System is running better then before now, thanks.
Heres the ComboFix Log:
ComboFix 08-08-18.01 - Boss 2008-08-18 17:06:23.10 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1033.18.2080 [GMT -7:00]
Running from: C:\Users\Boss\Desktop\ComboFix.exe
Command switches used :: C:\Users\Boss\Desktop\CFScript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][2].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\boss@fastclick[1].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\boss@findarticles[1].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\boss@gamespot[2].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\boss@insightexpressai[1].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\
[email protected][1].txt
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Cookies\boss@revsci[1].txt
.
((((((((((((((((((((((((( Files Created from 2008-07-19 to 2008-08-19 )))))))))))))))))))))))))))))))
.
2008-08-17 15:03 . 2008-08-17 15:08 <DIR> d-------- C:\HijackThis2
2008-08-17 15:00 . 2008-08-17 15:00 <DIR> d-------- C:\HijackThis
2008-08-17 14:48 . 2008-08-17 15:06 <DIR> d-------- C:\Users\All Users\Microsoft
2008-08-17 14:31 . 2008-08-17 14:31 2,718,447 --a------ C:\Users\Boss\ComboFix.exe
2008-08-17 14:21 . 2008-08-17 14:21 <DIR> d-------- C:\_OTMoveIt
2008-08-17 14:20 . 2008-08-17 14:20 291,840 --a------ C:\Users\Boss\OTMoveIt2.exe
2008-08-17 14:18 . 2008-08-17 14:18 <DIR> d-------- C:\Program Files\ERUNT
2008-08-17 14:18 . 2008-08-17 14:18 791,393 --a------ C:\Users\Boss\erunt-setup.exe
2008-08-16 14:51 . 2008-08-16 14:51 <DIR> d-------- C:\Program Files\Trend Micro
2008-08-16 14:51 . 2008-08-16 14:51 686,630 --a------ C:\Users\Boss\dss.exe
2008-08-15 06:59 . 2008-08-15 06:59 708,663 --a------ C:\Users\Boss\pbsetup.zip
2008-08-15 06:59 . 2008-08-15 06:59 9,573 --a------ C:\Windows\pbgame.htm
2008-08-15 06:59 . 2008-08-15 06:59 76 --a------ C:\Windows\pbuser.htm
2008-08-15 02:07 . 2008-08-15 02:07 0 --a------ C:\Users\Boss\CALL.OF.DUTY.4.MW.V1.0.ENG.RAZOR1911.NOCD.ZIP
2008-08-13 21:43 . 2008-08-13 21:43 <DIR> d-------- C:\Windows\Content.IE5
2008-08-12 02:01 . 2008-08-12 02:01 108,336 --a------ C:\Windows\System32\MSWINSCK.OCX
2008-08-11 01:35 . 2008-08-11 01:37 <DIR> d-------- C:\Program Files\shaw
2008-08-11 01:35 . 2003-11-18 00:37 72,192 --a------ C:\Windows\System32\zlib.dll
2008-08-11 01:32 . 2008-08-11 01:32 <DIR> d-------- C:\Program Files\KLC
2008-08-11 01:32 . 2004-08-04 03:56 431,616 --a------ C:\Windows\System32\temp.000
2008-08-11 01:32 . 2000-05-22 00:00 203,976 --a------ C:\Windows\System32\RICHTX32.OCX
2008-08-11 01:32 . 1999-12-07 07:00 61,491 --a------ C:\Windows\System32\wbemdisp.TLB
2008-08-10 05:42 . 2008-08-10 05:53 <DIR> d-------- C:\Users\Boss\AppData\Roaming\Vidalia
2008-08-10 05:42 . 2008-08-10 05:52 <DIR> d-------- C:\Users\Boss\AppData\Roaming\Tor
2008-08-10 05:42 . 2008-08-10 05:42 <DIR> d-------- C:\Program Files\Vidalia
2008-08-10 05:42 . 2008-08-10 05:42 <DIR> d-------- C:\Program Files\Tor
2008-08-10 05:42 . 2008-08-10 05:42 <DIR> d-------- C:\Program Files\Privoxy
2008-08-10 05:22 . 2008-08-10 05:22 <DIR> d-------- C:\Users\Boss\AppData\Roaming\ProxyCap
2008-08-10 05:21 . 2008-08-10 05:21 <DIR> d-------- C:\Program Files\Proxy Labs
2008-08-10 04:48 . 2008-08-11 01:14 <DIR> d-------- C:\Program Files\FreeCap
2008-08-10 04:02 . 2008-08-10 04:02 <DIR> d-------- C:\Naruto_412[SleepyFans]
2008-08-06 20:52 . 2008-05-02 02:38 301,656 --a------ C:\Windows\System32\BtCoreIf.dll
2008-08-06 20:51 . 2008-08-06 20:52 <DIR> d-------- C:\Program Files\Common Files\Logishrd
2008-08-06 00:51 . 2008-08-10 22:05 396,288 --a------ C:\Windows\System32\HijackThis.exe
2008-08-06 00:51 . 2008-08-10 22:05 362,496 --a------ C:\Windows\System32\hldj_1.4.06.exe
2008-08-05 23:25 . 2008-08-05 23:25 <DIR> d-------- C:\Users\Boss\AppData\Roaming\IGN_DLM
2008-08-05 17:05 . 2008-08-05 17:05 <DIR> d-------- C:\Program Files\Network Associates
2008-08-05 02:54 . 2008-08-05 02:54 165,888 --------- C:\Windows\RICHTX32.OCX
2008-08-04 20:55 . 2008-08-10 20:15 362,496 --a------ C:\hldj_1.4.06.exe
2008-08-04 20:55 . 2008-08-04 20:57 751 --a------ C:\hldj_v1.4.5.zip
2008-08-04 18:52 . 2008-08-04 18:53 <DIR> d-------- C:\Users\Boss\AppData\Roaming\ICQ
2008-08-04 18:51 . 2008-08-05 17:01 <DIR> d-------- C:\Program Files\ICQ6
2008-08-04 15:49 . 2008-08-04 15:49 2,423,179 --a------ C:\dbz_outside_stories_1_in_the_name_of_piccolo_daimao.zip
2008-08-04 06:40 . 2008-08-04 06:40 22 --a------ C:\filejoiner.zip
2008-08-04 06:33 . 2008-08-04 06:53 227 --a------ C:\projects.Stats
2008-08-04 06:32 . 2008-08-06 00:05 <DIR> d-------- C:\Program Files\SoftwarePassport
2008-08-04 06:32 . 2008-08-04 07:13 1,241 --a------ C:\projects.arm
2008-08-04 06:12 . 2008-08-14 03:40 <DIR> d-------- C:\UPX
2008-08-03 00:48 . 2008-08-03 00:48 <DIR> d-------- C:\PSC
2008-08-03 00:48 . 2008-08-03 00:48 <DIR> d-------- C:\Program Files\Common Files\Thraex Software
2008-08-03 00:48 . 2008-08-03 00:48 <DIR> d-------- C:\PacSteamT
2008-08-02 15:09 . 2008-08-14 03:22 <DIR> d-------- C:\New Folder (3)
2008-08-02 14:53 . 2008-08-02 14:53 <DIR> d-------- C:\AKL
2008-08-02 10:04 . 2008-08-02 14:52 <DIR> d-------- C:\Program Files\LeechFTP
2008-08-02 10:04 . 2008-08-10 22:00 18,944 --a------ C:\Windows\eraser.exe
2008-08-02 09:39 . 2008-08-14 03:33 <DIR> d-------- C:\Program Files\HTV
2008-08-02 09:35 . 2008-08-14 03:35 <DIR> d-------- C:\Program Files\PDM
2008-08-01 03:05 . 2008-08-01 03:07 <DIR> d-------- C:\perl2exe
2008-08-01 03:03 . 2008-08-01 03:03 <DIR> d-------- C:\perl
2008-08-01 02:37 . 2008-08-01 02:46 <DIR> d-------- C:\csdos
2008-08-01 00:18 . 2008-08-01 00:18 <DIR> d-------- C:\Naruto_411[Binktopia]
2008-07-31 01:43 . 2008-07-31 01:43 <DIR> d-------- C:\Program Files\East Imperial Soft
2008-07-31 01:43 . 2008-07-31 01:43 <DIR> d-------- C:\MU
2008-07-30 16:36 . 2008-07-30 16:36 <DIR> d-------- C:\UD
2008-07-27 00:07 . 2008-07-27 00:07 <DIR> d-------- C:\Naruto_410[Binktopia]
2008-07-22 17:07 . 2008-07-22 17:07 268 --ah----- C:\sqmdata07.sqm
2008-07-22 17:07 . 2008-07-22 17:07 244 --ah----- C:\sqmnoopt07.sqm
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-19 00:05 --------- d-s---w C:\Program Files\HLSW
2008-08-18 23:36 --------- d-----w C:\Program Files\Steam
2008-08-18 11:50 --------- d-----w C:\Users\Boss\AppData\Roaming\uTorrent
2008-08-18 06:29 111,928 ----a-w C:\Windows\System32\PnkBstrB.exe
2008-08-15 14:05 136,888 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-08-14 03:59 66,872 ----a-w C:\Windows\System32\PnkBstrA.exe
2008-08-14 03:57 22,328 ----a-w C:\Users\Boss\AppData\Roaming\PnkBstrK.sys
2008-08-11 09:25 --------- d-----w C:\Program Files\Common Files\Steam
2008-08-11 05:07 974,848 ----a-w C:\Windows\UNRecode.exe
2008-08-11 05:07 974,848 ----a-w C:\Windows\UNNeroVision.exe
2008-08-11 05:07 974,848 ----a-w C:\Windows\UNNeroShowTime.exe
2008-08-11 05:07 974,848 ----a-w C:\Windows\UNNeroMediaHome.exe
2008-08-11 05:07 974,848 ----a-w C:\Windows\UNNeroBackItUp.exe
2008-08-11 05:06 86,528 ----a-w C:\Windows\System32\VACFix.exe
2008-08-11 05:06 77,312 ----a-w C:\Windows\System32\VCCLSID.exe
2008-08-11 05:06 69,632 ----a-w C:\Windows\System32\TWUNK_32.EXE
2008-08-11 05:06 36,864 ----a-w C:\Windows\System32\OggDSuninst.exe
2008-08-11 05:06 25,600 ----a-w C:\Windows\System32\WS2Fix.exe
2008-08-11 05:06 175,616 ----a-w C:\Windows\System32\strings.exe
2008-08-11 05:02 90,112 ----a-w C:\Windows\System32\atibrtmon.exe
2008-08-11 05:02 81,920 ----a-w C:\Windows\System32\ATIODE.exe
2008-08-11 05:02 40,960 ----a-w C:\Windows\System32\ATIODCLI.exe
2008-08-11 05:01 77,824 ----a-w C:\Windows\KHALMNPR.Exe
2008-08-11 05:00 315,392 ----a-w C:\Windows\HideWin.exe
2008-08-11 04:59 187,392 ----a-w C:\Windows\Acer(Wide).scr
2008-08-11 04:59 187,392 ----a-w C:\Windows\Acer(Normal).scr
2008-08-11 03:15 396,288 ----a-w C:\HijackThis.exe
2008-08-11 03:13 396,288 ----a-w C:\Boss.exe
2008-08-10 04:22 --------- d-----w C:\Program Files\Paltalk Messenger
2008-08-10 04:21 --------- d-----w C:\Users\Boss\AppData\Roaming\Paltalk
2008-08-09 04:19 637 ----a-w C:\Program Files\TTTT.rtf.lnk
2008-08-09 03:20 1,877,243 ----a-w C:\Program Files\TTTT.rtf
2008-08-09 03:13 24,406 ----a-w C:\Program Files\New Text Document.txt
2008-08-07 03:52 --------- d-----w C:\Program Files\Common Files\Logitech
2008-08-07 03:51 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-06 03:51 --------- d-----w C:\Users\Boss\AppData\Roaming\mIRC
2008-08-06 03:51 --------- d-----w C:\Program Files\mIRC
2008-08-04 14:13 --------- d---a-w C:\ProgramData\TEMP
2008-08-02 16:32 --------- d-----w C:\ProgramData\avg8
2008-06-27 11:52 --------- d-----w C:\Users\Boss\AppData\Roaming\LimeWire
2008-06-25 23:52 176,128 ----a-w C:\Windows\System32\w2pxdrv.dll
2008-06-20 10:33 22 ----a-w C:\Users\Boss\naruto_405.zip
2008-06-12 19:55 444,952 ----a-w C:\Windows\System32\wrap_oal.dll
2008-06-12 19:55 109,080 ----a-w C:\Windows\System32\OpenAL32.dll
2008-06-09 07:13 144,384 ----a-w C:\Windows\System32\miccyhook.dll
2008-06-03 03:35 413,696 ----a-w C:\Windows\System32\ATIDEMGX.dll
2008-06-03 03:35 327,680 ----a-w C:\Windows\System32\atipdlxx.dll
2008-06-03 03:35 159,744 ----a-w C:\Windows\System32\atitmmxx.dll
2008-06-03 03:34 43,520 ----a-w C:\Windows\System32\ati2edxx.dll
2008-06-03 03:34 266,240 ----a-w C:\Windows\System32\Ati2evxx.dll
2008-06-03 03:34 262,144 ----a-w C:\Windows\System32\Oemdspif.dll
2008-06-03 03:33 684,032 ----a-w C:\Windows\System32\Ati2evxx.exe
2008-06-03 03:25 1,563,648 ----a-w C:\Windows\System32\atidxx32.dll
2008-06-03 03:19 3,401,216 ----a-w C:\Windows\System32\atiumdag.dll
2008-06-03 03:02 4,398,080 ----a-w C:\Windows\System32\atiumdva.dll
2008-06-03 02:50 49,664 ----a-w C:\Windows\System32\amdpcom32.dll
2008-06-03 02:49 32,256 ----a-w C:\Windows\System32\atiadlxx.dll
2008-06-03 02:48 10,043,392 ----a-w C:\Windows\System32\atioglxx.dll
2008-04-24 02:25 47,360 ----a-w C:\Users\Boss\AppData\Roaming\pcouffin.sys
2008-04-17 05:11 691 ----a-w C:\Users\Boss\AppData\Roaming\GetValue.vbs
2008-04-17 05:11 35 ----a-w C:\Users\Boss\AppData\Roaming\SetValue.bat
2008-04-14 09:04 101,865 ----a-w C:\Users\Boss\startuplist.zip
2007-10-28 21:55 174 --sha-w C:\Program Files\desktop.ini
2008-05-04 20:57 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-05-04 20:57 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-05-04 20:57 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot_2008-08-17_ 0.31.42.41 )))))))))))))))))))))))))))))))))))))))))
.
+ 2005-10-20 19:02:28 163,328 ----a-w C:\Windows\erdnt\8-17-2008\ERDNT.EXE
+ 2008-08-17 21:19:07 208,896 ----a-w C:\Windows\erdnt\8-17-2008\Users\
00000001\ntuser.dat
+ 2008-08-17 21:19:07 212,992 ----a-w C:\Windows\erdnt\8-17-2008\Users\
00000002\ntuser.dat
+ 2008-08-17 21:19:07 4,255,744 ----a-w C:\Windows\erdnt\8-17-2008\Users\
00000003\ntuser.dat
+ 2008-08-17 21:19:07 4,636,672 ----a-w C:\Windows\erdnt\8-17-2008\Users\
00000004\UsrClass.dat
+ 2005-10-20 19:02:28 163,328 ----a-w C:\Windows\erdnt\AutoBackup\2008-08-17\ERDNT.EXE
+ 2008-08-17 21:36:10 4,255,744 ----a-w C:\Windows\erdnt\AutoBackup\2008-08-17\Users\
00000001\ntuser.dat
+ 2008-08-17 21:36:10 4,636,672 ----a-w C:\Windows\erdnt\AutoBackup\2008-08-17\Users\
00000002\UsrClass.dat
+ 2005-10-20 19:02:28 163,328 ----a-w C:\Windows\erdnt\AutoBackup\8-17-2008\ERDNT.EXE
+ 2008-08-17 22:05:03 4,255,744 ----a-w C:\Windows\erdnt\AutoBackup\8-17-2008\Users\
00000001\ntuser.dat
+ 2008-08-17 22:05:04 4,636,672 ----a-w C:\Windows\erdnt\AutoBackup\8-17-2008\Users\
00000002\UsrClass.dat
- 2008-08-11 05:00:32 73,728 ----a-w C:\Windows\fdsv.exe
+ 2000-08-31 15:00:00 89,504 ----a-w C:\Windows\fdsv.exe
- 2008-08-11 05:00:44 80,384 ----a-w C:\Windows\grep.exe
+ 2000-08-31 15:00:00 80,412 ----a-w C:\Windows\grep.exe
- 2008-03-13 15:01:10 29,926 ----a-r C:\Windows\Installer\{508CE775-4BA4-4748-82DF-FE28DA9F03B0}\MsblIco.Exe
+ 2008-08-17 21:49:39 29,926 ----a-r C:\Windows\Installer\{508CE775-4BA4-4748-82DF-FE28DA9F03B0}\MsblIco.Exe
+ 2008-08-17 22:06:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-08-17 22:06:51 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-08-17 07:28:25 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-08-17 22:08:21 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-08-17 07:28:24 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-08-17 22:08:16 262,144 --sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-08-17 22:08:16 262,144 ---ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-08-17 07:01:54 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-08-17 21:17:01 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-08-17 07:01:54 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-08-17 21:17:01 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-08-17 07:01:54 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-08-17 21:17:01 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-08-16 21:23:51 70,680 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\settings.dat
+ 2008-08-17 22:05:34 70,680 ----a-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Webroot\Spy Sweeper\Data\settings.dat
- 2008-08-14 04:45:23 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
+ 2008-08-19 00:06:14 262,144 ----a-w C:\Windows\System32\config\systemprofile\ntuser.dat
- 2008-08-17 06:28:42 11,946 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3127582598-3418603043-2518255061-1001_UserData.bin
+ 2008-08-17 22:08:43 11,978 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3127582598-3418603043-2518255061-1001_UserData.bin
- 2008-08-17 06:28:42 84,338 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-08-17 22:08:43 84,478 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-08-16 21:27:36 57,836 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-08-17 22:08:42 58,362 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 12:35 536576 --a------ C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2008-08-10 21:20 5714944]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 05:36 201728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-20 01:56 4493312 C:\Windows\RtHDVCpl.exe]
"Kernel and Hardware Abstraction Layer"="KHALMNPR.EXE" [2008-08-10 22:01 77824 C:\Windows\KHALMNPR.Exe]
C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE [2005-10-20 12:04:08 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.mkdmp3enc"= C:\PROGRA~1\ACERAR~1\ACERSL~1\Kernel\Burner\MKDMP3Enc.ACM
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Empowering Technology Launcher.lnk
backup=C:\Windows\pss\Empowering Technology Launcher.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
backup=C:\Windows\pss\Logitech SetPoint.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^PalTalk.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\PalTalk.lnk
backup=C:\Windows\pss\PalTalk.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Privoxy.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Privoxy.lnk
backup=C:\Windows\pss\Privoxy.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^Boss^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Users\Boss\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CCUTRAYICON]
FactoryMode [X]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
--a------ 2008-08-10 20:23 1261568 C:\Program Files\Acer Assist\launcher.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Empowering Technology Monitor]
--a------ 2007-06-15 16:48 326440 C:\Acer\Empowering Technology\SysMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Product Registration]
--a------ 2008-08-10 20:24 3383296 C:\Program Files\Acer Registration\ACE1.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
--a------ 2008-08-10 20:31 34304 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater]
--a------ 2008-08-10 20:46 2315264 C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AIM]
--a------ 2008-08-10 20:33 61440 C:\Program Files\AIM\aim.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bdagent]
--a------ 2008-08-10 18:19 368640 C:\Program Files\BitDefender\BitDefender 2008\bdagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
--a------ 2008-08-10 20:47 106496 C:\Program Files\Common Files\Nero\Lib\NMBgMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\bitdefender antiphishing helper]
--a------ 2008-08-10 18:19 61440 C:\Program Files\BitDefender\BitDefender 2008\IEShow.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
--a------ 2007-06-29 16:03 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
--a------ 2008-08-10 20:48 167936 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
--a------ 2008-08-10 20:11 457216 C:\Acer\Empowering Technology\eDataSecurity\eDSLoader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
--a------ 2008-08-10 21:02 167936 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ]
--a------ 2008-08-10 21:01 172544 C:\Program Files\ICQ6\ICQ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2008-08-10 21:20 5714944 C:\Program Files\Windows Live\Messenger\msnmsgr.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NBKeyScan]
--a------ 2008-08-10 21:04 2215936 C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2008-08-10 20:47 155648 C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NMSSupport]
--a------ 2008-08-10 20:46 433152 C:\Program Files\Common Files\Intel\IntelDH\NMS\Support\IntelHCTAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PCMMediaSharing]
--a------ 2008-08-10 20:22 204800 C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDM Agent]
--a------ 2008-08-10 21:05 510464 C:\Program Files\PDM\PDM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
--a------ 2008-08-10 21:06 233472 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\shawnotify]
--a------ 2008-07-15 15:37 378144 c:\PROGRA~1\shaw\Update\siuloader.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
--a------ 2006-11-02 05:35 1196032 C:\Program Files\Windows Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\spysweeper]
--a------ 2008-01-04 20:56 5367664 C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StartCCC]
--a------ 2008-08-10 20:34 90112 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
--a------ 2008-05-05 22:59 1271032 c:\Program Files\Steam\Steam.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2008-08-10 21:02 126976 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
--a------ 2007-07-10 15:30 1006264 C:\Program Files\Windows Defender\MSASCui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
--a------ 2006-11-02 05:36 201728 C:\Program Files\Windows Media Player\wmpnscfg.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Kernel and Hardware Abstraction Layer]
--a------ 2008-08-10 22:01 77824 C:\Windows\KHALMNPR.Exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WindowsWelcomeCenter]
--a------ 2006-11-02 05:34 2159104 C:\Windows\System32\oobefldr.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{A5E2F4F9-4ACC-49D9-8E12-34C554A9F1C5}"= C:\Program Files\Acer Arcade Live\Acer Arcade Live Main Page\Acer Arcade Live.exe:Acer Arcade Live
"{CB7A8998-4B1E-4D90-B5D9-67E2D40F82F4}"= C:\Program Files\Acer Arcade Live\Acer DVDivine\Acer DVDivine.exe:Acer DVDivine
"{D7C7B185-CD7A-4FB4-9C8F-E488FF26D873}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia\Acer HomeMedia.exe:Acer HomeMedia
"{41DCE02C-9070-4DE4-A4AA-097557D75583}"= C:\Program Files\Acer Arcade Live\Acer VideoMagician\Acer VideoMagician.exe:Acer VideoMagician
"{9361F589-2C58-4607-9F3E-7EDDFC19A2FB}"= C:\Program Files\Acer Arcade Live\Acer DV Magician\Acer DV Magician.exe:Acer DV Magician
"{6C205EE7-6E99-49C4-974F-7B80F2BBA6F0}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Acer HomeMedia Connect.exe:Acer HomeMedia Connect
"{5A8AD70F-9DD5-4D8A-9B7C-E626EC865F3A}"= C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.EXE:Acer HomeMedia Connect Service
"{A6F6AFBC-E5E3-4FE5-99E2-7A541B465AFF}"= C:\Program Files\Acer Arcade Live\Acer SlideShow DVD\Acer SlideShow DVD.exe:Acer SlideShow DVD
"{712344DC-3475-4A33-8CE2-9D00FC463310}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{287BA272-D032-433E-A8A7-6AEDD2FA4BEC}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{D0D5264A-98A1-4CDB-B73A-87736FBCEA20}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{3C8ECEDC-D424-4B98-B403-3AF4A394DD2A}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.exe:SPCM
"{998EDADF-65F7-4ED7-BD23-D9AAF420769A}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{B1037FA5-CB88-4F8E-A3E5-851189B3BF45}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe:Intel® Remoting Service
"{9F614491-7339-4FDC-B9EB-6CD48575C958}"= UDP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{6D6DCD2A-740B-4E54-B68E-A2BCBB2BEBA0}"= TCP:Profile=Private|Profile=Public:LocalSubnet:LocalSubnet|C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe:Intel® Viiv Media Server
"{16AA6F9C-957B-435F-ACF1-C2C50D48B9A2}"= TCP:Profile=Private|Profile=Public|9442:127.0.0.1:Intel® Viiv Media Server Discovery
"{12591F3D-5523-4A1C-A864-560E0A37FBC8}"= TCP:Profile=Private|Profile=Public|1900:LocalSubnet:LocalSubnet:Intel® Viiv Media Server UPnP Discovery
"{C14AB52F-31A8-4107-B71F-15461DFAD792}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"{25857231-D771-4C01-8B58-8A1A2C0D0477}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis SP Demo\Bin32\Crysis.exe:Crysis_32_sp_demo
"TCP Query User{E3044BC8-6061-45DA-BB11-A6D4F25C4F2A}C:\\program files\\bittornado\\btdownloadgui.exe"= UDP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"UDP Query User{8496F8D9-EC27-429A-B88E-DD15C7E85E2C}C:\\program files\\bittornado\\btdownloadgui.exe"= TCP:C:\program files\bittornado\btdownloadgui.exe:btdownloadgui
"{6CA13711-570A-485E-96AB-A896129956F0}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{3C5B1A79-646C-4CBA-AD98-77167144067E}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{777150B1-0CF5-4C3A-A3AA-D0DCA50D683B}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{5BE49B3C-6BD0-4EBC-80CD-C652A572F293}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{7128608F-0F06-4D25-8E22-7F767D2FF67D}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{B4C66867-FD4B-4822-A29C-13FDDA056869}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{3EC75B3C-CE3C-46D9-83D2-4B8D021214F9}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{BF964E2A-A089-4345-87A0-A56C1E7FCDEC}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{8A7C66C0-C5E9-4F0C-8ACB-8AEE5E2F8C7A}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{6E713BA8-F107-4CC3-9AB6-8EB272CD542D}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{E5EDF402-75F4-4E9B-9970-2E8A455DF1FF}"= UDP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"{F887BB54-0725-4284-B808-AF68A9D8F9FB}"= TCP:C:\Program Files\Shareaza\Shareaza.exe:Shareaza
"TCP Query User{B4BD7D29-C84E-4226-8D0E-90ED0494507C}C:\\program files\\ares\\ares.exe"= UDP:C:\program files\ares\ares.exe:Ares p2p for windows
"UDP Query User{7011DE3F-C482-462C-A5CE-55FB6DC58654}C:\\program files\\ares\\ares.exe"= TCP:C:\program files\ares\ares.exe:Ares p2p for windows
"{5ADD0E4A-93B4-4A76-B13C-CABFCE8006BA}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{4B899C01-B222-4B88-A766-7DC5448E592A}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{DD810CF9-628D-48A1-8C7F-A078C7A970D7}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{017FDD7E-5BDF-41B4-9CCB-E3ECEC565734}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B3C8C70A-BB7D-4505-959D-4BD0921E695B}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{D1F3C5CC-4740-440F-BEE0-E1B3C1DE3AE3}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{53E5F994-E9BE-437D-BC25-DBD73DDB8EC4}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"TCP Query User{A3E646ED-24AC-4177-AE83-7BEBFED3890C}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= UDP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"UDP Query User{54E51792-72D8-4E4A-8581-AE5178E7A59E}C:\\program files\\veoh networks\\veoh\\veohclient.exe"= TCP:C:\program files\veoh networks\veoh\veohclient.exe:Veoh Client
"{A9BAB426-4033-4883-9FF0-13F37CC08A8C}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{334998E6-F357-4F5C-96FA-2ADAB0793A2D}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"{3B3A5C43-D85D-42BC-81D5-95713A305B6F}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{81DF5325-5AC1-4B10-B4E0-B34FA014C5E2}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exe:Orb
"{86D111F0-8477-4601-A82B-A2116CEBE22E}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{34AAF90A-3A83-4CF3-BA84-9DC5FEC03A30}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exe:OrbIR
"{CFEE345A-23C2-4766-A9AF-EA9A5AF8815E}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{4AB10BCD-5A29-4A1E-8119-A5B83772CF74}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:Orb Stream Client
"{9C0D7124-827A-45FA-A459-4DCA4C543C0E}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{E1CC601A-9539-42D4-9649-3871543464BA}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exe:OrbTray
"{6CF6F292-EB84-47F4-9B7D-334357098836}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{C9EE32B1-CE7B-4E63-9DF6-FD196DF213DE}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{138F8688-DFD4-4BF0-ACFF-DABB1C8F6A99}"= UDP:C:\Program Files\Codemasters\GRID\GRID.exe:GRID
"{7AD2649E-F774-49E9-B7CE-172B7EEFB418}"= TCP:C:\Program Files\Codemasters\GRID\GRID.exe:GRID
"{FDD21130-BE5D-49CB-B3CE-73BB241AAB0F}"= UDP:D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{DA59371D-7337-40EE-A316-2C58361FE745}"= TCP:D:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare
"{B5110496-8C6A-4F9E-8C94-987AEC39788B}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"EnableFirewall"= 0 (0x0)
"DisabledInterfaces"= {550542C4-3186-48D4-9701-CE8FC3FD0832}
R2 Acer HomeMedia Connect Service;Acer HomeMedia Connect Service;C:\Program Files\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe [2008-08-05 17:39]
R2 DQLWinService;DQLWinService;C:\Program Files\Common Files\Intel\IntelDH\NMS\AdpPlugins\DQLWinService.exe [2008-08-05 18:03]
R2 nmsunidr;UniDriver for NMS;C:\Windows\system32\DRIVERS\nmsunidr.sys [2007-02-18 20:34]
R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2008-06-02 23:22]
R3 IntelDH;IntelDH Driver;C:\Windows\system32\Drivers\IntelDH.sys [2007-10-28 14:33]
R3 SbieDrv;SbieDrv;C:\Program Files\Sandboxie\SbieDrv.sys [2008-04-27 06:22]
R3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-08-11 02:21]
S3 DHTRACE;Intel® DHTrace Controller;C:\Program Files\Common Files\Intel\IntelDH\bin\DHTraceController.exe [2008-08-10 20:46]
S3 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20061025.029\IDSvix86.sys [2006-11-20 21:42]
S3 IntelDHSvcConf;IntelDHSvcConf;C:\Program Files\Intel\IntelDH\Intel Media Server\Tools\IntelDHSvcConf.exe []
S3 NMSCore;Intel® NMSCore;C:\Program Files\Common Files\Intel\IntelDH\NMS\NMSCore\NMSCore.exe [2008-08-10 20:46]
S3 NPF;NetGroup Packet Filter Driver;C:\Windows\system32\drivers\npf.sys [2007-06-21 13:55]
S3 QualityManager;Intel® Quality Manager;C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\qualitymanager.exe [2008-08-10 21:02]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bdx REG_MULTI_SZ scan
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\J]
\shell\autorun\command - J:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{5eff3f94-86d1-11dc-8b87-0019212f80c2}]
\shell\AutoRun\command - K:\setup\rsrc\Autorun.exe
\shell\dinstall\command - K:\Directx\dxsetup.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{cd405468-98b9-11dc-9911-0019212f80c2}]
\shell\AutoRun\command - N:\autorun.exe
*Newly Created Service* - COMHOST
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-08-18 17:09:17
Windows 6.0.6000 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
C:\Users\Boss\AppData\Local\Microsoft\Messenger\
[email protected]\SharingMetadata\Working\database_B610_E9D7_10E9_9F1D\$db_clean$ 0 bytes
scan completed successfully
hidden files: 1
**************************************************************************
.
Completion time: 2008-08-18 17:10:56
ComboFix-quarantined-files.txt 2008-08-19 00:10:43
ComboFix2.txt 2008-08-17 21:56:53
ComboFix3.txt 2008-08-17 07:32:43
ComboFix4.txt 2008-04-30 01:57:35
ComboFix5.txt 2008-08-19 00:03:03
Pre-Run: 26,822,041,600 bytes free
Post-Run: 26,712,694,784 bytes free
452 --- E O F --- 2007-10-28 21:52:25