ComboFix 10-07-22.01 - MIKE 07/22/2010 19:04:33.2.2 - x86
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3263.2285 [GMT -4:00]
Running from: c:\users\MIKE\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 )))))))))))))))))))))))))))))))
.
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-07-22 23:02 . 2010-07-22 23:03 -------- d-----w- C:\32788R22FWJFW
2010-07-22 21:16 . 2010-07-22 21:16 125952 ----a-w- c:\programdata\ParetoLogic\UUS2\Temp\Update.exe
2010-07-22 21:09 . 2010-07-22 21:29 -------- d-----w- c:\programdata\ParetoLogic
2010-07-22 21:09 . 2010-07-22 21:29 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-07-21 12:35 . 2010-07-21 12:35 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 12:35 . 2010-07-21 12:35 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 12:35 . 2010-07-21 12:35 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 12:35 . 2010-07-21 12:35 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 12:35 . 2010-07-21 12:35 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 00:47 . 2010-07-22 17:16 63488 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-21 00:47 . 2010-07-21 00:47 52224 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-21 00:47 . 2010-07-22 17:16 117760 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-21 00:47 . 2010-07-21 00:47 -------- d-----w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com
2010-07-21 00:47 . 2010-07-21 00:47 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-21 00:47 . 2010-07-22 01:16 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-21 00:32 . 2010-07-21 00:32 -------- d-----w- c:\program files\Common Files\Java
2010-07-18 00:48 . 2010-07-22 20:42 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-07-18 00:47 . 2010-07-18 00:52 -------- d-----w- c:\programdata\Hitman Pro
2010-07-18 00:47 . 2010-07-18 00:47 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-07-17 21:51 . 2010-07-17 21:51 -------- d-----w- c:\users\MIKE\AppData\Local\Sunbelt Software
2010-07-17 21:39 . 2010-07-17 21:39 -------- dc-h--w- c:\programdata\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-07-17 21:39 . 2010-07-12 08:56 2979280 -c--a-w- c:\programdata\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-07-16 12:41 . 2010-07-16 12:41 242896 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-07-16 12:41 . 2010-07-16 12:41 216200 ----a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-07-16 12:40 . 2010-07-16 12:40 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-16 12:39 . 2010-07-16 12:39 813336 ----a-w- c:\programdata\avg9\update\backup\avginet.dll
2010-07-16 12:39 . 2010-07-16 12:39 624920 ----a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2010-07-16 12:39 . 2010-07-16 12:39 1690464 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-07-16 12:39 . 2010-07-16 12:39 1038688 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2010-07-05 22:10 . 2010-07-05 22:10 -------- d-----w- c:\users\MIKE\AppData\Local\Cooliris
2010-07-05 22:10 . 2010-06-14 16:08 4687872 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-07-05 22:10 . 2010-06-14 16:08 545280 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-07-05 22:10 . 2010-06-14 16:08 4687360 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-07-05 22:10 . 2010-06-14 16:08 103424 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-07-05 22:10 . 2010-06-14 16:08 425984 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-07-05 22:10 . 2010-06-14 16:08 152064 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-07-05 22:10 . 2010-06-14 16:08 57856 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-28 21:19 . 2010-06-28 21:19 -------- d-----w- c:\users\MIKE\AppData\Roaming\Enplase
2010-06-23 07:00 . 2009-11-25 16:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 07:00 . 2009-11-25 16:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 07:00 . 2009-11-25 16:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 07:00 . 2009-11-25 16:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 07:00 . 2009-11-25 16:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 00:31 . 2010-06-06 23:29 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 12:40 . 2009-12-16 22:32 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-16 12:40 . 2009-12-16 22:32 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-15 07:01 . 2009-12-19 15:43 -------- d-----w- c:\programdata\Microsoft Help
2010-07-12 08:55 . 2010-06-05 22:57 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-07-12 08:55 . 2010-01-04 14:44 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-08 01:12 . 2009-12-23 01:58 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 13:36 . 2009-12-16 22:32 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 16:58 . 2009-12-16 22:48 600680 ----a-w- c:\windows\system32\nvuninst.exe
2010-05-27 07:24 . 2010-06-09 08:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-09 08:13 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 22:00 . 2009-12-16 22:32 -------- d-----w- c:\programdata\avg9
2010-05-26 00:15 . 2010-05-26 00:15 -------- d-----w- c:\program files\Wondershare
2010-05-21 05:18 . 2010-06-09 08:13 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-01 14:49 . 2010-06-09 08:13 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-01-25 13:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-01-25 13:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-07-17_15.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-17 01:05 . 2010-07-22 21:58 29122 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-07-22 21:58 36528 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-05 22:57 . 2010-06-05 22:56 64288 c:\windows\System32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys
+ 2010-06-05 22:57 . 2010-07-12 08:55 64288 c:\windows\System32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys
- 2009-12-17 01:14 . 2010-07-17 12:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 01:14 . 2010-07-22 21:57 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 01:14 . 2010-07-22 21:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 01:14 . 2010-07-17 12:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-07-22 21:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-07-17 12:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:34 . 2010-07-22 21:15 85688 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2009-12-16 22:50 . 2010-07-17 15:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 23:10 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:57 . 2010-07-22 21:58 7106 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2735080834-11081467-332214384-1001_UserData.bin
- 2010-06-23 07:16 . 2010-06-23 07:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-22 21:57 . 2010-07-22 21:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-22 21:57 . 2010-07-22 21:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-06-23 07:16 . 2010-06-23 07:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-07-22 22:01 618264 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-07-16 23:20 618264 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-07-22 22:01 104546 c:\windows\System32\perfc009.dat
- 2009-07-14 02:05 . 2010-07-16 23:20 104546 c:\windows\System32\perfc009.dat
- 2010-06-06 23:29 . 2010-06-06 23:29 153376 c:\windows\System32\javaws.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 153376 c:\windows\System32\javaws.exe
- 2010-06-06 23:29 . 2010-06-06 23:29 145184 c:\windows\System32\javaw.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 145184 c:\windows\System32\javaw.exe
- 2010-06-06 23:29 . 2010-06-06 23:29 145184 c:\windows\System32\java.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 145184 c:\windows\System32\java.exe
+ 2010-07-21 00:32 . 2010-07-21 00:32 183808 c:\windows\Installer\ffa125e.msi
+ 2010-07-21 00:31 . 2010-07-21 00:31 681984 c:\windows\Installer\ffa1257.msi
+ 2009-07-14 02:03 . 2010-07-22 22:10 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:03 . 2010-07-17 05:16 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2010-07-17 21:39 . 2010-07-17 21:39 1869312 c:\windows\Installer\7eaf728e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-22 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-06 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-06 92704]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^MIKE^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\MIKE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-07-16 12:40 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-06 18:52 1832232 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-03-06 16:52 13605408 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-03-06 16:52 92704 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
2006-01-30 16:00 98304 ----a-r- c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDiagnosticM]
2007-02-27 21:29 315392 ----a-w- c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-03-28 07:05 1045800 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe
Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.3263.2285 [GMT -4:00]
Running from: c:\users\MIKE\Downloads\ComboFix.exe
SP: SUPERAntiSpyware *disabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
((((((((((((((((((((((((( Files Created from 2010-06-22 to 2010-07-22 )))))))))))))))))))))))))))))))
.
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Public\AppData\Local\temp
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-22 23:11 . 2010-07-22 23:11 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-07-22 23:02 . 2010-07-22 23:03 -------- d-----w- C:\32788R22FWJFW
2010-07-22 21:16 . 2010-07-22 21:16 125952 ----a-w- c:\programdata\ParetoLogic\UUS2\Temp\Update.exe
2010-07-22 21:09 . 2010-07-22 21:29 -------- d-----w- c:\programdata\ParetoLogic
2010-07-22 21:09 . 2010-07-22 21:29 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-07-21 12:35 . 2010-07-21 12:35 921440 ----a-w- c:\programdata\avg9\update\backup\avgemc.exe
2010-07-21 12:35 . 2010-07-21 12:35 4368224 ----a-w- c:\programdata\avg9\update\backup\avgcorex.dll
2010-07-21 12:35 . 2010-07-21 12:35 1615200 ----a-w- c:\programdata\avg9\update\backup\avgssie.dll
2010-07-21 12:35 . 2010-07-21 12:35 1373536 ----a-w- c:\programdata\avg9\update\backup\avgssff.dll
2010-07-21 12:35 . 2010-07-21 12:35 1107296 ----a-w- c:\programdata\avg9\update\backup\avgxpl.dll
2010-07-21 00:47 . 2010-07-22 17:16 63488 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-07-21 00:47 . 2010-07-21 00:47 52224 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-21 00:47 . 2010-07-22 17:16 117760 ----a-w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-07-21 00:47 . 2010-07-21 00:47 -------- d-----w- c:\users\MIKE\AppData\Roaming\SUPERAntiSpyware.com
2010-07-21 00:47 . 2010-07-21 00:47 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-07-21 00:47 . 2010-07-22 01:16 -------- d-----w- c:\program files\SUPERAntiSpyware
2010-07-21 00:32 . 2010-07-21 00:32 -------- d-----w- c:\program files\Common Files\Java
2010-07-18 00:48 . 2010-07-22 20:42 16968 ----a-w- c:\windows\system32\drivers\hitmanpro35.sys
2010-07-18 00:47 . 2010-07-18 00:52 -------- d-----w- c:\programdata\Hitman Pro
2010-07-18 00:47 . 2010-07-18 00:47 -------- d-----w- c:\program files\Hitman Pro 3.5
2010-07-17 21:51 . 2010-07-17 21:51 -------- d-----w- c:\users\MIKE\AppData\Local\Sunbelt Software
2010-07-17 21:39 . 2010-07-17 21:39 -------- dc-h--w- c:\programdata\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}
2010-07-17 21:39 . 2010-07-12 08:56 2979280 -c--a-w- c:\programdata\{BD986C1B-72EC-4B82-B47B-6CAC4E6F494E}\Ad-AwareInstall.exe
2010-07-16 12:41 . 2010-07-16 12:41 242896 ----a-w- c:\programdata\avg9\update\backup\avgtdix.sys
2010-07-16 12:41 . 2010-07-16 12:41 216200 ----a-w- c:\programdata\avg9\update\backup\avgldx86.sys
2010-07-16 12:40 . 2010-07-16 12:40 12536 ----a-w- c:\windows\system32\avgrsstx.dll
2010-07-16 12:39 . 2010-07-16 12:39 813336 ----a-w- c:\programdata\avg9\update\backup\avginet.dll
2010-07-16 12:39 . 2010-07-16 12:39 624920 ----a-w- c:\programdata\avg9\update\backup\avgiproxy.exe
2010-07-16 12:39 . 2010-07-16 12:39 1690464 ----a-w- c:\programdata\avg9\update\backup\avgupd.dll
2010-07-16 12:39 . 2010-07-16 12:39 1038688 ----a-w- c:\programdata\avg9\update\backup\avgupd.exe
2010-07-05 22:10 . 2010-07-05 22:10 -------- d-----w- c:\users\MIKE\AppData\Local\Cooliris
2010-07-05 22:10 . 2010-06-14 16:08 4687872 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\cooliris190.dll
2010-07-05 22:10 . 2010-06-14 16:08 545280 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2010-07-05 22:10 . 2010-06-14 16:08 4687360 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\cooliris192.dll
2010-07-05 22:10 . 2010-06-14 16:08 103424 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2010-07-05 22:10 . 2010-06-14 16:08 425984 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2010-07-05 22:10 . 2010-06-14 16:08 152064 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
2010-07-05 22:10 . 2010-06-14 16:08 57856 ----a-w- c:\users\MIKE\AppData\Roaming\Mozilla\Firefox\Profiles\5h6vm4il.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2010-06-28 21:19 . 2010-06-28 21:19 -------- d-----w- c:\users\MIKE\AppData\Roaming\Enplase
2010-06-23 07:00 . 2009-11-25 16:47 99176 ----a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-23 07:00 . 2009-11-25 16:47 49472 ----a-w- c:\windows\system32\netfxperf.dll
2010-06-23 07:00 . 2009-11-25 16:47 297808 ----a-w- c:\windows\system32\mscoree.dll
2010-06-23 07:00 . 2009-11-25 16:47 295264 ----a-w- c:\windows\system32\PresentationHost.exe
2010-06-23 07:00 . 2009-11-25 16:47 1130824 ----a-w- c:\windows\system32\dfshim.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-07-21 00:31 . 2010-06-06 23:29 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-16 12:40 . 2009-12-16 22:32 243024 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2010-07-16 12:40 . 2009-12-16 22:32 216400 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2010-07-15 07:01 . 2009-12-19 15:43 -------- d-----w- c:\programdata\Microsoft Help
2010-07-12 08:55 . 2010-06-05 22:57 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-07-12 08:55 . 2010-01-04 14:44 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-08 01:12 . 2009-12-23 01:58 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-02 13:36 . 2009-12-16 22:32 29584 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2010-05-28 16:58 . 2009-12-16 22:48 600680 ----a-w- c:\windows\system32\nvuninst.exe
2010-05-27 07:24 . 2010-06-09 08:13 34304 ----a-w- c:\windows\system32\atmlib.dll
2010-05-27 03:49 . 2010-06-09 08:13 293888 ----a-w- c:\windows\system32\atmfd.dll
2010-05-26 22:00 . 2009-12-16 22:32 -------- d-----w- c:\programdata\avg9
2010-05-26 00:15 . 2010-05-26 00:15 -------- d-----w- c:\program files\Wondershare
2010-05-21 05:18 . 2010-06-09 08:13 977920 ----a-w- c:\windows\system32\wininet.dll
2010-05-01 14:49 . 2010-06-09 08:13 2326528 ----a-w- c:\windows\system32\win32k.sys
2010-04-29 19:39 . 2010-01-25 13:08 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-04-29 19:39 . 2010-01-25 13:08 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-10 21:26 . 2009-07-14 02:04 9633792 --sha-r- c:\windows\Fonts\StaticCache.dat
2009-07-14 01:14 . 2009-07-13 23:42 396800 --sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe
.
((((((((((((((((((((((((((((( SnapShot@2010-07-17_15.03.22 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-12-17 01:05 . 2010-07-22 21:58 29122 c:\windows\System32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 04:55 . 2010-07-22 21:58 36528 c:\windows\System32\wdi\BootPerformanceDiagnostics_SystemData.bin
- 2010-06-05 22:57 . 2010-06-05 22:56 64288 c:\windows\System32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys
+ 2010-06-05 22:57 . 2010-07-12 08:55 64288 c:\windows\System32\DRVSTORE\lbd_9C578CA880A99903668A8694DEFB21244E9C4C62\Lbd.sys
- 2009-12-17 01:14 . 2010-07-17 12:55 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 01:14 . 2010-07-22 21:57 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 01:14 . 2010-07-22 21:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 01:14 . 2010-07-17 12:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:41 . 2010-07-22 21:57 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-07-14 04:41 . 2010-07-17 12:55 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:34 . 2010-07-22 21:15 85688 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\History\History.IE5\index.dat
+ 2009-12-17 00:02 . 2010-07-22 23:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2009-12-17 00:02 . 2010-07-17 15:02 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Temp\Cookies\index.dat
- 2009-12-16 22:50 . 2010-07-17 15:02 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 23:10 32768 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-12-16 22:50 . 2010-06-23 07:19 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:50 . 2010-07-22 21:57 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-12-16 22:57 . 2010-07-22 21:58 7106 c:\windows\System32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2735080834-11081467-332214384-1001_UserData.bin
- 2010-06-23 07:16 . 2010-06-23 07:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-22 21:57 . 2010-07-22 21:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2010-07-22 21:57 . 2010-07-22 21:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2010-06-23 07:16 . 2010-06-23 07:16 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-07-14 02:05 . 2010-07-22 22:01 618264 c:\windows\System32\perfh009.dat
- 2009-07-14 02:05 . 2010-07-16 23:20 618264 c:\windows\System32\perfh009.dat
+ 2009-07-14 02:05 . 2010-07-22 22:01 104546 c:\windows\System32\perfc009.dat
- 2009-07-14 02:05 . 2010-07-16 23:20 104546 c:\windows\System32\perfc009.dat
- 2010-06-06 23:29 . 2010-06-06 23:29 153376 c:\windows\System32\javaws.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 153376 c:\windows\System32\javaws.exe
- 2010-06-06 23:29 . 2010-06-06 23:29 145184 c:\windows\System32\javaw.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 145184 c:\windows\System32\javaw.exe
- 2010-06-06 23:29 . 2010-06-06 23:29 145184 c:\windows\System32\java.exe
+ 2010-07-21 00:32 . 2010-07-21 00:31 145184 c:\windows\System32\java.exe
+ 2010-07-21 00:32 . 2010-07-21 00:32 183808 c:\windows\Installer\ffa125e.msi
+ 2010-07-21 00:31 . 2010-07-21 00:31 681984 c:\windows\Installer\ffa1257.msi
+ 2009-07-14 02:03 . 2010-07-22 22:10 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
- 2009-07-14 02:03 . 2010-07-17 05:16 7077888 c:\windows\System32\SMI\Store\Machine\schema.dat
+ 2010-07-17 21:39 . 2010-07-17 21:39 1869312 c:\windows\Installer\7eaf728e.msi
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-07-22 2403568]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-06 13605408]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-06 92704]
"PSDiagnosticM"="c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe" [2007-02-27 315392]
"ContentTransferWMDetector.exe"="c:\program files\Sony\Content Transfer\ContentTransferWMDetector.exe" [2009-11-19 583016]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\System32\avgrsstx.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
backup=c:\windows\pss\Adobe Gamma Loader.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^MIKE^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=c:\users\MIKE\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=c:\windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
2010-06-09 08:06 976832 ----a-w- c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2010-06-20 02:04 35760 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG9_TRAY]
2010-07-16 12:40 2065760 ----a-w- c:\progra~1\AVG\AVG9\avgtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2008-10-25 16:44 31072 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
2008-06-06 18:52 1832232 ----a-w- c:\program files\Common Files\Nero\Lib\NMIndexStoreSvr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
2009-07-26 21:44 3883856 ----a-w- c:\program files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2009-03-06 16:52 13605408 ----a-w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2009-03-06 16:52 92704 ----a-w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OrderReminder]
2006-01-30 16:00 98304 ----a-r- c:\program files\Hewlett-Packard\OrderReminder\OrderReminder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSDiagnosticM]
2007-02-27 21:29 315392 ----a-w- c:\program files\Linksys Wireless-G Print Server\PSDiagnosticM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh]
2008-03-28 07:05 1045800 ----a-w- c:\program files\Synaptics\SynTP\SynTPEnh.exe