.
((((((((((((((((((((((((( Files Created from 2009-04-28 to 2009-05-31 )))))))))))))))))))))))))))))))
.
2009-05-30 19:15 . 2009-05-26 19:20 40160 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-30 19:15 . 2009-05-30 19:15 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-05-30 19:15 . 2009-05-30 19:15 -------- d-----w c:\documents and settings\All Users\Application Data\Malwarebytes
2009-05-30 19:15 . 2009-05-26 19:19 19096 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-30 19:01 . 2009-05-30 19:01 -------- d-----w c:\documents and settings\Khank\Application Data\Sunbelt
2009-05-30 19:01 . 2009-05-30 19:01 -------- d-----w c:\documents and settings\All Users\Application Data\Sunbelt
2009-05-30 19:00 . 2009-05-30 19:00 -------- d-----w c:\program files\Sunbelt Software
2009-05-29 19:04 . 2009-05-29 19:04 -------- d-----w c:\program files\Trend Micro
2009-05-27 13:48 . 2009-05-27 14:08 -------- d-----w c:\documents and settings\LocalService\Local Settings\Application Data\Google
2009-05-11 21:53 . 2009-05-11 21:53 -------- d-----w c:\program files\iTunes
2009-05-11 21:53 . 2009-05-11 21:53 -------- d-----w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
2009-05-11 21:43 . 2009-05-11 21:43 75048 ----a-w c:\documents and settings\All Users\Application Data\Apple Computer\Installer Cache\iTunes 8.1.1.10\SetupAdmin.exe
2009-05-11 13:01 . 2009-04-17 22:58 954368 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\PicLensHelper.exe
2009-05-11 13:01 . 2009-04-17 22:58 103424 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\pixomatic.dll
2009-05-11 13:01 . 2009-04-17 22:58 65536 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\components\coolirisstub.dll
2009-05-11 13:01 . 2009-04-17 22:58 1161626 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\avcodec-51.dll
2009-05-11 13:01 . 2009-04-17 22:58 344064 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\LaunchCooliris.exe
2009-05-11 13:01 . 2009-04-17 22:58 71652 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\avutil-49.dll
2009-05-11 13:01 . 2009-04-17 22:58 4579328 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\cooliris18.dll
2009-05-11 13:01 . 2009-04-17 22:58 4534272 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\cooliris19.dll
2009-05-11 13:01 . 2009-04-17 22:58 131868 ----a-w c:\documents and settings\Khank\Application Data\Mozilla\Firefox\Profiles\ulvay4f5.default\extensions\piclens@cooliris.com\libs\avformat-52.dll
2009-05-09 05:53 . 2009-05-09 05:53 -------- d-----w c:\program files\FLV to MP3 Converter
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-30 22:11 . 2008-08-04 14:20 -------- d-----w c:\documents and settings\Khank\Application Data\Azureus
2009-05-30 21:55 . 2007-08-09 00:46 -------- d-----w c:\documents and settings\All Users\Application Data\Viewpoint
2009-05-30 15:39 . 2007-08-08 02:45 60592 ----a-w c:\documents and settings\BaoChau\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-05-28 19:50 . 2007-08-08 21:23 -------- d-----w c:\program files\Google
2009-05-28 19:35 . 2009-03-13 20:25 -------- d-----w c:\program files\Ipod Video Converter
2009-05-28 15:35 . 2008-06-28 16:12 -------- d-----w c:\documents and settings\All Users\Application Data\Google Updater
2009-05-27 00:11 . 2009-03-30 18:05 -------- d-----w c:\program files\PowerISO
2009-05-27 00:06 . 2008-06-28 18:05 -------- d---a-w c:\documents and settings\All Users\Application Data\TEMP
2009-05-26 12:59 . 2008-06-28 18:04 -------- d-----w c:\program files\Spyware Doctor
2009-05-11 21:53 . 2007-11-23 02:58 -------- d-----w c:\program files\iPod
2009-05-11 21:53 . 2008-07-03 21:57 -------- d-----w c:\program files\Common Files\Apple
2009-05-05 02:26 . 2008-11-12 02:24 1 ----a-w c:\documents and settings\Khank\Application Data\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-04-21 13:01 . 2009-04-21 03:15 -------- d-----w c:\program files\Unlocker
2009-04-21 03:30 . 2007-08-08 20:51 -------- d-----w c:\program files\Warcraft III
2009-04-21 03:19 . 2007-08-08 20:53 160889 ----a-w c:\windows\War3Unin.dat
2009-04-21 03:16 . 2009-04-21 03:16 -------- d-----w c:\documents and settings\Khank\Application Data\Desktopicon
2009-04-14 22:29 . 2007-10-01 02:30 -------- d-----w c:\program files\Java
2009-04-14 22:27 . 2009-04-14 22:27 152576 ----a-w c:\documents and settings\Khank\Application Data\Sun\Java\jre1.6.0_13\lzma.dll
2009-04-11 14:14 . 2009-03-17 23:55 -------- d-----w c:\documents and settings\Khank\Application Data\Skype
2009-04-02 20:07 . 2007-08-08 21:04 -------- d--h--w c:\program files\InstallShield Installation Information
2009-04-02 20:07 . 2007-08-08 21:04 -------- d-----w c:\program files\LucasArts
2009-04-02 03:38 . 2009-04-02 03:38 -------- d-----w c:\documents and settings\All Users\Application Data\PC Drivers HeadQuarters
2009-03-30 18:36 . 2007-08-10 18:05 60592 ----a-w c:\documents and settings\Khank\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-03-22 00:12 . 2009-03-22 00:12 22169 ----a-w c:\program files\setuplog.txt
2009-03-22 00:12 . 2009-03-22 00:12 20254 ----a-w c:\program files\uninstall.log
2009-03-19 22:32 . 2009-03-19 22:32 23400 ----a-w c:\documents and settings\All Users\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}\x86\x86\GEARAspiWDM.sys
2009-03-19 22:32 . 2008-01-29 18:01 23400 ----a-w c:\windows\system32\drivers\GEARAspiWDM.sys
2009-03-17 19:26 . 2009-03-17 19:26 65320 ----a-w c:\windows\system32\sbbd.exe
2009-03-14 18:14 . 2009-03-14 18:14 152576 ----a-w c:\documents and settings\Khank\Application Data\Sun\Java\jre1.6.0_12\lzma.dll
2009-03-09 11:19 . 2008-11-24 03:33 410984 ----a-w c:\windows\system32\deploytk.dll
2009-03-06 14:22 . 2004-08-04 10:00 284160 ----a-w c:\windows\system32\pdh.dll
2009-03-06 05:59 . 2009-03-21 15:15 1900544 ----a-w c:\windows\system32\usbaaplrc.dll
2009-03-06 05:59 . 2008-07-03 21:57 36864 ----a-w c:\windows\system32\drivers\usbaapl.sys
2009-03-03 00:18 . 2006-03-04 03:33 826368 ----a-w c:\windows\system32\wininet.dll
.
(((((((((((((((((((((((((((((
SnapShot@2009-05-30_22.35.56 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-31 00:14 . 2009-05-31 00:14 40960 c:\windows\temp\rtdrvmon.exe
+ 2009-05-31 00:14 . 2009-05-31 00:14 16384 c:\windows\temp\Perflib_Perfdata_5c4.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"VeohPlugin"="c:\program files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe" [2008-12-16 3528440]
"Google Update"="c:\documents and settings\Khank\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-05-14 133104]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dell AIO Printer A920"="c:\program files\Dell AIO Printer A920\dlbkbmgr.exe" [2003-05-03 270336]
"dla"="c:\windows\system32\dla\tfswctrl.exe" [2003-08-06 114741]
"StorageGuard"="c:\program files\Common Files\Sonic\Update Manager\sgtray.exe" [2003-02-13 155648]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"MSPY2002"="c:\windows\system32\IME\PINTLGNT\ImScInst.exe" [2004-08-04 59392]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"AppleSyncNotifier"="c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe" [2009-03-26 177472]
"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2007-08-07 200704]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2009-04-02 342312]
"SBAMTray"="c:\program files\Sunbelt Software\CounterSpy\SBAMTray.exe" [2009-03-17 681256]
"BCMSMMSG"="BCMSMMSG.exe" - c:\windows\BCMSMMSG.exe [2003-08-29 122880]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office Fast Start.lnk - c:\msoffice\Office\FASTBOOT.EXE [1995-9-27 14848]
Microsoft Office Find Fast Indexer.lnk - c:\msoffice\Office\FINDFAST.EXE [1995-9-27 86528]
Microsoft Office Shortcut Bar.lnk - c:\msoffice\Office\MSOFFICE.EXE [1995-9-27 365056]
Nikon Monitor.lnk - c:\program files\Common Files\Nikon\Monitor\NkMonitor.exe [2007-10-18 479232]