"Sora ilX" - 2007-06-27 0:48:36 - ComboFix 07-06-23.5 - Service Pack 2 NTFS
Command switches used :: C:\Documents and Settings\Sora ilX\Desktop\ComboFix-Do.txt
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
C:\Program Files\Messenger Plus! Live
C:\Program Files\Messenger Plus! Live\Detoured.dll
C:\Program Files\Messenger Plus! Live\Events Style Sheet.xsl
C:\Program Files\Messenger Plus! Live\lame_enc.dll
C:\Program Files\Messenger Plus! Live\Languages\Lng_Arabic.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Catalan.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_ChineseSimplified.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_ChineseTraditional.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Danish.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Default.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Dutch.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Estonian.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Finnish.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_French.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_German.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Hebrew.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Hungarian.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Italian.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Japanese.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Korean.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Norwegian.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Portuguese.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Spanish.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Swedish.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Thai.ini
C:\Program Files\Messenger Plus! Live\Languages\Lng_Turkish.ini
C:\Program Files\Messenger Plus! Live\libsndfile.dll
C:\Program Files\Messenger Plus! Live\Log Viewer.exe
C:\Program Files\Messenger Plus! Live\MPScripts.dll
C:\Program Files\Messenger Plus! Live\MPTools.exe
C:\Program Files\Messenger Plus! Live\MsgPlusLive.dll
C:\Program Files\Messenger Plus! Live\MsgPlusLive1.dll
C:\Program Files\Messenger Plus! Live\MsgPlusLiveRes.dll
C:\Program Files\Messenger Plus! Live\MsgPlusLiveRes1.dll
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\_translationClass.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\_util.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\api.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\autoupdate.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\coverArt.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\dlls\wmp9.dll
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\hotkeys.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\About.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Commands.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Dp.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Lyrics.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Main.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Misc.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Misc2.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\NoCover.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Psm.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Remote.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Images\Tags.png
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\interface.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Languages\English.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Languages\Espanol.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Languages\Leet.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\Languages\Nederlands.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\lyric_parsers\azlyrics.lyrics.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\lyric_parsers\Leos.lyrics.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\lyric_parsers\Metro.lyrics.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\lyrics.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\main.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\ExamplePlayer.base.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\iTunes.player.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\jetAudio.player.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\MediaMonkey.player.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\Winamp.player.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\players\WMP.player.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\prefstore.js
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\updateInterface.xml
C:\Program Files\Messenger Plus! Live\Scripts\Now Playing\window.js
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\+Mapper.js
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\defaultmap.htm
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\editfunctions.javascript
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\General Functions.js
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\Images\delete.png
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\Images\loadingAnimation.gif
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\Images\maps.png
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\jquery.javascript
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\livedefault.htm
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\liveeditfunctions.javascript
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\Menu.js
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\thickbox.css
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\thickbox.javascript
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\Windows.js
C:\Program Files\Messenger Plus! Live\Scripts\Plus Mapper\windows.xml
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\Commands.js
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\Interface.js
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\Interface.xml
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\ReadThis.js
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\reg.js
C:\Program Files\Messenger Plus! Live\Scripts\ReadThis\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\_translationClass.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\_window.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\48pxAdditionalImage.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\bmp.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\countdown.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\jpg.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\logo.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\no_image.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\overlay.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\pnggif.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\preferences.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\server.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Images\vista_folder.png
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndAbout.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndAdvanced.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndAllContacts.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndCountdown.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndCountdownDisplay.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndFTPUpload.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndGeneral.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndHotkeys.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndLanguage.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndMultiChat.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndPref.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndPreview.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndRecentImages.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndScreenshotViewer.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndSelect.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndSubclass.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Interface\WndUpdate.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\Languages\English.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.functions.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.gdip_functions.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.gdip_variables.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.hotkey_functions.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.menu.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.preferences.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.registry.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.script.commands.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.timer.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.update.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\ss4.variables.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndAbout.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndAdvanced.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndAllContacts.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndCountdown.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndCountdownDisplay.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndFTPUpload.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndGeneral.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndLanguage.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndMultiChat.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndPref.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndPreview.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndRecentImages.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndScreenshotViewer.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\Screenshot Sender 4\WndSelect.handler.js
C:\Program Files\Messenger Plus! Live\Scripts\SendTo\_registry.js
C:\Program Files\Messenger Plus! Live\Scripts\SendTo\_sendfile.exe
C:\Program Files\Messenger Plus! Live\Scripts\SendTo\_sendto.js
C:\Program Files\Messenger Plus! Live\Scripts\SendTo\FileListener.xml
C:\Program Files\Messenger Plus! Live\Scripts\SendTo\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\_Stickynotes.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Data\Colors.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Data\Registry.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\functions.misc.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\functions.string.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.chatnotesender.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.menucommands.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.registryreader.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.stickynote.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.stickynotes.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\handler.xmlcarrier.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Accept_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Accept_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Accept_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Appearance_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Appearance_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Appearance_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Cancel_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Cancel_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Cancel_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Check_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Check_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Collapse_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Collapse_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Collapse_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Edit_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Edit_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Edit_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Expand_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Expand_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\header-about.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Lock_disabled.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Lock_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Lock_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\logo-small.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Thumbs.db
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Unlock_off.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Images\Unlock_on.png
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Interfaces\About.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Interfaces\Listener.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Interfaces\Options.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Interfaces\SendNotes.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Interfaces\Update.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Themes\Flair.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Themes\Simple.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\Themes\Square.xml
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\window.preferences.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\window.stickynote.js
C:\Program Files\Messenger Plus! Live\Scripts\Stickynotes\window.updates.js
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\AI.txt
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\AIdocs.txt
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\boom.mp3
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\config.ini
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\UNeed.js
C:\Program Files\Messenger Plus! Live\Scripts\UNeed Script\wot.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\_wlm.preview.box.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\handler.menu.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\handler.regestry.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\handler.window.pref.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\handler.window.preview.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\handler.window.preview.settings.js
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_close.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_close_hot.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_close_pushed.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_send.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_send_hot.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\btn_send_pushed.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\colorwheel.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\general.png
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\not needed.rar
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Images\Thumbs.db
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\About.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\not needed.rar
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\PreviewBox.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\UI.Colours.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\UI.General.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\UI.Help.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\Interfaces\UI.xml
C:\Program Files\Messenger Plus! Live\Scripts\WLM Preview Box\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\images\Thumbs.db
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\images\vd-logo.png
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\images\youtubelogo.png
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\ScriptInfo.xml
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\window.xml
C:\Program Files\Messenger Plus! Live\Scripts\YouTube Launcher\Youtube.js
C:\Program Files\Messenger Plus! Live\Uninstall.exe
C:\WINDOWS\system32\cid_store.dat
C:\WINDOWS\system32\RVHIOST.exe
((((((((((((((((((((((((( Files Created from 2007-05-26 to 2007-06-26 )))))))))))))))))))))))))))))))
2007-06-26 22:31 <DIR> d-------- C:\WINDOWS\system32\VIRepair
2007-06-26 22:19 6,181,376 --a------ C:\WINDOWS\system32\vistaui.exe
2007-06-26 22:19 498,176 --a------ C:\WINDOWS\system32\logon.scr
2007-06-26 22:19 305,447 --a------ C:\WINDOWS\system32\viwc.exe
2007-06-26 22:19 <DIR> d-------- C:\Program Files\VisualTooltip
2007-06-26 22:19 <DIR> d-------- C:\Program Files\ViStart
2007-06-26 22:15 94,208 --a------ C:\WINDOWS\system32\pskill.exe
2007-06-24 14:50 49,152 --a------ C:\WINDOWS\nircmd.exe
2007-06-24 13:13 <DIR> d--h----- C:\WINDOWS\system32\GroupPolicy
2007-06-24 02:24 <DIR> d-------- C:\My Music
2007-06-23 23:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1.SOR\APPLIC~1\Real
2007-06-23 23:51 <DIR> d-------- C:\DOCUME~1\ADMINI~1.SOR\APPLIC~1\Media Player Classic
2007-06-23 23:46 786,432 --ah----- C:\DOCUME~1\ADMINI~1.SOR\NTUSER.DAT
2007-06-21 20:37 152,833 --a------ C:\WINDOWS\system32\drivers\dump_wmimmc.sys
2007-06-17 03:37 656,600 -ra------ C:\WINDOWS\system32\drivers\cfosspeed.sys
2007-06-16 14:15 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\CenerTCPMessenger
2007-06-14 19:20 <DIR> d-------- C:\Program Files\Joost
2007-06-11 18:48 <DIR> d-------- C:\Program Files\Lavasoft
2007-06-11 18:48 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\Lavasoft
2007-06-11 18:23 <DIR> d-------- C:\Program Files\Windows Live
2007-06-11 18:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WLInstaller
2007-06-11 18:23 <DIR> d-------- C:\DOCUME~1\ALLUSE~1\APPLIC~1\WindowsLiveInstaller
2007-06-04 15:18 9,344 --a------ C:\WINDOWS\system32\drivers\NSDriver.sys
2007-06-04 15:17 8,320 --a------ C:\WINDOWS\system32\drivers\AWRTRD.sys
2007-06-04 15:14 6,272 --a------ C:\WINDOWS\system32\drivers\AWRTPD.sys
2007-06-01 16:05 <DIR> d-------- C:\DOCUME~1\SORAIL~1\APPLIC~1\Joost
2007-06-01 08:20 51,568 --a------ C:\WINDOWS\system32\sirenacm.dll
2007-05-30 00:16 33,952 --a------ C:\WINDOWS\system32\drivers\oreans32.sys
2007-05-27 15:37 <DIR> d-------- C:\Program Files\WinAVI Video Converter
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
2080-03-10 18:28:32 1,082,880 ----a-w C:\WINDOWS\system32\AutoPartNt.exe
2020-03-07 16:22:42 -------- d-----w C:\Program Files\Rapidown
2007-06-26 16:51:25 -------- d-----w C:\Program Files\Kaspersky Lab
2007-06-26 16:50:02 -------- d-----w C:\Program Files\cFosSpeed
2007-06-26 16:47:38 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\uTorrent
2007-06-26 16:47:20 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\foobar2000
2007-06-26 15:19:55 -------- d-----w C:\Program Files\Stardock
2007-06-26 14:49:07 -------- d-----w C:\Program Files\FlashGet
2007-06-24 08:48:00 -------- d-----w C:\Program Files\Warcraft III
2007-06-23 15:12:18 -------- d-----w C:\Program Files\Steam
2007-06-21 17:42:41 -------- d--h--w C:\Program Files\illusion
2007-06-21 15:08:45 -------- d-----w C:\Program Files\Granado Espada
2007-06-19 16:34:35 -------- d-----w C:\Program Files\SpeedFan
2007-06-19 14:47:17 -------- d-----w C:\Program Files\Tuotu
2007-06-15 16:45:58 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\VMware
2007-06-11 10:48:35 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\Lavasoft
2007-06-11 10:46:50 -------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2007-06-11 10:30:35 -------- d-----w C:\Program Files\MSN Messenger
2007-05-22 15:25:55 -------- d-----w C:\Program Files\OpenVPN
2007-05-16 15:12:02 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll
2007-05-16 08:38:37 -------- d-----w C:\Program Files\Combined Community Codec Pack
2007-05-13 17:47:00 -------- d-----w C:\Program Files\BT Engine
2007-05-13 06:14:06 -------- d--h--w C:\Program Files\Overflow
2007-05-12 15:40:36 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\Media Player Classic
2007-05-12 14:37:46 -------- d-----w C:\Program Files\K-Lite Codec Pack
2007-05-12 05:53:55 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\Reallusion
2007-05-12 05:52:48 -------- d-----w C:\Program Files\Reallusion
2007-05-12 05:52:16 -------- d--h--w C:\Program Files\InstallShield Installation Information
2007-05-11 18:15:13 -------- d-----w C:\Program Files\Guitar Pro 5
2007-05-09 12:19:39 -------- d-----w C:\Program Files\Microsoft CAPICOM 2.1.0.2
2007-05-05 07:13:56 -------- d-----w C:\Program Files\iTunes
2007-05-05 07:13:48 -------- d-----w C:\Program Files\iPod
2007-05-05 07:12:44 -------- d-----w C:\Program Files\QuickTime
2007-05-02 18:57:56 5,256 -c--a-w C:\WINDOWS\LoginUsers.dat
2007-05-02 18:57:55 -------- d-----w C:\Program Files\KuGoo3
2007-05-02 18:53:26 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\LimeWire
2007-05-01 05:46:10 -------- d-----w C:\Program Files\MediaMonkey
2007-04-28 18:39:39 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\Oxin's Style!
2007-04-28 06:40:36 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\FlashGet
2007-04-27 17:15:16 -------- d-----w C:\Program Files\eMule
2007-04-27 06:52:18 -------- d-----w C:\Program Files\MSXML 4.0
2007-04-26 16:08:41 -------- d-----w C:\Program Files\NextLink
2007-04-26 14:30:09 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\DataCast
2007-04-26 14:29:59 -------- d-----w C:\DOCUME~1\SORAIL~1\APPLIC~1\InstallShield
2007-04-25 14:21:15 144,896 ----a-w C:\WINDOWS\system32\schannel.dll
2007-04-18 16:12:23 2,854,400 ----a-w C:\WINDOWS\system32\msi.dll
2007-04-16 14:47:36 33,624 -c--a-w C:\WINDOWS\system32\wups.dll
2007-04-16 14:45:54 1,710,936 ----a-w C:\WINDOWS\system32\wuaueng.dll
2007-04-16 14:45:48 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll
2007-04-16 14:45:42 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll
2007-04-16 14:45:36 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll
2007-04-16 14:45:28 92,504 ----a-w C:\WINDOWS\system32\cdm.dll
2007-04-16 14:45:20 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe
2007-04-16 14:45:20 43,352 -c--a-w C:\WINDOWS\system32\wups2.dll
2007-04-16 14:44:20 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll
2007-04-16 14:44:18 208,248 ----a-w C:\WINDOWS\system32\muweb.dll
2007-04-13 10:58:36 471,040 -c--a-w C:\WINDOWS\system32\muzapp.dll
2007-04-13 10:58:36 167,936 -c--a-w C:\WINDOWS\system32\muzapp.exe
2007-04-13 10:58:36 110,592 -c--a-w C:\WINDOWS\system32\TG_VIEW0607.DLL
2007-04-13 10:58:35 90,112 -c--a-w C:\WINDOWS\system32\TG_SYNC.DLL
2007-04-13 10:58:35 90,112 -c--a-w C:\WINDOWS\system32\TG_DUMP0611.DLL
2007-04-13 07:19:52 7,680 ----a-w C:\WINDOWS\system32\lsdelete.exe
2007-04-06 00:19:04 227,856 ----a-w C:\WINDOWS\system32\PDBoot.exe
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects]
{00000AAA-A363-466E-BEF5-9BB68697AA7F}=C:\Program Files\Thunder Network\WebThunder\WebThunderBHO_016.dll [2007-01-24 19:10]
{02478D37-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Thunder Network\Thunder\ComDlls\XunLeiBHO_006.dll [2006-11-24 00:42]
{02478D38-C3F9-4EFB-9B51-7695ECA05670}=C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 10:28]
{2F364306-AA45-47B5-9F9D-39A8B94E7EF7}=C:\Program Files\FlashGet\jccatch.dll [2007-04-13 16:34]
{72853161-30C5-4D22-B7F9-0BBC1D38A37E}=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 00:48]
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}=C:\Program Files\Java\jre1.6.0_01\bin\ssv.dll [2007-03-14 03:43]
{9030D464-4C02-4ABF-8ECC-5164760863C6}=C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2006-08-31 20:33]
{A6984C00-C6EB-11D4-B4A4-080000180323}=C:\PROGRA~1\Rapidown\rapi310.dll [2007-04-06 21:03]
{AA58ED58-01DD-4d91-8333-CF10577473F7}=c:\program files\google\googletoolbar3.dll [2007-01-19 23:57]
{BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0}=C:\Program Files\Windows Live Toolbar\msntb.dll [2006-09-27 17:45]
{F156768E-81EF-470C-9057-481BA8380DBA}=C:\Program Files\FlashGet\getflash.dll [2007-04-13 17:34]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IMSCMIG40W"="C:\PROGRA~1\COMMON~1\MICROS~1\IME\IMSC40W\IMSCMIG.exe" [2006-03-20 16:10]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_01\bin\jusched.exe" [2007-03-14 03:43]
"RivaTunerStartupDaemon"="C:\Program Files\RivaTuner v2.0 RC 16.2\RivaTuner.exe" [2006-11-27 16:15]
"Google IME Autoupdater"="C:\Program Files\Google\Google Pinyin\GooglePinyinDaemon.exe" [2007-05-25 18:31]
"NvMediaCenter"="NvMCTray.dll" [2006-10-22 12:22 C:\WINDOWS\system32\nvmctray.dll]
"cFosSpeed"="C:\Program Files\cFosSpeed\cFosSpeed.exe" [2007-03-15 18:59]
"TkBellExe"="C:\Program Files\Common Files\Real\Update_OB\realsched.exe" [2006-12-06 01:57]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-09-01 08:00]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSharedDocuments"=00000000
"RestrictRun"=0 (0x0)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"="C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL" [2006-10-27 00:48]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"appinit_dlls"="C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll",wbsys.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\safeboot\minimal\aawservice]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Synchronizer.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Synchronizer.lnk
backup=C:\WINDOWS\pss\Adobe Reader Synchronizer.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Adobe Gamma.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Adobe Gamma.lnk
backup=C:\WINDOWS\pss\Adobe Gamma.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Diskeeper 10 Professional Edition Registration.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Diskeeper 10 Professional Edition Registration.lnk
backup=C:\WINDOWS\pss\Diskeeper 10 Professional Edition Registration.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Folding@Home 5.03.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Folding@Home 5.03.lnk
backup=C:\WINDOWS\pss\Folding@Home 5.03.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^LaunchU3.exe.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\LaunchU3.exe.lnk
backup=C:\WINDOWS\pss\LaunchU3.exe.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Morpheus.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Morpheus.lnk
backup=C:\WINDOWS\pss\Morpheus.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^OneNote 2007 Screen Clipper and Launcher.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
backup=C:\WINDOWS\pss\OneNote 2007 Screen Clipper and Launcher.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Rapidown.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Rapidown.lnk
backup=C:\WINDOWS\pss\Rapidown.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Styler.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Styler.lnk
backup=C:\WINDOWS\pss\Styler.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Sora ilX^Start Menu^Programs^Startup^Yahoo! Widget Engine.lnk]
path=C:\Documents and Settings\Sora ilX\Start Menu\Programs\Startup\Yahoo! Widget Engine.lnk
backup=C:\WINDOWS\pss\Yahoo! Widget Engine.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Blaero Start Orb]
C:\Program Files\Blaero Start Orb\Blaero Start Orb.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DU Meter]
C:\Program Files\DU Meter\DUMeter.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eMuleAutoStart]
C:\Program Files\eMule\emule.exe -AutoStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Flashget]
C:\Program Files\FlashGet\flashget.exe /min
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\GrooveMonitor]
"C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IMJPMIG8.1]
"C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
"C:\Program Files\iTunes\iTunesHelper.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
%systemroot%\system32\dumprep 0 -k
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MAAgent]
C:\Program Files\MarkAny\ContentSafer\MAAgent.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
RunDLL32.exe NvMCTray.dll,NvTaskbarInit
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\openvpn-gui]
C:\Program Files\OpenVPN\bin\openvpn-gui.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OSSelectorReinstall]
C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002A]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PHIME2002ASync]
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
"C:\Program Files\QuickTime\qttask.exe" -atboottime
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RivaTunerStartupDaemon]
"C:\Program Files\RivaTuner v2.0 RC 16.2\RivaTuner.exe" /S
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sidebar]
C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SMSTray]
C:\Program Files\Samsung\Samsung Media Studio 5\SMSTray.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
SOUNDMAN.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Styler]
C:\Program Files\Styler\Styler.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SWd]
C:\WINDOWS\winwd.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\1.0.720.3640\GoogleToolbarNotifier.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
"C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Vista Sidebar]
C:\Program Files\Vista Sidebar\sidebar.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VistaStartMenu]
"C:\Program Files\Vista Start Menu\VistaStartMenu.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VisualTooltip]
C:\Program Files\VisualTooltip\VisualToolTip.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WebThunder]
C:\Program Files\Thunder Network\WebThunder\WebThunder.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WheelMouse]
C:\Program Files\A4Tech\Mouse\Amoumain.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinPLOSION]
"C:\Program Files\WinPLOSION\winplosion.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
"C:\Program Files\Zune\ZuneLauncher.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"winser"=2 (0x2)
"SandraTheSrv"=3 (0x3)
"SandraDataSrv"=3 (0x3)
"LogMeIn"=3 (0x3)
"LMIMaint"=3 (0x3)
"VMware NAT Service"=2 (0x2)
"vmount2"=2 (0x2)
"VMnetDHCP"=2 (0x2)
"VMAuthdService"=2 (0x2)
"iPod Service"=3 (0x3)
"gusvc"=3 (0x3)
"DriveHealth"=3 (0x3)
"IDriverT"=3 (0x3)
"StarWindService"=2 (0x2)
"SQLWriter"=2 (0x2)
"SQLBrowser"=2 (0x2)
"MSSQL$MSSMLBIZ"=2 (0x2)
"MSCSPTISRV"=3 (0x3)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run-]
"Steam"="C:\Program Files\Steam\Steam.exe" -silent
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater\AdobeUpdater.exe
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"openvpn-gui"=C:\Program Files\OpenVPN\bin\openvpn-gui.exe
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Svchost - netsvcs
UxTuneUp
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{b74bc0bf-b80c-11db-957f-00095be3cde9}]
AutoRun\command- Q:\LaunchU3.exe -a
Contents of the 'Scheduled Tasks' folder
2007-06-22 09:21:34 C:\WINDOWS\tasks\1-Click Maintenance.job
2007-06-05 03:48:15 C:\WINDOWS\tasks\AppleSoftwareUpdate.job
2007-06-26 16:35:01 C:\WINDOWS\tasks\Check Updates for Windows Live Toolbar.job
2099-12-26 02:00:26 C:\WINDOWS\tasks\User_Feed_Synchronization-{588A7190-5FE9-4988-B0DE-5BB204EACCE2}.job
**************************************************************************
catchme 0.3.721 W2K/XP/Vista - userland rootkit detector by Gmer,
http://www.gmer.netRootkit scan 2007-06-27 00:52:36
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
Completion time: 2007-06-27 0:53:42
C:\ComboFix-quarantined-files.txt ... 2007-06-27 00:53
--- E O F ---