Part 5 of 5 ... hopefully:
(((((((((((((((((((((((((((((
SnapShot@2012-03-26_13.03.58 )))))))))))))))))))))))))))))))))))))))))
.
+ 2012-04-12 01:17 . 2012-04-12 01:17 16384 c:\windows\temp\Perflib_Perfdata_134.dat
- 2010-04-24 17:52 . 2009-01-07 22:21 26144 c:\windows\system32\spupdsvc.exe
+ 2010-04-24 17:52 . 2008-11-07 22:55 26144 c:\windows\system32\spupdsvc.exe
+ 2012-04-09 03:19 . 2008-04-13 23:00 12160 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\mouhid.sys
+ 2012-04-09 03:19 . 2008-04-13 23:00 23040 c:\windows\system32\ReinstallBackups\0008\DriverFiles\i386\mouclass.sys
+ 2012-04-09 03:08 . 2008-04-14 09:42 23552 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\wdmaud.drv
+ 2012-04-09 03:08 . 2008-04-14 05:15 49408 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\stream.sys
+ 2012-04-09 03:08 . 2008-04-14 05:15 60160 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\drmk.sys
+ 2012-04-09 03:08 . 2008-10-31 15:52 93184 c:\windows\system32\ReinstallBackups\0007\DriverFiles\AtiHdmi.sys
+ 2012-03-27 20:05 . 2008-04-14 04:09 14592 c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\kbdhid.sys
+ 2012-03-27 20:05 . 2008-04-14 04:09 24576 c:\windows\system32\ReinstallBackups\0006\DriverFiles\i386\kbdclass.sys
+ 2012-03-27 20:05 . 2008-04-13 23:00 32128 c:\windows\system32\ReinstallBackups\0005\DriverFiles\i386\usbccgp.sys
+ 2012-04-09 03:07 . 2001-11-09 13:01 24064 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ativcoxx.dll
+ 2012-04-09 03:07 . 2008-11-12 23:19 17408 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atitvo32.dll
+ 2012-04-09 03:07 . 2008-10-21 14:40 81920 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ATIODE.exe
+ 2012-04-09 03:07 . 2008-10-21 14:40 45056 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ATIODCLI.exe
+ 2012-04-09 03:07 . 2008-11-13 00:05 53248 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ATIDDC.DLL
+ 2012-04-09 03:07 . 2008-11-12 23:20 86016 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atiadlxx.dll
+ 2012-04-09 03:07 . 2008-11-13 00:08 26112 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\Ati2mdxx.exe
+ 2012-04-09 03:07 . 2008-11-12 23:19 53248 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2erec.dll
+ 2012-04-09 03:07 . 2008-11-13 00:08 43520 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2edxx.dll
+ 2012-04-09 03:07 . 2008-11-12 23:25 48640 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\amdpcom32.dll
+ 2012-04-09 02:58 . 2012-02-15 15:01 43520 c:\windows\system32\DRVSTORE\usbaapl_87F84F5DA3368BC69CA5BE7F6A79CAA709E36E13\usbaapl.sys
+ 2012-04-09 03:19 . 2011-08-01 19:56 40936 c:\windows\system32\DRVSTORE\point32_F3A4C20ECDA4E2F8AC61BB0104098F5E3A155AB4\point32.sys
+ 2012-03-27 20:05 . 2011-08-10 20:39 21784 c:\windows\system32\DRVSTORE\nuidfltr_E43E90E372F0A2F8BC202108BA821FE6CFC086E0\NuidFltr.sys
+ 2012-03-27 20:05 . 2011-08-10 20:39 45288 c:\windows\system32\DRVSTORE\dc3du_39E47C72985BACB24FE918E6F37284425E557DA1\dc3d.sys
+ 2012-04-09 03:19 . 2011-08-01 19:56 45288 c:\windows\system32\DRVSTORE\dc3dh_5AAC9D9A8E42927AFEBA0780EF6036EE556BE709\dc3d.sys
+ 2012-04-09 03:07 . 2012-03-09 03:52 82639 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\oemdspif.dll
+ 2012-04-09 03:07 . 2001-11-09 16:01 12614 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ativcoxx.dll
+ 2012-04-09 03:07 . 2010-08-27 18:32 81222 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiode.exe
+ 2012-04-09 03:07 . 2009-06-22 15:34 25130 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiodcli.exe
+ 2012-04-09 03:07 . 2012-03-09 04:12 41500 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atimpc32.dll
+ 2012-04-09 03:07 . 2012-03-09 03:48 28700 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiddc.dll
+ 2012-04-09 03:07 . 2009-05-11 21:35 71662 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atibtmon.exe
+ 2012-04-09 03:07 . 2012-03-09 03:46 61529 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiapfxx.exe
+ 2012-04-09 03:07 . 2012-03-09 03:52 16309 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2mdxx.exe
+ 2012-04-09 03:07 . 2012-03-09 04:21 13670 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2erec.dll
+ 2012-04-09 03:07 . 2012-03-09 03:51 28844 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2edxx.dll
+ 2009-07-14 14:35 . 2009-07-14 14:35 37608 c:\windows\system32\drivers\wdfldr.sys
+ 2008-04-13 23:00 . 2008-04-14 04:15 32128 c:\windows\system32\drivers\usbccgp.sys
- 2008-04-13 23:00 . 2008-04-13 23:00 32128 c:\windows\system32\drivers\usbccgp.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 49408 c:\windows\system32\drivers\stream.sys
+ 2008-04-14 00:15 . 2008-04-14 04:15 49408 c:\windows\system32\drivers\stream.sys
- 2001-08-17 13:48 . 2008-04-13 23:00 12160 c:\windows\system32\drivers\mouhid.sys
+ 2001-08-17 13:48 . 2001-08-17 17:48 12160 c:\windows\system32\drivers\mouhid.sys
- 2008-04-14 00:09 . 2008-04-13 23:00 23040 c:\windows\system32\drivers\mouclass.sys
+ 2008-04-14 00:09 . 2008-04-14 04:09 23040 c:\windows\system32\drivers\mouclass.sys
+ 2008-04-13 23:00 . 2008-04-14 04:09 14592 c:\windows\system32\drivers\kbdhid.sys
- 2008-04-13 23:00 . 2008-04-13 23:00 14592 c:\windows\system32\drivers\kbdhid.sys
- 2008-04-13 23:00 . 2008-04-13 23:00 24576 c:\windows\system32\drivers\kbdclass.sys
+ 2008-04-13 23:00 . 2008-04-14 04:09 24576 c:\windows\system32\drivers\kbdclass.sys
+ 2010-04-24 18:52 . 2008-04-14 04:15 60160 c:\windows\system32\drivers\drmk.sys
- 2010-04-24 18:52 . 2008-04-14 05:15 60160 c:\windows\system32\drivers\drmk.sys
+ 2008-04-13 23:00 . 2008-04-14 04:15 32128 c:\windows\system32\dllcache\usbccgp.sys
- 2008-04-14 00:15 . 2008-04-14 05:15 49408 c:\windows\system32\dllcache\stream.sys
+ 2008-04-14 00:15 . 2008-04-14 04:15 49408 c:\windows\system32\dllcache\stream.sys
+ 2001-08-17 13:48 . 2001-08-17 17:48 12160 c:\windows\system32\dllcache\mouhid.sys
+ 2008-04-14 00:09 . 2008-04-14 04:09 23040 c:\windows\system32\dllcache\mouclass.sys
+ 2008-04-13 23:00 . 2008-04-14 04:09 14592 c:\windows\system32\dllcache\kbdhid.sys
+ 2008-04-13 23:00 . 2008-04-14 04:09 24576 c:\windows\system32\dllcache\kbdclass.sys
+ 2010-04-24 18:52 . 2008-04-14 04:15 60160 c:\windows\system32\dllcache\drmk.sys
- 2010-04-24 18:52 . 2008-04-14 05:15 60160 c:\windows\system32\dllcache\drmk.sys
- 2010-04-25 14:36 . 2001-11-09 13:01 24064 c:\windows\system32\ativcoxx.dll
+ 2010-04-25 14:36 . 2001-11-09 16:01 24064 c:\windows\system32\ativcoxx.dll
+ 2010-04-25 14:36 . 2009-06-22 15:34 45056 c:\windows\system32\ATIODCLI.exe
- 2010-04-25 14:36 . 2008-10-21 14:40 45056 c:\windows\system32\ATIODCLI.exe
+ 2012-03-26 22:44 . 2012-03-26 22:44 22016 c:\windows\Installer\1bf73a1.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{FF9B0E3E-9D2E-2560-EEA2-BB35A369C491}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{FBFC6AFA-082C-CBEC-3D28-1EE9CA16D029}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{FA584B62-7ECF-A981-0D1E-A8BE67C604DB}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{F748B53A-A58F-17B4-F380-08EF92B6A6F4}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{E8D9FAA2-D3DB-7FA3-3FFE-0AC935251F99}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{DE464235-13EC-F0E2-2608-9A8103F52DF8}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{DA3DB4D7-429D-4292-F855-C47C6EA1AFF8}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{D3CD290C-C254-F440-962D-F9D0E60DD3F4}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{C6BD88D1-A8D3-B46F-781E-80A6A6927E09}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{BBC2068D-CE9C-48F5-A6EA-4B44B9DB14A5}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{B802B2D2-C777-1876-8204-C0F360CBF955}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{AB4FE709-7AC5-A7FF-A947-A110CEFCB074}\ARPPRODUCTICON.exe
+ 2012-04-09 03:07 . 2012-04-09 03:07 88102 c:\windows\Installer\{A997829F-090A-06FC-ADDA-B907E0D2562E}\NewShortcut5_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2012-04-09 03:07 . 2012-04-09 03:07 88102 c:\windows\Installer\{A997829F-090A-06FC-ADDA-B907E0D2562E}\NewShortcut4_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2012-04-09 03:07 . 2012-04-09 03:07 88102 c:\windows\Installer\{A997829F-090A-06FC-ADDA-B907E0D2562E}\NewShortcut3_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2012-04-09 03:07 . 2012-04-09 03:07 88102 c:\windows\Installer\{A997829F-090A-06FC-ADDA-B907E0D2562E}\NewShortcut2_4DEA5338A7B840A3B51CDC742625BF49.exe
+ 2012-04-09 03:07 . 2012-04-09 03:07 88102 c:\windows\Installer\{A997829F-090A-06FC-ADDA-B907E0D2562E}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{9BA4C082-183A-4869-06DB-4F563355D33F}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{96A092BE-173D-6824-14FD-1C8C0477C1D1}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{950A97A5-F8AF-26C7-8F8B-47F7C1F03363}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{8FB7E2C1-13A7-F9A0-277F-8CFB5B198E7E}\ARPPRODUCTICON.exe
+ 2010-06-05 07:00 . 2012-04-03 19:51 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
- 2010-06-05 07:00 . 2012-02-15 13:51 49152 c:\windows\Installer\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}\ConfigIcon.dll
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{821CF756-EDC0-5A8C-6ECA-3F4682DEAFD1}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{76B0FAA5-C23B-58E8-EB51-1195A4D6BEB7}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{69101ED4-FAEB-44EE-1A0E-0602CD6458F3}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{653B7F6E-F594-4B55-61BA-78F8FE6E500A}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{5DCB68D8-686F-0550-6DD3-957A366F8F99}\ARPPRODUCTICON.exe
+ 2012-04-09 03:06 . 2012-04-09 03:06 10134 c:\windows\Installer\{59A86970-E9AB-0D1D-A269-2381A89F0CF2}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{41B4F085-82E5-C9C2-9AB3-65D67EF60883}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{3BDCECE1-F7F8-81E3-EE26-AF8FD5172A56}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{3179E96B-2CCF-A00A-5738-4C14DBA0DACA}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{23481C75-AA13-858C-C707-51D7744F2309}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{0A68C819-3333-E57F-5881-D3FE31C1F2D5}\ARPPRODUCTICON.exe
+ 2012-04-09 03:10 . 2012-04-09 03:10 10134 c:\windows\Installer\{036138A4-CE69-54B3-EC3A-22EC160303E0}\ARPPRODUCTICON.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 17304 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\ViewerPS.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 35736 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\reader_sl.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 88992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlr.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 94608 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\eula.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 49064 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrotextextractor.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 17824 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32Info.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 63912 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acroiehelpershim.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 64928 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroIEHelper.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 63384 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\Acrofx32.dll
+ 2012-04-09 03:08 . 2008-04-14 10:41 4096 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\ksuser.dll
+ 2010-04-24 18:52 . 2008-04-14 09:41 4096 c:\windows\system32\ksuser.dll
- 2010-04-24 18:52 . 2008-04-14 10:41 4096 c:\windows\system32\ksuser.dll
+ 2012-04-09 03:07 . 2012-03-09 03:36 8348 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atitvo32.dll
+ 2010-04-24 18:52 . 2008-04-14 09:41 4096 c:\windows\system32\dllcache\ksuser.dll
- 2010-04-24 18:52 . 2008-04-14 10:41 4096 c:\windows\system32\dllcache\ksuser.dll
+ 2012-04-09 03:10 . 2012-04-09 03:10 9662 c:\windows\Installer\{69101ED4-FAEB-44EE-1A0E-0602CD6458F3}\NewShortcut11_EAB9635D261D49BE88DDE71A7C809B2D.exe
+ 2012-04-09 03:08 . 2008-04-14 05:49 146048 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\portcls.sys
+ 2012-04-09 03:08 . 2008-04-14 05:46 141056 c:\windows\system32\ReinstallBackups\0007\DriverFiles\i386\ks.sys
+ 2012-04-09 03:07 . 2008-11-13 00:08 147456 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\Oemdspif.dll
+ 2012-04-09 03:07 . 2008-11-12 23:39 887724 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ativva6x.dat
+ 2012-04-09 03:07 . 2008-11-13 00:08 188416 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atipdlxx.dll
+ 2012-04-09 03:07 . 2008-11-12 23:18 286720 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atiok3x2.dll
+ 2012-04-09 03:07 . 2008-11-12 23:21 401408 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atikvmag.dll
+ 2012-04-09 03:07 . 2008-11-12 23:47 307200 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atiiiexx.dll
+ 2012-04-09 03:07 . 2008-10-30 11:45 180720 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atiicdxx.dat
+ 2012-04-09 03:07 . 2008-11-13 00:20 425984 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ATIDEMGX.dll
+ 2012-04-09 03:07 . 2008-10-21 15:51 118784 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atibrtmon.exe
+ 2012-04-09 03:07 . 2008-11-13 00:06 598016 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2evxx.exe
+ 2012-04-09 03:07 . 2008-11-13 00:07 143360 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2evxx.dll
+ 2012-04-09 03:07 . 2008-11-13 00:19 318464 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2dvag.dll
+ 2012-04-09 03:07 . 2008-11-12 23:13 577536 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2cqag.dll
+ 2012-04-03 19:42 . 2012-04-03 19:42 353440 c:\windows\system32\Macromed\Flash\FlashUtil32_11_2_202_228_Plugin.exe
+ 2012-04-03 21:33 . 2012-04-03 21:33 353440 c:\windows\system32\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.exe
+ 2012-04-03 21:33 . 2012-04-03 21:33 424608 c:\windows\system32\Macromed\Flash\FlashUtil32_11_2_202_228_ActiveX.dll
+ 2012-04-03 19:42 . 2012-04-03 21:33 253600 c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
+ 2012-04-03 19:46 . 2012-04-08 21:54 224136 c:\windows\system32\javaws.exe
+ 2012-04-03 19:46 . 2012-04-08 21:54 173960 c:\windows\system32\javaw.exe
+ 2012-04-03 19:46 . 2012-04-08 21:54 173960 c:\windows\system32\java.exe
+ 2010-04-24 12:44 . 2012-04-12 01:00 366320 c:\windows\system32\FNTCACHE.DAT
- 2010-04-24 12:44 . 2012-03-17 18:31 366320 c:\windows\system32\FNTCACHE.DAT
+ 2012-04-09 03:19 . 2011-08-01 19:56 395624 c:\windows\system32\DRVSTORE\dc3dh_5AAC9D9A8E42927AFEBA0780EF6036EE556BE709\ipcoin82.dll
+ 2012-04-09 03:07 . 2012-03-09 04:51 501666 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ativvamv.dll
+ 2012-04-09 03:07 . 2012-03-09 04:30 887724 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ativva6x.dat
+ 2012-04-09 03:07 . 2012-03-09 03:52 110666 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atipdlxx.dll
+ 2012-04-09 03:07 . 2012-03-09 04:24 313812 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiok3x2.dll
+ 2012-04-09 03:07 . 2012-03-09 03:41 440762 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atikvmag.dll
+ 2012-04-09 03:07 . 2012-03-09 06:14 311296 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiiiexx.dll
+ 2012-04-09 03:07 . 2012-01-10 21:10 601728 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiicdxx.dat
+ 2012-04-09 03:07 . 2012-03-09 04:20 442368 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atidemgx.dll
+ 2012-04-09 03:07 . 2012-03-09 03:36 127858 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atiadlxx.dll
+ 2012-04-09 03:07 . 2012-03-09 03:50 346312 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2evxx.exe
+ 2012-04-09 03:07 . 2012-03-09 03:51 103718 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2evxx.dll
+ 2012-04-09 03:07 . 2012-03-09 04:18 192091 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2dvag.dll
+ 2012-04-09 03:07 . 2012-03-09 03:29 458468 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2cqag.dll
+ 2012-04-09 03:07 . 2011-12-20 07:39 100368 c:\windows\system32\DRVSTORE\AtihdXP3_C7329EE4FFEA165CE978211609F4AA169F815120\AtihdXP3.sys
+ 2009-07-14 14:35 . 2009-07-14 14:35 444136 c:\windows\system32\drivers\wdf01000.sys
- 2010-04-24 18:52 . 2008-04-14 05:49 146048 c:\windows\system32\drivers\portcls.sys
+ 2010-04-24 18:52 . 2008-04-14 04:49 146048 c:\windows\system32\drivers\portcls.sys
+ 2008-04-14 00:46 . 2008-04-14 04:46 141056 c:\windows\system32\drivers\ks.sys
- 2008-04-14 00:46 . 2008-04-14 05:46 141056 c:\windows\system32\drivers\ks.sys
+ 2010-04-24 18:52 . 2008-04-14 04:49 146048 c:\windows\system32\dllcache\portcls.sys
- 2010-04-24 18:52 . 2008-04-14 05:49 146048 c:\windows\system32\dllcache\portcls.sys
+ 2008-04-14 00:46 . 2008-04-14 04:46 141056 c:\windows\system32\dllcache\ks.sys
- 2008-04-14 00:46 . 2008-04-14 05:46 141056 c:\windows\system32\dllcache\ks.sys
+ 2002-04-11 14:41 . 2004-11-17 14:29 254000 c:\windows\system32\dllcache\a3d.dll
+ 2012-03-27 19:17 . 2012-03-27 19:17 262144 c:\windows\system32\config\systemprofile\NTUSER.DAT
- 2010-04-25 14:36 . 2008-11-12 23:39 887724 c:\windows\system32\ativva6x.dat
+ 2010-04-25 14:36 . 2012-03-09 04:30 887724 c:\windows\system32\ativva6x.dat
+ 2010-04-25 14:36 . 2010-08-27 18:32 294912 c:\windows\system32\ATIODE.exe
+ 2010-04-25 14:36 . 2012-01-10 21:10 601728 c:\windows\system32\atiicdxx.dat
+ 2002-04-11 14:41 . 2004-11-17 14:29 254000 c:\windows\system32\A3D.dll
+ 2012-04-09 03:10 . 2012-04-09 03:10 232960 c:\windows\Installer\d6352af.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 418304 c:\windows\Installer\d6352a9.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251904 c:\windows\Installer\d6352a3.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 249344 c:\windows\Installer\d63529d.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635297.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635291.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d63528b.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635285.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250880 c:\windows\Installer\d63527f.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635279.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635273.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d63526d.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250880 c:\windows\Installer\d635267.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250880 c:\windows\Installer\d635261.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d63525b.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635255.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d63524f.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635249.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d635243.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d63523d.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d635237.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d635231.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 251392 c:\windows\Installer\d63522b.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 250368 c:\windows\Installer\d635225.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 265728 c:\windows\Installer\d63521e.msi
+ 2012-04-09 03:10 . 2012-04-09 03:10 356352 c:\windows\Installer\d635218.msi
+ 2012-04-09 03:06 . 2012-04-09 03:06 442368 c:\windows\Installer\d6350b8.msi
+ 2012-04-08 21:57 . 2012-04-08 21:57 176128 c:\windows\Installer\c4d93de.msi
+ 2012-04-08 21:54 . 2012-04-08 21:54 938496 c:\windows\Installer\c4d93ce.msi
+ 2012-04-09 03:19 . 2012-04-09 03:19 301056 c:\windows\Installer\62f94.msi
+ 2012-04-03 19:46 . 2012-04-03 19:46 901120 c:\windows\Installer\1984bc6.msi
+ 2012-04-09 03:02 . 2012-04-09 03:02 380928 c:\windows\Installer\{23B8A91D-680B-462B-87AD-3D70F7341731}\iTunesIco.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 249232 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\sqlite.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 394136 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\pdfshell.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 103848 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\PDFPrevHndlrShim.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 183696 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\nppdf32.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 104344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AiodLite.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 937920 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\adobearm.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 102808 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRdIF.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 755088 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroPDF.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 296344 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\acrobroker.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 205720 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\a3dutils.dll
+ 2012-04-09 03:07 . 2008-11-12 23:39 2495232 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ativvaxx.dll
+ 2012-04-09 03:07 . 2008-11-12 23:39 3107788 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ativvaxx.dat
+ 2012-04-09 03:07 . 2008-11-12 23:39 3107788 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ativva5x.dat
+ 2012-04-09 03:07 . 2008-11-12 23:55 4118592 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati3duag.dll
+ 2012-04-09 03:07 . 2008-11-13 01:41 3451904 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\ati2mtag.sys
+ 2012-04-03 19:42 . 2012-04-03 19:42 8797344 c:\windows\system32\Macromed\Flash\NPSWF32_11_2_202_228.dll
+ 2012-04-09 02:58 . 2012-02-15 15:01 4547944 c:\windows\system32\DRVSTORE\usbaapl_87F84F5DA3368BC69CA5BE7F6A79CAA709E36E13\usbaaplrc.dll
+ 2012-04-09 03:19 . 2011-08-01 19:56 1461992 c:\windows\system32\DRVSTORE\point32_F3A4C20ECDA4E2F8AC61BB0104098F5E3A155AB4\wdfcoinstaller01009.dll
+ 2012-03-27 20:05 . 2011-08-10 20:39 1461992 c:\windows\system32\DRVSTORE\nuidfltr_E43E90E372F0A2F8BC202108BA821FE6CFC086E0\wdfcoinstaller01009.dll
+ 2012-03-27 20:05 . 2011-08-10 20:39 1461992 c:\windows\system32\DRVSTORE\dc3du_39E47C72985BACB24FE918E6F37284425E557DA1\WdfCoInstaller01009.dll
+ 2012-04-09 03:19 . 2011-08-01 19:56 1461992 c:\windows\system32\DRVSTORE\dc3dh_5AAC9D9A8E42927AFEBA0780EF6036EE556BE709\WdfCoInstaller01009.dll
+ 2012-04-09 03:07 . 2012-03-09 04:36 2115978 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ativvaxx.dll
+ 2012-04-09 03:07 . 2012-03-09 05:19 8621953 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\atioglxx.dll
+ 2012-04-09 03:07 . 2012-03-09 05:02 2836003 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati3duag.dll
+ 2012-04-09 03:07 . 2012-03-09 06:22 5043939 c:\windows\system32\DRVSTORE\CX135748_5FFE3C5FB83A59104D8CE155848AB6353F2162B4\B134676\ati2mtag.sys
+ 2010-04-25 14:35 . 2010-08-05 02:16 2127728 c:\windows\system32\drivers\viahduaa.sys
+ 2010-04-25 14:36 . 2012-03-09 06:22 7586304 c:\windows\system32\dllcache\ati2mtag.sys
+ 2012-04-09 03:10 . 2012-04-09 03:10 1136128 c:\windows\Installer\d6352b6.msi
+ 2012-04-09 03:07 . 2012-04-09 03:07 1720832 c:\windows\Installer\d6350bf.msi
+ 2012-04-09 03:02 . 2012-04-09 03:02 4288000 c:\windows\Installer\d6350b2.msi
+ 2012-04-09 02:58 . 2012-04-09 02:58 1718784 c:\windows\Installer\d634529.msi
+ 2012-04-09 02:56 . 2012-04-09 02:56 1530368 c:\windows\Installer\d6344d5.msi
+ 2012-04-08 21:58 . 2012-04-08 21:58 9474048 c:\windows\Installer\c4d968a.msi
+ 2012-03-27 20:05 . 2012-03-27 20:05 1289728 c:\windows\Installer\9c830.msi
+ 2012-04-09 03:20 . 2012-04-09 03:20 1415680 c:\windows\Installer\63105.msi
+ 2012-04-03 19:55 . 2012-04-03 19:55 2295808 c:\windows\Installer\1984cac.msi
+ 2011-06-06 16:55 . 2011-06-06 16:55 2215312 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\rt3d.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 1189004 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\JSByteCodeWin.bin
+ 2011-06-06 16:55 . 2011-06-06 16:55 6543768 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\authplay.dll
+ 2011-06-06 16:55 . 2011-06-06 16:55 1240992 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AdobeCollabSync.exe
+ 2011-06-06 16:55 . 2011-06-06 16:55 1480600 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.exe
+ 2012-04-09 03:07 . 2008-11-13 00:12 11304960 c:\windows\system32\ReinstallBackups\0002\DriverFiles\B_72069\atioglxx.dll
+ 2012-01-03 17:44 . 2012-01-03 17:44 15929344 c:\windows\Installer\1984cad.msp
+ 2012-04-03 19:51 . 2012-04-03 19:51 23622656 c:\windows\Installer\1984be1.msp
+ 2011-06-06 16:55 . 2011-06-06 16:55 24731544 c:\windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\AcroRd32.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\URLSearchHooks]
"{81017EA9-9AA8-4A6A-9734-7AF40E7D593F}"= "c:\program files\Yahoo!\Companion\Installs\cpn0\yt.dll" [2012-01-12 1517368]
.
[HKEY_CLASSES_ROOT\clsid\{81017ea9-9aa8-4a6a-9734-7af40e7d593f}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin.1]
[HKEY_CLASSES_ROOT\TypeLib\{003028C2-EA1C-4676-A316-B5CB50917002}]
[HKEY_CLASSES_ROOT\yt.YTNavAssistPlugin]
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Creative Detector"="c:\program files\Creative\MediaSource\Detector\CTDetect.exe" [2004-12-02 102400]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PDVDDXSrv"="c:\program files\CyberLink\PowerDVD DX\PDVDDXSrv.exe" [2009-06-25 140520]
"LockStatusTray"="c:\windows\LockStatusTray.exe" [2008-02-19 192512]
"ArcSoft Connection Service"="c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe" [2010-10-28 207424]
"EEventManager"="c:\program files\EPSON\Creativity Suite\Event Manager\EEventManager.exe" [2006-10-12 102400]
"Acrobat Assistant 7.0"="c:\program files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe" [2008-04-23 483328]
"P17Helper"="P17.dll" [2005-05-04 64512]
"CTSysVol"="c:\program files\Creative\SBAudigy\Surround Mixer\CTSysVol.exe" [2005-10-31 57344]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"AmazonGSDownloaderTray"="c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderTray.exe" [2009-10-23 326144]
"Desktop Disc Tool"="c:\program files\Roxio\Roxio Burn\RoxioBurnLauncher.exe" [2009-12-16 498160]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2011-06-15 997920]
"KodakShareButtonApp"="c:\program files\Kodak\KODAK Share Button App\Listener.exe" [2011-03-07 107008]
"itype"="c:\program files\Microsoft IntelliType Pro\itype.exe" [2011-08-10 1313640]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]
"WinPatrol"="c:\program files\BillP Studios\WinPatrol\winpatrol.exe" [2012-03-25 329312]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]
"StartCCC"="c:\program files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-03-09 98304]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-08-01 1821576]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"DWQueuedReporting"="c:\progra~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" [2007-02-26 437160]
.
c:\documents and settings\Papi\Start Menu\Programs\Startup\
SpywareGuard.lnk - c:\program files\SpywareGuard\sgmain.exe [2003-8-29 360448]
.
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Acrobat Speed Launcher.lnk - c:\windows\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe [2010-4-26 25214]
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2010-4-26 110592]
Camera Monitor HD.lnk - c:\program files\PIXELA\Everio MediaBrowser HD Edition\MBCameraMonitor.exe [2011-12-10 541976]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\MRCNotify]
2011-10-14 20:20 54224 ----a-w- c:\windows\dwrcs\DWRCWXL.dll
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
.
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Quicken\\qw.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeCam.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeEnC2.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeExp.exe"=
"c:\\Program Files\\Microsoft LifeCam\\LifeTray.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Google\\Google Earth\\plugin\\geplugin.exe"=
"c:\\Program Files\\Microsoft Games\\Age of Empires\\EMPIRESX.EXE"=
"c:\\WINDOWS\\system32\\mmc.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"c:\\WINDOWS\\system32\\dplaysvr.exe"=
"c:\\Program Files\\Sony Online Entertainment\\Installed Games\\DC Universe Online Live\\UNREAL3\\BINARIES\\WIN32\\DCGAME.EXE"=
"c:\\Program Files\\VideoLAN\\VLC\\vlc.exe"=
"c:\\Program Files\\Winamp\\winamp.exe"=
"c:\\Program Files\\Common Files\\Apple\\Apple Application Support\\WebKit2WebProcess.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
.
R2 AMD_RAIDXpert;AMD RAIDXpert;c:\program files\AMD\RAIDXpert\bin\RAIDXpertService.exe [10/2/2008 5:26 PM 122880]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdXP3.sys [4/8/2012 11:07 PM 100368]
R3 dc3d;MS Hardware Device Detection Driver (USB);c:\windows\system32\drivers\dc3d.sys [3/27/2012 4:05 PM 45288]
R3 Linksys_adapter_H;Linksys Adapter Network Driver;c:\windows\system32\drivers\AE2500xp.sys [10/7/2011 10:06 PM 1034240]
R3 VIAHdAudAddService;VIA High Definition Audio Driver Service;c:\windows\system32\drivers\viahduaa.sys [4/25/2010 10:35 AM 2127728]
S0 cerc6;cerc6;
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [7/9/2011 4:19 PM 136176]
S3 A5AGU;D-Link USB Wireless Network Adapter Service;c:\windows\system32\drivers\A5AGU.sys [4/24/2010 1:35 PM 377920]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [4/3/2012 3:42 PM 253600]
S3 Amazon Download Agent;Amazon Download Agent;c:\program files\Amazon\Amazon Games & Software Downloader\AmazonGSDownloaderService.exe [12/29/2010 6:12 PM 401920]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [7/9/2011 4:19 PM 136176]
S3 MSHUSBVideo;NX6000/NX3000/VX5000/VX5500/VX7000 Filter Driver;c:\windows\system32\drivers\nx6000.sys [3/6/2011 12:45 PM 33808]
S4 Aemicacnpaw;Aemicacnpaw;
.
Contents of the 'Scheduled Tasks' folder
.
2012-04-12 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-03 21:33]
.
2012-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-09 20:19]
.
2012-04-09 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-07-09 20:19]
.
2012-04-07 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1957994488-2147018087-1003Core.job
- c:\documents and settings\Papi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-08 03:22]
.
2012-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1957994488-2147018087-1003UA.job
- c:\documents and settings\Papi\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2011-04-08 03:22]
.
2012-04-08 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1957994488-2147018087-1007Core.job
- c:\documents and settings\Eddie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-13 22:56]
.
2012-04-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-682003330-1957994488-2147018087-1007UA.job
- c:\documents and settings\Eddie\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2012-03-13 22:56]
.
2012-03-27 c:\windows\Tasks\Microsoft_Hardware_Launch_IType_exe.job
- c:\program files\Microsoft IntelliType Pro\itype.exe [2011-08-10 20:39]
.
2012-04-12 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2011-04-27 19:39]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
uInternet Settings,ProxyOverride = *.local;<local>
IE: Convert link target to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert to existing PDF - c:\program files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
TCP: DhcpNameServer = 167.206.245.130 167.206.245.129 192.168.1.1
DPF: {108D3206-846A-4A93-BACB-F0572D043ED7} - hxxp://192.168.0.162/webrec.cab
FF - ProfilePath - c:\documents and settings\Papi\Application Data\Mozilla\Firefox\Profiles\m9zyoaj3.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.com/
FF - prefs.js: network.proxy.type - 0
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2012-04-11 21:17
Windows 5.1.2600 Service Pack 3 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'winlogon.exe'(832)
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\atiadlxx.dll
c:\windows\dwrcs\DWRCWXL.dll
.
- - - - - - - > 'explorer.exe'(3992)
c:\windows\system32\WININET.dll
c:\program files\BillP Studios\WinPatrol\PATROLPRO.DLL
c:\windows\system32\ieframe.dll
c:\windows\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.6195_x-ww_44262b86\MSVCR80.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\program files\Microsoft Security Client\Antimalware\MsMpEng.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\AMD\RAIDXpert\bin\RAIDXpert.exe
c:\windows\system32\CTsvcCDA.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
c:\program files\Microsoft LifeCam\MSCamS32.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\program files\Yahoo!\SoftwareUpdate\YahooAUService.exe
c:\windows\system32\wscntfy.exe
c:\windows\system32\Rundll32.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
c:\program files\Microsoft IntelliType Pro\dpupdchk.exe
c:\program files\Adobe\Acrobat 7.0\Acrobat\Acrobat_sl.exe
c:\program files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
c:\windows\system32\WinMsgBalloonServer.exe
c:\windows\system32\WinMsgBalloonClient.exe
.
**************************************************************************
.
Completion time: 2012-04-11 21:22:04 - machine was rebooted
ComboFix-quarantined-files.txt 2012-04-12 01:22
ComboFix2.txt 2012-03-26 13:05
.
Pre-Run: 117,352,873,984 bytes free
Post-Run: 120,041,598,976 bytes free
.
- - End Of File - - 1AC0BF3104B9C88446426F1497A45978