+ 2009-09-08 14:57 . 2009-09-08 14:57 135168 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\7bab199cdaf015448b5f5d4d0b1b4a43\WindowsLive.Writer.Passport.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 204800 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\743f03ae13a70a4d92655b3dbc870bb8\WindowsLive.Writer.BrowserControl.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 475136 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\6b6f00c27afd8e4f988e77c9d0a1bc71\WindowsLive.Writer.Localization.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 176128 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4c2ad8e2ebe40f418baf6d344249b6fa\WindowsLive.Writer.HtmlParser.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 286720 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\4937740f29188446a93696b8840252c2\WindowsLive.Writer.Mshtml.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\44326d2768da2147bb7355066f3ae7dd\WindowsLive.Writer.Instrumentation.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 143360 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3de0da6f4cc844469d321f932ca2dd60\WindowsLive.Writer.Extensibility.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 352256 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\3a532da25a8b5e45a95133fa6375dad5\WindowsLive.Writer.Interop.SHDocVw.ni.dll
+ 2009-09-08 14:56 . 2009-09-08 14:56 876544 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\322bceea105c1e44a9d0d4d07c76dff9\WindowsLive.Writer.Controls.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 376832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\2ec777b28da596489a8dcf1c91212c11\WindowsLive.Writer.SpellChecker.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 335872 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\06a5d858953cdc4cb11fcfb6cfcc3fc3\WindowsLive.Writer.Interop.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\858c57612104fe4fa1a09b60ba248b47\WindowsLive.Client.ni.dll
+ 2009-09-08 14:51 . 2009-09-08 14:51 876544 c:\windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1EE.tmp\WindowsLive.Writer.Controls.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\80a628ae3e0a7f4ebca5820e2af4f035\System.Web.RegularExpressions.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 684032 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\36f009dbdfc65f4dbe975324d3b94c34\System.Transactions.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 233472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\8178b344c9389b4aa1d3e83a910e6b16\System.ServiceProcess.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 729088 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\3d35debeb3265f4e8457e77d0e5b62f6\System.Security.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 339968 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\fced9bbf7055c2419f0d9b689cfb3770\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 815104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\860a157338feed4da037378f91f06bf9\System.Runtime.Remoting.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 294912 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\a089968bc316454fa8d9afea841c292b\System.EnterpriseServices.Wrapper.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 659456 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\a089968bc316454fa8d9afea841c292b\System.EnterpriseServices.ni.dll
+ 2009-09-08 13:43 . 2009-09-08 13:43 229376 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing.Desi#\cd760de6d1c99044a01db80641ce99e9\System.Drawing.Design.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 512000 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\f2abf40b8a75f443942f46a71964d89b\System.DirectoryServices.Protocols.ni.dll
+ 2009-09-08 14:56 . 2009-09-08 14:56 962560 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\f05d9d0140774a4fa766497ce30e40f1\System.Configuration.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 167936 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\e84133278e3bb642ad0c9b8271e34d18\System.Configuration.Install.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 163840 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\38355da01cae14419898fa18144d948d\Microsoft.Build.Utilities.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 880640 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\1144445ee46f1547b50b74ff0a6e7b07\Microsoft.Build.Engine.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 237568 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\2b09d93a4466144fb478be2df220bfe2\CustomMarshalers.ni.dll
+ 2009-09-08 14:51 . 2009-09-08 14:51 860160 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\c29bbd3049478c40915505423e65e7d6\AspNetMMCExt.ni.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 823296 c:\windows\assembly\GAC_MSIL\System.Web.Services\2.0.0.0__b03f5f7f11d50a3a\System.Web.Services.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 835584 c:\windows\assembly\GAC_MSIL\System.Web.Mobile\2.0.0.0__b03f5f7f11d50a3a\System.Web.Mobile.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 114688 c:\windows\assembly\GAC_MSIL\System.ServiceProcess\2.0.0.0__b03f5f7f11d50a3a\System.ServiceProcess.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 258048 c:\windows\assembly\GAC_MSIL\System.Security\2.0.0.0__b03f5f7f11d50a3a\System.Security.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 131072 c:\windows\assembly\GAC_MSIL\System.Runtime.Serialization.Formatters.Soap\2.0.0.0__b03f5f7f11d50a3a\System.Runtime.Serialization.Formatters.Soap.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 299008 c:\windows\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 258048 c:\windows\assembly\GAC_MSIL\System.Messaging\2.0.0.0__b03f5f7f11d50a3a\System.Messaging.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 368640 c:\windows\assembly\GAC_MSIL\System.Management\2.0.0.0__b03f5f7f11d50a3a\System.Management.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 700416 c:\windows\assembly\GAC_MSIL\System.Drawing\2.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 397312 c:\windows\assembly\GAC_MSIL\System.DirectoryServices\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 188416 c:\windows\assembly\GAC_MSIL\System.DirectoryServices.Protocols\2.0.0.0__b03f5f7f11d50a3a\System.DirectoryServices.Protocols.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 884736 c:\windows\assembly\GAC_MSIL\System.Deployment\2.0.0.0__b03f5f7f11d50a3a\System.Deployment.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 716800 c:\windows\assembly\GAC_MSIL\System.Data.SqlXml\2.0.0.0__b77a5c561934e089\System.Data.SqlXml.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 389120 c:\windows\assembly\GAC_MSIL\System.Configuration\2.0.0.0__b03f5f7f11d50a3a\System.configuration.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 110592 c:\windows\assembly\GAC_MSIL\sysglobl\2.0.0.0__b03f5f7f11d50a3a\sysglobl.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 667648 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 372736 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 110592 c:\windows\assembly\GAC_MSIL\Microsoft.VisualBasic.Compatibility.Data\8.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.Compatibility.Data.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 745472 c:\windows\assembly\GAC_MSIL\Microsoft.JScript\8.0.0.0__b03f5f7f11d50a3a\Microsoft.JScript.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 647168 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Tasks\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Tasks.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 413696 c:\windows\assembly\GAC_MSIL\Microsoft.Build.Engine\2.0.0.0__b03f5f7f11d50a3a\Microsoft.Build.Engine.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 503808 c:\windows\assembly\GAC_MSIL\AspNetMMCExt\2.0.0.0__b03f5f7f11d50a3a\AspNetMMCExt.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 260096 c:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 114176 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.Wrapper.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 258048 c:\windows\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a\System.EnterpriseServices.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 482304 c:\windows\assembly\GAC_32\System.Data.OracleClient\2.0.0.0__b77a5c561934e089\System.Data.OracleClient.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 1306624 c:\windows\Microsoft.NET\Framework\v2.0.50727\VsaVb7rt.dll
+ 2005-09-23 04:29 . 2005-09-23 04:29 1140920 c:\windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe
+ 2005-09-23 04:28 . 2005-09-23 04:28 2035712 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.XML.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 5316608 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Windows.Forms.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 5025792 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Web.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 3018752 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 5050368 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Design.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 2878976 c:\windows\Microsoft.NET\Framework\v2.0.50727\System.Data.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 5615616 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorwks.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 4308992 c:\windows\Microsoft.NET\Framework\v2.0.50727\mscorlib.dll
+ 2005-09-23 04:28 . 2005-09-23 04:28 1144832 c:\windows\Microsoft.NET\Framework\v2.0.50727\cscomp.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 2109440 c:\windows\Installer\11edc0.msi
+ 2009-09-08 14:51 . 2009-09-08 14:51 6516736 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\ea5c92a5b6f97346af3258123eea32b8\WindowsLive.Writer.PostEditor.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 2093056 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\a33e002ab858b74cb957b763cbf36008\WindowsLive.Writer.CoreServices.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 1163264 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\08a701f60a2e874fb80355216dc7cf02\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2009-09-08 13:43 . 2009-09-08 13:43 8093696 c:\windows\assembly\NativeImages_v2.0.50727_32\System\07f316dbe9fdf44d961590bb78a4fd7c\System.ni.dll
+ 2009-09-08 13:43 . 2009-09-08 13:43 5640192 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\6cd85232b259004292215df94ec4f50c\System.Xml.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 1945600 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\b2160535cc38ea4e915073a1d884955e\System.Web.Services.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 2310144 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\f7f3970b95e4a5478b42ec54682a4a28\System.Web.Mobile.ni.dll
+ 2009-09-08 13:43 . 2009-09-08 13:43 1626112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\728dc016bcb3d041b9987b0583ca0a37\System.Drawing.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 1220608 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\1a32fa7351f5b842abc888cbe34f687e\System.DirectoryServices.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\45f4c0327c570e4a95587b678465512d\System.Deployment.ni.dll
+ 2009-09-08 13:44 . 2009-09-08 13:44 6688768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\0559331e44910b4aa577dd76fba35bc5\System.Data.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 2703360 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\738f293b3161ca43808834c3fd7650b3\System.Data.SqlXml.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 1183744 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\30a6acd1413e8549bbfbad1bf1f6d747\System.Data.OracleClient.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 1724416 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\feb1a33223b6704d8656550051f35b24\Microsoft.VisualBasic.ni.dll
+ 2009-09-08 14:58 . 2009-09-08 14:58 1691648 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\9793ee0ace04b64e8a1731b38ee3a416\Microsoft.Build.Tasks.ni.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 3018752 c:\windows\assembly\GAC_MSIL\System\2.0.0.0__b77a5c561934e089\System.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 2035712 c:\windows\assembly\GAC_MSIL\System.Xml\2.0.0.0__b77a5c561934e089\System.XML.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 5316608 c:\windows\assembly\GAC_MSIL\System.Windows.Forms\2.0.0.0__b77a5c561934e089\System.Windows.Forms.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 5050368 c:\windows\assembly\GAC_MSIL\System.Design\2.0.0.0__b03f5f7f11d50a3a\System.Design.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 5025792 c:\windows\assembly\GAC_32\System.Web\2.0.0.0__b03f5f7f11d50a3a\System.Web.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 2878976 c:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 4308992 c:\windows\assembly\GAC_32\mscorlib\2.0.0.0__b77a5c561934e089\mscorlib.dll
+ 2005-09-23 04:48 . 2005-09-23 04:48 24863744 c:\windows\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\netfx.msi
+ 2009-09-08 13:43 . 2009-09-08 13:43 13107200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2adf9eb79cb9124789fa001e061be072\System.Windows.Forms.ni.dll
+ 2009-09-08 14:57 . 2009-09-08 14:57 11808768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\21cf161e353b4b48b0b60a545fc15889\System.Web.ni.dll
+ 2009-09-08 13:44 . 2009-09-08 13:44 10723328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Design\942436f6037a1146b4963cdaff061a44\System.Design.ni.dll
+ 2009-09-08 13:42 . 2009-09-08 13:42 11411456 c:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\72b405b499c1f844b10aa67a839c6d5e\mscorlib.ni.dll
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{3041D03E-FD4B-44E0-B742-2D9B88305F98}"= "c:\program files\AskBarDis\bar\bin\askBar.dll" [BU]
[HKEY_CLASSES_ROOT\clsid\{3041d03e-fd4b-44e0-b742-2d9b88305f98}]
[HKEY_CLASSES_ROOT\TypeLib\{4b1c1e16-6b34-430e-b074-5928eca4c150}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="c:\program files\Messenger\msmsgs.exe" [2008-04-14 1695232]
"DAEMON Tools Lite"="c:\program files\DAEMON Tools Lite\daemon.exe" [2008-03-21 486856]
"swg"="c:\program files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2009-07-25 39408]
"Google Update"="c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-08-07 133104]
"MsnMsgr"="c:\program files\Windows Live\Messenger\MsnMsgr.Exe" [2009-07-26 3883856]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RemoteControl"="c:\program files\CyberLink\PowerDVD\PDVDServ.exe" [2005-12-08 30208]
"LanguageShortcut"="c:\program files\CyberLink\PowerDVD\Language\Language.exe" [2006-04-13 49152]
"avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"Flashget"="c:\program files\FlashGet\FlashGet.exe" [2007-09-25 2007088]
"TkBellExe"="c:\program files\Common Files\Real\Update_OB\realsched.exe" [2009-09-07 198160]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-25 149280]
"SMSERIAL"="sm56hlpr.exe" - c:\windows\sm56hlpr.exe [2004-12-28 544768]
"SoundMan"="SOUNDMAN.EXE" - c:\windows\SOUNDMAN.EXE [2006-08-03 577536]
"VTTimer"="VTTimer.exe" - c:\windows\system32\VTTimer.exe [2006-09-21 53248]
"VTTrayp"="VTtrayp.exe" - c:\windows\system32\VTTrayp.exe [2007-02-06 176128]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
Ela-Salaty.lnk - c:\program files\Ela-Salaty\Salaty.exe [2007-3-5 5349888]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
WinZip Quick Pick.lnk - c:\program files\WinZip\WZQKPICK.EXE [2009-6-19 525640]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=c:\windows\system32\wbsys.dll
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^PalTalk.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\PalTalk.lnk
backup=c:\windows\pss\PalTalk.lnkCommon Startup
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Ace Translator\\AceTrans.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\FlashGet\\flashget.exe"=
"c:\\Program Files\\BitComet\\BitComet.exe"=
"d:\\games\\iron grip\\
Grip Warlord.Up By GALLANT\\Rip Games\\igwarlord.exe"=
"d:\\games\\MOTO GP 2\\MOTOGP2_KazaMiza.Com\\motogp2.exe"=
"d:\\games\\Street Racing\\European Street Racing.exe"=
"d:\\more another\\TrackMania Nations ESWC\\TmNationsESWC.exe"=
"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Documents and Settings\\Administrator\\My Documents\\CyberLink\\DCC.exe"=
"c:\\Program Files\\Paltalk Messenger\\paltalk.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11368:TCP"= 11368:TCP:BitComet 11368 TCP
"11368:UDP"= 11368:UDP:BitComet 11368 UDP
R2 AntiVirSchedulerService;Avira AntiVir Scheduler;c:\program files\Avira\AntiVir Desktop\sched.exe [25/07/2009 06:53 ص 108289]
R2 HssSrv;Hotspot Shield Routing Service;c:\program files\Hotspot Shield\HssWPR\hsssrv.exe [06/08/2009 09:58 م 331824]
R3 tap0901;TAP-Win32 Adapter V9;c:\windows\system32\drivers\tap0901.sys [22/07/2009 10:13 م 28592]
S2 gupdate1ca1710ffec1b0;خدمة تحديث Google (gupdate1ca1710ffec1b0);c:\program files\Google\Update\GoogleUpdate.exe [07/08/2009 06:35 ص 133104]
S3 HssTrayService;Hotspot Shield Tray Service;c:\program files\Hotspot Shield\bin\HssTrayService.exe [11/08/2009 02:19 ص 57640]
S4 ASKService;ASKService;c:\program files\AskBarDis\bar\bin\AskService.exe [15/08/2009 05:03 ص 464264]
S4 ASKUpgrade;ASKUpgrade;c:\program files\AskBarDis\bar\bin\ASKUpgrade.exe [15/08/2009 05:03 ص 234888]
S4 Findbasic Service;Findbasic Service;c:\documents and settings\All Users\Application Data\Findbasic\findbasic121.exe [04/09/2009 10:36 ص 54776]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{970EA2E9-E7B8-45E1-9CB5-0DEB37C2C28D}]
%SystemRoot%\System32\regsvr32.exe /s c:\program files\Microsoft\Microsoft Maren\Bin\TextService.dll
.
Contents of the 'Scheduled Tasks' folder
2009-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-07 03:35]
2009-09-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2009-08-07 03:35]
2009-09-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-1364589140-725345543-500Core.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-26 03:43]
2009-09-09 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-861567501-1364589140-725345543-500UA.job
- c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-08-26 03:43]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://paltalk.myway.com
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
IE: &Download All with FlashGet - c:\program files\FlashGet\jc_all.htm
IE: &Download with FlashGet - c:\program files\FlashGet\jc_link.htm
IE: &تصدير إلى Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
IE: Download All Links with IDM - c:\program files\Internet Download Manager\IEGetAll.htm
IE: Download FLV video content with IDM - c:\program files\Internet Download Manager\IEGetVL.htm
IE: Download with IDM - c:\program files\Internet Download Manager\IEExt.htm
IE: تحميل الفيديو بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlfvideo.htm
IE: تحميل الكل بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlall.htm
IE: تحميل الكل بواسطة Internet Download Manager - c:\documents and settings\Administrator\My Documents\Downloads\Compressed\Internet Download Manager 5.17 by hasan ali\Internet Download Manager 5.17\crack\IEGetAll.htm
IE: تحميل المحددة بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dlselected.htm
IE: تحميل بواسطة Free Download Manager - file://c:\program files\Free Download Manager\dllink.htm
IE: تحميل بواسطة Internet Download Manager - c:\documents and settings\Administrator\My Documents\Downloads\Compressed\Internet Download Manager 5.17 by hasan ali\Internet Download Manager 5.17\crack\IEExt.htm
IE: تحميل محتوى FLV بواسطة Internet Download Manager - c:\documents and settings\Administrator\My Documents\Downloads\Compressed\Internet Download Manager 5.17 by hasan ali\Internet Download Manager 5.17\crack\IEGetVL.htm
LSP: c:\windows\system32\idmmbc.dll
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cfvjcna6.default\
FF - prefs.js: browser.search.defaulturl - hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT1561552&SearchSource=3&q={searchTerms}
FF - prefs.js: browser.search.selectedEngine - Ask
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com.sa/
FF - prefs.js: keyword.URL - hxxp://toolbar.ask.com/toolbarv/askRedirect?o=101795&gct=&gc=1&q=
FF - prefs.js: network.proxy.ftp - 127.0.0.1
FF - prefs.js: network.proxy.ftp_port - 4001
FF - prefs.js: network.proxy.gopher - 127.0.0.1
FF - prefs.js: network.proxy.gopher_port - 4001
FF - prefs.js: network.proxy.socks - 127.0.0.1
FF - prefs.js: network.proxy.socks_port - 4001
FF - prefs.js: network.proxy.ssl - 127.0.0.1
FF - prefs.js: network.proxy.ssl_port - 4001
FF - prefs.js: network.proxy.type - 4
FF - component: c:\documents and settings\Administrator\Application Data\IDM\idmmzcc2\components\idmmzcc.dll
FF - component: c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\cfvjcna6.default\extensions\{c95a4e8e-816d-4655-8c79-d736da1adb6d}\components\FFExternalAlert.dll
FF - component: c:\program files\Real\RealPlayer\browserrecord\firefox\ext\components\nprpffbrowserrecordext.dll
FF - plugin: c:\documents and settings\Administrator\Local Settings\Application Data\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Google\Update\1.2.183.7\npGoogleOneClick8.dll
FF - plugin: c:\program files\Windows Live\Photo Gallery\NPWLPG.dll
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
Rootkit scan 2009-09-09 14:59
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'lsass.exe'(1668)
c:\windows\system32\idmmbc.dll
- - - - - - - > 'explorer.exe'(3964)
c:\windows\system32\WININET.dll
c:\program files\FlashGet\fgmgr.dll
c:\windows\system32\ieframe.dll
.
Completion time: 2009-09-09 15:02
ComboFix-quarantined-files.txt 2009-09-09 12:01
Pre-Run: 8,526,102,528 bytes free
Post-Run: 8,617,353,216 bytes free
645 --- E O F --- 2009-08-26 10:00