Ok, it took a while to run the Malwarebytes but I finally got everything.
ComboFix 08-09-15.02 - CJ 2008-09-17 15:29:53.3 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1258 [GMT -4:00]
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
Command switches used :: C:\Users\CJ\Desktop\CFscript.txt
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Users\CJ\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0d4405a1
C:\Users\CJ\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0d4405a1\Report.cab
C:\Users\CJ\AppData\Local\Microsoft\Windows\WER\ReportArchive\Report0d4405a1\Report.wer
C:\Users\CJ\Incomplete
C:\Users\CJ\Incomplete\AOZBDI3TVNICLRAKKH4QXCQXC2FMXIPM\.datDOOM 2.iso
C:\Users\CJ\Incomplete\AOZBDI3TVNICLRAKKH4QXCQXC2FMXIPM\DOOM 2.iso
C:\Users\CJ\Incomplete\CORRUPT-0-Blue Suede - Hooked On A Feeling (Ooga Chacka) - 70's Disco (VBR).mp3
C:\Users\CJ\Incomplete\downloads.bak
C:\Users\CJ\Incomplete\downloads.dat
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\.datThe Alphabet of Manliness
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
001.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
002.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
003.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
004.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
005.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
006.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
007.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
008.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
009.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
010.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
011.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
012.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\
013.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking 6 And B is for Boners.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\A is for Ass kicking.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\B is for Boners 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\B is for Boners 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\B is for Boners 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\B is for Boners 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\B is for Boners 6 and C is for Copping a feel.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 6.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\C is for copping a feel 7 and D is for Taking a dump.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\D is for taking a Dump 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\D is for taking a Dump 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\D is for taking a Dump 4 and E is for Enlightenment.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\E is for Enlightenment 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\E is for Enlightenment 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\E is for Enlightenment 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\E is for Enlightenment 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\F is for Female wrestling 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\F is for Female wrestling 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\F is for Female wrestling.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 6.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas 7.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\G is for Gas.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\H is for Hotsauce 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\H is for Hotsauce 3 and I is for Irate.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\H is for Hotsauce.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\I is for Irate 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\I is for Irate 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\I is for Irate 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\I is for Irate 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\J is for Beef Jerky 3 And K is for Knockers.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\J is for Beef Jerky.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\J is for Beef Jerky2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\K is for Knockers 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\K is for Knockers 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\K is for Knockers 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\L is for Lumber Jack 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\L is for Lumber Jack 3 and M is for Metal.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\L is for Lumber Jack.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 6.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 7.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\M is for Metal 8 And N is for Chuck Norris.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\N is for Chuck Norris 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\N is for Chuck Norris 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\N is for Chuck Norris 4 and O is for Obedience.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\O is for Obedience 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\O is for Obedience 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\O is for Obedience 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\P is for Pirates 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\P is for Pirates 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\P is for Pirates.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Q is for Quickie 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Q is for Quickie 3 and R is for RoadRage.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Q is for Quickie.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\R is for RoadRage 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\R is for RoadRage 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\R is for RoadRage 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\S is for Sneaking a peak 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\S is for Sneaking a peak 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\S is for Sneaking a peak.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\T is for Taunting 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\T is for Taunting 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\T is for Taunting 4 and U is for Urinal Etiqutte.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\T is for Taunting.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 6.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\U is for Urinal Etiqutte 7 and V is for Violence.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\V is for Violence 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\V is for Violence 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\V is for Violence 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\V is for Violence 5 and W is for Winner.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\W is for Winner 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\W is for Winner 3 and X is for XXX.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\X is for XXX 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\X is for XXX 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\X is for XXX 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\X is for XXX 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Y is for Yelling 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Y is for Yelling 3 and Z is for Zombies.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Y is for Yelling.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Z is for Zombies 2.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Z is for Zombies 3.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Z is for Zombies 4.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Z is for Zombies 5.jpg
C:\Users\CJ\Incomplete\HUH5UMNGUNZ2GT4Y6NT7HXJAYTPY5SSJ\The Alphabet of Manliness\Z is for Zombies 6 and Index.jpg
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\.datTiger Woods PGA Tour 08 (PC) with Crack + Keygen
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\Tiger Woods PGA Tour 08 (PC) with Crack + Keygen\instructions.txt
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\Tiger Woods PGA Tour 08 (PC) with Crack + Keygen\keygen.exe
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\Tiger Woods PGA Tour 08 (PC) with Crack + Keygen\Tiger Woods PGA Tour 08 .iso
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\Tiger Woods PGA Tour 08 (PC) with Crack + Keygen\TW2008.exe
C:\Users\CJ\Incomplete\PMXQ5IDO23FKCTACSX2DCG7WDZ2Y252J\Tiger Woods PGA Tour 08 (PC) with Crack + Keygen\Y-How to get the PlayStation 3 for nothing.rtf
C:\Users\CJ\Incomplete\T-113238-Mathworks Matlab 7.1.4 R14 SP3.zip
C:\Users\CJ\Incomplete\T-233472-Mathworks Matlab R2007a.exe
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Service_PermissionResearch
((((((((((((((((((((((((( Files Created from 2008-08-17 to 2008-09-17 )))))))))))))))))))))))))))))))
.
2008-09-16 17:20 . 2008-09-16 19:19 d——– C:\Lop SD
2008-09-15 20:37 . 2008-09-15 20:39 250 –a—— C:\Windows\gmer.ini
2008-09-15 19:43 . 2008-09-14 04:48 d——– C:\SDFix
2008-09-14 22:58 . 2008-09-14 22:58 d——– C:\Users\CJ\AppData\Roaming\Malwarebytes
2008-09-14 22:58 . 2008-09-14 22:58 d——– C:\Users\All Users\Malwarebytes
2008-09-14 22:58 . 2008-09-14 22:58 d——– C:\ProgramData\Malwarebytes
2008-09-14 22:58 . 2008-09-14 22:58 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-09-14 22:58 . 2008-09-10 00:04 38,528 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-09-14 22:58 . 2008-09-10 00:03 17,200 –a—— C:\Windows\System32\drivers\mbam.sys
2008-09-14 21:44 . 2008-09-14 21:44 96 –a—— C:\Windows\wininit.ini
2008-09-14 21:20 . 2008-09-17 02:11 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-09-14 21:20 . 2008-09-17 02:11 d——– C:\ProgramData\Spybot - Search & Destroy
2008-09-14 21:20 . 2008-09-14 21:20 d——– C:\Program Files\Spybot - Search & Destroy
2008-09-11 16:59 . 2008-09-11 16:59 d——– C:\WALKING_TALL
2008-09-11 16:32 . 2008-09-11 16:32 0 –ah—– C:\Windows\System32\drivers\Msft_User_WpdFs_01_00_00.Wdf
2008-09-11 15:58 . 2008-09-11 15:58 0 –a—— C:\Windows\EAREMOVE.INI
2008-09-10 23:46 . 2008-07-15 21:32 2,048 –a—— C:\Windows\System32\tzres.dll
2008-09-10 23:42 . 2008-06-25 23:29 303,616 –a—— C:\Windows\System32\wmpeffects.dll
2008-09-10 23:41 . 2008-08-01 21:01 625,152 –a—— C:\Windows\System32\drivers\dxgkrnl.sys
2008-09-10 23:41 . 2008-06-25 23:29 565,248 –a—— C:\Windows\System32\emdmgmt.dll
2008-09-10 23:41 . 2008-04-18 01:48 269,312 –a—— C:\Windows\System32\es.dll
2008-09-10 23:41 . 2008-05-08 15:21 211,968 –a—— C:\Windows\System32\drivers\mrxsmb10.sys
2008-09-10 23:41 . 2008-05-19 22:07 148,480 –a—— C:\Windows\System32\drivers\nwifi.sys
2008-09-10 23:41 . 2008-06-25 23:29 45,056 –a—— C:\Windows\System32\dataclen.dll
2008-09-10 23:41 . 2008-08-01 23:26 36,864 –a—— C:\Windows\System32\cdd.dll
2008-09-10 23:40 . 2008-06-26 21:55 1,383,424 –a—— C:\Windows\System32\mshtml.tlb
2008-09-10 23:40 . 2008-06-27 00:15 827,392 –a—— C:\Windows\System32\wininet.dll
2008-09-10 23:39 . 2008-04-10 01:12 738,304 –a—— C:\Windows\System32\inetcomm.dll
2008-09-10 23:39 . 2008-05-08 17:59 430,080 –a—— C:\Windows\System32\vbscript.dll
2008-09-10 23:39 . 2008-06-18 23:31 361,984 –a—— C:\Windows\System32\IPSECSVC.DLL
2008-09-10 23:39 . 2008-05-08 17:59 180,224 –a—— C:\Windows\System32\scrobj.dll
2008-09-10 23:39 . 2008-05-08 17:59 172,032 –a—— C:\Windows\System32\scrrun.dll
2008-09-10 23:39 . 2008-05-08 17:59 155,648 –a—— C:\Windows\System32\wscript.exe
2008-09-10 23:39 . 2008-05-08 17:58 135,168 –a—— C:\Windows\System32\wshom.ocx
2008-09-10 23:39 . 2008-05-08 17:58 135,168 –a—— C:\Windows\System32\cscript.exe
2008-09-10 23:39 . 2008-05-08 17:59 90,112 –a—— C:\Windows\System32\wshext.dll
2008-09-10 23:38 . 2008-04-26 04:25 3,600,952 –a—— C:\Windows\System32\ntkrnlpa.exe
2008-09-10 23:38 . 2008-04-26 04:25 3,549,240 –a—— C:\Windows\System32\ntoskrnl.exe
2008-09-10 23:38 . 2008-04-26 04:26 891,448 –a—— C:\Windows\System32\drivers\tcpip.sys
2008-09-10 23:38 . 2008-04-11 23:32 784,896 –a—— C:\Windows\System32\rpcrt4.dll
2008-09-10 23:38 . 2008-04-04 21:21 72,192 –a—— C:\Windows\System32\drivers\pacer.sys
2008-09-10 23:38 . 2008-04-04 23:34 15,360 –a—— C:\Windows\System32\pacerprf.dll
2008-08-23 18:25 . 2008-08-23 18:25 d——– C:\PerfLogs
2008-08-23 17:53 . 2008-08-23 17:06 152,576 –a—— C:\Windows\System32\SPWizUI.dll
2008-08-23 17:53 . 2008-08-23 17:06 47,560 –a—— C:\Windows\System32\SPReview.exe
2008-08-23 17:26 . 2008-01-18 23:36 6,656 –a—— C:\Windows\System32\sdspres.dll
2008-08-23 17:25 . 2008-01-18 23:33 193,024 –a—— C:\Windows\System32\recdisc.exe
2008-08-23 17:24 . 2008-01-18 23:33 599,552 –a—— C:\Windows\System32\vsp1cln.exe
2008-08-23 17:24 . 2008-01-18 23:36 142,336 –a—— C:\Windows\System32\spp.dll
2008-08-23 17:24 . 2008-01-18 23:36 28,160 –a—— C:\Windows\System32\sxproxy.dll
2008-08-23 17:15 . 2008-01-18 23:34 6,103,040 –a—— C:\Windows\System32\chtbrkr.dll
2008-08-23 17:07 . 2008-01-18 23:33 44,032 –a—— C:\Windows\System32\cbsra.exe
2008-08-23 17:06 . 2008-08-23 17:55 196,608 –a—— C:\Windows\SPInstall.etl
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-09-17 12:30 ——— d—–w C:\Program Files\LimeWire
2008-09-17 02:28 ——— d—–w C:\ProgramData\Google Updater
2008-09-17 02:06 50 —-a-w C:\Program Files\asft.txt
2008-09-12 22:00 ——— d—–w C:\Program Files\Norton Security Scan
2008-09-11 19:59 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-11 19:57 ——— d—–w C:\ProgramData\Media Center Programs
2008-09-11 19:51 ——— d—–w C:\Program Files\DominateGame
2008-09-11 19:47 ——— d—–w C:\Program Files\America's Army
2008-09-10 21:00 ——— d—–w C:\Users\CJ\AppData\Roaming\LimeWire
2008-09-10 03:56 ——— d—–w C:\Users\CJ\AppData\Roaming\Apple Computer
2008-08-23 22:43 174 –sha-w C:\Program Files\desktop.ini
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Sidebar
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Photo Gallery
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Mail
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Journal
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Collaboration
2008-08-23 22:30 ——— d—–w C:\Program Files\Windows Calendar
2008-08-23 22:29 ——— d—–w C:\Program Files\Windows Defender
2008-08-23 22:02 82,432 —-a-w C:\Windows\System32\axaltocm.dll
2008-08-23 22:02 101,888 —-a-w C:\Windows\System32\ifxcardm.dll
2008-08-13 19:47 ——— d—–w C:\Program Files\Free iPod Video Converter
2008-08-13 16:50 ——— d—–w C:\ProgramData\DVD Shrink
2008-08-13 16:47 ——— d—–w C:\Program Files\DVD Shrink
2008-08-12 15:50 ——— d—–w C:\Program Files\Winnydows
2008-08-11 03:22 ——— d—–w C:\Program Files\DVD Decrypter
2008-08-10 23:43 ——— d—–w C:\Program Files\Red Kawa
2008-08-10 23:43 ——— d—–w C:\Program Files\AviSynth 2.5
2008-08-10 15:03 ——— d—–w C:\Program Files\Xvid
2008-08-09 14:44 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-07-31 22:33 ——— d—–w C:\Program Files\Google
2008-06-26 03:29 801,280 —-a-w C:\Windows\System32\NaturalLanguage6.dll
2008-06-26 01:45 2,644,480 —-a-w C:\Windows\System32\NlsLexicons0009.dll
2008-06-26 01:45 12,240,896 —-a-w C:\Windows\System32\NlsLexicons0007.dll
2007-12-01 22:44 9,657 —-a-w C:\Program Files\hijackthis.log
2007-12-01 22:43 401,720 —-a-w C:\Program Files\hijackthis.exe
2007-09-28 03:23 1,460 —-a-w C:\Users\CJ\AppData\Roaming\wklnhst.dat
2007-08-23 03:49 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-08-23 03:49 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-08-23 03:49 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((( snapshot@2008-09-16_23.55.52.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2007-08-23 03:19:08 25,214 —-a-r C:\Windows\Installer\{7C9E6E52-EB11-44DB-A761-82D5D873A8D9}\ARPPRODUCTICON.exe
+ 2008-09-17 03:52:33 25,214 —-a-r C:\Windows\Installer\{7C9E6E52-EB11-44DB-A761-82D5D873A8D9}\ARPPRODUCTICON.exe
- 2008-09-17 03:38:59 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-09-17 19:34:45 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2008-09-17 03:38:59 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2008-09-17 19:34:45 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-09-17 03:49:04 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
+ 2008-09-17 19:35:19 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
- 2008-09-17 03:49:04 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-09-17 19:35:19 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat
+ 2008-09-17 12:32:42 2,202 —-a-w C:\Windows\SoftwareDistribution\EventCache\{87D4F8CC-5D81-4B4F-A1DE-581C654A409F}.bin
- 2008-09-17 03:51:22 14,612 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2708974533-3029715495-2889588139-1000_UserData.bin
+ 2008-09-17 19:37:19 14,828 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-2708974533-3029715495-2889588139-1000_UserData.bin
- 2008-09-17 03:50:55 71,420 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-09-17 19:37:19 71,524 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-09-17 02:41:49 52,618 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-09-17 12:43:12 52,950 —-a-w C:\Windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"DellSupport"="C:\Program Files\DellSupport\DSAgnt.exe" [2006-11-12 446976]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-18 125952]
"swg"="C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2007-06-22 68856]
"DellTransferAgent"="C:\ProgramData\Dell\TransferAgent\TransferAgent.exe" [2007-11-13 135168]
"Aim6"="C:\Program Files\AIM6\aim6.exe" [2007-10-04 50528]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-07-07 2156368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2006-11-17 815104]
"Broadcom Wireless Manager UI"="C:\Windows\system32\WLTRAY.exe" [2006-11-27 1540096]
"ATICCC"="C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" [2006-07-11 90112]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2006-10-03 81920]
"Google Desktop Search"="C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" [2008-04-25 29744]
"PinnacleDriverCheck"="C:\Windows\system32\PSDrvCheck.exe" [2004-03-10 406016]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2006-11-22 107112]
"vptray"="C:\PROGRA~1\SYMANT~1\VPTray.exe" [2006-11-28 134808]
"GrooveMonitor"="C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe" [2007-08-24 33648]
"QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-02-01 385024]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-02-19 267048]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe" [2008-02-22 144784]
"SigmatelSysTrayApp"="sttray.exe" [2007-02-08 C:\Windows\sttray.exe]
C:\Users\CJ\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
OneNote 2007 Screen Clipper and Launcher.lnk - C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE [2007-08-24 101784]
Webshots.lnk - C:\Program Files\Webshots\Launcher.exe [2007-06-25 63064]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-23 29696]
Clean Access Agent.lnk - C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe [2007-09-06 2056275]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2007-06-02 50688]
Google Updater.lnk - C:\Program Files\Google\Google Updater\GoogleUpdater.exe [2007-12-18 125624]
myGannonAssistant.exe [2007-07-24 49152]
QuickSet.lnk - C:\Windows\Installer\{7F0C4457-8E64-491B-8D7B-991504365D1E}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe [2007-06-02 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"vidc.i420"= vdrcodec.dll
"VIDC.MJPG"= Pvmjpg21.dll
"VIDC.PIM1"= pclepim1.dll
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{89FFC2C2-3F68-431E-B8C7-608AA64EFE3B}"= UDP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{E7AD0A3B-26EC-4D85-A419-21E905DDDB4A}"= TCP:C:\Program Files\Yahoo!\Yahoo! Music Jukebox\YahooMusicEngine.exe:Yahoo! Music Jukebox
"{6F2E4B3D-C620-4D9B-B69D-8EB2A09F6CB3}"= UDP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{50EFE488-1DF5-466C-A894-20AA4A0C407E}"= TCP:C:\Program Files\LimeWire\LimeWire.exe:LimeWire
"{8077DBF4-0FCC-4BDB-B262-F7042B7D6144}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{2952BE5F-6349-4F28-9263-5C4B236C3DDF}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"TCP Query User{149DA2B0-0FA2-4080-BFB5-327F295A3D89}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{F1D8FA16-8A03-4B41-9CD5-F8C8E5F5449B}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{8202B5BE-0D08-4B8C-9A1D-C77FD6CF8B88}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL Connectivity Service Dialer
"{89A25B8A-560B-4257-A903-19C8FE113FCC}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLDial.exe:AOL Connectivity Service Dialer
"{9677247C-0E0F-4898-8490-705C49D50103}"= UDP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL Connectivity Service
"{EC061941-D082-43F0-8C27-85408C99803C}"= TCP:C:\Program Files\Common Files\AOL\ACS\AOLacsd.exe:AOL Connectivity Service
"TCP Query User{54FF0DAA-2A5F-47BE-AEF7-C2DDCEC89E5E}C:\\program files\\america's army\\system\\armyops.exe"= UDP:C:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{84A61B42-2152-43CB-B182-8310E1AB9242}C:\\program files\\america's army\\system\\armyops.exe"= TCP:C:\program files\america's army\system\armyops.exe:ArmyOps
"{D9FF0012-B9B0-45F7-A61E-6C2C66E173B9}"= UDP:C:\Program Files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{B9A7F462-DAC3-411D-A615-D2A586D3B1D1}"= TCP:C:\Program Files\Symantec AntiVirus\Rtvscan.exe:Symantec Antivirus
"{ED3D0125-1E6A-4CC5-B29B-182A68B7A40B}"= UDP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{8349E3B5-3403-493F-841F-FBBD020F3FE6}"= TCP:C:\Program Files\Common Files\Symantec Shared\ccApp.exe:Symantec Email
"{6ABFD43F-0F66-458D-BF8E-40916B70BBE2}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{51A5A98F-76D8-481C-9574-F36DA509A1DD}"= UDP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{9790B1D3-C448-4A72-9F03-EE3022DC9BDA}"= TCP:C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{B76293AF-726D-49A7-96BD-77BBA332EA7F}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{F6688F63-173C-4626-9464-F27637B73DA4}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{DCF1508B-5B8D-4717-9171-19F8ACD9575A}C:\\program files\\quake iii arena\\quake3.exe"= UDP:C:\program files\quake iii arena\quake3.exe:quake3
"UDP Query User{6653B69D-B2DF-4831-8D1D-855B64B54B08}C:\\program files\\quake iii arena\\quake3.exe"= TCP:C:\program files\quake iii arena\quake3.exe:quake3
"TCP Query User{C2E6F2EA-6433-4707-B61D-8F8DBF81802B}C:\\program files\\aim6\\aim6.exe"= UDP:C:\program files\aim6\aim6.exe:AIM
"UDP Query User{ECDF1516-B174-446A-9EFB-B2B518C1DED5}C:\\program files\\aim6\\aim6.exe"= TCP:C:\program files\aim6\aim6.exe:AIM
"TCP Query User{EEE29942-CFC8-4897-A57B-D82B046D887E}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{DD599164-8017-436C-B331-6051A3903FC2}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{3F9C3DBC-5972-40EA-8985-B84D02013D4F}"= UDP:C:\Program Files\Flagship Studios\Hellgate London Demo\Launcher.exe:Hellgate: London
"{857AB196-9A2C-4B21-A13C-ECED2A59070E}"= TCP:C:\Program Files\Flagship Studios\Hellgate London Demo\Launcher.exe:Hellgate: London
"{C8C41A5A-897F-4A06-8E07-B2B3BB635F2D}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{50ECD3EF-81D7-4943-8AD7-94C1CFEFE961}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{F22F9FAF-C352-432B-B985-925526DB6630}"= UDP:C:\Program Files\Common Files\AOL\1184960157\ee\aolsoftware.exe:AOL Services
"{67A88828-E279-493B-86D3-AD9B486E0121}"= TCP:C:\Program Files\Common Files\AOL\1184960157\ee\aolsoftware.exe:AOL Services
"{B6EF35CE-9924-4201-B86D-43ACC949B2FC}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{D0C25A94-0230-4552-BDC6-A8B2FDE5B2C7}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{43AE73D1-8D47-479E-B4EC-9E08FF0F0C06}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{312C6189-341C-47A5-BE23-00AE685B0AFD}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{AD31353D-49AC-4B77-91DF-1CD45A1BE713}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{C53943B9-2FA0-4CDD-941A-117A1EA9805B}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{868E7EC4-D6A2-4404-9845-74B2E79F0E8E}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{4F2852E5-537E-4D4B-AEA2-BA8C144D9ADF}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{E5456988-3022-4A57-9AA6-57C599011067}"= UDP:C:\Program Files\Ruckus Player\Ruckus.exe:Ruckus
"{2559DC56-4901-4AEF-A6A5-8267740F5102}"= TCP:C:\Program Files\Ruckus Player\Ruckus.exe:Ruckus
"{E35EA61D-7DC9-4172-9092-A8FF1A5DF72A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{F7E88B9C-9598-4F5F-B365-BEC53E9BB6D0}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{38E60125-37FC-440A-BD51-0D83A9042A74}C:\\program files\\dna\\btdna.exe"= UDP:C:\program files\dna\btdna.exe:btdna
"UDP Query User{8D0630C4-5AB8-493F-A8DA-1E353CAFA7AE}C:\\program files\\dna\\btdna.exe"= TCP:C:\program files\dna\btdna.exe:btdna
"TCP Query User{19C7FB4C-C42B-462D-9017-F9CEC6F2FA89}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{38B153C4-D9E8-4A71-B494-81BF2BE710DA}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:uTorrent
"{F797ADCF-0FA2-4E74-BAC6-1BC4F4000C69}"= UDP:C:\Windows\System32\prmrsr.exe:prmrsr.exe
"{C4603A9C-F359-467E-9026-74549072F6A7}"= TCP:C:\Windows\System32\prmrsr.exe:prmrsr.exe
"{6358F0F8-EF82-4111-BE3D-508061BB7CA6}"= UDP:C:\Windows\Temp\~os5C9D.tmp\ossproxy.exe:ossproxy.exe
"TCP Query User{BAB60CC9-9810-4BB3-B916-02EF263A5066}C:\\program files\\mozilla firefox\\firefox.exe"= UDP:C:\program files\mozilla firefox\firefox.exe:Firefox
"UDP Query User{06A28913-EB41-4D4E-A591-862591ECBFB5}C:\\program files\\mozilla firefox\\firefox.exe"= TCP:C:\program files\mozilla firefox\firefox.exe:Firefox
"{DCC60159-27BD-4FDB-9B33-923842152E70}"= UDP:29186:C:\Program Files\LimeWire\LimeWire.exe
"{FE18DEBD-2112-4F06-AE3B-843D1B53677D}"= UDP:C:\Windows\explorer.exe:Windows Explorer
"{19532C82-D45D-48E0-9EA9-589D60183DB4}"= TCP:C:\Windows\explorer.exe:Windows Explorer
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R2 GenPort;GenPort;C:\Windows\system32\drivers\GenPort.sys [1997-09-24 4832]
R2 MapMem;MapMem;C:\Windows\system32\drivers\MapMem.sys [1997-09-24 6816]
R2 NTRemap;NTRemap;C:\Windows\system32\drivers\NTRemap.sys [1997-09-24 6336]
S3 GoogleDesktopManager-022208-143751;Google Desktop Manager 5.7.802.22438;C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2008-04-25 29744]
S3 MBAMSwissArmy;MBAMSwissArmy;C:\Windows\system32\drivers\mbamswissarmy.sys [2008-09-10 38528]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\G]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{1e804fb7-8d58-11dc-a1ea-00038a000015}]
\shell\AutoRun\command - G:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{71873c97-d431-11dc-af02-00038a000015}]
\shell\AutoRun\command - F:\LaunchU3.exe -a
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9fa18f45-24ab-11dc-9baf-0019b979cedf}]
\shell\AutoRun\command - F:\LaunchU3.exe -a
.
Contents of the 'Scheduled Tasks' folder
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-xrt_Shell - C:\Users\CJ\xrt_beaw.exe
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-09-17 15:35:48
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
———————— Other Running Processes ————————
.
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\audiodg.exe
C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
C:\Windows\System32\Ati2evxx.exe
C:\Windows\System32\WLTRYSVC.EXE
C:\Windows\System32\BCMWLTRY.EXE
C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\Windows\System32\drivers\XAudio.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\myGannonAssistant.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\System32\msiexec.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
.
**************************************************************************
.
Completion time: 2008-09-17 15:43:49 - machine was rebooted
ComboFix-quarantined-files.txt 2008-09-17 19:43:31
ComboFix2.txt 2008-09-17 12:48:57
ComboFix3.txt 2008-09-17 03:57:32
Pre-Run: 55,858,634,752 bytes free
Post-Run: 55,758,991,360 bytes free
445 — E O F — 2008-07-25 22:37:33
Malwarebytes' Anti-Malware 1.28
Database version: 1165
Windows 6.0.6001 Service Pack 1
9/17/2008 10:57:33 PM
mbam-log-2008-09-17 (22-57-27).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 154134
Time elapsed: 1 hour(s), 29 minute(s), 26 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 7
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\oincs.oinanalytics (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\oincs.oinanalytics.1 (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\{f7fa36a4-3177-4b57-b9c1-e9c5b2e0d3a9} (Adware.BHO) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\OINAnalytics (Adware.BHO) -> No action taken.
HKEY_CLASSES_ROOT\AppID\OINAnalytics.DLL (Adware.BHO) -> No action taken.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xrt_Shell (Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_patch (Backdoor.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\xrt_control_crc (Backdoor.Agent) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\wallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> No action taken.
HKEY_CURRENT_USER\Control Panel\Desktop\scrnsave.exe (Hijack.Wallpaper) -> No action taken.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Qoobox\Quarantine\C\Program Files\iCheck\iCheck.exe.vir (Adware.ISM) -> No action taken.
C:\Qoobox\Quarantine\C\Windows\system32\blphcrh8j0et6d.scr.vir (Fake.BlueScreenError) -> No action taken.
C:\Qoobox\Quarantine\C\Windows\system32\lphcrh8j0et6d.exe.vir (Trojan.Downloader) -> No action taken.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:06:02 PM, on 9/17/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Windows\System32\WLTRAY.EXE
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Symantec AntiVirus\VPTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Windows\sttray.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Windows\ehome\ehtray.exe
C:\ProgramData\Dell\TransferAgent\TransferAgent.exe
C:\Program Files\AIM6\aim6.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Google\Google Updater\GoogleUpdater.exe
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\myGannonAssistant.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\Windows\System32\mobsync.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Aware2007.exe
C:\Program Files\AIM6\aolsoftware.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.exe
C:\Program Files\Java\jre1.6.0_05\bin\jucheck.exe
C:\Windows\Explorer.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.com/0SEENUS/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\Windows\system32\WLTRAY.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\Windows\system32\PSDrvCheck.exe -CheckReg
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] sttray.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellTransferAgent] "C:\ProgramData\Dell\TransferAgent\TransferAgent.exe"
O4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imApp
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [xrt_Shell] C:\Users\CJ\xrt_beaw.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Clean Access Agent.lnk = C:\Program Files\Cisco Systems\Clean Access Agent\CCAAgent.exe
O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe
O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe
O4 - Global Startup: myGannonAssistant.exe
O4 - Global Startup: QuickSet.lnk = ?
O8 - Extra context menu item: &Webshots; Photo Search - res://C:\Program Files\Webshots\WSToolbar4IE.dll/MENUSEARCH.HTM
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Desktop Manager 5.7.802.22438 (GoogleDesktopManager-022208-143751) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\Windows\System32\WLTRYSVC.EXE
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 10238 bytes