.
((((((((((((((((((((((((( Files Created from 2009-05-06 to 2009-06-06 )))))))))))))))))))))))))))))))
.
2009-06-06 03:48 . 2009-06-06 03:48 -------- d-sh--w- \$RECYCLE.BIN
2009-06-06 03:47 . 2009-06-06 03:48 -------- d-----w- c:\users\Michael\AppData\Local\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- C:\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- \temp
2009-06-06 03:42 . 2009-06-06 03:48 -------- d-s---w- \combofixz
2009-06-06 03:01 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\naveng.sys
2009-06-06 03:01 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\navex15.sys
2009-06-06 03:01 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\eeCtrl.sys
2009-06-06 03:01 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\naveng32.dll
2009-06-06 03:01 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\navex32a.dll
2009-06-06 03:01 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\ERASER.sys
2009-06-06 03:01 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\ecmsvr32.dll
2009-06-06 03:01 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\cceraser.dll
2009-06-06 00:22 . 2009-06-06 03:43 -------- d-----w- \Qoobox
2009-06-06 00:20 . 2009-06-05 09:07 1342 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\tmp581b.tmp\cur.scr
2009-06-05 23:54 . 2009-06-05 23:54 -------- d-----w- c:\program files\TokBox
2009-06-03 04:22 . 2009-06-03 04:24 -------- d-----w- \Avenger
2009-06-03 00:56 . 2009-06-03 00:56 -------- d-----w- c:\program files\Trend Micro
2009-05-16 03:05 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\naveng.sys
2009-05-16 03:05 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\navex15.sys
2009-05-16 03:05 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\naveng32.dll
2009-05-16 03:05 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\navex32a.dll
2009-05-16 03:05 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\eeCtrl.sys
2009-05-16 03:05 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\cceraser.dll
2009-05-16 03:05 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\ERASER.sys
2009-05-16 03:05 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\ecmsvr32.dll
2009-05-08 03:56 . 2009-03-19 23:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-08 03:56 . 2008-04-17 19:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\program files\iPod
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\program files\iTunes
2009-05-08 03:55 . 2009-05-08 03:55 -------- d-----w- c:\program files\Bonjour
2009-05-08 03:54 . 2009-05-08 03:54 -------- d-----w- c:\program files\QuickTime
2009-05-08 03:45 . 2009-05-08 03:45 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 03:47 . 2007-04-12 11:58 2392719360 --sha-w- \pagefile.sys
2009-06-06 00:26 . 2008-02-23 07:23 -------- d-----w- c:\program files\Norton Security Scan
2009-06-06 00:26 . 2007-04-29 06:38 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-05 05:26 . 2007-12-15 02:48 -------- d-----w- c:\program files\Warcraft III
2009-06-05 03:39 . 2008-09-27 19:27 -------- d-----w- c:\program files\Garena
2009-05-27 03:25 . 2007-06-26 21:44 -------- d-----w- c:\program files\Steam
2009-05-22 05:19 . 2008-08-28 02:32 -------- d-----w- c:\users\Michael\AppData\Roaming\FrostWire
2009-05-08 03:56 . 2007-09-18 07:10 -------- d-----w- c:\program files\Common Files\Apple
2009-04-25 05:22 . 2009-04-24 01:08 -------- d-----w- c:\programdata\NOS
2009-04-25 05:22 . 2009-04-24 01:08 -------- d-----w- c:\program files\NOS
2009-04-24 01:16 . 2009-04-24 01:15 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-19 18:18 . 2007-09-14 22:26 -------- d-----w- c:\program files\Common Files\Steam
2009-04-12 21:49 . 2009-04-12 21:48 34 ----a-w- c:\users\Michael\jagex_runescape_preferences.dat
2009-04-07 22:01 . 2009-04-07 03:44 77055 ----a-w- c:\windows\War3Unin.dat
2009-04-07 03:47 . 2009-04-07 03:44 2829 ----a-w- c:\windows\War3Unin.pif
2009-04-07 03:47 . 2009-04-07 03:44 139264 ----a-w- c:\windows\War3Unin.exe
2009-03-26 22:23 . 2009-03-26 22:23 36864 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-26 22:23 . 2009-03-26 22:23 1900544 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 ----a-w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-16 08:00 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-03-16 08:00 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-03-16 08:00 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-03-16 08:00 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-03-16 08:00 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-03-16 08:00 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-03-16 08:00 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-03-14 05:07 . 2009-03-14 05:07 15440 ----a-w- c:\windows\system32\drivers\hamachi.sys
2008-07-07 03:14 . 2008-07-07 03:14 8 --sha-r- c:\windows\System32\B80BE66F79.sys
2008-07-07 04:11 . 2008-07-07 03:14 2516 --sha-w- c:\windows\System32\KGyGaAvL.sys
2007-04-12 19:56 . 2007-04-12 19:55 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-06_00.44.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-04-12 12:35 . 2009-06-06 03:34 55808 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-04-15 01:44 . 2009-06-06 03:34 14770 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3350525115-1583221867-2151667216-1000_UserData.bin
- 2007-04-15 01:35 . 2009-06-05 23:56 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-04-15 01:35 . 2009-06-05 23:56 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-04-15 01:35 . 2009-06-05 23:56 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:05 . 2009-06-06 03:39 134934 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-12 273864]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-01-17 486856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2006-11-02 2159104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-08 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-08 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-08 81920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-15 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-15 2407184]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_16\bin\jusched.exe" [2008-05-28 75256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-02-08 303104]
c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TokBox.lnk - c:\program files\TokBox\TokBox.exe [2009-6-5 95744]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-4-12 45056]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-12 67128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders credssp.dll, digeste.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
((((((((((((((((((((((((( Files Created from 2009-05-06 to 2009-06-06 )))))))))))))))))))))))))))))))
.
2009-06-06 03:48 . 2009-06-06 03:48 -------- d-sh--w- \$RECYCLE.BIN
2009-06-06 03:47 . 2009-06-06 03:48 -------- d-----w- c:\users\Michael\AppData\Local\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- c:\users\Guest\AppData\Local\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- C:\temp
2009-06-06 03:47 . 2009-06-06 03:47 -------- d-----w- \temp
2009-06-06 03:42 . 2009-06-06 03:48 -------- d-s---w- \combofixz
2009-06-06 03:01 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\naveng.sys
2009-06-06 03:01 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\navex15.sys
2009-06-06 03:01 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\eeCtrl.sys
2009-06-06 03:01 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\naveng32.dll
2009-06-06 03:01 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\navex32a.dll
2009-06-06 03:01 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\ERASER.sys
2009-06-06 03:01 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\ecmsvr32.dll
2009-06-06 03:01 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090605.003\cceraser.dll
2009-06-06 00:22 . 2009-06-06 03:43 -------- d-----w- \Qoobox
2009-06-06 00:20 . 2009-06-05 09:07 1342 ----a-w- c:\programdata\Symantec\Definitions\SymcData\virusdefs-2.5-e\tmp581b.tmp\cur.scr
2009-06-05 23:54 . 2009-06-05 23:54 -------- d-----w- c:\program files\TokBox
2009-06-03 04:22 . 2009-06-03 04:24 -------- d-----w- \Avenger
2009-06-03 00:56 . 2009-06-03 00:56 -------- d-----w- c:\program files\Trend Micro
2009-05-16 03:05 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\naveng.sys
2009-05-16 03:05 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\navex15.sys
2009-05-16 03:05 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\naveng32.dll
2009-05-16 03:05 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\navex32a.dll
2009-05-16 03:05 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\eeCtrl.sys
2009-05-16 03:05 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\cceraser.dll
2009-05-16 03:05 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\ERASER.sys
2009-05-16 03:05 . 2008-11-20 09:00 259368 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\20090515.003\ecmsvr32.dll
2009-05-08 03:56 . 2009-03-19 23:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-05-08 03:56 . 2008-04-17 19:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\program files\iPod
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-08 03:56 . 2009-05-08 03:56 -------- d-----w- c:\program files\iTunes
2009-05-08 03:55 . 2009-05-08 03:55 -------- d-----w- c:\program files\Bonjour
2009-05-08 03:54 . 2009-05-08 03:54 -------- d-----w- c:\program files\QuickTime
2009-05-08 03:45 . 2009-05-08 03:45 75048 ----a-w- c:\programdata\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-06 03:47 . 2007-04-12 11:58 2392719360 --sha-w- \pagefile.sys
2009-06-06 00:26 . 2008-02-23 07:23 -------- d-----w- c:\program files\Norton Security Scan
2009-06-06 00:26 . 2007-04-29 06:38 -------- d-----w- c:\program files\Common Files\Symantec Shared
2009-06-05 05:26 . 2007-12-15 02:48 -------- d-----w- c:\program files\Warcraft III
2009-06-05 03:39 . 2008-09-27 19:27 -------- d-----w- c:\program files\Garena
2009-05-27 03:25 . 2007-06-26 21:44 -------- d-----w- c:\program files\Steam
2009-05-22 05:19 . 2008-08-28 02:32 -------- d-----w- c:\users\Michael\AppData\Roaming\FrostWire
2009-05-08 03:56 . 2007-09-18 07:10 -------- d-----w- c:\program files\Common Files\Apple
2009-04-25 05:22 . 2009-04-24 01:08 -------- d-----w- c:\programdata\NOS
2009-04-25 05:22 . 2009-04-24 01:08 -------- d-----w- c:\program files\NOS
2009-04-24 01:16 . 2009-04-24 01:15 -------- d-----w- c:\program files\Common Files\Adobe
2009-04-19 18:18 . 2007-09-14 22:26 -------- d-----w- c:\program files\Common Files\Steam
2009-04-12 21:49 . 2009-04-12 21:48 34 ----a-w- c:\users\Michael\jagex_runescape_preferences.dat
2009-04-07 22:01 . 2009-04-07 03:44 77055 ----a-w- c:\windows\War3Unin.dat
2009-04-07 03:47 . 2009-04-07 03:44 2829 ----a-w- c:\windows\War3Unin.pif
2009-04-07 03:47 . 2009-04-07 03:44 139264 ----a-w- c:\windows\War3Unin.exe
2009-03-26 22:23 . 2009-03-26 22:23 36864 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-03-26 22:23 . 2009-03-26 22:23 1900544 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-03-19 23:32 . 2009-03-19 23:32 23400 ----a-w- c:\programdata\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-16 08:00 . 2009-03-16 08:00 89104 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng.sys
2009-03-16 08:00 . 2009-03-16 08:00 876144 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex15.sys
2009-03-16 08:00 . 2009-03-16 08:00 371248 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\eeCtrl.sys
2009-03-16 08:00 . 2009-03-16 08:00 2414128 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\cceraser.dll
2009-03-16 08:00 . 2009-03-16 08:00 177520 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\naveng32.dll
2009-03-16 08:00 . 2009-03-16 08:00 1181040 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\navex32a.dll
2009-03-16 08:00 . 2009-03-16 08:00 101936 ----a-w- c:\programdata\Symantec\Definitions\VirusDefs\BinHub\ERASER.sys
2009-03-14 05:07 . 2009-03-14 05:07 15440 ----a-w- c:\windows\system32\drivers\hamachi.sys
2008-07-07 03:14 . 2008-07-07 03:14 8 --sha-r- c:\windows\System32\B80BE66F79.sys
2008-07-07 04:11 . 2008-07-07 03:14 2516 --sha-w- c:\windows\System32\KGyGaAvL.sys
2007-04-12 19:56 . 2007-04-12 19:55 8192 --sha-w- c:\windows\Users\Default\NTUSER.DAT
.
((((((((((((((((((((((((((((( SnapShot@2009-06-06_00.44.07 )))))))))))))))))))))))))))))))))))))))))
.
+ 2007-04-12 12:35 . 2009-06-06 03:34 55808 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2007-04-15 01:44 . 2009-06-06 03:34 14770 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-3350525115-1583221867-2151667216-1000_UserData.bin
- 2007-04-15 01:35 . 2009-06-05 23:56 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 32768 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2007-04-15 01:35 . 2009-06-05 23:56 49152 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2007-04-15 01:35 . 2009-06-06 03:42 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2007-04-15 01:35 . 2009-06-05 23:56 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2006-11-02 13:05 . 2009-06-06 03:39 134934 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2008-01-09 1232896]
"DAEMON Tools Pro Agent"="c:\program files\DAEMON Tools Pro\DTProAgent.exe" [2007-12-12 273864]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-01-17 486856]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 201728]
"WindowsWelcomeCenter"="oobefldr.dll" - c:\windows\System32\oobefldr.dll [2006-11-02 2159104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2006-12-08 90191]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-12-08 7766016]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2006-12-08 81920]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"ECenter"="c:\dell\E-Center\EULALauncher.exe" [2006-11-17 17920]
"ISUSPM Startup"="c:\progra~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe" [2006-10-03 221184]
"ccApp"="c:\program files\Common Files\Symantec Shared\ccApp.exe" [2007-01-10 115816]
"vptray"="c:\progra~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-15 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-15 2407184]
"SunJavaUpdateSched"="c:\program files\Java\jre1.5.0_16\bin\jusched.exe" [2008-05-28 75256]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-02-28 35696]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SigmatelSysTrayApp"="sttray.exe" - c:\windows\sttray.exe [2007-02-08 303104]
c:\users\Michael\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
TokBox.lnk - c:\program files\TokBox\TokBox.exe [2009-6-5 95744]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Digital Line Detect.lnk - c:\program files\Digital Line Detect\DLG.exe [2007-4-12 45056]
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe [2008-11-12 67128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"mixer"=wdmaud.drv
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
SecurityProviders credssp.dll, digeste.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001