ComboFix 10-09-12.04 - Administrator 21/09/2010 5:34.1.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.65.1033.18.3068.1715 [GMT 8:00]
Running from: c:\users\Administrator\Desktop\ComboFix.exe
SP: Anti-spyware *enabled* (Updated) {D25F8255-FCD5-47DC-B7C3-2DEF4C9D3B3F}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\program files\Anti-Spyware\Anti-Spyware.url
c:\program files\Anti-Spyware\DataBase.ref
.
((((((((((((((((((((((((( Files Created from 2010-08-20 to 2010-09-20 )))))))))))))))))))))))))))))))
.
2010-09-20 21:37 . 2010-09-20 21:37 -------- d-----w- c:\users\Administrator\AppData\Local\temp
2010-09-20 17:50 . 2010-09-20 17:50 -------- d-----w- c:\users\Administrator\AppData\Local\Threat Expert
2010-09-13 15:17 . 2010-08-30 05:57 767952 ----a-w- c:\windows\BDTSupport.dll
2010-09-13 15:17 . 2010-08-26 01:30 2074 ----a-w- c:\windows\UDB.zip
2010-09-13 15:17 . 2010-08-23 01:36 149456 ----a-w- c:\windows\SGDetectionTool.dll
2010-09-13 15:17 . 2008-11-26 03:08 131 ----a-w- c:\windows\IDB.zip
2010-09-13 15:17 . 2010-09-02 07:00 739280 ----a-w- c:\windows\PCTBDRes.dll
2010-09-13 15:17 . 2010-09-02 07:00 1865680 ----a-w- c:\windows\PCTBDCore.dll
2010-09-13 14:58 . 2010-07-16 06:59 656320 ----a-w- c:\windows\system32\drivers\pctEFA.sys
2010-09-13 14:58 . 2010-07-16 06:59 338880 ----a-w- c:\windows\system32\drivers\pctDS.sys
2010-09-13 14:58 . 2010-09-01 02:13 247824 ----a-w- c:\windows\system32\drivers\pctgntdi.sys
2010-09-13 14:58 . 2010-08-28 03:28 102184 ----a-w- c:\windows\system32\drivers\pctwfpfilter.sys
2010-09-13 10:22 . 2010-09-13 10:28 -------- d-----w- c:\users\Administrator\AppData\Local\EnglishHarbourCasino
2010-09-13 09:55 . 2010-09-13 09:55 -------- d-----w- c:\windows\system32\N360_BACKUP
2010-09-13 07:21 . 2010-09-13 07:43 -------- d-----w- c:\users\Administrator\AppData\Roaming\CasinoOnNet
2010-09-13 07:21 . 2010-09-13 07:30 -------- d-----w- c:\program files\CasinoOnNet
2010-09-13 06:28 . 2010-09-13 06:28 1563648 ----a-w- c:\users\Administrator\AppData\Roaming\Notepad++\plugins\config\plugin_install_temp\plugin1\bin\NppFTP.dll
2010-09-13 06:28 . 2010-09-13 06:28 1539584 ----a-w- c:\users\Administrator\AppData\Roaming\Notepad++\plugins\config\plugin_install_temp\plugin1\bin\NppFTPA.dll
2010-09-13 06:26 . 2010-09-13 06:28 -------- d-----w- c:\users\Administrator\AppData\Roaming\Notepad++
2010-09-13 06:26 . 2010-09-13 06:26 -------- d-----w- c:\program files\Notepad++
2010-09-12 19:34 . 2010-09-12 19:34 -------- d-----w- c:\program files\Common Files\PCSuite
2010-09-12 19:34 . 2010-09-12 19:34 -------- d-----w- c:\program files\Common Files\Nokia
2010-09-12 19:33 . 2008-08-26 02:26 18816 ----a-w- c:\windows\system32\drivers\pccsmcfd.sys
2010-09-12 19:18 . 2010-09-12 19:17 36365624 ----a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Nokia_PC_Suite_eng.exe
2010-09-12 19:17 . 2010-09-12 19:17 95232 ----a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\pcswpcsi.exe
2010-09-12 19:17 . 2010-09-12 19:17 61440 ----a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-09-12 19:17 . 2010-09-12 19:17 10240 ----a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstPCS.exe
2010-09-12 19:17 . 2010-09-12 19:17 8192 ----a-w- c:\programdata\Installations\{225DB4AA-3CFF-47E8-B3C8-6DAD713E986E}\Installer\CommonCustomActions\UninstCCD.exe
2010-09-12 18:59 . 2010-09-12 18:59 -------- d-----w- c:\users\Administrator\AppData\Roaming\PC Suite
2010-09-12 18:58 . 2010-09-12 19:46 -------- d-----w- c:\users\Administrator\AppData\Roaming\Nokia
2010-09-12 18:55 . 2010-09-12 18:55 733783 ----a-w- c:\programdata\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Packages\Nokia_PC_Suite\CustomActions\NSU_Inst_fix.exe
2010-09-12 18:55 . 2010-09-12 18:55 8192 ----a-w- c:\programdata\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstCCD.exe
2010-09-12 18:55 . 2010-09-12 18:55 61440 ----a-w- c:\programdata\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstPCSFEMsi.exe
2010-09-12 18:55 . 2010-09-12 18:55 10240 ----a-w- c:\programdata\Installations\{29466F9C-7C6A-419C-B301-F440FAF78760}\Installer\CommonCustomActions\UninstPCS.exe
2010-09-12 18:55 . 2010-09-12 19:17 -------- d-----w- c:\programdata\Installations
2010-09-12 15:30 . 2010-09-12 15:30 -------- d-----w- c:\users\Administrator\AppData\Roaming\MPEG Streamclip
2010-09-12 14:44 . 2007-03-12 15:34 77312 ----a-w- c:\windows\system32\ztvunace26.dll
2010-09-12 14:44 . 2007-03-12 15:34 69632 ----a-w- c:\windows\system32\ztvcabinet.dll
2010-09-12 14:44 . 2007-03-12 15:34 162304 ----a-w- c:\windows\system32\ztvunrar36.dll
2010-09-12 14:43 . 2010-09-12 14:44 -------- d-----w- c:\program files\TUGZip
2010-09-12 13:56 . 2010-09-12 13:56 -------- d-----w- c:\program files\iPod
2010-09-12 13:56 . 2010-09-12 13:57 -------- d-----w- c:\program files\iTunes
2010-09-11 16:04 . 2010-09-11 16:04 -------- d-----w- c:\users\Administrator\AppData\Roaming\Scooter Software
2010-09-11 16:04 . 2010-09-11 16:26 -------- d-----w- c:\program files\Beyond Compare 3
2010-09-11 03:22 . 2010-09-11 03:22 -------- d-----w- c:\program files\Common Files\Java
2010-09-10 16:29 . 2010-09-10 16:29 81016 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\71\1\.cp\lib\S1SLEngineWrapper.dll
2010-09-10 16:29 . 2010-09-10 16:29 101496 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\81\1\.cp\lib\USBFlash.dll
2010-09-10 16:02 . 2010-09-10 16:02 56440 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\73\1\.cp\lib\sef3x1Controller.dll
2010-09-10 15:59 . 2010-09-10 15:59 109688 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\83\1\.cp\lib\WinMobileWrapper.dll
2010-09-10 15:59 . 2010-09-10 15:59 109752 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\67\1\.cp\lib\osds.dll
2010-09-10 15:58 . 2010-09-10 15:58 85176 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\79\1\.cp\lib\UAC.dll
2010-09-10 15:58 . 2010-09-10 15:58 323648 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DIFxAPI.dll
2010-09-10 15:58 . 2010-09-10 15:58 216184 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\69\1\.cp\lib\RegistryReader.dll
2010-09-10 15:58 . 2010-09-10 15:58 158840 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\10\1\.cp\lib\win32\DriverInstaller.exe
2010-09-10 15:58 . 2010-09-10 15:58 154744 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\8\1\.cp\lib\win32\DeviceRemover.exe
2010-09-10 15:58 . 2010-09-10 15:58 117880 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\6\1\.cp\lib\DeviceManager.dll
2010-09-10 15:58 . 2010-09-10 15:58 57344 ----a-w- c:\programdata\Sony Ericsson\SEMC OMSI Module\omsiconf\org.eclipse.osgi\bundles\4\1\.cp\lib\serialio.dll
2010-09-10 04:13 . 2010-09-10 04:13 851968 ----a-w- c:\programdata\MGS\cache\b\biathlonbonus.1867224e07f193acaf7efbba325b104b.dll
2010-09-10 04:11 . 2010-09-10 04:11 2117632 ----a-w- c:\programdata\MGS\cache\a\advancedslots1_gao_sept_2010.a14bcfe0be9a08dacc20f3b3716a56ea.dll
2010-09-10 04:11 . 2010-09-10 04:11 1323008 ----a-w- c:\programdata\MGS\cache\a\advancedslots1xxx_gao_sept_2010.b4ef82cefbff5adee5c54e1665ff11d9.dll
2010-09-10 04:11 . 2010-09-10 04:11 765952 ----a-w- c:\programdata\MGS\cache\t\transition_gao_sept_2010.c5019682c8e08f3f5b171a343182a7a6.dll
2010-09-10 02:31 . 2009-06-10 09:43 88576 ----a-w- c:\windows\system32\tlntsess.exe
2010-09-10 02:31 . 2009-06-10 09:43 71168 ----a-w- c:\windows\system32\telnet.exe
2010-09-09 15:26 . 2010-09-09 15:26 -------- d-----w- c:\users\Administrator\AppData\Roaming\QQMusicUpdate
2010-09-09 15:26 . 2010-09-09 15:26 -------- d-----w- c:\users\Administrator\AppData\Roaming\Tencent
2010-09-09 11:36 . 2010-09-09 14:36 -------- d-----w- c:\users\Administrator\AppData\Local\Sony
2010-09-09 11:35 . 2010-09-09 11:35 -------- d-----w- c:\users\Administrator\Podcasts
2010-09-09 11:35 . 2010-09-09 11:35 -------- d-----w- c:\users\Administrator\AppData\Roaming\Sony
2010-09-09 10:30 . 2010-09-09 10:30 -------- d-----w- c:\users\Administrator\AppData\Local\Sony Corporation
2010-09-08 23:32 . 2010-09-08 23:32 -------- d-----w- c:\program files\7-Zip
2010-09-08 20:34 . 2009-06-12 10:18 26600 ----a-r- c:\windows\system32\drivers\GEARAspiWDM.sys
2010-09-08 20:34 . 2008-01-29 04:32 107368 ----a-r- c:\windows\system32\GEARAspi.dll
2010-09-08 20:25 . 2010-09-08 20:25 -------- d-----w- C:\inetpub
2010-09-08 20:04 . 2010-09-13 14:57 -------- d-----w- c:\program files\Symantec
2010-09-08 15:25 . 2010-09-08 15:30 -------- d-----w- c:\users\Administrator\AppData\Roaming\Auslogics
2010-09-08 14:31 . 2010-09-08 14:31 -------- d-----w- c:\users\Administrator\AppData\Local\TopoGrafix
2010-09-08 14:31 . 2010-09-11 13:55 -------- d-----w- c:\program files\EasyGPS
2010-09-08 12:13 . 2010-09-08 12:13 57344 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.dll
2010-09-08 12:12 . 2010-09-08 12:08 185640 ----a-w- c:\programdata\DivX\Setup\finishPlugin.dll
2010-09-08 12:12 . 2010-09-08 12:08 1062184 ----a-w- c:\programdata\DivX\Setup\Resource.dll
2010-09-08 12:12 . 2010-09-08 12:08 850200 ----a-w- c:\programdata\DivX\Setup\DivXSetup.exe
2010-09-08 12:12 . 2010-09-08 12:12 56765 ----a-w- c:\programdata\DivX\DivXPlusShortcuts\Uninstaller.exe
2010-09-08 12:11 . 2010-09-08 12:12 56997 ----a-w- c:\programdata\DivX\WebPlayer\Uninstaller.exe
2010-09-08 12:11 . 2010-09-08 12:11 53600 ----a-w- c:\programdata\DivX\Update\Uninstaller.exe
2010-09-08 12:11 . 2010-09-08 12:11 57691 ----a-w- c:\programdata\DivX\Player\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 18:08 -------- d-----w- c:\users\Administrator\AppData\Roaming\DivX
2010-09-08 12:10 . 2010-09-08 12:10 84063 ----a-w- c:\programdata\DivX\TransferWizard\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 57054 ----a-w- c:\programdata\DivX\DSDesktopComponents\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 54166 ----a-w- c:\programdata\DivX\DSAVCDecoder\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 57532 ----a-w- c:\programdata\DivX\DSASPDecoder\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 56458 ----a-w- c:\programdata\DivX\DivXDecoderShortcut\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 54174 ----a-w- c:\programdata\DivX\DSAACDecoder\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 54153 ----a-w- c:\programdata\DivX\DFXPlugin\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 54128 ----a-w- c:\programdata\DivX\Converter\Uninstaller.exe
2010-09-08 12:10 . 2010-09-08 12:10 54644 ----a-w- c:\programdata\DivX\TranscodeEngine\Uninstaller.exe
2010-09-08 12:09 . 2010-09-08 12:09 54101 ----a-w- c:\programdata\DivX\MPEG2Plugin\Uninstaller.exe
2010-09-08 12:09 . 2010-09-08 12:09 57409 ----a-w- c:\programdata\DivX\ControlPanel\Uninstaller.exe
2010-09-08 12:09 . 2010-09-08 12:09 52963 ----a-w- c:\programdata\DivX\MSVC80CRTRedist\Uninstaller.exe
2010-09-08 12:09 . 2010-09-08 12:09 54073 ----a-w- c:\programdata\DivX\Qt4.5\Uninstaller.exe
2010-09-08 12:09 . 2010-09-08 12:09 -------- d-----w- c:\program files\Common Files\DivX Shared
2010-09-08 12:09 . 2010-09-08 12:09 56969 ----a-w- c:\programdata\DivX\ASPEncoder\Uninstaller.exe
2010-09-08 12:08 . 2010-09-08 12:12 -------- d-----w- c:\program files\DivX
2010-09-08 12:08 . 2010-09-09 18:24 144696 ----a-w- c:\programdata\DivX\RunAsUser\RUNASUSERPROCESS.exe
2010-09-08 12:08 . 2010-09-08 12:12 -------- d-----w- c:\programdata\DivX
2010-09-08 12:05 . 2010-09-11 13:55 -------- d-----w- c:\program files\Smith Micro
2010-09-08 09:57 . 2010-09-08 09:57 -------- d-----w- c:\programdata\ParetoLogic
2010-09-08 09:57 . 2010-09-08 09:57 -------- d-----w- c:\program files\Common Files\ParetoLogic
2010-09-08 09:57 . 2010-09-08 09:57 -------- d-----w- c:\program files\ParetoLogic
2010-09-08 09:11 . 2010-09-08 09:11 -------- d-----w- c:\program files\Uniblue
2010-09-08 08:47 . 2010-09-08 08:47 -------- d-----w- c:\program files\Data Rescue PC 3
2010-09-05 07:37 . 2010-09-05 07:37 -------- d-----w- c:\users\Administrator\AppData\Roaming\Malwarebytes
2010-09-05 07:36 . 2010-09-05 07:36 -------- d-----w- c:\programdata\Malwarebytes
2010-09-03 06:38 . 2010-09-03 06:38 1019904 ----a-w- c:\programdata\MGS\cache\s\simplepickuntilbonus_gao_sept_2010.6cac7171bd4af7dccbfa536b185365c5.dll
2010-09-03 06:38 . 2010-09-03 06:38 1323008 ----a-w- c:\programdata\MGS\cache\a\advancedslots1xxx_gao_sept_2010.9fd0f3becbeef11fbd18f922c2415d4e.dll
2010-09-03 06:38 . 2010-09-03 06:38 2113536 ----a-w- c:\programdata\MGS\cache\a\advancedslots1_gao_sept_2010.bff514082b50d7a815e2a21aacd9736e.dll
2010-09-03 06:37 . 2010-09-03 06:37 1933312 ----a-w- c:\programdata\MGS\cache\s\simplepickxofybonus_gao_sept_2010.fcc526c9467e81ccb387fd5cfdc704a2.dll
2010-09-03 06:29 . 2010-09-03 06:29 1798144 ----a-w- c:\programdata\MGS\cache\c\complexpickxofybonus_gao_sept_2010.10749ccbe15cd8c682312d5d228e059e.dll
2010-09-03 06:28 . 2010-09-03 06:28 765952 ----a-w- c:\programdata\MGS\cache\t\transition_gao_sept_2010.1922b5af032b5756b5d14b9df35203cf.dll
2010-09-03 06:17 . 2010-09-03 06:17 1318912 ----a-w- c:\programdata\MGS\cache\a\advancedslots1xxx_gao_may_2010_ts2.9ab5bb140595bba8fd13b83b24083d91.dll
2010-09-03 06:17 . 2010-09-03 06:17 1273856 ----a-w- c:\programdata\MGS\cache\p\progressivepickxofybonus_gao_may_2010_ts2.f4e34337c173dd0414d8f4ce6301c5e1.dll
2010-09-03 06:16 . 2010-09-03 06:16 2023424 ----a-w- c:\programdata\MGS\cache\a\advancedslots1_gao_may_2010_ts2.f449c9d999de976113be9b55d69527ea.dll
2010-09-03 06:16 . 2010-09-03 06:16 761856 ----a-w- c:\programdata\MGS\cache\t\transition_gao_may_2010_ts2.c7b3419015c96c5796347014e1a92974.dll
2010-09-03 05:57 . 2010-09-03 05:57 106496 ----a-w- c:\programdata\MGS\cache\a\aurora.4a5fa118e253af82dc18a442da7d696d.dll
2010-09-03 05:53 . 2010-09-03 05:53 65536 ----a-w- c:\programdata\MGS\cache\v\void.c19b3dfc09b07295326d40aca47e2109.dll
2010-09-03 05:52 . 2010-09-03 05:52 94208 ----a-w- c:\programdata\MGS\cache\l\lua51host.1b8962f1114286ac91f3ce67ee9654e7.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-09-20 21:32 . 2008-12-05 01:03 225871 ----a-w- c:\programdata\nvModes.dat
2010-09-20 20:55 . 2010-09-13 14:58 -------- d-----w- c:\program files\PC Tools Security
2010-09-20 17:26 . 2010-05-23 11:54 -------- d-----w- c:\program files\Norton 360
2010-09-20 17:26 . 2010-05-03 01:41 -------- d-----w- c:\programdata\Norton
2010-09-13 15:17 . 2010-09-13 14:53 -------- d-----w- c:\program files\Common Files\PC Tools
2010-09-13 14:59 . 2010-09-13 14:58 2141292 ----a-w- c:\windows\system32\drivers\Cat.DB
2010-09-13 14:58 . 2010-09-13 14:14 -------- d-----w- c:\programdata\PC Tools
2010-09-13 14:58 . 2010-05-03 01:41 -------- d-----w- c:\program files\NortonInstaller
2010-09-13 14:58 . 2010-09-13 14:58 -------- d-----w- c:\users\Administrator\AppData\Roaming\PC Tools
2010-09-13 14:57 . 2009-04-24 11:41 -------- d-----w- c:\program files\Common Files\Symantec Shared
2010-09-13 14:53 . 2010-09-13 14:53 -------- d-----w- c:\program files\PC Tools Registry Tool
2010-09-13 14:19 . 2010-09-13 14:14 76704968 ----a-w- c:\programdata\PC Tools\DownloadManager\Spyware Doctor with AntiVirus8.0\sdasetup_dl.exe
2010-09-13 10:34 . 2008-12-05 01:26 -------- d--h--w- c:\program files\InstallShield Installation Information
2010-09-13 09:56 . 2008-12-05 00:15 2140 ----a-w- c:\windows\bthservsdp.dat
2010-09-13 09:15 . 2010-04-27 05:12 110200 ----a-w- c:\windows\system32\GDIPFONTCACHEV1.DAT
2010-09-13 06:26 . 2010-08-11 21:05 -------- d-----w- c:\programdata\FileCure
2010-09-12 19:33 . 2009-06-29 18:10 -------- d-----w- c:\program files\DIFX
2010-09-12 19:33 . 2009-08-22 07:00 -------- d-----w- c:\program files\PC Connectivity Solution
2010-09-12 13:57 . 2010-04-27 05:13 -------- d-----w- c:\users\Administrator\AppData\Roaming\Apple Computer
2010-09-12 13:53 . 2009-04-24 12:00 -------- d-----w- c:\program files\Bonjour
2010-09-11 13:58 . 2010-04-30 12:50 -------- d-----w- c:\program files\TuneUp Utilities 2010
2010-09-11 13:57 . 2008-12-05 01:27 -------- d-----w- c:\program files\Dolby
2010-09-11 13:56 . 2010-08-11 22:19 -------- d-----w- c:\program files\IObit
2010-09-11 13:04 . 2010-08-10 18:54 -------- d-----w- c:\program files\Opera
2010-09-11 12:22 . 2008-12-05 03:22 -------- d-----w- c:\program files\Common Files\Sony Shared
2010-09-11 03:21 . 2010-06-30 22:04 423656 ----a-w- c:\windows\system32\deployJava1.dll
2010-09-10 15:56 . 2010-03-11 05:01 -------- d-----w- c:\program files\Common Files\Sony Ericsson
2010-09-10 15:56 . 2010-01-21 04:56 -------- d-----w- c:\program files\Sony Ericsson
2010-09-10 15:56 . 2010-01-21 05:29 -------- d-----w- c:\programdata\Sony Ericsson
2010-09-09 18:21 . 2007-01-13 06:41 -------- d-----w- c:\program files\ArcSoft
2010-09-09 17:36 . 2010-08-11 22:36 -------- d-----w- c:\users\Administrator\AppData\Roaming\CBS Interactive
2010-09-09 16:41 . 2008-12-05 03:25 -------- d-----w- c:\program files\Sony
2010-09-09 14:35 . 2010-04-27 05:10 -------- d-----w- c:\users\Administrator\AppData\Roaming\Sony Corporation
2010-09-08 22:57 . 2009-04-24 11:42 -------- d-----w- c:\programdata\Symantec
2010-09-08 20:32 . 2010-05-03 01:41 -------- d-----w- c:\programdata\NortonInstaller
2010-09-08 19:27 . 2008-12-05 03:25 -------- d-----w- c:\programdata\Sony Corporation
2010-09-08 16:27 . 2008-12-05 01:26 319488 ----a-w- c:\windows\HideWin.exe
2010-09-08 12:42 . 2010-08-11 21:35 -------- d-----w- c:\users\Administrator\AppData\Roaming\Uniblue
2010-09-08 12:12 . 2009-04-25 07:06 -------- d-----w- c:\program files\Google
2010-09-08 11:51 . 2009-05-06 05:16 -------- d--h--w- c:\programdata\ArcSoft
2010-09-07 23:57 . 2010-08-11 22:50 -------- d-----w- c:\users\Administrator\AppData\Roaming\ArcSoft
2010-09-03 09:59 . 2010-08-12 00:20 -------- d-----w- c:\users\Administrator\AppData\Roaming\Skype
2010-09-03 06:52 . 2007-01-13 06:20 -------- d-----w- c:\programdata\Microsoft Help
2010-09-03 03:28 . 2010-09-13 14:58 87400 ----a-w- c:\windows\system32\drivers\pctNdis-PacketFilter.sys
2010-09-02 21:04 . 2010-09-02 21:04 0 ---ha-w- c:\windows\system32\drivers\Msft_User_WpdRapi_01_00_00.Wdf
2010-09-02 18:47 . 2010-06-28 15:52 -------- d-----w- c:\program files\Microsoft Silverlight
2010-09-02 17:12 . 2007-01-13 06:57 -------- d-----w- c:\program files\Windows Live
2010-08-30 14:02 . 2010-08-09 22:25 110200 ----a-w- c:\users\Melancholy\AppData\Local\GDIPFONTCACHEV1.DAT
2010-08-30 12:31 . 2009-12-29 17:18 -------- d-----w- c:\programdata\Messenger Plus!
2010-08-27 02:13 . 2010-09-13 14:53 159296 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys
2010-08-27 01:13 . 2010-05-28 16:49 -------- d-----w- c:\program files\Mobile Broadband Modem
2010-08-27 01:06 . 2010-05-03 16:33 -------- d-----w- c:\program files\Yahoo!
2010-08-27 00:26 . 2010-09-13 14:58 70536 ----a-w- c:\windows\system32\drivers\pctplsg.sys
2010-08-27 00:26 . 2010-09-13 14:58 123968 ----a-w- c:\windows\system32\drivers\pctplfw.sys
2010-08-26 18:28 . 2010-08-12 03:54 -------- d-----w- c:\users\Administrator\AppData\Roaming\COWON
2010-08-24 07:33 . 2009-09-26 13:12 -------- d-----w- c:\programdata\Apple Computer
2010-08-18 05:51 . 2010-09-13 14:53 237632 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2010-08-15 08:24 . 2010-08-12 00:15 -------- d-----w- c:\program files\PhotoScape
2010-08-15 07:29 . 2010-08-12 02:37 -------- d-----w- c:\users\Melancholy\AppData\Roaming\ArcSoft
2010-08-15 06:18 . 2010-08-01 12:21 -------- d-----w- c:\program files\DSHappyBox
2010-08-14 09:41 . 2010-08-14 09:41 -------- d-----w- c:\programdata\Intel
2010-08-14 09:40 . 2010-08-14 09:39 -------- d-----w- c:\program files\Cisco
2010-08-14 09:39 . 2010-08-14 09:39 -------- d-----w- c:\program files\Common Files\Intel
2010-08-14 08:43 . 2010-08-14 08:43 -------- d-----w- c:\program files\SystemRequirementsLab
2010-08-14 08:37 . 2010-08-14 08:37 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\Yahoo!
2010-08-14 08:37 . 2010-08-14 08:37 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\ArcSoft
2010-08-12 19:26 . 2010-05-03 13:29 30528 ----a-w- c:\windows\system32\TURegOpt.exe
2010-08-12 18:29 . 2010-08-12 18:29 2772992 ----a-w- c:\windows\system32\GPhotos.scr
2010-08-12 13:23 . 2007-01-13 06:41 -------- d-----w- c:\program files\Common Files\ArcSoft
2010-08-12 08:37 . 2010-06-28 16:39 -------- d-----w- c:\programdata\Kaspersky Lab
2010-08-12 08:37 . 2010-05-06 11:35 -------- d-----w- c:\programdata\TSLOG
2010-08-12 08:33 . 2010-08-11 22:19 -------- d-----w- c:\users\Administrator\AppData\Roaming\IObit
2010-08-12 08:21 . 2010-08-12 08:21 -------- d-----w- c:\programdata\IObit
2010-08-12 06:40 . 2009-04-24 14:31 -------- d-----w- c:\program files\Microsoft
2010-08-12 04:07 . 2008-06-16 20:55 126448 ------w- c:\windows\system32\pxinsi64.exe
2010-08-12 04:07 . 2008-06-16 11:00 45648 ------w- c:\windows\system32\drivers\pxhelp20.sys
2010-08-12 04:07 . 2007-01-13 06:24 133616 ------w- c:\windows\system32\pxafs.dll
2010-08-12 03:40 . 2010-05-03 16:37 -------- d-----w- c:\users\Administrator\AppData\Roaming\Yahoo!
2010-08-12 03:38 . 2010-08-11 20:57 -------- d-----w- c:\users\Administrator\AppData\Roaming\FreeFileViewer
2010-08-12 03:36 . 2010-08-12 03:36 -------- d-----w- c:\users\Melancholy\AppData\Roaming\PhotoScape
2010-08-12 03:26 . 2010-04-27 10:24 -------- d-----r- c:\program files\Skype
2010-08-12 02:33 . 2010-08-11 22:36 -------- d-----w- c:\users\Administrator\AppData\Roaming\OpenCandy
2010-08-12 00:46 . 2010-08-12 00:26 -------- d-----w- c:\users\Administrator\AppData\Roaming\PhotoScape
2010-08-12 00:28 . 2010-08-12 00:28 -------- d-----w- c:\program files\SKYPE Recorder9
2010-08-12 00:27 . 2010-08-12 00:27 56 ---ha-w- c:\windows\system32\ezsidmv.dat
2010-08-12 00:27 . 2010-08-12 00:27 -------- d-----w- c:\users\Administrator\AppData\Roaming\skypePM
2010-08-12 00:18 . 2010-08-12 00:18 -------- d-----w- c:\programdata\FreeRIP
2010-08-11 23:56 . 2010-08-11 23:56 -------- d-----w- c:\users\Administrator\AppData\Roaming\PhotoFiltre
2010-08-11 22:50 . 2010-07-25 12:33 -------- d-----w- c:\program files\Common Files\Adobe AIR
2010-08-11 22:49 . 2010-07-25 12:33 53632 ----a-w- c:\users\Default\AppData\Roaming\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-08-11 22:36 . 2010-08-11 22:36 333048 ----a-w- c:\users\Administrator\AppData\Roaming\OpenCandy\DLMgr_3_1.6.63.exe
2010-08-11 22:31 . 2010-04-30 12:41 -------- d-----w- c:\program files\CCleaner
2010-08-11 22:05 . 2010-08-11 22:05 -------- d-----w- c:\users\Administrator\AppData\Roaming\Registry Mechanic
2010-08-11 12:15 . 2007-01-13 06:41 -------- d-----w- c:\programdata\McAfee
2010-08-11 11:57 . 2010-08-11 11:57 -------- d-----w- c:\windows\system32\config\systemprofile\AppData\Roaming\McAfee
2010-08-11 11:57 . 2010-07-25 16:04 -------- d-----w- c:\program files\McAfee Security Scan
2010-08-11 11:49 . 2006-11-02 11:18 -------- d-----w- c:\program files\Windows Mail
2010-08-10 22:02 . 2007-01-13 06:22 -------- d-----w- c:\program files\Microsoft Works
2010-08-10 22:02 . 2010-04-27 10:24 -------- d-----w- c:\program files\Common Files\Skype
2010-08-10 20:18 . 2010-08-10 19:59 -------- d-----w- c:\users\Melancholy\AppData\Roaming\VTExtra
2009-05-04 05:14 . 2010-05-06 10:58 36864 ----a-w- c:\program files\mozilla firefox\components\NsThunderLoader.dll
2010-04-09 06:55 . 2010-05-06 10:58 79664 ----a-w- c:\program files\mozilla firefox\components\ThunderComponent.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-21 1008184]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-08-19 1348904]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2008-11-05 13556256]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2009-11-11 1468256]
"Norton Online Backup"="c:\program files\Symantec\Norton Online Backup\NOBuClient.exe" [2010-06-08 968536]
"PCTools FGuard"="c:\program files\PC Tools Security\BDT\FGuard.exe" [2010-09-02 108496]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2008-10-15 776744]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\VESWinlogon]
2008-11-06 02:32 98304 ----a-w- c:\windows\System32\VESWinlogon.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Messenger (Yahoo!)"="c:\progra~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" /background
"WMPNSCFG"=c:\program files\Windows Media Player\WMPNSCFG.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"NvMediaCenter"=RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe"
"MobileConnect"=%programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
"ArcSoft Connection Service"=c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" -atboottime
"DivXUpdate"="c:\program files\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
"CTRegRun"=c:\windows\CTRegRun.EXE
"GrooveMonitor"="c:\program files\Microsoft Office\Office12\GrooveMonitor.exe"
"ApMain"=c:\program files\AlpsPoint\ApMain.exe
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
R1 hname;hname;c:\windows\system32\hname.SYS [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-08-12 135664]
R2 OMSI download service;Sony Ericsson OMSI download service;c:\program files\Sony Ericsson\Sony Ericsson PC Suite\SupServ.exe [2009-04-30 90112]
R2 TuneUp.UtilitiesSvc;TuneUp Utilities Service;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe [2010-08-12 1051968]
R3 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;c:\program files\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-09-16 169312]
R3 ApPS2;Alps StickPointer for VAIO;c:\windows\system32\DRIVERS\ApPS2.sys [2009-02-12 67120]
R3 cpudrv;cpudrv;c:\program files\SystemRequirementsLab\cpudrv.sys [2009-12-18 11336]
R3 ewusbnet;HUAWEI USB-NDIS miniport;c:\windows\system32\DRIVERS\ewusbnet.sys [2009-02-17 112128]
R3 ggflt;SEMC USB Flash Driver Filter;c:\windows\system32\DRIVERS\ggflt.sys [2010-01-21 13224]
R3 hwusbfake;Huawei DataCard USB Fake;c:\windows\system32\DRIVERS\ewusbfake.sys [2008-12-30 103040]
R3 massfilter;ZTE Mass Storage Filter Driver;c:\windows\system32\DRIVERS\massfilter.sys [2008-11-12 7680]
R3 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 nmwcdnsu;Nokia USB Flashing Phone Parent;c:\windows\system32\drivers\nmwcdnsu.sys [2010-02-26 137344]
R3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\DRIVERS\s0016bus.sys [2008-05-16 89256]
R3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s0016mdfl.sys [2008-05-16 15016]
R3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s0016mdm.sys [2008-05-16 120744]
R3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s0016mgmt.sys [2008-05-16 114216]
R3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\DRIVERS\s0016nd5.sys [2008-05-16 25512]
R3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s0016obex.sys [2008-05-16 110632]
R3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\DRIVERS\s0016unic.sys [2008-05-16 115752]
R3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\DRIVERS\s1018bus.sys [2008-06-04 90408]
R3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\DRIVERS\s1018mdfl.sys [2008-06-04 15016]
R3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\DRIVERS\s1018mdm.sys [2008-06-04 122024]
R3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\DRIVERS\s1018mgmt.sys [2008-06-04 115368]
R3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\DRIVERS\s1018nd5.sys [2008-06-04 25768]
R3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\DRIVERS\s1018obex.sys [2008-06-04 111784]
R3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\DRIVERS\s1018unic.sys [2008-06-04 117544]
R3 sdAuxService;PC Tools Auxiliary Service;c:\program files\PC Tools Security\pctsAuxs.exe [2010-03-15 366840]
R3 VcmXmlIfHelper;VAIO Content Metadata XML Interface; [x]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
R3 ZTEusbnet;ZTE USB-NDIS miniport;c:\windows\system32\DRIVERS\ZTEusbnet.sys [2008-11-12 110080]
R3 ZTEusbvoice;ZTE VoUSB Port;c:\windows\system32\DRIVERS\ZTEusbvoice.sys [2008-11-12 104960]
S0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [2010-08-18 237632]
S0 pctDS;PC Tools Data Store;c:\windows\system32\drivers\pctDS.sys [2010-07-16 338880]
S0 pctEFA;PC Tools Extended File Attributes;c:\windows\system32\drivers\pctEFA.sys [2010-07-16 656320]
S1 ElRawDisk;ElRawDisk;c:\windows\system32\drivers\dddsk.sys [2009-02-12 22312]
S2 atashost;WebEx Service Host for Support Center;c:\windows\system32\atashost.exe [2009-03-06 20376]
S2 Browser Defender Update Service;Browser Defender Update Service;c:\program files\PC Tools Security\BDT\BDTUpdateService.exe [2010-09-02 235472]
S2 EmmaDevMgmtSvc;Emma Device Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaDeviceMgmt.exe [2010-08-24 306296]
S2 EmmaUpdMgmtSvc;Emma Update Management;c:\program files\Common Files\Sony Ericsson\Emma Core\Services\EmmaUpdateMgmt.exe [2010-08-24 162936]
S2 FsUsbExService;FsUsbExService;c:\windows\system32\FsUsbExService.Exe [2009-04-07 233472]
S2 iprip;RIP Listener;c:\windows\System32\svchost.exe [2008-01-21 21504]
S2 NOBU;Norton Online Backup;c:\program files\Symantec\Norton Online Backup\NOBuAgent.exe SERVICE [x]
S2 NSUService;NSUService;c:\program files\Sony\Network Utility\NSUService.exe [2008-12-05 303104]
S2 regi;regi;c:\windows\system32\drivers\regi.sys [2007-04-18 11032]
S2 SampleCollector;Intel(R) Sample Collector;c:\program files\Sony\VAIO Care\collsvc.exe [2009-09-16 122880]
S2 SOHCImp;VAIO Media plus Content Importer;c:\program files\Sony\VAIO Media plus\SOHCImp.exe [2008-10-21 103712]
S2 SOHDms;VAIO Media plus Digital Media Server;c:\program files\Sony\VAIO Media plus\SOHDms.exe [2008-10-21 353568]
S2 SOHDs;VAIO Media plus Device Searcher;c:\program files\Sony\VAIO Media plus\SOHDs.exe [2008-10-21 62752]
S2 uCamMonitor;CamMonitor;c:\program files\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [2008-09-18 104960]
S2 VCFw;VAIO Content Folder Watcher;c:\program files\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [2009-03-05 5189992]
S2 VcmIAlzMgr;VAIO Content Metadata Intelligent Analyzing Manager;c:\program files\Sony\VCM Intelligent Analyzing Manager\VcmIAlzMgr.exe [2009-09-16 480624]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-11-04 14336]
S3 ArcSoftKsUFilter;ArcSoft Magic-I Visual Effect;c:\windows\system32\DRIVERS\ArcSoftKsUFilter.sys [2008-04-24 17920]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2008-11-05 29736]
S3 FsUsbExDisk;FsUsbExDisk;c:\windows\system32\FsUsbExDisk.SYS [2009-04-07 36608]
S3 NETw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\NETw5v32.sys [2010-05-31 6638080]
S3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\DRIVERS\seehcri.sys [2008-01-09 27632]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys [2008-08-22 9344]
S3 TuneUpUtilitiesDrv;TuneUpUtilitiesDrv;c:\program files\TuneUp Utilities 2010\TuneUpUtilitiesDriver32.sys [2010-02-25 10064]
--- Other Services/Drivers In Memory ---
*Deregistered* - PCTSDInjDriver32
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
bthsvcs REG_MULTI_SZ BthServ
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
rsmsvcs REG_MULTI_SZ ntmssvc
ipripsvc REG_MULTI_SZ iprip
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{2796e0a1-30be-11de-afe0-806e6f6e6963}]
\shell\AutoRun\command - G:\N8800_SapphireArte.exe
.
Contents of the 'Scheduled Tasks' folder
2010-09-20 c:\windows\Tasks\AutoSmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-08-12 10:08]
2010-09-08 c:\windows\Tasks\FileCure Default.job
- c:\program files\ParetoLogic\FileCure\FileCure.exe [2010-03-28 19:47]
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-12 00:18]
2010-09-20 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-12 00:18]
2010-09-13 c:\windows\Tasks\ParetoLogic Registration3.job
- c:\program files\Common Files\ParetoLogic\UUS3\UUS3.dll [2009-08-04 18:19]
2010-09-11 c:\windows\Tasks\ParetoLogic Update Version3.job
- c:\program files\Common Files\ParetoLogic\UUS3\Pareto_Update3.exe [2009-08-04 18:19]
2010-09-08 c:\windows\Tasks\RegistryBooster.job
- c:\program files\Uniblue\RegistryBooster\rbmonitor.exe [2010-09-08 00:25]
2010-09-12 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2010-08-12 10:08]
2010-09-20 c:\windows\Tasks\User_Feed_Synchronization-{103B65BD-4798-4CA0-9487-EB211B637804}.job
- c:\windows\system32\msfeedssync.exe [2010-08-11 04:24]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://vaio-online.sony.com/
mStart Page = hxxp://vaio-online.sony.com/
uInternet Settings,ProxyServer = 192.168.1.18:80
uInternet Settings,ProxyOverride = *.local
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Send image to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
IE: {{B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - c:\users\Administrator\Desktop\PartyCasino\RunApp.exe
IE: {{d9288080-1baa-4bc4-9cf8-a92d743db949} - c:\users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IMVU\Run IMVU.lnk
FF - ProfilePath - c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\msq56u7x.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.yahoo.com/search?fr=ffsp1&p=
FF - prefs.js: browser.search.selectedEngine - Yahoo
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=ffds1&p=
FF - component: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\msq56u7x.default\extensions\
[email protected]\platform\WINNT_x86-msvc\components\WeaveCrypto.dll
FF - component: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\msq56u7x.default\extensions\
[email protected]\platform\WINNT_x86-msvc\components\lpxpcom.dll
FF - plugin: c:\program files\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: c:\program files\Google\Picasa3\npPicasa3.dll
FF - plugin: c:\program files\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\Microsoft\Office Live\npOLW.dll
FF - plugin: c:\program files\Sony\Media Go\npmediago.dll
FF - plugin: c:\program files\Tencent\QQMusic\npQzoneMusic.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: c:\users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\msq56u7x.default\extensions\
[email protected]\platform\WINNT_x86-msvc\plugins\npfax.dll
FF - plugin: c:\users\Administrator\AppData\Roaming\Mozilla\plugins\np-mswmp.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: network.http.max-persistent-connections-per-server - 4
FF - user.js: nglayout.initialpaint.delay - 600
FF - user.js: content.notify.interval - 600000
FF - user.js: content.max.tokenizing.time - 1800000
FF - user.js: content.switch.threshold - 600000
FF - user.js: browser.blink_allowed - true
FF - user.js: browser.xul.error_pages.enabled - true
FF - user.js: dom.disable_window_open_feature.resizable - true
FF - user.js: dom.disable_window_open_feature.location - false
FF - user.js: browser.tabs.tabMinWidth - 125
FF - user.js: browser.tabs.closeButtons - 1
FF - user.js: yahoo.ytff.general.dontshowhpoffer - truec:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgbaam7a8h", true);
c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.IDN.whitelist.xn--mgberp4a5d4ar", true);
c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
.
- - - - ORPHANS REMOVED - - - -
Toolbar-Locked - (no file)
WebBrowser-{D4027C7F-154A-4066-A1AD-4243D8127440} - (no file)
WebBrowser-{081230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file)
HKU-Default-Run-Nokia.PCSync - c:\users\Administrator\Desktop\Nokia PC Suite 6\PcSync2.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
GMER - Rootkit Detector and Remover
Rootkit scan 2010-09-21 05:37
Windows 6.0.6002 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\SampleCollector]
"ImagePath"="\"c:\program files\Sony\VAIO Care\collsvc.exe\" \"/service\" \"/counter=\Processor(_Total)\% Processor Time:5\" \"/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:5\" \"/counter=\Network Interface(*)\Bytes Total/sec:5\" \"/directory=inteldata\""
.
--------------------- LOCKED REGISTRY KEYS ---------------------
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,99,3f,aa,b2,c5,03,2e,44,99,fa,93,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,c1,6b,fc,62,db,04,8e,41,bb,4f,64,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,99,3f,aa,b2,c5,03,2e,44,99,fa,93,\
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.3fr\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.@db\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\SymIMIns.exe"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aif\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aifc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.aiff\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AIFF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.arw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.asx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.au\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.avi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.avi"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.BMP\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cda\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.CDA"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.cr2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.crw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dat\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\AcroRd32.exe"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dcr\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DIB\UserChoice]
@Denied: (2) (Administrator)
"Progid"="PhotoViewer.FileAssoc.Bitmap"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dng\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.DVR\UserChoice]
@Denied: (2) (Administrator)
"Progid"="MediaCenter.DVR"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.dvr-ms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="MediaCenter.DVR-MS"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.erf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.raw.14.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.GIF\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.htm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.html\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.HTM"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ICO\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.ico.14.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JFIF\UserChoice]
@Denied: (2) (Administrator)
"Progid"="PhotoViewer.FileAssoc.JFIF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPE\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPEG\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.JPG\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kdc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.loc\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\ARestore.exe"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m1v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.M2V\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.m3u\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.M3U"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.MHT"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mid\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.midi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.MOD\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp2v\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mp3\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MP3"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpa\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpe\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpeg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpg\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mpv2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MPEG"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.mrw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nef\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.nrw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.orf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pef\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.PNG\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.ptx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WindowsLive.PhotoGallery.raw.14.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rar\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Applications\\SymIMIns.exe"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.raw\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rmi\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.MIDI"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rw2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.shtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.snd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.AU"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.sr2\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.srf\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TGA\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIF\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.TIFF\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.url\UserChoice]
@Denied: (2) (Administrator)
"Progid"="IE.AssocFile.URL"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wav\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAV"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wax\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WAX"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wdp\UserChoice]
@Denied: (2) (Administrator)
"Progid"="PhotoViewer.FileAssoc.Wdp"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASF"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wma\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMA"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmd\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMD"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wms\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMS"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmv\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMV"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.ASX"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wmz\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WMZ"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wpl\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WPL"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.wvx\UserChoice]
@Denied: (2) (Administrator)
"Progid"="WMP11.AssocFile.WVX"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.x3f\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Google.PhotoViewer.3.0"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xht\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtm\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Opera.HTML"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xhtml\UserChoice]
@Denied: (2) (Administrator)
"Progid"="FirefoxHTML"
[HKEY_USERS\S-1-5-21-446587383-725776139-2801741393-500\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.xls\UserChoice]
@Denied: (2) (Administrator)
"Progid"="Excel.Sheet.8"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe,-101"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10i_ActiveX.exe"
[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
[HKEY_LOCAL_MACHINE\software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,99,3f,aa,b2,c5,03,2e,44,99,fa,93,\
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,99,3f,aa,b2,c5,03,2e,44,99,fa,93,\
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0008\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000001
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0009\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0010\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0011\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0012\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0013\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0014\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0017\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0018\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0021\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0022\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0023\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0024\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0025\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0027\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Completion time: 2010-09-21 05:42:31
ComboFix-quarantined-files.txt 2010-09-20 21:42
Pre-Run: 183,863,402,496 bytes free
Post-Run: 185,407,442,944 bytes free
- - End Of File - - 3E5C59478D2D7F5680A0F0A6B1CC864A