.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-13 23:39 . 2009-04-17 01:57 -------- d---a-w- c:\documents and settings\All Users\Application Data\TEMP
2009-06-13 23:14 . 2004-08-10 04:00 182912 ----a-w- c:\windows\system32\drivers\ndis.sys
2009-06-11 21:40 . 2006-11-17 03:24 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-06-08 20:00 . 2009-04-24 05:47 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\LimeWire
2009-06-07 09:57 . 2009-04-07 23:34 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Apple Computer
2009-06-07 00:23 . 2009-04-10 09:40 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Ventrilo
2009-06-02 19:09 . 2009-04-17 01:57 -------- d-----w- c:\program files\Spyware Doctor
2009-06-02 07:34 . 2009-04-07 23:33 -------- d-----w- c:\program files\iTunes
2009-06-02 07:34 . 2009-04-07 23:32 -------- d-----w- c:\program files\Common Files\Apple
2009-06-02 07:32 . 2009-04-07 23:33 -------- d-----w- c:\program files\QuickTime
2009-05-29 20:36 . 2009-04-07 23:32 39424 ----a-w- c:\windows\system32\drivers\usbaapl.sys
2009-05-29 20:36 . 2009-04-07 23:32 2060288 ----a-w- c:\windows\system32\usbaaplrc.dll
2009-05-20 06:45 . 2006-11-17 03:29 -------- d-----w- c:\program files\Common Files\Adobe
2009-05-20 04:33 . 2006-11-17 03:22 119976 ----a-w- c:\documents and settings\Administrator\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-09 21:00 . 2009-05-09 21:00 -------- d-----w- c:\program files\AutoIt3
2009-05-08 13:59 . 2009-05-08 13:59 -------- d-----w- c:\program files\AhnLab
2009-05-07 20:53 . 2009-05-06 07:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Logishrd
2009-05-07 06:40 . 2009-05-07 06:33 -------- d-----w- c:\documents and settings\All Users\Application Data\Microsoft Help
2009-05-07 06:36 . 2006-11-17 03:26 -------- d-----w- c:\program files\Microsoft Works
2009-05-07 06:36 . 2009-05-07 06:36 -------- d-----w- c:\program files\MSBuild
2009-05-07 06:35 . 2009-05-07 06:35 -------- d-----w- c:\program files\Microsoft.NET
2009-05-06 07:08 . 2009-05-06 07:06 -------- d-----w- c:\program files\Common Files\LogiShrd
2009-05-06 07:07 . 2009-05-06 07:07 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Leadertech
2009-05-06 07:06 . 2009-05-06 07:06 -------- d-----w- c:\documents and settings\All Users\Application Data\Logitech
2009-05-06 07:06 . 2009-05-06 07:06 -------- d-----w- c:\program files\Logitech
2009-05-05 21:48 . 2009-05-05 21:48 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\teamspeak2
2009-05-05 21:48 . 2009-05-05 21:48 -------- d-----w- c:\program files\Teamspeak2_RC2
2009-05-02 01:02 . 2009-05-02 01:02 -------- d-----w- c:\program files\Windows Journal Viewer
2009-04-24 05:35 . 2009-04-24 05:35 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-04-24 05:35 . 2006-11-17 02:53 -------- d-----w- c:\program files\Java
2009-04-24 05:35 . 2009-04-24 05:35 152576 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Sun\Java\jre1.6.0_11\lzma.dll
2009-04-23 04:14 . 2009-04-08 07:32 -------- d-----w- c:\program files\Conduit
2009-04-23 04:13 . 2006-11-17 03:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo! Companion
2009-04-23 04:06 . 2009-01-23 04:06 47616 --sha-w- c:\windows\system32\sogasuba.exe
2009-04-22 05:15 . 2009-04-22 05:03 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\HP
2009-04-22 05:14 . 2009-04-22 05:03 112954 ----a-w- c:\windows\hpoins07.dat
2009-04-22 05:13 . 2009-04-22 05:13 -------- d-----w- c:\documents and settings\All Users\Application Data\HP
2009-04-22 05:13 . 2006-11-17 03:12 -------- d-----w- c:\program files\HP
2009-04-22 05:12 . 2006-11-17 03:24 -------- d-----w- c:\program files\Hewlett-Packard
2009-04-22 05:11 . 2009-04-22 05:11 -------- d-----w- c:\program files\Common Files\Hewlett-Packard
2009-04-21 23:24 . 2009-04-21 23:24 64160 ----a-w- c:\documents and settings\All Users\Application Data\Lavasoft\Ad-Aware\Update\Drivers\32\lbd.sys
2009-04-21 23:24 . 2009-04-07 23:24 64160 ----a-w- c:\windows\system32\drivers\Lbd.sys
2009-04-21 00:38 . 2009-04-21 00:36 -------- d-----w- c:\documents and settings\All Users\Application Data\Yahoo!
2009-04-21 00:37 . 2009-04-21 00:37 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Yahoo!
2009-04-21 00:37 . 2009-04-21 00:37 823 ----a-w- c:\program files\Yahoo! Messenger.lnk
2009-04-21 00:36 . 2006-11-17 03:41 -------- d-----w- c:\program files\Yahoo!
2009-04-21 00:17 . 2009-04-21 00:17 438592 ----a-w- c:\program files\msgr9us.exe
2009-04-20 06:45 . 2009-04-17 02:05 130936 ----a-w- c:\windows\system32\drivers\PCTCore.sys
2009-04-19 20:14 . 2006-11-17 03:19 -------- d-----w- c:\program files\HP Games
2009-04-19 20:14 . 2006-11-17 03:19 -------- d-----w- c:\program files\WildTangent
2009-04-19 20:14 . 2006-11-17 03:19 -------- d-----w- c:\documents and settings\All Users\Application Data\WildTangent
2009-04-19 10:05 . 2009-04-19 10:05 -------- d-----w- c:\program files\Microsoft CAPICOM 2.1.0.2
2009-04-19 10:01 . 2009-04-19 10:01 -------- d-----w- c:\program files\MSXML 4.0
2009-04-19 08:43 . 2009-04-19 08:43 -------- d-----w- c:\program files\JAP
2009-04-18 01:04 . 2009-04-18 01:04 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Malwarebytes
2009-04-18 00:15 . 2009-04-18 00:14 52770576 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Sony Setup\64993CD0-67D1-4244-A2BC-FD73F4DA5B62\dotnetfx3.exe
2009-04-17 23:40 . 2009-04-08 02:15 -------- d-----w- c:\program files\Last.fm
2009-04-17 23:13 . 2009-04-17 23:13 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-04-17 23:13 . 2009-04-17 23:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-04-17 02:47 . 2009-04-17 02:47 -------- d-----w- c:\program files\Trend Micro
2009-04-17 02:44 . 2009-04-17 02:33 -------- d-----w- c:\program files\True Sword 5
2009-04-17 02:33 . 2009-04-17 02:33 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\True Sword
2009-04-17 02:20 . 2009-04-17 01:57 -------- d-----w- c:\program files\Common Files\PC Tools
2009-04-17 01:57 . 2009-04-17 01:57 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\PC Tools
2009-04-17 01:57 . 2009-04-17 01:57 -------- d-----w- c:\documents and settings\All Users\Application Data\PC Tools
2009-04-17 01:57 . 2009-04-17 01:55 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\GetRightToGo
2009-04-16 08:28 . 2009-04-16 08:28 -------- d-----w- c:\documents and settings\HP_Administrator\Application Data\Sony Setup
2009-04-16 08:27 . 2009-04-16 08:27 -------- d-----w- c:\program files\Sony Setup
2009-04-08 22:35 . 2009-04-07 23:14 139 ----a-w- c:\documents and settings\HP_Administrator\Local Settings\Application Data\fusioncache.dat
2009-04-08 02:16 . 2009-04-08 02:16 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstWMP\unins000.exe
2009-04-08 02:16 . 2009-04-08 02:16 184 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\uninst2.bat
2009-04-08 02:16 . 2009-04-08 02:16 683801 ----a-w- c:\documents and settings\All Users\Application Data\Last.fm\Client\UninstITW\unins000.exe
2009-04-07 23:23 . 2009-04-07 23:23 167376 ----a-w- c:\documents and settings\HP_Administrator\Application Data\Mozilla\Firefox\Profiles\8kzs7j02.default\FlashGot.exe
2009-04-07 23:20 . 2009-04-07 23:20 0 ----a-w- c:\windows\nsreg.dat
2009-04-06 22:32 . 2009-04-17 23:13 38496 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-04-06 22:32 . 2009-04-17 23:13 15504 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-03-19 23:32 . 2009-04-07 23:34 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-19 23:32 . 2009-03-19 23:32 23400 ----a-w- c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 00:55 . 2009-04-21 00:36 607472 ----a-w- c:\documents and settings\All Users\Application Data\Yahoo!\YUpdater\yupdater.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AIM (R)"="c:\program files\AIM95\aim.exe" [2002-07-26 57344]
"RegistryMechanic"="c:\program files\Registry Mechanic\RegMech.exe" [2008-07-09 2828184]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-02-07 3885408]
"Messenger (Yahoo!)"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2009-03-19 4363504]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2009-04-23 691656]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="c:\windows\ehome\ehtray.exe" [2005-09-30 67584]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2006-05-09 7311360]
"DMAScheduler"="c:\program files\HP DigitalMedia Archive\DMAScheduler.exe" [2006-04-13 90112]
"HPBootOp"="c:\program files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" [2006-02-16 249856]
"Ad-Watch"="c:\program files\Lavasoft\Ad-Aware\AAWTray.exe" [2009-05-26 518488]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"LogitechCommunicationsManager"="c:\program files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe" [2008-08-15 565008]
"LogitechQuickCamRibbon"="c:\program files\Logitech\QuickCam\Quickcam.exe" [2008-08-15 2407184]
"AdobeCS4ServiceManager"="c:\program files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2009-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-05-30 292136]
"phime2002async"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-09 455168]
"phime2002a"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-09 455168]
"mspy2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-09 59392]
"imjpmig8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-09 208952]
"MSConfig"="c:\windows\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2005-09-27 169984]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2006-05-09 1519616]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2005-5-11 282624]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Updates from HP\\9972322\\Program\\Updates from HP.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\AIM95\\aim.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqscnvw.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqCopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpfccopy.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqPhUnl.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\Unload\\HpqDIA.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpoews01.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"c:\\Program Files\\mIRC\\mirc.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\GlobalSCAPE\\CuteFTP 8 Professional\\ftpte.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"53:UDP"= 53:UDP:Promo
R0 Lbd;Lbd;c:\windows\system32\drivers\Lbd.sys [4/7/2009 4:24 PM 64160]
R0 PCTCore;PCTools KDS;c:\windows\system32\drivers\PCTCore.sys [4/16/2009 7:05 PM 130936]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 12:06 PM 1005904]
S3 CXFALCON;Conexant Falcon II NTSC Video Capture;c:\windows\system32\drivers\cxfalcon.sys [11/16/2006 8:09 PM 82048]
S3 sdAuxService;PC Tools Auxiliary Service;c:\program files\Spyware Doctor\pctsAuxs.exe [4/16/2009 6:57 PM 348752]
S3 XDva225;XDva225;\??\c:\windows\system32\XDva225.sys --> c:\windows\system32\XDva225.sys [?]
.
Contents of the 'Scheduled Tasks' folder
2009-06-09 c:\windows\Tasks\Ad-Aware Update (Weekly).job
- c:\program files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 23:24]
.
- - - - ORPHANS REMOVED - - - -
BHO-{7c5c0f58-e061-457d-9033-77307f5ed00c} - (no file)
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://www.daemon-search.com/startpageuDefault_Search_URL =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktopmStart Page =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktopmSearch Bar =
hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktopuInternet Settings,ProxyOverride = *.local;
uInternet Settings,ProxyServer = http=localhost:7171
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
FF - ProfilePath -