((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ASKService
-------\Legacy_ASKUpgrade
-------\Service_ASKService
-------\Service_ASKUpgrade
((((((((((((((((((((((((( Files Created from 2009-05-16 to 2009-06-16 )))))))))))))))))))))))))))))))
.
2009-06-16 05:18 . 2009-06-16 05:18 -------- d-sh--w- C:\found.000
2009-06-16 02:37 . 2009-06-16 02:37 -------- d-----w- c:\documents and settings\63\Application Data\Malwarebytes
2009-06-15 18:18 . 2009-05-26 17:20 40160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-06-15 18:18 . 2009-06-16 02:37 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-06-15 18:18 . 2009-06-15 18:18 -------- d-----w- c:\documents and settings\All Users\Application Data\Malwarebytes
2009-06-15 18:18 . 2009-05-26 17:19 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-06-15 16:32 . 2009-06-15 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\98727026
2009-06-15 16:32 . 2009-06-15 17:20 -------- d-----w- c:\documents and settings\All Users\Application Data\18717034
2009-06-12 21:50 . 2009-06-12 22:23 -------- d-----w- c:\documents and settings\63\Application Data\Command & Conquer 3 Tiberium Wars
2009-06-12 21:49 . 2009-06-12 21:49 98304 ----a-w- c:\windows\system32CmdLineExt.dll
2009-06-11 21:59 . 2009-06-11 22:00 -------- d-----w- c:\documents and settings\63\Application Data\Red Alert 3 Demo
2009-06-05 08:26 . 2009-06-05 08:26 -------- d--h--r- c:\documents and settings\63\Application Data\SecuROM
2009-06-05 08:26 . 2009-06-12 18:32 -------- d-----w- c:\documents and settings\All Users\Application Data\Electronic Arts
2009-06-05 08:26 . 2009-06-05 08:26 -------- d-----w- C:\ProgramData
2009-06-05 08:24 . 2009-06-05 08:24 10134 ----a-r- c:\documents and settings\63\Application Data\Microsoft\Installer\{E3E71D07-CD27-46CB-8448-16D4FB29AA13}\ARPPRODUCTICON.exe
2009-06-05 08:24 . 2008-11-09 01:21 447752 ----a-w- c:\windows\system32\vp6vfw.dll
2009-06-05 08:24 . 2009-06-05 08:24 -------- d-----w- c:\program files\Microsoft WSE
2009-06-05 01:34 . 2009-06-11 18:33 -------- d-----w- c:\documents and settings\63\Application Data\IGN_DLM
2009-06-04 23:58 . 2009-06-04 23:58 -------- d-----w- c:\documents and settings\63\Local Settings\Application Data\Electronic Arts
2009-06-04 23:39 . 2009-06-04 23:40 -------- d-----w- c:\program files\MediaMonkey
2009-06-04 21:46 . 2009-06-04 23:50 -------- d-----w- c:\program files\Incomplete
2009-06-04 20:20 . 2009-06-04 20:20 -------- d-----w- c:\documents and settings\63\Local Settings\Application Data\World in Conflict - DEMO
2009-05-22 08:42 . 2009-06-12 21:38 -------- d-----w- c:\program files\Electronic Arts
2009-05-21 07:15 . 2009-05-21 07:15 -------- d-----w- c:\documents and settings\63\Local Settings\Application Data\Funcom
2009-05-19 04:33 . 2009-05-19 04:33 -------- d-----w- c:\documents and settings\63\Local Settings\Application Data\PunkBuster
2009-05-19 04:15 . 2009-05-19 04:18 -------- d-----w- c:\windows\NV3940448.TMP
2009-05-19 03:38 . 2009-03-09 19:27 453456 ----a-w- c:\windows\system32\d3dx10_41.dll
2009-05-19 03:38 . 2009-03-09 19:27 4178264 ----a-w- c:\windows\system32\D3DX9_41.dll
2009-05-19 03:38 . 2009-03-09 19:27 1846632 ----a-w- c:\windows\system32\D3DCompiler_41.dll
2009-05-19 03:38 . 2009-03-16 18:18 69448 ----a-w- c:\windows\system32\XAPOFX1_3.dll
2009-05-19 03:38 . 2009-03-16 18:18 517448 ----a-w- c:\windows\system32\XAudio2_4.dll
2009-05-19 03:38 . 2009-03-16 18:18 235352 ----a-w- c:\windows\system32\xactengine3_4.dll
2009-05-19 03:38 . 2009-03-16 18:18 22360 ----a-w- c:\windows\system32\X3DAudio1_6.dll
2009-05-19 02:01 . 2009-05-19 02:01 -------- d-----w- c:\documents and settings\63\Local Settings\Application Data\Activision
2009-05-19 01:44 . 2009-05-28 03:49 -------- d-----w- c:\program files\Activision
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-06-16 03:50 . 2009-04-25 19:54 -------- d-----w- c:\program files\Steam
2009-06-16 00:14 . 2009-03-19 06:18 -------- d-----w- c:\program files\Trend Micro
2009-06-15 17:20 . 2009-03-08 05:07 -------- d-----w- c:\documents and settings\All Users\Application Data\avg8
2009-06-15 17:17 . 2005-11-10 19:28 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-05-21 02:11 . 2009-05-05 09:44 189496 ----a-w- c:\windows\system32\PnkBstrB.exe
2009-05-19 04:33 . 2009-05-05 05:06 75064 ----a-w- c:\windows\system32\PnkBstrA.exe
2009-05-19 01:59 . 2009-05-05 05:07 22328 ----a-w- c:\documents and settings\63\Application Data\PnkBstrK.sys
2009-05-19 01:59 . 2009-05-05 05:07 22328 ----a-w- c:\documents and settings\63\Application Data\PnkBstrK.sys
2009-05-16 19:24 . 2009-05-16 19:24 -------- d-----w- c:\program files\Windows Media Connect 2
2009-05-15 08:21 . 2009-05-15 08:21 201728 ----a-w- c:\windows\system32\[adult swim] neon light.scr
2009-05-15 05:43 . 2009-05-15 05:43 -------- d-----w- c:\program files\Common Files\Blizzard Entertainment
2009-05-15 05:43 . 2009-05-15 05:43 -------- d-----w- c:\program files\Google
2009-05-15 05:43 . 2009-05-15 05:43 -------- d-----w- c:\program files\ZSoft
2009-05-15 05:43 . 2009-05-15 05:43 -------- d-----w- c:\program files\Yahoo!
2009-05-15 05:43 . 2009-05-15 05:43 -------- d-----w- c:\program files\Three Rings Design
2009-05-15 05:32 . 2008-05-27 06:00 -------- d-----w- c:\documents and settings\63\Application Data\StumbleUpon
2009-05-13 06:32 . 2009-05-02 20:10 -------- d-----w- c:\program files\Microsoft Games for Windows - LIVE
2009-05-10 06:36 . 2008-04-18 17:11 13104 ----a-w- c:\documents and settings\63\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-08 19:07 . 2009-04-30 19:32 -------- d-----w- c:\program files\Common Files\Wise Installation Wizard
2009-05-07 15:32 . 2005-08-31 14:51 345600 ----a-w- c:\windows\system32\localspl.dll
2009-05-06 09:55 . 2009-05-06 09:55 -------- d-----w- c:\documents and settings\63\Application Data\The Creative Assembly
2009-05-02 20:18 . 2009-05-02 20:18 -------- d-----w- c:\program files\MSBuild
2009-05-02 20:18 . 2009-05-02 20:18 62304 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
2009-05-02 20:13 . 2009-05-02 20:13 -------- d-----w- c:\program files\Reference Assemblies
2009-05-02 17:28 . 2009-03-08 05:07 11952 ----a-w- c:\windows\system32\avgrsstx.dll
2009-05-02 17:28 . 2009-03-08 05:07 325896 ----a-w- c:\windows\system32\drivers\avgldx86.sys
2009-05-02 17:28 . 2009-03-08 05:07 27784 ----a-w- c:\windows\system32\drivers\avgmfx86.sys
2009-05-02 17:28 . 2009-03-08 05:07 108552 ----a-w- c:\windows\system32\drivers\avgtdix.sys
2009-05-01 20:01 . 2009-05-01 20:01 -------- d-----w- c:\program files\AGEIA Technologies
2009-05-01 19:58 . 2009-05-01 19:58 664 ----a-w- c:\windows\system32\d3d9caps.dat
2009-04-30 19:34 . 2008-04-25 01:16 -------- d-----w- c:\documents and settings\63\Application Data\Ventrilo
2009-04-29 04:56 . 2005-08-31 14:52 827392 ----a-w- c:\windows\system32\wininet.dll
2009-04-29 04:55 . 2009-03-26 18:12 78336 ----a-w- c:\windows\system32\ieencode.dll
2009-04-22 04:20 . 2009-04-22 04:20 14311680 ----a-w- c:\windows\system32\xlive.dll
2009-04-22 04:20 . 2009-04-22 04:20 13642496 ----a-w- c:\windows\system32\xlivefnt.dll
2009-04-17 12:26 . 2005-08-31 14:52 1847168 ----a-w- c:\windows\system32\win32k.sys
2009-04-15 14:51 . 2005-08-31 14:51 585216 ----a-w- c:\windows\system32\rpcrt4.dll
2009-03-27 12:14 . 2009-05-01 19:57 453152 ----a-w- c:\windows\system32\nvuninst.exe
2009-03-19 08:41 . 2009-03-19 08:41 0 -c--a-w- c:\windows\nsreg.dat
.
(((((((((((((((((((((((((((((
SnapShot@2009-06-16_02.18.33 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-06-16 05:11 . 2009-06-16 05:11 389120 c:\windows\system32\CF17612.exe
+ 2009-06-16 05:06 . 2009-06-16 05:06 262144 c:\windows\assembly\NativeImages_v2.0.50727_32\sysglobl\
06cd76a12ea77cd8970e8656d56b7ca1\sysglobl.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 548864 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\f06ebb12e5c56642e954d1463e445deb\PresentationFramework.Luna.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 393216 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\9b48bb7ecb43b4a5ef94d2d72ef40ae2\PresentationFramework.Aero.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 241664 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\36dc8c2c9445aeeccd5ea7151a9ec0b4\PresentationFramework.Classic.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 270336 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\119803efd068b21ef3f7514709344347\PresentationFramework.Royale.ni.dll
+ 2009-06-16 05:06 . 2009-06-16 05:06 2306048 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\fb6b930a82241b8225e3fef4270f45d1\System.Web.Mobile.ni.dll
+ 2009-06-16 05:06 . 2009-06-16 05:06 2031616 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Speech\42a7fa124b7e36d9526db4abcf639425\System.Speech.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 1118208 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Printing\2d7ad3127512db61941682c3b2e29f98\System.Printing.ni.dll
+ 2009-06-16 05:05 . 2009-06-16 05:05 2396160 c:\windows\assembly\NativeImages_v2.0.50727_32\ReachFramework\1b1314af0ff7ab9c24d24edc0210c1f5\ReachFramework.ni.dll
+ 2009-06-16 03:49 . 2009-06-16 03:49 1982464 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationUI\f20e7e2fcbd3b19605b7898c483c8a12\PresentationUI.ni.dll
+ 2009-06-16 02:19 . 2009-06-16 02:19 1568768 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationBuildTa#\1620e3706790a642192e46dec3f9ee80\PresentationBuildTasks.ni.dll
+ 2009-06-16 02:19 . 2009-06-16 02:19 1720320 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\af58828489f52407c691608baed905ac\Microsoft.VisualBasic.ni.dll
+ 2009-06-16 03:49 . 2009-06-16 03:49 14680064 c:\windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\a4a686abd38ad3d931b0e798692fa811\PresentationFramework.ni.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"Steam"="c:\program files\steam\steam.exe" [2009-06-10 1217784]
"EA Core"="c:\program files\Electronic Arts\EADM\Core.exe" [2009-04-29 3338240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2008-11-04 413696]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-05-02 1947928]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-15 135168]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-15 159744]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-15 131072]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-03-28 13684736]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-03-28 86016]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2009-03-28 1657376]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34 24576 ----a-w- c:\program files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]
2009-05-02 17:28 11952 ----a-w- c:\windows\system32\avgrsstx.dll
[HKLM\~\startupfolder\C:^Documents and Settings^63^Start Menu^Programs^Startup^FrostWire On Startup.lnk]
path=c:\documents and settings\63\Start Menu\Programs\Startup\FrostWire On Startup.lnk
backup=c:\windows\pss\FrostWire On Startup.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\Steam\\steamapps\\sargentpepper06\\team fortress 2\\hl2.exe"=
"c:\\Program Files\\Steam\\Steam.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Steam\\steamapps\\sargentpepper06\\day of defeat source\\hl2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicDownloader\\RelicDownloader.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dawn of war 2\\DOW2.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\dead space\\Dead Space.exe"=
"c:\\Program Files\\Electronic Arts\\EADM\\Core.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\RelicCOH.exe"=
"c:\\Program Files\\Steam\\steamapps\\common\\company of heroes\\help.htm"=
"c:\\Program Files\\Steam\\steamapps\\common\\left 4 dead\\left4dead.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724