c:\windows\system32\_003692_.tmp.dll
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003700_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003725_.tmp.dll
c:\windows\system32\_003726_.tmp.dll
c:\windows\system32\_006755_.tmp.dll
c:\windows\system32\_006756_.tmp.dll
c:\windows\system32\_006757_.tmp.dll
c:\windows\system32\_006758_.tmp.dll
c:\windows\system32\_006765_.tmp.dll
c:\windows\system32\_006766_.tmp.dll
c:\windows\system32\_006767_.tmp.dll
c:\windows\system32\_006769_.tmp.dll
c:\windows\system32\_006770_.tmp.dll
c:\windows\system32\_006773_.tmp.dll
c:\windows\system32\_006774_.tmp.dll
c:\windows\system32\_006776_.tmp.dll
c:\windows\system32\_006777_.tmp.dll
c:\windows\system32\_006778_.tmp.dll
c:\windows\system32\_006780_.tmp.dll
c:\windows\system32\_006783_.tmp.dll
c:\windows\system32\_006784_.tmp.dll
c:\windows\system32\_006788_.tmp.dll
c:\windows\system32\_006789_.tmp.dll
c:\windows\system32\_006791_.tmp.dll
c:\windows\system32\_006794_.tmp.dll
c:\windows\system32\_006796_.tmp.dll
c:\windows\system32\_006797_.tmp.dll
c:\windows\system32\_006798_.tmp.dll
c:\windows\system32\_006799_.tmp.dll
c:\windows\system32\_006802_.tmp.dll
c:\windows\system32\_006803_.tmp.dll
c:\windows\system32\_006804_.tmp.dll
c:\windows\system32\_006805_.tmp.dll
c:\windows\system32\_006806_.tmp.dll
c:\windows\system32\_006811_.tmp.dll
c:\windows\system32\_006813_.tmp.dll
c:\windows\system32\_006814_.tmp.dll
c:\windows\twain_16.dll
.
((((((((((((((((((((((((( Files Created from 2010-08-08 to 2010-09-08 )))))))))))))))))))))))))))))))
.
2010-09-06 20:59 . 2010-09-06 20:59 -------- d-----w- C:\_OTM
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\windows\system32\wbem\Repository
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\Reno 911 Paintball
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\G-Force
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\BitTorrent
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Gwen\Application Data\Viewpoint
2010-09-03 03:56 . 2010-09-03 03:56 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-09-02 00:58 . 2010-09-02 00:58 -------- d-----w- c:\documents and settings\Family\Application Data\Registry Mechanic
2010-08-31 20:50 . 2010-08-31 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-08-28 19:38 . 2010-08-28 19:40 -------- d-----w- c:\documents and settings\Family\Application Data\QuickScan
2010-08-27 21:22 . 2010-09-03 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-08-23 05:10 . 2010-08-23 05:10 -------- d-----w- c:\program files\The Weather Channel FW
2010-08-21 07:13 . 2010-08-21 07:13 -------- d-----w- c:\documents and settings\Gwen\Local Settings\Application Data\Threat Expert
2010-08-21 06:30 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-21 06:28 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-21 02:40 . 2010-08-21 02:40 -------- d-----w- c:\program files\MSSOAP
2010-08-21 02:39 . 2010-08-21 02:39 164 ----a-w- c:\windows\install.dat
2010-08-19 00:53 . 2010-08-19 00:53 -------- d-----w- c:\program files\MSBuild
2010-08-19 00:52 . 2010-08-19 00:52 -------- d-----w- c:\windows\system32\XPSViewer
2010-08-19 00:52 . 2010-08-19 00:52 -------- d-----w- c:\windows\system32\URTTemp
2010-08-18 22:42 . 2010-08-19 00:51 -------- d-----w- c:\program files\Microsoft Platform SDK
2010-08-10 03:46 . 2010-08-10 06:17 -------- d-----w- c:\documents and settings\Family\Local Settings\Application Data\FLVService
2010-08-10 03:46 . 2010-08-10 03:46 -------- d-----w- c:\windows\Freecorder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-08 21:22 . 2010-07-06 22:15 -------- d-----w- c:\program files\Blue Coat K9 Web Protection
2010-09-06 07:01 . 2007-08-29 03:37 -------- d-----w- c:\program files\ESET
2010-09-06 05:58 . 2010-07-21 01:44 63488 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-06 05:58 . 2010-07-21 01:44 117760 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-05 03:59 . 2007-07-07 04:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-04 04:22 . 2008-01-26 23:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2010-09-03 04:11 . 2009-12-09 04:00 -------- d-----w- c:\program files\Steam
2010-09-03 04:08 . 2007-05-13 01:29 -------- d-----w- c:\program files\Logitech
2010-09-03 04:08 . 2007-06-16 00:39 -------- d-----w- c:\program files\DivX
2010-09-03 04:06 . 2009-10-12 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-09-02 06:51 . 2010-09-02 06:51 0 ----a-w- c:\documents and settings\Family\ntuser.tmp
2010-09-01 21:39 . 2005-09-23 22:18 98920 ----a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-31 20:52 . 2007-04-04 00:32 -------- d-----w- c:\documents and settings\Family\Application Data\Uniblue
2010-08-27 21:22 . 2010-08-27 21:22 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-08-27 20:13 . 2010-02-22 08:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-25 00:18 . 2007-05-02 04:02 -------- d-----w- c:\documents and settings\Family\Application Data\Creative
2010-08-21 06:18 . 2010-08-21 06:18 7089544 ----a-w- c:\documents and settings\Administrator\Application Data\wruninstall.exe
2010-08-21 06:18 . 2010-08-21 06:18 7089544 ----a-w- c:\documents and settings\Administrator\Application Data\wruninstall.exe
2010-08-20 00:13 . 2005-09-14 19:38 -------- d-----w- c:\program files\Java
2010-08-20 00:11 . 2010-08-20 00:11 503808 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\msvcp71.dll
2010-08-20 00:11 . 2010-08-20 00:11 61440 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3ecac15c-n\decora-sse.dll
2010-08-20 00:11 . 2010-08-20 00:11 499712 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\jmc.dll
2010-08-20 00:11 . 2010-08-20 00:11 348160 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\msvcr71.dll
2010-08-20 00:11 . 2010-08-20 00:11 12800 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3ecac15c-n\decora-d3d.dll
2010-08-20 00:11 . 2005-09-14 19:38 -------- d-----w- c:\program files\Common Files\Java
2010-08-19 03:23 . 2010-08-02 05:04 -------- d-----w- c:\program files\Full Tilt Poker
2010-08-19 00:50 . 2007-07-22 08:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-17 18:10 . 2010-09-01 02:37 372736 ------w- c:\documents and settings\All Users\Application Data\Dell\DSL\DSLCheck.exe
2010-08-17 07:27 . 2007-09-07 00:36 -------- d-----w- c:\documents and settings\Family\Application Data\LimeWire
2010-08-08 02:53 . 2005-09-23 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-21 01:44 . 2010-07-21 01:44 52224 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-21 01:44 . 2010-07-21 01:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-21 01:44 . 2010-07-21 01:44 -------- d-----w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com
2010-07-21 01:42 . 2008-01-21 08:33 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-07-21 01:35 . 2010-07-21 01:35 -------- d-----w- c:\documents and settings\Family\Application Data\AVS4YOU
2010-07-21 01:27 . 2009-12-04 00:57 -------- d-----w- c:\documents and settings\Family\Application Data\Amazon
2010-07-18 23:29 . 2010-07-18 23:29 -------- d-----w- c:\documents and settings\Family\Application Data\BigBrainz
2010-07-18 22:20 . 2010-07-18 22:20 388096 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 12:00 . 2010-06-16 20:42 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-15 05:32 . 2010-07-15 05:32 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}
2010-07-11 22:31 . 2010-04-15 23:37 -------- d-----w- c:\documents and settings\Family\Application Data\SanDisk
2010-07-11 21:41 . 2009-08-23 03:27 -------- d-----w- c:\program files\SanDisk
2010-07-11 21:29 . 2010-07-11 21:29 -------- d-----w- c:\program files\Python31
2010-07-11 08:03 . 2010-07-11 08:03 -------- d-----w- c:\documents and settings\Family\Application Data\ssorgatem productions
2010-07-06 17:29 . 2010-07-15 05:32 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}\Ad-AwareInstall.exe
2010-07-06 17:28 . 2010-05-12 03:33 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-30 12:31 . 2010-05-09 03:34 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-08-19 20:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2010-05-09 03:34 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-22 20:55 . 2009-12-28 04:59 75636 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-21 15:27 . 2010-05-09 03:34 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 05:09 . 2010-06-19 05:09 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-19 03:16 . 2009-10-17 23:07 87 ----a-w- c:\documents and settings\Family\jagex_runescape_preferences2.dat
2010-06-19 03:16 . 2008-08-20 02:34 45 ----a-w- c:\documents and settings\Family\jagex_runescape_preferences.dat
2010-06-19 03:14 . 2010-06-19 03:14 0 ----a-w- c:\documents and settings\Family\jagex__preferences3.dat
2010-06-17 14:03 . 2004-08-19 20:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-16 20:43 . 2010-06-16 20:43 503808 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\msvcp71.dll
2010-06-16 20:43 . 2010-06-16 20:43 499712 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\jmc.dll
2010-06-16 20:43 . 2010-06-16 20:43 348160 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\msvcr71.dll
2010-06-16 20:43 . 2010-06-16 20:43 61440 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66ef6111-n\decora-sse.dll
2010-06-16 20:43 . 2010-06-16 20:43 12800 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66ef6111-n\decora-d3d.dll
2010-06-14 07:41 . 2004-08-19 20:49 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_E8445D1F15C9D9AE94D47B.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_C13252BF82CA8110419144.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_6FEFF9B68218417F98F549.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_1DF2F493C354ABFB693331.exe
2004-05-21 08:30 . 2005-10-06 20:57 52736 ----a-w- c:\program files\cryptainerlemobile.exe
2009-10-20 02:59 . 2010-05-02 04:49 47104 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
2009-11-24 21:14 . 2009-11-24 21:14 10437264 ----a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2009-11-28 20:10 . 2009-11-28 20:10 107760 ----a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2005-10-24 19:13 . 2005-10-24 19:13 66560 --sha-r- c:\windows\MOTA113.exe
2006-03-22 00:35 . 2005-12-02 21:02 56 --sha-r- c:\windows\system32\2F0796B60D.sys
2005-06-26 23:32 . 2005-06-26 23:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-22 06:37 . 2005-06-22 06:37 45568 --sha-r- c:\windows\system32\cygz.dll
2004-01-25 08:00 . 2004-01-25 08:00 70656 --sha-r- c:\windows\system32\i420vfw.dll
2006-03-22 00:35 . 2006-03-16 23:34 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2005-02-28 21:16 . 2005-02-28 21:16 240128 --sha-r- c:\windows\system32\x.264.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-19 333120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Uninstall Webroot RunOnce.lnk - c:\documents and settings\Administrator\Application Data\wruninstall.exe [2010-8-20 7089544]
c:\documents and settings\Gwen\Start Menu\Programs\Startup\
Download Manager.lnk - c:\program files\Snocap\Download Manager\NodeStarter.exe [2008-1-30 352256]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
c:\windows\system32\_003693_.tmp.dll
c:\windows\system32\_003695_.tmp.dll
c:\windows\system32\_003696_.tmp.dll
c:\windows\system32\_003700_.tmp.dll
c:\windows\system32\_003701_.tmp.dll
c:\windows\system32\_003703_.tmp.dll
c:\windows\system32\_003706_.tmp.dll
c:\windows\system32\_003708_.tmp.dll
c:\windows\system32\_003709_.tmp.dll
c:\windows\system32\_003710_.tmp.dll
c:\windows\system32\_003711_.tmp.dll
c:\windows\system32\_003714_.tmp.dll
c:\windows\system32\_003715_.tmp.dll
c:\windows\system32\_003716_.tmp.dll
c:\windows\system32\_003717_.tmp.dll
c:\windows\system32\_003718_.tmp.dll
c:\windows\system32\_003723_.tmp.dll
c:\windows\system32\_003725_.tmp.dll
c:\windows\system32\_003726_.tmp.dll
c:\windows\system32\_006755_.tmp.dll
c:\windows\system32\_006756_.tmp.dll
c:\windows\system32\_006757_.tmp.dll
c:\windows\system32\_006758_.tmp.dll
c:\windows\system32\_006765_.tmp.dll
c:\windows\system32\_006766_.tmp.dll
c:\windows\system32\_006767_.tmp.dll
c:\windows\system32\_006769_.tmp.dll
c:\windows\system32\_006770_.tmp.dll
c:\windows\system32\_006773_.tmp.dll
c:\windows\system32\_006774_.tmp.dll
c:\windows\system32\_006776_.tmp.dll
c:\windows\system32\_006777_.tmp.dll
c:\windows\system32\_006778_.tmp.dll
c:\windows\system32\_006780_.tmp.dll
c:\windows\system32\_006783_.tmp.dll
c:\windows\system32\_006784_.tmp.dll
c:\windows\system32\_006788_.tmp.dll
c:\windows\system32\_006789_.tmp.dll
c:\windows\system32\_006791_.tmp.dll
c:\windows\system32\_006794_.tmp.dll
c:\windows\system32\_006796_.tmp.dll
c:\windows\system32\_006797_.tmp.dll
c:\windows\system32\_006798_.tmp.dll
c:\windows\system32\_006799_.tmp.dll
c:\windows\system32\_006802_.tmp.dll
c:\windows\system32\_006803_.tmp.dll
c:\windows\system32\_006804_.tmp.dll
c:\windows\system32\_006805_.tmp.dll
c:\windows\system32\_006806_.tmp.dll
c:\windows\system32\_006811_.tmp.dll
c:\windows\system32\_006813_.tmp.dll
c:\windows\system32\_006814_.tmp.dll
c:\windows\twain_16.dll
.
((((((((((((((((((((((((( Files Created from 2010-08-08 to 2010-09-08 )))))))))))))))))))))))))))))))
.
2010-09-06 20:59 . 2010-09-06 20:59 -------- d-----w- C:\_OTM
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\windows\system32\wbem\Repository
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\Reno 911 Paintball
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\G-Force
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Family\Application Data\BitTorrent
2010-09-03 04:11 . 2010-09-03 04:11 -------- d-----w- c:\documents and settings\Gwen\Application Data\Viewpoint
2010-09-03 03:56 . 2010-09-03 03:56 -------- d-----w- c:\documents and settings\All Users\Application Data\F-Secure
2010-09-02 00:58 . 2010-09-02 00:58 -------- d-----w- c:\documents and settings\Family\Application Data\Registry Mechanic
2010-08-31 20:50 . 2010-08-31 20:50 -------- d-----w- c:\documents and settings\All Users\Application Data\Office Genuine Advantage
2010-08-28 19:38 . 2010-08-28 19:40 -------- d-----w- c:\documents and settings\Family\Application Data\QuickScan
2010-08-27 21:22 . 2010-09-03 04:08 -------- d-----w- c:\documents and settings\All Users\Application Data\DivX
2010-08-23 05:10 . 2010-08-23 05:10 -------- d-----w- c:\program files\The Weather Channel FW
2010-08-21 07:13 . 2010-08-21 07:13 -------- d-----w- c:\documents and settings\Gwen\Local Settings\Application Data\Threat Expert
2010-08-21 06:30 . 2010-04-29 22:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-08-21 06:28 . 2010-04-29 22:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-08-21 02:40 . 2010-08-21 02:40 -------- d-----w- c:\program files\MSSOAP
2010-08-21 02:39 . 2010-08-21 02:39 164 ----a-w- c:\windows\install.dat
2010-08-19 00:53 . 2010-08-19 00:53 -------- d-----w- c:\program files\MSBuild
2010-08-19 00:52 . 2010-08-19 00:52 -------- d-----w- c:\windows\system32\XPSViewer
2010-08-19 00:52 . 2010-08-19 00:52 -------- d-----w- c:\windows\system32\URTTemp
2010-08-18 22:42 . 2010-08-19 00:51 -------- d-----w- c:\program files\Microsoft Platform SDK
2010-08-10 03:46 . 2010-08-10 06:17 -------- d-----w- c:\documents and settings\Family\Local Settings\Application Data\FLVService
2010-08-10 03:46 . 2010-08-10 03:46 -------- d-----w- c:\windows\Freecorder
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-08 21:22 . 2010-07-06 22:15 -------- d-----w- c:\program files\Blue Coat K9 Web Protection
2010-09-06 07:01 . 2007-08-29 03:37 -------- d-----w- c:\program files\ESET
2010-09-06 05:58 . 2010-07-21 01:44 63488 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10006.dll
2010-09-06 05:58 . 2010-07-21 01:44 117760 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\UIREPAIR.DLL
2010-09-05 03:59 . 2007-07-07 04:03 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2010-09-04 04:22 . 2008-01-26 23:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Dell
2010-09-03 04:11 . 2009-12-09 04:00 -------- d-----w- c:\program files\Steam
2010-09-03 04:08 . 2007-05-13 01:29 -------- d-----w- c:\program files\Logitech
2010-09-03 04:08 . 2007-06-16 00:39 -------- d-----w- c:\program files\DivX
2010-09-03 04:06 . 2009-10-12 22:39 -------- d-----w- c:\documents and settings\All Users\Application Data\NOS
2010-09-02 06:51 . 2010-09-02 06:51 0 ----a-w- c:\documents and settings\Family\ntuser.tmp
2010-09-01 21:39 . 2005-09-23 22:18 98920 ----a-w- c:\documents and settings\Family\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2010-08-31 20:52 . 2007-04-04 00:32 -------- d-----w- c:\documents and settings\Family\Application Data\Uniblue
2010-08-27 21:22 . 2010-08-27 21:22 144696 ----a-w- c:\documents and settings\All Users\Application Data\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-08-27 20:13 . 2010-02-22 08:01 -------- d-----w- c:\program files\Microsoft Silverlight
2010-08-25 00:18 . 2007-05-02 04:02 -------- d-----w- c:\documents and settings\Family\Application Data\Creative
2010-08-21 06:18 . 2010-08-21 06:18 7089544 ----a-w- c:\documents and settings\Administrator\Application Data\wruninstall.exe
2010-08-21 06:18 . 2010-08-21 06:18 7089544 ----a-w- c:\documents and settings\Administrator\Application Data\wruninstall.exe
2010-08-20 00:13 . 2005-09-14 19:38 -------- d-----w- c:\program files\Java
2010-08-20 00:11 . 2010-08-20 00:11 503808 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\msvcp71.dll
2010-08-20 00:11 . 2010-08-20 00:11 61440 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3ecac15c-n\decora-sse.dll
2010-08-20 00:11 . 2010-08-20 00:11 499712 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\jmc.dll
2010-08-20 00:11 . 2010-08-20 00:11 348160 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\4\7ec4bf04-1e3f901a-n\msvcr71.dll
2010-08-20 00:11 . 2010-08-20 00:11 12800 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\42\4488892a-3ecac15c-n\decora-d3d.dll
2010-08-20 00:11 . 2005-09-14 19:38 -------- d-----w- c:\program files\Common Files\Java
2010-08-19 03:23 . 2010-08-02 05:04 -------- d-----w- c:\program files\Full Tilt Poker
2010-08-19 00:50 . 2007-07-22 08:15 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2010-08-17 18:10 . 2010-09-01 02:37 372736 ------w- c:\documents and settings\All Users\Application Data\Dell\DSL\DSLCheck.exe
2010-08-17 07:27 . 2007-09-07 00:36 -------- d-----w- c:\documents and settings\Family\Application Data\LimeWire
2010-08-08 02:53 . 2005-09-23 00:03 -------- d-----w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2010-07-21 01:44 . 2010-07-21 01:44 52224 ----a-w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\SDDLLS\SD10005.dll
2010-07-21 01:44 . 2010-07-21 01:44 -------- d-----w- c:\documents and settings\All Users\Application Data\SUPERAntiSpyware.com
2010-07-21 01:44 . 2010-07-21 01:44 -------- d-----w- c:\documents and settings\Family\Application Data\SUPERAntiSpyware.com
2010-07-21 01:42 . 2008-01-21 08:33 -------- d-----w- c:\program files\Common Files\AVSMedia
2010-07-21 01:35 . 2010-07-21 01:35 -------- d-----w- c:\documents and settings\Family\Application Data\AVS4YOU
2010-07-21 01:27 . 2009-12-04 00:57 -------- d-----w- c:\documents and settings\Family\Application Data\Amazon
2010-07-18 23:29 . 2010-07-18 23:29 -------- d-----w- c:\documents and settings\Family\Application Data\BigBrainz
2010-07-18 22:20 . 2010-07-18 22:20 388096 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-07-17 12:00 . 2010-06-16 20:42 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-07-15 05:32 . 2010-07-15 05:32 -------- dc-h--w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}
2010-07-11 22:31 . 2010-04-15 23:37 -------- d-----w- c:\documents and settings\Family\Application Data\SanDisk
2010-07-11 21:41 . 2009-08-23 03:27 -------- d-----w- c:\program files\SanDisk
2010-07-11 21:29 . 2010-07-11 21:29 -------- d-----w- c:\program files\Python31
2010-07-11 08:03 . 2010-07-11 08:03 -------- d-----w- c:\documents and settings\Family\Application Data\ssorgatem productions
2010-07-06 17:29 . 2010-07-15 05:32 2979280 -c--a-w- c:\documents and settings\All Users\Application Data\{65893B95-F47B-4483-B883-86BA181E9B54}\Ad-AwareInstall.exe
2010-07-06 17:28 . 2010-05-12 03:33 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-30 12:31 . 2010-05-09 03:34 149504 ----a-w- c:\windows\system32\schannel.dll
2010-06-24 12:22 . 2004-08-19 20:49 916480 ----a-w- c:\windows\system32\wininet.dll
2010-06-23 13:44 . 2010-05-09 03:34 1851904 ----a-w- c:\windows\system32\win32k.sys
2010-06-22 20:55 . 2009-12-28 04:59 75636 ---ha-w- c:\windows\system32\mlfcache.dat
2010-06-21 15:27 . 2010-05-09 03:34 354304 ----a-w- c:\windows\system32\drivers\srv.sys
2010-06-19 05:09 . 2010-06-19 05:09 72504 ----a-w- c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 9.2.0.61\SetupAdmin.exe
2010-06-19 03:16 . 2009-10-17 23:07 87 ----a-w- c:\documents and settings\Family\jagex_runescape_preferences2.dat
2010-06-19 03:16 . 2008-08-20 02:34 45 ----a-w- c:\documents and settings\Family\jagex_runescape_preferences.dat
2010-06-19 03:14 . 2010-06-19 03:14 0 ----a-w- c:\documents and settings\Family\jagex__preferences3.dat
2010-06-17 14:03 . 2004-08-19 20:49 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-16 20:43 . 2010-06-16 20:43 503808 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\msvcp71.dll
2010-06-16 20:43 . 2010-06-16 20:43 499712 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\jmc.dll
2010-06-16 20:43 . 2010-06-16 20:43 348160 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-119fa94c-n\msvcr71.dll
2010-06-16 20:43 . 2010-06-16 20:43 61440 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66ef6111-n\decora-sse.dll
2010-06-16 20:43 . 2010-06-16 20:43 12800 ----a-w- c:\documents and settings\Family\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-66ef6111-n\decora-d3d.dll
2010-06-14 07:41 . 2004-08-19 20:49 1172480 ----a-w- c:\windows\system32\msxml3.dll
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_E8445D1F15C9D9AE94D47B.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_C13252BF82CA8110419144.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_6FEFF9B68218417F98F549.exe
2010-06-13 04:11 . 2010-06-13 04:11 25214 ----a-r- c:\documents and settings\Family\Application Data\Microsoft\Installer\{4E1CE76A-B1FF-48FB-813F-22094537D143}\_1DF2F493C354ABFB693331.exe
2004-05-21 08:30 . 2005-10-06 20:57 52736 ----a-w- c:\program files\cryptainerlemobile.exe
2009-10-20 02:59 . 2010-05-02 04:49 47104 ----a-w- c:\program files\mozilla firefox\components\FFComm.dll
2009-11-24 21:14 . 2009-11-24 21:14 10437264 ----a-w- c:\program files\mozilla firefox\plugins\PDFNetC.dll
2009-11-28 20:10 . 2009-11-28 20:10 107760 ----a-w- c:\program files\mozilla firefox\plugins\ScorchPDFWrapper.dll
2005-10-24 19:13 . 2005-10-24 19:13 66560 --sha-r- c:\windows\MOTA113.exe
2006-03-22 00:35 . 2005-12-02 21:02 56 --sha-r- c:\windows\system32\2F0796B60D.sys
2005-06-26 23:32 . 2005-06-26 23:32 616448 --sha-r- c:\windows\system32\cygwin1.dll
2005-06-22 06:37 . 2005-06-22 06:37 45568 --sha-r- c:\windows\system32\cygz.dll
2004-01-25 08:00 . 2004-01-25 08:00 70656 --sha-r- c:\windows\system32\i420vfw.dll
2006-03-22 00:35 . 2006-03-16 23:34 1682 --sha-w- c:\windows\system32\KGyGaAvL.sys
2005-02-28 21:16 . 2005-02-28 21:16 240128 --sha-r- c:\windows\system32\x.264.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2006-09-11 218032]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Logitech Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2007-09-21 55824]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2008-09-19 333120]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2010-03-02 282792]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2009-05-21 206064]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2010-03-18 421888]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Uninstall Webroot RunOnce.lnk - c:\documents and settings\Administrator\Application Data\wruninstall.exe [2010-8-20 7089544]
c:\documents and settings\Gwen\Start Menu\Programs\Startup\
Download Manager.lnk - c:\program files\Snocap\Download Manager\NodeStarter.exe [2008-1-30 352256]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk /p \??\C\0autocheck autochk *\0lsdelete
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Gamma Loader.lnk]
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]