Hopefully this is good, I received a error telling me to do a CHKDSK and all of a sudden my computer blue screened when combo fix said it was preparing the log file. If I messed up tell me and ill make sure to do it again. Here's the log:
ComboFix 10-06-22.02 - Alan 06/22/2010 17:10:30.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2927.2104 [GMT -4]
Running from: C:\Documents and Settings\Alan\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-05-22 to 2010-06-22 )))))))))))))))))))))))))))))))
.
2010-06-22 20:34:18 . 2010-06-22 20:34:18 -------- d-----w- C:\found.000
2010-06-22 20:25:29 . 2010-05-12 23:52:31 552960 ----a-r- C:\OTLPE.exe
2010-06-22 20:24:36 . 2010-06-22 20:24:36 -------- d-----w- C:\_OTL
2010-06-15 21:33:27 . 2010-06-15 21:33:27 -------- d-----w- C:\Documents and Settings\Alan\Application Data\Datel
2010-06-15 21:32:56 . 2010-06-15 21:32:56 -------- d-----w- C:\Documents and Settings\Alan\Local Settings\Application Data\GameTuts
2010-06-15 21:32:55 . 2010-06-15 21:32:55 -------- d-----w- C:\Documents and Settings\Alan\Application Data\GameTuts
2010-06-11 15:52:42 . 2010-06-11 15:52:42 -------- d-sh--w- C:\Documents and Settings\LocalService\IETldCache
2010-06-11 14:24:42 . 2010-06-11 14:24:42 64949 ----a-w- C:\WINDOWS\BricoPackUninst.cmd
2010-06-11 14:21:45 . 2010-06-11 14:24:42 6112 ----a-w- C:\WINDOWS\BricoPackFoldersDelete.cmd
2010-06-11 14:21:17 . 2010-06-11 14:21:17 -------- d-----w- C:\WINDOWS\BricoPacks
2010-06-09 03:18:58 . 2010-05-06 10:41:48 743424 -c----w- C:\WINDOWS\system32\dllcache\iedvtool.dll
2010-06-05 18:57:10 . 2010-06-05 19:08:01 -------- d-----w- C:\Program Files\LastCo
2010-06-02 20:37:35 . 2010-06-02 20:37:35 155360 ----a-w- C:\Documents and Settings\Alan\Application Data\GameRanger\GameRanger\Data\GameRanger.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 503808 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\msvcp71.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 499712 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\jmc.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 348160 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\msvcr71.dll
2010-05-28 12:33:13 . 2010-05-28 12:33:13 61440 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6d70696c-n\decora-sse.dll
2010-05-28 12:33:13 . 2010-05-28 12:33:13 12800 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6d70696c-n\decora-d3d.dll
2010-05-28 00:09:00 . 2010-05-28 00:09:00 41872 ----a-w- C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-22 21:00:21 . 2010-04-05 01:41:30 -------- d-----w- C:\Program Files\FlashGet
2010-06-22 20:48:59 . 2010-06-08 20:37:20 -------- d-----w- C:\Documents and Settings\Alan\Application Data\LimeWire
2010-06-22 20:48:47 . 2009-11-28 22:32:42 -------- d-----w- C:\Program Files\Steamm
2010-06-13 15:56:23 . 2009-04-25 12:43:21 -------- d-----w- C:\Documents and Settings\Alan\Application Data\Xfire
2010-06-11 19:33:19 . 2008-11-02 16:33:08 1324 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
2010-06-11 15:51:38 . 2008-11-16 04:40:26 139152 ----a-w- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2010-06-11 15:51:31 . 2008-11-16 04:40:13 111928 ----a-w- C:\WINDOWS\system32\PnkBstrB.exe
2010-06-11 05:09:18 . 2009-12-20 03:15:17 -------- d-----w- C:\Program Files\AlienGUIse
2010-06-09 07:34:19 . 2009-03-13 20:47:07 -------- d-----w- C:\Program Files\Microsoft Silverlight
2010-06-09 07:15:33 . 2008-11-06 03:19:11 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-06-04 16:10:46 . 2009-04-25 12:43:17 -------- d-s---w- C:\Program Files\Xfire
2010-06-03 10:23:39 . 2009-10-31 17:10:28 1240800 ----a-w- C:\Documents and Settings\Alan\Application Data\GameRanger\GameRanger\GameRanger.exe
2010-05-23 20:41:27 . 2010-04-16 01:29:39 -------- d-----w- C:\Program Files\World of Warcraft
2010-05-13 21:14:06 . 2009-04-13 18:15:16 -------- d-----w- C:\Program Files\Diablo II
2010-05-13 21:13:39 . 2010-05-13 21:11:18 17934 ----a-w- C:\WINDOWS\DIIUnin.dat
2010-05-13 21:12:36 . 2009-04-13 18:42:31 21840 ----atw- C:\WINDOWS\system32\SIntfNT.dll
2010-05-13 21:12:36 . 2009-04-13 18:42:31 17212 ----atw- C:\WINDOWS\system32\SIntf32.dll
2010-05-13 21:12:36 . 2009-04-13 18:42:31 12067 ----atw- C:\WINDOWS\system32\SIntf16.dll
2010-05-13 21:11:11 . 2010-05-13 21:11:11 94208 ----a-w- C:\WINDOWS\DIIUnin.exe
2010-05-13 21:11:11 . 2010-05-13 21:11:11 2829 ----a-w- C:\WINDOWS\DIIUnin.pif
2010-05-08 15:24:00 . 2009-10-10 17:22:08 -------- d-----w- C:\Program Files\McAfee.com
2010-05-08 14:46:34 . 2009-06-07 04:11:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee
2010-05-08 14:46:33 . 2009-06-07 04:56:36 -------- d-----w- C:\Program Files\McAfee
2010-05-08 14:45:29 . 2009-10-10 17:22:08 -------- d-----w- C:\Program Files\Common Files\McAfee
2010-05-06 10:41:53 . 2008-04-14 12:00:00 907264 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-05-02 05:22:50 . 2008-04-14 12:00:00 1851264 ----a-w- C:\WINDOWS\system32\win32k.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:52 9344 ----a-w- C:\WINDOWS\system32\drivers\mfeclnk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 95568 ----a-w- C:\WINDOWS\system32\drivers\mfeapfk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 88480 ----a-w- C:\WINDOWS\system32\drivers\mfendisk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 83496 ----a-w- C:\WINDOWS\system32\drivers\mferkdet.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 82952 ----a-w- C:\WINDOWS\system32\drivers\mfetdi2k.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 55456 ----a-w- C:\WINDOWS\system32\drivers\cfwids.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 312616 ----a-w- C:\WINDOWS\system32\drivers\mfefirek.sys
2010-04-27 21:16:24 . 2009-07-08 17:44:20 385880 ----a-w- C:\WINDOWS\system32\drivers\mfehidk.sys
2010-04-27 21:16:24 . 2009-06-07 04:57:03 51688 ----a-w- C:\WINDOWS\system32\drivers\mfebopk.sys
2010-04-27 21:16:24 . 2009-06-07 04:57:03 152320 ----a-w- C:\WINDOWS\system32\drivers\mfeavfk.sys
2010-04-22 01:02:29 . 2010-01-30 03:49:21 75 ----a-w- C:\Documents and Settings\Alan\jagex_runescape_preferences2.dat
2010-04-22 01:02:29 . 2008-12-07 20:15:12 41 -c--a-w- C:\Documents and Settings\Alan\jagex_runescape_preferences.dat
2010-04-20 05:30:08 . 2008-04-14 12:00:00 285696 ----a-w- C:\WINDOWS\system32\atmfd.dll
2010-04-18 16:48:57 . 2010-04-18 16:48:57 71960 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Plugins\npoctoshape.dll
2010-04-07 22:36:58 . 2010-04-07 22:36:58 45056 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\MapleStory.exe1_C19AB6C4BBD049EF927D9C7CB80BC0B0.exe
2010-04-07 22:36:58 . 2010-04-07 22:36:58 45056 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\MapleStory.exe_C19AB6C4BBD049EF927D9C7CB80BC0B0.exe
2010-04-07 22:36:58 . 2010-04-07 22:36:58 10134 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\ARPPRODUCTICON.exe
2010-04-06 09:12:08 . 2010-05-12 21:06:36 114360 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 98304 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 258352 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 126976 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:23 401408 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:22 765952 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:22 172032 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2010-03-28 04:12:24 . 2010-03-28 04:12:24 0 ----a-w- C:\Documents and Settings\Alan\jagex__preferences3.dat
2010-03-25 15:27:46 . 2010-04-08 21:24:26 1107264 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2010-04-27 21:16:24 . 2010-05-03 01:42:52 24376 ----a-w- C:\Program Files\mozilla firefox\components\Scriptff.dll
2009-01-27 01:34:38 . 2009-01-27 01:34:38 1044480 -c--a-w- C:\Program Files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34:38 . 2009-01-27 01:34:38 200704 -c--a-w- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2009-08-06 23:24:06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)] . . C:\WINDOWS\system32\wuauclt.exe
[-] 2009-08-06 23:24:06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)] . . C:\WINDOWS\system32\dllcache\wuauclt.exe
[7] 2008-10-16 19:09:44 . E654B78D2F1D791B30D0ED9A8195EC22 . 51224 . . [7.2.6001.788 (winmain_oob/wu_wsuswlc(wmbla).081016-1330)] . . C:\WINDOWS\ERDNT\cache\wuauclt.exe
[-] 2010-05-06 10:41:52 . 2FFDB270D0BC419421F3B3B2F7165790 . 6224896 . . [8.00.6001.18928 (longhorn_ie8_gdr.100503-1700)] . . C:\WINDOWS\system32\mshtml.dll
[-] 2010-05-06 10:41:52 . 2FFDB270D0BC419421F3B3B2F7165790 . 6224896 . . [8.00.6001.18928 (longhorn_ie8_gdr.100503-1700)] . . C:\WINDOWS\system32\dllcache\mshtml.dll
[7] 2010-05-06 10:36:26 . 9BE28F749A7FE7F8F177C6AA2E9DA609 . 5953024 . . [8.00.6001.23019 (longhorn_ie8_ldr.100503-1800)] . . C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
[7] 2010-02-25 06:24:36 . 7054F6ADC9B670887659F1561603B0D0 . 5944832 . . [8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)] . . C:\WINDOWS\ie8updates\KB982381-IE8\mshtml.dll
[7] 2010-02-25 06:19:43 . 974772C74DA7C7A8E7C813A9908A845F . 5946880 . . [8.00.6001.22995 (longhorn_ie8_ldr.100223-0100)] . . C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
[7] 2009-12-21 19:14:04 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876 (longhorn_ie8_gdr.091218-1700)] . . C:\WINDOWS\ie8updates\KB980182-IE8\mshtml.dll
[7] 2009-12-21 19:09:28 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967 (longhorn_ie8_ldr.091219-0100)] . . C:\WINDOWS\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[7] 2009-10-29 07:45:44 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945 (longhorn_ie8_ldr.091027-0100)] . . C:\WINDOWS\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[7] 2009-10-29 07:45:37 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854 (longhorn_ie8_gdr.091026-1700)] . . C:\WINDOWS\ie8updates\KB978207-IE8\mshtml.dll
[7] 2009-10-22 09:19:04 . CDA69BC1C23B0EA033B989F67CB722FF . 5939712 . . [8.00.6001.18852 (longhorn_ie8_gdr.091020-1827)] . . C:\WINDOWS\ie8updates\KB976325-IE8\mshtml.dll
[7] 2009-10-22 09:18:10 . A6CF28C6E0B6D10098AB601D85EE55E8 . 5943296 . . [8.00.6001.22942 (longhorn_ie8_ldr.091021-0230)] . . C:\WINDOWS\$hf_mig$\KB976749-IE8\SP3QFE\mshtml.dll
[7] 2009-08-29 08:08:20 . 0E49677EE57A928765FC47FFBACD5326 . 5940224 . . [8.00.6001.18828 (longhorn_ie8_gdr.090826-1700)] . . C:\WINDOWS\ie8updates\KB976749-IE8\mshtml.dll
[7] 2009-08-29 08:01:43 . B68F6E6C66D17D9EDABF3D5DA71046DA . 5942272 . . [8.00.6001.22918 (longhorn_ie8_ldr.090827-0100)] . . C:\WINDOWS\$hf_mig$\KB974455-IE8\SP3QFE\mshtml.dll
[7] 2009-07-19 13:18:59 . 5A32B43A48D6DCA339BF24105D9A028F . 5937152 . . [8.00.6001.18812 (longhorn_ie8_gdr.090717-2100)] . . C:\WINDOWS\ie8updates\KB974455-IE8\mshtml.dll
[7] 2009-07-19 13:17:52 . F25D866DD486AD30E05E5596CB363C3E . 5938176 . . [8.00.6001.22902 (longhorn_ie8_ldr.090718-0500)] . . C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE\mshtml.dll
[7] 2009-03-08 08:41:16 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\ie8updates\KB972260-IE8\mshtml.dll
[7] 2009-02-21 07:39:54 . 1BB754AB47B327DE8DBF2FA18C36357C . 3596800 . . [7.00.6000.21015 (vista_ldr.090218-1505)] . . C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[7] 2009-02-20 18:09:37 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825 (vista_gdr.090218-1505)] . . C:\WINDOWS\ERDNT\cache\mshtml.dll
[7] 2009-02-20 18:09:37 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825 (vista_gdr.090218-1505)] . . C:\WINDOWS\ie8\mshtml.dll
[7] 2009-01-17 02:35:14 . 3B413267DA8AE71C20E5EF3E54F74728 . 3594752 . . [7.00.6000.16809 (vista_gdr.090114-1504)] . . C:\WINDOWS\ie7updates\KB963027-IE7\mshtml.dll
[7] 2009-01-16 16:24:38 . CC9D001B7370B292C35B366CA05B12B4 . 3596288 . . [7.00.6000.20996 (vista_ldr.090114-1504)] . . C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[7] 2008-12-13 06:40:02 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788 (vista_gdr.081211-1619)] . . C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll
[7] 2008-12-13 06:26:56 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973 (vista_ldr.081211-1619)] . . C:\WINDOWS\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[7] 2008-10-17 07:08:40 . EACAEDEF6FA2A969DE5B36190D45396F . 3593216 . . [7.00.6000.16762 (vista_gdr.081013-1507)] . . C:\WINDOWS\ie7updates\KB960714-IE7\mshtml.dll
[7] 2008-10-16 20:24:10 . B74F31A4BD83797D7A083F922169287D . 3595264 . . [7.00.6000.20935 (vista_ldr.081013-1507)] . . C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[7] 2008-08-27 08:24:32 . 1AD035E04A7068EC2820B055A3131ED8 . 3593216 . . [7.00.6000.16735 (vista_gdr.080820-1506)] . . C:\WINDOWS\ie7updates\KB958215-IE7\mshtml.dll
[7] 2008-08-26 09:08:43 . 25CC085720EE3617FD1F8AB9E2F7CAB2 . 3594752 . . [7.00.6000.20900 (vista_ldr.080820-1506)] . . C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[7] 2008-08-20 05:30:53 . 507BDA42F7DB8209C0F0B3556A043491 . 3067904 . . [6.00.2900.5659 (xpsp_sp3_gdr.080819-1237)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\mshtml.dll
[7] 2008-08-20 04:58:54 . BD45470B132A0F98596277323D9F2E5A . 3067904 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\mshtml.dll
[7] 2008-08-20 04:58:54 . BD45470B132A0F98596277323D9F2E5A . 3067904 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\mshtml.dll
[7] 2008-04-14 12:00:00 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ie7\mshtml.dll
[7] 2007-08-13 22:54:12 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13 (longhorn(wmbla).070711-1130)] . . C:\WINDOWS\ie7updates\KB956390-IE7\mshtml.dll
[-] 2010-05-06 10:41:53 . DE6A3492ABC54F2327CAA43AD17CAD7B . 907264 . . [8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)] . . C:\WINDOWS\system32\wininet.dll
[-] 2010-05-06 10:41:53 . DE6A3492ABC54F2327CAA43AD17CAD7B . 907264 . . [8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)] . . C:\WINDOWS\system32\dllcache\wininet.dll
[7] 2010-05-06 10:36:27 . C1490F68B44AF8B781F52F12F564625D . 919040 . . [8.00.6001.23014 (longhorn_ie8_ldr.100419-1507)] . . C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
[7] 2010-02-25 06:24:37 . 7A42CFED96CDA7F2FB1A26D1F9F65775 . 916480 . . [8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)] . . C:\WINDOWS\ie8updates\KB982381-IE8\wininet.dll
[7] 2010-02-25 06:19:44 . 4458D59F2B0369F4D3B137541D284041 . 919040 . . [8.00.6001.22995 (longhorn_ie8_ldr.100223-0100)] . . C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll
[7] 2009-12-21 19:14:05 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876 (longhorn_ie8_gdr.091218-1700)] . . C:\WINDOWS\ie8updates\KB980182-IE8\wininet.dll
[7] 2009-12-21 19:09:28 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967 (longhorn_ie8_ldr.091219-0100)] . . C:\WINDOWS\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[7] 2009-10-29 07:45:45 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945 (longhorn_ie8_ldr.091027-0100)] . . C:\WINDOWS\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[7] 2009-10-29 07:45:38 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854 (longhorn_ie8_gdr.091026-1700)] . . C:\WINDOWS\ie8updates\KB978207-IE8\wininet.dll
[7] 2009-08-29 08:08:21 . CF0A5FE05BF614C24950D8FAEC1BC309 . 916480 . . [8.00.6001.18828 (longhorn_ie8_gdr.090826-1700)] . . C:\WINDOWS\ie8updates\KB976325-IE8\wininet.dll
[7] 2009-08-29 08:01:44 . 972B226BDAD71C55F3CC9A72BBF8F1C1 . 916480 . . [8.00.6001.22918 (longhorn_ie8_ldr.090827-0100)] . . C:\WINDOWS\$hf_mig$\KB974455-IE8\SP3QFE\wininet.dll
[7] 2009-07-03 17:09:28 . 7E8A47A2E6561274B83E257CE74803FD . 915456 . . [8.00.6001.18806 (longhorn_ie8_gdr.090701-1700)] . . C:\WINDOWS\ie8updates\KB974455-IE8\wininet.dll
[7] 2009-07-03 17:06:51 . 38114DAB42FB2EB84D1726C42B8D80C5 . 915456 . . [8.00.6001.22896 (longhorn_ie8_ldr.090702-0100)] . . C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE\wininet.dll
[7] 2009-03-08 08:34:58 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\ie8updates\KB972260-IE8\wininet.dll
[7] 2009-03-03 00:18:25 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827 (vista_gdr.090226-1506)] . . C:\WINDOWS\ERDNT\cache\wininet.dll
[7] 2009-03-03 00:18:25 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827 (vista_gdr.090226-1506)] . . C:\WINDOWS\ie8\wininet.dll
[7] 2009-03-03 00:17:40 . C8667854873938CA13C986F16B0CD183 . 828416 . . [7.00.6000.21020 (vista_ldr.090226-1506)] . . C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[7] 2008-12-20 23:56:00 . 044E0A4E9FE97C0FB9AFE9C89E2A82E6 . 827904 . . [7.00.6000.20978 (vista_ldr.081217-1620)] . . C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[7] 2008-12-20 23:15:41 . A82935D32D0672E8FF4E91AE398E901C . 826368 . . [7.00.6000.16791 (vista_gdr.081217-1620)] . . C:\WINDOWS\ie7updates\KB963027-IE7\wininet.dll
[7] 2008-10-16 20:38:40 . 6741EAF7B7F110E803A6E38F6E5FA6B0 . 826368 . . [7.00.6000.16762 (vista_gdr.081013-1507)] . . C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll
[7] 2008-10-16 20:24:11 . 0D5B75171FF51775B630A431B6C667E8 . 827904 . . [7.00.6000.20935 (vista_ldr.081013-1507)] . . C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 09:08:45 . 77C192FE56A70D7FA0247BA0A6201C32 . 827904 . . [7.00.6000.20900 (vista_ldr.080820-1506)] . . C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 07:24:31 . EF8EBA98145BFA44E80D17A3B3453300 . 826368 . . [7.00.6000.16735 (vista_gdr.080820-1506)] . . C:\WINDOWS\ie7updates\KB958215-IE7\wininet.dll
[7] 2008-08-20 05:30:51 . 9AF5F25124FBDC36E2B510729CBA2674 . 666112 . . [6.00.2900.5659 (xpsp_sp3_gdr.080819-1237)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\wininet.dll
[7] 2008-08-20 04:58:48 . 94418F53D2612C26DBADC04DAFBC197C . 666624 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
[7] 2008-08-20 04:58:48 . 94418F53D2612C26DBADC04DAFBC197C . 666624 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\wininet.dll
[7] 2008-04-14 12:00:00 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ie7\wininet.dll
[7] 2007-08-13 22:54:10 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13 (longhorn(wmbla).070711-1130)] . . C:\WINDOWS\ie7updates\KB956390-IE7\wininet.dll
[-] 2008-04-14 12:00:00 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\explorer.exe
[7] 2008-04-14 12:00:00 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\explorer.exe
[-] 2008-04-14 12:00:00 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="C:\Program Files\Pando Networks\Media Booster\PMB.exe" [2010-02-06 23:12:52 2937528]
"Steam"="c:\program files\steamm\steam.exe" [2010-05-08 14:50:53 1238352]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 11:57:08 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-09-18 04:55:00 13574144]
"AdobeCS4ServiceManager"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 11:58:34 611712]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2009-05-26 21:18:30 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2009-07-13 18:03:10 292128]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-01 14:48:16 524632]
"ULiRaid"="C:\Program Files\ULiRaid\ULiRaid.exe" [2006-05-12 18:57:40 630784]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 20:21:52 246504]
"LogMeIn Hamachi Ui"="C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 15:16:16 1820040]
"Flashget"="C:\Program Files\FlashGet\FlashGet.exe" [2007-09-25 08:10:50 2007088]
"mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2010-04-02 03:05:04 1180976]
C:\Documents and Settings\Alan\Start Menu\Programs\Startup\
crisisx_updater.jar [2010-4-1 53790]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2010-5-26 503808]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-6-1 65536]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 02:41:34 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34:52 24576 ----a-w- C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Alan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Alan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=C:\WINDOWS\pss\Snagit 9.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2008-11-06 01:08:55 65536 -c--a-w- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis True Image Monitor]
2008-11-06 01:08:55 471637 -c--a-w- C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 07:38:00 34672 -c--a-w- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00:00 15360 ------w- C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 21:50:42 221184 -c--a-w- C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 21:50:18 81920 -c--a-w- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2007-08-31 19:13:41 988584 -c--a-w- C:\Program Files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
2010-04-02 03:05:04 1180976 ----a-w- C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-09-18 04:55:00 13574144 ----a-w- C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-09-18 04:55:00 86016 -c--a-w- C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-09-18 04:55:00 1657376 -c--a-w- C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-11-01 00:42:40 32768 -c----w- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 14:00:00 1116920 -c--a-w- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-07-27 22:01:36 68096 -c--a-w- C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
2008-04-04 16:38:00 88584 -c--a-w- C:\Program Files\Logitech\Gaming Software\LWEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"C:\\Program Files\\Steamm\\Steam.exe"=
"C:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"C:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"C:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\Launcher.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.3.0.10958-enUS-downloader.exe"=
"C:\\Documents and Settings\\Alan\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"C:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"C:\\Program Files\\Steamm\\steamapps\\basketcase378\\garrysmod\\hl2.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Steamm\\steamapps\\soarrin211\\condition zero\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57640:TCP"= 57640:TCP:*:Disabled:Pando Media Booster
"57640:UDP"= 57640:UDP:*:Disabled:Pando Media Booster
"56630:TCP"= 56630:TCP:*:Disabled:Pando Media Booster
"56630:UDP"= 56630:UDP:*:Disabled:Pando Media Booster
"56494:TCP"= 56494:TCP:*:Disabled:Pando Media Booster
"56494:UDP"= 56494:UDP:*:Disabled:Pando Media Booster
"86:TCP"= 86:TCP:BroadCam Web Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"58485:TCP"= 58485:TCP:Pando Media Booster
"58485:UDP"= 58485:UDP:Pando Media Booster
"58082:TCP"= 58082:TCP:Pando Media Booster
"58082:UDP"= 58082:UDP:Pando Media Booster
R0 JAHCI;JAHCI;C:\WINDOWS\system32\drivers\JAHCI.sys [11/5/2008 8:53:02 PM 33280]
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [7/24/2009 9:48:45 AM 64160]
R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys [11/2/2009 8:50:08 AM 52480]
R1 mfetdi2k;McAfee Inc. mfetdi2k;C:\WINDOWS\system32\drivers\mfetdi2k.sys [5/2/2010 9:42:44 PM 82952]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [3/30/2010 11:16:12 AM 1107336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06:55 PM 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [10/10/2009 1:24:28 PM 93320]
R2 McMPFSvc;McAfee Personal Firewall;"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [5/2/2010 9:42:35 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [5/2/2010 9:42:35 PM 271480]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [5/2/2010 9:42:55 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [5/2/2010 9:42:45 PM 141792]
R3 cfwids;McAfee Inc. cfwids;C:\WINDOWS\system32\drivers\cfwids.sys [5/2/2010 9:42:44 PM 55456]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;C:\WINDOWS\system32\drivers\libusb0.sys [7/23/2009 8:28:34 PM 28672]
R3 mfefirek;McAfee Inc. mfefirek;C:\WINDOWS\system32\drivers\mfefirek.sys [5/2/2010 9:42:44 PM 312616]
R3 mfendiskmp;mfendiskmp;C:\WINDOWS\system32\drivers\mfendisk.sys [5/2/2010 9:42:44 PM 88480]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\drivers\ULILAN51.SYS [10/20/2008 10:11:22 PM 28672]
S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [10/31/2009 11:23:09 PM 691696]
S3 BroadCamService;BroadCam Service;C:\Program Files\NCH Software\BroadCam\broadCam.exe [6/16/2009 9:27:32 PM 368644]
S3 GarenaPEngine;GarenaPEngine;\??\C:\DOCUME~1\Alan\LOCALS~1\Temp\UAK27D.tmp --> C:\DOCUME~1\Alan\LOCALS~1\Temp\UAK27D.tmp [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;C:\WINDOWS\system32\drivers\mfendisk.sys [5/2/2010 9:42:44 PM 88480]
S3 mferkdet;McAfee Inc. mferkdet;C:\WINDOWS\system32\drivers\mferkdet.sys [5/2/2010 9:42:44 PM 83496]
S3 npggsvc;nProtect GameGuard Service;C:\WINDOWS\system32\GameMon.des -service --> C:\WINDOWS\system32\GameMon.des -service [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 8:28:04 PM 47128]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 8:01:16 AM 2799808]
S4 RsFx0102;RsFx0102 Driver;C:\WINDOWS\system32\drivers\RsFx0102.sys [7/10/2008 2:49:14 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 8:28:06 PM 369688]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
2010-06-21 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06:56 . 2010-03-01 14:48:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
IE: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
IE: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - component: C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: C:\Program Files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: C:\Documents and Settings\Alan\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: C:\Program Files\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiCHPlugin.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - trueC:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-AbyssWebServer - C:\Documents and Settings\Alan\Desktop\UberRO\Server\Abyss Web Server\abyssws.exe
MSConfigStartUp-Steam - C:\Program Files\Steam\Steam.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Documents and Settings\Alan\Desktop\UberScape\bin\jusched.exe
Last edited by mattferd on 22nd June 2010, 10:22 pm; edited 1 time in total (Reason for editing : Explaining my problem with ComboFix)
ComboFix 10-06-22.02 - Alan 06/22/2010 17:10:30.3.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2927.2104 [GMT -4]
Running from: C:\Documents and Settings\Alan\Desktop\ComboFix.exe
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *disabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Resident AV is active
.
((((((((((((((((((((((((( Files Created from 2010-05-22 to 2010-06-22 )))))))))))))))))))))))))))))))
.
2010-06-22 20:34:18 . 2010-06-22 20:34:18 -------- d-----w- C:\found.000
2010-06-22 20:25:29 . 2010-05-12 23:52:31 552960 ----a-r- C:\OTLPE.exe
2010-06-22 20:24:36 . 2010-06-22 20:24:36 -------- d-----w- C:\_OTL
2010-06-15 21:33:27 . 2010-06-15 21:33:27 -------- d-----w- C:\Documents and Settings\Alan\Application Data\Datel
2010-06-15 21:32:56 . 2010-06-15 21:32:56 -------- d-----w- C:\Documents and Settings\Alan\Local Settings\Application Data\GameTuts
2010-06-15 21:32:55 . 2010-06-15 21:32:55 -------- d-----w- C:\Documents and Settings\Alan\Application Data\GameTuts
2010-06-11 15:52:42 . 2010-06-11 15:52:42 -------- d-sh--w- C:\Documents and Settings\LocalService\IETldCache
2010-06-11 14:24:42 . 2010-06-11 14:24:42 64949 ----a-w- C:\WINDOWS\BricoPackUninst.cmd
2010-06-11 14:21:45 . 2010-06-11 14:24:42 6112 ----a-w- C:\WINDOWS\BricoPackFoldersDelete.cmd
2010-06-11 14:21:17 . 2010-06-11 14:21:17 -------- d-----w- C:\WINDOWS\BricoPacks
2010-06-09 03:18:58 . 2010-05-06 10:41:48 743424 -c----w- C:\WINDOWS\system32\dllcache\iedvtool.dll
2010-06-05 18:57:10 . 2010-06-05 19:08:01 -------- d-----w- C:\Program Files\LastCo
2010-06-02 20:37:35 . 2010-06-02 20:37:35 155360 ----a-w- C:\Documents and Settings\Alan\Application Data\GameRanger\GameRanger\Data\GameRanger.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 503808 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\msvcp71.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 499712 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\jmc.dll
2010-05-28 12:33:14 . 2010-05-28 12:33:14 348160 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\46\f84c6ae-3ad6330f-n\msvcr71.dll
2010-05-28 12:33:13 . 2010-05-28 12:33:13 61440 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6d70696c-n\decora-sse.dll
2010-05-28 12:33:13 . 2010-05-28 12:33:13 12800 ----a-w- C:\Documents and Settings\Alan\Application Data\Sun\Java\Deployment\SystemCache\6.0\50\5535ab32-6d70696c-n\decora-d3d.dll
2010-05-28 00:09:00 . 2010-05-28 00:09:00 41872 ----a-w- C:\WINDOWS\system32\xfcodec.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-22 21:00:21 . 2010-04-05 01:41:30 -------- d-----w- C:\Program Files\FlashGet
2010-06-22 20:48:59 . 2010-06-08 20:37:20 -------- d-----w- C:\Documents and Settings\Alan\Application Data\LimeWire
2010-06-22 20:48:47 . 2009-11-28 22:32:42 -------- d-----w- C:\Program Files\Steamm
2010-06-13 15:56:23 . 2009-04-25 12:43:21 -------- d-----w- C:\Documents and Settings\Alan\Application Data\Xfire
2010-06-11 19:33:19 . 2008-11-02 16:33:08 1324 ----a-w- C:\WINDOWS\system32\d3d9caps.dat
2010-06-11 15:51:38 . 2008-11-16 04:40:26 139152 ----a-w- C:\WINDOWS\system32\drivers\PnkBstrK.sys
2010-06-11 15:51:31 . 2008-11-16 04:40:13 111928 ----a-w- C:\WINDOWS\system32\PnkBstrB.exe
2010-06-11 05:09:18 . 2009-12-20 03:15:17 -------- d-----w- C:\Program Files\AlienGUIse
2010-06-09 07:34:19 . 2009-03-13 20:47:07 -------- d-----w- C:\Program Files\Microsoft Silverlight
2010-06-09 07:15:33 . 2008-11-06 03:19:11 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-06-04 16:10:46 . 2009-04-25 12:43:17 -------- d-s---w- C:\Program Files\Xfire
2010-06-03 10:23:39 . 2009-10-31 17:10:28 1240800 ----a-w- C:\Documents and Settings\Alan\Application Data\GameRanger\GameRanger\GameRanger.exe
2010-05-23 20:41:27 . 2010-04-16 01:29:39 -------- d-----w- C:\Program Files\World of Warcraft
2010-05-13 21:14:06 . 2009-04-13 18:15:16 -------- d-----w- C:\Program Files\Diablo II
2010-05-13 21:13:39 . 2010-05-13 21:11:18 17934 ----a-w- C:\WINDOWS\DIIUnin.dat
2010-05-13 21:12:36 . 2009-04-13 18:42:31 21840 ----atw- C:\WINDOWS\system32\SIntfNT.dll
2010-05-13 21:12:36 . 2009-04-13 18:42:31 17212 ----atw- C:\WINDOWS\system32\SIntf32.dll
2010-05-13 21:12:36 . 2009-04-13 18:42:31 12067 ----atw- C:\WINDOWS\system32\SIntf16.dll
2010-05-13 21:11:11 . 2010-05-13 21:11:11 94208 ----a-w- C:\WINDOWS\DIIUnin.exe
2010-05-13 21:11:11 . 2010-05-13 21:11:11 2829 ----a-w- C:\WINDOWS\DIIUnin.pif
2010-05-08 15:24:00 . 2009-10-10 17:22:08 -------- d-----w- C:\Program Files\McAfee.com
2010-05-08 14:46:34 . 2009-06-07 04:11:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\McAfee
2010-05-08 14:46:33 . 2009-06-07 04:56:36 -------- d-----w- C:\Program Files\McAfee
2010-05-08 14:45:29 . 2009-10-10 17:22:08 -------- d-----w- C:\Program Files\Common Files\McAfee
2010-05-06 10:41:53 . 2008-04-14 12:00:00 907264 ----a-w- C:\WINDOWS\system32\wininet.dll
2010-05-02 05:22:50 . 2008-04-14 12:00:00 1851264 ----a-w- C:\WINDOWS\system32\win32k.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:52 9344 ----a-w- C:\WINDOWS\system32\drivers\mfeclnk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 95568 ----a-w- C:\WINDOWS\system32\drivers\mfeapfk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 88480 ----a-w- C:\WINDOWS\system32\drivers\mfendisk.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 83496 ----a-w- C:\WINDOWS\system32\drivers\mferkdet.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 82952 ----a-w- C:\WINDOWS\system32\drivers\mfetdi2k.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 55456 ----a-w- C:\WINDOWS\system32\drivers\cfwids.sys
2010-04-27 21:16:24 . 2010-05-03 01:42:44 312616 ----a-w- C:\WINDOWS\system32\drivers\mfefirek.sys
2010-04-27 21:16:24 . 2009-07-08 17:44:20 385880 ----a-w- C:\WINDOWS\system32\drivers\mfehidk.sys
2010-04-27 21:16:24 . 2009-06-07 04:57:03 51688 ----a-w- C:\WINDOWS\system32\drivers\mfebopk.sys
2010-04-27 21:16:24 . 2009-06-07 04:57:03 152320 ----a-w- C:\WINDOWS\system32\drivers\mfeavfk.sys
2010-04-22 01:02:29 . 2010-01-30 03:49:21 75 ----a-w- C:\Documents and Settings\Alan\jagex_runescape_preferences2.dat
2010-04-22 01:02:29 . 2008-12-07 20:15:12 41 -c--a-w- C:\Documents and Settings\Alan\jagex_runescape_preferences.dat
2010-04-20 05:30:08 . 2008-04-14 12:00:00 285696 ----a-w- C:\WINDOWS\system32\atmfd.dll
2010-04-18 16:48:57 . 2010-04-18 16:48:57 71960 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Plugins\npoctoshape.dll
2010-04-07 22:36:58 . 2010-04-07 22:36:58 45056 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\MapleStory.exe1_C19AB6C4BBD049EF927D9C7CB80BC0B0.exe
2010-04-07 22:36:58 . 2010-04-07 22:36:58 45056 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\MapleStory.exe_C19AB6C4BBD049EF927D9C7CB80BC0B0.exe
2010-04-07 22:36:58 . 2010-04-07 22:36:58 10134 ----a-r- C:\Documents and Settings\Alan\Application Data\Microsoft\Installer\{C19AB6C4-BBD0-49EF-927D-9C7CB80BC0B0}\ARPPRODUCTICON.exe
2010-04-06 09:12:08 . 2010-05-12 21:06:36 114360 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 98304 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 258352 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\unicows.dll
2010-04-05 01:58:21 . 2009-07-05 14:02:23 126976 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\nxgameus.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:23 401408 -c--a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGMResource.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:22 765952 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGMDll.dll
2010-04-05 01:58:20 . 2009-07-05 14:02:22 172032 ----a-w- C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe
2010-03-28 04:12:24 . 2010-03-28 04:12:24 0 ----a-w- C:\Documents and Settings\Alan\jagex__preferences3.dat
2010-03-25 15:27:46 . 2010-04-08 21:24:26 1107264 ----a-w- C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\DTToolbar@toolbarnet.com\components\DTToolbarFF.dll
2010-04-27 21:16:24 . 2010-05-03 01:42:52 24376 ----a-w- C:\Program Files\mozilla firefox\components\Scriptff.dll
2009-01-27 01:34:38 . 2009-01-27 01:34:38 1044480 -c--a-w- C:\Program Files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34:38 . 2009-01-27 01:34:38 200704 -c--a-w- C:\Program Files\mozilla firefox\plugins\ssldivx.dll
.
------- Sigcheck -------
[-] 2009-08-06 23:24:06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)] . . C:\WINDOWS\system32\wuauclt.exe
[-] 2009-08-06 23:24:06 . 0B6DABD6FFF1AD42A3CD65A1C7EE8F35 . 68832 . . [7.4.7600.226 (winmain_wtr_wsus3sp2(wmbla).090806-1834)] . . C:\WINDOWS\system32\dllcache\wuauclt.exe
[7] 2008-10-16 19:09:44 . E654B78D2F1D791B30D0ED9A8195EC22 . 51224 . . [7.2.6001.788 (winmain_oob/wu_wsuswlc(wmbla).081016-1330)] . . C:\WINDOWS\ERDNT\cache\wuauclt.exe
[-] 2010-05-06 10:41:52 . 2FFDB270D0BC419421F3B3B2F7165790 . 6224896 . . [8.00.6001.18928 (longhorn_ie8_gdr.100503-1700)] . . C:\WINDOWS\system32\mshtml.dll
[-] 2010-05-06 10:41:52 . 2FFDB270D0BC419421F3B3B2F7165790 . 6224896 . . [8.00.6001.18928 (longhorn_ie8_gdr.100503-1700)] . . C:\WINDOWS\system32\dllcache\mshtml.dll
[7] 2010-05-06 10:36:26 . 9BE28F749A7FE7F8F177C6AA2E9DA609 . 5953024 . . [8.00.6001.23019 (longhorn_ie8_ldr.100503-1800)] . . C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\mshtml.dll
[7] 2010-02-25 06:24:36 . 7054F6ADC9B670887659F1561603B0D0 . 5944832 . . [8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)] . . C:\WINDOWS\ie8updates\KB982381-IE8\mshtml.dll
[7] 2010-02-25 06:19:43 . 974772C74DA7C7A8E7C813A9908A845F . 5946880 . . [8.00.6001.22995 (longhorn_ie8_ldr.100223-0100)] . . C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\mshtml.dll
[7] 2009-12-21 19:14:04 . BE6EEBEF636773A8E7A82214E81C563A . 5942784 . . [8.00.6001.18876 (longhorn_ie8_gdr.091218-1700)] . . C:\WINDOWS\ie8updates\KB980182-IE8\mshtml.dll
[7] 2009-12-21 19:09:28 . E6B64C6C729BBC38AB7CC92CE33F97A5 . 5945856 . . [8.00.6001.22967 (longhorn_ie8_ldr.091219-0100)] . . C:\WINDOWS\$hf_mig$\KB978207-IE8\SP3QFE\mshtml.dll
[7] 2009-10-29 07:45:44 . C0F9AC6FAB2C788FFEE3E69585A0E93F . 5944320 . . [8.00.6001.22945 (longhorn_ie8_ldr.091027-0100)] . . C:\WINDOWS\$hf_mig$\KB976325-IE8\SP3QFE\mshtml.dll
[7] 2009-10-29 07:45:37 . CBB1EF54B86EDB78649909DD1699E5CA . 5940736 . . [8.00.6001.18854 (longhorn_ie8_gdr.091026-1700)] . . C:\WINDOWS\ie8updates\KB978207-IE8\mshtml.dll
[7] 2009-10-22 09:19:04 . CDA69BC1C23B0EA033B989F67CB722FF . 5939712 . . [8.00.6001.18852 (longhorn_ie8_gdr.091020-1827)] . . C:\WINDOWS\ie8updates\KB976325-IE8\mshtml.dll
[7] 2009-10-22 09:18:10 . A6CF28C6E0B6D10098AB601D85EE55E8 . 5943296 . . [8.00.6001.22942 (longhorn_ie8_ldr.091021-0230)] . . C:\WINDOWS\$hf_mig$\KB976749-IE8\SP3QFE\mshtml.dll
[7] 2009-08-29 08:08:20 . 0E49677EE57A928765FC47FFBACD5326 . 5940224 . . [8.00.6001.18828 (longhorn_ie8_gdr.090826-1700)] . . C:\WINDOWS\ie8updates\KB976749-IE8\mshtml.dll
[7] 2009-08-29 08:01:43 . B68F6E6C66D17D9EDABF3D5DA71046DA . 5942272 . . [8.00.6001.22918 (longhorn_ie8_ldr.090827-0100)] . . C:\WINDOWS\$hf_mig$\KB974455-IE8\SP3QFE\mshtml.dll
[7] 2009-07-19 13:18:59 . 5A32B43A48D6DCA339BF24105D9A028F . 5937152 . . [8.00.6001.18812 (longhorn_ie8_gdr.090717-2100)] . . C:\WINDOWS\ie8updates\KB974455-IE8\mshtml.dll
[7] 2009-07-19 13:17:52 . F25D866DD486AD30E05E5596CB363C3E . 5938176 . . [8.00.6001.22902 (longhorn_ie8_ldr.090718-0500)] . . C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE\mshtml.dll
[7] 2009-03-08 08:41:16 . D469A0EBA2EF5C6BEE8065B7E3196E5E . 5937152 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\ie8updates\KB972260-IE8\mshtml.dll
[7] 2009-02-21 07:39:54 . 1BB754AB47B327DE8DBF2FA18C36357C . 3596800 . . [7.00.6000.21015 (vista_ldr.090218-1505)] . . C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\mshtml.dll
[7] 2009-02-20 18:09:37 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825 (vista_gdr.090218-1505)] . . C:\WINDOWS\ERDNT\cache\mshtml.dll
[7] 2009-02-20 18:09:37 . C7C3E41CC2F6EB4A629FE2184136C098 . 3595264 . . [7.00.6000.16825 (vista_gdr.090218-1505)] . . C:\WINDOWS\ie8\mshtml.dll
[7] 2009-01-17 02:35:14 . 3B413267DA8AE71C20E5EF3E54F74728 . 3594752 . . [7.00.6000.16809 (vista_gdr.090114-1504)] . . C:\WINDOWS\ie7updates\KB963027-IE7\mshtml.dll
[7] 2009-01-16 16:24:38 . CC9D001B7370B292C35B366CA05B12B4 . 3596288 . . [7.00.6000.20996 (vista_ldr.090114-1504)] . . C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\mshtml.dll
[7] 2008-12-13 06:40:02 . 121EC39A64D64205A88C2C45B034B455 . 3593216 . . [7.00.6000.16788 (vista_gdr.081211-1619)] . . C:\WINDOWS\ie7updates\KB961260-IE7\mshtml.dll
[7] 2008-12-13 06:26:56 . C79FAD61CD4A26ED5AA8C16D991C6FBD . 3594752 . . [7.00.6000.20973 (vista_ldr.081211-1619)] . . C:\WINDOWS\$hf_mig$\KB960714-IE7\SP2QFE\mshtml.dll
[7] 2008-10-17 07:08:40 . EACAEDEF6FA2A969DE5B36190D45396F . 3593216 . . [7.00.6000.16762 (vista_gdr.081013-1507)] . . C:\WINDOWS\ie7updates\KB960714-IE7\mshtml.dll
[7] 2008-10-16 20:24:10 . B74F31A4BD83797D7A083F922169287D . 3595264 . . [7.00.6000.20935 (vista_ldr.081013-1507)] . . C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\mshtml.dll
[7] 2008-08-27 08:24:32 . 1AD035E04A7068EC2820B055A3131ED8 . 3593216 . . [7.00.6000.16735 (vista_gdr.080820-1506)] . . C:\WINDOWS\ie7updates\KB958215-IE7\mshtml.dll
[7] 2008-08-26 09:08:43 . 25CC085720EE3617FD1F8AB9E2F7CAB2 . 3594752 . . [7.00.6000.20900 (vista_ldr.080820-1506)] . . C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\mshtml.dll
[7] 2008-08-20 05:30:53 . 507BDA42F7DB8209C0F0B3556A043491 . 3067904 . . [6.00.2900.5659 (xpsp_sp3_gdr.080819-1237)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\mshtml.dll
[7] 2008-08-20 04:58:54 . BD45470B132A0F98596277323D9F2E5A . 3067904 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\mshtml.dll
[7] 2008-08-20 04:58:54 . BD45470B132A0F98596277323D9F2E5A . 3067904 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\mshtml.dll
[7] 2008-04-14 12:00:00 . A706E122B398FE1AB85CB9B75D044223 . 3066880 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ie7\mshtml.dll
[7] 2007-08-13 22:54:12 . C6EC2493346ED8888A549F59210A8ED3 . 3578368 . . [7.00.5730.13 (longhorn(wmbla).070711-1130)] . . C:\WINDOWS\ie7updates\KB956390-IE7\mshtml.dll
[-] 2010-05-06 10:41:53 . DE6A3492ABC54F2327CAA43AD17CAD7B . 907264 . . [8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)] . . C:\WINDOWS\system32\wininet.dll
[-] 2010-05-06 10:41:53 . DE6A3492ABC54F2327CAA43AD17CAD7B . 907264 . . [8.00.6001.18923 (longhorn_ie8_gdr.100419-1241)] . . C:\WINDOWS\system32\dllcache\wininet.dll
[7] 2010-05-06 10:36:27 . C1490F68B44AF8B781F52F12F564625D . 919040 . . [8.00.6001.23014 (longhorn_ie8_ldr.100419-1507)] . . C:\WINDOWS\$hf_mig$\KB982381-IE8\SP3QFE\wininet.dll
[7] 2010-02-25 06:24:37 . 7A42CFED96CDA7F2FB1A26D1F9F65775 . 916480 . . [8.00.6001.18904 (longhorn_ie8_gdr.100222-1700)] . . C:\WINDOWS\ie8updates\KB982381-IE8\wininet.dll
[7] 2010-02-25 06:19:44 . 4458D59F2B0369F4D3B137541D284041 . 919040 . . [8.00.6001.22995 (longhorn_ie8_ldr.100223-0100)] . . C:\WINDOWS\$hf_mig$\KB980182-IE8\SP3QFE\wininet.dll
[7] 2009-12-21 19:14:05 . FF4241C74E0C0A5AFFFE05F584213ECB . 916480 . . [8.00.6001.18876 (longhorn_ie8_gdr.091218-1700)] . . C:\WINDOWS\ie8updates\KB980182-IE8\wininet.dll
[7] 2009-12-21 19:09:28 . 5E1F666B8955FD77E65D65C4C4D882A3 . 916480 . . [8.00.6001.22967 (longhorn_ie8_ldr.091219-0100)] . . C:\WINDOWS\$hf_mig$\KB978207-IE8\SP3QFE\wininet.dll
[7] 2009-10-29 07:45:45 . 6AF52998B90F72FF2325D84D90EDA1CC . 916480 . . [8.00.6001.22945 (longhorn_ie8_ldr.091027-0100)] . . C:\WINDOWS\$hf_mig$\KB976325-IE8\SP3QFE\wininet.dll
[7] 2009-10-29 07:45:38 . 75240F6EDBCE7B85DF66874407D38A4F . 916480 . . [8.00.6001.18854 (longhorn_ie8_gdr.091026-1700)] . . C:\WINDOWS\ie8updates\KB978207-IE8\wininet.dll
[7] 2009-08-29 08:08:21 . CF0A5FE05BF614C24950D8FAEC1BC309 . 916480 . . [8.00.6001.18828 (longhorn_ie8_gdr.090826-1700)] . . C:\WINDOWS\ie8updates\KB976325-IE8\wininet.dll
[7] 2009-08-29 08:01:44 . 972B226BDAD71C55F3CC9A72BBF8F1C1 . 916480 . . [8.00.6001.22918 (longhorn_ie8_ldr.090827-0100)] . . C:\WINDOWS\$hf_mig$\KB974455-IE8\SP3QFE\wininet.dll
[7] 2009-07-03 17:09:28 . 7E8A47A2E6561274B83E257CE74803FD . 915456 . . [8.00.6001.18806 (longhorn_ie8_gdr.090701-1700)] . . C:\WINDOWS\ie8updates\KB974455-IE8\wininet.dll
[7] 2009-07-03 17:06:51 . 38114DAB42FB2EB84D1726C42B8D80C5 . 915456 . . [8.00.6001.22896 (longhorn_ie8_ldr.090702-0100)] . . C:\WINDOWS\$hf_mig$\KB972260-IE8\SP3QFE\wininet.dll
[7] 2009-03-08 08:34:58 . 6CE32F7778061CCC5814D5E0F282D369 . 914944 . . [8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)] . . C:\WINDOWS\ie8updates\KB972260-IE8\wininet.dll
[7] 2009-03-03 00:18:25 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827 (vista_gdr.090226-1506)] . . C:\WINDOWS\ERDNT\cache\wininet.dll
[7] 2009-03-03 00:18:25 . 28775945CCD53DEE280EF58DEA1A94C4 . 826368 . . [7.00.6000.16827 (vista_gdr.090226-1506)] . . C:\WINDOWS\ie8\wininet.dll
[7] 2009-03-03 00:17:40 . C8667854873938CA13C986F16B0CD183 . 828416 . . [7.00.6000.21020 (vista_ldr.090226-1506)] . . C:\WINDOWS\$hf_mig$\KB963027-IE7\SP3QFE\wininet.dll
[7] 2008-12-20 23:56:00 . 044E0A4E9FE97C0FB9AFE9C89E2A82E6 . 827904 . . [7.00.6000.20978 (vista_ldr.081217-1620)] . . C:\WINDOWS\$hf_mig$\KB961260-IE7\SP2QFE\wininet.dll
[7] 2008-12-20 23:15:41 . A82935D32D0672E8FF4E91AE398E901C . 826368 . . [7.00.6000.16791 (vista_gdr.081217-1620)] . . C:\WINDOWS\ie7updates\KB963027-IE7\wininet.dll
[7] 2008-10-16 20:38:40 . 6741EAF7B7F110E803A6E38F6E5FA6B0 . 826368 . . [7.00.6000.16762 (vista_gdr.081013-1507)] . . C:\WINDOWS\ie7updates\KB961260-IE7\wininet.dll
[7] 2008-10-16 20:24:11 . 0D5B75171FF51775B630A431B6C667E8 . 827904 . . [7.00.6000.20935 (vista_ldr.081013-1507)] . . C:\WINDOWS\$hf_mig$\KB958215-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 09:08:45 . 77C192FE56A70D7FA0247BA0A6201C32 . 827904 . . [7.00.6000.20900 (vista_ldr.080820-1506)] . . C:\WINDOWS\$hf_mig$\KB956390-IE7\SP2QFE\wininet.dll
[7] 2008-08-26 07:24:31 . EF8EBA98145BFA44E80D17A3B3453300 . 826368 . . [7.00.6000.16735 (vista_gdr.080820-1506)] . . C:\WINDOWS\ie7updates\KB958215-IE7\wininet.dll
[7] 2008-08-20 05:30:51 . 9AF5F25124FBDC36E2B510729CBA2674 . 666112 . . [6.00.2900.5659 (xpsp_sp3_gdr.080819-1237)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3gdr\wininet.dll
[7] 2008-08-20 04:58:48 . 94418F53D2612C26DBADC04DAFBC197C . 666624 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\$hf_mig$\KB956390\SP3QFE\wininet.dll
[7] 2008-08-20 04:58:48 . 94418F53D2612C26DBADC04DAFBC197C . 666624 . . [6.00.2900.5659 (xpsp_sp3_qfe.080819-1352)] . . C:\WINDOWS\SoftwareDistribution\Download\1185bc01976431096846a9c917b224df\sp3qfe\wininet.dll
[7] 2008-04-14 12:00:00 . 7A4F775ABB2F1C97DEF3E73AFA2FAEDD . 666112 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ie7\wininet.dll
[7] 2007-08-13 22:54:10 . A4A0FC92358F39538A6494C42EF99FE9 . 818688 . . [7.00.5730.13 (longhorn(wmbla).070711-1130)] . . C:\WINDOWS\ie7updates\KB956390-IE7\wininet.dll
[-] 2008-04-14 12:00:00 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\explorer.exe
[7] 2008-04-14 12:00:00 . 12896823FB95BFB3DC9B46BCAEDC9923 . 1033728 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\ERDNT\cache\explorer.exe
[-] 2008-04-14 12:00:00 . 561A50497324F378E30F55D09B4E1258 . 975872 . . [6.00.2900.5512 (xpsp.080413-2105)] . . C:\WINDOWS\system32\dllcache\explorer.exe
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]
@="{C5994560-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]
@="{C5994561-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]
@="{C5994562-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]
@="{C5994563-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]
@="{C5994564-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]
@="{C5994565-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]
@="{C5994566-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]
@="{C5994567-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]
@="{C5994568-53D9-4125-87C9-F193FC689CB2}"
[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]
2009-08-13 23:55:46 85768 ----a-w- C:\Program Files\Common Files\TortoiseOverlays\TortoiseOverlays.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Pando Media Booster"="C:\Program Files\Pando Networks\Media Booster\PMB.exe" [2010-02-06 23:12:52 2937528]
"Steam"="c:\program files\steamm\steam.exe" [2010-05-08 14:50:53 1238352]
"DAEMON Tools Lite"="C:\Program Files\DAEMON Tools Lite\DTLite.exe" [2009-10-30 11:57:08 369200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2008-09-18 04:55:00 13574144]
"AdobeCS4ServiceManager"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 11:58:34 611712]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2009-05-26 21:18:30 413696]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2009-07-13 18:03:10 292128]
"Ad-Watch"="C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe" [2010-03-01 14:48:16 524632]
"ULiRaid"="C:\Program Files\ULiRaid\ULiRaid.exe" [2006-05-12 18:57:40 630784]
"SunJavaUpdateSched"="C:\Program Files\Common Files\Java\Java Update\jusched.exe" [2010-01-11 20:21:52 246504]
"LogMeIn Hamachi Ui"="C:\Program Files\LogMeIn Hamachi\hamachi-2-ui.exe" [2010-03-30 15:16:16 1820040]
"Flashget"="C:\Program Files\FlashGet\FlashGet.exe" [2007-09-25 08:10:50 2007088]
"mcui_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2010-04-02 03:05:04 1180976]
C:\Documents and Settings\Alan\Start Menu\Programs\Startup\
crisisx_updater.jar [2010-4-1 53790]
LimeWire On Startup.lnk - C:\Program Files\LimeWire\LimeWire.exe [2010-5-26 503808]
TransBar.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\TransBar\TransBar.exe [2005-6-1 65536]
UberIcon.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\UberIcon\UberIcon Manager.exe [2006-5-21 180224]
Y'z Shadow.lnk - C:\WINDOWS\BricoPacks\Vista Inspirat 2\YzShadow\YzShadow.exe [2006-5-21 155648]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 02:41:34 304128]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WB]
2001-12-21 04:34:52 24576 ----a-w- C:\Program Files\AlienGUIse\fastload.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\WINDOWS\system32\wbsys.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^Alan^Start Menu^Programs^Startup^Xfire.lnk]
path=C:\Documents and Settings\Alan\Start Menu\Programs\Startup\Xfire.lnk
backup=C:\WINDOWS\pss\Xfire.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Snagit 9.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
backup=C:\WINDOWS\pss\Snagit 9.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Search.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
backup=C:\WINDOWS\pss\Windows Search.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis Scheduler2 Service]
2008-11-06 01:08:55 65536 -c--a-w- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acronis True Image Monitor]
2008-11-06 01:08:55 471637 -c--a-w- C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
2008-06-12 07:38:00 34672 -c--a-w- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 12:00:00 15360 ------w- C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
2004-07-27 21:50:42 221184 -c--a-w- C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
2004-07-27 21:50:18 81920 -c--a-w- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\itype]
2007-08-31 19:13:41 988584 -c--a-w- C:\Program Files\Microsoft IntelliType Pro\itype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\mcagent_exe]
2010-04-02 03:05:04 1180976 ----a-w- C:\Program Files\McAfee.com\Agent\mcagent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2008-09-18 04:55:00 13574144 ----a-w- C:\WINDOWS\system32\nvcpl.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2008-09-18 04:55:00 86016 -c--a-w- C:\WINDOWS\system32\nvmctray.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2008-09-18 04:55:00 1657376 -c--a-w- C:\WINDOWS\system32\nwiz.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
2003-11-01 00:42:40 32768 -c----w- C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RoxioDragToDisc]
2006-08-17 14:00:00 1116920 -c--a-w- C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
2004-07-27 22:01:36 68096 -c--a-w- C:\WINDOWS\SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Start WingMan Profiler]
2008-04-04 16:38:00 88584 -c--a-w- C:\Program Files\Logitech\Gaming Software\LWEMon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"C:\\Program Files\\EA GAMES\\Battlefield 2\\BF2.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"C:\\Program Files\\Xfire\\xfire.exe"=
"C:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"C:\\Documents and Settings\\All Users\\Application Data\\NexonUS\\NGM\\NGM.exe"=
"C:\\Program Files\\Common Files\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"C:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"C:\\Program Files\\iTunes\\iTunes.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"C:\\Program Files\\Steamm\\Steam.exe"=
"C:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=
"C:\\Program Files\\Pando Networks\\Media Booster\\PMB.exe"=
"C:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"C:\\Program Files\\FlashGet\\flashget.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"C:\\Program Files\\World of Warcraft\\Launcher.exe"=
"C:\\Program Files\\World of Warcraft\\WoW-3.2.0.10192-to-3.3.0.10958-enUS-downloader.exe"=
"C:\\Documents and Settings\\Alan\\Application Data\\Octoshape\\Octoshape Streaming Services\\OctoshapeClient.exe"=
"C:\\Program Files\\Common Files\\McAfee\\McSvcHost\\McSvHost.exe"=
"C:\\Program Files\\Steamm\\steamapps\\basketcase378\\garrysmod\\hl2.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\Program Files\\Steamm\\steamapps\\soarrin211\\condition zero\\hl.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"57640:TCP"= 57640:TCP:*:Disabled:Pando Media Booster
"57640:UDP"= 57640:UDP:*:Disabled:Pando Media Booster
"56630:TCP"= 56630:TCP:*:Disabled:Pando Media Booster
"56630:UDP"= 56630:UDP:*:Disabled:Pando Media Booster
"56494:TCP"= 56494:TCP:*:Disabled:Pando Media Booster
"56494:UDP"= 56494:UDP:*:Disabled:Pando Media Booster
"86:TCP"= 86:TCP:BroadCam Web Server
"5353:TCP"= 5353:TCP:Adobe CSI CS4
"58485:TCP"= 58485:TCP:Pando Media Booster
"58485:UDP"= 58485:UDP:Pando Media Booster
"58082:TCP"= 58082:TCP:Pando Media Booster
"58082:UDP"= 58082:UDP:Pando Media Booster
R0 JAHCI;JAHCI;C:\WINDOWS\system32\drivers\JAHCI.sys [11/5/2008 8:53:02 PM 33280]
R0 Lbd;Lbd;C:\WINDOWS\system32\drivers\Lbd.sys [7/24/2009 9:48:45 AM 64160]
R0 m5289;m5289;C:\WINDOWS\system32\drivers\m5289.sys [11/2/2009 8:50:08 AM 52480]
R1 mfetdi2k;McAfee Inc. mfetdi2k;C:\WINDOWS\system32\drivers\mfetdi2k.sys [5/2/2010 9:42:44 PM 82952]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;C:\Program Files\LogMeIn Hamachi\hamachi-2.exe [3/30/2010 11:16:12 AM 1107336]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [3/9/2009 3:06:55 PM 1029456]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;C:\Program Files\McAfee\SiteAdvisor\McSACore.exe [10/10/2009 1:24:28 PM 93320]
R2 McMPFSvc;McAfee Personal Firewall;"C:\Program Files\Common Files\Mcafee\McSvcHost\McSvHost.exe" /McCoreSvc [5/2/2010 9:42:35 PM 271480]
R2 McNaiAnn;McAfee VirusScan Announcer;"C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe" /McCoreSvc [5/2/2010 9:42:35 PM 271480]
R2 mfefire;McAfee Firewall Core Service;C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe [5/2/2010 9:42:55 PM 188136]
R2 mfevtp;McAfee Validation Trust Protection Service;C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [5/2/2010 9:42:45 PM 141792]
R3 cfwids;McAfee Inc. cfwids;C:\WINDOWS\system32\drivers\cfwids.sys [5/2/2010 9:42:44 PM 55456]
R3 libusb0;LibUsb-Win32 - Kernel Driver, Version 0.1.12.1;C:\WINDOWS\system32\drivers\libusb0.sys [7/23/2009 8:28:34 PM 28672]
R3 mfefirek;McAfee Inc. mfefirek;C:\WINDOWS\system32\drivers\mfefirek.sys [5/2/2010 9:42:44 PM 312616]
R3 mfendiskmp;mfendiskmp;C:\WINDOWS\system32\drivers\mfendisk.sys [5/2/2010 9:42:44 PM 88480]
R3 ULI5261XP;ULi M526X Ethernet NT Driver;C:\WINDOWS\system32\drivers\ULILAN51.SYS [10/20/2008 10:11:22 PM 28672]
S0 sptd;sptd;C:\WINDOWS\system32\drivers\sptd.sys [10/31/2009 11:23:09 PM 691696]
S3 BroadCamService;BroadCam Service;C:\Program Files\NCH Software\BroadCam\broadCam.exe [6/16/2009 9:27:32 PM 368644]
S3 GarenaPEngine;GarenaPEngine;\??\C:\DOCUME~1\Alan\LOCALS~1\Temp\UAK27D.tmp --> C:\DOCUME~1\Alan\LOCALS~1\Temp\UAK27D.tmp [?]
S3 mfendisk;McAfee Core NDIS Intermediate Filter;C:\WINDOWS\system32\drivers\mfendisk.sys [5/2/2010 9:42:44 PM 88480]
S3 mferkdet;McAfee Inc. mferkdet;C:\WINDOWS\system32\drivers\mferkdet.sys [5/2/2010 9:42:44 PM 83496]
S3 npggsvc;nProtect GameGuard Service;C:\WINDOWS\system32\GameMon.des -service --> C:\WINDOWS\system32\GameMon.des -service [?]
S4 MSSQLServerADHelper100;SQL Active Directory Helper Service;C:\Program Files\Microsoft SQL Server\100\Shared\sqladhlp.exe [7/10/2008 8:28:04 PM 47128]
S4 msvsmon80;Visual Studio 2005 Remote Debugger;C:\Program Files\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [9/23/2005 8:01:16 AM 2799808]
S4 RsFx0102;RsFx0102 Driver;C:\WINDOWS\system32\drivers\RsFx0102.sys [7/10/2008 2:49:14 AM 242712]
S4 SQLAgent$SQLEXPRESS;SQL Server Agent (SQLEXPRESS);C:\Program Files\Microsoft SQL Server\MSSQL10.SQLEXPRESS\MSSQL\Binn\SQLAGENT.EXE [7/10/2008 8:28:06 PM 369688]
--- Other Services/Drivers In Memory ---
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
2010-06-21 C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
- C:\Program Files\Lavasoft\Ad-Aware\Ad-AwareAdmin.exe [2009-03-09 19:06:56 . 2010-03-01 14:48:17]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.ca/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://search.yahoo.com/search?fr=mcafee&p=%s
IE: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htm
IE: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htm
IE: &Google Search - C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
IE: Backward Links - C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
IE: Similar Pages - C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate into English - C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
Trusted Zone: internet
Trusted Zone: mcafee.com
FF - ProfilePath - C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\
FF - prefs.js: browser.search.selectedEngine - Secure Search
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/
FF - prefs.js: keyword.URL - hxxp://search.yahoo.com/search?fr=mcafee&p=
FF - component: C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{0b457cAA-602d-484a-8fe7-c1d894a011ba}\platform\WINNT_x86-msvc\components\SSSLauncher.dll
FF - component: C:\Documents and Settings\Alan\Application Data\Mozilla\Firefox\Profiles\5mxin21v.default\extensions\{81BF1D23-5F17-408D-AC6B-BD6DF7CAF670}\components\XpcomOpusConnector.dll
FF - component: C:\Program Files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: C:\Documents and Settings\Alan\Application Data\Mozilla\plugins\npoctoshape.dll
FF - plugin: C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\npNxGameUS.dll
FF - plugin: C:\Program Files\McAfee\Supportability\MVT\NPMVTPlugin.dll
FF - plugin: C:\Program Files\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiautoinstallpluginff.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiCHPlugin.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npijjiFFPlugin1.dll
FF - plugin: C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
FF - plugin: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: yahoo.homepage.dontask - trueC:\Program Files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
C:\Program Files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pref", true);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
C:\Program Files\Mozilla Firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
C:\Program Files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
.
- - - - ORPHANS REMOVED - - - -
WebBrowser-{8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - (no file)
MSConfigStartUp-AbyssWebServer - C:\Documents and Settings\Alan\Desktop\UberRO\Server\Abyss Web Server\abyssws.exe
MSConfigStartUp-Steam - C:\Program Files\Steam\Steam.exe
MSConfigStartUp-SunJavaUpdateSched - C:\Documents and Settings\Alan\Desktop\UberScape\bin\jusched.exe
Last edited by mattferd on 22nd June 2010, 10:22 pm; edited 1 time in total (Reason for editing : Explaining my problem with ComboFix)