c:\program files\zango\bin\10.3.79.0\Toolbar.dll
c:\program files\zango\bin\10.3.79.0\Weather.exe
c:\program files\zango\bin\10.3.79.0\WeSkin.dll
c:\program files\zango\bin\10.3.79.0\ZangoSA.exe
c:\program files\zango\bin\10.3.79.0\ZangoSAAX.dll
c:\program files\zango\bin\10.3.79.0\ZangoSADF.exe
c:\program files\zango\bin\10.3.79.0\ZangoSAHook.dll
c:\windows\COUPON~1.OCX
c:\windows\CouponPrinter.ocx
c:\windows\Downloaded Program Files\PurpleBean.exe
c:\windows\Installer\a8420de.msi
c:\windows\Installer\c0d44.msi
c:\windows\Installer\c0dd5.msi
c:\windows\MailSwitch.ocx
c:\windows\system32\drivers\gxvxcyxvlfsmaowkhbnymoqurfhlcedrwxomj.sys
c:\windows\system32\gxvxccounter
c:\windows\system32\gxvxcvsebndpxpaqahptlnljhygklwaornnus.dll
c:\windows\system32\iAlmcoin.dll
D:\Autorun.inf
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Service_gxvxcserv.sys
((((((((((((((((((((((((( Files Created from 2009-07-03 to 2009-08-03 )))))))))))))))))))))))))))))))
.
2009-08-01 20:27 . 2009-08-01 20:27 -------- d-----w- c:\program files\Trend Micro
2009-07-31 20:49 . 2009-06-22 14:58 24576 ----a-w- c:\windows\system32\drivers\ndisrd.sys
2009-07-31 20:49 . 2009-05-14 09:58 61440 ----a-w- c:\windows\system32\ndisapi.dll
2009-07-31 18:52 . 2009-07-31 22:56 -------- d-----w- c:\program files\Common Files\Uninstall
2009-07-31 18:51 . 2009-07-31 22:43 -------- dc----w- c:\program files\PersonalAV
2009-07-18 20:43 . 2009-07-18 20:43 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\SCE
2009-07-18 15:00 . 2009-07-18 15:00 80384 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{CC4C261A-B915-4F23-BD23-7E1AE5713B4E}\Icon6FDEE4821.exe
2009-07-18 14:55 . 2009-07-18 14:55 -------- d-----w- c:\windows\CC4C261AB9154F23BD237E1AE5713B4E.TMP
2009-07-18 01:29 . 2009-07-18 01:30 -------- d-----w- c:\documents and settings\Owner\Local Settings\Application Data\Unity
2009-07-18 01:29 . 2009-07-18 01:29 -------- d-----w- c:\program files\Unity
2009-07-17 19:15 . 2008-05-01 02:28 1654869 ----a-w- c:\documents and settings\All Users\Application Data\DynuEncrypt.dll
2009-07-17 01:34 . 2009-07-17 19:11 1123994715 ----a-w- c:\documents and settings\Owner\Application Data\ijjigame\U_LUNIA_setup.exe
2009-07-17 01:33 . 2009-07-17 01:50 -------- d-----w- c:\documents and settings\Owner\Application Data\ijjigame
2009-07-17 01:33 . 2009-07-17 01:33 -------- d-----w- C:\ijji
2009-07-07 22:07 . 2009-07-07 22:07 -------- d-----w- c:\program files\GALA-NET
2009-07-07 03:35 . 2009-07-07 03:35 971544 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\6500\install\d3dx9_31.dll
2009-07-07 03:35 . 2009-07-07 03:35 34512 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\6500\install\xinput9_1_0.dll
2009-07-07 03:35 . 2009-07-07 03:35 335360 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\6500\install\fmodex.dll
2009-07-07 03:35 . 2009-07-07 03:35 1457160 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\6500\install\d3dx9_36.dll
2009-07-07 03:35 . 2009-07-07 03:35 2043392 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\6500\install\Lore.exe
2009-07-07 03:22 . 2009-07-07 03:22 4919296 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\Legions.exe
2009-07-07 03:22 . 2009-07-07 03:22 3727720 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\d3dx9_35.dll
2009-07-07 03:22 . 2009-07-07 03:22 369664 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\products\www_instantaction_com\102\install\fmodex.dll
2009-07-07 02:49 . 2009-05-20 20:46 685376 ----a-w- c:\documents and settings\Owner\Application Data\GarageGames\IAPlayer\iaplugin.dll
2009-07-07 02:49 . 2009-07-07 02:49 -------- d-----w- c:\documents and settings\Owner\Application Data\GarageGames
2009-07-07 02:29 . 2009-07-07 02:42 -------- d-----w- c:\documents and settings\Owner\Application Data\Splitscreen Studios
2009-07-06 22:33 . 2009-07-06 22:33 -------- d-----w- c:\program files\Common Files\DirectX
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-08-03 23:14 . 2009-06-01 16:26 1494560 --sha-w- c:\windows\system32\drivers\fidbox.dat
2009-08-03 22:20 . 2009-06-01 16:26 3596 --sha-w- c:\windows\system32\drivers\fidbox2.idx
2009-08-03 22:20 . 2009-06-01 16:26 18740 --sha-w- c:\windows\system32\drivers\fidbox.idx
2009-08-03 22:20 . 2009-06-01 16:26 133152 --sha-w- c:\windows\system32\drivers\fidbox2.dat
2009-08-03 17:26 . 2009-06-11 13:21 -------- d-----w- c:\documents and settings\Owner\Application Data\DNA
2009-08-03 17:06 . 2009-06-11 13:21 -------- d-----w- c:\program files\DNA
2009-07-25 15:35 . 2003-02-20 18:17 -------- d--h--w- c:\program files\InstallShield Installation Information
2009-07-24 19:01 . 2009-04-12 22:17 34 ----a-w- c:\documents and settings\Owner\jagex_runescape_preferences.dat
2009-07-02 03:55 . 2009-06-06 16:53 -------- d-----w- c:\program files\GameSpy Arcade
2009-07-02 02:39 . 2009-07-02 02:39 -------- d-----w- c:\program files\OpenAL
2009-07-02 02:39 . 2009-07-02 02:39 413696 ----a-w- c:\windows\system32\wrap_oal.dll
2009-07-02 02:39 . 2009-07-02 02:39 86016 ----a-w- c:\windows\system32\OpenAL32.dll
2009-06-27 04:29 . 2009-06-27 03:12 256 ----a-w- c:\windows\system32\pool.bin
2009-06-27 03:12 . 2009-06-27 03:12 -------- d-----w- c:\documents and settings\Owner\Application Data\Research In Motion
2009-06-27 03:11 . 2009-06-27 03:11 10134 ----a-r- c:\documents and settings\Owner\Application Data\Microsoft\Installer\{03B0EB18-51D2-4302-B92C-BBAE869FFBBF}\ARPPRODUCTICON.exe
2009-06-27 03:11 . 2009-06-27 03:11 -------- d-----w- c:\program files\Common Files\Research In Motion
2009-06-17 23:22 . 2009-04-17 19:31 -------- d-----w- c:\documents and settings\Owner\Application Data\Verizon
2009-06-17 19:38 . 2009-06-17 19:38 -------- d-----w- c:\documents and settings\All Users\Application Data\Raxco
2009-06-17 19:37 . 2009-06-17 19:37 -------- d-----w- c:\program files\Raxco
2009-06-17 19:37 . 2009-04-17 17:17 -------- d-----w- c:\program files\Verizon
2009-06-17 19:37 . 2009-04-17 19:31 -------- d-----w- c:\documents and settings\All Users\Application Data\Verizon
2009-06-11 13:57 . 2009-06-11 13:57 -------- d-----w- c:\program files\Common Files\INCA Shared
2009-06-11 00:05 . 2009-06-11 00:05 -------- d-----w- c:\documents and settings\Owner\Application Data\Gabob.NowBoarding.B1EDF665FD3C3F3F09EA618A6CFE5BBDBDB5E912.1
2009-06-11 00:04 . 2009-06-11 00:04 -------- d-----w- c:\program files\Common Files\Adobe AIR
2009-06-11 00:03 . 2009-06-11 00:04 38208 ----a-w- c:\documents and settings\Owner\Application Data\Macromedia\Flash Player\
www.macromedia.com\bin\airappinstaller\airappinstaller.exe2009-06-06 17:02 . 2009-06-06 17:02 -------- d-----w- c:\program files\directx
2009-06-06 12:03 . 2009-05-16 17:28 12288 ----a-w- C:\mtwb.dat
2009-06-06 12:02 . 2009-06-06 12:02 -------- d-----w- c:\documents and settings\Owner\Application Data\MySpace
2009-06-06 12:02 . 2009-06-06 12:02 7040776 ----a-w- c:\documents and settings\Owner\Application Data\MySpace\IM\Install\MSIMClientSetup.1.0.789.0-static-A.exe
2009-05-27 17:44 . 2009-05-27 17:44 622592 ----a-w- c:\documents and settings\Owner\Application Data\Verizon\VSP\downloads\Verizon-Welcome-70-WithAdsTracking.6334.zip.dir\all\tools\TCC.exe
2009-05-27 17:44 . 2009-05-27 17:44 622592 ----a-w- c:\documents and settings\Owner\Application Data\Verizon\VSP\downloads\Verizon-VISS-Fulfillment-RED-WithAdsTracking.41.zip.dir\all\tools\TCC.exe
2007-07-15 16:07 . 2004-09-29 20:44 441 ---ha-w- c:\program files\hpothb07.dat
2004-09-29 20:44 . 2004-09-29 20:44 753 ---ha-w- c:\program files\hpothb07.tif
2003-08-27 19:19 . 2004-01-09 00:33 36963 ----a-r- c:\program files\Common Files\SM1updtr.dll
2003-06-03 23:41 . 2003-06-03 23:41 168720 ----a-w- c:\program files\kmdupdate.exe
2003-04-27 20:23 . 2003-04-27 20:23 490608 ----a-w- c:\program files\ie6setup.exe
2003-04-27 17:05 . 2003-04-27 17:05 2552191 ----a-w- c:\program files\webfall.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2004-10-13 1694208]
"NvMediaCenter"="c:\windows\System32\NVMCTRAY.DLL" [2003-07-28 49152]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\Monitor.exe" [2005-11-30 57344]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"DW6"="c:\program files\The Weather Channel FW\Desktop\DesktopWeather.exe" [2009-03-19 801904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-08 52736]
"HotKeysCmds"="c:\windows\System32\hkcmd.exe" [2002-10-16 114688]
"Share-to-Web Namespace Daemon"="c:\program files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe" [2002-04-18 69632]
"CamMonitor"="c:\program files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 69632]
"KBD"="c:\hp\KBD\KBD.EXE" [2001-07-07 61440]
"StorageGuard"="c:\program files\VERITAS Software\Update Manager\sgtray.exe" [2002-06-18 155648]
"WCOLOREAL"="c:\program files\Coloreal\coloreal.exe" [2002-11-27 131072]
"PS2"="c:\windows\system32\ps2.exe" [2002-10-16 81920]
"HPDJ Taskbar Utility"="c:\windows\system32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-22 188416]
"SM1BG"="c:\windows\SM1BG.EXE" [2003-08-27 94208]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-07-28 4841472]
"HostManager"="c:\program files\Common Files\AOL\1149110705\ee\AOLSoftware.exe" [2008-06-24 41824]
"AOLDialer"="c:\program files\Common Files\AOL\ACS\AOLDial.exe" [2006-10-23 71216]
"OM_Monitor"="c:\program files\OLYMPUS\OLYMPUS Master\FirstStart.exe" [2005-11-30 40960]
"HP Software Update"="c:\program files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe" [2006-02-19 49152]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-04-12 148888]
"Verizon_McciTrayApp"="c:\program files\Verizon\McciTrayApp.exe" [2009-03-10 1553920]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SGPUpdater"="c:\program files\Search Guard PlusU\sgpUpdaters.exe" [2009-05-11 67456]
"FBSearch"="c:\program files\Search Guard Plus\SearchGuardPlus.exe" [2009-05-04 194432]
"VerizonServicepoint.exe"="c:\program files\Verizon\VSP\VerizonServicepoint.exe" [2009-03-12 2303216]
"nwiz"="nwiz.exe" - c:\windows\system32\nwiz.exe [2003-07-28 323584]
"AlcxMonitor"="ALCXMNTR.EXE" - c:\windows\ALCXMNTR.EXE [2004-09-07 57344]
c:\documents and settings\Owner\Start Menu\Programs\Startup\
PowerReg Scheduler V3.exe [2008-6-6 225280]
Webshots.lnk - c:\program files\Webshots\Launcher.exe [2004-10-11 45056]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
hp center UI.lnk - c:\program files\hp center\137903\Shadow\ShadowBar.exe [2003-2-20 69632]
hp center.lnk - c:\program files\hp center\137903\Program\BackWeb-137903.exe [2003-2-20 16384]
HP Digital Imaging Monitor.lnk - c:\program files\Hewlett-Packard\Digital Imaging\bin\hpqtra08.exe [2006-2-19 288472]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ PDBoot.exe\0autocheck autochk *
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\hp center\\137903\\Program\\BackWeb-137903.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLDial.exe"=
"c:\\Program Files\\Common Files\\AOL\\ACS\\AOLacsd.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149110705\\EE\\AOLServiceHost.exe"=
"c:\\Program Files\\Common Files\\AOL\\1149110705\\EE\\aolsoftware.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=