Here you go!
ComboFix 09-04-30.02 - Mitchel 04/30/2009 17:42.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1535.1148 [GMT -4:00]
Running from: E:\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guest\Application Data\ShoppingReport
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\LocalService\protect.dll
c:\documents and settings\Mitchel\protect.dll
c:\documents and settings\Mitchel\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\Mitchel\Start Menu\Programs\Startup\ChkDisk.lnk
c:\program files\A360
c:\program files\INSTALL.LOG
c:\program files\Need2Find
c:\program files\Need2Find\bar\History\search
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\windows\Fonts\acrsecB.fon
c:\windows\Fonts\acrsecI.fon
c:\windows\sysguard.exe
c:\windows\system32\__c005DF9A.dat
c:\windows\system32\ak1.exe
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\frmwrk32.exe
c:\windows\system32\ftp_non_crp.exe
c:\windows\system32\lmppcsetup.exe
c:\windows\system32\loader49.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\ovfsthxdotehtkb.dll
c:\windows\system32\ovfsthxgvpawoll.dat
c:\windows\system32\ovfsthxltobxgww.dat
c:\windows\system32\ovfsthxqbwsmfss.dll
c:\windows\system32\ovfsthxsrqpardl.dll
c:\windows\system32\p2hhr.bat
c:\windows\system32\sdra64.exe
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
c:\windows\system32\winglsetup.exe
c:\windows\system32\yhs783ijfo3fe.dll
c:\windows\Temp\tmp3.tmp
C:\xcrashdump.dat
Infected copy of c:\windows\system32\sfcfiles.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_NETDDEDSMA
-------\Legacy_OREANS32
-------\Legacy_SFC
-------\Service_MyWebSearchService
-------\Service_NetDDEdsma
-------\Service_oreans32
-------\Service_sfc
((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 )))))))))))))))))))))))))))))))
.
2009-04-30 17:39 . 2009-04-30 17:39 266 ----a-w C:\avexport.bat
2009-04-29 22:21 . 2009-03-24 20:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-29 22:21 . 2009-04-29 22:21 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-04-29 22:21 . 2009-04-29 22:21 -------- d-----w c:\program files\Avira
2009-04-29 03:57 . 2009-04-29 03:57 -------- d-----w c:\program files\Trend Micro
2009-04-29 00:34 . 2007-03-29 12:56 7168 -c----w c:\windows\system32\dllcache\bitsprx4.dll
2009-04-29 00:34 . 2007-03-29 12:56 7168 ------w c:\windows\system32\bitsprx4.dll
2009-04-29 00:34 . 2007-03-29 12:56 18944 -c----w c:\windows\system32\dllcache\qmgrprxy.dll
2009-04-29 00:34 . 2007-03-29 12:56 409600 -c----w c:\windows\system32\dllcache\qmgr.dll
2009-04-24 02:16 . 2009-04-24 02:16 -------- d-----w c:\documents and settings\Mitchel\Local Settings\Application Data\PunkBuster
2009-04-21 18:09 . 2009-04-21 18:09 -------- d-----w c:\program files\KingsIsle Entertainment
2009-04-14 22:42 . 2009-03-06 14:44 283648 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 22:42 . 2005-07-26 04:39 60416 -c----w c:\windows\system32\dllcache\colbact.dll
2009-04-14 22:42 . 2009-02-09 10:20 399360 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 22:42 . 2009-02-06 17:14 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 22:42 . 2009-02-09 10:20 473088 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 22:42 . 2009-02-06 16:39 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 22:42 . 2009-02-09 10:20 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 22:42 . 2009-02-09 10:20 616960 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 22:42 . 2009-02-09 10:20 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 22:41 . 2008-04-21 10:02 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-10 02:57 . 2009-04-10 02:57 -------- d-----w c:\program files\InterActual
2009-04-01 16:05 . 2009-04-30 20:52 -------- d-----w c:\program files\Windows Live Safety Center
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 15:23 . 2006-10-29 16:22 -------- d-----w c:\program files\Lx_cats
2009-04-24 02:30 . 2007-11-15 11:00 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-24 02:17 . 2007-11-15 11:00 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-24 02:17 . 2007-11-15 10:59 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-04-21 18:09 . 2005-06-07 15:42 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-29 00:45 . 2008-04-03 21:28 -------- d-----w c:\program files\LimeWire
2009-03-06 14:44 . 2003-07-16 20:41 283648 ------w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-02-18 20:19 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 ------w c:\windows\system32\ieencode.dll
2009-02-09 10:20 . 2005-01-14 05:33 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2003-07-16 20:32 723456 ------w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2003-07-16 20:39 714752 ------w c:\windows\system32\ntdll.dll
2009-02-09 10:20 . 2003-07-16 20:23 616960 ------w c:\windows\system32\advapi32.dll
2009-02-09 10:19 . 2003-07-16 20:51 1846272 ------w c:\windows\system32\win32k.sys
2009-02-06 17:22 . 2003-07-16 20:39 2136064 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 17:14 . 2003-07-16 20:44 110592 ------w c:\windows\system32\services.exe
2009-02-06 16:54 . 2003-07-16 20:43 35328 ------w c:\windows\system32\sc.exe
2009-02-06 16:49 . 2002-08-29 01:04 2015744 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 20:08 . 2003-07-16 20:44 55808 ----a-w c:\windows\system32\secur32.dll
2006-05-13 00:32 . 2006-05-13 00:32 774144 ----a-w c:\program files\RngInterstitial.dll
2005-07-22 20:45 . 2005-07-22 20:45 39 -c--a-w c:\program files\guest.txt
2005-07-22 20:44 . 2005-07-18 17:48 452 -c--a-w c:\program files\deb.log
2005-07-22 20:44 . 2005-07-18 17:53 297 -c--a-w c:\program files\interface_cfg.txt
2005-07-22 20:44 . 2005-07-18 17:53 109 -c--a-w c:\program files\card_cfg.txt
2005-07-22 20:44 . 2005-07-18 17:47 4060 -c--a-w c:\program files\cfg.txt
2005-04-30 15:49 . 2005-07-18 17:46 16228 -c--a-w c:\program files\README.txt
2005-04-30 15:24 . 2005-07-18 17:48 1454080 -c--a-w c:\program files\LFS.exe
2007-09-16 06:35 . 2008-06-28 19:36 66408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 . 2008-06-28 19:36 54112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 . 2008-06-28 19:36 34688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 . 2008-06-28 19:36 46456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 . 2008-06-28 19:36 171880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"E6TaskPanel"="c:\program files\EarthLink TotalAccess\TaskPanl.exe" [2005-03-05 942080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-17 4800512]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"LXCJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [2005-09-08 73728]
"lxcjmon.exe"="c:\program files\Lexmark 8300 Series\lxcjmon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 8300 Series\ezprint.exe" [2005-08-01 94208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
c:\documents and settings\Computer1\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-3-10 139776]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
MiniEYE-MiniREAD Launch.lnk - c:\program files\Infinite Mind LC\eyeQ\ARLaunch.exe [2006-4-8 323584]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll
"wave5"= serwvdrv.dll
"wave6"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\Mitchel\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
S2 litsgt;litsgt;c:\windows\system32\DRIVERS\litsgt.sys [2006-04-09 137344]
S2 tansgt;tansgt;c:\windows\system32\DRIVERS\tansgt.sys [2006-04-09 12032]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]
ComboFix 09-04-30.02 - Mitchel 04/30/2009 17:42.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1535.1148 [GMT -4:00]
Running from: E:\ComboFix.exe
AV: AntiVir Desktop *On-access scanning disabled* (Outdated)
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Guest\Application Data\ShoppingReport
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\Config.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\db\Aliases.dbs
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\db\Sites.dbs
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\dwld\WhiteList.xip
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\report\aggr_storage.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\report\send_storage.xml
c:\documents and settings\Guest\Application Data\ShoppingReport\cs\res1\WhiteList.dbs
c:\documents and settings\LocalService\protect.dll
c:\documents and settings\Mitchel\protect.dll
c:\documents and settings\Mitchel\Start Menu\Programs\Startup\ChkDisk.dll
c:\documents and settings\Mitchel\Start Menu\Programs\Startup\ChkDisk.lnk
c:\program files\A360
c:\program files\INSTALL.LOG
c:\program files\Need2Find
c:\program files\Need2Find\bar\History\search
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013
c:\recycler\S-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini
c:\windows\Fonts\acrsecB.fon
c:\windows\Fonts\acrsecI.fon
c:\windows\sysguard.exe
c:\windows\system32\__c005DF9A.dat
c:\windows\system32\ak1.exe
c:\windows\system32\autochk.dll
c:\windows\system32\config\systemprofile\protect.dll
c:\windows\system32\frmwrk32.exe
c:\windows\system32\ftp_non_crp.exe
c:\windows\system32\lmppcsetup.exe
c:\windows\system32\loader49.exe
c:\windows\system32\lowsec
c:\windows\system32\lowsec\local.ds
c:\windows\system32\lowsec\user.ds
c:\windows\system32\lowsec\user.ds.lll
c:\windows\system32\ovfsthxdotehtkb.dll
c:\windows\system32\ovfsthxgvpawoll.dat
c:\windows\system32\ovfsthxltobxgww.dat
c:\windows\system32\ovfsthxqbwsmfss.dll
c:\windows\system32\ovfsthxsrqpardl.dll
c:\windows\system32\p2hhr.bat
c:\windows\system32\sdra64.exe
c:\windows\system32\uniq.tll
c:\windows\system32\win32hlp.cnf
c:\windows\system32\winglsetup.exe
c:\windows\system32\yhs783ijfo3fe.dll
c:\windows\Temp\tmp3.tmp
C:\xcrashdump.dat
Infected copy of c:\windows\system32\sfcfiles.dll was found and disinfected
Restored copy from - c:\windows\ServicePackFiles\i386\sfcfiles.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_MYWEBSEARCHSERVICE
-------\Legacy_NETDDEDSMA
-------\Legacy_OREANS32
-------\Legacy_SFC
-------\Service_MyWebSearchService
-------\Service_NetDDEdsma
-------\Service_oreans32
-------\Service_sfc
((((((((((((((((((((((((( Files Created from 2009-03-28 to 2009-04-30 )))))))))))))))))))))))))))))))
.
2009-04-30 17:39 . 2009-04-30 17:39 266 ----a-w C:\avexport.bat
2009-04-29 22:21 . 2009-03-24 20:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-04-29 22:21 . 2009-04-29 22:21 -------- d-----w c:\documents and settings\All Users\Application Data\Avira
2009-04-29 22:21 . 2009-04-29 22:21 -------- d-----w c:\program files\Avira
2009-04-29 03:57 . 2009-04-29 03:57 -------- d-----w c:\program files\Trend Micro
2009-04-29 00:34 . 2007-03-29 12:56 7168 -c----w c:\windows\system32\dllcache\bitsprx4.dll
2009-04-29 00:34 . 2007-03-29 12:56 7168 ------w c:\windows\system32\bitsprx4.dll
2009-04-29 00:34 . 2007-03-29 12:56 18944 -c----w c:\windows\system32\dllcache\qmgrprxy.dll
2009-04-29 00:34 . 2007-03-29 12:56 409600 -c----w c:\windows\system32\dllcache\qmgr.dll
2009-04-24 02:16 . 2009-04-24 02:16 -------- d-----w c:\documents and settings\Mitchel\Local Settings\Application Data\PunkBuster
2009-04-21 18:09 . 2009-04-21 18:09 -------- d-----w c:\program files\KingsIsle Entertainment
2009-04-14 22:42 . 2009-03-06 14:44 283648 -c----w c:\windows\system32\dllcache\pdh.dll
2009-04-14 22:42 . 2005-07-26 04:39 60416 -c----w c:\windows\system32\dllcache\colbact.dll
2009-04-14 22:42 . 2009-02-09 10:20 399360 -c----w c:\windows\system32\dllcache\rpcss.dll
2009-04-14 22:42 . 2009-02-06 17:14 110592 -c----w c:\windows\system32\dllcache\services.exe
2009-04-14 22:42 . 2009-02-09 10:20 473088 -c----w c:\windows\system32\dllcache\fastprox.dll
2009-04-14 22:42 . 2009-02-06 16:39 227840 -c----w c:\windows\system32\dllcache\wmiprvse.exe
2009-04-14 22:42 . 2009-02-09 10:20 453120 -c----w c:\windows\system32\dllcache\wmiprvsd.dll
2009-04-14 22:42 . 2009-02-09 10:20 616960 -c----w c:\windows\system32\dllcache\advapi32.dll
2009-04-14 22:42 . 2009-02-09 10:20 714752 -c----w c:\windows\system32\dllcache\ntdll.dll
2009-04-14 22:41 . 2008-04-21 10:02 215552 -c----w c:\windows\system32\dllcache\wordpad.exe
2009-04-10 02:57 . 2009-04-10 02:57 -------- d-----w c:\program files\InterActual
2009-04-01 16:05 . 2009-04-30 20:52 -------- d-----w c:\program files\Windows Live Safety Center
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-04-26 15:23 . 2006-10-29 16:22 -------- d-----w c:\program files\Lx_cats
2009-04-24 02:30 . 2007-11-15 11:00 189072 ----a-w c:\windows\system32\PnkBstrB.exe
2009-04-24 02:17 . 2007-11-15 11:00 138920 ----a-w c:\windows\system32\drivers\PnkBstrK.sys
2009-04-24 02:17 . 2007-11-15 10:59 75064 ----a-w c:\windows\system32\PnkBstrA.exe
2009-04-21 18:09 . 2005-06-07 15:42 -------- d--h--w c:\program files\InstallShield Installation Information
2009-03-29 00:45 . 2008-04-03 21:28 -------- d-----w c:\program files\LimeWire
2009-03-06 14:44 . 2003-07-16 20:41 283648 ------w c:\windows\system32\pdh.dll
2009-03-03 00:18 . 2005-02-18 20:19 826368 ----a-w c:\windows\system32\wininet.dll
2009-02-20 18:09 . 2004-08-04 07:56 78336 ------w c:\windows\system32\ieencode.dll
2009-02-09 10:20 . 2005-01-14 05:33 399360 ----a-w c:\windows\system32\rpcss.dll
2009-02-09 10:20 . 2003-07-16 20:32 723456 ------w c:\windows\system32\lsasrv.dll
2009-02-09 10:20 . 2003-07-16 20:39 714752 ------w c:\windows\system32\ntdll.dll
2009-02-09 10:20 . 2003-07-16 20:23 616960 ------w c:\windows\system32\advapi32.dll
2009-02-09 10:19 . 2003-07-16 20:51 1846272 ------w c:\windows\system32\win32k.sys
2009-02-06 17:22 . 2003-07-16 20:39 2136064 ----a-w c:\windows\system32\ntoskrnl.exe
2009-02-06 17:14 . 2003-07-16 20:44 110592 ------w c:\windows\system32\services.exe
2009-02-06 16:54 . 2003-07-16 20:43 35328 ------w c:\windows\system32\sc.exe
2009-02-06 16:49 . 2002-08-29 01:04 2015744 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-02-03 20:08 . 2003-07-16 20:44 55808 ----a-w c:\windows\system32\secur32.dll
2006-05-13 00:32 . 2006-05-13 00:32 774144 ----a-w c:\program files\RngInterstitial.dll
2005-07-22 20:45 . 2005-07-22 20:45 39 -c--a-w c:\program files\guest.txt
2005-07-22 20:44 . 2005-07-18 17:48 452 -c--a-w c:\program files\deb.log
2005-07-22 20:44 . 2005-07-18 17:53 297 -c--a-w c:\program files\interface_cfg.txt
2005-07-22 20:44 . 2005-07-18 17:53 109 -c--a-w c:\program files\card_cfg.txt
2005-07-22 20:44 . 2005-07-18 17:47 4060 -c--a-w c:\program files\cfg.txt
2005-04-30 15:49 . 2005-07-18 17:46 16228 -c--a-w c:\program files\README.txt
2005-04-30 15:24 . 2005-07-18 17:48 1454080 -c--a-w c:\program files\LFS.exe
2007-09-16 06:35 . 2008-06-28 19:36 66408 ----a-w c:\program files\mozilla firefox\components\jar50.dll
2007-09-16 06:35 . 2008-06-28 19:36 54112 ----a-w c:\program files\mozilla firefox\components\jsd3250.dll
2007-09-16 06:35 . 2008-06-28 19:36 34688 ----a-w c:\program files\mozilla firefox\components\myspell.dll
2007-09-16 06:35 . 2008-06-28 19:36 46456 ----a-w c:\program files\mozilla firefox\components\spellchk.dll
2007-09-16 06:35 . 2008-06-28 19:36 171880 ----a-w c:\program files\mozilla firefox\components\xpinstal.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]
"Yahoo! Pager"="c:\program files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2008-01-28 2097488]
"E6TaskPanel"="c:\program files\EarthLink TotalAccess\TaskPanl.exe" [2005-03-05 942080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="c:\windows\System32\NvCpl.dll" [2003-10-17 4800512]
"diagent"="c:\program files\Creative\SBLive\Diagnostics\diagent.exe" [2002-04-03 135264]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"SunJavaUpdateSched"="c:\program files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"LXCJCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXCJtime.dll" [2005-09-08 73728]
"lxcjmon.exe"="c:\program files\Lexmark 8300 Series\lxcjmon.exe" [2005-09-30 200704]
"EzPrint"="c:\program files\Lexmark 8300 Series\ezprint.exe" [2005-08-01 94208]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2008-07-10 116040]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2008-05-27 413696]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2008-07-30 289064]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2008-04-17 9117696]
c:\documents and settings\Computer1\Start Menu\Programs\Startup\
Adobe Gamma.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2009-3-10 139776]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-3-16 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-9-23 29696]
MiniEYE-MiniREAD Launch.lnk - c:\program files\Infinite Mind LC\eyeQ\ARLaunch.exe [2006-4-8 323584]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSetActiveDesktop"= 1 (0x1)
HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32
"wave"= serwvdrv.dll
"wave2"= serwvdrv.dll
"wave3"= serwvdrv.dll
"wave4"= serwvdrv.dll
"wave5"= serwvdrv.dll
"wave6"= serwvdrv.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WdfLoadGroup]
@=""
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\LimeWire\\LimeWire.exe"=
"c:\\Program Files\\EA GAMES\\Battlefield 1942\\BF1942.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\America's Army\\System\\ArmyOps.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\Program Files\\Xfire\\Xfire.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\WINDOWS\\system32\\dxdiag.exe"=
"c:\\WINDOWS\\system32\\dpnsvr.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"c:\\Program Files\\Opera\\Opera.exe"=
"c:\\WINDOWS\\system32\\PnkBstrA.exe"=
"c:\\WINDOWS\\system32\\PnkBstrB.exe"=
"c:\\Program Files\\Activision\\Call of Duty 4 - Modern Warfare\\iw3mp.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\MSN Messenger\\msnmsgr.exe"=
"c:\\Program Files\\MSN Messenger\\livecall.exe"=
"c:\\Documents and Settings\\Mitchel\\Application Data\\mjusbsp\\magicJack.exe"=
"c:\\Program Files\\MySpace\\IM\\MySpaceIM.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"8097:TCP"= 8097:TCP:EarthLink UHP Modem Support
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
S2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289]
S2 litsgt;litsgt;c:\windows\system32\DRIVERS\litsgt.sys [2006-04-09 137344]
S2 tansgt;tansgt;c:\windows\system32\DRIVERS\tansgt.sys [2006-04-09 12032]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
.
Contents of the 'Scheduled Tasks' folder
2009-04-21 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-04-11 16:34]