Combo Fix Log
ComboFix 08-05-19.4 - Michael 2008-05-20 20:36:03.4 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1142 [GMT 1:00]
Running from: C:\Users\Michael\Desktop\ComboFix.exe
Command switches used :: C:\Users\Michael\Desktop\CFScript.txt
* Resident AV is active
FILE ::
C:\Windows\System32\drenaore.dll
C:\Windows\System32\gmklstyu.dll
C:\Windows\System32\ljJBtqPg.dll
C:\Windows\System32\mlJYstSK.dll
C:\Windows\System32\oamjyayc.exe
C:\Windows\System32\qtakwlwq.dll
C:\Windows\System32\rwhslixn.dll
C:\Windows\System32\spxaudwh.dll
C:\Windows\System32\toqtdjtl.exe
C:\Windows\System32\uvdqvobd.dll
C:\Windows\System32\vfkwqivg.dll
C:\Windows\System32\vlowspyj.dll
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\System32\drenaore.dll
C:\Windows\System32\gmklstyu.dll
C:\Windows\system32\gPqtBJjl.ini
C:\Windows\System32\gPqtBJjl.ini2
C:\Windows\System32\ljJBtqPg.dll
C:\Windows\System32\mlJYstSK.dll
C:\Windows\System32\oamjyayc.exe
C:\Windows\System32\qtakwlwq.dll
C:\Windows\System32\rwhslixn.dll
C:\Windows\System32\spxaudwh.dll
C:\Windows\System32\toqtdjtl.exe
C:\Windows\System32\uvdqvobd.dll
C:\Windows\System32\vfkwqivg.dll
C:\Windows\System32\vlowspyj.dll
.
((((((((((((((((((((((((( Files Created from 2008-04-20 to 2008-05-20 )))))))))))))))))))))))))))))))
.
2008-05-20 20:41 . 2008-05-20 20:41 54,156 --ah----- C:\Windows\QTFont.qfn
2008-05-20 20:41 . 2008-05-20 20:41 1,409 --a------ C:\Windows\QTFont.for
2008-05-20 16:54 . 2008-05-20 16:54 2,560 --a------ C:\Windows\System32\myvrkuhe.exe
2008-05-20 16:48 . 2008-05-20 16:48 92,160 --a------ C:\Windows\System32\irbbeich.dll
2008-05-20 16:47 . 2008-05-20 16:47 126,976 --a------ C:\Windows\System32\nnwsogni.dll
2008-05-20 16:31 . 2008-05-20 20:32 414 ---hs---- C:\Windows\System32\nxilshwr.ini
2008-05-19 22:12 . 2008-05-19 22:12 <DIR> d-------- C:\fixwareout
2008-05-19 21:27 . 2008-05-19 21:27 <DIR> d-------- C:\VundoFix Backups
2008-05-19 20:45 . 2008-05-19 20:45 <DIR> d-------- C:\Program Files\Trend Micro
2008-05-19 18:35 . 2008-05-19 18:38 <DIR> d-------- C:\Users\Michael\Torrents
2008-05-18 12:51 . 2008-05-18 12:58 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{31975520-24c1-11dd-a51f-005056c00008}.TMContainer00000000000000000002.regtrans-ms
2008-05-18 12:51 . 2008-05-20 20:40 524,288 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{31975520-24c1-11dd-a51f-005056c00008}.TMContainer00000000000000000001.regtrans-ms
2008-05-18 12:51 . 2008-05-18 12:58 524,288 --ahs---- C:\Users\Michael\NTUSER.DAT{31975522-24c1-11dd-a51f-005056c00008}.TMContainer00000000000000000002.regtrans-ms
2008-05-18 12:51 . 2008-05-20 20:40 524,288 --ahs---- C:\Users\Michael\NTUSER.DAT{31975522-24c1-11dd-a51f-005056c00008}.TMContainer00000000000000000001.regtrans-ms
2008-05-18 12:51 . 2008-05-20 20:40 65,536 --ahs---- C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT{31975520-24c1-11dd-a51f-005056c00008}.TM.blf
2008-05-18 12:51 . 2008-05-20 20:40 65,536 --ahs---- C:\Users\Michael\NTUSER.DAT{31975522-24c1-11dd-a51f-005056c00008}.TM.blf
2008-05-17 13:36 . 2008-05-17 13:36 <DIR> d-------- C:\Users\Michael\AppData\Roaming\NCH Swift Sound
2008-05-17 13:36 . 2008-05-17 13:36 <DIR> d-------- C:\Program Files\NCH Swift Sound
2008-05-16 15:32 . 2008-05-16 15:32 <DIR> d-------- C:\Program Files\MillieSoft
2008-05-16 15:13 . 2008-05-16 15:13 <DIR> d-------- C:\Program Files\Devnz
2008-05-15 13:30 . 2008-01-27 01:09 615,424 --a------ C:\Windows\System32\themeui.dll
2008-05-15 13:30 . 2008-01-27 01:09 240,128 --a------ C:\Windows\System32\uxtheme.dll
2008-05-14 15:56 . 2008-05-14 15:56 <DIR> d-------- C:\merged
2008-05-13 18:18 . 2008-05-13 18:18 <DIR> d-------- C:\Users\Michael\AppData\Roaming\vlc
2008-05-13 18:16 . 2008-05-13 18:16 <DIR> d-------- C:\Program Files\VideoLAN
2008-05-13 17:43 . 2008-05-13 17:43 <DIR> d-------- C:\Program Files\DVD Decrypter
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Videos
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Searches
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Saved Games
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Pictures
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Music
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Links
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Downloads
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> dr------- C:\Windows\System32\config\systemprofile\Documents
2008-05-13 13:12 . 2008-05-13 13:12 <DIR> d-------- C:\Users\Michael\AppData\Roaming\Nikon
2008-05-13 13:11 . 2008-05-13 13:11 <DIR> d-------- C:\Program Files\Nikon
2008-05-13 13:10 . 2008-05-13 13:10 <DIR> d-------- C:\ProgramData\Ultima_T15
2008-05-13 13:10 . 2008-05-13 13:10 <DIR> d-------- C:\ProgramData\EnterNHelp
2008-05-13 13:10 . 2008-05-13 13:13 <DIR> d-------- C:\Program Files\Common Files\Nikon
2008-05-13 13:10 . 2008-05-13 13:10 0 --a------ C:\ProgramData\PKP_DLbz.DAT
2008-05-12 19:19 . 2008-05-12 19:19 <DIR> d-------- C:\Users\Michael\AppData\Roaming\iPodifier
2008-05-12 19:19 . 2008-05-12 19:19 <DIR> d-------- C:\Program Files\iPodifier
2008-05-12 19:18 . 2008-05-12 19:18 <DIR> d-------- C:\Windows\Downloaded Installations
2008-05-08 18:46 . 2008-05-08 18:56 <DIR> d-------- C:\Users\Michael\AppData\Roaming\Winamp
2008-05-08 18:46 . 2008-05-08 18:47 <DIR> d-------- C:\Program Files\Winamp
2008-05-07 11:50 . 2008-05-07 11:50 <DIR> d-------- C:\Program Files\vixy.net
2008-05-04 15:39 . 2008-05-17 12:46 <DIR> d-------- C:\Program Files\Microsoft Visual Studio 9.0
2008-05-04 15:30 . 2008-05-04 15:30 <DIR> d-------- C:\temp\ext18866
2008-05-04 15:30 . 2008-05-04 15:30 <DIR> d-------- C:\temp
2008-05-03 14:26 . 2008-05-17 13:03 <DIR> d-------- C:\Program Files\Handbrake
2008-04-30 14:06 . 2008-04-30 14:06 <DIR> d-------- C:\Program Files\Virtual Earth 3D
2008-04-29 13:58 . 2008-04-29 13:58 <DIR> d-------- C:\Program Files\iTunes
2008-04-29 13:58 . 2008-04-29 13:58 <DIR> d-------- C:\Program Files\iPod
2008-04-29 13:55 . 2008-04-29 13:55 <DIR> d-------- C:\Program Files\QuickTime
2008-04-29 13:52 . 2008-04-29 13:52 <DIR> d-------- C:\Program Files\Apple Software Update
2008-04-29 13:21 . 2008-04-29 13:29 <DIR> d-------- C:\Users\Michael\AppData\Roaming\FrostWire
2008-04-29 13:21 . 2008-04-29 13:22 <DIR> d-------- C:\Program Files\FrostWire
2008-04-28 16:26 . 2008-04-30 16:16 <DIR> d-------- C:\Program Files\Shareaza
2008-04-26 20:00 . 2008-04-26 20:00 <DIR> d-------- C:\Users\Michael\{a58d0d1c-25cd-4b20-a8e0-1308dcfd2b60}
2008-04-26 19:52 . 2008-04-26 19:52 <DIR> d-------- C:\Hauppauge
2008-04-26 19:52 . 2007-03-23 18:25 57,472 --a------ C:\Windows\System32\drivers\hcwu2dtd.sys
2008-04-26 19:52 . 2007-03-23 18:21 18,560 --a------ C:\Windows\System32\drivers\hcwu2dtl.sys
2008-04-23 18:44 . 2008-04-23 18:45 <DIR> d-------- C:\Users\Michael\AppData\Roaming\FLV Extract
2008-04-20 21:29 . 2007-10-08 09:27 436,784 --a------ C:\Windows\System32\vnetlib.dll
2008-04-20 21:29 . 2007-10-08 09:26 150,064 --a------ C:\Windows\System32\vmnat.exe
2008-04-20 21:29 . 2007-10-08 09:26 121,392 --a------ C:\Windows\System32\vmnetdhcp.exe
2008-04-20 21:29 . 2007-10-08 09:26 50,992 -ra------ C:\Windows\System32\vmnetbridge.dll
2008-04-20 21:29 . 2007-10-08 09:26 28,592 -ra------ C:\Windows\System32\drivers\vmnetbridge.sys
2008-04-20 21:29 . 2007-10-08 09:27 25,008 --a------ C:\Windows\System32\drivers\vmnetuserif.sys
2008-04-20 21:29 . 2007-10-08 09:26 17,712 -ra------ C:\Windows\System32\drivers\vmnet.sys
2008-04-20 21:29 . 2007-10-08 09:26 16,816 --a------ C:\Windows\System32\drivers\vmnetadapter.sys
2008-04-20 21:29 . 2007-10-08 09:26 13,104 --a------ C:\Windows\System32\vnetinst.dll
2008-04-20 21:28 . 2007-10-08 09:26 30,768 --a------ C:\Windows\System32\drivers\vmusb.sys
2008-04-20 21:28 . 2007-10-08 09:27 20,912 --a------ C:\Windows\System32\drivers\VMkbd.sys
2008-04-20 21:26 . 2008-04-20 21:26 <DIR> d-------- C:\Program Files\VMware
2008-04-20 21:26 . 2008-04-20 21:26 <DIR> d-------- C:\Program Files\Common Files\VMware
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-05-20 19:41 --------- d-----w C:\Users\Michael\AppData\Roaming\VMware
2008-05-20 16:06 --------- d-----w C:\Users\Michael\AppData\Roaming\SiteAdvisor
2008-05-19 19:46 262,144 ----a-w C:\ntuser.dat
2008-05-19 17:53 --------- d-----w C:\Users\Michael\AppData\Roaming\uTorrent
2008-05-17 12:03 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-05-17 12:03 --------- d-----w C:\Program Files\nLite
2008-05-17 11:46 --------- d-----w C:\ProgramData\Microsoft Help
2008-05-14 14:57 1,392,304 ----a-w C:\Windows\System32\AutoPartNt.exe
2008-05-13 17:59 --------- d-----w C:\Users\Michael\AppData\Roaming\Vso
2008-05-04 14:28 --------- d-----w C:\Program Files\Microsoft Silverlight
2008-04-30 14:56 --------- d-----w C:\Program Files\UltiDev
2008-04-29 13:19 --------- d-----w C:\Users\Michael\AppData\Roaming\VideoReDoPlus
2008-04-29 13:16 --------- d---a-w C:\ProgramData\TEMP
2008-04-29 12:21 --------- d-----w C:\Program Files\LimeWire
2008-04-26 15:39 --------- d-----w C:\Program Files\Microsoft Games
2008-04-26 14:21 --------- d-----w C:\Program Files\RocketDock
2008-04-23 10:19 --------- d-----w C:\ProgramData\VMware
2008-04-19 12:59 --------- d-----w C:\Program Files\DivX
2008-04-19 12:44 --------- d-----w C:\Users\Michael\AppData\Roaming\JAM Software
2008-04-19 12:39 --------- d-----w C:\Program Files\vLite
2008-04-15 18:55 --------- d-----w C:\Program Files\Java
2008-04-15 13:13 --------- d-----w C:\Program Files\Google
2008-04-14 20:24 --------- d-----w C:\Users\Michael\AppData\Roaming\Sony Corporation
2008-04-14 12:59 --------- d-----w C:\Program Files\Microsoft SQL Server
2008-04-14 12:57 --------- d-----w C:\Program Files\Microsoft.NET
2008-04-14 12:33 --------- d-----w C:\Users\Michael\AppData\Roaming\LimeWire
2008-04-12 09:55 --------- d-----w C:\ProgramData\Spybot - Search & Destroy
2008-04-11 22:37 --------- d-----w C:\Program Files\InterMute
2008-04-11 22:35 3,192 ----a-w C:\Windows\System32\tmp.reg
2008-04-11 21:32 --------- d-----w C:\Program Files\ESET
2008-04-11 21:07 691 ----a-w C:\Users\Michael\AppData\Roaming\GetValue.vbs
2008-04-11 21:07 35 ----a-w C:\Users\Michael\AppData\Roaming\SetValue.bat
2008-04-10 21:34 --------- d-----w C:\ProgramData\NVIDIA Corporation
2008-04-10 21:34 --------- d-----w C:\Program Files\NVIDIA Corporation
2008-04-09 10:44 --------- d-----w C:\Program Files\Vista4Cast
2008-04-09 10:29 --------- d-----w C:\Program Files\Windows Mail
2008-04-05 12:45 --------- d-----w C:\Program Files\Acoustica Mixcraft 4
2008-04-05 12:44 --------- d-----w C:\Program Files\Acoustica Shared Effects
2008-04-05 10:41 --------- d-----w C:\ProgramData\Pinnacle VideoSpin
2008-04-05 10:40 --------- d-----w C:\ProgramData\VideoSpin
2008-04-05 10:40 --------- d-----w C:\Program Files\Pinnacle
2008-04-05 10:40 --------- d-----w C:\Program Files\Common Files\Yahoo!
2008-04-05 10:38 --------- d-----w C:\ProgramData\Pinnacle
2008-04-04 11:12 0 ---ha-w C:\Windows\system32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-04-03 15:53 --------- d-----w C:\Program Files\DVBViewer
2008-04-02 20:21 --------- d-----w C:\Users\Michael\AppData\Roaming\Auslogics
2008-04-02 20:21 --------- d-----w C:\Program Files\Auslogics
2008-04-02 17:21 --------- d-----w C:\ProgramData\Team MediaPortal
2008-04-02 17:21 --------- d-----w C:\Program Files\Team MediaPortal
2008-03-29 15:04 --------- d-----w C:\ProgramData\CMUV
2008-03-29 13:03 --------- d-----w C:\Program Files\Foxit Software
2008-03-28 23:57 --------- d-----w C:\Program Files\Common Files\Adobe
2008-03-28 23:55 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-03-28 16:27 --------- d-----w C:\Program Files\SmartDraw 2008
2008-03-27 21:54 --------- d-----w C:\Users\Michael\AppData\Roaming\SmartDraw
2008-03-27 21:41 --------- d-----w C:\Program Files\MagicISO
2008-03-26 18:51 --------- d-----w C:\Users\Michael\AppData\Roaming\Acronis
2008-03-24 18:38 350,208 ----a-w C:\Windows\System32\d3drm.dll
2008-03-24 18:37 619,008 ----a-w C:\Windows\System32\dx7vb.dll
2008-03-24 18:37 1,227,264 ----a-w C:\Windows\System32\dx8vb.dll
2008-03-24 18:37 --------- d-----w C:\Program Files\mackoy
2008-03-24 11:54 --------- d-----w C:\Program Files\Stardock
2008-03-23 16:45 --------- d-----w C:\Program Files\MSN Messenger
2008-03-22 12:26 --------- d-----w C:\ProgramData\Lavasoft
2008-03-22 12:25 --------- d-----w C:\Program Files\Lavasoft
2008-03-22 11:52 --------- d-----w C:\ProgramData\Sony Corporation
2008-03-22 11:51 --------- d-----w C:\Program Files\Sony
2008-03-21 11:54 --------- d-----w C:\Program Files\Microsoft Works
2008-03-19 20:52 174 --sha-w C:\Program Files\desktop.ini
2008-03-19 20:14 82,432 ----a-w C:\Windows\System32\axaltocm.dll
2008-03-19 20:14 101,888 ----a-w C:\Windows\System32\ifxcardm.dll
2008-03-05 15:03 479,752 ----a-w C:\Windows\System32\XAudio2_0.dll
2008-03-05 15:03 238,088 ----a-w C:\Windows\System32\xactengine3_0.dll
2008-03-05 15:00 25,608 ----a-w C:\Windows\System32\X3DAudio1_3.dll
2008-03-05 14:56 3,786,760 ----a-w C:\Windows\System32\D3DX9_37.dll
2008-03-05 14:56 1,420,824 ----a-w C:\Windows\System32\D3DCompiler_37.dll
2008-03-03 13:25 5,702 ---ha-w C:\Windows\nod32restoretemdono.reg
2008-02-29 07:14 19,000 ----a-w C:\Windows\System32\kd1394.dll
2008-02-29 07:11 988,216 ----a-w C:\Windows\System32\winload.exe
2008-02-29 07:11 927,288 ----a-w C:\Windows\System32\winresume.exe
2008-02-29 06:53 46,592 ----a-w C:\Windows\System32\setbcdlocale.dll
2008-02-29 06:53 40,960 ----a-w C:\Windows\System32\srclient.dll
2008-02-29 06:53 378,368 ----a-w C:\Windows\System32\srcore.dll
2008-02-29 06:35 6,656 ----a-w C:\Windows\System32\kbd106n.dll
2008-02-29 04:21 2,032,128 ----a-w C:\Windows\System32\win32k.sys
2008-02-29 04:12 318,464 ----a-w C:\Windows\System32\rstrui.exe
2008-02-29 04:12 14,848 ----a-w C:\Windows\System32\srdelayed.exe
2008-02-22 09:35 256,536 ----a-w C:\Windows\System32\igfxsrvc.exe
2008-02-22 09:35 170,520 ----a-w C:\Windows\System32\igfxzoom.exe
2008-02-22 09:35 141,848 ----a-w C:\Windows\System32\igfxtray.exe
2008-02-22 09:34 539,160 ----a-w C:\Windows\System32\igfxcfg.exe
2008-02-22 09:34 170,520 ----a-w C:\Windows\System32\igfxext.exe
2008-02-22 09:34 166,424 ----a-w C:\Windows\System32\hkcmd.exe
2008-02-22 09:34 133,656 ----a-w C:\Windows\System32\igfxpers.exe
2008-02-22 05:05 615,992 ----a-w C:\Windows\System32\ci.dll
2008-02-22 05:01 826,880 ----a-w C:\Windows\System32\wininet.dll
2008-02-22 04:57 295,936 ----a-w C:\Windows\System32\gdi32.dll
2007-12-06 19:24 144 ----a-w C:\Users\Michael\AppData\Roaming\wklnhst.dat
2007-12-02 00:09 604 ---ha-w C:\Program Files\STLL Notifier
2007-11-26 20:31 47,360 ----a-w C:\Users\Michael\AppData\Roaming\pcouffin.sys
2007-12-24 00:21 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-24 00:21 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-24 00:21 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2006-05-03 09:06 163,328 --sh--r C:\Windows\System32\flvDX.dll
2007-02-21 10:47 31,232 --sh--r C:\Windows\System32\msfDX.dll
.
(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
---- Directory of C:\temp\ext18866 ----
---- Directory of C:\Users\Michael\{a58d0d1c-25cd-4b20-a8e0-1308dcfd2b60} ----
2007-04-17 20:22 11211 --a------ C:\Users\Michael\{a58d0d1c-25cd-4b20-a8e0-1308dcfd2b60}\hcwu2dtd.cat
---- Directory of C:\Users\Michael\Torrents ----
2008-05-19 18:41 95104 --a------ C:\Users\Michael\Torrents\Apple.QuickTime.Pro.v7.4.5.Multilanguage.(+. Keymaker)\~uTorrentPartFile_15FEE00.dat
2008-05-19 18:41 348672 --a------ C:\Users\Michael\Torrents\Apple.QuickTime.Pro.v7.4.5.Multilanguage.(+. Keymaker)\Keygen.exe
------- Sigcheck -------
.
((((((((((((((((((((((((((((( snapshot_2008-05-20_16.29.31.16 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-05-20 15:25:04 67,584 --s-a-w C:\Windows\bootstat.dat
+ 2008-05-20 19:41:18 67,584 --s-a-w C:\Windows\bootstat.dat
- 2008-05-20 15:25:24 217,088 ----a-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-05-20 19:41:38 217,088 ----a-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
- 2008-05-20 15:25:23 241,664 ----a-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-05-20 19:41:37 241,664 ----a-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
- 2008-05-20 15:19:07 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-05-20 19:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2008-05-20 15:19:07 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-05-20 19:35:50 32,768 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-05-20 15:19:07 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-05-20 19:35:50 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-05-20 09:13:20 16,336 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3390100157-130006372-542817148-1000_UserData.bin
+ 2008-05-20 19:29:19 16,586 ----a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3390100157-130006372-542817148-1000_UserData.bin
- 2008-05-20 09:13:19 74,350 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-05-20 19:29:19 74,390 ----a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-05-20 09:13:14 71,974 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-05-20 19:29:17 72,006 ----a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
- 2008-05-20 15:07:51 338,230 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
+ 2008-05-20 19:28:01 338,254 ----a-w C:\Windows\System32\WDI\SuspendPerformanceDiagnostics_SystemData_S3.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{514A5C49-0C7D-42c3-A71B-38864A269B7A}]
2008-05-20 16:48 92160 --a------ C:\Windows\system32\irbbeich.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 08:33 125952]
"RocketDock"="C:\Program Files\RocketDock\RocketDock.exe" [2007-09-02 13:58 495616]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="C:\Program Files\Windows Defender\MSASCui.exe" [2008-01-19 08:38 1008184]
"RtHDVCpl"="RtHDVCpl.exe" [2007-06-26 01:39 4489216 C:\Windows\RtHDVCpl.exe]
"Apoint"="C:\Program Files\Apoint\Apoint.exe" [2007-06-10 01:12 118784]
"ISBMgr.exe"="C:\Program Files\Sony\ISB Utility\ISBMgr.exe" [2007-06-12 02:27 317560]
"Samsung PanelMgr"="C:\Windows\Samsung\PanelMgr\SSMMgr.exe" [2007-01-03 05:47 520192]
"egui"="C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" [2008-02-20 11:06 1443072]
"IgfxTray"="C:\Windows\system32\igfxtray.exe" [2008-02-22 10:35 141848]
"HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2008-02-22 10:34 166424]
"Persistence"="C:\Windows\system32\igfxpers.exe" [2008-02-22 10:34 133656]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048]
"vmware-tray"="C:\Program Files\VMware\VMware Workstation\vmware-tray.exe" [2007-10-08 09:27 72240]
"56cb42d7"="C:\Windows\system32\rwhslixn.dll" [ ]
"BM55f8714b"="C:\Windows\system32\nnwsogni.dll" [2008-05-20 16:47 126976]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"TaskbarNoThumbnail"= 0 (0x0)
"NoWinKeys"= 0 (0x0)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{E23136A1-1AC4-4D1B-926F-5D537CFFF359}"= C:\Windows\system32\mlJYstSK.dll [ ]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
VESWinlogon.dll 2007-07-25 03:26 98304 C:\Windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= i420vfw.dll
"VIDC.dvsd"= C:\Program Files\Common Files\Sony Shared\VideoLib\sonydv.dll
"vidc.mjpg"= pvmjpg30.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 relog_ap
[HKLM\~\startupfolder\C:^Users^Michael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\Windows\pss\Adobe Gamma.lnk.Startup
backupExtension=.Startup
[HKLM\~\startupfolder\C:^Users^Michael^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\Windows\pss\OneNote 2007 Screen Clipper and Launcher.lnk.Startup
backupExtension=.Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
--a------ 2007-10-30 21:07 140568 C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AcronisTimounterMonitor]
--a------ 2007-10-30 21:11 909208 C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM]
C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
--a------ 2007-09-25 02:11 132496 C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
--a------ 2007-11-29 15:03 185632 C:\Program Files\Common Files\Real\Update_OB\realsched.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TrueImageMonitor.exe]
--a------ 2007-10-30 21:06 2595616 C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VMware hqtray]
--a------ 2007-10-08 09:26 55856 C:\Program Files\VMware\VMware Workstation\hqtray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vmware-tray]
--a------ 2007-10-08 09:27 72240 C:\Program Files\VMware\VMware Workstation\vmware-tray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
--a------ 2006-11-02 13:35 176128 C:\Windows\system32\WpcUmi.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc\S-1-5-21-3390100157-130006372-542817148-1000]
"EnableNotificationsRef"=dword:00000002
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DefaultOutboundAction"= 0 (0x0)
"DefaultInboundAction"= 1 (0x1)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{9296F22B-990F-42B6-9EF4-8198383B6147}"= UDP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{FE1E8A57-C32A-4159-B035-CADDFF2191F4}"= TCP:C:\Program Files\Google\Google Talk\googletalk.exe:Google Talk
"{2DE4B469-CCE9-4DE8-82BF-09634B239122}"= Disabled:UDP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{DDDA5625-5F0C-413A-B168-E7908AEF23CC}"= Disabled:TCP:C:\Program Files\Sony\VAIO Media 6.0\Vc.exe:[VAIO Media] VAIO Media
"{DB867C86-FD55-4636-B14A-F74F4C59CB16}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"{1585C0CE-D192-4D20-BAD8-27CFB0D6A663}"= UDP:6884:utor
"TCP Query User{9FF671CF-4AD7-4EF3-980E-FCB28FD4FD19}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{A714B1AF-03AF-4474-B38B-2D648941DB86}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"{1C434C2F-0EEC-4984-873D-2734AE01E688}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{3AD5EC32-740B-4C96-9884-99D27B51C0DC}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{2E49F8EF-E5D4-49DD-924E-EC8A3A93DAF5}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{DAC93052-72FE-4847-825E-F90433CB4208}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{972873BC-8C51-4050-8081-F2C5DA044F98}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"TCP Query User{583244E3-9D8C-45BA-BB08-6C567BE6F1D3}C:\\program files\\intervideo\\dvd8\\windvd.exe"= UDP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
"UDP Query User{CED32301-D66D-4B92-8EFD-35BA23E23011}C:\\program files\\intervideo\\dvd8\\windvd.exe"= TCP:C:\program files\intervideo\dvd8\windvd.exe:WinDVD
"95aea77c-e579-4903-b8b2-91e6c95fe2e1"= UDP:17989:lw
"{8217D371-5D20-4C4D-AC68-2217CFBB8973}"= TCP:6884:utor2
"TCP Query User{5C95ADE3-33B4-4263-858B-634C4C21B777}C:\\program files\\quicktime\\quicktimeplayer.exe"= UDP:C:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"UDP Query User{DAFBA970-A89D-475C-B0D0-B7BBB459B8D8}C:\\program files\\quicktime\\quicktimeplayer.exe"= TCP:C:\program files\quicktime\quicktimeplayer.exe:QuickTime Player
"TCP Query User{B4A7984F-4D85-47BD-8D9D-57F6EB5557C6}C:\\users\\michael\\desktop\\xampp-win32-1.6.5\\xampp\\apache\\bin\\apache.exe"= UDP:C:\users\michael\desktop\xampp-win32-1.6.5\xampp\apache\bin\apache.exe:apache.exe
"UDP Query User{237CD129-391E-4BD9-9F5C-E4916FA8D224}C:\\users\\michael\\desktop\\xampp-win32-1.6.5\\xampp\\apache\\bin\\apache.exe"= TCP:C:\users\michael\desktop\xampp-win32-1.6.5\xampp\apache\bin\apache.exe:apache.exe
"TCP Query User{FF2EE3CC-8D8A-450C-9E22-551AEF4AEBB6}C:\\users\\michael\\desktop\\xampp-win32-1.6.5\\xampp\\mysql\\bin\\mysqld.exe"= UDP:C:\users\michael\desktop\xampp-win32-1.6.5\xampp\mysql\bin\mysqld.exe:mysqld.exe
"UDP Query User{FF920B09-4E47-4F1F-BA04-71E0383994D6}C:\\users\\michael\\desktop\\xampp-win32-1.6.5\\xampp\\mysql\\bin\\mysqld.exe"= TCP:C:\users\michael\desktop\xampp-win32-1.6.5\xampp\mysql\bin\mysqld.exe:mysqld.exe
"{150F7F7B-EB14-4571-8EE7-4C602BBFC975}"= UDP:6346:limewire
"TCP Query User{953D4D3D-68A7-4CE3-99B2-94B04EDEC72F}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3C274CC5-1E39-4289-80CE-DE585AA54EC8}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{81A1BB1F-3FBD-4547-BE74-C4CFA0392623}C:\\program files\\soundspectrum\\whitecap\\whitecap standalone.exe"= UDP:C:\program files\soundspectrum\whitecap\whitecap standalone.exe:WhiteCap Standalone
"UDP Query User{ACA2F011-BB40-4635-BA9A-919C8AF446BA}C:\\program files\\soundspectrum\\whitecap\\whitecap standalone.exe"= TCP:C:\program files\soundspectrum\whitecap\whitecap standalone.exe:WhiteCap Standalone
"{82EA312B-8A8E-4DFE-B0FD-E524F590EA3C}"= UDP:C:\Users\Michael\AppData\Local\Temp\Installer.exe:SpeedTouch Home Install Wizard
"{B0D1672B-5DAF-4A2F-87A3-7A18AAB88C51}"= TCP:C:\Users\Michael\AppData\Local\Temp\Installer.exe:SpeedTouch Home Install Wizard
"{1A8F7EB9-452F-4D8C-9197-9871B3E0143D}"= UDP:C:\Users\Michael\Desktop\Vista41C\Installer.exe:SpeedTouch Home Install Wizard
"{06642459-4E0C-437B-AE32-83D39D64A5D1}"= TCP:C:\Users\Michael\Desktop\Vista41C\Installer.exe:SpeedTouch Home Install Wizard
"{F37B408F-DA2F-4FF9-B47E-7D5F3185BF9F}"= UDP:C:\Program Files\Thomson\ST330\service\st330service.exe:ST330 service
"{063408C1-BF23-4DD0-B3B9-6DA838CF1F83}"= TCP:C:\Program Files\Thomson\ST330\service\st330service.exe:ST330 service
"{F6F74C65-3A73-4B84-8857-92513DF73FFC}"= UDP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{A14EFE97-6446-4866-A7F4-B599702140D4}"= TCP:C:\Program Files\Bonjour\mDNSResponder.exe:Bonjour
"{A1825DD4-27E2-43BD-857B-BAEA57146C07}"= UDP:C:\Program Files\Thomson\ST330\service\st330service.exe:ST330 service
"{63AC1D89-B914-4FE1-A18B-5DDB13BCBB4E}"= TCP:C:\Program Files\Thomson\ST330\service\st330service.exe:ST330 service
"{45501F5D-A395-4DE3-A7EC-DE116AAE957F}"= UDP:C:\Users\Michael\AppData\Local\Temp\Installer.exe:SpeedTouch Home Install Wizard
"{E8A7670B-239E-4219-939F-A2529797D29B}"= TCP:C:\Users\Michael\AppData\Local\Temp\Installer.exe:SpeedTouch Home Install Wizard
"{4BFA30EE-436F-4FC8-B3F8-065AECFCCEDF}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{77EE46B7-1AB9-4775-9B0D-29BCAA965A62}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"TCP Query User{83148997-93AA-451F-AE8B-C668C57D6EEA}C:\\program files\\webguide\\webguide4\\bin\\webguide_configuration.exe"= UDP:C:\program files\webguide\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"UDP Query User{81BF9D4F-ABE8-47FB-85D9-0DD40E5A22D2}C:\\program files\\webguide\\webguide4\\bin\\webguide_configuration.exe"= TCP:C:\program files\webguide\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"{4DE093D7-728D-4862-BE28-A77E95B2C659}"= UDP:51394:WebGuide
"{2780D502-22EB-42D7-89F0-3D070A31DE35}"= UDP:51395:WebGuide
"{4EA9575A-B3D0-4216-B6C9-6E9D458ADABF}"= UDP:51393:WebGuide
"{A7B9B0F2-3558-4908-8B97-B3E35EFA364C}"= UDP:51861:WebGuide
"{21392598-91B2-4215-B0E6-B113E9D2ED1A}"= UDP:51862:WebGuide
"4f0bed32-b4f7-4e09-9db8-eed16d6d4fbb"= UDP:Profile=Public|51861:webguide
"TCP Query User{A19E772A-970A-40C4-8400-45A44A27C55D}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{DB0B7526-3B2B-48C8-85E6-35978BD32B6E}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{1131D2C5-AA0A-4E05-8510-D94A1D00C0DF}"= UDP:51861:WebGuide
"TCP Query User{170FE7D8-16F7-4788-918F-5730D78219B4}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{5E74932F-034D-423F-B43F-BB5E49AE899C}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"{A8E9F08E-D658-4C85-A5E4-0C16887423AE}"= C:\Program Files\MSN Messenger\livecall.exe:Windows Live Messenger 8.1 (Phone)
"TCP Query User{577D78FE-871A-4202-8C60-A9AE3F3E45D0}C:\\program files\\webguide\\webguide4\\bin\\webguide_configuration.exe"= UDP:C:\program files\webguide\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"UDP Query User{D65A53FC-45F3-44D1-913B-9AB25D2486DD}C:\\program files\\webguide\\webguide4\\bin\\webguide_configuration.exe"= TCP:C:\program files\webguide\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"{3E559374-AE81-41C8-BD5F-797A347B30B3}"= UDP:8077:WebGuide
"{31A32B1D-84A2-48C5-BCDC-76AC9E77FE88}"= UDP:51862:WebGuide
"TCP Query User{E232EA43-CB3A-407D-9563-29611CBFB951}C:\\program files\\dvbviewer\\dvbserver.exe"= UDP:C:\program files\dvbviewer\dvbserver.exe:DVBViewer Pro NetworkServer
"UDP Query User{CD21EAAE-F392-45B5-A1A4-F5929EECECF1}C:\\program files\\dvbviewer\\dvbserver.exe"= TCP:C:\program files\dvbviewer\dvbserver.exe:DVBViewer Pro NetworkServer
"{C2ED6B95-2BF7-4AE8-860C-969D638B1502}"= UDP:C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:Render Manager
"{C14E5698-9A55-43D5-B66C-E8F06BDD3438}"= TCP:C:\Program Files\Pinnacle\VideoSpin\Programs\RM.exe:Render Manager
"{26C78D71-7F9F-4963-A1AC-4A1CB5997A52}"= UDP:C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:PMSRegisterFile
"{5AAC07C4-138C-4B9A-823D-EDC970610946}"= TCP:C:\Program Files\Pinnacle\VideoSpin\Programs\PMSRegisterFile.exe:PMSRegisterFile
"{9DAAB247-9066-4F80-8B20-3B85E800D0B4}"= UDP:C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:umi
"{E509E8E9-238D-4C86-B976-4A4E9A9E3D24}"= TCP:C:\Program Files\Pinnacle\VideoSpin\Programs\umi.exe:umi
"{6D9832D3-D98D-4036-B09A-1DC45D0A63C3}"= UDP:C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:Pinnacle VideoSpin
"{26A282B5-D175-4FC6-89A0-CCF7D6DEE158}"= TCP:C:\Program Files\Pinnacle\VideoSpin\Programs\VideoSpin.exe:Pinnacle VideoSpin
"TCP Query User{3095738F-EB4C-42F3-964F-0924B36FDF7B}C:\\program files\\pinnacle\\videospin\\programs\\videospin.exe"= UDP:C:\program files\pinnacle\videospin\programs\videospin.exe:Pinnacle VideoSpin program file
"UDP Query User{8E2A3B31-22DF-4B47-ADD7-284661AF7094}C:\\program files\\pinnacle\\videospin\\programs\\videospin.exe"= TCP:C:\program files\pinnacle\videospin\programs\videospin.exe:Pinnacle VideoSpin program file
"9091af9d-727e-42b5-8e51-5fc989ed6f68"= %USERPROFILE%\Desktop\Wubi-8.04-beta-rev487.exe:wubi
"{ED021FA3-21EB-4596-A56F-3F5FDA6A46B5}"= UDP:62056:WebGuide
"{6DCF84A3-2720-443D-9AED-27F724836805}"= UDP:62057:WebGuide
"TCP Query User{8342B1F8-8248-4B9D-AE37-8060BC3B6E0F}C:\\webguide4\\bin\\webguide_configuration.exe"= UDP:C:\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"UDP Query User{F31778A9-257B-4049-B6A6-E6C608528469}C:\\webguide4\\bin\\webguide_configuration.exe"= TCP:C:\webguide4\bin\webguide_configuration.exe:WebGuide_Configuration
"{00A9E808-471D-4EBB-809F-AA82FD27ABDC}"= UDP:2141:WebGuide
"{85D1CE6D-2DEE-4AB7-B310-6225C63CB884}"= UDP:2142:WebGuide
"{053F3FF0-57EF-429D-9B7C-0C2515F8B98A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{7D16CFA0-69D2-4E47-AED2-8EF444AA99E1}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{460AD5BF-2CE4-4F3B-948E-4AD0FA192A9A}"= UDP:8295:WebGuide
"{D0C72269-38B0-4AC1-B93C-EA35E31B814D}"= UDP:8296:WebGuide
"{BDB40C80-3BC0-400A-853B-FF0F07268ED3}"= UDP:C:\Program Files\FrostWire\FrostWire.exe:LimeWire
"{5768C715-C908-4746-A127-515705D37A32}"= TCP:C:\Program Files\FrostWire\FrostWire.exe:LimeWire
"TCP Query User{A4D27B99-8857-4C57-9454-1C2F1AFB189A}C:\\program files\\freewire\\freewire television\\freewire television.exe"= UDP:C:\program files\freewire\freewire television\freewire television.exe:Freewire Television
"UDP Query User{BA37426A-5F8C-4FBB-B4E3-F92818A620E2}C:\\program files\\freewire\\freewire television\\freewire television.exe"= TCP:C:\program files\freewire\freewire television\freewire television.exe:Freewire Television
"{73988511-E7F8-4F5C-B6F2-7AE6C085F293}"= UDP:C:\Program Files\Orb Networks\Orb\bin\Orb.exe:Orb
"{017D949D-1E25-4D44-93D5-1742B90016F7}"= TCP:C:\Program Files\Orb Networks\Orb\bin\Orb.exe:Orb
"{2DE80A82-011C-4806-8782-DD79E49D1C3A}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray
"{42B74061-B596-4C99-A5DD-57E85E6D3744}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe:OrbTray
"{674B8D4C-0F38-406B-B61B-97B45A52B26A}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR
"{054037E3-48F1-4FBF-9906-8E8480691464}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbIR.exe:OrbIR
"{CD29A0F3-1CAC-43D4-887A-F272C3E45E48}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client
"{EC9AD095-6C86-4F61-B84D-4BF4E03E57F2}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbStreamerClient.exe:Orb Stream Client
"{EC3DB4A4-33ED-4952-B8B9-7342C1DC69CD}"= UDP:C:\Program Files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide
"{48EBF07E-1B0D-465B-9B59-2CB375E73513}"= TCP:C:\Program Files\Orb Networks\Orb\bin\xmltv.exe:OrbTVGuide
"{887705E2-6814-4592-8C6F-4FB4EE13DC8B}"= UDP:C:\Program Files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan
"{08FFB4E0-5A37-497D-A6AF-2382638DE1B8}"= TCP:C:\Program Files\Orb Networks\Orb\bin\OrbChannelScan.exe:OrbChannelScan
R0 tdrpman;Acronis Try&Decide and Restore Points filter;C:\Windows\system32\DRIVERS\tdrpman.sys [2008-03-11 16:04]
R1 epfwtdir;epfwtdir;C:\Windows\system32\DRIVERS\epfwtdir.sys [2008-02-20 11:11]
R2 CrackTcpip;Crack Tcpip;C:\Windows\system32\drivers\CrackTcpip.sys [2008-01-13 17:55]
R2 NMSAccessU;NMSAccessU;C:\Program Files\CDBurnerXP\NMSAccessU.exe [2008-03-09 12:20]
R2 NSUService;NSUService;"C:\Program Files\Sony\Network Utility\NSUService.exe" [2008-01-16 13:49]
R2 SSPORT;SSPORT;C:\Windows\system32\Drivers\SSPORT.sys [2006-12-08 19:50]
R2 TryAndDecideService;Acronis Try And Decide Service;"C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe" [2007-10-30 21:51]
R2 XAudio;XAudio;C:\Windows\system32\DRIVERS\xaudio.sys [2007-05-08 01:01]
R3 HCWU2DTD;Hauppauge Nova USB2 DVB-T TV Receiver;C:\Windows\system32\Drivers\hcwu2dtd.sys [2007-03-23 18:25]
R3 igfx;igfx;C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 11:36]
R3 ti21sony;ti21sony;C:\Windows\system32\drivers\ti21sony.sys [2007-06-06 01:00]
R3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\system32\DRIVERS\yk60x86.sys [2007-07-25 01:23]
S2 NOD32FiXTemDono;Eset Nod32 Boot;C:\Windows\system32\regedt32.exe [2006-11-02 10:45]
S3 AcronisOSSReinstallSvc;Acronis OS Selector Reinstall Service;"C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall_svc.exe" [2007-02-22 20:53]
S3 athr;Atheros Extensible Wireless LAN device driver;C:\Windows\system32\DRIVERS\athr.sys [2007-06-15 01:28]
S3 HCWU2DTL;Hauppauge Nova-USB2-T Adapter Firmware Loader;C:\Windows\system32\DRIVERS\hcwu2dtl.sys [2007-03-23 18:21]
S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\s115mdfl.sys [2007-04-23 14:54]
S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\s115mdm.sys [2007-04-23 14:54]
S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\Windows\system32\DRIVERS\s115mgmt.sys [2007-04-23 14:54]
S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\Windows\system32\DRIVERS\s115obex.sys [2007-04-23 14:54]
S3 ST330;ST330;C:\Windows\system32\drivers\st330.sys [2008-02-29 17:01]
S3 STBUS;STBUS;C:\Windows\system32\drivers\stbus.sys [2008-02-29 17:01]
S3 stppp;Speedtouch PPP Adapter Adapter;C:\Windows\system32\DRIVERS\stppp.sys [2008-02-29 17:01]
S3 VAIOMediaPlatform-UCLS-AppServer;VAIO Media Content Collection;C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe [2007-01-11 00:51]
S3 VAIOMediaPlatform-UCLS-HTTP;VAIO Media Content Collection (HTTP);"C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe" /Service=VAIOMediaPlatform-UCLS-HTTP /RegRoot="SOFTWARE\Sony Corporation\VAIO Media Platform\2.0" /RegExt="\Applications\UCLS\HTTP" []
S3 VAIOMediaPlatform-UCLS-UPnP;VAIO Media Content Collection (UPnP);C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe [2007-06-20 23:34]
S3 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;"C:\Program Files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe" [2007-07-06 03:12]
S3 VcmXmlIfHelper;VAIO Content Metadata XML Interface;"C:\Program Files\Common Files\Sony Shared\VcmXml\VcmXmlIfHelper.exe" [2007-07-06 01:43]
.
Contents of the 'Scheduled Tasks' folder
"2008-05-20 19:44:33 C:\Windows\Tasks\User_Feed_Synchronization-{287A80A8-B648-4746-823F-5EB2E92E0959}.job"
- C:\Windows\system32\msfeedssync.exe
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2008-05-20 20:42:05
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Windows\System32\audiodg.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Apoint\ApMsgFwd.exe
C:\Windows\System32\igfxsrvc.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Apoint\ApntEx.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
C:\Program Files\Sony\VAIO Event Service\VESMgr.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe
C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe
C:\Program Files\Windows Media Player\wmplayer.exe
C:\Windows\System32\igfxext.exe
C:\Windows\System32\igfxsrvc.exe
C:\Windows\System32\igfxext.exe
C:\Windows\System32\igfxsrvc.exe
C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
C:\Windows\ehome\ehsched.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\ehome\ehrecvr.exe
C:\Windows\System32\wbem\unsecapp.exe
.
**************************************************************************
.
Completion time: 2008-05-20 20:46:52 - machine was rebooted
ComboFix-quarantined-files.txt 2008-05-20 19:46:47
ComboFix2.txt 2008-05-20 15:31:35
ComboFix3.txt 2008-04-12 10:15:21
Pre-Run: 168,480,346,112 bytes free
Post-Run: 168,438,935,552 bytes free
518 --- E O F --- 2008-05-17 10:12:42