ComboFix 09-12-26.05 - Ken Sparrow 12/27/2009 12:30:02.5.1 - x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.1279.739 [GMT -6:00] Running from: C:\ComboFix.exe Command switches used :: C:\CFScript.txt AV: avast! antivirus 4.8.1368 [VPS 091227-1] *On-access scanning disabled* (Updated) {7591DB91-41F0-48A3-B128-1A293FD8233D} file zipped: C:\WINDOWS\system32\hdwwiz6.dll . ((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\Boggle Supreme.1.torrent C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\Boggle Supreme.torrent C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\dht.dat C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\dht.dat.old C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\DriveClone Pro 5 .1.rar.torrent C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\resume.dat C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\resume.dat.old C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\rss.dat C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\rss.dat.old C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\settings.dat C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\settings.dat.old C:\Documents and Settings\Ken Sparrow\Application Data\uTorrent\utorrent.lng C:\Program Files\uTorrent C:\Program Files\uTorrent\uTorrent.exe C:\WINDOWS\system32\hdwwiz6.dll . ((((((((((((((((((((((((( Files Created from 2009-11-27 to 2009-12-27 ))))))))))))))))))))))))))))))) . 2009-12-27 18:23:10 . 2009-12-27 14:42:10 3867118 ----a-r- C:\ComboFix.exe 2009-12-27 16:25:56 . 2009-12-27 16:25:57 47376 ----a-w- C:\ComboFix.zip 2009-12-27 15:34:11 . 2001-08-23 12:00:00 41600 -c--a-w- C:\WINDOWS\system32\dllcache\weitekp9.dll 2009-12-27 15:34:11 . 2001-08-23 12:00:00 31232 -c--a-w- C:\WINDOWS\system32\dllcache\weitekp9.sys 2009-12-27 15:34:09 . 2001-08-23 12:00:00 48256 -c--a-w- C:\WINDOWS\system32\dllcache\w32.dll 2009-12-27 15:34:08 . 2004-08-03 22:32:36 86073 -c--a-w- C:\WINDOWS\system32\dllcache\voicesub.dll 2009-12-27 15:34:08 . 2004-08-03 22:32:36 426041 -c--a-w- C:\WINDOWS\system32\dllcache\voicepad.dll 2009-12-27 15:34:01 . 2004-08-03 23:04:12 76288 -c--a-w- C:\WINDOWS\system32\dllcache\uniime.dll 2009-12-27 15:34:00 . 2001-08-23 12:00:00 14336 -c--a-w- C:\WINDOWS\system32\dllcache\tsprof.exe 2009-12-27 15:32:59 . 2004-08-03 22:31:56 155705 -c--a-w- C:\WINDOWS\system32\dllcache\imjpdsvr.exe 2009-12-27 15:31:59 . 2001-08-23 12:00:00 19456 -c--a-w- C:\WINDOWS\system32\dllcache\agt0804.dll 2009-12-27 15:29:51 . 2001-08-23 12:00:00 16384 -c--a-w- C:\WINDOWS\system32\dllcache\isignup.exe 2009-12-27 15:19:52 . 2009-12-27 15:19:53 -------- d-----w- C:\WINDOWS\LastGood.Tmp 2009-12-27 15:19:48 . 2001-08-23 12:00:00 24661 -c--a-w- C:\WINDOWS\system32\dllcache\spxcoins.dll 2009-12-27 15:19:48 . 2001-08-23 12:00:00 24661 ----a-w- C:\WINDOWS\system32\spxcoins.dll 2009-12-27 15:19:48 . 2001-08-23 12:00:00 13312 -c--a-w- C:\WINDOWS\system32\dllcache\irclass.dll 2009-12-27 15:19:48 . 2001-08-23 12:00:00 13312 ----a-w- C:\WINDOWS\system32\irclass.dll 2009-12-25 21:00:54 . 2009-12-25 21:00:54 249856 ----a-w- C:\WINDOWS\Setup1.exe 2009-12-25 21:00:53 . 2009-12-25 21:00:53 73216 ----a-w- C:\WINDOWS\ST6UNST.EXE 2009-12-25 13:39:16 . 2005-05-17 21:48:16 24576 ----a-w- C:\Documents and Settings\Ken Sparrow\Application Data\Mozilla\Firefox\Profiles\c01bnm35.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll 2009-12-24 21:08:57 . 2009-12-24 21:09:04 -------- d-----w- C:\Program Files\Safari 2009-12-24 21:08:57 . 2009-12-24 21:08:57 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Apple Computer 2009-12-24 21:08:43 . 2009-12-24 21:08:43 -------- d-----w- C:\Program Files\Bonjour 2009-12-24 19:36:30 . 2009-12-24 19:36:30 40064 ---ha-w- C:\WINDOWS\system32\mlfcache.dat 2009-12-24 19:32:00 . 2009-12-24 19:32:01 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Apple Computer 2009-12-24 19:32:00 . 2009-12-24 19:32:00 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Local Settings\Application Data\Apple Computer 2009-12-24 19:30:28 . 2009-12-24 19:30:28 -------- d-----w- C:\Program Files\Common Files\Apple 2009-12-24 19:29:46 . 2009-12-24 19:29:46 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Local Settings\Application Data\Apple 2009-12-24 19:29:32 . 2009-12-24 19:29:35 -------- d-----w- C:\Program Files\Apple Software Update 2009-12-24 19:29:32 . 2009-12-24 19:29:32 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Apple 2009-12-23 14:21:24 . 2009-12-23 14:29:33 -------- d-----w- C:\Program Files\Microsoft Bootvis 2009-12-23 14:09:42 . 2009-12-23 14:09:42 -------- d-----w- C:\Program Files\Resource Kit 2009-12-23 13:34:22 . 2009-12-23 13:37:18 -------- d-----w- C:\Documents and Settings\All Users\Application Data\NOS 2009-12-23 11:39:19 . 2009-12-23 11:40:43 -------- d-----w- C:\WINDOWS\$regcmp$ 2009-12-23 11:37:21 . 2009-12-23 11:37:21 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Local Settings\Application Data\PCHealth 2009-12-22 13:51:15 . 2009-12-22 13:52:16 1531392 ----a-w- C:\Documents and Settings\Ken Sparrow\Application Data\tsdnwin.dll 2009-12-22 13:45:44 . 2009-12-22 13:45:44 -------- d-----w- C:\Program Files\SAMSUNG 2009-12-22 00:13:41 . 2009-12-22 00:13:41 -------- d-----w- C:\WINDOWS\Sun 2009-12-21 19:49:56 . 2009-12-21 19:49:56 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\iWin 2009-12-21 19:47:46 . 2009-12-21 19:47:46 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\SpinTop 2009-12-20 14:53:17 . 2009-12-20 14:53:17 -------- d-----w- C:\Program Files\Common Files\Adobe AIR 2009-12-19 23:25:05 . 2009-12-19 23:25:05 -------- d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla 2009-12-19 23:15:08 . 2009-11-24 23:49:07 48560 ----a-w- C:\WINDOWS\system32\drivers\aswTdi.sys 2009-12-19 23:15:08 . 2009-11-24 23:48:57 23120 ----a-w- C:\WINDOWS\system32\drivers\aswRdr.sys 2009-12-19 23:15:07 . 2009-11-24 23:47:54 27408 ----a-w- C:\WINDOWS\system32\drivers\aavmker4.sys 2009-12-19 23:15:06 . 2009-11-24 23:47:28 97480 ----a-w- C:\WINDOWS\system32\AvastSS.scr 2009-12-19 23:15:05 . 2009-11-24 23:51:09 93424 ----a-w- C:\WINDOWS\system32\drivers\aswmon.sys 2009-12-19 23:15:05 . 2009-11-24 23:50:59 94160 ----a-w- C:\WINDOWS\system32\drivers\aswmon2.sys 2009-12-19 23:15:05 . 2009-11-24 23:50:12 114768 ----a-w- C:\WINDOWS\system32\drivers\aswSP.sys 2009-12-19 23:15:05 . 2009-11-24 23:50:00 20560 ----a-w- C:\WINDOWS\system32\drivers\aswFsBlk.sys 2009-12-19 23:14:44 . 2009-11-24 23:54:29 1280480 ----a-w- C:\WINDOWS\system32\aswBoot.exe 2009-12-19 23:14:44 . 2003-03-18 20:14:52 499712 ----a-w- C:\WINDOWS\system32\MSVCP71.dll 2009-12-19 23:14:42 . 2009-12-19 23:14:42 -------- d-----w- C:\Program Files\Alwil Software 2009-12-19 21:17:42 . 2009-12-19 21:17:29 411368 ----a-w- C:\WINDOWS\system32\deploytk.dll 2009-12-19 21:17:25 . 2009-12-19 21:17:25 -------- d-----w- C:\Program Files\Java 2009-12-19 15:03:07 . 2009-12-19 15:03:09 -------- d-----w- C:\MGTools 2009-12-19 14:04:36 . 2009-12-19 14:04:36 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com 2009-12-19 14:04:25 . 2009-12-20 00:08:07 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\SUPERAntiSpyware.com 2009-12-19 14:04:25 . 2009-12-20 00:08:03 -------- d-----w- C:\Program Files\SUPERAntiSpyware 2009-12-19 02:07:27 . 2009-12-19 02:07:27 388096 ----a-r- C:\Documents and Settings\Ken Sparrow\Application Data\Microsoft\Installer\{0761C9A8-8F3A-4216-B4A7-B7AFBF24A24A}\HiJackThis.exe 2009-12-19 02:07:27 . 2009-12-19 02:07:27 -------- d-----w- C:\Program Files\TrendMicro 2009-12-19 01:45:09 . 2009-12-19 01:45:09 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Local Settings\Application Data\Threat Expert 2009-12-18 01:51:47 . 2009-12-25 21:09:51 -------- d-----w- C:\Hijack this 2009-12-16 20:20:45 . 2009-12-19 11:04:30 -------- d-----w- C:\$AVG 2009-12-16 20:20:09 . 2009-12-19 23:06:56 -------- d-----w- C:\Documents and Settings\All Users\Application Data\avg9 2009-12-16 16:47:05 . 2009-12-16 16:48:26 -------- dc-h--w- C:\WINDOWS\ie8 2009-12-16 14:04:45 . 2009-12-16 14:16:04 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\AGI 2009-12-16 14:04:45 . 2009-12-16 14:04:45 -------- d-----w- C:\Program Files\Webshots 2009-12-16 14:04:37 . 2009-12-16 14:04:37 -------- d-----w- C:\Program Files\AGI 2009-12-16 14:03:24 . 2009-12-16 14:04:45 -------- d-----w- C:\Documents and Settings\All Users\Application Data\agi 2009-12-15 17:18:01 . 2009-11-03 02:42:06 195456 ----a-w- C:\WINDOWS\system32\MpSigStub.exe 2009-12-15 17:17:13 . 2009-12-15 17:17:14 -------- d-----w- C:\Program Files\Windows Defender 2009-12-15 13:59:21 . 2009-12-15 13:59:21 4844296 ----a-w- C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe 2009-12-14 18:32:49 . 2009-12-14 18:32:49 -------- d-sh--w- C:\Documents and Settings\Ken Sparrow\IECompatCache 2009-12-14 17:33:07 . 2009-12-14 17:33:08 -------- d-----w- C:\Documents and Settings\All Users\Application Data\XoftSpySE 2009-12-14 13:31:51 . 2009-12-14 13:31:51 -------- d-sh--w- C:\WINDOWS\system32\config\systemprofile\IETldCache 2009-12-08 18:42:27 . 2009-12-08 18:42:27 -------- d-----w- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google 2009-12-08 15:06:09 . 2009-12-08 15:06:09 104512 ----a-w- C:\WINDOWS\system32\drivers\AnyDVD.sys 2009-12-08 00:10:39 . 2001-08-18 04:36:30 5632 ----a-w- C:\WINDOWS\system32\ptpusb.dll 2009-12-08 00:10:38 . 2008-04-14 00:12:04 159232 ----a-w- C:\WINDOWS\system32\ptpusd.dll 2009-12-05 02:34:55 . 2009-12-05 02:34:55 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\ImgBurn 2009-12-05 02:32:32 . 2009-12-05 02:37:03 -------- d-----w- C:\Program Files\ImgBurn 2009-12-04 19:38:52 . 2009-12-04 19:38:52 -------- d-----w- C:\CloneDVDTemp 2009-12-01 23:51:30 . 2009-12-19 22:58:26 -------- dc----w- C:\WINDOWS\system32\DRVSTORE 2009-12-01 23:11:47 . 2009-12-19 22:58:26 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Lavasoft 2009-11-30 01:36:25 . 2009-11-30 01:36:25 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Malwarebytes 2009-11-30 01:36:20 . 2009-12-03 22:14:06 38224 ----a-w- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2009-11-30 01:36:18 . 2009-12-24 19:25:15 -------- d-----w- C:\Program Files\Malwarebytes' Anti-Malware 2009-11-30 01:36:18 . 2009-12-03 22:13:56 19160 ----a-w- C:\WINDOWS\system32\drivers\mbam.sys 2009-11-30 01:36:18 . 2009-11-30 01:36:18 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Malwarebytes 2009-11-29 17:45:41 . 2009-11-29 17:45:41 -------- d-----w- C:\Program Files\Registry Clean Expert 2009-11-29 17:42:45 . 2009-12-25 13:16:34 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2009-11-29 17:40:23 . 2009-12-24 13:41:30 -------- d-----w- C:\Program Files\SpywareBlaster 2009-11-29 17:40:04 . 2009-11-29 17:40:04 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\IObit 2009-11-29 17:40:02 . 2009-11-29 17:40:02 -------- d-----w- C:\Program Files\IObit 2009-11-29 17:34:20 . 2009-12-02 00:43:40 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\RegistryDefense 2009-11-29 17:33:56 . 2009-11-29 17:33:58 -------- d-----w- C:\Program Files\Registry Defense 2009-11-29 17:33:08 . 2009-11-29 17:33:11 -------- d-----w- C:\Program Files\CCleaner 2009-11-29 00:42:48 . 2009-11-29 00:42:49 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Canon . (((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-12-27 15:29:05 . 2009-11-23 19:18:21 23348 ----a-w- C:\WINDOWS\system32\emptyregdb.dat 2009-12-27 01:34:59 . 2009-11-24 02:21:42 -------- d---a-w- C:\Documents and Settings\All Users\Application Data\TEMP 2009-12-25 13:57:25 . 2009-11-24 03:07:37 -------- d-----w- C:\Program Files\The Weather Channel Toolbar 2009-12-24 14:45:10 . 2009-11-24 00:41:39 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\DVD Profiler 2009-12-24 14:41:30 . 2009-11-24 00:53:02 -------- d-----w- C:\Program Files\DVD Profiler 2009-12-23 11:36:19 . 2009-11-24 02:08:36 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2009-12-22 13:54:17 . 2009-12-22 13:53:40 45 ----a-w- C:\Documents and Settings\Ken Sparrow\Application Data\TSDNWIN.TMP 2009-12-22 13:45:44 . 2009-11-23 22:20:02 -------- d--h--w- C:\Program Files\InstallShield Installation Information 2009-12-22 13:44:58 . 2009-11-23 22:19:21 -------- d-----w- C:\Program Files\Common Files\InstallShield 2009-12-20 21:12:11 . 2009-11-23 23:59:12 -------- d-----w- C:\Program Files\Common Files\Adobe 2009-12-16 15:09:48 . 2009-11-24 00:12:00 -------- d-----w- C:\Program Files\TClockEx 2009-12-16 14:05:09 . 2009-11-24 00:19:16 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Webshots 2009-12-09 02:12:34 . 2009-11-24 17:02:02 -------- d-----w- C:\Documents and Settings\All Users\Application Data\WinZip 2009-12-08 12:45:53 . 2009-12-08 12:45:53 -------- d-----w- C:\Program Files\Common Files\Logitech 2009-12-08 12:45:52 . 2009-12-08 12:45:52 -------- d-----w- C:\Program Files\Logitech 2009-11-25 17:55:56 . 2009-11-24 21:52:45 -------- d-----w- C:\Program Files\Microsoft Silverlight 2009-11-24 21:29:49 . 2009-11-24 21:29:48 -------- d-----w- C:\Program Files\Microsoft CAPICOM 2.1.0.2 2009-11-24 17:00:07 . 2009-11-24 17:00:07 -------- d-----w- C:\Program Files\7-Zip 2009-11-24 14:57:24 . 2009-11-24 02:42:57 -------- d-----w- C:\Program Files\Quicken 2009-11-24 14:11:26 . 2009-11-24 14:11:26 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Zeon 2009-11-24 03:01:26 . 2009-11-24 03:01:26 -------- d-----w- C:\Documents and Settings\All Users\Application Data\RoboForm 2009-11-24 03:01:05 . 2009-11-24 03:01:05 -------- d-----w- C:\Program Files\Siber Systems 2009-11-24 02:54:30 . 2009-11-24 02:54:30 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Elaborate Bytes 2009-11-24 02:51:41 . 2009-11-24 02:51:41 -------- d-----w- C:\Documents and Settings\All Users\Application Data\SlySoft 2009-11-24 02:51:29 . 2009-11-24 02:51:29 -------- d-----w- C:\Program Files\Elaborate Bytes 2009-11-24 02:50:31 . 2009-11-24 02:50:31 -------- d-----w- C:\Program Files\SlySoft 2009-11-24 02:43:27 . 2009-11-24 02:43:27 -------- d-----w- C:\Program Files\Common Files\Palo Alto Software 2009-11-24 02:43:15 . 2009-11-24 02:43:15 -------- d-----w- C:\Program Files\Common Files\Intuit 2009-11-24 02:24:04 . 2009-11-23 21:46:50 46352 ----a-w- C:\Documents and Settings\Ken Sparrow\Local Settings\Application Data\GDIPFONTCACHEV1.DAT 2009-11-24 02:24:01 . 2009-11-24 02:23:58 -------- d-----w- C:\Program Files\OpenXML-ODF Translator 2009-11-24 02:21:40 . 2009-11-24 02:21:40 -------- d-----w- C:\Program Files\Classic Menu for Office 2009-11-24 02:17:46 . 2009-11-24 02:12:56 -------- d-----w- C:\Program Files\Microsoft Works 2009-11-24 02:11:44 . 2009-11-24 02:11:44 -------- d-----w- C:\Program Files\Microsoft.NET 2009-11-24 01:50:59 . 2009-11-24 01:50:59 -------- d-----w- C:\Documents and Settings\All Users\Application Data\Anvsoft 2009-11-24 01:50:23 . 2009-11-24 01:50:11 -------- d-----w- C:\Program Files\Photo DVD Maker Professional 2009-11-24 01:47:43 . 2009-11-24 01:47:36 -------- d-----w- C:\Program Files\Google 2009-11-24 01:08:38 . 2009-11-24 01:08:38 -------- d-----w- C:\Program Files\MSXML 4.0 2009-11-24 00:29:07 . 2009-11-24 00:29:07 -------- d-----w- C:\Program Files\Analog Devices 2009-11-24 00:00:51 . 2009-11-24 00:00:51 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Leadertech 2009-11-23 23:57:55 . 2009-11-23 23:57:55 -------- d-----w- C:\WINDOWS\system32\config\systemprofile\Application Data\Zeon 2009-11-23 23:57:50 . 2009-11-23 23:57:50 -------- d-----w- C:\Documents and Settings\All Users\Application Data\zeon 2009-11-23 23:57:34 . 2009-11-23 23:56:55 -------- d-----w- C:\Documents and Settings\All Users\Application Data\ScanSoft 2009-11-23 23:57:25 . 2009-11-23 23:56:36 -------- d-----w- C:\Program Files\ScanSoft 2009-11-23 23:57:04 . 2009-11-23 23:57:04 -------- d-----w- C:\Documents and Settings\All Users\Application Data\InstallShield 2009-11-23 23:57:01 . 2009-11-23 23:57:01 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\ScanSoft 2009-11-23 23:56:57 . 2009-11-23 23:56:57 -------- d-----w- C:\Program Files\Common Files\ScanSoft Shared 2009-11-23 22:48:59 . 2009-11-23 22:48:59 0 ----a-w- C:\WINDOWS\nsreg.dat 2009-11-23 22:42:37 . 2009-11-23 22:37:38 -------- d-----w- C:\Program Files\EPSON 2009-11-23 22:40:48 . 2009-11-23 22:40:45 -------- d-----w- C:\Program Files\Epson Software 2009-11-23 22:39:50 . 2009-11-23 22:39:50 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\InstallShield 2009-11-23 22:38:43 . 2009-11-23 22:38:41 -------- d-----w- C:\Documents and Settings\All Users\Application Data\EPSON 2009-11-23 22:29:50 . 2009-11-23 22:29:50 -------- d-----w- C:\Program Files\Canon 2009-11-23 22:20:06 . 2009-11-23 22:20:01 -------- d-----w- C:\Program Files\FaxTools 2009-11-23 22:20:01 . 2009-11-23 22:20:01 -------- d-----w- C:\Documents and Settings\All Users\Application Data\BVRP Software 2009-11-23 22:07:06 . 2009-11-23 22:07:06 -------- d-----w- C:\Program Files\Trogladite Software 2009-11-23 21:36:38 . 2009-11-23 21:36:38 -------- d-----w- C:\Program Files\MSBuild 2009-11-23 21:36:32 . 2009-11-23 21:36:32 -------- d-----w- C:\Program Files\Reference Assemblies 2009-11-23 21:26:31 . 2009-11-23 21:16:51 -------- d-----w- C:\Program Files\Windows Desktop Search 2009-11-23 21:19:57 . 2009-11-23 21:19:57 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Windows Search 2009-11-23 21:17:17 . 2009-11-23 21:17:17 -------- d-----w- C:\Documents and Settings\Ken Sparrow\Application Data\Windows Desktop Search 2009-11-23 21:15:57 . 2009-11-23 21:15:56 -------- d-----w- C:\Program Files\Windows Media Connect 2 2009-11-23 20:34:39 . 2009-11-23 19:20:10 76487 ----a-w- C:\WINDOWS\pchealth\helpctr\OfflineCache\index.dat 2009-11-23 19:21:24 . 2009-11-23 19:21:24 -------- d-----w- C:\Program Files\microsoft frontpage 2009-11-06 03:16:58 . 2009-11-06 03:16:58 73728 ----a-w- C:\Documents and Settings\All Users\Application Data\Apple Computer\Installer Cache\Safari 5.31.21.10\SetupAdmin.exe 2009-10-08 20:57:02 . 2009-10-08 20:57:02 611328 ----a-w- C:\WINDOWS\system32\uiautomationcore.dll . ((((((((((((((((((((((((((((( SnapShot_2009-12-27_16.15.24 ))))))))))))))))))))))))))))))))))))))))) . + 2009-12-27 18:36:14 . 2009-12-27 18:36:14 16384 C:\WINDOWS\temp\Perflib_Perfdata_598.dat + 2009-12-27 18:35:21 . 2009-12-27 18:35:21 16384 C:\WINDOWS\temp\Perflib_Perfdata_518.dat . ((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))))) . . *Note* empty entries & legit default entries are not shown REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TClockEx"="C:\Program Files\TClockEx\TCLOCKEX.EXE" [2000-03-09 07:15:18 89088] "RoboForm"="C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe" [2009-12-24 12:32:19 160592] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2004-08-03 02:03:00 4493312] "Opware15"="C:\Program Files\ScanSoft\OmniPage15.0\Opware15.exe" [2005-07-06 06:58:36 69632] "avast!"="C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 23:51:40 81000] "Logitech Utility"="Logi_MwX.Exe" [2003-12-17 15:50:00 19968] "nwiz"="nwiz.exe" [2004-08-03 02:03:00 917504] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "tscuninstall"="C:\WINDOWS\system32\tscupgrd.exe" [2004-08-03 22:59:28 44544] C:\Documents and Settings\Ken Sparrow\Start Menu\Programs\Startup\ Webshots.lnk - C:\Program Files\Webshots\3.1.5.7617\Launcher.exe [2009-12-16 157088] [hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 04:41:34 304128] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\rootrepeal.sys] @="" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend] @="Service" [HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Quicken Scheduled Updates.lnk] backup=C:\WINDOWS\pss\Quicken Scheduled Updates.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM] 2009-09-04 18:08:30 935288 ----a-r- C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] 2007-03-09 17:09:58 63712 ----a-w- C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] 2009-10-03 10:08:38 35696 ----a-w- C:\Program Files\Adobe\Reader 9.0\Reader\reader_sl.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor] 2008-10-25 17:44:34 31072 ----a-w- C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Name of App] 2009-10-12 22:51:28 692321 ----a-w- C:\Program Files\SAMSUNG\FW LiveUpdate\FWManager.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpAgent] 2005-07-06 07:02:30 143360 ----a-w- C:\Program Files\ScanSoft\OmniPage15.0\OpAgent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PDF3 Registry Controller] 2005-04-12 16:16:10 106496 ----a-w- C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\registrycontroller.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate] 2003-09-30 06:14:58 155648 ----a-r- C:\Program Files\Common Files\ScanSoft Shared\SSBkgdUpdate\SSBkgdUpdate.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] 2009-12-19 21:17:29 149280 ----a-w- C:\Program Files\Java\jre6\bin\jusched.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\WINDOWS\\system32\\fxsclnt.exe"= "C:\\Program Files\\Bonjour\\mDNSResponder.exe"= R1 aswSP;avast! Self Protection;C:\WINDOWS\system32\drivers\aswSP.sys [12/19/2009 5:15:05 PM 114768] R2 aswFsBlk;aswFsBlk;C:\WINDOWS\system32\drivers\aswFsBlk.sys [12/19/2009 5:15:05 PM 20560] R2 WinDefend;Windows Defender;C:\Program Files\Windows Defender\MsMpEng.exe [11/3/2006 7:19:58 PM 13592] S2 AGCoreService;AG Core Services;C:\Program Files\AGI\core\4.2\AGCoreService.exe [12/16/2009 8:04:38 AM 20480] S2 mrtRate;mrtRate; [x] . ------- Supplementary Scan ------- . uStart Page = hxxp://www.conwaycorp.com/ uInternet Settings,ProxyOverride = *.local IE: Customize Menu - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html IE: Fill Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html IE: Open with Scansoft PDF Converter 3.0 - C:\Program Files\ScanSoft\OmniPage15.0\PDFConverter3\IEShellExt.dll /100 IE: RoboForm Toolbar - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html IE: Save Forms - file://C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html TCP: {75515E52-5D31-43AB-B8D9-D41383D8457D} = 24.144.0.4,68.94.156.1 FF - ProfilePath - C:\Documents and Settings\Ken Sparrow\Application Data\Mozilla\Firefox\Profiles\c01bnm35.default\ FF - prefs.js: browser.search.selectedEngine - Searchalot FF - prefs.js: browser.startup.homepage - hxxp://number1.searchalot.com/ FF - component: C:\Documents and Settings\Ken Sparrow\Application Data\Mozilla\Firefox\Profiles\c01bnm35.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}\components\PlainOldFavorites.dll FF - component: C:\Program Files\Siber Systems\AI RoboForm\Firefox\components\rfproxy_31.dll FF - plugin: C:\Program Files\Google\Picasa3\npPicasa3.dll .