Third portion
- 2008-04-14 00:11:57 310,272 ------w c:\windows\system32\mp43dmod.dll
+ 2006-10-19 01:47:14 4,096 ------w c:\windows\system32\MP43DMOD.dll
+ 2006-10-19 01:47:14 317,440 ------w c:\windows\system32\MP4SDECD.dll
- 2008-04-14 00:11:57 384,512 ------w c:\windows\system32\mp4sdmod.dll
+ 2006-10-19 01:47:14 4,096 ------w c:\windows\system32\MP4SDMOD.dll
+ 2006-10-19 01:47:14 259,072 ------w c:\windows\system32\MPG4DECD.dll
- 2008-04-14 00:11:57 240,640 ----a-w c:\windows\system32\mpg4dmod.dll
+ 2006-10-19 01:47:14 4,096 ----a-w c:\windows\system32\MPG4DMOD.dll
+ 2006-10-02 19:28:42 312,128 ------w c:\windows\system32\msdelta.dll
- 2008-04-14 00:12:55 259,072 ----a-w c:\windows\system32\msnetobj.dll
+ 2006-10-19 01:47:16 179,712 ----a-w c:\windows\system32\msnetobj.dll
- 2008-04-14 00:12:00 52,224 ------w c:\windows\system32\mspmsnsv.dll
+ 2006-10-19 01:47:16 27,136 ------w c:\windows\system32\mspmsnsv.dll
- 2008-04-14 00:12:00 201,728 ----a-w c:\windows\system32\mspmsp.dll
+ 2006-10-19 01:47:16 175,616 ----a-w c:\windows\system32\mspmsp.dll
- 2008-04-14 00:12:56 356,352 ----a-w c:\windows\system32\msscp.dll
+ 2006-12-04 20:21:50 414,720 ----a-w c:\windows\system32\msscp.dll
- 2008-04-14 00:12:01 245,760 ----a-w c:\windows\system32\mswmdm.dll
+ 2006-10-19 01:47:16 321,536 ----a-w c:\windows\system32\mswmdm.dll
+ 2006-11-23 04:55:48 782,336 ----a-w c:\windows\system32\OALInst.exe
- 2002-07-19 15:54:50 135,168 ----a-w c:\windows\system32\openal32.dll
+ 2002-07-19 14:54:50 135,168 ----a-w c:\windows\system32\openal32.dll
- 1999-12-17 06:00:00 6,752 ------w c:\windows\system32\PFMODNT.SYS
+ 1999-12-17 05:00:00 6,752 ------w c:\windows\system32\PFMODNT.SYS
- 2002-07-19 15:55:00 110,592 ----a-w c:\windows\system32\piaproxy.dll
+ 2007-04-09 16:21:42 81,920 ----a-w c:\windows\system32\piaproxy.dll
+ 2006-10-19 01:47:18 284,160 ------w c:\windows\system32\PortableDeviceApi.dll
+ 2006-10-19 01:47:18 101,888 ------w c:\windows\system32\PortableDeviceClassExtension.dll
+ 2006-10-19 01:47:18 166,912 ------w c:\windows\system32\PortableDeviceTypes.dll
+ 2006-10-19 01:47:18 132,096 ------w c:\windows\system32\PortableDeviceWiaCompat.dll
+ 2006-10-19 01:47:18 199,168 ------w c:\windows\system32\PortableDeviceWMDRM.dll
+ 2007-04-09 16:32:32 37,888 ----a-w c:\windows\system32\psconv.exe
- 2008-04-14 00:12:03 237,568 ----a-w c:\windows\system32\qasf.dll
+ 2006-10-19 01:47:18 211,456 ----a-w c:\windows\system32\qasf.dll
+ 2007-04-09 16:32:36 38,400 ----a-w c:\windows\system32\readreg.exe
+ 2007-04-09 16:21:44 48,128 ----a-w c:\windows\system32\regplib.exe
+ 2002-07-19 14:43:06 65,536 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\a3d.dll
+ 2002-07-19 14:46:28 127,948 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctac32k.sys
+ 2002-08-12 15:03:30 837,548 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctaud2k.sys
+ 2002-07-19 15:07:26 113,273 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctbas2w.dat
+ 2002-07-19 14:56:50 44,055 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctdaught.dat
+ 2002-07-19 15:07:30 164,044 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctdlang.dat
+ 2002-07-19 14:48:04 195,432 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctoss2k.sys
+ 2002-07-19 14:48:08 11,068 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctprxy2k.sys
+ 2002-07-19 14:48:22 213,860 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctsfm2k.sys
+ 2002-07-19 14:59:32 179,669 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ctstatic.dat
+ 2002-07-19 14:48:32 156,604 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\emupia2k.sys
+ 2002-08-12 14:49:32 998,004 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\ha10kx2k.sys
+ 2008-04-13 18:45:14 60,160 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\drmk.sys
+ 2008-04-13 19:16:36 141,056 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\ks.sys
+ 2008-04-14 01:11:56 4,096 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\ksuser.dll
+ 2008-04-13 19:19:42 146,048 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\portcls.sys
+ 2008-04-13 18:45:16 49,408 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\stream.sys
+ 2008-04-14 01:12:46 23,552 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\i386\wdmaud.drv
+ 2001-08-17 18:35:46 36,864 ----a-w c:\windows\system32\ReinstallBackups\
0008\DriverFiles\sfman32.dll
- 2001-08-17 19:35:44 36,864 ----a-w c:\windows\system32\sfman32.dll
+ 2007-04-09 16:21:48 22,528 ----a-w c:\windows\system32\sfman32.dll
- 2002-07-19 15:56:12 270,336 ----a-w c:\windows\system32\sfms32.dll
+ 2007-04-09 16:21:46 130,048 ----a-w c:\windows\system32\sfms32.dll
- 2008-10-13 18:55:34 16,928 ------w c:\windows\system32\spmsg.dll
+ 2007-07-27 13:41:40 16,760 ------w c:\windows\system32\spmsg.dll
+ 2006-10-19 01:58:00 8,704 ------w c:\windows\system32\uwdf.exe
+ 2006-10-19 01:47:18 4,096 ------w c:\windows\system32\wdfapi.dll
+ 2006-10-19 01:58:00 8,704 ------w c:\windows\system32\wdfmgr.exe
- 2008-04-14 00:12:09 408,064 ----a-w c:\windows\system32\wmadmod.dll
+ 2006-10-19 01:47:18 757,248 ----a-w c:\windows\system32\WMADMOD.dll
- 2008-04-14 00:12:09 670,720 ----a-w c:\windows\system32\wmadmoe.dll
+ 2006-10-19 01:47:18 1,117,696 ----a-w c:\windows\system32\WMADMOE.dll
- 2008-04-14 00:12:09 230,912 ----a-w c:\windows\system32\wmasf.dll
+ 2007-10-27 21:40:30 222,720 ----a-w c:\windows\system32\wmasf.dll
- 2008-04-14 00:12:09 27,136 ----a-w c:\windows\system32\wmdmlog.dll
+ 2006-10-19 01:47:18 33,792 ----a-w c:\windows\system32\wmdmlog.dll
- 2008-04-14 00:12:09 23,552 ----a-w c:\windows\system32\wmdmps.dll
+ 2006-10-19 01:47:18 37,376 ----a-w c:\windows\system32\wmdmps.dll
+ 2006-10-19 01:47:18 429,056 ------w c:\windows\system32\wmdrmdev.dll
+ 2006-10-19 01:47:20 348,672 ------w c:\windows\system32\wmdrmnet.dll
+ 2006-10-19 01:47:20 535,040 ------w c:\windows\system32\wmdrmsdk.dll
- 2008-04-13 17:23:24 168,448 ------w c:\windows\system32\wmerror.dll
+ 2006-10-19 01:47:20 227,328 ------w c:\windows\system32\wmerror.dll
- 2008-04-14 00:12:09 151,552 ------w c:\windows\system32\wmidx.dll
+ 2006-10-19 01:47:20 157,184 ----a-w c:\windows\system32\wmidx.dll
- 2008-06-10 11:11:46 1,053,696 ----a-w c:\windows\system32\WMNetmgr.dll
+ 2008-06-18 09:03:08 938,496 ----a-w c:\windows\system32\WMNetmgr.dll
- 2008-04-14 00:12:09 4,874,240 ------w c:\windows\system32\wmp.dll
+ 2007-06-12 03:51:12 10,834,944 ----a-w c:\windows\system32\wmp.dll
- 2008-04-14 00:12:09 114,688 ------w c:\windows\system32\wmpasf.dll
+ 2006-10-19 01:47:20 242,688 ------w c:\windows\system32\wmpasf.dll
- 2008-04-14 00:12:09 233,472 ------w c:\windows\system32\wmpdxm.dll
+ 2006-10-19 01:47:20 314,880 ------w c:\windows\system32\wmpdxm.dll
+ 2008-06-24 22:12:58 295,936 ------w c:\windows\system32\wmpeffects.dll
+ 2006-10-19 01:47:20 1,661,440 ------w c:\windows\system32\wmpencen.dll
- 2008-04-13 17:28:21 2,940,928 ----a-w c:\windows\system32\wmploc.dll
+ 2006-10-19 01:47:20 8,231,936 ----a-w c:\windows\system32\wmploc.dll
+ 2006-10-19 01:47:20 613,376 ------w c:\windows\system32\wmpmde.dll
+ 2006-10-19 01:47:20 130,048 ------w c:\windows\system32\wmpps.dll
- 2008-04-14 00:12:09 102,400 ----a-w c:\windows\system32\wmpshell.dll
+ 2006-10-19 01:47:20 99,840 ----a-w c:\windows\system32\wmpshell.dll
+ 2006-10-19 01:47:20 204,288 ------w c:\windows\system32\wmpsrcwp.dll
- 2008-04-14 00:12:09 759,296 ----a-w c:\windows\system32\wmsdmod.dll
+ 2006-10-19 01:47:22 4,096 ----a-w c:\windows\system32\wmsdmod.dll
- 2008-04-14 00:12:09 1,119,744 ------w c:\windows\system32\wmsdmoe2.dll
+ 2006-10-19 01:47:22 4,096 ------w c:\windows\system32\wmsdmoe2.dll
- 2008-04-14 00:12:09 485,376 ------w c:\windows\system32\wmspdmod.dll
+ 2006-10-19 01:47:22 603,648 ------w c:\windows\system32\WMSPDMOD.dll
- 2008-04-14 00:12:10 897,024 ------w c:\windows\system32\wmspdmoe.dll
+ 2006-10-19 01:47:22 1,329,152 ------w c:\windows\system32\WMSPDMOE.dll
+ 2006-10-19 01:47:22 4,096 ------w c:\windows\system32\WMVADVD.dll
+ 2006-10-19 01:47:22 4,096 ------w c:\windows\system32\WMVADVE.DLL
- 2008-11-07 21:45:32 2,174,976 ----a-w c:\windows\system32\WMVCore.dll
+ 2008-06-18 09:03:14 2,458,112 ----a-w c:\windows\system32\WMVCore.dll
+ 2006-10-19 01:47:22 1,543,680 ------w c:\windows\system32\WMVDECOD.dll
- 2008-04-14 00:12:10 809,984 ----a-w c:\windows\system32\wmvdmod.dll
+ 2006-10-19 01:47:22 4,096 ----a-w c:\windows\system32\wmvdmod.dll
- 2008-04-14 00:12:10 1,001,472 ------w c:\windows\system32\wmvdmoe2.dll
+ 2006-10-19 01:47:22 4,096 ------w c:\windows\system32\wmvdmoe2.dll
+ 2006-10-19 01:47:22 1,574,912 ------w c:\windows\system32\WMVENCOD.dll
+ 2006-10-19 01:47:22 1,382,912 ------w c:\windows\system32\WMVSDECD.dll
+ 2006-10-19 01:47:22 767,488 ------w c:\windows\system32\WMVSENCD.dll
+ 2006-10-19 01:47:22 656,896 ------w c:\windows\system32\WMVXENCD.dll
+ 2006-10-19 01:47:22 629,760 ------w c:\windows\system32\wpd_ci.dll
+ 2006-10-19 01:47:22 35,840 ------w c:\windows\system32\wpdconns.dll
+ 2006-10-19 01:47:22 154,624 ------w c:\windows\system32\wpdmtp.dll
+ 2006-10-19 01:47:22 63,488 ------w c:\windows\system32\wpdmtpus.dll
+ 2006-10-19 01:47:22 2,603,008 ------w c:\windows\system32\WpdShext.dll
+ 2006-10-19 00:00:14 17,408 ------w c:\windows\system32\wpdshextautoplay.exe
+ 2006-10-19 01:47:22 38,400 ------w c:\windows\system32\wpdshextres.dll
+ 2006-10-19 01:47:22 133,632 ------w c:\windows\system32\WPDShServiceObj.dll
+ 2006-10-19 01:47:22 356,352 ------w c:\windows\system32\wpdsp.dll
+ 2009-03-13 13:14:20 16,384 ----atw c:\windows\Temp\Perflib_Perfdata_208.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{EEE6C35D-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgHelper.dll" [2008-10-08 173368]
[HKEY_CLASSES_ROOT\clsid\{eee6c35d-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook.1]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SweetIM_URLSearchHook.ToolbarURLSearchHook]
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}]
2008-10-08 13:22 1172792 --a------ c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]
"{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792]
[HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3]
[HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}]
[HKEY_CLASSES_ROOT\SWEETIE.SWEETIE]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-13 15360]
"Skype"="c:\program files\Skype\Phone\Skype.exe" [2008-11-18 21633320]
"LDM"="c:\program files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe" [2009-02-11 16384]
"Uniblue RegistryBooster 2009"="c:\program files\Uniblue\RegistryBooster\RegistryBooster.exe" [2008-08-26 2019624]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"cctray"="c:\program files\CA\CA Internet Security Suite\cctray\cctray.exe" [2008-08-30 181488]
"CAVRID"="c:\program files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe" [2008-08-30 234736]
"capfupgrade"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe" [2008-08-28 259312]
"capfasem"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe" [2008-08-28 173296]
"cafw"="c:\program files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe" [2008-08-28 771312]
"SweetIM"="c:\program files\SweetIM\Messenger\SweetIM.exe" [2009-01-01 111928]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Jet Detection"="c:\program files\Creative\SBAudigy\PROGRAM\ADGJDet.exe" [2001-10-04 28672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-02-11 148888]
"LVCOMS"="c:\program files\Common Files\Logitech\QCDriver\LVCOMS.EXE" [2002-06-10 102400]
"LogitechGalleryRepair"="c:\program files\Logitech\ImageStudio\ISStart.exe" [2002-06-20 155648]
"LogitechImageStudioTray"="c:\program files\Logitech\ImageStudio\LogiTray.exe" [2002-06-20 45056]
"Adobe Photo Downloader"="c:\program files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe" [2007-03-09 63712]
"CTHelper"="CTHELPER.EXE" [2007-04-09 c:\windows\system32\CtHelper.exe]
"WINDVDPatch"="CTHELPER.EXE" [2007-04-09 c:\windows\system32\CtHelper.exe]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Logitech Desktop Messenger.lnk - c:\program files\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe [2009-02-11 169472]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"EnableShellExecuteHooks"= 1 (0x1)
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{1869181A-9F50-4FCF-8BFF-1B8588ECB85C}"= "c:\program files\CA\CA Internet Security Suite\CA Website Inspector\LinkAdvisor\CIDLinkAdvisor.dll" [2008-06-23 1373624]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\PFW]
2007-05-18 14:30 79368 c:\windows\system32\UmxWNP.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ctmp3"= c:\windows\system32\ctmp3.acm
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\CA Personal Firewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\ComputerAssociatesAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R0 KmxStart;KmxStart;c:\windows\system32\drivers\KmxStart.sys [2008-03-19 93712]
R1 KmxAgent;KmxAgent;c:\windows\system32\drivers\KmxAgent.sys [2008-03-21 63504]
R1 KmxFile;KmxFile;c:\windows\system32\drivers\KmxFile.sys [2008-03-21 45584]
R1 KmxFw;KmxFw;c:\windows\system32\drivers\KmxFw.sys [2008-03-19 115216]
R2 BRA_Scheduler;Brother BRAdminPro Scheduler;c:\program files\Brother\BRAdmin Professional 3\bratimer.exe [2009-02-11 65536]
R2 KmxCF;KmxCF;c:\windows\system32\drivers\KmxCF.sys [2008-06-04 134648]
R2 KmxSbx;KmxSbx;c:\windows\system32\drivers\KmxSbx.sys [2008-03-21 66576]
R2 UmxAgent;HIPS Event Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter;c:\program files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296]
R2 UmxPol;HIPS Policy Manager;c:\program files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-04-15 281104]
R3 KmxCfg;KmxCfg;c:\windows\system32\drivers\KmxCfg.sys [2008-05-30 88816]
R3 LNE100;Linksys LNE100TX(v5) Fast Ethernet Adapter;c:\windows\system32\drivers\lne100v5.sys [2008-02-06 36224]
R3 PPCtlPriv;PPCtlPriv;c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe [2008-10-01 185584]
S3 getPlus(R) Helper;getPlus(R) Helper;c:\program files\NOS\bin\getPlus_HelperSvc.exe [2008-12-18 33752]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
Contents of the 'Scheduled Tasks' folder
2008-12-04 c:\windows\Tasks\CAAntiSpywareScan_Daily as Owner at 1 03 AM.job
- c:\program files\CA\CA Internet Security Suite\CA Anti-Spyware\CAAntiSpyware.exe [2008-08-27 18:44]
2009-03-13 c:\windows\Tasks\Check Updates for Windows Live Toolbar.job
- c:\program files\Windows Live Toolbar\MSNTBUP.EXE [2007-10-19 13:20]
2009-03-12 c:\windows\Tasks\ParetoLogic Registration.job
- c:\program files\Common Files\ParetoLogic\UUS2\UUS.dll []
2009-03-11 c:\windows\Tasks\ParetoLogic Update Version2.job
- c:\program files\Common Files\ParetoLogic\UUS2\Pareto_Update.exe []
2009-03-13 c:\windows\Tasks\RegCure Program Check.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 14:55]
2008-12-21 c:\windows\Tasks\RegCure.job
- c:\program files\RegCure\RegCure.exe [2008-11-27 14:55]
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-WebCamRT.exe - (no file)
.
------- Supplementary Scan -------
.
uInternet Settings,ProxyOverride = localhost
LSP: c:\windows\system32\VetRedir.dll
DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab
DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab
.
**************************************************************************
catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-03-13 09:28:42
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(1688)
c:\windows\system32\UmxWnp.Dll
c:\program files\CA\SharedComponents\PPRT\bin\CACheck.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAHook.dll
c:\program files\CA\SharedComponents\PPRT\bin\CAServer.dll
.
Completion time: 2009-03-13 9:30:59
ComboFix-quarantined-files.txt 2009-03-13 13:30:51
ComboFix2.txt 2009-03-12 19:49:34
Pre-Run: 180,625,656,832 bytes free
Post-Run: 180,925,233,152 bytes free
910 --- E O F --- 2009-03-13 04:29:48