ComboFix Pt. 3+ 2009-08-10 19:28 . 2008-06-20 01:14 168968 c:\windows\assembly\GAC_MSIL\ComSvcConfig\3.0.0.0__b03f5f7f11d50a3a\ComSvcConfig.exe
+ 2009-08-10 19:28 . 2008-06-20 01:14 368640 c:\windows\assembly\GAC_32\System.Printing\3.0.0.0__31bf3856ad364e35\System.Printing.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 163840 c:\windows\assembly\GAC_32\Microsoft.Transactions.Bridge.Dtc\3.0.0.0__b03f5f7f11d50a3a\Microsoft.Transactions.Bridge.Dtc.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1630208 c:\windows\winsxs\x86_wwf-system.workflow.componentmodel_31bf3856ad364e35_6.0.6001.22208_none_8c75ba7a272c
1073\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1630208 c:\windows\winsxs\x86_wwf-system.workflow.componentmodel_31bf3856ad364e35_6.0.6001.18096_none_8b88cbe90e59
3c4d\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1630208 c:\windows\winsxs\x86_wwf-system.workflow.componentmodel_31bf3856ad364e35_6.0.6000.20864_none_8a4a9b242a39
c1cc\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1630208 c:\windows\winsxs\x86_wwf-system.workflow.componentmodel_31bf3856ad364e35_6.0.6000.16708_none_8a05df0910e7
dfb8\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1138688 c:\windows\winsxs\x86_wwf-system.workflow.activities_31bf3856ad364e35_6.0.6001.22208_none_32f793e391151502\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1138688 c:\windows\winsxs\x86_wwf-system.workflow.activities_31bf3856ad364e35_6.0.6001.18096_none_320aa552784240dc\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:12 1138688 c:\windows\winsxs\x86_wwf-system.workflow.activities_31bf3856ad364e35_6.0.6000.20864_none_30cc748d9422c65b\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1138688 c:\windows\winsxs\x86_wwf-system.workflow.activities_31bf3856ad364e35_6.0.6000.16708_none_3087b8727ad0e447\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1245184 c:\windows\winsxs\x86_wpf-windowsbase_31bf3856ad364e35_6.0.6001.22208_none_57feade560dc8728\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1245184 c:\windows\winsxs\x86_wpf-windowsbase_31bf3856ad364e35_6.0.6001.18096_none_5711bf544809b302\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:12 1245184 c:\windows\winsxs\x86_wpf-windowsbase_31bf3856ad364e35_6.0.6000.20864_none_55d38e8f63ea3881\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1245184 c:\windows\winsxs\x86_wpf-windowsbase_31bf3856ad364e35_6.0.6000.16708_none_558ed2744a98566d\WindowsBase.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 5283840 c:\windows\winsxs\x86_wpf-presentationframework_31bf3856ad364e35_6.0.6001.22208_none_6f17fd076f0ccf52\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5283840 c:\windows\winsxs\x86_wpf-presentationframework_31bf3856ad364e35_6.0.6001.18096_none_6e2b0e765639fb2c\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 5283840 c:\windows\winsxs\x86_wpf-presentationframework_31bf3856ad364e35_6.0.6000.20864_none_6cecddb1721a80ab\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:18 5283840 c:\windows\winsxs\x86_wpf-presentationframework_31bf3856ad364e35_6.0.6000.16708_none_6ca8219658c89e97\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 5931008 c:\windows\winsxs\x86_wcf-system.servicemodel_b03f5f7f11d50a3a_6.0.6001.22208_none_fe2a5a5f051cb345\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5931008 c:\windows\winsxs\x86_wcf-system.servicemodel_b03f5f7f11d50a3a_6.0.6001.18096_none_1501316ceb6d03bb\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 5931008 c:\windows\winsxs\x86_wcf-system.servicemodel_b03f5f7f11d50a3a_6.0.6000.20864_none_fe54bb7304c5d874\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:17 5931008 c:\windows\winsxs\x86_wcf-system.servicemodel_b03f5f7f11d50a3a_6.0.6000.16708_none_151c0556eb2446e8\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 1738760 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6001.22208_none_acc2b340a90ab125\wpfgfx_v0300.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 4210688 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6001.22208_none_acc2b340a90ab125\PresentationCore.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 1738760 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6001.18096_none_abd5c4af9037dcff\wpfgfx_v0300.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 4210688 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6001.18096_none_abd5c4af9037dcff\PresentationCore.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 1738760 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6000.20864_none_aa9793eaac18627e\wpfgfx_v0300.dll
+ 2009-08-10 19:28 . 2008-06-20 01:12 4210688 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6000.20864_none_aa9793eaac18627e\PresentationCore.dll
+ 2009-08-10 19:27 . 2008-06-20 01:18 1738760 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6000.16708_none_aa52d7cf92c6806a\wpfgfx_v0300.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 4210688 c:\windows\winsxs\x86_presentationcore_31bf3856ad364e35_6.0.6000.16708_none_aa52d7cf92c6806a\PresentationCore.dll
+ 2009-08-08 18:47 . 2009-06-17 08:02 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.22160_none_f4b74f0181eee730\OESpamFilter.dat
+ 2009-08-08 18:47 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6002.18056_none_f43e83de68c3c37f\OESpamFilter.dat
+ 2009-08-08 18:47 . 2009-06-17 07:30 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.22459_none_f2e4af9f84b85a2a\OESpamFilter.dat
+ 2009-08-08 18:47 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6001.18278_none_f24470cc6babdbc4\OESpamFilter.dat
+ 2009-08-08 18:47 . 2009-06-17 07:35 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.21074_none_f0e3a5eb87a6b883\OESpamFilter.dat
+ 2009-08-08 18:47 . 2009-06-17 07:36 2409776 c:\windows\winsxs\x86_microsoft-windows-oespamfilter-dat_31bf3856ad364e35_6.0.6000.16876_none_f05c31926e871825\OESpamFilter.dat
+ 2009-08-08 18:45 . 2009-07-18 11:45 6081024 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.22180_none_66bc01a4c4a3d534\ieframe.dll
+ 2009-08-08 18:45 . 2009-07-18 11:32 6079488 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6002.18071_none_663e350fab7d32d0\ieframe.dll
+ 2009-08-08 18:45 . 2009-07-18 09:55 6072832 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.22475_none_64e5611ac770e2d2\ieframe.dll
+ 2009-08-08 18:45 . 2009-07-18 16:01 6069248 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6001.18294_none_64452247ae64646c\ieframe.dll
+ 2009-08-08 18:46 . 2009-07-18 12:09 6070784 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.21089_none_62f829ecca4f0949\ieframe.dll
+ 2009-08-08 18:46 . 2009-07-18 12:10 6067200 c:\windows\winsxs\x86_microsoft-windows-ieframe_31bf3856ad364e35_6.0.6000.16890_none_625ae279b1416e1f\ieframe.dll
+ 2009-08-08 18:46 . 2009-07-18 11:45 3600384 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.22180_none_155ca7a138ae4707\mshtml.dll
+ 2009-08-08 18:46 . 2009-07-18 11:33 3599360 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6002.18071_none_14dedb0c1f87a4a3\mshtml.dll
+ 2009-08-08 18:45 . 2009-07-18 11:54 3584512 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.22475_none_138607173b7b54a5\mshtml.dll
+ 2009-08-08 18:45 . 2009-07-18 16:02 3583488 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6001.18294_none_12e5c844226ed63f\mshtml.dll
+ 2009-08-08 18:46 . 2009-07-18 12:12 3600384 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.21089_none_1198cfe93e597b1c\mshtml.dll
+ 2009-08-08 18:46 . 2009-07-18 12:13 3597824 c:\windows\winsxs\x86_microsoft-windows-ie-htmlrendering_31bf3856ad364e35_6.0.6000.16890_none_10fb8876254bdff2\mshtml.dll
+ 2009-08-08 18:46 . 2009-06-18 06:56 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.21089_none_f9e7d3a487ee8c39\ieapfltr.dat
+ 2009-08-08 18:46 . 2009-06-18 06:57 2452872 c:\windows\winsxs\x86_microsoft-windows-ie-antiphishfilter_31bf3856ad364e35_6.0.6000.16890_none_f94a8c316ee0f10f\ieapfltr.dat
+ 2009-08-08 18:45 . 2009-07-18 11:47 1167872 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.22180_none_b6fcace0ed4eb73e\urlmon.dll
+ 2009-08-08 18:45 . 2009-07-18 11:34 1167872 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6002.18071_none_b67ee04bd42814da\urlmon.dll
+ 2009-08-08 18:45 . 2009-07-18 11:56 1166848 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.22475_none_b5260c56f01bc4dc\urlmon.dll
+ 2009-08-08 18:45 . 2009-07-18 16:06 1166336 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6001.18294_none_b485cd83d70f4676\urlmon.dll
+ 2009-08-08 18:45 . 2009-07-18 12:16 1163264 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.21089_none_b338d528f2f9eb53\urlmon.dll
+ 2009-08-08 18:45 . 2009-07-18 12:16 1159680 c:\windows\winsxs\x86_microsoft-windows-i..ersandsecurityzones_31bf3856ad364e35_6.0.6000.16890_none_b29b8db5d9ec5029\urlmon.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1245184 c:\windows\winsxs\msil_windowsbase_31bf3856ad364e35_6.0.6001.22208_none_97b08b7448b9ff5f\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1245184 c:\windows\winsxs\msil_windowsbase_31bf3856ad364e35_6.0.6001.18096_none_96c39ce32fe72b39\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:12 1245184 c:\windows\winsxs\msil_windowsbase_31bf3856ad364e35_6.0.6000.20864_none_95856c1e4bc7b0b8\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1245184 c:\windows\winsxs\msil_windowsbase_31bf3856ad364e35_6.0.6000.16708_none_9540b0033275cea4\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1630208 c:\windows\winsxs\msil_system.workflow.componentmodel_31bf3856ad364e35_6.0.6001.22208_none_e9
0a0d4ae97e2ccb\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1630208 c:\windows\winsxs\msil_system.workflow.componentmodel_31bf3856ad364e35_6.0.6001.18096_none_e8
1d1eb9d0ab58a5\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1630208 c:\windows\winsxs\msil_system.workflow.componentmodel_31bf3856ad364e35_6.0.6000.20864_none_e6
deedf4ec8bde24\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1630208 c:\windows\winsxs\msil_system.workflow.componentmodel_31bf3856ad364e35_6.0.6000.16708_none_e6
9a31d9d339fc10\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:13 1138688 c:\windows\winsxs\msil_system.workflow.activities_31bf3856ad364e35_6.0.6001.22208_none_293330
886c8121bc\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1138688 c:\windows\winsxs\msil_system.workflow.activities_31bf3856ad364e35_6.0.6001.18096_none_284641
f753ae4d96\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:12 1138688 c:\windows\winsxs\msil_system.workflow.activities_31bf3856ad364e35_6.0.6000.20864_none_270811
326f8ed315\System.Workflow.Activities.dll
+ 2009-08-10 19:28 . 2008-06-20 01:18 1138688 c:\windows\winsxs\msil_system.workflow.activities_31bf3856ad364e35_6.0.6000.16708_none_26c355
17563cf101\System.Workflow.Activities.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 5931008 c:\windows\winsxs\msil_system.servicemodel_b77a5c561934e089_6.0.6001.22208_none_8e1bf2cea44da
c8d\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5931008 c:\windows\winsxs\msil_system.servicemodel_b77a5c561934e089_6.0.6001.18096_none_a4f2c9dc8a9df
d03\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 5931008 c:\windows\winsxs\msil_system.servicemodel_b77a5c561934e089_6.0.6000.20864_none_8e4653e2a3f6d
1bc\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:17 5931008 c:\windows\winsxs\msil_system.servicemodel_b77a5c561934e089_6.0.6000.16708_none_a50d9dc68a554
030\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 5931008 c:\windows\winsxs\msil_system.servicemodel.ref_b77a5c561934e089_6.0.6001.22208_none_559775022
c5c3394\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5931008 c:\windows\winsxs\msil_system.servicemodel.ref_b77a5c561934e089_6.0.6001.18096_none_6c6e4c101
2ac840a\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 5931008 c:\windows\winsxs\msil_system.servicemodel.ref_b77a5c561934e089_6.0.6000.20864_none_55c1d6162
c0558c3\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:17 5931008 c:\windows\winsxs\msil_system.servicemodel.ref_b77a5c561934e089_6.0.6000.16708_none_6c891ffa1
263c737\System.ServiceModel.dll
+ 2009-08-10 19:27 . 2008-06-20 01:13 5283840 c:\windows\winsxs\msil_presentationframework_31bf3856ad364e35_6.0.6001.22208_none_774937060d1
32321\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5283840 c:\windows\winsxs\msil_presentationframework_31bf3856ad364e35_6.0.6001.18096_none_765c4874f44
04efb\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:12 5283840 c:\windows\winsxs\msil_presentationframework_31bf3856ad364e35_6.0.6000.20864_none_751e17b0102
0d47a\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:18 5283840 c:\windows\winsxs\msil_presentationframework_31bf3856ad364e35_6.0.6000.16708_none_74d95b94f6c
ef266\PresentationFramework.dll
+ 2009-08-08 18:45 . 2009-07-18 16:06 1166336 c:\windows\System32\urlmon.dll
- 2009-06-10 22:48 . 2009-04-24 16:05 1166336 c:\windows\System32\urlmon.dll
+ 2006-11-02 10:22 . 2009-08-11 05:48 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-08-08 18:53 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-08-08 18:45 . 2009-07-18 16:02 3583488 c:\windows\System32\mshtml.dll
+ 2009-08-08 18:45 . 2009-07-18 16:01 6069248 c:\windows\System32\ieframe.dll
- 2009-06-10 22:48 . 2009-04-24 16:02 6069248 c:\windows\System32\ieframe.dll
+ 2006-11-02 12:47 . 2009-08-09 17:36 2318144 c:\windows\System32\FNTCACHE.DAT
- 2006-11-02 12:47 . 2009-06-22 17:24 2318144 c:\windows\System32\FNTCACHE.DAT
+ 2008-07-30 03:40 . 2008-07-30 03:40 1720824 c:\windows\Microsoft.NET\Framework\v3.5\vbc.exe
+ 2008-07-29 22:47 . 2008-07-29 22:47 1054208 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\vs_setup.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 1364992 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\SITSetup.dll
+ 2008-07-29 22:47 . 2008-07-29 22:47 1064448 c:\windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\gencomp.dll
+ 2008-07-30 03:40 . 2008-07-30 03:40 1548280 c:\windows\Microsoft.NET\Framework\v3.5\csc.exe
+ 2009-08-10 19:27 . 2008-06-20 01:14 1738760 c:\windows\Microsoft.NET\Framework\v3.0\WPF\wpfgfx_v0300.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5931008 c:\windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\System.ServiceModel.dll
+ 2009-05-26 22:54 . 2009-05-26 22:54 4192768 c:\windows\Installer\56741.msp
+ 2009-07-02 20:23 . 2009-07-02 20:23 5027328 c:\windows\Installer\56715.msp
+ 2008-12-25 22:21 . 2009-08-09 15:30 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
- 2008-12-25 22:21 . 2009-06-15 12:11 1172240 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\xlicons.exe
+ 2008-12-25 22:21 . 2009-08-09 15:30 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2008-12-25 22:21 . 2009-06-15 12:11 1165584 c:\windows\Installer\{91120000-0014-0000-0000-0000000FF1CE}\accicons.exe
- 2009-03-17 21:49 . 2009-06-15 12:10 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
+ 2009-03-17 21:49 . 2009-08-09 15:30 1172240 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\xlicons.exe
- 2009-03-17 21:49 . 2009-06-15 12:10 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-03-17 21:49 . 2009-08-09 15:30 1165584 c:\windows\Installer\{90120000-0011-0000-0000-0000000FF1CE}\accicons.exe
+ 2009-08-10 19:35 . 2009-08-10 19:35 3311104 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\400510870f710fd409ee7fc71b4a69aa\WindowsBase.ni.dll
+ 2009-08-11 05:12 . 2009-08-11 05:12 1049600 c:\windows\assembly\NativeImages_v2.0.50727_32\UIAutomationClients#\c8b13dcfc97e24405e4fc0475ce6f8f6\UIAutomationClientsideProviders.ni.dll
+ 2009-08-11 05:12 . 2009-08-11 05:12 1355264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\2deca0680ab84ffa0d02529e6008c3af\System.WorkflowServices.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 1904128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\5d6b641086cce5fdc858845791bceb39\System.Workflow.Runtime.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 4510720 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\4ebf9425af71d1715702beddca876205\System.Workflow.ComponentModel.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 2989568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\9a3bbad437aad5decc858ca4ff6aa95e\System.Workflow.Activities.ni.dll
+ 2009-08-11 05:12 . 2009-08-11 05:12 2400256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\7a2ff61712242ed5a8ed3e2051913d8a\System.Web.Extensions.ni.dll
+ 2009-08-11 05:12 . 2009-08-11 05:12 1705984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9cd971129846bdc7b4d6f4de75d0d56f\System.ServiceModel.Web.ni.dll
+ 2009-08-11 01:21 . 2009-08-11 01:21 2338304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\6a0e6b429befa7ae3195cfc8c92ea2cc\System.Runtime.Serialization.ni.dll
+ 2009-08-11 01:22 . 2009-08-11 01:22 1035264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\828c0797125f0e89f76c00c87708cd08\System.Printing.ni.dll
+ 2009-08-11 01:21 . 2009-08-11 01:21 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\833aa4f13464ecb314a27adbcfca1e22\System.IdentityModel.ni.dll
+ 2009-08-11 05:12 . 2009-08-11 05:12 1326080 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\41610b6770b86d583f850fe48761ff0c\System.Data.Services.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 2510848 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Linq\f38eb6cd3804a40cbff2d1103f541776\System.Data.Linq.ni.dll
+ 2009-08-11 05:11 . 2009-08-11 05:11 9903104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\dd4ce78d33fde0033fa5bd50e24c8fbc\System.Data.Entity.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 2294784 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Core\6c69930d05c557da70144bcc0add7065\System.Core.ni.dll
+ 2009-08-11 01:22 . 2009-08-11 01:22 2126336 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\87d2215a3b6b8ebec883f6bf82b6b781\ReachFramework.ni.dll
+ 2009-08-11 01:21 . 2009-08-11 01:21 1656832 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\4746ed9ba78a700176711accdea55be1\PresentationUI.ni.dll
+ 2009-08-11 01:22 . 2009-08-11 01:22 1451008 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\4425dd4db3b0530d0a9369b7b259088b\PresentationBuildTasks.ni.dll
+ 2009-08-11 01:21 . 2009-08-11 01:21 1092608 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\88b610bb7a660a1b06385d595a72d272\Microsoft.Transactions.Bridge.ni.dll
+ 2009-08-11 01:22 . 2009-08-11 01:22 1965568 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\cd6eeb3d7ea1f65c28a43e665db38644\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2009-08-11 01:22 . 2009-08-11 01:22 1886208 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\ce984d7bbd9a6d5d3cca28c4e5038020\Microsoft.Build.Engine.ni.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1245184 c:\windows\assembly\GAC_MSIL\WindowsBase\3.0.0.0__31bf3856ad364e35\WindowsBase.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1630208 c:\windows\assembly\GAC_MSIL\System.Workflow.ComponentModel\3.0.0.0__31bf3856ad364e35\System.Workflow.ComponentModel.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 1138688 c:\windows\assembly\GAC_MSIL\System.Workflow.Activities\3.0.0.0__31bf3856ad364e35\System.Workflow.Activities.dll
+ 2009-08-10 19:33 . 2009-08-10 19:33 1277952 c:\windows\assembly\GAC_MSIL\System.Web.Extensions\3.5.0.0__31bf3856ad364e35\System.Web.Extensions.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5931008 c:\windows\assembly\GAC_MSIL\System.ServiceModel\3.0.0.0__b77a5c561934e089\System.ServiceModel.dll
+ 2009-08-10 19:33 . 2009-08-10 19:33 2879488 c:\windows\assembly\GAC_MSIL\System.Data.Entity\3.5.0.0__b77a5c561934e089\System.Data.Entity.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 5283840 c:\windows\assembly\GAC_MSIL\PresentationFramework\3.0.0.0__31bf3856ad364e35\PresentationFramework.dll
+ 2009-08-10 19:27 . 2008-06-20 01:14 1738760 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
+ 2009-08-10 19:28 . 2008-06-20 01:14 4210688 c:\windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\PresentationCore.dll
+ 2009-06-13 07:01 . 2009-08-10 19:32 77842451 c:\windows\winsxs\ManifestCache\6.0.6002.18005_001c11ba_blobs.bin
+ 2006-11-02 10:24 . 2009-07-07 15:10 24539592 c:\windows\System32\mrt.exe
+ 2009-08-11 01:21 . 2009-08-11 01:21 17313792 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\8916ab751fafa7245dc9dfa6cfac3cfc\System.ServiceModel.ni.dll
+ 2009-08-10 19:36 . 2009-08-10 19:36 14320128 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\2606f840d6783c9c2307965650735ada\PresentationFramework.ni.dll
+ 2009-08-10 19:35 . 2009-08-10 19:35 12213248 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\9895974a8ff48335614f44603ff16a9d\PresentationCore.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2008-12-16 39408]
"RocketDock"="c:\program files\RocketDock\RocketDock.exe" [2007-09-02 495616]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-12-29 687560]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"Apoint"="c:\program files\DellTPad\Apoint.exe" [2008-07-17 196608]
"SysTrayApp"="c:\program files\IDT\WDM\sttray.exe" [2008-07-17 442433]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-07-18 150040]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-07-18 170520]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-07-18 145944]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2008-08-05 3563520]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 34672]
"Google Desktop Search"="c:\program files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-12-16 30192]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-01-09 645328]
"Dell Webcam Central"="c:\program files\Dell Webcam\Dell Webcam Central\WebcamDell.exe" [2008-06-03 446635]
"PCMService"="c:\program files\Dell\MediaDirect\PCMService.exe" [2008-01-14 132392]
"dellsupportcenter"="c:\program files\Dell Support Center\bin\sprtcmd.exe" [2008-10-04 206064]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2008-11-02 167936]
"nmctxth"="c:\program files\Common Files\Pure Networks Shared\Platform\nmctxth.exe" [2008-12-12 642856]
"nmapp"="c:\program files\Pure Networks\Network Magic\nmapp.exe" [2008-12-14 467240]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-01-09 1176808]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"Adobe Acrobat Speed Launcher"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe" [2008-06-12 37232]
"Acrobat Assistant 8.0"="c:\program files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe" [2008-06-12 640376]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-26 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-06-05 292136]
"RemoteControl8"="c:\program files\CyberLink\PowerDVD8\PDVD8Serv.exe" [2008-03-21 83240]
"PDVD8LanguageShortcut"="c:\program files\CyberLink\PowerDVD8\Language\Language.exe" [2007-12-14 50472]
"BDRegion"="c:\program files\Cyberlink\Shared Files\brs.exe" [2009-06-24 91432]
c:\users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2006-1-21 118784]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
QuickSet.lnk - c:\program files\Dell\QuickSet\quickset.exe [2008-7-9 1616976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\SharedTaskScheduler]
"{73526E5A-FD53-4BE7-B5E2-D3C89D7413DC}"= "c:\users\Brandon\Documents\Downloads\Compressed\AveFolderBg\32bits\VistaFolderBackground.dll" [2008-09-17 184320]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\progra~1\Google\GOOGLE~3\GoogleDesktopNetwork3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
SetupExecute REG_MULTI_SZ \0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{83EBE4D4-420E-4770-A6EA-72C1B6139ACC}"= Profile=Private|Profile=Public|c:\program files\Common Files\Mcafee\MNA\McNaSvc.exe:McAfee Network Agent
"{5DA30AFC-D792-46F0-AAD1-B06D75914C5C}"= c:\program files\Dell\MediaDirect\MediaDirect.exe:Dell MediaDirect
"{3276E660-7CEC-4959-AD16-340C5B4CDDF1}"= c:\program files\Dell\MediaDirect\PCMService.exe:CyberLink PowerCinema Resident Program
"{63B77538-D270-49E2-BDB7-E26C92616C65}"= c:\program files\Dell\MediaDirect\Kernel\DMP\CLBrowserEngine.exe:Cyberlink Media Server Browser Engine
"{E2D0029C-0CDF-4081-9401-68CF7AF8732E}"= c:\program files\Dell\MediaDirect\Kernel\DMS\CLMSService.exe:CyberLink Media Server
"{D05DE99F-D323-4130-963F-6181DBABB181}"= UDP:c:\program files\Dell Remote Access\ezi_ra.exe:Dell Remote Access
"{AFEA741D-E902-42A5-AEB6-77F5762AD625}"= TCP:c:\program files\Dell Remote Access\ezi_ra.exe:Dell Remote Access
"{5BF27FD1-310A-42DA-B3B6-48FAF15C1F11}"= UDP:c:\programdata\SingleClick Systems\Advanced Networking Service\hnm_svc.exe:Advanced Networking Service
"{FED72049-7622-4DDB-87EC-7B84366DD52A}"= TCP:c:\programdata\SingleClick Systems\Advanced Networking Service\hnm_svc.exe:Advanced Networking Service
"{02B4B086-FA54-473E-831E-A7FB64D1501B}"= UDP:c:\program files\Dell Video Chat\DellVideoChat.exe:SightSpeed
"{C688789D-9D25-4278-A4B7-2FFC86A4C565}"= TCP:c:\program files\Dell Video Chat\DellVideoChat.exe:SightSpeed
"{D33E9505-6F0A-491E-A514-5E255FAF86AF}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{96A6E6BE-03B2-4AA1-8E4A-0A05B4628D05}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3E77C399-2295-42C2-B5DF-7E1F7C00E271}"= UDP:c:\windows\System32\dldtcoms.exe:V305 Server
"{6E87E812-B5B6-4C80-9EB7-09029BE3D566}"= TCP:c:\windows\System32\dldtcoms.exe:V305 Server
"{9D2A0E06-BE68-4E98-AD26-B03084332911}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{AA8755D8-C835-4B5F-991E-D1DC541704F8}"= Disabled:UDP:c:\programdata\SingleClick Systems\VLC\vlc.exe:Remote Access VLC
"{DEC841EC-3E88-4919-8F1D-8B1670DBACB3}"= Disabled:TCP:c:\programdata\SingleClick Systems\VLC\vlc.exe:Remote Access VLC
"{5922F539-6744-42E2-83B8-109F30836DC2}"= UDP:c:\users\Brandon\Downloads\utorrent.exe:µTorrent (TCP-In)
"{00E20032-68C0-4940-9FE3-A9038AEB0C66}"= TCP:c:\users\Brandon\Downloads\utorrent.exe:µTorrent (UDP-In)
"{D1D21194-0F4E-4B52-9B0F-EBC3FE0EBBEB}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{8BE3EA4B-5691-4A3C-B292-0C79730B7B6B}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{E0BE5A99-AA27-4149-B223-1A6400F4B02D}c:\\program files\\thq\\company of heroes\\reliccoh.exe"= UDP:c:\program files\thq\company of heroes\reliccoh.exe:RelicCOH
"UDP Query User{FBAD8F50-A553-4441-85F3-941612C4BBF4}c:\\program files\\thq\\company of heroes\\reliccoh.exe"= TCP:c:\program files\thq\company of heroes\reliccoh.exe:RelicCOH
"{C569B9A3-8CEF-40DC-AA5B-A76C820B178B}"= UDP:c:\program files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"{0E0FCDA2-C2AD-4FBA-9DE0-647274A1039B}"= TCP:c:\program files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"TCP Query User{7C90511D-4A71-4A41-AEEE-758FF6DAAE80}c:\\program files\\bohemia interactive\\arma\\arma.exe"= UDP:c:\program files\bohemia interactive\arma\arma.exe:ArmA
"UDP Query User{04E2D00C-C683-4622-BBC5-20E19FFEDFC6}c:\\program files\\bohemia interactive\\arma\\arma.exe"= TCP:c:\program files\bohemia interactive\arma\arma.exe:ArmA
"TCP Query User{A9F4ACD7-F98C-4127-913A-1ACD4270CEE3}c:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= UDP:c:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java Platform SE binary
"UDP Query User{2C7C9D74-7D17-4E20-83D4-B2576DF9354F}c:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= TCP:c:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java Platform SE binary
"TCP Query User{8B2D711B-4638-4ED9-A25C-2F83B2CFF680}c:\\windows\\system32\\java.exe"= UDP:c:\windows\system32\java.exe:Java Platform SE binary
"UDP Query User{02ED14D3-38E8-48DD-995B-84F3543B566A}c:\\windows\\system32\\java.exe"= TCP:c:\windows\system32\java.exe:Java Platform SE binary
"{4F0188FC-6227-4965-B077-607E250234CF}"= UDP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{F50E3B51-7E9B-41B8-9351-F5732E0BC121}"= TCP:c:\program files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{9F4749D8-F8D4-41FE-B735-B280F82C02D2}c:\\program files\\corel\\dvd9\\windvd.exe"= UDP:c:\program files\corel\dvd9\windvd.exe:WinDVD
"UDP Query User{A0A8ABF6-D28A-4B23-BE7C-AD8050BA815D}c:\\program files\\corel\\dvd9\\windvd.exe"= TCP:c:\program files\corel\dvd9\windvd.exe:WinDVD
"{C08916A0-B3F0-4C38-8EAD-F305A3FD4E80}"= UDP:c:\users\Brandon\Downloads\utorrent.exe:µTorrent (TCP-In)
"{BB1A5692-3A89-4301-8B8C-49D4DF182310}"= TCP:c:\users\Brandon\Downloads\utorrent.exe:µTorrent (UDP-In)
"{AAB92EDE-AAD6-47AD-B112-C4278DA22C85}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{FEB2FB92-5A6D-4B6C-BFA2-77A761F0295A}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{B29E131E-EB0F-4EFC-B95A-590CCCF7C4B7}"= c:\program files\Rosetta Stone\Rosetta Stone V3\RosettaStoneVersion3.exe:Rosetta Stone V3 Application
"{BABC665E-F652-4A37-BEC8-7C75850CA3C5}"= c:\program files\Rosetta Stone\Rosetta Stone V3\RosettaStoneVersion3.exe:Rosetta Stone V3 Application
"{ECEBB919-64E0-455F-8067-7311AD54222C}"= TCP:67:DHCP Discovery Service
"{E83E16F2-4C9C-4EC0-82CD-4F009113D2B9}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{A312F297-7BB3-4116-8535-E6DB76A6D61E}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"TCP Query User{3981A14B-82DB-46F8-92AB-3B40013947A2}c:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= UDP:c:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java Platform SE binary
"UDP Query User{BFA43B18-BFCC-4EE1-96DE-8C168531A418}c:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= TCP:c:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java Platform SE binary
"TCP Query User{8A5B3753-C0A8-4515-96C2-B0E1FFBDDCAA}c:\\windows\\system32\\java.exe"= UDP:c:\windows\system32\java.exe:Java Platform SE binary
"UDP Query User{BACB5001-B936-4CD9-BF94-FF891DB6F3D8}c:\\windows\\system32\\java.exe"= TCP:c:\windows\system32\java.exe:Java Platform SE binary
"TCP Query User{CC54EA53-A8CA-4EA1-9C7A-2B214504AFCD}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:µTorrent
"UDP Query User{95626CA2-E99A-4360-9F7B-F811751A4CCC}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:µTorrent
"{07EB25C7-D697-4E7D-94E7-9B8904D98DB0}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{10B47747-A986-40B2-9680-211029088F15}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{B74BA92B-25BE-4063-9532-78A083D1A0EB}"= UDP:5353:Adobe CSI CS4
"{29E554A0-21D5-45BB-8C80-52A2A7A8E5EA}"= UDP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{F70A48F7-69AD-401A-8AD0-D85FA9226A8B}"= TCP:c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:Adobe CSI CS4
"{8B2F7E38-6094-4DE7-BBFA-C76729CCC0E6}"= UDP:3703:Adobe Version Cue CS4 Server
"{ADB4A37E-5526-49B2-BC05-344F6687D986}"= UDP:3704:Adobe Version Cue CS4 Server
"{397A7695-A3E5-4D70-8920-8482AC1ED959}"= UDP:51000:Adobe Version Cue CS4 Server
"{1B48C767-F255-40BC-A80A-4D275D9CF666}"= UDP:51001:Adobe Version Cue CS4 Server
"{5C027302-A250-43D3-B203-01C59C4F7916}"= UDP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server
"{560AE378-2AFA-4B2F-8445-4E7DD661DB5B}"= TCP:c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe:Adobe Version Cue CS4 Server
"{417BD20A-AA5D-4085-9D94-728E9528B7C8}"= UDP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"{0F878590-77B0-4DBF-BEA2-66AC33EABAC2}"= TCP:c:\program files\LimeWire\LimeWire.exe:LimeWire
"TCP Query User{74DBDB92-FC02-469A-BFEF-9D9C34F5C8F4}c:\\program files\\mozilla firefox\\firefox.exe"= UDP:c:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{16D936E0-F492-406C-96E8-0F52073E6FC3}c:\\program files\\mozilla firefox\\firefox.exe"= TCP:c:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{70C44E82-B287-4B91-9F1B-99F25046D5B2}c:\\windows\\system32\\spool\\drivers\\w32x86\\3\\dldtpswx.exe"= UDP:c:\windows\system32\spool\drivers\w32x86\3\dldtpswx.exe:Printer Status Window Interface
"UDP Query User{B6C288BB-379F-4AAB-AD9F-5F9F63D7AB6B}c:\\windows\\system32\\spool\\drivers\\w32x86\\3\\dldtpswx.exe"= TCP:c:\windows\system32\spool\drivers\w32x86\3\dldtpswx.exe:Printer Status Window Interface
"TCP Query User{4DFF0279-A1CA-4B1C-8533-9B01BA55F9CE}c:\\users\\brandon\\downloads\\torrents\\left.4.dead.full-rip.skullptura\\left.4.dead.full-rip.skullptura\\left 4 dead\\left4dead.exe"= UDP:c:\users\brandon\downloads\torrents\left.4.dead.full-rip.skullptura\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe:left4dead.exe
"UDP Query User{A27675BE-C887-407E-960D-7654F21147C6}c:\\users\\brandon\\downloads\\torrents\\left.4.dead.full-rip.skullptura\\left.4.dead.full-rip.skullptura\\left 4 dead\\left4dead.exe"= TCP:c:\users\brandon\downloads\torrents\left.4.dead.full-rip.skullptura\left.4.dead.full-rip.skullptura\left 4 dead\left4dead.exe:left4dead.exe
"{FA746B78-F747-4F43-B0E6-FA43F436A626}"= UDP:c:\program files\Hamachi\hamachi.exe:Hamachi
"{FB6D18D0-60F8-44C3-90E2-4F13866AAEF6}"= TCP:c:\program files\Hamachi\hamachi.exe:Hamachi
"{E909E2FF-A708-42C0-8F23-7E73FCD9FEB2}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{361C93C3-FDB9-4145-80EC-C38B9CFF2CD4}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{57061080-9DEB-4CCC-98CF-1FD7A213A673}"= UDP:c:\program files\AIM6\aim6.exe:AIM
"{608650D9-0567-4B33-9367-E67BEC08BC90}"= TCP:c:\program files\AIM6\aim6.exe:AIM
"TCP Query User{C0189F08-AEFB-45C9-BF62-7536AAE5418D}c:\\program files\\limewire\\limewire.exe"= UDP:c:\program files\limewire\limewire.exe:LimeWire
"UDP Query User{C978A9B0-4D40-4BC5-8B9B-D9FF67751B92}c:\\program files\\limewire\\limewire.exe"= TCP:c:\program files\limewire\limewire.exe:LimeWire
"{CC1AB3BA-32E5-4AAA-A331-86B0B5341310}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"{B564F6F0-DA3A-464E-8666-031D0516A753}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour
"TCP Query User{9CD34495-1988-43D8-93EF-B1F12F15E287}c:\\windows\\system32\\spool\\drivers\\w32x86\\3\\dldtpswx.exe"= UDP:c:\windows\system32\spool\drivers\w32x86\3\dldtpswx.exe:Printer Status Window Interface
"UDP Query User{4DD8914C-E120-4DD7-A76E-76422E68417E}c:\\windows\\system32\\spool\\drivers\\w32x86\\3\\dldtpswx.exe"= TCP:c:\windows\system32\spool\drivers\w32x86\3\dldtpswx.exe:Printer Status Window Interface
"{413B7B6A-C2EB-48F8-A046-65F510A6ADAA}"= TCP:67:DHCP Discovery Service
"{7981B309-AFFD-4084-AD91-815025BAEA59}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{B9479245-6BC3-40D2-9635-FEA8E96E98AA}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"TCP Query User{859F62A1-403E-4913-805F-9A5D4D8E6B10}c:\\users\\brandon\\downloads\\new folder\\utorrent.exe"= UDP:c:\users\brandon\downloads\new folder\utorrent.exe:utorrent.exe
"UDP Query User{7E80C1C0-ADBD-48B8-BE23-7BE72ACE0BC6}c:\\users\\brandon\\downloads\\new folder\\utorrent.exe"= TCP:c:\users\brandon\downloads\new folder\utorrent.exe:utorrent.exe
"{8437E028-A85A-4AA9-B203-C0FB2BDF0CE7}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{BC1A49B0-7300-4855-ACB6-2E76F97D5552}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{402351C0-CAFD-4C8A-937C-C36D11D06561}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{F1082134-CF0A-424F-8304-6A34A80F6C49}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{970F42F2-64E7-4D0C-A4EB-3D0A5BE3F36C}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{B4870AA1-A182-4FE1-8253-C14BCE1E7714}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{8B14894A-9F7F-4299-A472-59E3A47C1D43}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{7154ED56-7482-404D-B968-59B9B8ACC734}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{D04A3B03-AF48-4BBC-A0EB-F63EFDF77113}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{C6F32EE2-4E27-46A3-9732-8089BA85DAF2}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{B3D5976D-72A1-4DAD-BDEF-632C4BD289DF}c:\\users\\brandon\\documents\\my games\\left 4 dead\\left4dead.exe"= UDP:c:\users\brandon\documents\my games\left 4 dead\left4dead.exe:left4dead.exe
"UDP Query User{C1CEB6D3-71F9-4D64-98CC-E528B2E2B0E8}c:\\users\\brandon\\documents\\my games\\left 4 dead\\left4dead.exe"= TCP:c:\users\brandon\documents\my games\left 4 dead\left4dead.exe:left4dead.exe
"{B9C83106-D278-4AF9-863F-4B1DB4680D31}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{0FCC08F5-19E0-4E20-B9C1-FD04D9532B6E}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{BBD3E1E4-E281-48B6-AB1E-313808934264}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{AA2052AA-9FE2-447D-91AB-1CF8DCCDF62C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{8B76376D-8B64-4B64-A2A8-8FB64BAC7D3F}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{197D8A14-1FCE-48E5-9D51-B8A3D3BBDA1D}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{6CF5E2EA-A038-4899-A914-82FDC5D3A9E5}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{FCECA3D6-5FEE-4618-9547-53811F68C533}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{040E7865-A8C8-4481-A76F-58468AFAB90C}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{4617E45F-8D52-4752-985E-403C7173F252}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{53BB006C-C402-4319-A44F-C75EE82CC943}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\RosettaStoneVersion3.exe:Rosetta Stone Version 3 Application
"{EFDC1CF0-BD88-4C9B-92B2-860F38FA8CAC}"= c:\program files\Rosetta Stone\Rosetta Stone Version 3\support\bin\win\RosettaStoneLtdServices.exe:Rosetta Stone Ltd Services
"{085B09F6-64F7-4941-835D-00D8ABAD4BE8}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{8718FEAD-D596-4A96-9F75-5E2922E6B8F1}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{AE51EC29-4960-4F30-8E8A-A839162E8ADD}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{DF0F80B5-56A0-493F-82BE-DF87680A200F}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{BBAD0EBD-BA1D-411B-B19F-493C9D6CA653}"= c:\program files\CyberLink\PowerDVD8\PowerDVD8.EXE:CyberLink PowerDVD 8.0
"{532E270B-2C21-404D-92DC-7AEB30D43953}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{6230EC30-B3C3-4ABF-A43F-1E821B12BF62}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{83EDB4EE-8770-452A-993B-C27E82320B49}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{362ED3DD-7D1B-46DB-BE10-D43109DBC23C}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{1CE637DA-AC58-4303-97BC-0FFBE22E5B9F}"= UDP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (TCP-In)
"{8E3DA0E5-D01A-49C0-8066-9264728BE30C}"= TCP:c:\users\Brandon\Downloads\New Folder\utorrent.exe:µTorrent (UDP-In)
"{334795D2-1775-40D0-B812-24E21E3FE600}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{607E302F-CFD0-4471-AC4D-9BB9F9BB7589}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{C89CE12A-38D0-479C-8FB5-E46069B69A7D}"= UDP:c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:Pure Networks Platform Service
"{77C2B7C6-4C1D-4C7A-9FBD-53607CAB67A4}"= TCP:c:\program files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe:Pure Networks Platform Service
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};c:\program files\CyberLink\PowerDVD8\000.fcl [5/15/2008 12:07 PM 61424]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\System32\DriverStore\FileRepository\stwrt.inf_f091b975\AEstSrv.exe [12/16/2008 9:04 PM 73728]
R2 dldt_device;dldt_device;c:\windows\system32\dldtcoms.exe -service --> c:\windows\system32\dldtcoms.exe -service [?]
R2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [9/24/2008 12:09 AM 155648]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [1/9/2009 12:51 PM 210216]
R2 regi;regi;c:\windows\System32\drivers\regi.sys [4/17/2007 9:09 PM 11032]
R3 IntcHdmiAddService;Intel® High Definition Audio HDMI;c:\windows\System32\drivers\IntcHdmi.sys [12/16/2008 9:04 PM 113664]
R3 itecir;ITECIR Infrared Receiver;c:\windows\System32\drivers\itecir.sys [12/16/2008 9:04 PM 54784]
R3 k57nd60x;Broadcom NetLink Gigabit Ethernet - NDIS 6.0;c:\windows\System32\drivers\k57nd60x.sys [12/16/2008 9:04 PM 203264]
R3 MBAMProtector;MBAMProtector;c:\windows\System32\drivers\mbam.sys [8/2/2009 5:27 PM 19096]
R3 OA001Ufd;Creative Camera OA001 Upper Filter Driver;c:\windows\System32\drivers\OA001Ufd.sys [12/16/2008 9:04 PM 144672]
R3 OA001Vid;Creative Camera OA001 Function Driver;c:\windows\System32\drivers\OA001Vid.sys [12/16/2008 9:04 PM 277632]
S2 MBAMService;MBAMService;c:\program files\Malwarebytes' Anti-Malware\mbamservice.exe [8/2/2009 5:27 PM 211216]
S3 Adobe Version Cue CS4;Adobe Version Cue CS4;c:\program files\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe [8/15/2008 6:46 AM 284016]
S3 GoogleDesktopManager-092308-165331;Google Desktop Manager 5.8.809.23506;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [12/16/2008 7:45 PM 30192]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - PNKBSTRK
*Deregistered* - PnkBstrK
.
Contents of the 'Scheduled Tasks' folder
2009-03-15 c:\windows\Tasks\McDefragTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-27 14:53]
2009-07-01 c:\windows\Tasks\McQcTask.job
- c:\progra~1\mcafee\mqc\QcConsol.exe [2009-03-27 14:53]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=3081217
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://www.google.com/search/?q=%s
IE: &AIM Toolbar Search - c:\programdata\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
IE: Append Link Target to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Append to Existing PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert Link Target to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert to Adobe PDF - c:\program files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\7pkx9c9b.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrie7&query=
FF - prefs.js: browser.search.selectedEngine - Wikipedia (en)
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType=tb50fftrab&query=
FF - component: c:\program files\Mozilla Firefox\components\GoogleDesktopMozilla.dll
FF - component: c:\users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\7pkx9c9b.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\K-Lite Codec Pack\Real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: c:\users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\7pkx9c9b.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll
FF - plugin: c:\users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\7pkx9c9b.default\extensions\piclens@cooliris.com\plugins\npcoolirisplugin.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2009-08-11 19:59
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}]
"ImagePath"="\??\c:\program files\CyberLink\PowerDVD8\000.fcl"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-2873835703-867658926-3654523082-1000_Classes\CLSID\{5ED60779-4DE2-4E07-B862-974CA4FF2E9C}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"scansk"=hex(0):fe,f9,02,01,49,51,2d,a9,51,ce,c1,b9,cc,fa,8d,f0,21,da,c3,c8,27,
a2,da,bb,f8,d8,30,8b,17,45,c3,61,6a,a3,23,10,14,95,87,a9,00,00,00,00,00,00,\
[HKEY_USERS\S-1-5-21-2873835703-867658926-3654523082-1000_Classes\CLSID\{f310d0cc-7f52-40b9-b20d-ea09c65043ee}]
@Denied: (Full) (Everyone)
@Allowed: (Read) (RestrictedCode)
"Model"=dword:00000037
"Therad"=dword:0000001e
"MData"=hex(0):2b,8f,78,29,5a,0c,ce,ec,48,d4,68,e5,9f,6a,96,3e,ab,de,c5,81,26,
38,95,44,f8,0b,f2,c4,7d,43,2e,bd,6a,e5,31,bf,56,c8,9e,be,15,3a,96,84,18,94,\
.
Completion time: 2009-08-11 20:02
ComboFix-quarantined-files.txt 2009-08-12 00:02
ComboFix2.txt 2009-08-08 19:56
Pre-Run: 144,958,623,744 bytes free
Post-Run: 144,989,466,624 bytes free
1184 --- E O F --- 2009-08-10 15:09