c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Client\cd1079f4cde453ac6b1a72a488688aec\WindowsLive.Client.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 400896 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml.Linq\43dff2d60cc1e2d83207d115d6ebd5da\System.Xml.Linq.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 129536 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Routing\bbbbee6aee8efc2a3fe36297df61558c\System.Web.Routing.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 202240 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.RegularE#\4918daec30cc88a92e9089d6e6ddf65b\System.Web.RegularExpressions.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 859648 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\1abbdbd4a1de53b702bae22e4714b95d\System.Web.Extensions.Design.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 328704 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity\adaa9f715be2debd2b11674077f3afda\System.Web.Entity.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 301056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Entity.D#\23a843aedd80a0f43e0baa1986bcd83f\System.Web.Entity.Design.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 547328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.DynamicD#\a68617197d12be5a9a8bb91b4e7873ec\System.Web.DynamicData.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Abstract#\8ff474534be27f40db5c17fee04a9fe7\System.Web.Abstractions.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 627200 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\9aa6ef5e5d40a8b8fb2850ee4a3e7bb3\System.Transactions.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceProce#\b74d61184e254ac814bb3ceae5cc1095\System.ServiceProcess.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 676352 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Security\3ef9383bddd7283406d0ba7303f38e46\System.Security.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 311296 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\aab1f5149537a106a50b1508d9b18eb5\System.Runtime.Serialization.Formatters.Soap.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 771584 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\bb055968cb987dffa2f558cc5a2713f7\System.Runtime.Remoting.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 621056 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Net\90e7b21b6f94a25cb4470ac854999479\System.Net.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 998400 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\d7ad7924159136fb7e13cfdf3d01cf21\System.Management.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 330752 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.I#\7081191709ba39f5b18f2f52f61c6aab\System.Management.Instrumentation.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 181248 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\fafc03597676e65dfb8f4697ac647c62\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 188928 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\f32313a8dec56494438c80f5d54305f6\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 169984 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\ea77ee92b00cbefb83da28fce1b67019\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 169472 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\ddc0417f8addef49288190f918af1dac\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 154624 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\c6e875d1a64aea766fbdd75037851222\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 154112 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\c5de04699aa38a2dabea09019dea086d\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 177664 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\892b5420690274f0e84073f1e52428bf\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 221184 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\84b0a0d2a43a3e3d7a530b46bb49bdee\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 160256 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\646fab05d237a943021a9ceaa6c32c7b\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 172544 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\0d8ad65fa89646d47bfc0fd29a015f6e\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\09c54e2aad75149a41492bd38567ae26\System.Management.Automation.resources.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 381440 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IO.Log\c88bdc0770617f2bec70e82b2877712e\System.IO.Log.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 212992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityMode#\9830b36108b5acc8bfecd4b523ae6422\System.IdentityModel.Selectors.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 280064 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\34bd8d1c5589efe26dfd69cfef05888c\System.EnterpriseServices.Wrapper.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 627712 c:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\34bd8d1c5589efe26dfd69cfef05888c\System.EnterpriseServices.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 881152 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\2e171d3863d31c9760be4a76d7a41842\System.DirectoryServices.AccountManagement.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 455680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\26c2dd48768ead8ab6981c502c33a16b\System.DirectoryServices.Protocols.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 939008 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\a157c98a0bd61c92cc324ccb085c0c2f\System.Data.Services.Client.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 354816 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Service#\43ebb69f9f13b4d50877a718fe7e2fec\System.Data.Services.Design.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 756736 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity.#\6f40c0b03a35585ad314a0459ebd3721\System.Data.Entity.Design.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 135680 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.DataSet#\67b8b52a93087400d9c8efa36d28ba0f\System.Data.DataSetExtensions.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 971264 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\33f46842f1687b027c3471ca1ba6e929\System.Configuration.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 141312 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuratio#\d5f4012b6c896418365813c53c5e46ce\System.Configuration.Install.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 633856 c:\windows\assembly\NativeImages_v2.0.50727_32\System.AddIn\338d4c7d84af692ae64bdee6e66bd04a\System.AddIn.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 366080 c:\windows\assembly\NativeImages_v2.0.50727_32\SMSvcHost\57b773ae9a151b61e0d669e8bbc64275\SMSvcHost.ni.exe
+ 2010-03-25 10:26 . 2010-03-25 10:26 256000 c:\windows\assembly\NativeImages_v2.0.50727_32\SMDiagnostics\c047fb6624ebfd95bdbc916e0068e6e9\SMDiagnostics.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 320512 c:\windows\assembly\NativeImages_v2.0.50727_32\ServiceModelReg\ce9e424d230401a889211771dec6b896\ServiceModelReg.ni.exe
+ 2010-03-25 10:27 . 2010-03-25 10:27 133632 c:\windows\assembly\NativeImages_v2.0.50727_32\MSBuild\9f2d92e6bde466705c09e3ecf53878a5\MSBuild.ni.exe
+ 2010-03-25 10:25 . 2010-03-25 10:25 386560 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\49805534376724ae137ff41cda393d19\Microsoft.Transactions.Bridge.Dtc.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 433664 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\9e64552e502e83ea9f36a635da673f2a\Microsoft.PowerShell.Commands.Management.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 968192 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\7a87e180c6853689a6962cfabf5a4a22\Microsoft.PowerShell.Commands.Utility.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 492032 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\263801f28bdfc6390257bfd325c791d4\Microsoft.PowerShell.ConsoleHost.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 148480 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.PowerShel#\0b22303173840a037788ee88b4f664cc\Microsoft.PowerShell.Security.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 144384 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\caf2207b404aa5bcb77833e3302fc5b6\Microsoft.Build.Utilities.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 175104 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Uti#\74290c786353b8f4341550847169adb1\Microsoft.Build.Utilities.v3.5.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 839680 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\ecad09aa540d7011ff615077bba756c9\Microsoft.Build.Engine.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 222720 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Con#\d326c3841b68b469dc70eab552dc0764\Microsoft.Build.Conversion.v3.5.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 220672 c:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\7966bb0eeae06d6e0a0999f7e57945c3\CustomMarshalers.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 410112 c:\windows\assembly\NativeImages_v2.0.50727_32\ComSvcConfig\aa863a2ee18166e2c56f9b310352b160\ComSvcConfig.ni.exe
+ 2010-03-25 10:26 . 2010-03-25 10:26 842240 c:\windows\assembly\NativeImages_v2.0.50727_32\AspNetMMCExt\ab21507db0a8b7a8b8bd86f468bed2d4\AspNetMMCExt.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 2002432 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\bb29db714cd9e02fc81c2c4c9e8f02bc\WindowsLive.Writer.CoreServices.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 6392832 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\94955e7aa3de2831287efe8332434242\WindowsLive.Writer.PostEditor.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 1105920 c:\windows\assembly\NativeImages_v2.0.50727_32\WindowsLive.Writer.#\93ea9de52afb1bcc60d26c6581b7a59f\WindowsLive.Writer.ApplicationFramework.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 1356288 c:\windows\assembly\NativeImages_v2.0.50727_32\System.WorkflowServ#\ad2b413a977164493c9498e6eea9836a\System.WorkflowServices.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 1908224 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Run#\56f5b5b7fbb513b20a8c42d6ede20716\System.Workflow.Runtime.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 4514304 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Com#\4428b243d69bdd25c325fcf5a4d9f1eb\System.Workflow.ComponentModel.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 2992640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Workflow.Act#\1133d8b77e7e94edc069d95e93eb0531\System.Workflow.Activities.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 1840640 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\affca324d68452f7827a9be5e355e445\System.Web.Services.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 2209280 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Mobile\dec2660e1581be57dacf9c6104e8d252\System.Web.Mobile.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 2403328 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Extensio#\9c987fc21a6763c2bd5b1f7ec5b5b153\System.Web.Extensions.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 1706496 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel#\9195677eb52d4545a918a70636cacaac\System.ServiceModel.Web.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 2344960 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Seri#\0f1d3fc0f9bd72295c053a66090472e1\System.Runtime.Serialization.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 4949504 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Management.A#\a61c36c0207c5c67294c2e53fb3f55c7\System.Management.Automation.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 1056768 c:\windows\assembly\NativeImages_v2.0.50727_32\System.IdentityModel\3b589e5c7262c5564668e893ed5fa347\System.IdentityModel.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 1116672 c:\windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\3102dd31a0e81701ab4c3e3627210885\System.DirectoryServices.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 1801216 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Deployment\299b46ce8a9cd708aad0b34a6817c3c9\System.Deployment.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 2510336 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SqlXml\0f4ca76e1a55a8b10a169e26fb5ae852\System.Data.SqlXml.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 1328128 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Services\6d3af39f54f52966f62c89d88ea2d106\System.Data.Services.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 1115136 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.OracleC#\d97e96e4d4075c86d51ff133fd0dbd1c\System.Data.OracleClient.ni.dll
+ 2010-03-25 10:28 . 2010-03-25 10:28 9924096 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.Entity\f0ffa7c1091f11d9b3442926e44f2756\System.Data.Entity.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 1712128 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\16fc2faef3984a77e7ee02cafd94c5f4\Microsoft.VisualBasic.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 1093120 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Transacti#\01bf250452829c199bdc583e3e007685\Microsoft.Transactions.Bridge.ni.dll
+ 2010-03-25 10:29 . 2010-03-25 10:29 2332160 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.JScript\1d4ab5c6748b01243403b915fb76e068\Microsoft.JScript.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 1966080 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\e5581e288bb26364dc6d4987251dfdf5\Microsoft.Build.Tasks.v3.5.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 1620992 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Tas#\19627bc5e3955d69e007b4c4f49489db\Microsoft.Build.Tasks.ni.dll
+ 2010-03-25 10:27 . 2010-03-25 10:27 1888768 c:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Build.Eng#\e25766aa55cbe4b36e3c6b1a498beb0d\Microsoft.Build.Engine.ni.dll
+ 2010-03-25 10:26 . 2010-03-25 10:26 11796992 c:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\3d959bc1e5bef926783107fd981701b6\System.Web.ni.dll
+ 2010-03-25 10:25 . 2010-03-25 10:25 17317888 c:\windows\assembly\NativeImages_v2.0.50727_32\System.ServiceModel\737db428238916034602919cb948166c\System.ServiceModel.ni.dll
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"AGRSMMSG"="AGRSMMSG.exe" [2003-06-27 88363]
"SynTPLpr"="c:\program files\Synaptics\SynTP\SynTPLpr.exe" [2008-07-04 118784]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2008-07-04 1323008]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-12-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-12-11 948672]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-10-11 149280]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Windows Search.lnk - c:\program files\Windows Desktop Search\WindowsSearch.exe [2008-5-26 123904]
[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"= "c:\program files\Windows Desktop Search\MSNLNamespaceMgr.dll" [2009-05-25 304128]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [8/16/2008 9:51 PM 24652]
S3 PCX500;Cisco Wireless LAN Adapters Driver;c:\windows\system32\drivers\pcx500.sys [8/15/2008 7:59 PM 222720]
S3 PCX500MP;Cisco 350 Series Lower Device Filter;c:\windows\system32\drivers\pcx500mp.sys [8/5/2002 2:46 PM 4990]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2010-03-25 20:08
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(684)
c:\windows\system32\Ati2evxx.dll
.
Completion time: 2010-03-25 20:11:58
ComboFix-quarantined-files.txt 2010-03-26 00:11
ComboFix2.txt 2010-03-25 03:28
Pre-Run: 22,288,273,408 bytes free
Post-Run: 22,245,429,248 bytes free
- - End Of File - - CBEB9018565D1403F66428554248469E