Hi,
Here is c:\combofix.txt
ComboFix 10-03-04.02 - Fred 03/07/2010 5:03.3.1 - x86 NETWORK
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.1.1033.18.3582.3071 [GMT -5:00]
Running from: c:\users\Fred\Desktop\Combo-Fix.exe
SP: SUPERAntiSpyware *enabled* (Updated) {222A897C-5018-402e-943F-7E7AC8560DA7}
.
ADS - Windows: deleted 0 bytes in 1 streams. ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\$recycle.bin\S-1-5-21-2152478756-3922319563-605102323-500
c:\$recycle.bin\S-1-5-21-2999670558-2758420469-3129876585-500
c:\windows\jestertb.dll
c:\windows\system32\tmp.reg
c:\windows\system32\twain_32.dll
c:\windows\system32\Ultra.dll
.
((((((((((((((((((((((((( Files Created from 2010-02-07 to 2010-03-07 )))))))))))))))))))))))))))))))
.
2010-03-07 11:36 . 2010-03-07 11:38 -------- d-----w- c:\users\Fred\AppData\Local\temp
2010-03-07 11:36 . 2010-03-07 11:36 -------- d-----w- c:\users\TEMP.Fred-PC\AppData\Local\temp
2010-03-07 11:36 . 2010-03-07 11:36 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-03-07 11:36 . 2010-03-07 11:36 -------- d-----w- c:\users\Guest\AppData\Local\temp
2010-03-07 09:52 . 2010-03-07 09:53 -------- d-----w- C:\32788R22FWJFW
2010-03-07 08:55 . 2010-03-07 08:55 93056 ----a-w- C:\kwldypob.sys
2010-03-07 06:29 . 2010-03-07 06:34 -------- d-----w- c:\program files\Svchost Fix Wizard
2010-03-07 06:29 . 2009-04-16 19:13 81920 ----a-w- c:\windows\eSellerateControl350.dll
2010-03-07 06:29 . 2009-04-16 19:13 356352 ----a-w- c:\windows\eSellerateEngine.dll
2010-03-07 06:16 . 2010-03-07 06:16 -------- d-----w- c:\program files\RegCure
2010-03-07 06:16 . 2010-03-07 06:16 -------- d-----w- c:\programdata\RegCure
2010-03-06 02:19 . 2010-03-06 02:19 -------- d-----w- c:\program files\Sophos
2010-03-06 00:40 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\07663842.sys
2010-03-06 00:40 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\0766384.sys
2010-03-06 00:40 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\07663841.sys
2010-03-06 00:34 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\25825422.sys
2010-03-06 00:34 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\2582542.sys
2010-03-06 00:34 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\25825421.sys
2010-03-06 00:16 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\41835662.sys
2010-03-06 00:16 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\4183566.sys
2010-03-06 00:16 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\41835661.sys
2010-03-06 00:08 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\88396992.sys
2010-03-06 00:08 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\8839699.sys
2010-03-06 00:08 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\88396991.sys
2010-03-05 23:18 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\85710942.sys
2010-03-05 23:18 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\8571094.sys
2010-03-05 23:18 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\85710941.sys
2010-03-05 23:17 . 2010-03-07 03:30 -------- d-----w- c:\programdata\Kaspersky Lab
2010-03-05 23:16 . 2009-10-22 17:54 37392 ----a-w- c:\windows\system32\drivers\61669202.sys
2010-03-05 23:16 . 2009-10-10 03:31 311312 ----a-w- c:\windows\system32\drivers\6166920.sys
2010-03-05 23:16 . 2009-09-25 21:59 128016 ----a-w- c:\windows\system32\drivers\61669201.sys
2010-03-05 20:43 . 2010-03-07 07:44 439816 ----a-w- c:\users\Fred\AppData\Roaming\Real\Update\setup3.10\setup.exe
2010-03-05 18:33 . 2010-03-05 18:33 -------- d-----w- c:\program files\Trend Micro
2010-03-05 16:55 . 2010-03-05 16:55 -------- d-----w- c:\users\Fred\AppData\Roaming\SUPERAntiSpyware.com
2010-03-05 16:55 . 2010-03-05 16:55 -------- d-----w- c:\programdata\SUPERAntiSpyware.com
2010-03-04 23:31 . 2010-01-07 21:07 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-03-04 23:31 . 2010-03-06 19:59 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-03-04 23:31 . 2010-01-07 21:07 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-03-03 23:31 . 2010-03-03 23:31 -------- d-----w- c:\program files\ESET
2010-03-03 07:38 . 2010-03-03 07:38 -------- d-----w- c:\programdata\Kaspersky Lab Setup Files
2010-03-01 20:02 . 2010-03-01 20:11 -------- d-----w- c:\users\Fred\AppData\Roaming\DiskSpaceFan
2010-03-01 20:02 . 2010-03-01 20:02 -------- d-----w- c:\program files\DiskSpaceFan
2010-02-22 20:06 . 2009-12-16 21:05 471040 ----a-w- c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\biey3q3p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\DictionaryCompressionFF.dll
2010-02-22 20:06 . 2009-12-16 21:05 347136 ----a-w- c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\biey3q3p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff3.dll
2010-02-22 20:06 . 2009-12-16 21:05 340992 ----a-w- c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\biey3q3p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\libraries\googletoolbar-ff2.dll
2010-02-22 20:06 . 2009-12-16 21:05 43008 ----a-w- c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\biey3q3p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\googletoolbarloader.dll
2010-02-22 20:06 . 2009-12-16 21:05 1452032 ----a-w- c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\biey3q3p.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}\components\frozen.dll
2010-02-19 23:47 . 2010-02-19 23:47 -------- d-----w- c:\users\Fred\AppData\Roaming\WTouch
2010-02-19 23:47 . 2009-11-23 20:53 245032 ----a-w- c:\windows\system32\Touch_Tablet.dll
2010-02-19 23:44 . 2010-02-19 23:47 -------- d-----w- c:\program files\WTouch
2010-02-19 23:44 . 2009-07-09 14:16 13480 ----a-w- c:\windows\system32\drivers\WacomVTHid.sys
2010-02-19 23:44 . 2010-02-19 23:44 -------- d-----w- c:\program files\TabletPlugins
2010-02-16 21:54 . 2009-09-30 17:11 288096 ----a-r- c:\users\Fred\AppData\Roaming\McAfee\Supportability\MVTLogs\Results\detect.dll
2010-02-16 21:51 . 2010-02-16 21:51 -------- d-----w- c:\users\Fred\AppData\Roaming\McAfee
2010-02-15 03:50 . 2010-02-15 03:50 -------- d-----w- c:\program files\JRE
2010-02-15 02:59 . 2010-02-15 02:59 -------- d-----w- c:\users\Fred\AppData\Roaming\Registry Mechanic
2010-02-15 00:53 . 2010-02-15 05:41 1 ----a-w- c:\users\Fred\AppData\Roaming\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2010-02-15 00:53 . 2010-02-15 00:53 -------- d-----w- c:\users\Fred\AppData\Roaming\OpenOffice.org
2010-02-14 17:56 . 2010-02-15 03:50 -------- d-----w- c:\program files\OpenOffice.org 3
2010-02-13 20:11 . 2004-08-04 13:00 506368 ----a-w- c:\windows\system32\msxml.dll
2010-02-13 20:11 . 2010-02-13 20:11 -------- d-----w- c:\program files\Common Files\PC Tools
2010-02-10 22:59 . 2010-02-10 22:59 -------- d-----w- c:\programdata\ATI
2010-02-10 22:39 . 2010-02-10 22:39 10134 ----a-r- c:\users\Fred\AppData\Roaming\Microsoft\Installer\{590B3F7B-C516-B2A0-0F9A-085FBD1D4432}\ARPPRODUCTICON.exe
2010-02-10 04:20 . 2009-12-11 12:07 301568 ----a-w- c:\windows\system32\drivers\srv.sys
2010-02-10 04:20 . 2009-12-11 12:07 98304 ----a-w- c:\windows\system32\drivers\srvnet.sys
2010-02-10 04:18 . 2009-12-04 16:12 105472 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-02-10 04:18 . 2009-12-04 16:12 212992 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-02-10 01:37 . 2010-02-18 19:03 -------- d-----w- c:\users\Fred\AppData\Roaming\Azureus
2010-02-10 01:35 . 2010-02-12 20:53 -------- d-----w- c:\program files\Vuze
2010-02-10 00:09 . 2010-02-10 00:09 -------- d-----w- c:\users\TEMP.Fred-PC\AppData\Roaming\TuneUp Software
2010-02-10 00:09 . 2010-02-10 00:09 -------- d-----w- c:\users\TEMP.Fred-PC\AppData\Roaming\IObit
2010-02-10 00:09 . 2010-02-10 00:09 -------- d-----w- c:\users\TEMP.Fred-PC\AppData\Roaming\WTablet
2010-02-07 19:48 . 2010-02-07 19:48 -------- d-----w- c:\users\Fred\AppData\Local\Microsoft_Research
2010-02-07 19:42 . 2010-02-07 19:42 -------- d-----w- c:\program files\Microsoft Research
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-03-07 08:08 . 2008-12-03 02:08 12 ----a-w- c:\windows\bthservsdp.dat
2010-03-07 04:08 . 2007-10-13 16:46 -------- d-----w- c:\users\Fred\AppData\Roaming\WTablet
2010-03-07 03:46 . 2008-06-03 21:36 -------- d-----w- c:\programdata\Google Updater
2010-03-05 20:23 . 2008-03-20 14:47 691 ----a-w- c:\users\Fred\AppData\Roaming\GetValue.vbs
2010-03-05 20:23 . 2008-03-20 14:47 35 ----a-w- c:\users\Fred\AppData\Roaming\SetValue.bat
2010-03-05 20:23 . 2008-03-20 14:47 35 ----a-w- c:\users\Fred\AppData\Roaming\SetValue.bat
2010-03-05 15:58 . 2007-09-22 04:49 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2010-03-05 15:44 . 2007-12-03 17:35 1356 ----a-w- c:\users\Fred\AppData\Local\d3d9caps.dat
2010-03-03 09:23 . 2007-09-18 15:19 -------- d-----w- c:\programdata\FLEXnet
2010-03-03 08:05 . 2009-11-04 03:16 -------- d-----w- c:\programdata\McAfee
2010-03-03 08:05 . 2009-11-04 03:36 -------- d-----w- c:\program files\McAfee
2010-03-03 08:04 . 2009-11-04 03:36 -------- d-----w- c:\program files\Common Files\McAfee
2010-03-03 05:39 . 2007-09-18 05:36 143888 ----a-w- c:\users\Fred\AppData\Local\GDIPFONTCACHEV1.DAT
2010-03-03 03:56 . 2007-12-09 04:54 -------- d-----w- c:\users\Fred\AppData\Roaming\StumbleUpon
2010-03-03 01:20 . 2008-09-12 21:19 -------- d-----w- c:\program files\Mozilla Thunderbird
2010-02-28 19:43 . 2007-03-29 20:35 -------- d-----w- c:\programdata\Microsoft Help
2010-02-19 23:43 . 2007-10-06 15:10 -------- d-----w- c:\program files\Tablet
2010-02-19 22:35 . 2007-12-21 22:13 3662 --sha-w- c:\programdata\KGyGaAvL.sys
2010-02-19 22:35 . 2007-12-21 22:13 3662 --sha-w- c:\programdata\KGyGaAvL.sys
2010-02-16 23:40 . 2009-11-04 03:40 -------- d-----w- c:\program files\SiteAdvisor
2010-02-15 04:15 . 2007-12-22 16:41 -------- d-----w- c:\program files\Common Files\Java
2010-02-15 04:11 . 2007-09-18 06:27 -------- d-----w- c:\program files\Java
2010-02-15 03:46 . 2008-11-27 15:35 411368 ----a-w- c:\windows\system32\deploytk.dll
2010-02-13 21:55 . 2009-06-13 22:57 72080 ----a-w- c:\users\Fred\g2mdlhlpx.exe
2010-02-12 01:21 . 2007-09-22 17:55 -------- d-----w- c:\program files\Eudora
2010-02-12 00:44 . 2007-03-29 20:32 -------- d-----w- c:\program files\Common Files\Adobe
2010-02-11 03:09 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-02-10 23:00 . 2009-03-15 01:25 -------- d-----w- c:\program files\ATI
2010-02-10 22:39 . 2009-03-15 01:25 -------- d-----w- c:\program files\ATI Technologies
2010-02-10 17:31 . 2009-09-15 19:55 -------- d-----r- c:\program files\Skype
2010-02-10 00:55 . 2009-11-24 01:14 -------- d-----w- c:\users\Fred\AppData\Roaming\Dropbox
2010-02-09 17:12 . 2007-09-23 17:57 -------- d-----w- c:\users\Fred\AppData\Roaming\Winamp
2010-02-04 00:29 . 2008-09-12 21:19 -------- d-----w- c:\users\Fred\AppData\Roaming\Thunderbird
2010-02-03 23:00 . 2010-02-03 23:00 -------- d-----w- c:\program files\Common Files\xing shared
2010-02-02 02:55 . 2008-06-04 04:12 231996 ---ha-w- c:\windows\system32\mlfcache.dat
2010-02-02 02:53 . 2007-09-19 15:45 -------- d-----w- c:\users\Fred\AppData\Roaming\Apple Computer
2010-02-02 02:52 . 2010-02-02 02:51 -------- d-----w- c:\program files\Safari
2010-01-27 00:26 . 2007-09-18 06:29 -------- d-----w- c:\program files\Google
2010-01-24 11:01 . 2009-03-24 00:01 -------- d-----w- c:\program files\SmartFTP Client
2010-01-20 01:28 . 2008-02-16 23:01 -------- d-----w- c:\programdata\Corel
2010-01-02 06:38 . 2010-01-21 20:21 916480 ----a-w- c:\windows\system32\wininet.dll
2010-01-02 06:32 . 2010-01-21 20:21 109056 ----a-w- c:\windows\system32\iesysprep.dll
2010-01-02 06:32 . 2010-01-21 20:21 71680 ----a-w- c:\windows\system32\iesetup.dll
2010-01-02 04:57 . 2010-01-21 20:21 133632 ----a-w- c:\windows\system32\ieUnatt.exe
2009-12-28 12:35 . 2010-02-10 04:19 11776 ----a-w- c:\windows\system32\tsbyuv.dll
2009-12-28 12:35 . 2010-02-10 04:19 1314816 ----a-w- c:\windows\system32\quartz.dll
2009-12-28 12:32 . 2010-02-10 04:19 22528 ----a-w- c:\windows\system32\msyuv.dll
2009-12-28 12:32 . 2010-02-10 04:19 31744 ----a-w- c:\windows\system32\msvidc32.dll
2009-12-28 12:32 . 2010-02-10 04:19 123904 ----a-w- c:\windows\system32\msvfw32.dll
2009-12-28 12:32 . 2010-02-10 04:19 13312 ----a-w- c:\windows\system32\msrle32.dll
2009-12-28 12:31 . 2010-02-10 04:19 82944 ----a-w- c:\windows\system32\mciavi32.dll
2009-12-28 12:31 . 2010-02-10 04:19 50176 ----a-w- c:\windows\system32\iyuv_32.dll
2009-12-28 12:28 . 2010-02-10 04:19 65024 ----a-w- c:\windows\system32\avicap32.dll
2009-12-28 12:28 . 2010-02-10 04:19 91136 ----a-w- c:\windows\system32\avifil32.dll
2009-12-17 12:43 . 2009-12-17 12:43 79144 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 9.0.2.25\SetupAdmin.exe
2009-12-11 21:03 . 2009-12-11 21:03 5188096 ----a-w- c:\windows\system32\drivers\atipmdag.sys
2009-12-11 21:03 . 2009-12-11 21:03 5188096 ----a-w- c:\windows\system32\drivers\atikmdag.sys
2009-12-11 20:45 . 2009-12-11 20:45 446464 ----a-w- c:\windows\system32\ATIDEMGX.dll
2009-12-11 20:45 . 2009-12-11 20:45 372736 ----a-w- c:\windows\system32\atieclxx.exe
2009-12-11 20:44 . 2009-12-11 20:44 172032 ----a-w- c:\windows\system32\atiesrxx.exe
2009-12-11 20:43 . 2009-03-15 03:42 159744 ----a-w- c:\windows\system32\atitmmxx.dll
2009-12-11 20:42 . 2009-03-15 03:42 356352 ----a-w- c:\windows\system32\atipdlxx.dll
2009-12-11 20:42 . 2009-12-11 20:42 274432 ----a-w- c:\windows\system32\Oemdspif.dll
2009-12-11 20:42 . 2009-12-11 20:42 11776 ----a-w- c:\windows\system32\atimuixx.dll
2009-12-11 20:42 . 2009-12-11 20:42 43520 ----a-w- c:\windows\system32\ati2edxx.dll
2009-12-11 20:39 . 2009-12-11 20:39 3060224 ----a-w- c:\windows\system32\atidxx32.dll
2009-12-11 20:35 . 2009-12-11 20:35 400384 ----a-w- c:\windows\system32\aticfx32.dll
2009-12-11 20:26 . 2009-12-11 20:26 13383168 ----a-w- c:\windows\system32\atioglxx.dll
2009-12-11 20:22 . 2009-03-15 03:42 3601920 ----a-w- c:\windows\system32\atiumdag.dll
2009-12-11 20:11 . 2009-12-11 20:11 50176 ----a-w- c:\windows\system32\coinst.dll
2009-12-11 20:04 . 2009-12-11 20:04 53248 ----a-w- c:\windows\system32\aticalrt.dll
2009-12-11 20:04 . 2009-03-15 03:42 2912768 ----a-w- c:\windows\system32\atiumdva.dll
2009-12-11 20:04 . 2009-12-11 20:04 53248 ----a-w- c:\windows\system32\aticalcl.dll
2009-12-11 20:03 . 2009-12-11 20:03 3641344 ----a-w- c:\windows\system32\aticaldd.dll
2009-12-11 19:52 . 2009-12-11 19:52 52224 ----a-w- c:\windows\system32\atimpc32.dll
2009-12-11 19:52 . 2009-12-11 19:52 52224 ----a-w- c:\windows\system32\amdpcom32.dll
2009-12-11 19:52 . 2009-12-11 19:52 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll
2009-12-11 19:51 . 2009-12-11 19:51 225280 ----a-w- c:\windows\system32\atiadlxx.dll
2009-12-11 19:51 . 2009-12-11 19:51 12800 ----a-w- c:\windows\system32\atiglpxx.dll
2009-12-11 19:51 . 2009-12-11 19:51 15360 ----a-w- c:\windows\system32\atigktxx.dll
2009-12-11 19:50 . 2009-12-11 19:50 125440 ----a-w- c:\windows\system32\drivers\atikmpag.sys
2009-12-11 19:50 . 2009-12-11 19:50 27136 ----a-w- c:\windows\system32\atiuxpag.dll
2009-12-11 19:50 . 2009-12-11 19:50 20480 ----a-w- c:\windows\system32\atiu9pag.dll
2009-12-11 19:49 . 2009-12-11 19:49 23040 ----a-w- c:\windows\system32\atitmpxx.dll
2009-12-08 20:52 . 2010-02-10 04:19 897624 ----a-w- c:\windows\system32\drivers\tcpip.sys
2009-12-08 20:52 . 2010-02-10 04:19 3597912 ----a-w- c:\windows\system32\ntkrnlpa.exe
2009-12-08 20:52 . 2010-02-10 04:19 3546200 ----a-w- c:\windows\system32\ntoskrnl.exe
2009-05-01 23:45 . 2009-05-01 23:45 135680 ------w- c:\program files\mozilla firefox\components\GoogleDesktopMozilla.dll
2007-09-19 14:28 . 2007-09-19 14:28 8 --sha-r- c:\windows\System32\3CFBE0E1F4.sys
2009-03-16 04:50 . 2007-09-19 14:28 900 --sha-w- c:\windows\System32\KGyGaAvL.sys
.
------- Sigcheck -------
[-] 2008-01-19 . 53B202ABEE6455406254444303E87BE1 . 17408 . . [6.0.6001.18000] . . c:\windows\System32\drivers\asyncmac.sys
[-] 2008-01-19 . 67E506B75BD5326A3EC7B70BD014DFB6 . 6144 . . [6.0.6001.18000] . . c:\windows\System32\drivers\beep.sys
[-] 2008-01-19 . C5DBBCDA07D780BDA9B685DF333BB41E . 4608 . . [6.0.6001.18000] . . c:\windows\System32\drivers\null.sys
[-] 2008-01-19 . A3629A0C4226F9E9C72FAAEEBC3AD33C . 81920 . . [6.0.6000.16386] . . c:\windows\System32\browser.dll
[-] 2009-06-15 . A911ECAC81F94ADEAFBE8E3F7873EDB0 . 9728 . . [6.0.6000.16386] . . c:\windows\System32\lsass.exe
[-] 2008-01-19 . C8052711DAECC48B982434C5116CA401 . 274432 . . [6.0.6000.16386] . . c:\windows\System32\netman.dll
[-] 2009-04-11 . 93952506C6D67330367F7E7934B6A02F . 758784 . . [7.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6002.18005_none_257c3df8f693d6d8\qmgr.dll
[-] 2008-01-19 . 02ED7B4DBC2A3232A389106DA7515C3D . 758272 . . [7.0.6001.18000] . . c:\windows\System32\qmgr.dll
[-] 2009-04-11 . 3B5B4D53FEC14F7476CA29A20CC31AC9 . 550400 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-com-base-qfe-rpcss_31bf3856ad364e35_6.0.6002.18005_none_6bb655083b01c988\rpcss.dll
[-] 2009-03-03 . 301AE00E12408650BADDC04DBC832830 . 551424 . . [6.0.6000.16386] . . c:\windows\System32\rpcss.dll
[-] 2009-04-11 . D4E6D91C1349B7BFB3599A6ADA56851B . 279552 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[-] 2008-01-19 . 2B336AB6286D6C81FA02CBAB914E3C6C . 279040 . . [6.0.6000.16386] . . c:\windows\System32\services.exe
[-] 2009-04-11 . 524BFBEA40E6E404737CCBC754647A2E . 127488 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-printing-spooler-core_31bf3856ad364e35_6.0.6002.18005_none_d8371c2dbeaa9062\spoolsv.exe
[-] 2008-01-19 . 846CDF9A3CF4DA9B306ADFB7D55EE4C2 . 125952 . . [6.0.6000.16386] . . c:\windows\System32\spoolsv.exe
[-] 2009-04-11 . 898E7C06A350D4A1A64A9EA264D55452 . 314368 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[-] 2008-01-19 . C2610B6BDBEFC053BBDAB4F1B965CB24 . 314880 . . [6.0.6001.18000] . . c:\windows\System32\winlogon.exe
[-] 2009-04-11 . 0C2236FB7195A1CF2A632D530349E673 . 1686016 . . [5.82] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll
[-] 2008-01-19 . 50CDFD99E606D172875E73B87C64053D . 531968 . . [5.82] . . c:\windows\System32\comctl32.dll
[-] 2009-04-11 . FB27772BEAF8E1D28CCD825C09DA939B . 129024 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-cryptsvc-dll_31bf3856ad364e35_6.0.6002.18005_none_77eb127097f11935\cryptsvc.dll
[-] 2008-01-19 . 6DE363F9F99334514C46AEC02D3E3678 . 128000 . . [6.0.6000.16386] . . c:\windows\System32\cryptsvc.dll
[-] 2009-04-11 . 67058C46504BC12D821F38CF99B7B28F . 268800 . . [2001.12.6932.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-c..complus-eventsystem_31bf3856ad364e35_6.0.6002.18005_none_0ed918294edf6b75\es.dll
[-] 2008-04-18 . 3CB3343D720168B575133A0A20DC2465 . 269312 . . [2001.12.6931.18057] . . c:\windows\System32\es.dll
[-] 2009-04-11 . C8BDCECEE082B54F0BAC838BF0A34597 . 114688 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-imm32_31bf3856ad364e35_6.0.6002.18005_none_5e419722778cc84e\imm32.dll
[-] 2008-01-19 . EC17194A193CD8E90D27CFB93DFA9A2E . 114688 . . [6.0.6001.18000] . . c:\windows\System32\imm32.dll
[-] 2009-04-11 . BB8509089E7DF514310814E1B2593FFC . 891392 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-kernel32_31bf3856ad364e35_6.0.6002.18005_none_95a95e4d536d53fa\kernel32.dll
[-] 2009-02-13 . DB6E3731E6F5C8AE2843F80B5787F7C6 . 888832 . . [6.0.6001.18000] . . c:\windows\System32\kernel32.dll
[-] 2006-11-02 . 24F90AEFEBE601D427CB4511E74CDCB6 . 22016 . . [6.0.6000.16386] . . c:\windows\System32\linkinfo.dll
[-] 2008-01-19 . DD496299B7351E16E602FC4299345A33 . 23552 . . [6.0.6001.18000] . . c:\windows\System32\lpk.dll
[-] 2010-01-02 . DF4D546A6E1C8D0F4FC10FCC9E422763 . 5942784 . . [8.00.6001.18702] . . c:\windows\System32\mshtml.dll
[-] 2009-08-27 . E9C51FD04019DC14CAE9CEDE3C7B08E3 . 5942272 . . [8.00.6001.22918] . . c:\windows\SoftwareDistribution\Download\fa8c2d28d4f83f2d821668f4c68d7ffc\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22918_none_f6b3057751153c65\mshtml.dll
[-] 2009-08-27 . 7172C1681283EC40A8DA9ED4180FF390 . 5940224 . . [8.00.6001.18828] . . c:\windows\SoftwareDistribution\Download\fa8c2d28d4f83f2d821668f4c68d7ffc\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18828_none_f61e98c037ffb88c\mshtml.dll
[-] 2009-05-12 . 5F3B323A3758C9B156B199F54A888882 . 5936128 . . [8.00.6001.22874] . . c:\windows\SoftwareDistribution\Download\7825d2f301c03b6bb63b926dc19881f5\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.22874_none_f66e22e151498188\mshtml.dll
[-] 2009-05-09 . 89CCF8069B59780BDEF45E345E671347 . 5936128 . . [8.00.6001.18783] . . c:\windows\SoftwareDistribution\Download\7825d2f301c03b6bb63b926dc19881f5\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_8.0.6001.18783_none_f5d8b5e03834e458\mshtml.dll
[-] 2009-04-11 . A4D04D404AFC1D30EDA01EE50D27AA51 . 3596288 . . [7.00.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18005_none_152e8ba81f4b4668\mshtml.dll
[-] 2008-10-02 . 3E3D3E24BD1F862CD1A772C0DAD3F134 . 3578880 . . [7.00.6001.18148] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18148_none_131fd7222242b2bf\mshtml.dll
[-] 2008-10-02 . 713D3D802424C56F28A3AC21F843D9E4 . 3593216 . . [7.00.6000.16757] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16757_none_112dc84625252468\mshtml.dll
[-] 2008-10-02 . 56942EB5D17DFA38CA0B2B234BB578A3 . 3579392 . . [7.00.6001.22278] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22278_none_138904293b78a65c\mshtml.dll
[-] 2008-10-02 . 34311116C0A994BD82D7732D0950999C . 3594752 . . [7.00.6000.20927] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.20927_none_11d7d6bb3e2a6d86\mshtml.dll
[-] 2009-04-11 . F5E991236960137B1F5449C5E5DF4656 . 679936 . . [7.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-msvcrt_31bf3856ad364e35_6.0.6002.18005_none_d340af2c9c07e8f9\msvcrt.dll
[-] 2008-01-19 . 04CBEAA089B6A752B3EB660BEE8C4964 . 680448 . . [7.0.6001.18000] . . c:\windows\System32\msvcrt.dll
[-] 2004-08-05 . 351B1AD22FD0EC70D889766E0B4F72ED . 343040 . . [7.0.2600.2180] . . c:\windows\SMINST\msvcrt.dll
[-] 2009-04-11 . 8617350C9B590B63E620881092751BCB . 223232 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-w..-infrastructure-bsp_31bf3856ad364e35_6.0.6002.18005_none_ba3ed0122a6d89da\mswsock.dll
[-] 2008-01-19 . 89FD0595EEA4E505CABEFCF7008F2612 . 223232 . . [6.0.6000.16386] . . c:\windows\System32\mswsock.dll
[-] 2009-04-11 . 95DAECF0FB120A7B5DA679CC54E37DDE . 592896 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_ffa3304f351bb3a3\netlogon.dll
[-] 2008-01-19 . A8EFC0B6E75B789F7FD3BA5025D4E37F . 592384 . . [6.0.6001.18000] . . c:\windows\System32\netlogon.dll
[-] 2009-04-11 . 9A7F4B2EDACD11444D048AA19CBB26AF . 98816 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-userpowermanagement_31bf3856ad364e35_6.0.6002.18005_none_a505176cf9fa2abd\powrprof.dll
[-] 2008-01-19 . 51832219A52C3535BF4771C375E63F9B . 97280 . . [6.0.6001.18000] . . c:\windows\System32\powrprof.dll
[-] 2009-04-11 . 8FC182167381E9915651267044105EE1 . 177152 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_39f95b67d63d3a5e\scecli.dll
[-] 2008-01-19 . 28B84EB538F7E8A0FE8B9299D591E0B9 . 177152 . . [6.0.6000.16386] . . c:\windows\System32\scecli.dll
[-] 2006-11-02 . F4E1AA5D59C849A4AB47E895DC76B9C8 . 4608 . . [6.0.6000.16386] . . c:\windows\System32\sfc.dll
[-] 2008-01-19 . 3794B461C45882E06856F282EEF025AF . 21504 . . [6.0.6000.16386] . . c:\windows\System32\svchost.exe
[-] 2009-04-11 . D7673E4B38CE21EE54C59EEEB65E2483 . 242688 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-tapiservice_31bf3856ad364e35_6.0.6002.18005_none_e52851e7e21463cb\tapisrv.dll
[-] 2008-01-19 . 680916BB09EE0F3A6ACA7C274B0D633F . 242688 . . [6.0.6000.16386] . . c:\windows\System32\tapisrv.dll
[-] 2009-04-11 . 75510147B94598407666F4802797C75A . 627712 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-user32_31bf3856ad364e35_6.0.6002.18005_none_cf23e54d6a7e4a7e\user32.dll
[-] 2008-01-19 . B974D9F06DC7D1908E825DC201681269 . 627200 . . [6.0.6001.18000] . . c:\windows\System32\user32.dll
[-] 2008-01-19 . 0E135526E9785D085BCD9AEDE6FBCBF9 . 25088 . . [6.0.6000.16386] . . c:\windows\System32\userinit.exe
[-] 2010-01-02 . 91B8712BDC74295DA14A08F519B70D65 . 916480 . . [8.00.6001.18702] . . c:\windows\System32\wininet.dll
[-] 2009-08-27 . D0DD9439DB3C927209CFFE095AA1F097 . 916480 . . [8.00.6001.22918] . . c:\windows\SoftwareDistribution\Download\fa8c2d28d4f83f2d821668f4c68d7ffc\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.22918_none_e558e658d0bed32f\wininet.dll
[-] 2009-08-27 . E3AB6EBE520E1898663B011D2FC0DF11 . 916480 . . [8.00.6001.18828] . . c:\windows\SoftwareDistribution\Download\fa8c2d28d4f83f2d821668f4c68d7ffc\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18828_none_e4c479a1b7a94f56\wininet.dll
[-] 2009-05-12 . 4BEDA2520729640D927E09A51AB916C4 . 915456 . . [8.00.6001.22874] . . c:\windows\SoftwareDistribution\Download\7825d2f301c03b6bb63b926dc19881f5\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.22874_none_e51403c2d0f31852\wininet.dll
[-] 2009-05-09 . D78B62CC91F043CED52F23F0085E7FE2 . 915456 . . [8.00.6001.18783] . . c:\windows\SoftwareDistribution\Download\7825d2f301c03b6bb63b926dc19881f5\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_8.0.6001.18783_none_e47e96c1b7de7b22\wininet.dll
[-] 2009-04-11 . 8777B44511D8BCCF47B5A7CBDC02DE11 . 828416 . . [7.00.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6002.18005_none_03d46c899ef4dd32\wininet.dll
[-] 2008-10-02 . C373C19F10601C1AFE7E40907AE48694 . 827392 . . [7.00.6001.18148] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.18148_none_01c5b803a1ec4989\wininet.dll
[-] 2008-10-02 . 8BF7D225505A4ADA25D9444E91811CEA . 826368 . . [7.00.6000.16757] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.16757_none_ffd3a927a4cebb32\wininet.dll
[-] 2008-10-02 . 6B2591CDCEFEB8451594288426677CBB . 827904 . . [7.00.6001.22278] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6001.22278_none_022ee50abb223d26\wininet.dll
[-] 2008-10-02 . C85EF7DE97ABBF00B16AD11EDFEAC637 . 827904 . . [7.00.6000.20927] . . c:\windows\SoftwareDistribution\Download\d291756ffb63508531c78734583f5fd7\x86_microsoft-windows-i..tocolimplementation_31bf3856ad364e35_6.0.6000.20927_none_007db79cbdd40450\wininet.dll
[-] 2008-01-19 . B304D47D5744BA20FCB99FB8B2C07B0B . 179200 . . [6.0.6000.16386] . . c:\windows\System32\ws2_32.dll
[-] 2009-04-11 . D07D4C3038F3578FFCE1C0237F2A1253 . 2926592 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[-] 2008-10-29 . 4F554999D7D5F05DAAEBBA7B5BA1089D . 2927104 . . [6.0.6000.16386] . . c:\windows\explorer.exe
[-] 2006-11-02 . 7F15B4953378C8B5161D65C26D5FED4D . 11776 . . [6.0.6000.16386] . . c:\windows\System32\cngaudit.dll
[-] 2006-11-02 . 22BFD03DF51065A9ED8D17F8FB72296B . 8704 . . [6.0.6000.16386] . . c:\windows\System32\ctfmon.exe
[-] 2009-04-11 . C818C44C201898399BF999BB6B35D4E3 . 247296 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-shsvcs_31bf3856ad364e35_6.0.6002.18005_none_cf1bd6361a0f622e\shsvcs.dll
[-] 2008-01-19 . 27F10F348E508243F6254846F8370D0D . 247296 . . [6.0.6000.16386] . . c:\windows\System32\shsvcs.dll
[-] 2009-04-11 . 9E6894EA18DAFF37B63E1005F83AE4AB . 107008 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-remoteregistry-service_31bf3856ad364e35_6.0.6002.18005_none_8b517ec580991c4d\regsvc.dll
[-] 2008-01-19 . CC4E32400F3C7253400CF8F3F3A0B676 . 106496 . . [6.0.6000.16386] . . c:\windows\System32\regsvc.dll
[-] 2009-04-11 . 323AE0BDFD2EB15B668DDA50CC597329 . 595456 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-taskscheduler-service_31bf3856ad364e35_6.0.6002.18005_none_30ec979d94244404\schedsvc.dll
[-] 2008-01-19 . 1D5E99DB3C10F4FA034010DC49043CA4 . 596992 . . [6.0.6001.18000] . . c:\windows\System32\schedsvc.dll
[-] 2008-01-19 . 03D50B37234967433A5EA5BA72BC0B62 . 155648 . . [6.0.6000.16386] . . c:\windows\System32\ssdpsrv.dll
[-] 2009-04-11 . BB95DA09BEF6E7A131BFF3BA5032090D . 449024 . . [6.0.6002.18005] . . c:\windows\SoftwareDistribution\Download\cde11068f5b77b180111333ef9781925\x86_microsoft-windows-t..teconnectionmanager_31bf3856ad364e35_6.0.6002.18005_none_908abad45165e2ae\termsrv.dll
[-] 2008-01-19 . D605031E225AACCBCEB5B76A4F1603A6 . 448512 . . [6.0.6001.18000] . . c:\windows\System32\termsrv.dll
[-] 2008-01-19 . 7A5F8218325F00396DAEA2F985FA0ECB . 18944 . . [6.0.6001.18000] . . c:\windows\System32\ias.dll
[-] 2006-11-02 09:46 . BA8639F9EB0F74F2946DE6DE1AF4691F . 924944 . . [4.1.6140] . . c:\windows\System32\mfc40u.dll
[-] 2008-01-19 . 68308183F4AE0BE7BF8ECD07CB297999 . 259072 . . [6.0.6000.16386] . . c:\windows\System32\upnphost.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
2008-10-02 20:44 325000 ------w- c:\program files\AskBarDis\bar\bin\askBar.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{3041d03e-fd4b-44e0-b742-2d9b88305f98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-02 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [2008-10-02 325000]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-14 03:19 527296 ------r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Green]
@="{95A27763-F62A-4114-9072-E81D87DE3B68}"
[HKEY_CLASSES_ROOT\CLSID\{95A27763-F62A-4114-9072-E81D87DE3B68}]
2008-06-14 03:19 527296 ------r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Blue]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Partial]
@="{E300CD91-100F-4E67-9AF3-1384A6124015}"
[HKEY_CLASSES_ROOT\CLSID\{E300CD91-100F-4E67-9AF3-1384A6124015}]
2008-06-14 03:19 527296 ------r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Red]
@="{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}"
[HKEY_CLASSES_ROOT\CLSID\{01CCCC8C-1D50-4b13-B96D-4B922DD3128B}]
2008-06-14 03:19 527296 ------r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\Carbonite.Yellow]
@="{5E529433-B50E-4bef-A63B-16A6B71B071A}"
[HKEY_CLASSES_ROOT\CLSID\{5E529433-B50E-4bef-A63B-16A6B71B071A}]
2008-06-14 03:19 527296 ------r- c:\program files\Carbonite\Carbonite Backup\CarboniteNSE.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RoboTask Lite"="c:\program files\RoboTask Lite\RoboTaskLite.exe" [2008-03-26 615424]
"RoboForm"="c:\program files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-09-19 160592]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2005-02-17 221184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mobile Device Center"="c:\windows\WindowsMobile\wmdc.exe" [2007-05-31 648072]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-05-16 430080]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2010-02-03 198160]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-12-11 98304]
"Monitor"="c:\windows\PixArt\PAC207\Monitor.exe" [2006-11-03 319488]
"LELA"="c:\program files\Linksys\Linksys EasyLink Advisor\Linksys EasyLink Advisor.exe" [2008-05-01 131072]
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe" [2008-10-25 31072]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2009-05-01 1838592]
"Carbonite Backup"="c:\program files\Carbonite\Carbonite Backup\CarboniteUI.exe" [2008-06-14 600000]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Photo Downloader"="c:\program files\Adobe\Adobe Photoshop Lightroom 1.4\apdproxy.exe" [2008-04-01 61440]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce]
"GrpConv"="grpconv -o" [X]
c:\users\Fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - c:\program files\Microsoft Office\Office12\ONENOTEM.EXE [2008-10-25 98696]
c:\users\Fred\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
MagicDisc.lnk - c:\program files\MagicDisc\MagicDisc.exe [2008-5-10 546816]
MOG-O-MATIC.lnk - c:\program files\MOG-O-MATIC\MogClient.exe [2007-11-11 677888]
Woopra.lnk - c:\program files\Woopra\Woopra.exe [2008-7-29 508416]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Vista Caller-ID.lnk - c:\windows\Installer\{6101BE40-84B8-48F2-89BF-7FFBF641D600}\_45738C77BC790C3EB3601A.exe [2008-4-21 10134]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\AutorunsDisabled
Compaq Connections.lnk - c:\program files\Compaq Connections\3572475\Program\Compaq Connections.exe [2007-3-29 34520]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}"= "c:\program files\Eudora\EuShlExt.dll" [2005-11-14 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GO333C~1\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\startupfolder\C:^Users^Fred^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
backup=c:\windows\pss\Adobe Gamma.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acrobat Assistant 8.0]
2008-06-12 02:43 640376 ----a-w- c:\program files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
2006-09-28 13:42 65536 ----a-w- c:\hp\support\hpsysdrv.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KBD]
2006-12-08 19:16 65536 ----a-w- c:\hp\KBD\KbdStub.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
2007-12-03 18:21 2213160 ------w- c:\program files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
2007-03-01 18:57 153136 ------w- c:\program files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
2008-04-09 05:15 648504 ------w- c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-05-23 01:49 13539872 ------w- c:\windows\System32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-05-23 01:49 92704 ------w- c:\windows\System32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSDMonitor]
2009-10-14 20:42 104408 ----a-w- c:\program files\Common Files\PC Tools\sMonitor\SSDMonitor.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"ISUSPM Startup"=c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
"AdobeUpdater"="c:\program files\Common Files\Adobe\Updater5\AdobeUpdater.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
"DNS7reminder"="c:\program files\Nuance\NaturallySpeaking9\Ereg\Ereg.exe" -r "c:\programdata\Nuance\NaturallySpeaking9\Ereg.ini
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe"
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" -osboot
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"SerialNumber"="
removed"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
R0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2008-05-14 715248]
R1 07663841;07663841;c:\windows\system32\DRIVERS\07663841.sys [2009-09-25 128016]
R1 25825421;25825421;c:\windows\system32\DRIVERS\25825421.sys [2009-09-25 128016]
R1 41835661;41835661;c:\windows\system32\DRIVERS\41835661.sys [2009-09-25 128016]
R1 61669201;61669201;c:\windows\system32\DRIVERS\61669201.sys [2009-09-25 128016]
R1 85710941;85710941;c:\windows\system32\DRIVERS\85710941.sys [2009-09-25 128016]
R1 88396991;88396991;c:\windows\system32\DRIVERS\88396991.sys [2009-09-25 128016]
R1 SABKUTIL;SABKUTIL;c:\users\Fred\Desktop\SABKUTIL.sys [x]
R1 SASDIFSV;SASDIFSV;c:\users\Fred\AppData\Local\Temp\SAS_SelfExtract\SASDIFSV.SYS [x]
R1 SASKUTIL;SASKUTIL;c:\users\Fred\AppData\Local\Temp\SAS_SelfExtract\SASKUTIL.sys [x]
R3 3xHybrid;3xHybrid service;c:\windows\system32\DRIVERS\3xHybrid.sys [2007-12-04 946816]
R3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atipmdag.sys [2009-12-11 5188096]
R3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2009-12-11 125440]
R3 cpuz131;cpuz131;c:\users\Fred\AppData\Local\Temp\cpuz131\cpuz_x32.sys [x]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2010-01-07 38224]
R3 NPF;WinPcap Packet Driver (NPF);c:\windows\system32\drivers\NPF.sys [2008-05-21 34576]
R3 PAC207;CIF USB Camera;c:\windows\system32\DRIVERS\PFC027.SYS [2006-11-10 505984]
R3 rootbeer;rootbeer;c:\windows\system32\drivers\rootbeer.sys [x]
R3 SASENUM;SASENUM;c:\users\Fred\AppData\Local\Temp\SAS_SelfExtract\SASENUM.SYS [x]
R3 wacmoumonitor;Wacom Mode Helper;c:\windows\system32\DRIVERS\wacmoumonitor.sys [2008-03-17 15144]
R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam.sys [2008-05-16 11520]
R4 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [2008-08-15 284016]
R4 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-11 172032]
R4 ASTSRV;Nalpeiron Licensing Service;c:\windows\system32\ASTSRV.EXE [2008-05-19 57344]
R4 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2009-09-14 133104]
R4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2009-09-21 1028432]
R4 LinksysUpdater;Linksys Updater;c:\program files\Linksys\Linksys Updater\bin\LinksysUpdater.exe [2008-04-18 204800]
R4 lxbl_device;lxbl_device;c:\windows\system32\lxblcoms.exe [2007-04-20 537520]
R4 PCToolsSSDMonitorSvc;PC Tools Startup and Shutdown Monitor service;c:\program files\Common Files\PC Tools\sMonitor\StartManSvc.exe [2009-10-14 583640]
R4 TabletServicePen;TabletServicePen;c:\windows\system32\Pen_Tablet.exe [2009-11-23 4497704]
R4 VundoFixSvc;VundoFix Service;VundoFixSVC.exe [x]
R4 WDBtnMgrSvc.exe;WD Drive Manager Service;c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe [2008-05-16 102400]
R4 WTouchService;WTouch Service;c:\program files\WTouch\WTouchService.exe [2009-11-23 113448]
S0 07663842;07663842 Boot Guard Driver;c:\windows\system32\DRIVERS\07663842.sys [2009-10-22 37392]
S0 25825422;25825422 Boot Guard Driver;c:\windows\system32\DRIVERS\25825422.sys [2009-10-22 37392]
S0 41835662;41835662 Boot Guard Driver;c:\windows\system32\DRIVERS\41835662.sys [2009-10-22 37392]
S0 61669202;61669202 Boot Guard Driver;c:\windows\system32\DRIVERS\61669202.sys [2009-10-22 37392]
S0 85710942;85710942 Boot Guard Driver;c:\windows\system32\DRIVERS\85710942.sys [2009-10-22 37392]
S0 88396992;88396992 Boot Guard Driver;c:\windows\system32\DRIVERS\88396992.sys [2009-10-22 37392]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2009-07-03 64160]
S3 WacomVTHid;Virtual Touch Driver;c:\windows\system32\DRIVERS\WacomVTHid.sys [2009-07-09 13480]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WindowsMobile REG_MULTI_SZ wcescomm rapimgr
LocalServiceRestricted REG_MULTI_SZ WcesComm RapiMgr
bthsvcs REG_MULTI_SZ BthServ
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
.
Contents of the 'Scheduled Tasks' folder
2010-03-07 c:\windows\Tasks\1-Click Maintenance.job
- c:\program files\TuneUp Utilities 2009\OneClickStarter.exe [2009-04-27 19:37]
2010-02-28 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-07-03 14:08]
2010-03-07 c:\windows\Tasks\Google Software Updater.job
- c:\program files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-11 11:07]
2010-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-14 01:25]
2010-03-07 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-09-14 01:25]
2010-02-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-04 17:22]
2010-02-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-11-04 17:22]
.
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = *.local
Trusted Zone: internet
Trusted Zone: mcafee.com
Trusted Zone: real.com\rhap-app-4-0
Trusted Zone: real.com\rhapreg
FF - ProfilePath - c:\users\Fred\AppData\Roaming\Mozilla\Firefox\Profiles\VERSION 2\
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPTURNMED.dll
FF - plugin: c:\program files\Picasa2\npPicasa2.dll
FF - plugin: c:\users\Fred\AppData\Roaming\Mozilla\plugins\npPxPlay.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);
.
.
------- File Associations -------
.
jsefile\shell\open2\command=c:\windows\System32\CScript.exe "%1" %*
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
ShellIconOverlayIdentifiers-{FB314ED9-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDA-A251-47B7-93E1-CDD82E34AF8B} - (no file)
ShellIconOverlayIdentifiers-{FB314EDB-A251-47B7-93E1-CDD82E34AF8B} - (no file)
HKLM-RunOnce-<NO NAME> - (no file)
AddRemove-Active WebCam - c:\program files\Active WebCam\PY_UNINSTAL.EXE SOFTWARE\PySoft\Act_WebCam
AddRemove-_{05D60953-9012-44DF-A1A6-9DD97AD6580A} - c:\program files\Corel\Corel Painter X\MSILauncher {05D60953-9012-44DF-A1A6-9DD97AD6580A}
AddRemove-Octoshape add-in for Adobe Flash Player - c:\users\Fred\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-03-07 06:37
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A916788E-14BA-C917-6694-8E98615249A3}\InProcServer32*]
"japdjenlicbbhfbebcce"=hex:6a,61,61,66,6b,61,6a,6e,66,62,6f,6b,6c,6c,61,61,6e,
70,65,66,00,00
"iapddehhciibopmcdg"=hex:6a,61,61,66,6c,61,6b,6e,61,65,67,70,70,63,63,64,69,6f,
6b,6b,00,00
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{BEB3C0C7-B648-4257-96D9-B5D024816E27}\Version*Version]
"Version"=hex:1f,a0,84,35,4c,77,de,c9,da,c9,ec,48,f5,b2,30,d3,aa,94,c6,5b,a1,
2b,49,5e,b8,38,1c,22,57,15,13,8d,59,21,fe,6a,0a,3d,7a,4a,ef,b9,cf,9a,24,d4,\
[HKEY_LOCAL_MACHINE\software\Minnetonka Audio Software\SurCode Dolby Digital Premiere\Version*Version]
"Version"=hex:1f,a0,84,35,4c,77,de,c9,da,c9,ec,48,f5,b2,30,d3,aa,94,c6,5b,a1,
2b,49,5e,b8,38,1c,22,57,15,13,8d,59,21,fe,6a,0a,3d,7a,4a,ef,b9,cf,9a,24,d4,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-03-07 07:58:51
ComboFix-quarantined-files.txt 2010-03-07 12:58
ComboFix2.txt 2008-10-20 18:17
Pre-Run: 66,744,586,240 bytes free
Post-Run: 66,507,948,032 bytes free
- - End Of File - - 7771EA4DC9283C281E4CD4E8F056A7F4
Regards,
Fred
Edited by myrti, 07 March 2010 - 03:43 PM.
removed serial number