------- C:\WINDOWS\system32\FPAP-EXL600
    2008-04-16 13:40 . 2008-04-16 13:40 <DIR> d-------- C:\Documents and Settings\user\Application Data\ABIG
    2008-04-16 13:35 . 2008-04-16 13:35 <DIR> d-------- C:\Program Files\Trend Micro
    2008-04-16 13:34 . 2008-04-16 13:34 812,344 --a------ C:\Program Files\HJTInstall.exe
    2008-04-13 16:35 . 2008-04-13 16:37 <DIR> d-------- C:\Documents and Settings\user\Application Data\.clamwin
    2008-04-13 16:33 . 2008-04-13 17:32 <DIR> d-------- C:\Program Files\ClamWin
    2008-04-13 16:33 . 2008-04-13 17:32 <DIR> d-------- C:\Documents and Settings\user\.clamwin
    2008-04-13 16:27 . 2008-04-13 17:30 18,739,797 --a------ C:\Program Files\clamwin-0.92.zip
    2008-04-13 15:12 . 2008-04-13 17:21 <DIR> d-------- C:\Program Files\XoftSpySE
    2008-04-13 15:02 . 2008-04-13 17:21 <DIR> d-------- C:\Program Files\Files-Secure
    2008-04-13 00:58 . 2008-04-13 17:21 <DIR> d-------- C:\db32b8e91be7ae5a6711a584
    2008-04-10 12:56 . 2008-03-27 01:30 96,577 --------- C:\WINDOWS\hpqins16.dat.temp
    2008-04-09 13:27 . 2008-04-09 13:27 0 --a------ C:\WINDOWS\PlayList.Fpl
    2008-04-08 15:31 . 2008-04-08 15:31 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\QuickTime
    2008-04-08 13:50 . 2008-04-08 13:50 <DIR> d-------- C:\Program Files\MultSlim
    2008-04-08 13:50 . 2008-04-08 13:50 77 --a------ C:\WINDOWS\MultSlim.UNI
    2008-04-08 03:27 . 2007-04-23 16:28 18,432 --a------ C:\WINDOWS\system32\drivers\TClass2k.sys
    2008-04-08 03:27 . 2007-05-31 18:33 12,800 --a------ C:\WINDOWS\system32\drivers\UCTblHid.sys
    2008-04-08 02:29 . 2008-04-08 02:30 <DIR> d-------- C:\Program Files\TABLET
    2008-04-06 02:44 . 2008-04-06 02:44 <DIR> d-------- C:\Documents and Settings\user\Application Data\MailFrontier
    2008-04-06 01:24 . 2008-04-06 01:24 46,804,880 --a------ C:\Program Files\zlsSetup_70_470_000_en.exe
    2008-04-05 18:39 . 2008-04-05 18:39 601,448 --a------ C:\Program Files\Q810243_WXP_SP2_x86_ENU.exe
    2008-04-05 12:53 . 2008-04-13 19:29 <DIR> d-------- C:\Documents and Settings\user\Application Data\Prevx
    2008-04-05 12:52 . 2008-04-16 15:07 <DIR> d-------- C:\Program Files\Prevx1
    2008-04-05 12:52 . 2008-04-16 14:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Prevx
    2008-04-05 12:52 . 2006-12-08 13:36 9,728 --a------ C:\WINDOWS\system32\drivers\pxscinst.dll
    2008-04-05 12:52 . 2006-12-08 13:36 7,680 --a------ C:\WINDOWS\system32\drivers\pxinst.dll
    2008-04-04 17:36 . 2008-04-04 17:36 0 --a------ C:\WINDOWS\system32\atiicdxx.dat
    2008-04-04 17:02 . 2008-04-04 17:02 <DIR> d-------- C:\Program Files\PrevxCSI
    2008-04-04 17:02 . 2008-04-08 18:01 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\PrevxCSI
    2008-04-04 17:02 . 2008-04-04 17:02 900,152 --a------ C:\Program Files\PREVXCSIFREE.EXE
    2008-04-04 17:01 . 2008-04-04 17:10 <DIR> d-------- C:\Documents and Settings\user\Application Data\RegistrySmart
    2008-04-04 17:00 . 2008-04-04 17:00 1,118,904 --a------ C:\Program Files\setupxv.exe
    2008-04-04 16:28 . 2008-04-04 16:28 10 --a------ C:\WINDOWS\WININIT.INI
    2008-04-04 02:18 . 2008-04-09 13:26 389,120 --a------ C:\WINDOWS\system32\ACTSKN43.OCX
    2008-04-04 02:13 . 2008-04-04 02:13 <DIR> d-------- C:\WINDOWS\system32\FTCodecs
    2008-04-04 02:13 . 2008-04-04 02:13 <DIR> d-------- C:\Program Files\Fantasysoft-Studio
    2008-04-04 02:13 . 2006-04-21 00:27 544,768 --a------ C:\WINDOWS\system32\CLVSD.ax
    2008-04-04 02:13 . 2003-03-25 05:49 45,056 --a------ C:\WINDOWS\system32\ogg.dll
    2008-04-04 02:13 . 2008-04-09 13:27 3,185 --a------ C:\WINDOWS\FantasyDVD.ini
    2008-04-04 02:13 . 2008-04-09 13:27 2,417 --a------ C:\WINDOWS\ShortCutInf.ini
    2008-04-04 02:12 . 2008-04-04 02:12 <DIR> d-------- C:\Program Files\real
    2008-04-04 02:06 . 2008-04-04 02:06 <DIR> d-------- C:\Program Files\DVD Region+CSS Free
    2008-04-04 02:06 . 2008-04-10 23:38 101 --a------ C:\WINDOWS\DVDRegionFree.INI
    2008-04-02 18:27 . 2008-04-02 18:27 <DIR> d-------- C:\Documents and Settings\user\Application Data\ATI
    2008-04-02 18:09 . 2008-04-04 16:35 <DIR> d-------- C:\Program Files\Common Files\ATI Technologies
    2008-04-02 18:04 . 2008-04-02 18:04 <DIR> d-------- C:\Program Files\Attansic
    2008-04-02 16:38 . 2008-04-02 17:57 29 --a------ C:\WINDOWS\AVFTP.INI
    2008-04-02 16:37 . 2008-04-02 16:38 <DIR> d-------- C:\Program Files\AV DVD Player Morpher
    2008-04-02 16:37 . 2008-04-02 16:37 10,129,172 --a------ C:\Program Files\dvd_player_morpher.exe
    2008-04-02 16:23 . 2008-04-02 16:23 172,623 --a------ C:\Program Files\Cdvd.exe
    2008-04-02 16:15 . 2008-04-02 16:15 <DIR> d-------- C:\Documents and Settings\user\Application Data\CyberLink
    2008-04-02 16:14 . 2008-04-02 16:14 1,409 --a------ C:\WINDOWS\system32\tmp74E7A.FOT
    2008-03-29 01:32 . 2008-03-29 01:32 1,409 --a------ C:\WINDOWS\system32\tmp537E1.FOT
    2008-03-29 01:15 . 2008-03-29 01:15 1,584 --a------ C:\WINDOWS\TrustyFiles.INI
    2008-03-27 21:58 . 2008-03-27 21:58 <DIR> d-------- C:\Program Files\Solent
    2008-03-27 21:58 . 2008-03-27 22:06 <DIR> d-------- C:\Documents and Settings\user\Application Data\WebCam Recorder
    2008-03-27 17:42 . 2008-03-27 17:45 <DIR> d-------- C:\Program Files\FXhome VisionLab Studio
    2008-03-27 01:30 . 2008-04-10 12:56 96,577 --a------ C:\WINDOWS\hpqins16.dat
    2008-03-25 15:53 . 2008-03-25 15:53 <DIR> d-------- C:\Program Files\Burn4Free Toolbar
    2008-03-25 15:53 . 2008-04-13 21:32 <DIR> d-------- C:\Program Files\Burn4Free
    2008-03-25 15:53 . 2008-03-25 15:53 232,034 --a------ C:\WINDOWS\Burn4Free_Toolbar_Uninstaller_5796.exe
    2008-03-23 16:23 . 2008-03-23 16:28 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\FLEXnet
    2008-03-23 16:13 . 2008-03-23 16:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\ALM
    2008-03-23 15:52 . 2007-02-20 17:04 2,463,976 --a------ C:\WINDOWS\system32\NPSWF32.dll
    2008-03-23 15:52 . 2007-02-20 17:04 190,696 --a------ C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
    2008-03-23 15:42 . 2008-03-23 15:42 <DIR> d-------- C:\Program Files\Bonjour
    2008-03-22 18:22 . 2006-11-12 12:39 483,328 --a------ C:\WINDOWS\system32\actskn45.ocx
    2008-03-22 16:06 . 2008-03-22 16:06 1,409 --a------ C:\WINDOWS\system32\tmp49B7E.FOT
    2008-03-22 15:56 . 2008-03-22 15:56 <DIR> d-------- C:\WINDOWS\vbSkinner
    2008-03-22 15:11 . 2008-03-29 00:39 <DIR> d-------- C:\Program Files\PFConfig
    2008-03-22 15:11 . 2008-03-22 15:11 3,072,462 --a------ C:\Program Files\PFCSetup1.0.187.exe
    2008-03-22 13:54 . 2008-04-05 12:48 <DIR> d-------- C:\Program Files\Ceremu
    2008-03-22 13:53 . 2008-03-22 13:54 <DIR> d-------- C:\Temp
    2008-03-21 22:40 . 2008-03-29 00:47 <DIR> d-------- C:\Documents and Settings\user\Application Data\DivX
    2008-03-20 20:26 . 2008-03-23 14:56 <DIR> d-------- C:\WINDOWS\system32\NtmsData
    2008-03-20 20:20 . 2008-03-20 20:20 <DIR> d-------- C:\Program Files\Windows Installer Clean Up
    2008-03-20 20:19 . 2008-03-20 20:19 <DIR> d-------- C:\Program Files\MSECACHE
    2008-03-20 20:19 . 2008-03-20 20:19 359,656 --a------ C:\Program Files\msicuu2.exe
    2008-03-20 20:15 . 2008-03-20 20:15 1,000,745 --a------ C:\Program Files\wincs3clean.zip
    2008-03-20 19:37 . 2008-03-20 19:37 <DIR> d-------- C:\Program Files\Lily_Utils
    2008-03-20 19:37 . 2002-08-21 11:22 202,240 --a------ C:\WINDOWS\NFUninst.exe
    2008-03-19 03:09 . 2008-03-19 03:10 <DIR> d-------- C:\Program Files\DivX
    2008-03-19 03:09 . 2008-03-19 03:10 17,067,560 --a------ C:\Program Files\DivXInstaller.exe
    2008-03-19 03:09 . 2008-02-21 03:05 129,784 --------- C:\WINDOWS\system32\pxafs.dll
    2008-03-19 03:09 . 2008-02-21 03:05 120,056 --------- C:\WINDOWS\system32\pxcpyi64.exe
    2008-03-19 03:09 . 2008-02-21 03:05 118,520 --------- C:\WINDOWS\system32\pxinsi64.exe
    2008-03-19 01:15 . 2006-10-26 20:56 32,592 --a------ C:\WINDOWS\system32\msonpmon.dll
    2008-03-19 01:13 . 2008-03-19 01:13 <DIR> d-------- C:\Program Files\MSBuild
    2008-03-19 01:09 . 2008-03-19 01:09 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 8
    2008-03-19 01:07 . 2008-04-10 16:00 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Microsoft Help
    2008-03-17 13:02 . 2008-03-17 13:02 <DIR> d-------- C:\Program Files\Common Files\Adobe Systems Shared
    2008-03-16 22:46 . 2008-03-16 22:55 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\TEMP

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2008-04-16 12:59 29,753,312 --sha-w C:\WINDOWS\system32\drivers\fidbox.dat
    2008-04-16 12:59 254,516 --sha-w C:\WINDOWS\system32\drivers\fidbox.idx
    2008-04-14 20:39 --------- d-----w C:\Documents and Settings\user\Application Data\uTorrent
    2008-04-13 23:13 --------- d-----w C:\Program Files\uTorrent
    2008-04-13 15:37 --------- d-----w C:\Documents and Settings\user\Application Data\.clamwin
    2008-04-10 11:55 --------- d-----w C:\Program Files\HP
    2008-04-04 16:07 --------- d-----w C:\Program Files\SpyRemover
    2008-04-02 17:10 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2008-03-28 11:37 --------- d-----w C:\Program Files\Common Files\Adobe
    2008-03-27 00:47 --------- d-----w C:\Program Files\Voice
    2008-03-22 23:34 --------- d-----w C:\Documents and Settings\user\Application Data\Bearshare Premium P2P
    2008-03-19 00:14 --------- d-----w C:\Program Files\Microsoft Works
    2008-03-17 16:44 --------- d-----w C:\Documents and Settings\user\Application Data\Download Manager
    2008-03-13 20:56 --------- d-----w C:\Program Files\MagicDisc
    2008-03-12 11:03 --------- d-----w C:\Program Files\Autodesk
    2008-03-11 13:07 948,090 ----a-w C:\Program Files\free-wma-mp3-converter.exe
    2008-03-11 13:07 --------- d-----w C:\Program Files\Free WMA to MP3 Converter
    2008-03-08 14:18 --------- d-----w C:\Documents and Settings\user\Application Data\Apple Computer
    2008-03-08 12:57 327,168 ----a-w C:\Program Files\ftweak-speed.msi
    2008-03-08 12:50 --------- d-----w C:\Program Files\Common Files\Apple
    2008-03-08 12:07 21,321,008 ----a-w C:\Program Files\QuickTimeInstaller.exe
    2008-03-07 13:41 --------- d-----w C:\Documents and Settings\user\Application Data\Search Settings
    2008-03-07 13:38 --------- d-----w C:\Program Files\Java
    2008-03-07 13:37 --------- d-----w C:\Program Files\Common Files\Java
    2008-03-05 21:48 17,788,920 ----a-w C:\Program Files\antivir_workstation_win7u_en_h.exe
    2008-03-05 20:29 --------- d-----w C:\Documents and Settings\user\Application Data\HP
    2008-03-05 15:18 25,009,085 ----a-w C:\Program Files\vexp007.zip
    2008-03-05 13:57 25,072,608 ----a-w C:\Program Files\AVSDVDPlayer.exe
    2008-03-05 13:57 --------- d-----w C:\Program Files\Common Files\AVSMedia
    2008-03-05 13:57 --------- d-----w C:\Program Files\AVSMedia
    2008-03-05 12:11 --------- d-----w C:\Program Files\Realtek
    2008-03-05 12:08 --------- d-----w C:\Program Files\ASUS
    2008-03-05 11:54 --------- d-----w C:\Program Files\VIA
    2008-03-05 11:54 --------- d-----w C:\Program Files\DIFX
    2008-03-04 18:25 --------- d-----w C:\Program Files\Disc2Phone
    2008-03-03 19:45 --------- d-----w C:\Documents and Settings\All Users\Application Data\HP
    2008-03-03 19:43 --------- d-----w C:\Program Files\Common Files\Sonic Shared
    2008-03-03 19:43 --------- d-----w C:\Documents and Settings\All Users\Application Data\Sonic
    2008-03-03 19:42 --------- d-----w C:\Program Files\Common Files\HP
    2008-03-03 19:40 --------- d-----w C:\Program Files\Hewlett-Packard
    2008-03-03 19:39 --------- d-----w C:\Program Files\Common Files\Hewlett-Packard
    2008-03-03 16:12 47,616 ----a-w C:\WINDOWS\system32\drivers\Haspnt.sys
    2008-03-03 16:12 --------- d-----w C:\Program Files\GLOBEtrotter Software Inc
    2008-03-03 16:09 --------- d-----w C:\Program Files\Common Files\Alias Shared
    2008-03-03 16:08 --------- d-----w C:\Program Files\Common Files\InstallShield
    2008-03-03 16:08 --------- d-----w C:\Program Files\Common Files\Autodesk Shared
    2008-03-01 16:53 --------- d-----w C:\Program Files\TalkTalk
    2008-03-01 16:53 --------- d-----w C:\Documents and Settings\All Users\Application Data\SupportSoft
    2008-03-01 16:49 --------- d-----w C:\Program Files\SupportSoft
    2008-03-01 16:49 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
    2008-02-29 14:01 --------- d-----w C:\Program Files\MT882
    2008-02-28 21:28 --------- d-----w C:\Program Files\Ubisoft
    2008-02-28 20:49 --------- d-----w C:\Program Files\Common Files\SupportSoft
    2008-02-28 19:30 --------- d-----w C:\Program Files\PowerISO
    2008-02-26 14:08 --------- d-----w C:\Program Files\Microsoft Windows OneCare Live(2)
    2008-02-26 12:53 --------- d-----w C:\Program Files\Common Files\Macrovision Shared
    2008-02-25 19:09 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
    2008-02-25 19:01 --------- d-----w C:\Program Files\Yahoo!
    2008-02-25 18:36 --------- d-----w C:\Program Files\Google
    2008-02-25 18:35 1,145,896 ----a-w C:\Program Files\GoogleToolbarInstaller.exe
    2008-02-25 17:55 --------- d-----w C:\Program Files\ZoneAlarmSB
    2008-02-25 17:54 --------- d-----w C:\Program Files\Zone Labs
    2008-02-25 17:52 206,584 ----a-w C:\Program Files\zaSetup_en.exe
    2008-02-25 11:51 --------- d-----w C:\Program Files\Common Files\L&H
    2008-02-25 11:50 --------- d-----w C:\Program Files\Microsoft.NET
    2008-02-25 11:50 --------- d-----w C:\Program Files\Microsoft ActiveSync
    2008-02-25 11:46 --------- d-----w C:\Program Files\Common Files\Ahead
    2008-02-25 11:46 --------- d-----w C:\Program Files\Ahead
    2008-02-25 11:45 --------- d-----w C:\Documents and Settings\user\Application Data\InterTrust
    2008-02-25 11:44 --------- d-----w C:\Program Files\CyberLink
    2008-02-25 11:44 --------- d-----w C:\Documents and Settings\All Users\Application Data\CyberLink
    2008-02-25 11:39 --------- d-----w C:\Program Files\microsoft frontpage
    2008-02-18 17:29 96,256 ----a-w C:\WINDOWS\system32\drivers\mcdbus.sys
    2008-02-18 11:16 30,464 ----a-w C:\WINDOWS\system32\drivers\usbaapl.sys
    .

    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown
    REGEDIT4

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{24F06550-65E3-4D1C-8CFE-839C296B5530}]
    2007-06-28 17:25 57344 --a------ C:\Program Files\real\IEeREAD.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6A19C29D-ED45-4483-8999-9F939C8161F2}]
    2008-02-01 10:20 57224 --a------ C:\Program Files\real\WebHook.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D187A56B-A33F-4CBE-9D77-459FC0BAE012}]
    2008-03-25 15:53 806912 --a------ C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E312764E-7706-43F1-8DAB-FCDD2B1E416D}]
    2007-12-06 12:58 1198432 --a------ C:\Program Files\Search Settings\kb125\SearchSettings.dll

    [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}]
    2008-02-25 18:55 262144 --a------ C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    "{F0D4B239-DA4B-4DAF-81E4-DFEE4931A4AA}"= "C:\Program Files\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL" [2008-02-25 18:55 262144]
    "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= "C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll" [2008-03-25 15:53 806912]

    [HKEY_CLASSES_ROOT\clsid\{f0d4b239-da4b-4daf-81e4-dfee4931a4aa}]

    [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]

    [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser]
    "{4F11ACBB-393F-4C86-A214-FF3D0D155CC3}"= C:\Program Files\Burn4Free Toolbar\v3.3.0.1\Burn4Free_Toolbar.dll [2008-03-25 15:53 806912]

    [HKEY_CLASSES_ROOT\clsid\{4f11acbb-393f-4c86-a214-ff3d0d155cc3}]

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\IconOverlay1EXL600]
    @={BF9B13E4-FE9B-4121-853F-866F4E9E2830}

    [HKEY_CLASSES_ROOT\CLSID\{BF9B13E4-FE9B-4121-853F-866F4E9E2830}]
    2007-11-13 03:08 599552 --a------ C:\WINDOWS\system32\FPAP-EXL600\FileptcIconOverlay.dll

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-03 21:26 15360]
    "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2008-02-25 19:36 171448]
    "Uniblue RegistryBooster 2"="C:\Program Files\Uniblue\RegistryBooster 2\RegistryBooster.exe" [ ]
    "ClamWin"="C:\Program Files\ClamWin\bin\ClamTray.exe" [2008-01-20 22:08 77824]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "IMJPMIG8.1"="C:\WINDOWS\IME\imjp8_1\IMJPMIG.exe" [2004-08-03 19:02 208952]
    "PHIME2002ASync"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 19:02 455168]
    "PHIME2002A"="C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.exe" [2004-08-03 19:02 455168]
    "NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 12:50 155648]
    "SkyTel"="SkyTel.EXE" [2006-05-16 19:04 2879488 C:\WINDOWS\SkyTel.exe]
    "PWRISOVM.EXE"="C:\Program Files\PowerISO\PWRISOVM.EXE" [2007-04-09 13:23 200704]
    "TalkTalk"="C:\Program Files\TalkTalk\bin\sprtcmd.exe" [2005-08-16 01:12 192512]
    "HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2007-05-08 16:24 54840]
    "RTHDCPL"="RTHDCPL.EXE" [2006-09-06 12:44 16262656 C:\WINDOWS\RTHDCPL.exe]
    "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-03-06 13:43 249896]
    "SearchSettings"="C:\Program Files\Search Settings\SearchSettings.exe" [2007-12-06 12:58 1069920]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2008-02-01 00:13 385024]
    "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 14:10 267048]
    "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 23:16 39792]
    "Service"="C:\WINDOWS\system32\SoftwareDistribution\Setup\ServiceStartup\wups.dll\Winupdate\Servicerun.exe" [ ]
    "GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2006-10-27 01:47 31016]
    "Acrobat Assistant 8.0"="C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" [2007-05-10 23:46 624248]
    "Adobe_ID0EYTHM"="C:\PROGRA~1\COMMON~1\Adobe\ADOBEV~1\Server\bin\VERSIO~2.EXE" [2007-03-20 17:40 1884160]
    "PrevxOne"="C:\Program Files\Prevx1\PXConsole.exe" [2007-01-12 18:52 1503232]
    "WTClient"="WTClient.exe" [2007-04-11 17:27 40960 C:\WINDOWS\system32\WTClient.exe]
    "MultSlim"="C:\PROGRA~1\MultSlim\MMKeybd.EXE" [2003-12-12 13:16 110592]
    "KPDrv4XP"="C:\PROGRA~1\MultSlim\KPDrv4XP.exe" [2003-06-12 10:51 32768]
    "ZoneAlarm Client"="C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" [2008-03-13 23:11 919016]
    "MbWzdFPAP-EXL600"="C:\WINDOWS\system32\FPAP-EXL600\PdtGuide.exe" [2007-12-05 12:50 1030656]
    "RegistrySmart"="C:\Program Files\RegistrySmart\RegistrySmart.exe" [2008-04-01 09:41 4453616]

    C:\Documents and Settings\user\Start Menu\Programs\Startup\
    MagicDisc.lnk - C:\Program Files\MagicDisc\MagicDisc.exe [2008-03-13 21:56:03 546816]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
    HP Digital Imaging Monitor.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe [2006-02-19 05:21:22 288472]
    HP Photosmart Premier Fast Start.lnk - C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe [2006-02-10 08:56:20 73728]

    [hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
    "{93994DE8-8239-4655-B1D1-5F4E91300429}"= C:\PROGRA~1\DVDREG~1\DVDShell.dll [2004-10-09 15:18 49152]

    [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ZoneLabsFirewall]
    "DisableMonitoring"=dword:00000001

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
    "EnableFirewall"= 0 (0x0)

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
    "%windir%\\system32\\sessmgr.exe"=
    "C:\\Program Files\\uTorrent\\uTorrent.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
    "C:\\Program Files\\HP\\Digital Imaging\\bin\\hpqnrs08.exe"=
    "C:\\Program Files\\iTunes\\iTunes.exe"=
    "C:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
    "C:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
    "C:\\Program Files\\Attansic\\Attansic Giga Ethernet Utility\\Mimo.exe"=
    "C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
    "C:\\Program Files\\Common Files\\Adobe\\Adobe Version Cue CS3\\Server\\bin\\VersionCueCS3.exe"=

    [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
    "6346:TCP"= 6346:TCP:shareaza
    "6346:UDP"= 6346:UDP:shareaza
    "3703:TCP"= 3703:TCP:Adobe Version Cue CS3 Server
    "3704:TCP"= 3704:TCP:Adobe Version Cue CS3 Server
    "50900:TCP"= 50900:TCP:Adobe Version Cue CS3 Server
    "50901:TCP"= 50901:TCP:Adobe Version Cue CS3 Server

    R0 mv614x;mv614x;C:\WINDOWS\system32\DRIVERS\mv614x.sys [2006-07-03 20:21]
    R0 videX32;videX32;C:\WINDOWS\system32\DRIVERS\videX32.sys [2006-02-23 12:38]
    R0 xfilt;VIA SATA IDE Hot-plug Driver;C:\WINDOWS\system32\DRIVERS\xfilt.sys [2006-02-23 12:39]
    R2 dvdmmg;dvdmmg;C:\WINDOWS\system32\drivers\dvdmmg.sys [2007-09-06 11:15]
    R2 HIDKbFlt;Dritek USB Keyboard HID Filter;C:\WINDOWS\system32\DRIVERS\HIDKbFlt.sys [2004-01-05 09:12]
    R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Adapter;C:\WINDOWS\system32\DRIVERS\atl01_xp.sys [2006-08-22 14:36]
    R3 PTSimBus;PenTablet Bus Enumerator;C:\WINDOWS\system32\DRIVERS\PTSimBus.sys [2007-06-07 18:16]
    R3 PTSimHid;PenTablet Simulated HID MiniDriver;C:\WINDOWS\system32\DRIVERS\PTSimHid.sys [2007-04-23 16:28]
    R3 usbprint;Microsoft USB PRINTER Class;C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-04 00:01]
    S3 iadusb;MT882;C:\WINDOWS\system32\DRIVERS\glauiad.sys [2006-07-27 16:37]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
    \Shell\AutoRun\command - F:\PdtStart.exe

    *Newly Created Service* - CATCHME
    .
    Contents of the 'Scheduled Tasks' folder
    "2008-04-09 16:44:03 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    "2008-04-10 02:30:00 C:\WINDOWS\Tasks\RegistrySmart Scheduled Scan.job"
    - C:\Program Files\RegistrySmart\RegistrySmart.ex
    - C:\Program Files\RegistrySmart
    "2008-03-28 12:59:00 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC Nag.job"
    - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
    "2008-03-08 12:59:32 C:\WINDOWS\Tasks\Uniblue SpeedUpMyPC.job"
    - C:\Program Files\Uniblue\SpeedUpMyPC 3\SpeedUpMyPC.exe
    "2008-04-16 13:00:43 C:\WINDOWS\Tasks\XoftSpySE 2.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    "2008-04-13 14:13:06 C:\WINDOWS\Tasks\XoftSpySE.job"
    - C:\Program Files\XoftSpySE\XoftSpy.exe
    .
    **************************************************************************
    scanning hidden processes ...

    scanning hidden autostart entries ...

    scanning hidden files ...

    scan completed successfully
    hidden files:

    **************************************************************************
    .
    Completion time: 2008-04-16 15:18:50
    ComboFix-quarantined-files.txt 2008-04-16 14:18:42

    Pre-Run: 163,821,711,360 bytes free
    Post-Run: 166,057,672,704 bytes free
    .
    2008-04-13 17:02:04 --- E O F ---
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/704322

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice