2010-10-12 02:15 . 2010-10-12 02:15 552 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\7B2238AACCEDC3F1FFE8E7EB5F575EC9
2010-10-12 02:15 . 2010-10-12 02:15 132 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\7B2238AACCEDC3F1FFE8E7EB5F575EC9
2010-10-12 02:15 . 2010-10-12 02:15 528 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\E04822AD18D472EA5B582E6E6F8C6B9A
2010-10-12 02:15 . 2010-10-12 02:15 140 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\E04822AD18D472EA5B582E6E6F8C6B9A
2010-10-12 00:07 . 2010-10-12 00:07 518 ----a-w- c:\documents and settings\Admin\Recent\10102010_114759 (3).lnk
2010-10-12 00:02 . 2010-10-12 00:02 415 ----a-w- c:\documents and settings\Admin\Recent\aaw7boot.lnk
2010-10-11 23:43 . 2010-10-11 23:43 518 ----a-w- c:\documents and settings\Admin\Recent\10102010_114759 (2).lnk
2010-10-11 23:40 . 2010-10-11 23:40 518 ----a-w- c:\documents and settings\Admin\Recent\10102010_114759.lnk
2010-10-11 23:39 . 2010-10-11 23:34 32768 --sha-w- c:\documents and settings\Admin\Local Settings\History\History.IE5\MSHist012010100420101011\index.dat
2010-10-10 16:03 . 2010-10-12 01:53 293 ----a-w- c:\documents and settings\Admin\Recent\Local Disk (C).lnk
2010-10-10 16:02 . 2010-10-10 16:02 269 ----a-w- c:\documents and settings\Admin\Recent\error.lnk
2010-10-10 15:51 . 2010-10-10 15:51 4108 ----a-w- c:\documents and settings\Admin\Desktop\10102010_114759.log
2010-10-10 15:46 . 2010-10-10 15:43 253 ----a-w- c:\documents and settings\Admin\Desktop\filepaths.txt
2010-10-10 15:46 . 2010-10-22 02:38 186 ----a-w- c:\documents and settings\Admin\Recent\TOSHIBA (E).lnk
2010-10-10 15:46 . 2010-10-10 15:44 1211285 ----a-w- c:\documents and settings\Admin\Desktop\tdsskiller.zip
2010-10-10 15:46 . 2010-10-10 15:43 519680 ----a-w- c:\documents and settings\Admin\Desktop\OTM.exe
2010-10-10 02:43 . 2010-10-10 02:43 399 ----a-w- c:\documents and settings\Admin\Recent\services 4.lnk
2010-10-10 02:43 . 2010-10-10 02:43 181140 ----a-w- c:\documents and settings\Admin\Desktop\services 4.JPG
2010-10-10 02:43 . 2010-10-10 02:43 168479 ----a-w- c:\documents and settings\Admin\Desktop\services 3.JPG
2010-10-10 02:43 . 2010-10-10 02:43 399 ----a-w- c:\documents and settings\Admin\Recent\services 3.lnk
2010-10-10 02:43 . 2010-10-10 02:43 399 ----a-w- c:\documents and settings\Admin\Recent\services 2.lnk
2010-10-10 02:43 . 2010-10-10 02:43 157192 ----a-w- c:\documents and settings\Admin\Desktop\services 2.JPG
2010-10-10 02:42 . 2010-10-10 02:42 387 ----a-w- c:\documents and settings\Admin\Recent\services.lnk
2010-10-10 02:42 . 2010-10-10 02:42 152360 ----a-w- c:\documents and settings\Admin\Desktop\services.JPG
2010-10-10 02:33 . 2010-10-10 02:33 15 ----a-w- c:\documents and settings\Admin\resetlog.txt
2010-10-10 02:19 . 2010-10-10 02:19 602 ----a-w- c:\documents and settings\Admin\Recent\DW WLAN Card.lnk
2010-10-10 02:19 . 2010-10-10 02:19 620 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\DW WLAN Card.LNK
2010-10-10 02:19 . 2010-10-10 02:19 723 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\Readme.LNK
2010-10-10 02:19 . 2010-10-10 02:19 775 ----a-w- c:\documents and settings\Admin\Recent\Readme.lnk
2010-10-10 02:15 . 2010-10-09 17:22 24750424 ----a-w- c:\documents and settings\Admin\Desktop\R138226.EXE
2010-10-10 02:15 . 2010-10-09 17:27 119415640 ----a-w- c:\documents and settings\Admin\Desktop\R242906.exe
2010-10-10 02:15 . 2010-10-09 17:23 5002248 ----a-w- c:\documents and settings\Admin\Desktop\R116101.EXE
2010-10-10 02:12 . 2010-10-12 02:18 261 ----a-w- c:\documents and settings\Admin\Recent\log.lnk
2010-10-10 02:07 . 2010-10-10 02:10 14373 ----a-w- c:\documents and settings\Admin\Desktop\Attach.txt
2010-10-10 02:07 . 2010-10-10 02:09 7134 ----a-w- c:\documents and settings\Admin\Desktop\DDS.txt
2010-10-10 01:30 . 2010-10-10 01:30 893 ----a-w- c:\documents and settings\Admin\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-2010-10-09 (21-30-19).txt
2010-10-10 01:30 . 2010-10-10 01:30 1684 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Word12.pip
2010-10-10 01:30 . 2010-10-10 01:30 15403 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Templates\Normal.dotm
2010-10-10 01:30 . 2010-10-10 01:30 766 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\Templates.LNK
2010-10-10 01:30 . 2010-10-10 02:19 119 ---h--w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\index.dat
2010-10-10 01:30 . 2010-10-10 01:30 731 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\changes.LNK
2010-10-10 01:30 . 2010-10-10 01:30 623 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Recent\Malwarebytes' Anti-Malware.LNK
2010-10-10 01:29 . 2006-10-27 13:32 322380 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Document Building Blocks\1033\Building Blocks.dotx
2010-10-10 01:29 . 2010-10-10 01:29 37814 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\MSO1033.acl
2010-10-10 01:29 . 2010-10-10 01:30 605 ----a-w- c:\documents and settings\Admin\Recent\Malwarebytes' Anti-Malware.lnk
2010-10-10 01:29 . 2010-10-10 01:30 801 ----a-w- c:\documents and settings\Admin\Recent\changes.lnk
2010-10-10 01:23 . 2010-10-10 01:23 3446 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions.rdf
2010-10-10 01:23 . 2010-10-10 01:23 430 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions.ini
2010-10-10 01:23 . 2010-10-10 01:23 582 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions.cache
2010-10-10 01:23 . 2009-03-18 18:40 2005 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome.manifest
2010-10-10 01:23 . 2009-03-18 18:40 1271 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\install.rdf
2010-10-10 01:23 . 2009-03-18 18:40 27394 -c--a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\chrome\chrome_user.jar
2010-10-10 01:23 . 2009-03-18 18:40 424 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}\defaults\preferences\defaults.js
2010-10-10 01:22 . 2010-10-10 01:22 7226 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\tabiconcache.dat
2010-10-10 01:21 . 2010-10-18 05:39 3584 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\Recovery\Last Active\RecoveryStore.{C0808B3E-D40C-11DF-8839-0015C543FF13}.dat
2010-10-10 01:21 . 2010-10-15 02:56 171 ----a-w- c:\documents and settings\Admin\Cookies\admin@kontera[2].txt
2010-10-10 01:21 . 2010-10-10 01:21 177 ----a-w- c:\documents and settings\Admin\Cookies\admin@demdex[1].txt
2010-10-10 01:21 . 2010-10-15 03:18 444 ----a-w- c:\documents and settings\Admin\Cookies\admin@atdmt[1].txt
2010-10-10 01:21 . 2010-10-10 01:21 108 ----a-w- c:\documents and settings\Admin\Cookies\admin@imageshack[1].txt
2010-10-10 01:21 . 2010-10-10 01:21 202 ----a-w- c:\documents and settings\Admin\Cookies\admin@abmr[2].txt
2010-10-10 01:21 . 2010-10-10 01:21 78 ----a-w- c:\documents and settings\Admin\Cookies\admin@apture[1].txt
2010-10-10 01:21 . 2010-10-10 01:21 123 ----a-w- c:\documents and settings\Admin\Cookies\admin@doubleclick[1].txt
2010-10-10 01:21 . 2010-10-10 01:21 394 ----a-w- c:\documents and settings\Admin\Cookies\admin@collective-media[1].txt
2010-10-10 01:20 . 2010-10-10 01:20 868352 --sha-w- c:\documents and settings\Admin\IECompatCache\index.dat
2010-10-10 01:17 . 2010-10-10 01:17 4220 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\bookmarkbackups\bookmarks-2010-10-09.json
2010-10-10 00:59 . 2010-10-10 02:09 452 ----a-w- c:\documents and settings\Admin\Recent\msg.lnk
2010-10-10 00:36 . 2010-10-10 01:16 1111 ----a-w- c:\documents and settings\Admin\Desktop\log.txt
2010-10-10 00:36 . 2010-10-10 00:36 898 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\60E31627FDA0A46932B0E5948949F2A5
2010-10-10 00:36 . 2010-10-10 00:36 94 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\60E31627FDA0A46932B0E5948949F2A5
2010-10-10 00:35 . 2010-10-10 00:35 95984 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\A8FABA189DB7D25FBA7CAC806625FD30
2010-10-10 00:35 . 2010-10-10 00:35 124 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\A8FABA189DB7D25FBA7CAC806625FD30
2010-10-10 00:35 . 2010-10-10 00:35 32042 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\94308059B57B3142E455B38A6EB92015
2010-10-10 00:35 . 2010-10-10 00:35 216 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\94308059B57B3142E455B38A6EB92015
2010-10-10 00:35 . 2010-10-10 00:35 18 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\2BF68F4714092295550497DD56F57004
2010-10-10 00:35 . 2010-10-10 00:35 216 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\2BF68F4714092295550497DD56F57004
2010-10-10 00:33 . 2010-10-10 00:33 549 ----a-w- c:\documents and settings\Admin\Cookies\admin@microsoft[1].txt
2010-10-10 00:32 . 2010-10-10 00:34 585 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Symantec\Symantec AntiVirus Corporate Edition\7.5\Logs\10092010.Log
2010-10-10 00:30 . 2010-10-10 02:12 471 ----a-w- c:\documents and settings\Admin\Recent\Attach.lnk
2010-10-10 00:30 . 2010-10-11 23:40 452 ----a-w- c:\documents and settings\Admin\Recent\DDS.lnk
2010-10-10 00:26 . 2010-10-15 02:29 8590 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\HTML Help\hh.dat
2010-10-10 00:24 . 2010-10-10 00:24 75312 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-10-09 17:58 . 2010-10-10 01:24 2048 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\downloads.sqlite
2010-10-09 17:57 . 2010-10-18 05:02 154 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\urlclassifierkey3.txt
2010-10-09 17:57 . 2010-10-09 17:57 11264 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\signons.sqlite
2010-10-09 17:57 . 2010-10-09 17:57 7168 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\content-prefs.sqlite
2010-10-09 17:57 . 2010-10-18 05:02 16384 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\key3.db
2010-10-09 17:57 . 2010-10-18 05:02 65536 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\cert8.db
2010-10-09 17:57 . 2010-10-09 17:57 16384 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\secmod.db
2010-10-09 17:57 . 2010-10-18 05:02 8192 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\cookies.sqlite
2010-10-09 17:57 . 2010-10-10 01:25 4096 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\formhistory.sqlite
2010-10-09 17:57 . 2010-10-09 17:57 11719 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\search.json
2010-10-09 17:57 . 2010-10-10 01:25 2048 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\search.sqlite
2010-10-09 17:57 . 2010-10-18 05:02 9681 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\pluginreg.dat
2010-10-09 17:57 . 2010-10-09 17:57 3406 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\mimeTypes.rdf
2010-10-09 17:57 . 2010-10-10 01:29 188416 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\places.sqlite
2010-10-09 17:57 . 2010-10-18 05:02 0 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\places.sqlite-journal
2010-10-09 17:57 . 2010-10-09 17:57 2048 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\permissions.sqlite
2010-10-09 17:57 . 2010-10-10 01:23 147032 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\compreg.dat
2010-10-09 17:57 . 2010-10-10 01:23 101604 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\xpti.dat
2010-10-09 17:57 . 2010-10-09 17:57 187 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\compatibility.ini
2010-10-09 17:57 . 2010-04-01 15:56 663 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\chrome\userContent-example.css
2010-10-09 17:57 . 2010-04-01 15:56 959 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\chrome\userChrome-example.css
2010-10-09 17:57 . 2010-04-01 15:56 6284 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\bookmarks.html
2010-10-09 17:57 . 2010-10-09 17:57 111 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\profiles.ini
2010-10-09 17:57 . 2010-10-09 17:57 10 ----a-w- c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Crash Reports\InstallTime20100401080539
2010-10-09 17:39 . 2010-10-09 17:39 1150 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
2010-10-09 17:39 . 2010-10-09 17:39 289 ----a-w- c:\documents and settings\Admin\Cookies\admin@www.microsoft[2].txt
2010-10-09 17:39 . 2010-10-09 17:39 15654 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\D725F3459E2275E9EA5871B92AD896D0
2010-10-09 17:39 . 2010-10-09 17:39 110 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\D725F3459E2275E9EA5871B92AD896D0
2010-10-09 17:39 . 2010-10-09 17:39 840 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\Content\FB788E090BC1F3AA2FBC9E8FB2859601
2010-10-09 17:39 . 2010-10-09 17:39 134 --s-a-w- c:\documents and settings\Admin\Application Data\Microsoft\CryptnetUrlCache\MetaData\FB788E090BC1F3AA2FBC9E8FB2859601
2010-10-09 17:39 . 2010-10-09 17:39 0 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\L4XUX3F5\ieonline.microsoft[1]
2010-10-09 17:39 . 2010-10-10 01:22 32768 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Suggested Sites~.feed-ms
2010-10-09 17:39 . 2010-10-09 17:39 302 ----a-w- c:\documents and settings\Admin\Favorites\Links\Suggested Sites.url
2010-10-09 17:38 . 2010-10-09 17:38 16384 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\MSIMGSIZ.DAT
2010-10-09 17:38 . 2010-10-18 05:36 180224 --sha-w- c:\documents and settings\Admin\PrivacIE\index.dat
2010-10-09 17:34 . 2010-10-09 17:34 3584 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2010-10-09 17:34 . 2010-10-09 17:34 24 --sha-w- c:\documents and settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-839522115-688789844-725345543-1004\Preferred
2010-10-09 17:34 . 2010-10-09 17:34 388 --sha-w- c:\documents and settings\Admin\Application Data\Microsoft\Protect\S-1-5-21-839522115-688789844-725345543-1004\94815c83-27ce-411d-b4c9-4538c9fbb8a5
2010-10-09 17:34 . 2010-10-09 17:34 24 --sha-w- c:\documents and settings\Admin\Application Data\Microsoft\Protect\CREDHIST
2010-10-09 16:54 . 2010-10-22 02:45 3767034 ---ha-w- c:\documents and settings\Admin\Local Settings\Application Data\IconCache.db
2010-10-09 16:53 . 2010-10-18 04:00 6141 ----a-w- c:\documents and settings\Admin\reset.log
2010-10-09 16:36 . 2010-10-26 03:24 144 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Office\Groove12.pip
2010-10-09 16:35 . 2010-10-09 16:35 7917 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.bak
2010-10-09 16:35 . 2010-10-09 16:35 0 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\HHC01VB0\fwlink[1]
2010-10-09 16:35 . 2010-10-09 16:35 28672 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds\{5588ACFD-6436-411B-A5CE-666AE6A92D3D}~\WebSlices~\Web Slice Gallery~.feed-ms
2010-10-09 16:35 . 2010-10-09 16:35 226 ----a-w- c:\documents and settings\Admin\Favorites\Links\Web Slice Gallery.url
2010-10-09 16:35 . 2010-10-09 16:35 0 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\P36MHRD2\fwlink[1]
2010-10-09 16:35 . 2010-10-09 16:35 28672 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Work~.feed-ms
2010-10-09 16:35 . 2010-10-09 16:35 0 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\0IBNNJ8D\fwlink[1]
2010-10-09 16:35 . 2010-10-10 01:22 5632 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds\FeedsStore.feedsdb-ms
2010-10-09 16:35 . 2010-10-09 16:35 28672 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds\Microsoft Feeds~\Microsoft at Home~.feed-ms
2010-10-09 16:35 . 2010-10-09 16:35 67 --sh--w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\L4XUX3F5\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 67 --sh--w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\0IBNNJ8D\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 67 --sh--w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\HHC01VB0\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 67 --sh--w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\P36MHRD2\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 67 --sh--w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\desktop.ini
2010-10-09 16:35 . 2010-10-18 05:36 32768 --sha-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Feeds Cache\index.dat
2010-10-09 16:35 . 2010-10-09 16:35 84 --sha-w- c:\documents and settings\Admin\Favorites\Links\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 134 ----a-w- c:\documents and settings\Admin\Favorites\Microsoft Websites\Microsoft Store.url
2010-10-09 16:35 . 2010-10-09 16:35 133 ----a-w- c:\documents and settings\Admin\Favorites\Microsoft Websites\Microsoft At Work.url
2010-10-09 16:35 . 2010-10-09 16:35 133 ----a-w- c:\documents and settings\Admin\Favorites\Microsoft Websites\Microsoft At Home.url
2010-10-09 16:35 . 2010-10-09 16:35 133 ----a-w- c:\documents and settings\Admin\Favorites\Microsoft Websites\IE Add-on site.url
2010-10-09 16:35 . 2010-10-09 16:35 133 ----a-w- c:\documents and settings\Admin\Favorites\Microsoft Websites\IE site on Microsoft.com.url
2010-10-09 16:35 . 2010-10-09 16:35 7801 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Internet Explorer\brndlog.txt
2010-10-09 16:35 . 2010-10-09 16:35 815 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
2010-10-09 16:35 . 2010-10-09 16:35 803 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Internet Explorer.lnk
2010-10-09 16:35 . 2010-10-09 16:35 833 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\System Tools\Internet Explorer (No Add-ons).lnk
2010-10-09 16:35 . 2010-10-09 16:35 122 --sha-w- c:\documents and settings\Admin\Favorites\Desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 60 --sh--w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 150 --sha-w- c:\documents and settings\Admin\Recent\Desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 79 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
2010-10-09 16:35 . 2010-10-09 16:35 774 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Address Book.lnk
2010-10-09 16:35 . 2010-10-09 16:35 738 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Outlook Express.lnk
2010-10-09 16:35 . 2010-10-09 16:35 2572 --sha-w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\Desktop.htt
2010-10-09 16:35 . 2010-10-09 16:35 0 ----a-w- c:\documents and settings\Admin\SendTo\My Documents.mydocs
2010-10-09 16:35 . 2010-10-09 16:35 638 ----a-w- c:\documents and settings\Admin\My Documents\My Music\Sample Music.lnk
2010-10-09 16:35 . 2010-10-09 16:35 181 --sha-w- c:\documents and settings\Admin\My Documents\My Music\Desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 668 ----a-w- c:\documents and settings\Admin\My Documents\My Pictures\Sample Pictures.lnk
2010-10-09 16:35 . 2010-10-09 16:35 183 --sha-w- c:\documents and settings\Admin\My Documents\My Pictures\Desktop.ini
2010-10-09 16:35 . 2010-10-09 16:35 76 --sha-w- c:\documents and settings\Admin\My Documents\desktop.ini
2010-10-09 16:35 . 2010-10-15 03:50 245760 --sha-w- c:\documents and settings\Admin\IETldCache\index.dat
2010-10-09 16:35 . 2010-10-22 02:45 178 --sh--w- c:\documents and settings\Admin\ntuser.ini
2010-10-09 16:35 . 2010-10-18 05:40 262144 ---ha-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat
2010-10-09 16:35 . 2010-10-26 03:24 1024 ---ha-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG
2010-10-09 16:35 . 2009-03-16 22:51 62 --sha-w- c:\documents and settings\Admin\Application Data\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:46 113 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\brndlog.bak
2010-10-09 16:35 . 2009-03-17 05:46 141 ----a-w- c:\documents and settings\Admin\Application Data\Microsoft\Internet Explorer\brndlog.txt
2010-10-09 16:35 . 2009-03-17 05:46 498 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.DTD
2010-10-09 16:35 . 2010-10-26 03:45 32768 ----a-w- c:\documents and settings\Admin\Cookies\index.dat
2010-10-09 16:35 . 2009-03-17 05:46 720896 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Media Player\CurrentDatabase_59R.wmdb
2010-10-09 16:35 . 2009-03-17 05:46 12784 ----a-w- c:\documents and settings\Admin\Local Settings\Application Data\Microsoft\Windows Media\9.0\WMSDKNS.XML
2010-10-09 16:35 . 2010-10-10 01:20 67 --sh--w- c:\documents and settings\Admin\Local Settings\History\History.IE5\desktop.ini
2010-10-09 16:35 . 2010-10-26 03:24 62 --sha-w- c:\documents and settings\Admin\Local Settings\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:50 113 --sha-w- c:\documents and settings\Admin\Local Settings\History\desktop.ini
2010-10-09 16:35 . 2010-10-26 03:45 65536 ----a-w- c:\documents and settings\Admin\Local Settings\History\History.IE5\index.dat
2010-10-09 16:35 . 2009-03-17 05:45 0 ----a-w- c:\documents and settings\Admin\SendTo\Compressed (zipped) Folder.ZFSendToTarget
2010-10-09 16:35 . 2009-03-17 05:45 0 ----a-w- c:\documents and settings\Admin\SendTo\Desktop (create shortcut).DeskLink
2010-10-09 16:35 . 2009-03-17 05:45 181 --sha-w- c:\documents and settings\Admin\SendTo\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:45 0 ----a-w- c:\documents and settings\Admin\SendTo\Mail Recipient.MAPIMail
2010-10-09 16:35 . 2009-03-16 22:51 62 --sha-w- c:\documents and settings\Admin\Start Menu\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:46 348 --sha-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Accessibility\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:46 1525 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Accessibility\Magnifier.lnk
2010-10-09 16:35 . 2009-03-17 05:46 1532 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Accessibility\Narrator.lnk
2010-10-09 16:35 . 2009-03-17 05:46 1501 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Accessibility\On-Screen Keyboard.lnk
2010-10-09 16:35 . 2009-03-17 05:46 1555 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Command Prompt.lnk
2010-10-09 16:35 . 2010-10-09 16:35 542 --sha-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:46 1539 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Accessibility\Utility Manager.lnk
2010-10-09 16:35 . 2010-10-10 00:58 1519 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Notepad.lnk
2010-10-09 16:35 . 2009-03-17 05:46 386 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Program Compatibility Wizard.lnk
2010-10-09 16:35 . 2009-03-17 05:46 84 --sha-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Entertainment\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:46 1519 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Synchronize.lnk
2010-10-09 16:35 . 2010-10-09 16:35 804 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Entertainment\Windows Media Player.lnk
2010-10-09 16:35 . 2009-03-17 05:46 1527 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Tour Windows XP.lnk
2010-10-09 16:35 . 2010-10-09 16:35 190 --sha-w- c:\documents and settings\Admin\Start Menu\Programs\desktop.ini
2010-10-09 16:35 . 2009-03-17 05:45 1487 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Accessories\Windows Explorer.lnk
2010-10-09 16:35 . 2009-03-17 05:46 1599 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Remote Assistance.lnk
2010-10-09 16:35 . 2010-10-09 16:35 792 ----a-w- c:\documents and settings\Admin\Start Menu\Programs\Windows Media Player.lnk
2010-10-09 16:35 . 2004-08-04 10:00 4570 ----a-w- c:\documents and settings\Admin\Templates\amipro.sam
2010-10-09 16:35 . 2004-08-04 10:00 5632 ----a-w- c:\documents and settings\Admin\Templates\excel.xls
2010-10-09 16:35 . 2004-08-04 10:00 1518 ----a-w- c:\documents and settings\Admin\Templates\excel4.xls
2010-10-09 16:35 . 2009-03-17 05:46 84 --sha-w- c:\documents and settings\Admin\Start Menu\Programs\Startup\desktop.ini
2010-10-09 16:35 . 2004-08-04 10:00 2448 ----a-w- c:\documents and settings\Admin\Templates\lotus.wk4
2010-10-09 16:35 . 2004-08-04 10:00 12288 ----a-w- c:\documents and settings\Admin\Templates\powerpnt.ppt
2010-10-09 16:35 . 2004-08-04 10:00 461 ----a-w- c:\documents and settings\Admin\Templates\presenta.shw
2010-10-09 16:35 . 2004-08-04 10:00 4017 ----a-w- c:\documents and settings\Admin\Templates\quattro.wb2
2010-10-09 16:35 . 2004-08-04 10:00 58 ----a-w- c:\documents and settings\Admin\Templates\sndrec.wav
2010-10-09 16:35 . 2004-08-04 10:00 4608 ----a-w- c:\documents and settings\Admin\Templates\winword.doc
2010-10-09 16:35 . 2004-08-04 10:00 1769 ----a-w- c:\documents and settings\Admin\Templates\winword2.doc
2010-10-09 16:35 . 2004-08-04 10:00 30 ----a-r- c:\documents and settings\Admin\Templates\wordpfct.wpd
2010-10-09 16:35 . 2004-08-04 10:00 57 ----a-r- c:\documents and settings\Admin\Templates\wordpfct.wpg
2010-10-09 16:35 . 2010-10-26 03:49 1024 ---ha-w- c:\documents and settings\Admin\Ntuser.dat.LOG
2010-10-09 16:35 . 2010-10-26 03:47 1572864 ---ha-w- c:\documents and settings\Admin\NTUSER.DAT
2010-10-04 13:08 . 2010-10-04 13:08 1325656 ----a-w- c:\documents and settings\Admin\Desktop\TDSSKiller.exe
2010-05-17 20:15 . 2010-05-17 20:15 2258 ----a-w- c:\documents and settings\Admin\Desktop\tdsskiller\eula.txt
((((((((((((((((((((((((((((( SnapShot@2010-10-12_02.15.04 )))))))))))))))))))))))))))))))))))))))))
.
+ 2010-10-18 04:46 . 2009-10-07 19:01 2649216 c:\windows\system32\ReinstallBackups\0018\DriverFiles\BCMWL5.SYS
- 2010-10-10 02:17 . 2009-10-07 19:01 2649216 c:\windows\system32\ReinstallBackups\0018\DriverFiles\BCMWL5.SYS
+ 2010-10-26 03:43 . 2010-10-26 03:43 1094656 c:\windows\Installer\11ebc8.msi
+ 2009-07-10 00:57 . 2010-10-15 13:05 35385288 c:\windows\system32\MRT.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2009-10-07 2498560]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Ad-Watch]
2010-04-11 03:38 524632 ----a-w- c:\program files\Lavasoft\Ad-Aware\AAWTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
2005-09-09 05:18 57344 ----a-w- c:\program files\Adobe\Photoshop Elements 4.0\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2009-02-27 22:10 35696 ----a-w- c:\program files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater6]
2009-01-08 12:36 2521464 ----a-w- c:\program files\Common Files\Adobe\Updater6\Adobe_Updater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Boingo Wi-Fi]
2010-10-06 04:57 2179 -c--a-w- c:\program files\Boingo\Boingo Wi-Fi\Boingo.lnk
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Broadcom Wireless Manager UI]
2009-10-07 19:01 2498560 ----a-w- c:\windows\system32\WLTRAY.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
2006-07-20 00:26 52896 ----a-w- c:\program files\Common Files\Symantec Shared\ccApp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2004-08-04 10:00 15360 ----a-w- c:\windows\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DLA]
2005-09-08 10:20 122940 ----a-w- c:\windows\system32\DLA\DLACTRLW.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DVDLauncher]
2005-12-10 01:29 49152 ------w- c:\program files\CyberLink\PowerDVD\DVDLauncher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\googletalk]
2007-01-01 21:22 3739648 ----a-w- c:\program files\Google\Google Talk\googletalk.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
2006-10-27 05:47 31016 ----a-w- c:\program files\Microsoft Office\Office12\GrooveMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 21:50 221184 ----a-w- c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 21:50 81920 ----a-w- c:\program files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
2010-06-15 20:33 141624 ----a-w- c:\program files\iTunes\iTunesHelper.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Malwarebytes Anti-Malware (reboot)]
2010-04-29 19:39 1090952 ----a-w- c:\program files\Malwarebytes' Anti-Malware\mbam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-01-19 14:14 7401472 ----a-w- c:\windows\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NVHotkey]
2006-01-19 14:14 73728 ----a-w- c:\windows\system32\nvhotkey.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-01-19 14:14 1519616 ----a-w- c:\windows\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2010-03-19 02:16 421888 ----a-w- c:\program files\QuickTime\QTTask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SigmatelSysTrayApp]
2006-03-24 22:30 282624 ----a-w- c:\windows\stsystra.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
2009-04-01 04:05 148888 ----a-w- c:\program files\Java\jre6\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
2006-09-28 01:33 125168 ----a-w- c:\progra~1\SYMANT~1\VPTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zinio DLM]
2009-07-21 18:02 2707526 ----a-w- c:\program files\Zinio\ZinioReader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"PlugPlay"=2 (0x2)
"Netman"=2 (0x2)
"CryptSvc"=3 (0x3)
"AudioSrv"=2 (0x2)
"aspnet_state"=3 (0x3)
"AppMgmt"=3 (0x3)
"Apple Mobile Device"=2 (0x2)
"ALG"=3 (0x3)
"ADVService"=2 (0x2)
"AdobeActiveFileMonitor4.0"=2 (0x2)
"ACDaemon"=3 (0x3)
"xmlprov"=3 (0x3)
"WZCSVC"=2 (0x2)
"wuauserv"=2 (0x2)
"wscsvc"=2 (0x2)
"WmiApSrv"=3 (0x3)
"Wmi"=3 (0x3)
"WmdmPmSN"=3 (0x3)
"wltrysvc"=2 (0x2)
"winmgmt"=2 (0x2)
"WebClient"=2 (0x2)
"W32Time"=2 (0x2)
"VSS"=3 (0x3)
"UPS"=3 (0x3)
"upnphost"=2 (0x2)
"TlntSvr"=3 (0x3)
"Themes"=2 (0x2)
"TermService"=3 (0x3)
"TapiSrv"=3 (0x3)
"SysmonLog"=3 (0x3)
"Symantec AntiVirus"=2 (0x2)
"SwPrv"=3 (0x3)
"stisvc"=3 (0x3)
"SSDPSRV"=3 (0x3)
"srservice"=2 (0x2)
"Spooler"=2 (0x2)
"SNDSrvc"=2 (0x2)
"ShellHWDetection"=2 (0x2)
"SharedAccess"=2 (0x2)
"SENS"=2 (0x2)
"seclogon"=2 (0x2)
"Schedule"=2 (0x2)
"SCardSvr"=3 (0x3)
"SamSs"=2 (0x2)
"RSVP"=3 (0x3)
"RemoteRegistry"=2 (0x2)
"RemoteAccess"=3 (0x3)
"RDSessMgr"=3 (0x3)
"RasMan"=3 (0x3)
"RasAuto"=3 (0x3)
"ProtectedStorage"=2 (0x2)
"PolicyAgent"=2 (0x2)
"odserv"=2 (0x2)
"NtmsSvc"=3 (0x3)
"NtLmSsp"=3 (0x3)
"Nla"=2 (0x2)
"Netlogon"=3 (0x3)
"NetDDEdsdm"=3 (0x3)
"NetDDE"=3 (0x3)
"MSIServer"=3 (0x3)
"mnmsrvc"=3 (0x3)
"Messenger"=2 (0x2)
"LmHosts"=2 (0x2)
"lanmanworkstation"=2 (0x2)
"lanmanserver"=2 (0x2)
"helpsvc"=2 (0x2)
"EventSystem"=3 (0x3)
"Eventlog"=2 (0x2)
"ERSvc"=2 (0x2)
"Dnscache"=2 (0x2)
"dmserver"=3 (0x3)
"dmadmin"=3 (0x3)
"Dhcp"=2 (0x2)
"DefWatch"=2 (0x2)
"COMSysApp"=3 (0x3)
"ClipSrv"=3 (0x3)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Browser"=2 (0x2)
"BITS"=3 (0x3)
"Alerter"=3 (0x3)
"TrkWks"=2 (0x2)
"SavRoam"=2 (0x2)
"MSDTC"=3 (0x3)
"HTTPFilter"=3 (0x3)
"FastUserSwitchingCompatibility"=3 (0x3)
"CiSvc"=3 (0x3)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\GROOVE.EXE"=
"c:\\Program Files\\Microsoft Office\\Office12\\ONENOTE.EXE"=
"c:\\Program Files\\QuickTime\\QuickTimePlayer.exe"=
"c:\\Program Files\\Google\\Google Talk\\googletalk.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Citrix\\Secure Access Client\\nsload.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [3/17/2009 3:13 AM 64160]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [10/1/2010 8:06 PM 102448]
R3 Net6IM;Net6;c:\windows\system32\drivers\net6im51.sys [3/18/2009 12:19 PM 73368]
S3 NWUSBCDFIL;Novatel Wireless Installation CD;c:\windows\system32\drivers\NwUsbCdFil.sys [12/18/2009 12:13 PM 20480]
S3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver;c:\windows\system32\drivers\nwusbser2.sys [12/18/2009 12:12 PM 174720]
S3 SMSIVZAM5;SMSIVZAM5 NDIS Protocol Driver;c:\progra~1\VERIZO~1\VZACCE~1\SMSIVZAM5.SYS [5/25/2009 3:43 PM 32408]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06 PM 1029456]
S4 nsverctl;Citrix Secure Access Client Service;c:\program files\Citrix\Secure Access Client\nsverctl.exe [3/18/2009 12:19 PM 139264]
S4 SavRoam;SAVRoam;c:\program files\Symantec AntiVirus\SavRoam.exe [9/27/2006 9:33 PM 116464]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
.
Contents of the 'Scheduled Tasks' folder
2010-10-05 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 03:38]
.
.
------- Supplementary Scan -------
.
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
DPF: {3F777025-3835-4117-B9FA-5E5230669310} - hxxps://law.lexisnexis.com/resources/fyi/dataflight_fyi.cab
FF - ProfilePath - c:\documents and settings\Admin\Application Data\Mozilla\Firefox\Profiles\d1gk3n47.default\
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(560)
c:\windows\System32\BCMLogon.dll
- - - - - - - > 'explorer.exe'(1944)
c:\windows\system32\WININET.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\MSVCR80.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\msi.dll
c:\windows\system32\webcheck.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\msiexec.exe
c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe
.
**************************************************************************
.
Completion time: 2010-10-26 00:01:43 - machine was rebooted
ComboFix-quarantined-files.txt 2010-10-26 04:01
ComboFix2.txt 2010-10-22 02:29
ComboFix3.txt 2010-10-12 02:17
Pre-Run: 25,956,585,472 bytes free
Post-Run: 25,909,669,888 bytes free
- - End Of File - - 53E477F1CE40061D5BF09247E25218EA
Check this Seevice: Start> Run> type in services.msc> Double click on Cryptography Services> should be set to Automatic Startup Type and Started. If it is not, set it that way. Then check Remote Procedure Call> should also be set to Automatic/Start.
I changed the settings on those two services. Would it be helpful for me to take a screenshot of all my services/settings in services.msc and post it?
Also, just to be sure, I am still using (and will continue to use) the Selective Startup in the System Config Utility. The only item that is checked under the startup tab is "WLTRAY". Everything else is disabled. Is this the correct setting?
Thanks again for your help. Sorry this is such a pain!!