Page 1 of 3 123 LastLast
Results 1 to 10 of 24

Thread: System checkup

  1. #1
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default System checkup

    I dont know if I'm infected or not since the last time I ran Spybot, it detected a virtumondo. I cleaned it (using spybot), restarted my pc and re-scanned my pc. It yielded zero results, yet im still doubtful.

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 8:13:47 PM, on 11/9/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\COMODO\SafeSurf\cssurf.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\FRAPS\FRAPS.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.zyxel.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {0808798f-a2a0-4c79-8fe7-efeb2f487cba} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {67C5CBB2-6E04-495B-838D-EF85E50B04E8} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {D1974D4D-77D7-4EEB-A76A-1EFFFC19C825} - (no file)
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
    O20 - Winlogon Notify: awttqrPj - C:\WINDOWS\
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 8795 bytes


    Looking forward to your assistance

  2. #2
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi Vhaeraun

    • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
    • Double click on RSIT.exe to run RSIT.
    • Click Continue at the disclaimer screen.
    • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  3. #3
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default

    Log.txt

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Vhaeraun at 2008-11-10 19:23:11
    Microsoft Windows XP Professional Service Pack 2
    System drive C: has 42 GB (70%) free of 60 GB
    Total RAM: 2047 MB (72% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 7:23:17 PM, on 11/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\COMODO\SafeSurf\cssurf.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\FRAPS\FRAPS.EXE
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\wuauclt.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\Program Files\Internet Explorer\iexplore.exe
    D:\Games\Melty Blood\MBACWIN\mbcaster.exe
    C:\Documents and Settings\Vhaeraun\Desktop\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\Vhaeraun.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.zyxel.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {0808798f-a2a0-4c79-8fe7-efeb2f487cba} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {67C5CBB2-6E04-495B-838D-EF85E50B04E8} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {D1974D4D-77D7-4EEB-A76A-1EFFFC19C825} - (no file)
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [COMODO SafeSurf] "C:\Program Files\COMODO\SafeSurf\cssurf.exe" -s
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
    O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
    O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
    O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll/206 (file missing)
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
    O20 - Winlogon Notify: awttqrPj - C:\WINDOWS\
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 8857 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\EasyShare Registration Task.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0808798f-a2a0-4c79-8fe7-efeb2f487cba}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{39F7E362-828A-4B5A-BCAF-5B79BFDFEA60}]
    BitComet Helper - C:\Program Files\BitComet\tools\BitCometBHO_1.2.8.7.dll [2008-08-11 656696]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-12 222448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67C5CBB2-6E04-495B-838D-EF85E50B04E8}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1974D4D-77D7-4EEB-A76A-1EFFFC19C825}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
    EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]
    {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-02-25 16125440]
    "SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
    "AsusStartupHelp"=C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe [2006-11-13 363008]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-09-17 13574144]
    "nwiz"=nwiz.exe /install []
    "avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
    "PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2008-07-06 167936]
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-09-17 86016]
    "WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-07-09 36352]
    "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
    "COMODO SafeSurf"=C:\Program Files\COMODO\SafeSurf\cssurf.exe [2008-10-04 278264]
    "COMODO Firewall Pro"=C:\Program Files\COMODO\Firewall\cfp.exe [2008-10-31 1797880]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
    "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
    "COMODO Internet Security"=C:\Program Files\COMODO\Firewall\cfp.exe [2008-10-31 1797880]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2008-09-19 4347120]
    "DownloadAccelerator"=C:\Program Files\DAP\DAP.EXE /STARTUP []
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
    "Fraps"=C:\FRAPS\FRAPS.EXE [2008-09-10 3305128]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awttqrPj]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "NoDrives"=
    "NoDriveAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
    "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "D:\Games\Melty Blood\MBACWIN\mbcaster.exe"="D:\Games\Melty Blood\MBACWIN\mbcaster.exe:*:Enabled:mbcaster"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
    "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e23d757-8f61-11dd-b9f4-001bfce397fe}]
    shell\AutoRun\command - G:\LaunchU3.exe


    ======List of files/folders created in the last 3 months======

    2008-11-10 19:23:11 ----D---- C:\rsit
    2008-11-03 22:52:29 ----A---- C:\DTSHDSpOut.txt
    2008-11-02 11:24:30 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\EPSON
    2008-10-30 22:22:39 ----D---- C:\Program Files\Common Files\SWF Studio
    2008-10-26 20:42:19 ----D---- C:\Program Files\StepMania
    2008-10-26 01:29:34 ----D---- C:\Program Files\Download Express
    2008-10-26 01:29:34 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\MetaProducts
    2008-10-23 21:21:29 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Apple Computer
    2008-10-22 22:09:03 ----D---- C:\DVDVideoSoft
    2008-10-22 22:08:34 ----D---- C:\Program Files\DVDVideoSoft
    2008-10-22 22:08:34 ----D---- C:\Program Files\Common Files\DVDVideoSoft
    2008-10-22 22:08:34 ----A---- C:\WINDOWS\system32\msvcr70.dll
    2008-10-22 21:47:25 ----D---- C:\WINDOWS\Applian FLV Player
    2008-10-22 21:45:27 ----A---- C:\WINDOWS\Applian FLV Player Setup Log.txt
    2008-10-19 13:07:20 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Mozilla
    2008-10-10 12:01:06 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-10-10 12:00:55 ----D---- C:\WINDOWS\WBEM
    2008-10-10 12:00:54 ----D---- C:\WINDOWS\system32\en-US
    2008-10-10 11:59:46 ----HDC---- C:\WINDOWS\ie7
    2008-10-10 11:59:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
    2008-10-10 11:59:08 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
    2008-10-10 11:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
    2008-10-10 11:58:39 ----HD---- C:\WINDOWS\$hf_mig$
    2008-10-10 11:58:37 ----N---- C:\WINDOWS\system32\xmllite.dll
    2008-10-10 11:54:30 ----D---- C:\Program Files\DivX
    2008-10-10 11:54:30 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\DivX
    2008-10-09 19:08:52 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\dvdcss
    2008-10-09 08:03:46 ----D---- C:\logs
    2008-10-09 08:03:37 ----D---- C:\Program Files\Chikka Messenger
    2008-10-07 18:45:07 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2008-10-07 18:45:06 ----D---- C:\Program Files\Xvid
    2008-10-07 18:45:06 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbdkor.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbdjpn.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbd106.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd103.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd101c.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd101b.dll
    2008-10-07 01:15:05 ----D---- C:\WINDOWS\Sun
    2008-10-06 23:39:42 ----D---- C:\ComboFix
    2008-10-06 21:00:04 ----D---- C:\Program Files\Sun
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\java.exe
    2008-10-06 20:57:53 ----D---- C:\Program Files\Common Files\Java
    2008-10-06 20:36:06 ----D---- C:\Program Files\SDM20
    2008-10-06 20:03:43 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Sun
    2008-10-06 20:03:06 ----D---- C:\WINDOWS\system32\appmgmt
    2008-10-06 19:57:31 ----SHD---- C:\RECYCLER
    2008-10-06 19:52:24 ----D---- C:\Program Files\Common Files\Adobe AIR
    2008-10-06 15:23:04 ----D---- C:\WINDOWS\temp
    2008-10-04 20:43:38 ----D---- C:\Program Files\SpywareBlaster
    2008-10-04 20:37:00 ----A---- C:\WINDOWS\system32\cssdll32.dll
    2008-10-04 20:36:17 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Comodo
    2008-10-04 20:36:16 ----D---- C:\Documents and Settings\All Users\Application Data\comodo
    2008-10-04 20:36:16 ----A---- C:\WINDOWS\system32\guard32.dll
    2008-10-04 20:36:15 ----D---- C:\Program Files\COMODO
    2008-10-04 18:24:19 ----A---- C:\WINDOWS\wininit.ini
    2008-10-04 13:43:46 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-10-04 13:43:37 ----D---- C:\WINDOWS\system32\DRVSTORE
    2008-10-04 13:43:33 ----D---- C:\Program Files\Common Files\Kodak
    2008-10-04 13:43:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
    2008-10-04 13:41:09 ----D---- C:\Config.Msi
    2008-10-04 13:30:18 ----A---- C:\VundoFix.txt
    2008-10-04 12:50:55 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Malwarebytes
    2008-10-04 12:50:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-04 12:50:53 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-04 12:29:02 ----D---- C:\Program Files\Trend Micro
    2008-10-04 12:08:14 ----D---- C:\WINDOWS\erdnt
    2008-10-04 11:03:48 ----D---- C:\Program Files\Spybot - Search & Destroy
    2008-10-04 11:03:48 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-10-04 10:59:53 ----D---- C:\Program Files\Lavasoft
    2008-10-04 10:59:53 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-10-03 19:36:24 ----D---- C:\Program Files\QuickTime
    2008-10-03 19:36:09 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-10-03 19:35:27 ----D---- C:\WINDOWS\system32\BWKDLogs
    2008-10-03 19:34:54 ----A---- C:\WINDOWS\system32\ptpusb.dll
    2008-10-03 19:34:53 ----A---- C:\WINDOWS\system32\ptpusd.dll
    2008-10-03 19:30:44 ----D---- C:\Program Files\Kodak
    2008-10-03 19:26:35 ----D---- C:\Documents and Settings\All Users\Application Data\Kodak
    2008-10-03 14:27:40 ----SHD---- C:\found.000
    2008-10-03 14:23:09 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
    2008-10-03 14:23:09 ----A---- C:\WINDOWS\system32\NPSWF32.dll
    2008-10-03 14:14:06 ----D---- C:\Program Files\Bonjour
    2008-10-03 14:09:09 ----D---- C:\Program Files\Common Files\Macrovision Shared
    2008-10-03 14:06:16 ----N---- C:\WINDOWS\system32\spmsg.dll
    2008-10-03 14:06:05 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    2008-10-02 16:37:52 ----D---- C:\Documents and Settings\All Users\Application Data\SpeedBit
    2008-10-02 16:37:47 ----D---- C:\Program Files\DAP
    2008-10-01 22:53:05 ----A---- C:\WINDOWS\system32\bb75a282-.txt
    2008-10-01 22:38:59 ----D---- C:\WINDOWS\Minidump
    2008-10-01 22:13:43 ----D---- C:\WINDOWS\NV21602468.TMP
    2008-10-01 22:13:31 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-10-01 21:32:36 ----D---- C:\Virtual dub
    2008-10-01 21:08:13 ----D---- C:\NVIDIA
    2008-10-01 20:45:44 ----D---- C:\Program Files\SystemRequirementsLab
    2008-10-01 08:04:56 ----A---- C:\WINDOWS\system32\wmpns.dll
    2008-10-01 07:38:27 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\vlc
    2008-10-01 07:30:43 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\WinRAR
    2008-10-01 07:28:07 ----D---- C:\Program Files\WinRAR
    2008-10-01 07:20:59 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2008-10-01 07:20:56 ----D---- C:\Fraps
    2008-10-01 07:19:38 ----D---- C:\Program Files\7-Zip
    2008-09-30 23:21:19 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Hamachi
    2008-09-30 23:21:00 ----D---- C:\Program Files\Hamachi
    2008-09-30 23:13:46 ----D---- C:\Program Files\Java
    2008-09-30 23:11:16 ----D---- C:\Program Files\Mozilla Firefox
    2008-09-30 23:06:55 ----A---- C:\WINDOWS\ODBC.INI
    2008-09-30 23:06:41 ----D---- C:\Program Files\Microsoft ActiveSync
    2008-09-30 23:06:39 ----D---- C:\Program Files\Common Files\DESIGNER
    2008-09-30 23:06:33 ----D---- C:\WINDOWS\SHELLNEW
    2008-09-30 23:06:32 ----D---- C:\Program Files\Microsoft Office
    2008-09-30 21:49:42 ----RD---- C:\WINDOWS\AsDmiHtm
    2008-09-30 20:05:08 ----D---- C:\Downloads
    2008-09-30 19:34:31 ----D---- C:\Program Files\BitComet
    2008-09-30 19:33:19 ----D---- C:\Program Files\PowerISO
    2008-09-30 19:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\UDL
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK2.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK.ini
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICEntry.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\EPPicMgr.dll
    2008-09-30 19:28:53 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
    2008-09-30 19:28:52 ----A---- C:\WINDOWS\system32\E_FLBBFP.DLL
    2008-09-30 19:28:52 ----A---- C:\WINDOWS\system32\E_FD4BBFP.DLL
    2008-09-30 19:00:35 ----D---- C:\WINDOWS\RegisteredPackages
    2008-09-30 18:58:48 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Yahoo!
    2008-09-30 18:58:48 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxsfs.dll
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxinsa64.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxhpinst.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxdrv.dll
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxcpya64.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxafs.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\pxwave.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\pxmas.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\px.dll
    2008-09-30 18:58:25 ----D---- C:\Program Files\Winamp
    2008-09-30 18:58:25 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Winamp
    2008-09-30 18:57:34 ----D---- C:\Program Files\VideoLAN
    2008-09-30 18:48:14 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
    2008-09-30 18:47:12 ----A---- C:\YServer.txt
    2008-09-30 18:47:05 ----D---- C:\Program Files\Yahoo!
    2008-09-30 18:45:09 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Macromedia
    2008-09-30 18:45:09 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Adobe
    2008-09-30 18:43:29 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-09-30 18:43:25 ----D---- C:\Program Files\Common Files\Adobe
    2008-09-30 18:43:25 ----D---- C:\Program Files\Adobe
    2008-09-30 18:41:25 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
    2008-09-30 18:41:20 ----D---- C:\Program Files\WinZip
    2008-09-30 18:33:18 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\U3
    2008-09-30 18:31:25 ----D---- C:\Program Files\Avira
    2008-09-30 18:31:25 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
    2008-09-30 13:48:29 ----D---- C:\WINDOWS\system32\Lang
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSTPLOG.TXT
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSTPLOG.BAK
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSMTL32.TXT
    2008-09-30 13:39:18 ----D---- C:\Program Files\epson
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\escwiad.dll
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\escimgd.dll
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\esccmd.dll
    2008-09-30 13:39:11 ----A---- C:\WINDOWS\CDE CX2900EC.ini
    2008-09-30 13:38:47 ----A---- C:\WINDOWS\epsswt_log.txt
    2008-09-30 13:37:03 ----D---- C:\WINDOWS\nview
    2008-09-30 13:37:02 ----A---- C:\WINDOWS\system32\nvudisp.exe
    2008-09-30 13:36:12 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
    2008-09-30 13:23:00 ----D---- C:\Program Files\InterVideo
    2008-09-30 13:19:34 ----RA---- C:\WINDOWS\system32\AsIO.dll
    2008-09-30 13:19:32 ----D---- C:\Program Files\ASUS
    2008-09-30 13:19:03 ----RA---- C:\WINDOWS\system32\ChCfg.exe
    2008-09-30 13:18:47 ----D---- C:\WINDOWS\system32\RTCOM
    2008-09-30 13:18:45 ----A---- C:\WINDOWS\system32\ksuser.dll
    2008-09-30 13:18:21 ----A---- C:\WINDOWS\system32\spupdsvc.exe
    2008-09-30 13:18:20 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
    2008-09-30 13:18:17 ----R---- C:\WINDOWS\SoundMan.exe
    2008-09-30 13:18:16 ----R---- C:\WINDOWS\SkyTel.exe
    2008-09-30 13:18:15 ----R---- C:\WINDOWS\RtlUpd.exe
    2008-09-30 13:18:12 ----R---- C:\WINDOWS\RTLCPL.exe
    2008-09-30 13:18:06 ----R---- C:\WINDOWS\RTHDCPL.exe
    2008-09-30 13:18:05 ----R---- C:\WINDOWS\MicCal.exe
    2008-09-30 13:18:03 ----R---- C:\WINDOWS\alcwzrd.exe
    2008-09-30 13:18:03 ----R---- C:\WINDOWS\Alcmtr.exe
    2008-09-30 13:18:02 ----D---- C:\Program Files\Realtek
    2008-09-30 13:18:01 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-09-30 13:17:59 ----A---- C:\WINDOWS\HideWin.exe
    2008-09-30 13:17:58 ----R---- C:\WINDOWS\RtlExUpd.dll
    2008-09-30 13:17:55 ----D---- C:\Program Files\Common Files\InstallShield
    2008-09-30 13:17:27 ----A---- C:\WINDOWS\Ascd_log.ini
    2008-09-30 13:09:50 ----A---- C:\WINDOWS\Ascd_tmp.ini
    2008-09-30 13:09:47 ----A---- C:\WINDOWS\AS_Debug.txt
    2008-09-30 13:08:00 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Identities
    2008-09-30 13:07:59 ----HD---- C:\Program Files\Uninstall Information
    2008-09-30 13:07:54 ----SD---- C:\Documents and Settings\Vhaeraun\Application Data\Microsoft
    2008-09-30 13:07:54 ----ASH---- C:\Documents and Settings\Vhaeraun\Application Data\desktop.ini
    2008-09-30 13:07:01 ----D---- C:\WINDOWS\SoftwareDistribution
    2008-09-30 13:07:00 ----SD---- C:\WINDOWS\system32\Microsoft
    2008-09-30 13:07:00 ----D---- C:\WINDOWS\Prefetch
    2008-09-30 13:07:00 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-09-30 13:04:00 ----D---- C:\WINDOWS\system32\xircom
    2008-09-30 13:04:00 ----D---- C:\Program Files\xerox
    2008-09-30 13:04:00 ----D---- C:\Program Files\microsoft frontpage
    2008-09-30 13:03:48 ----A---- C:\WINDOWS\control.ini
    2008-09-30 13:03:48 ----A---- C:\AUTOEXEC.BAT
    2008-09-30 13:03:41 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-09-30 13:03:38 ----A---- C:\WINDOWS\system32\mapi32.dll
    2008-09-30 13:03:00 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-09-30 13:03:00 ----RD---- C:\WINDOWS\Offline Web Pages
    2008-09-30 13:03:00 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
    2008-09-30 13:02:56 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
    2008-09-30 13:02:52 ----HD---- C:\Program Files\WindowsUpdate
    2008-09-30 13:02:36 ----D---- C:\WINDOWS\system32\DirectX
    2008-09-30 13:02:18 ----A---- C:\WINDOWS\system32\atrace.dll
    2008-09-30 13:02:16 ----A---- C:\WINDOWS\system32\desktop.ini
    2008-09-30 13:02:16 ----A---- C:\WINDOWS\desktop.ini
    2008-09-30 13:02:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
    2008-09-30 13:02:07 ----D---- C:\Program Files\Common Files\Services
    2008-09-30 13:02:07 ----A---- C:\WINDOWS\system32\acctres.dll
    2008-09-30 13:02:04 ----SD---- C:\WINDOWS\Tasks
    2008-09-30 13:02:04 ----A---- C:\WINDOWS\system32\icfgnt5.dll
    2008-09-30 13:02:03 ----D---- C:\Program Files\Common Files\MSSoap
    2008-09-30 13:02:00 ----D---- C:\WINDOWS\srchasst
    2008-09-30 13:01:59 ----D---- C:\WINDOWS\system32\Macromed
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuweb.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wucltui.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuauserv.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wups.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuauclt1.exe
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuapi.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\qmgr.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll
    2008-09-30 13:01:53 ----D---- C:\Program Files\Movie Maker
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrslv.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrdm.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\racpldlg.dll
    2008-09-30 13:01:46 ----A---- C:\WINDOWS\system32\fltMc.exe
    2008-09-30 13:01:46 ----A---- C:\WINDOWS\system32\fltlib.dll
    2008-09-30 13:01:45 ----D---- C:\WINDOWS\system32\Restore
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srsvc.dll
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srrstr.dll
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srclient.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\msconf.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\ils.dll
    2008-09-30 13:01:41 ----D---- C:\Program Files\NetMeeting
    2008-09-30 13:01:41 ----A---- C:\WINDOWS\system32\msoert2.dll
    2008-09-30 13:01:41 ----A---- C:\WINDOWS\system32\msoeacct.dll
    2008-09-30 13:01:40 ----A---- C:\WINDOWS\system32\inetres.dll
    2008-09-30 13:01:40 ----A---- C:\WINDOWS\system32\inetcomm.dll
    2008-09-30 13:01:39 ----D---- C:\Program Files\Outlook Express
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\mstinit.exe
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\mstask.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\isign32.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\inetcfg.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\icwphbk.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\icwdial.dll
    2008-09-30 13:01:33 ----D---- C:\Program Files\Common Files\System
    2008-09-30 13:01:28 ----D---- C:\Program Files\Internet Explorer
    2008-09-30 13:01:01 ----D---- C:\WINDOWS\Registration
    2008-09-30 12:02:55 ----D---- C:\Program Files\ComPlus Applications
    2008-09-30 12:02:53 ----A---- C:\WINDOWS\vbaddin.ini
    2008-09-30 12:02:53 ----A---- C:\WINDOWS\vb.ini
    2008-09-30 12:02:44 ----D---- C:\Program Files\Windows Media Player
    2008-09-30 12:02:44 ----D---- C:\Program Files\Online Services
    2008-09-30 12:02:39 ----D---- C:\Program Files\Messenger
    2008-09-30 12:02:36 ----D---- C:\Program Files\MSN Gaming Zone
    2008-09-30 12:02:36 ----A---- C:\WINDOWS\system32\write.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\winchat.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\sndvol32.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\hticons.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avwav.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avtapi.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avmeter.dll
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\winmine.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\sol.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\getuname.dll
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\charmap.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\calc.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\usrlogon.cmd
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tsshutdn.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tslabels.ini
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tskill.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tsdiscon.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tscon.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\shadow.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\rwinsta.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\reset.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\regini.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\qwinsta.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\qappsrv.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\mshearts.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\msg.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\freecell.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxlegih.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxex.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxdm.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\msdtcprf.ini
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\logoff.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\comrepl.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\comaddin.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\cdmodem.dll
    2008-09-30 12:02:22 ----A---- C:\WINDOWS\system32\stclient.dll
    2008-09-30 12:02:22 ----A---- C:\WINDOWS\system32\comsnap.dll
    2008-09-30 12:02:19 ----A---- C:\WINDOWS\system32\wmimgmt.msc
    2008-09-30 12:02:11 ----D---- C:\Program Files\MSN
    2008-09-30 12:02:10 ----D---- C:\Program Files\Windows NT
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\sndrec32.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\mspaint.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\mplay32.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\hypertrm.dll
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\accwiz.exe
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\spider.exe
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\mstscax.dll
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\clipbrd.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\tscupgrd.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\termsrv.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\sessmgr.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\remotepg.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdshost.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdsaddin.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpwsx.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpsnd.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpclip.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdchost.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\qprocess.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\mstsc.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\icaapi.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\cfgbkend.dll
    2008-09-30 12:02:07 ----D---- C:\WINDOWS\system32\MsDtc
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\xolehlp.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\mtxoci.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtctm.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtcprx.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtclog.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtc.exe
    2008-09-30 12:02:06 ----D---- C:\WINDOWS\system32\Com
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\comsvcs.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\colbact.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\clbcatex.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrvut.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrvps.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrv.dll
    2008-09-30 12:02:05 ----A---- C:\WINDOWS\system32\comuid.dll
    2008-09-30 12:02:05 ----A---- C:\WINDOWS\system32\clbcatq.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\servdeps.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\mmfutil.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\licwmi.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\cmprops.dll
    2008-09-30 05:55:54 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
    2008-09-30 05:55:50 ----RA---- C:\WINDOWS\SET2B.tmp
    2008-09-30 05:55:48 ----RA---- C:\WINDOWS\SET1F.tmp
    2008-09-30 05:55:47 ----RA---- C:\WINDOWS\SET1C.tmp
    2008-09-30 05:55:29 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-09-30 05:00:45 ----A---- C:\WINDOWS\system32\h323log.txt
    2008-09-30 04:58:21 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
    2008-09-30 04:58:21 ----A---- C:\WINDOWS\system32\HSFCISP2.dll
    2008-09-30 04:58:06 ----A---- C:\WINDOWS\system32\usbui.dll
    2008-09-30 04:57:23 ----A---- C:\WINDOWS\imsins.BAK
    2008-09-30 04:57:21 ----SHD---- C:\WINDOWS\Installer
    2008-09-30 04:57:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-09-30 04:57:20 ----D---- C:\Program Files\Common Files\ODBC
    2008-09-30 04:57:20 ----A---- C:\WINDOWS\ODBCINST.INI
    2008-09-30 04:57:18 ----D---- C:\Program Files\Common Files\SpeechEngines
    2008-09-30 04:57:17 ----RD---- C:\Program Files
    2008-09-30 04:57:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-09-30 04:57:17 ----D---- C:\Program Files\Common Files
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdazel.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdycc.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbduzb.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdur.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdtat.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdru1.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdru.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdmon.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdbu.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdblr.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdaze.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhept.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlv.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlt.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdest.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdycl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdsl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdro.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdpl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdhu.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcr.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\spxcoins.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\irclass.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\EqnClass.Dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\dgsetup.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\TASKMAN.EXE
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\system32\CONFIG.TMP
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\system32\batt.dll
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\NOTEPAD.EXE
    2008-09-30 04:57:05 ----A---- C:\WINDOWS\system32\storprop.dll
    2008-09-30 04:56:56 ----RA---- C:\WINDOWS\SET8.tmp
    2008-09-30 04:56:54 ----RA---- C:\WINDOWS\SET4.tmp
    2008-09-30 04:56:53 ----RA---- C:\WINDOWS\SET3.tmp
    2008-09-30 04:56:49 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-09-30 04:56:49 ----D---- C:\WINDOWS\system32\CatRoot
    2008-09-30 04:56:30 ----A---- C:\WINDOWS\setuplog.txt
    2008-09-30 04:56:27 ----SHD---- C:\System Volume Information
    2008-09-30 04:56:27 ----D---- C:\Documents and Settings
    2008-09-30 04:52:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-09-30 04:52:11 ----RSD---- C:\WINDOWS\Fonts
    2008-09-30 04:52:11 ----RD---- C:\WINDOWS\Web
    2008-09-30 04:52:11 ----HD---- C:\WINDOWS\inf
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\WinSxS
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\twain_32
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\wins
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\wbem
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\usmt
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\spool
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ShellExt
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\Setup
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ras
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\oobe
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\npp
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\mui
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\inetsrv
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\IME
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\icsxml
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ias
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\export
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\drivers
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\dhcp
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\config
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\3com_dmi
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\3076
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\2052
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1054
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1042
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1041
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1037
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1033
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1031
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1028
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1025
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\security
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Resources
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\repair
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Provisioning
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\PeerNet
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\pchealth
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\mui
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\msapps
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\msagent
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Media
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\java
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\ime
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Help
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\ehome
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Driver Cache
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Debug
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Cursors
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Connection Wizard
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Config
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\AppPatch
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\addins
    2008-09-30 04:52:11 ----D---- C:\WINDOWS
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
    2008-09-15 16:12:54 ----A---- C:\WINDOWS\system32\ssldivx.dll
    2008-09-15 16:12:54 ----A---- C:\WINDOWS\system32\libdivx.dll
    2008-09-09 22:37:22 ----A---- C:\WINDOWS\system32\frapsvid.dll

    ======List of files/folders modified in the last 3 months======

    2008-10-06 15:24:55 ----A---- C:\WINDOWS\system.ini
    2008-09-30 23:06:47 ----A---- C:\WINDOWS\win.ini
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nwiz.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwss.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvshell.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nview.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvgames.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcod.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvapi.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\keystone.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-17 12664]
    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-06-27 75072]
    R1 cmdGuard;COMODO Firewall Pro Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2008-11-09 99856]
    R1 cmdHlp;COMODO Firewall Pro Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2008-11-09 31504]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 36096]
    R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-07-06 56108]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
    R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
    R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-09-30 25280]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
    R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
    R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-01 4484608]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
    R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-09-17 6132576]
    R3 SiSGbeXP;SiS191/SiS190 Ethernet Device NDIS 5.1 Driver; C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys [2006-12-19 41600]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
    S3 usbscan;Usbscan; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-04 611664]
    R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-25 68865]
    R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-25 151297]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\Firewall\cmdagent.exe [2008-11-09 614136]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-17 163908]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-03 654848]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

    -----------------EOF-----------------

  4. #4
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default

    info.txt (sorry for the double post. the post is too long, it says)

    info.txt logfile of random's system information tool 1.04 2008-11-10 19:23:20

    ======Uninstall list======

    -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
    Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Add or Remove Adobe Creative Suite 3 Master Collection-->C:\Program Files\Common Files\Adobe\Installers\4dcfd9b7e901b57f81f667144603236\Setup.exe
    Adobe After Effects CS3 Presets-->MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}
    Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
    Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
    Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
    Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
    Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
    Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
    Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
    Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
    Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
    Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
    Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
    Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
    Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
    Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
    Adobe Creative Suite 3 Master Collection-->MsiExec.exe /I{8718DC03-D066-4957-94E5-50C3C5042E8E}
    Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
    Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
    Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
    Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
    Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
    Adobe Flash Player 9 Plugin-->MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
    Adobe Help Viewer CS3-->MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}
    Adobe InDesign CS3 Icon Handler-->MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
    Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
    Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
    Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
    Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
    Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
    Adobe Setup-->MsiExec.exe /I{4458C442-7376-4CF9-AF58-E8CEA6722363}
    Adobe SING CS3-->MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}
    Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
    Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
    Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
    Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
    Adobe Video Profiles-->MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
    Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
    Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
    Adobe XMP DVA Panels CS3-->MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
    Adobe XMP Panels CS3-->MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
    AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
    Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Documents and Settings\Vhaeraun\Desktop\ela\Uninstall\uninstall.xml"
    Ask Toolbar-->rundll32 C:\PROGRA~1\AskSBar\bar\1.bin\AskSBar.dll,O
    ASUSUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x9
    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
    BitComet 1.04-->C:\Program Files\BitComet\uninst.exe
    CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
    Chikka Messenger V4-->C:\PROGRA~1\CHIKKA~1\CHIKKA~1.4\UNWISE.EXE C:\PROGRA~1\CHIKKA~1\CHIKKA~1.4\INSTALL.LOG
    COMODO Firewall Pro-->C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
    COMODO SafeSurf-->C:\Program Files\COMODO\SafeSurf\cssconfg.exe -u
    DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
    EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall
    EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x9 UNINST
    EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x9 UNINST
    EPSON Printer Software-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
    EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
    EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
    EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x9 -anything
    ESCX2800_2900 User's Guide-->C:\Program Files\EPSON\TPMANUAL\ESCX2800_2900\USE_G\DOCUNINS.EXE
    ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
    ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
    ESScore-->MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
    ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
    ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
    ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
    ESSPDock-->MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
    ESSSONIC-->MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
    ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
    essvatgt-->MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
    fflink-->MsiExec.exe /I{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}
    Fraps (remove only)-->"C:\Fraps\uninstall.exe"
    Free Disc Burner version 1.1-->"C:\Program Files\DVDVideoSoft\Free Disc Burner\unins000.exe"
    Free DVD Video Burner version 1.1-->"C:\Program Files\DVDVideoSoft\Free DVD Video Burner\unins000.exe"
    Free Video to DVD Converter version 1.1-->"C:\Program Files\DVDVideoSoft\Free Video to DVD Converter\unins000.exe"
    Free YouTube Download 2.2-->"C:\Program Files\DVDVideoSoft\Free YouTube Download\unins000.exe"
    Hamachi 1.0.3.0-->C:\Program Files\Hamachi\uninstall.exe
    High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
    InterVideo DVDCopy5-->"C:\Program Files\InstallShield Installation Information\{C167A588-87AA-47BF-A88E-5B0F9A14480D}\setup.exe" --u:{C167A588-87AA-47BF-A88E-5B0F9A14480D}
    Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Java(TM) SE Development Kit 6 Update 7-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160070}
    kgcbaby-->MsiExec.exe /I{E18B549C-5D15-45DA-8D8F-8FD2BD946344}
    kgcbase-->MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
    kgchday-->MsiExec.exe /I{11F3F858-4131-4FFA-A560-3FE282933B6E}
    kgchlwn-->MsiExec.exe /I{03EDED24-8375-407D-A721-4643D9768BE1}
    kgcinvt-->MsiExec.exe /I{9BD54685-1496-46A5-AB62-357CD140ED8B}
    kgckids-->MsiExec.exe /I{693C08A7-9E76-43FF-B11E-9A58175474C4}
    kgcmove-->MsiExec.exe /I{A1588373-1D86-4D44-86C9-78ABD190F9CC}
    kgcvday-->MsiExec.exe /I{8A8664E1-84C8-4936-891C-BC1F07797549}
    Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_1e3074\Setup.exe /APR-REMOVE
    KSU-->MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    MELTY BLOOD Act Cadenza Ver.B WindowsӁ-->D:\Games\Melty Blood\MBACWIN\data\uninst.exe -f"D:\Games\Melty Blood\MBACWIN\data\uninst.dat"
    MetaProducts Download Express-->C:\Program Files\Download Express\dep.exe /UnInstall
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    netbrdg-->MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
    Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
    NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
    OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
    PC Probe II-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\setup.exe" -l0x9
    PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
    PIF DESIGNER-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x9 anything
    PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
    QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
    SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
    SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
    skin0001-->MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
    SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
    staticcr-->MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
    StepMania (remove only)-->"C:\Program Files\StepMania\uninstall.exe"
    Sun(TM) Download Manager 2.0-->C:\Program Files\SDM20\Uninstal.exe
    System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
    TBN Networks Media Player-->"C:\Documents and Settings\Vhaeraun\Desktop\ela\TBN\unins000.exe"
    tooltips-->MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
    Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
    VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
    Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
    Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
    Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
    Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
    WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
    WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
    Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
    Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
    Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
    Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
    Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

    =====HijackThis Backups=====

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
    O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL

    ======Hosts File======

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com

    ======Security center information======

    AV: Avira AntiVir PersonalEdition
    FW: COMODO Firewall

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
    "PROCESSOR_REVISION"=0f0d
    "NUMBER_OF_PROCESSORS"=2
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip

    -----------------EOF-----------------

  5. #5
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    IMPORTANT I notice there are signs of one or more P2P (Peer to Peer) File Sharing Programs on your computer.

    BitComet 1.04

    I'd like you to read the this thread.

    Please go to Control Panel > Add/Remove Programs and uninstall the programs listed above (in red).

    Uninstall also these:

    Ask Toolbar
    Comodo SafeSurf

    Delete info.txt from c:\rsit folder.

    Please run a new RSIT scan when finished and post the log back here.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #6
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default

    I've removed the rest but I can't remove ask toolbar via add/remove programs.

  7. #7
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    That is fine, just skip that one then
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #8
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default

    info.txt:

    info.txt logfile of random's system information tool 1.04 2008-11-10 23:35:40

    ======Uninstall list======

    -->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE
    -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
    7-Zip 4.57-->"C:\Program Files\7-Zip\Uninstall.exe"
    Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
    Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
    Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
    Add or Remove Adobe Creative Suite 3 Master Collection-->C:\Program Files\Common Files\Adobe\Installers\4dcfd9b7e901b57f81f667144603236\Setup.exe
    Adobe After Effects CS3 Presets-->MsiExec.exe /I{193EAFD0-1BAF-4FB4-B18F-79D5D6A4B285}
    Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
    Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
    Adobe Anchor Service CS3-->MsiExec.exe /I{90176341-0A8B-4CCC-A78D-F862228A6B95}
    Adobe Asset Services CS3-->MsiExec.exe /I{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}
    Adobe Bridge CS3-->MsiExec.exe /I{9C9824D9-9000-4373-A6A5-D0E5D4831394}
    Adobe Bridge Start Meeting-->MsiExec.exe /I{08B32819-6EEF-4057-AEDA-5AB681A36A23}
    Adobe BridgeTalk Plugin CS3-->MsiExec.exe /I{B73CFB12-C814-4638-AFFD-7E3AAFAF0B4E}
    Adobe Camera Raw 4.0-->MsiExec.exe /I{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}
    Adobe CMaps-->MsiExec.exe /I{A2B242BD-FF8D-4840-9DAA-9170EABEC59C}
    Adobe Color - Photoshop Specific-->MsiExec.exe /I{A2D81E70-2A98-4A08-A628-94388B063C5E}
    Adobe Color Common Settings-->MsiExec.exe /I{DADD7B8A-BCB0-44F5-967A-ECB6B4F2ECD9}
    Adobe Color EU Extra Settings-->MsiExec.exe /I{51846830-E7B2-4218-8968-B77F0FF475B8}
    Adobe Color JA Extra Settings-->MsiExec.exe /I{DD7DB3C5-6FA3-4FA3-8A71-C2F2940EB029}
    Adobe Color NA Recommended Settings-->MsiExec.exe /I{95655ED4-7CA5-46DF-907F-7144877A32E5}
    Adobe Creative Suite 3 Master Collection-->MsiExec.exe /I{8718DC03-D066-4957-94E5-50C3C5042E8E}
    Adobe Default Language CS3-->MsiExec.exe /I{B9B35331-B7E4-4E5C-BF4C-7BC87856124D}
    Adobe Device Central CS3-->MsiExec.exe /I{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}
    Adobe ExtendScript Toolkit 2-->MsiExec.exe /I{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}
    Adobe Extension Manager CS3-->MsiExec.exe /I{BE5F3842-8309-4754-92D5-83E02E6077A3}
    Adobe Flash Player 9 ActiveX-->MsiExec.exe /X{BC4F8E84-5E29-49EC-B4E7-E6F9CB50986C}
    Adobe Flash Player 9 Plugin-->MsiExec.exe /X{88D422DB-E9C7-4E16-9D80-2999F4FD6AD9}
    Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
    Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
    Adobe Fonts All-->MsiExec.exe /I{6ABE0BEE-D572-4FE8-B434-9E72A289431B}
    Adobe Help Viewer CS3-->MsiExec.exe /I{7ACFB90E-8FD0-4397-AD3A-5195412623A3}
    Adobe InDesign CS3 Icon Handler-->MsiExec.exe /I{EA7B3CC4-366D-4CF6-8350-FD7A7034116E}
    Adobe Linguistics CS3-->MsiExec.exe /I{54793AA1-5001-42F4-ABB6-C364617C6078}
    Adobe MotionPicture Color Files-->MsiExec.exe /I{6B708481-748A-4EB4-97C1-CD386244FF77}
    Adobe PDF Library Files-->MsiExec.exe /I{D2559B88-CC9D-4B48-81BB-F492BAA9C48C}
    Adobe Photoshop CS3-->MsiExec.exe /I{0046FA01-C5B9-4985-BACB-398DC480FC05}
    Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
    Adobe Setup-->MsiExec.exe /I{4458C442-7376-4CF9-AF58-E8CEA6722363}
    Adobe SING CS3-->MsiExec.exe /I{B671CBFD-4109-4D35-9252-3062D3CCB7B2}
    Adobe Stock Photos CS3-->MsiExec.exe /I{29E5EA97-5F74-4A57-B8B2-D4F169117183}
    Adobe Type Support-->MsiExec.exe /I{8E6808E2-613D-4FCD-81A2-6C8FA8E03312}
    Adobe Update Manager CS3-->MsiExec.exe /I{E69AE897-9E0B-485C-8552-7841F48D42D8}
    Adobe Version Cue CS3 Client-->MsiExec.exe /I{D0DFF92A-492E-4C40-B862-A74A173C25C5}
    Adobe Video Profiles-->MsiExec.exe /I{845A8DB9-8802-4FD3-9FE3-938A6C46A2EC}
    Adobe WAS CS3-->MsiExec.exe /I{C5BD220A-EFE8-48A5-B70E-9503D535FACE}
    Adobe WinSoft Linguistics Plugin-->MsiExec.exe /I{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}
    Adobe XMP DVA Panels CS3-->MsiExec.exe /I{0224CACC-994D-45F8-B973-D65056EA9C2F}
    Adobe XMP Panels CS3-->MsiExec.exe /I{D5A31AB1-345D-47C7-A87B-036A669F6DF1}
    AHV content for Acrobat and Flash-->MsiExec.exe /I{6BBAA81D-6A7E-43AD-8889-2F002DCAAFDD}
    Applian FLV Player-->"C:\WINDOWS\Applian FLV Player\uninstall.exe" "/U:C:\Documents and Settings\Vhaeraun\Desktop\ela\Uninstall\uninstall.xml"
    Ask Toolbar-->rundll32 C:\PROGRA~1\AskSBar\bar\1.bin\AskSBar.dll,O
    ASUSUpdate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{587178E7-B1DF-494E-9838-FA4DD36E873C}\setup.exe" -l0x9
    Avira AntiVir Personal - Free Antivirus-->C:\Program Files\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE
    CCScore-->MsiExec.exe /I{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}
    Chikka Messenger V4-->C:\PROGRA~1\CHIKKA~1\CHIKKA~1.4\UNWISE.EXE C:\PROGRA~1\CHIKKA~1\CHIKKA~1.4\INSTALL.LOG
    COMODO Firewall Pro-->C:\Program Files\COMODO\Firewall\cfpconfg.exe -u
    DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
    EPSON Attach To Email-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG
    EPSON Copy Utility 3-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x9 -UnInstall
    EPSON Easy Photo Print-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x9 UNINST
    EPSON File Manager-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x9 UNINST
    EPSON Printer Software-->C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R
    EPSON Scan Assistant-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x9 -u
    EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
    EPSON Web-To-Page-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x9 -anything
    ESCX2800_2900 User's Guide-->C:\Program Files\EPSON\TPMANUAL\ESCX2800_2900\USE_G\DOCUNINS.EXE
    ESSBrwr-->MsiExec.exe /I{643EAE81-920C-4931-9F0B-4B343B225CA6}
    ESSCDBK-->MsiExec.exe /I{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}
    ESScore-->MsiExec.exe /I{42938595-0D83-404D-9F73-F8177FDD531A}
    ESSgui-->MsiExec.exe /I{91517631-A9F3-4B7C-B482-43E0068FD55A}
    ESSini-->MsiExec.exe /I{8E92D746-CD9F-4B90-9668-42B74C14F765}
    ESSPCD-->MsiExec.exe /I{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}
    ESSPDock-->MsiExec.exe /I{FCDB1C92-03C6-4C76-8625-371224256091}
    ESSSONIC-->MsiExec.exe /I{073F22CE-9A5B-4A40-A604-C7270AC6BF34}
    ESSTOOLS-->MsiExec.exe /I{8A502E38-29C9-49FA-BCFA-D727CA062589}
    essvatgt-->MsiExec.exe /I{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}
    fflink-->MsiExec.exe /I{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}
    Fraps (remove only)-->"C:\Fraps\uninstall.exe"
    Free Disc Burner version 1.1-->"C:\Program Files\DVDVideoSoft\Free Disc Burner\unins000.exe"
    Free DVD Video Burner version 1.1-->"C:\Program Files\DVDVideoSoft\Free DVD Video Burner\unins000.exe"
    Free Video to DVD Converter version 1.1-->"C:\Program Files\DVDVideoSoft\Free Video to DVD Converter\unins000.exe"
    Free YouTube Download 2.2-->"C:\Program Files\DVDVideoSoft\Free YouTube Download\unins000.exe"
    Hamachi 1.0.3.0-->C:\Program Files\Hamachi\uninstall.exe
    High Definition Audio Driver Package - KB888111-->"C:\WINDOWS\$NtUninstallKB888111WXPSP2$\spuninst\spuninst.exe"
    HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
    Hotfix for Windows XP (KB915865)-->"C:\WINDOWS\$NtUninstallKB915865$\spuninst\spuninst.exe"
    InterVideo DVDCopy5-->"C:\Program Files\InstallShield Installation Information\{C167A588-87AA-47BF-A88E-5B0F9A14480D}\setup.exe" --u:{C167A588-87AA-47BF-A88E-5B0F9A14480D}
    Java DB 10.3.1.4-->MsiExec.exe /X{CD49361E-3FE6-457E-90A1-9C59E29B5D02}
    Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
    Java(TM) SE Development Kit 6 Update 7-->MsiExec.exe /I{32A3A4F4-B792-11D6-A78A-00B0D0160070}
    kgcbaby-->MsiExec.exe /I{E18B549C-5D15-45DA-8D8F-8FD2BD946344}
    kgcbase-->MsiExec.exe /I{F22C222C-3CE2-4A4B-A83F-AF4681371ABE}
    kgchday-->MsiExec.exe /I{11F3F858-4131-4FFA-A560-3FE282933B6E}
    kgchlwn-->MsiExec.exe /I{03EDED24-8375-407D-A721-4643D9768BE1}
    kgcinvt-->MsiExec.exe /I{9BD54685-1496-46A5-AB62-357CD140ED8B}
    kgckids-->MsiExec.exe /I{693C08A7-9E76-43FF-B11E-9A58175474C4}
    kgcmove-->MsiExec.exe /I{A1588373-1D86-4D44-86C9-78ABD190F9CC}
    kgcvday-->MsiExec.exe /I{8A8664E1-84C8-4936-891C-BC1F07797549}
    Kodak EasyShare software-->C:\Documents and Settings\All Users\Application Data\Kodak\EasyShareSetup\$SETUP_140002_1e3074\Setup.exe /APR-REMOVE
    KSU-->MsiExec.exe /I{B997C2A0-4383-41BF-B76E-9B8B7ECFB267}
    Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
    MELTY BLOOD Act Cadenza Ver.B WindowsӁ-->D:\Games\Melty Blood\MBACWIN\data\uninst.exe -f"D:\Games\Melty Blood\MBACWIN\data\uninst.dat"
    MetaProducts Download Express-->C:\Program Files\Download Express\dep.exe /UnInstall
    Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe"
    Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe"
    Microsoft Office Professional Edition 2003-->MsiExec.exe /I{90110409-6000-11D3-8CFE-0150048383C9}
    Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
    Mozilla Firefox (3.0.3)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
    netbrdg-->MsiExec.exe /I{4537EA4B-F603-4181-89FB-2953FC695AB1}
    Notifier-->MsiExec.exe /I{0008546E-DF6E-4CC1-AFD0-2CB8E16C95A2}
    NVIDIA Drivers-->C:\WINDOWS\system32\nvuninst.exe UninstallGUI
    OfotoXMI-->MsiExec.exe /I{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}
    PC Probe II-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F7338FA3-DAB5-49B2-900D-0AFB5760C166}\setup.exe" -l0x9
    PDF Settings-->MsiExec.exe /I{AC5B0C19-D851-42F4-BDA0-410ECF7F70A5}
    PIF DESIGNER-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x9 anything
    PowerISO-->"C:\Program Files\PowerISO\uninstall.exe"
    QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}
    Realtek High Definition Audio Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x9 -removeonly
    SFR-->MsiExec.exe /I{DB02F716-6275-42E9-B8D2-83BA2BF5100B}
    SHASTA-->MsiExec.exe /I{605A4E39-613C-4A12-B56F-DEFBE6757237}
    skin0001-->MsiExec.exe /I{5316DFC9-CE99-4458-9AB3-E8726EDE0210}
    SKINXSDK-->MsiExec.exe /I{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}
    Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
    SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
    staticcr-->MsiExec.exe /I{8943CE61-53BD-475E-90E1-A580869E98A2}
    StepMania (remove only)-->"C:\Program Files\StepMania\uninstall.exe"
    Sun(TM) Download Manager 2.0-->C:\Program Files\SDM20\Uninstal.exe
    System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
    TBN Networks Media Player-->"C:\Documents and Settings\Vhaeraun\Desktop\ela\TBN\unins000.exe"
    tooltips-->MsiExec.exe /I{E79987F0-0E34-42CC-B8FF-6C860AEEB26A}
    Uninstall 1.0.0.1-->"C:\Program Files\Common Files\DVDVideoSoft\unins000.exe"
    VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
    VPRINTOL-->MsiExec.exe /I{999D43F4-9709-4887-9B1A-83EBB15A8370}
    Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
    Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe"
    Windows Internet Explorer 7-->"C:\WINDOWS\ie7\spuninst\spuninst.exe"
    Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
    WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
    WinZip-->"C:\Program Files\WinZip\WINZIP32.EXE" /uninstall
    WIRELESS-->MsiExec.exe /I{F9593CFB-D836-49BC-BFF1-0E669A411D9F}
    Xvid 1.1.3 final uninstall-->"C:\Program Files\Xvid\unins000.exe"
    Yahoo! Browser Services-->C:\PROGRA~1\Yahoo!\Common\UNIN_Y~1.EXE /S
    Yahoo! Install Manager-->C:\WINDOWS\system32\regsvr32 /u C:\PROGRA~1\Yahoo!\Common\YINSTH~1.DLL
    Yahoo! Internet Mail-->C:\WINDOWS\system32\regsvr32 /u /s C:\PROGRA~1\Yahoo!\Common\YMMAPI.dll
    Yahoo! Messenger-->C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG
    Yahoo! Toolbar-->C:\PROGRA~1\Yahoo!\Common\UNYT_W~1.EXE

    =====HijackThis Backups=====

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL
    O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLL

    ======Hosts File======

    127.0.0.1 www.007guard.com
    127.0.0.1 007guard.com
    127.0.0.1 008i.com
    127.0.0.1 www.008k.com
    127.0.0.1 008k.com
    127.0.0.1 www.00hq.com
    127.0.0.1 00hq.com
    127.0.0.1 010402.com
    127.0.0.1 www.032439.com
    127.0.0.1 032439.com

    ======Security center information======

    AV: Avira AntiVir PersonalEdition
    FW: COMODO Firewall

    ======Environment variables======

    "ComSpec"=%SystemRoot%\system32\cmd.exe
    "Path"=%systemroot%\system32;%systemroot%;%systemroot%\system32\wbem;C:\Program Files\QuickTime\QTSystem
    "windir"=%SystemRoot%
    "FP_NO_HOST_CHECK"=NO
    "OS"=Windows_NT
    "PROCESSOR_ARCHITECTURE"=x86
    "PROCESSOR_LEVEL"=6
    "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 15 Stepping 13, GenuineIntel
    "PROCESSOR_REVISION"=0f0d
    "NUMBER_OF_PROCESSORS"=2
    "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
    "TEMP"=%SystemRoot%\TEMP
    "TMP"=%SystemRoot%\TEMP
    "CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip
    "QTJAVA"=C:\Program Files\Java\jre1.6.0_06\lib\ext\QTJava.zip

    -----------------EOF-----------------

  9. #9
    Junior Member
    Join Date
    Oct 2008
    Posts
    23

    Default

    log.txt:

    Logfile of random's system information tool 1.04 (written by random/random)
    Run by Vhaeraun at 2008-11-10 23:35:34
    Microsoft Windows XP Professional Service Pack 2
    System drive C: has 42 GB (70%) free of 60 GB
    Total RAM: 2047 MB (71% free)

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 11:35:39 PM, on 11/10/2008
    Platform: Windows XP SP2 (WinNT 5.01.2600)
    MSIE: Internet Explorer v7.00 (7.00.5730.0013)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\RTHDCPL.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    C:\Program Files\PowerISO\PWRISOVM.EXE
    C:\WINDOWS\system32\RUNDLL32.EXE
    C:\Program Files\Winamp\winampa.exe
    C:\Program Files\COMODO\SafeSurf\cssurf.exe
    C:\Program Files\COMODO\Firewall\cfp.exe
    C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\FRAPS\FRAPS.EXE
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    C:\Program Files\Bonjour\mDNSResponder.exe
    C:\Program Files\COMODO\Firewall\cmdagent.exe
    C:\WINDOWS\system32\nvsvc32.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\Yahoo!\MESSEN~1\YAHOOM~1.EXE
    C:\WINDOWS\system32\wuauclt.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Vhaeraun\Desktop\RSIT.exe
    C:\Program Files\Trend Micro\HijackThis\Vhaeraun.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.zyxel.com/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O2 - BHO: (no name) - {0808798f-a2a0-4c79-8fe7-efeb2f487cba} - (no file)
    O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O2 - BHO: (no name) - {67C5CBB2-6E04-495B-838D-EF85E50B04E8} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: (no name) - {D1974D4D-77D7-4EEB-A76A-1EFFFC19C825} - (no file)
    O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
    O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll
    O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
    O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE
    O4 - HKLM\..\Run: [AsusStartupHelp] C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    O4 - HKLM\..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE
    O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
    O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [COMODO Firewall Pro] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\Firewall\cfp.exe" -h
    O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
    O4 - HKCU\..\Run: [DownloadAccelerator] "C:\Program Files\DAP\DAP.EXE" /STARTUP
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - HKCU\..\Run: [Fraps] C:\FRAPS\FRAPS.EXE
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: + &Download Express: download this file - C:\Program Files\Download Express\Add_Url.htm
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/Driver...sysreqlab3.cab
    O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
    O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://go.divx.com/plugin/DivXBrowserPlugin.cab
    O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} (Java Plug-in 1.6.0_06) -
    O20 - Winlogon Notify: awttqrPj - C:\WINDOWS\
    O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
    O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:\Program Files\COMODO\Firewall\cmdagent.exe
    O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

    --
    End of file - 8080 bytes

    ======Scheduled tasks folder======

    C:\WINDOWS\tasks\EasyShare Registration Task.job

    ======Registry dump======

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
    &Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0808798f-a2a0-4c79-8fe7-efeb2f487cba}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
    Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
    Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
    Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2007-12-12 222448]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{67C5CBB2-6E04-495B-838D-EF85E50B04E8}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
    SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D1974D4D-77D7-4EEB-A76A-1EFFFC19C825}]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E99421FB-68DD-40F0-B4AC-B7027CAE2F1A}]
    EpsonToolBandKicker Class - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
    {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2008-05-15 817936]
    {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - EPSON Web-To-Page - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll [2005-02-22 368640]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
    "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2007-02-25 16125440]
    "SkyTel"=C:\WINDOWS\SkyTel.EXE [2006-05-16 2879488]
    "AsusStartupHelp"=C:\Program Files\ASUS\AASP\1.00.17\AsRunHelp.exe [2006-11-13 363008]
    "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-09-17 13574144]
    "nwiz"=nwiz.exe /install []
    "avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
    "PWRISOVM.EXE"=C:\Program Files\PowerISO\PWRISOVM.EXE [2008-07-06 167936]
    "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-09-17 86016]
    "WinampAgent"=C:\Program Files\Winamp\winampa.exe [2008-07-09 36352]
    "QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-09-01 282624]
    "COMODO Firewall Pro"=C:\Program Files\COMODO\Firewall\cfp.exe [2008-10-31 1797880]
    "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
    "SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
    "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k []
    "COMODO Internet Security"=C:\Program Files\COMODO\Firewall\cfp.exe [2008-10-31 1797880]

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
    "Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2008-09-19 4347120]
    "DownloadAccelerator"=C:\Program Files\DAP\DAP.EXE /STARTUP []
    "SpybotSD TeaTimer"=C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
    "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-03 15360]
    "Fraps"=C:\FRAPS\FRAPS.EXE [2008-09-10 3305128]

    C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    InterVideo WinCinema Manager.lnk - C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\awttqrPj]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]

    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
    "dontdisplaylastusername"=0
    "legalnoticecaption"=
    "legalnoticetext"=
    "shutdownwithoutlogon"=1
    "undockwithoutlogon"=1

    [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDrives"=0

    [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
    "NoDriveTypeAutoRun"=
    "NoDrives"=
    "NoDriveAutoRun"=

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
    "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
    "C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
    "D:\Games\Melty Blood\MBACWIN\mbcaster.exe"="D:\Games\Melty Blood\MBACWIN\mbcaster.exe:*:Enabled:mbcaster"
    "C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
    "C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe"="C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe:*:Disabled:Kodak Software Updater"
    "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe"="C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare"

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
    "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{0e23d757-8f61-11dd-b9f4-001bfce397fe}]
    shell\AutoRun\command - G:\LaunchU3.exe


    ======List of files/folders created in the last 3 months======

    2008-11-10 19:23:11 ----D---- C:\rsit
    2008-11-03 22:52:29 ----A---- C:\DTSHDSpOut.txt
    2008-11-02 11:24:30 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\EPSON
    2008-10-30 22:22:39 ----D---- C:\Program Files\Common Files\SWF Studio
    2008-10-26 20:42:19 ----D---- C:\Program Files\StepMania
    2008-10-26 01:29:34 ----D---- C:\Program Files\Download Express
    2008-10-26 01:29:34 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\MetaProducts
    2008-10-23 21:21:29 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Apple Computer
    2008-10-22 22:09:03 ----D---- C:\DVDVideoSoft
    2008-10-22 22:08:34 ----D---- C:\Program Files\DVDVideoSoft
    2008-10-22 22:08:34 ----D---- C:\Program Files\Common Files\DVDVideoSoft
    2008-10-22 22:08:34 ----A---- C:\WINDOWS\system32\msvcr70.dll
    2008-10-22 21:47:25 ----D---- C:\WINDOWS\Applian FLV Player
    2008-10-22 21:45:27 ----A---- C:\WINDOWS\Applian FLV Player Setup Log.txt
    2008-10-19 13:07:20 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Mozilla
    2008-10-10 12:01:06 ----HD---- C:\WINDOWS\msdownld.tmp
    2008-10-10 12:00:55 ----D---- C:\WINDOWS\WBEM
    2008-10-10 12:00:54 ----D---- C:\WINDOWS\system32\en-US
    2008-10-10 11:59:46 ----HDC---- C:\WINDOWS\ie7
    2008-10-10 11:59:27 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$
    2008-10-10 11:59:08 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$
    2008-10-10 11:58:39 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$
    2008-10-10 11:58:39 ----HD---- C:\WINDOWS\$hf_mig$
    2008-10-10 11:58:37 ----N---- C:\WINDOWS\system32\xmllite.dll
    2008-10-10 11:54:30 ----D---- C:\Program Files\DivX
    2008-10-10 11:54:30 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\DivX
    2008-10-09 19:08:52 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\dvdcss
    2008-10-09 08:03:46 ----D---- C:\logs
    2008-10-09 08:03:37 ----D---- C:\Program Files\Chikka Messenger
    2008-10-07 18:45:07 ----A---- C:\WINDOWS\system32\xvidcore.dll
    2008-10-07 18:45:06 ----D---- C:\Program Files\Xvid
    2008-10-07 18:45:06 ----A---- C:\WINDOWS\system32\xvidvfw.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbdkor.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbdjpn.dll
    2008-10-07 14:16:55 ----A---- C:\WINDOWS\system32\kbd106.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd103.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd101c.dll
    2008-10-07 14:16:54 ----A---- C:\WINDOWS\system32\kbd101b.dll
    2008-10-07 01:15:05 ----D---- C:\WINDOWS\Sun
    2008-10-06 23:39:42 ----D---- C:\ComboFix
    2008-10-06 21:00:04 ----D---- C:\Program Files\Sun
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\javaws.exe
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\javaw.exe
    2008-10-06 21:00:00 ----A---- C:\WINDOWS\system32\java.exe
    2008-10-06 20:57:53 ----D---- C:\Program Files\Common Files\Java
    2008-10-06 20:36:06 ----D---- C:\Program Files\SDM20
    2008-10-06 20:03:43 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Sun
    2008-10-06 20:03:06 ----D---- C:\WINDOWS\system32\appmgmt
    2008-10-06 19:57:31 ----SHD---- C:\RECYCLER
    2008-10-06 19:52:24 ----D---- C:\Program Files\Common Files\Adobe AIR
    2008-10-06 15:23:04 ----D---- C:\WINDOWS\temp
    2008-10-04 20:43:38 ----D---- C:\Program Files\SpywareBlaster
    2008-10-04 20:37:00 ----A---- C:\WINDOWS\system32\cssdll32.dll
    2008-10-04 20:36:17 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Comodo
    2008-10-04 20:36:16 ----D---- C:\Documents and Settings\All Users\Application Data\comodo
    2008-10-04 20:36:16 ----A---- C:\WINDOWS\system32\guard32.dll
    2008-10-04 20:36:15 ----D---- C:\Program Files\COMODO
    2008-10-04 18:24:19 ----A---- C:\WINDOWS\wininit.ini
    2008-10-04 13:43:46 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
    2008-10-04 13:43:37 ----D---- C:\WINDOWS\system32\DRVSTORE
    2008-10-04 13:43:33 ----D---- C:\Program Files\Common Files\Kodak
    2008-10-04 13:43:20 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
    2008-10-04 13:41:09 ----D---- C:\Config.Msi
    2008-10-04 13:30:18 ----A---- C:\VundoFix.txt
    2008-10-04 12:50:55 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Malwarebytes
    2008-10-04 12:50:53 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
    2008-10-04 12:50:53 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
    2008-10-04 12:29:02 ----D---- C:\Program Files\Trend Micro
    2008-10-04 12:08:14 ----D---- C:\WINDOWS\erdnt
    2008-10-04 11:03:48 ----D---- C:\Program Files\Spybot - Search & Destroy
    2008-10-04 11:03:48 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2008-10-04 10:59:53 ----D---- C:\Program Files\Lavasoft
    2008-10-04 10:59:53 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
    2008-10-03 19:36:24 ----D---- C:\Program Files\QuickTime
    2008-10-03 19:36:09 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer
    2008-10-03 19:35:27 ----D---- C:\WINDOWS\system32\BWKDLogs
    2008-10-03 19:34:54 ----A---- C:\WINDOWS\system32\ptpusb.dll
    2008-10-03 19:34:53 ----A---- C:\WINDOWS\system32\ptpusd.dll
    2008-10-03 19:30:44 ----D---- C:\Program Files\Kodak
    2008-10-03 19:26:35 ----D---- C:\Documents and Settings\All Users\Application Data\Kodak
    2008-10-03 14:27:40 ----SHD---- C:\found.000
    2008-10-03 14:23:09 ----A---- C:\WINDOWS\system32\NPSWF32_FlashUtil.exe
    2008-10-03 14:23:09 ----A---- C:\WINDOWS\system32\NPSWF32.dll
    2008-10-03 14:14:06 ----D---- C:\Program Files\Bonjour
    2008-10-03 14:09:09 ----D---- C:\Program Files\Common Files\Macrovision Shared
    2008-10-03 14:06:16 ----N---- C:\WINDOWS\system32\spmsg.dll
    2008-10-03 14:06:05 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$
    2008-10-02 16:37:52 ----D---- C:\Documents and Settings\All Users\Application Data\SpeedBit
    2008-10-02 16:37:47 ----D---- C:\Program Files\DAP
    2008-10-01 22:53:05 ----A---- C:\WINDOWS\system32\bb75a282-.txt
    2008-10-01 22:38:59 ----D---- C:\WINDOWS\Minidump
    2008-10-01 22:13:43 ----D---- C:\WINDOWS\NV21602468.TMP
    2008-10-01 22:13:31 ----D---- C:\WINDOWS\system32\ReinstallBackups
    2008-10-01 21:32:36 ----D---- C:\Virtual dub
    2008-10-01 21:08:13 ----D---- C:\NVIDIA
    2008-10-01 20:45:44 ----D---- C:\Program Files\SystemRequirementsLab
    2008-10-01 08:04:56 ----A---- C:\WINDOWS\system32\wmpns.dll
    2008-10-01 07:38:27 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\vlc
    2008-10-01 07:30:43 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\WinRAR
    2008-10-01 07:28:07 ----D---- C:\Program Files\WinRAR
    2008-10-01 07:20:59 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
    2008-10-01 07:20:56 ----D---- C:\Fraps
    2008-10-01 07:19:38 ----D---- C:\Program Files\7-Zip
    2008-09-30 23:21:19 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Hamachi
    2008-09-30 23:21:00 ----D---- C:\Program Files\Hamachi
    2008-09-30 23:13:46 ----D---- C:\Program Files\Java
    2008-09-30 23:11:16 ----D---- C:\Program Files\Mozilla Firefox
    2008-09-30 23:06:55 ----A---- C:\WINDOWS\ODBC.INI
    2008-09-30 23:06:41 ----D---- C:\Program Files\Microsoft ActiveSync
    2008-09-30 23:06:39 ----D---- C:\Program Files\Common Files\DESIGNER
    2008-09-30 23:06:33 ----D---- C:\WINDOWS\SHELLNEW
    2008-09-30 23:06:32 ----D---- C:\Program Files\Microsoft Office
    2008-09-30 21:49:42 ----RD---- C:\WINDOWS\AsDmiHtm
    2008-09-30 20:05:08 ----D---- C:\Downloads
    2008-09-30 19:34:31 ----D---- C:\Program Files\BitComet
    2008-09-30 19:33:19 ----D---- C:\Program Files\PowerISO
    2008-09-30 19:29:43 ----D---- C:\Documents and Settings\All Users\Application Data\UDL
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK2.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK.ini
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICSDK.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\PICEntry.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\EpPicPrt.dll
    2008-09-30 19:29:18 ----A---- C:\WINDOWS\system32\EPPicMgr.dll
    2008-09-30 19:28:53 ----A---- C:\WINDOWS\system32\E_DCINST.DLL
    2008-09-30 19:28:52 ----A---- C:\WINDOWS\system32\E_FLBBFP.DLL
    2008-09-30 19:28:52 ----A---- C:\WINDOWS\system32\E_FD4BBFP.DLL
    2008-09-30 19:00:35 ----D---- C:\WINDOWS\RegisteredPackages
    2008-09-30 18:58:48 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Yahoo!
    2008-09-30 18:58:48 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxsfs.dll
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxinsa64.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxhpinst.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxdrv.dll
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxcpya64.exe
    2008-09-30 18:58:31 ----A---- C:\WINDOWS\system32\pxafs.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\pxwave.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\pxmas.dll
    2008-09-30 18:58:30 ----A---- C:\WINDOWS\system32\px.dll
    2008-09-30 18:58:25 ----D---- C:\Program Files\Winamp
    2008-09-30 18:58:25 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Winamp
    2008-09-30 18:57:34 ----D---- C:\Program Files\VideoLAN
    2008-09-30 18:48:14 ----D---- C:\Documents and Settings\All Users\Application Data\Yahoo!
    2008-09-30 18:47:12 ----A---- C:\YServer.txt
    2008-09-30 18:47:05 ----D---- C:\Program Files\Yahoo!
    2008-09-30 18:45:09 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Macromedia
    2008-09-30 18:45:09 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Adobe
    2008-09-30 18:43:29 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
    2008-09-30 18:43:25 ----D---- C:\Program Files\Common Files\Adobe
    2008-09-30 18:43:25 ----D---- C:\Program Files\Adobe
    2008-09-30 18:41:25 ----D---- C:\Documents and Settings\All Users\Application Data\WinZip
    2008-09-30 18:41:20 ----D---- C:\Program Files\WinZip
    2008-09-30 18:33:18 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\U3
    2008-09-30 18:31:25 ----D---- C:\Program Files\Avira
    2008-09-30 18:31:25 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
    2008-09-30 13:48:29 ----D---- C:\WINDOWS\system32\Lang
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSTPLOG.TXT
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSTPLOG.BAK
    2008-09-30 13:39:25 ----A---- C:\WINDOWS\EPSMTL32.TXT
    2008-09-30 13:39:18 ----D---- C:\Program Files\epson
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\escwiad.dll
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\escimgd.dll
    2008-09-30 13:39:18 ----A---- C:\WINDOWS\system32\esccmd.dll
    2008-09-30 13:39:11 ----A---- C:\WINDOWS\CDE CX2900EC.ini
    2008-09-30 13:38:47 ----A---- C:\WINDOWS\epsswt_log.txt
    2008-09-30 13:37:03 ----D---- C:\WINDOWS\nview
    2008-09-30 13:37:02 ----A---- C:\WINDOWS\system32\nvudisp.exe
    2008-09-30 13:36:12 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
    2008-09-30 13:23:00 ----D---- C:\Program Files\InterVideo
    2008-09-30 13:19:34 ----RA---- C:\WINDOWS\system32\AsIO.dll
    2008-09-30 13:19:32 ----D---- C:\Program Files\ASUS
    2008-09-30 13:19:03 ----RA---- C:\WINDOWS\system32\ChCfg.exe
    2008-09-30 13:18:47 ----D---- C:\WINDOWS\system32\RTCOM
    2008-09-30 13:18:45 ----A---- C:\WINDOWS\system32\ksuser.dll
    2008-09-30 13:18:21 ----A---- C:\WINDOWS\system32\spupdsvc.exe
    2008-09-30 13:18:20 ----HDC---- C:\WINDOWS\$NtUninstallKB888111WXPSP2$
    2008-09-30 13:18:17 ----R---- C:\WINDOWS\SoundMan.exe
    2008-09-30 13:18:16 ----R---- C:\WINDOWS\SkyTel.exe
    2008-09-30 13:18:15 ----R---- C:\WINDOWS\RtlUpd.exe
    2008-09-30 13:18:12 ----R---- C:\WINDOWS\RTLCPL.exe
    2008-09-30 13:18:06 ----R---- C:\WINDOWS\RTHDCPL.exe
    2008-09-30 13:18:05 ----R---- C:\WINDOWS\MicCal.exe
    2008-09-30 13:18:03 ----R---- C:\WINDOWS\alcwzrd.exe
    2008-09-30 13:18:03 ----R---- C:\WINDOWS\Alcmtr.exe
    2008-09-30 13:18:02 ----D---- C:\Program Files\Realtek
    2008-09-30 13:18:01 ----HD---- C:\Program Files\InstallShield Installation Information
    2008-09-30 13:17:59 ----A---- C:\WINDOWS\HideWin.exe
    2008-09-30 13:17:58 ----R---- C:\WINDOWS\RtlExUpd.dll
    2008-09-30 13:17:55 ----D---- C:\Program Files\Common Files\InstallShield
    2008-09-30 13:17:27 ----A---- C:\WINDOWS\Ascd_log.ini
    2008-09-30 13:09:50 ----A---- C:\WINDOWS\Ascd_tmp.ini
    2008-09-30 13:09:47 ----A---- C:\WINDOWS\AS_Debug.txt
    2008-09-30 13:08:00 ----D---- C:\Documents and Settings\Vhaeraun\Application Data\Identities
    2008-09-30 13:07:59 ----HD---- C:\Program Files\Uninstall Information
    2008-09-30 13:07:54 ----SD---- C:\Documents and Settings\Vhaeraun\Application Data\Microsoft
    2008-09-30 13:07:54 ----ASH---- C:\Documents and Settings\Vhaeraun\Application Data\desktop.ini
    2008-09-30 13:07:01 ----D---- C:\WINDOWS\SoftwareDistribution
    2008-09-30 13:07:00 ----SD---- C:\WINDOWS\system32\Microsoft
    2008-09-30 13:07:00 ----D---- C:\WINDOWS\Prefetch
    2008-09-30 13:07:00 ----A---- C:\WINDOWS\SchedLgU.Txt
    2008-09-30 13:04:00 ----D---- C:\WINDOWS\system32\xircom
    2008-09-30 13:04:00 ----D---- C:\Program Files\xerox
    2008-09-30 13:04:00 ----D---- C:\Program Files\microsoft frontpage
    2008-09-30 13:03:48 ----A---- C:\WINDOWS\control.ini
    2008-09-30 13:03:48 ----A---- C:\AUTOEXEC.BAT
    2008-09-30 13:03:41 ----A---- C:\WINDOWS\OEWABLog.txt
    2008-09-30 13:03:38 ----A---- C:\WINDOWS\system32\mapi32.dll
    2008-09-30 13:03:00 ----SD---- C:\WINDOWS\Downloaded Program Files
    2008-09-30 13:03:00 ----RD---- C:\WINDOWS\Offline Web Pages
    2008-09-30 13:03:00 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
    2008-09-30 13:02:56 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
    2008-09-30 13:02:52 ----HD---- C:\Program Files\WindowsUpdate
    2008-09-30 13:02:36 ----D---- C:\WINDOWS\system32\DirectX
    2008-09-30 13:02:18 ----A---- C:\WINDOWS\system32\atrace.dll
    2008-09-30 13:02:16 ----A---- C:\WINDOWS\system32\desktop.ini
    2008-09-30 13:02:16 ----A---- C:\WINDOWS\desktop.ini
    2008-09-30 13:02:09 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
    2008-09-30 13:02:07 ----D---- C:\Program Files\Common Files\Services
    2008-09-30 13:02:07 ----A---- C:\WINDOWS\system32\acctres.dll
    2008-09-30 13:02:04 ----SD---- C:\WINDOWS\Tasks
    2008-09-30 13:02:04 ----A---- C:\WINDOWS\system32\icfgnt5.dll
    2008-09-30 13:02:03 ----D---- C:\Program Files\Common Files\MSSoap
    2008-09-30 13:02:00 ----D---- C:\WINDOWS\srchasst
    2008-09-30 13:01:59 ----D---- C:\WINDOWS\system32\Macromed
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuweb.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wucltui.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuauserv.dll
    2008-09-30 13:01:57 ----A---- C:\WINDOWS\system32\wuaueng1.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wups.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuaueng.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuauclt1.exe
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuauclt.exe
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\wuapi.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\qmgr.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\bitsprx3.dll
    2008-09-30 13:01:56 ----A---- C:\WINDOWS\system32\bitsprx2.dll
    2008-09-30 13:01:53 ----D---- C:\Program Files\Movie Maker
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrslv.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrdm.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\safrcdlg.dll
    2008-09-30 13:01:48 ----A---- C:\WINDOWS\system32\racpldlg.dll
    2008-09-30 13:01:46 ----A---- C:\WINDOWS\system32\fltMc.exe
    2008-09-30 13:01:46 ----A---- C:\WINDOWS\system32\fltlib.dll
    2008-09-30 13:01:45 ----D---- C:\WINDOWS\system32\Restore
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srsvc.dll
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srrstr.dll
    2008-09-30 13:01:45 ----A---- C:\WINDOWS\system32\srclient.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\nmmkcert.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\msconf.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\mnmdd.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\isrdbg32.dll
    2008-09-30 13:01:44 ----A---- C:\WINDOWS\system32\ils.dll
    2008-09-30 13:01:41 ----D---- C:\Program Files\NetMeeting
    2008-09-30 13:01:41 ----A---- C:\WINDOWS\system32\msoert2.dll
    2008-09-30 13:01:41 ----A---- C:\WINDOWS\system32\msoeacct.dll
    2008-09-30 13:01:40 ----A---- C:\WINDOWS\system32\inetres.dll
    2008-09-30 13:01:40 ----A---- C:\WINDOWS\system32\inetcomm.dll
    2008-09-30 13:01:39 ----D---- C:\Program Files\Outlook Express
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\schedsvc.dll
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\mstinit.exe
    2008-09-30 13:01:39 ----A---- C:\WINDOWS\system32\mstask.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\isign32.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\inetcfg.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\icwphbk.dll
    2008-09-30 13:01:38 ----A---- C:\WINDOWS\system32\icwdial.dll
    2008-09-30 13:01:33 ----D---- C:\Program Files\Common Files\System
    2008-09-30 13:01:28 ----D---- C:\Program Files\Internet Explorer
    2008-09-30 13:01:01 ----D---- C:\WINDOWS\Registration
    2008-09-30 12:02:55 ----D---- C:\Program Files\ComPlus Applications
    2008-09-30 12:02:53 ----A---- C:\WINDOWS\vbaddin.ini
    2008-09-30 12:02:53 ----A---- C:\WINDOWS\vb.ini
    2008-09-30 12:02:44 ----D---- C:\Program Files\Windows Media Player
    2008-09-30 12:02:44 ----D---- C:\Program Files\Online Services
    2008-09-30 12:02:39 ----D---- C:\Program Files\Messenger
    2008-09-30 12:02:36 ----D---- C:\Program Files\MSN Gaming Zone
    2008-09-30 12:02:36 ----A---- C:\WINDOWS\system32\write.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\winchat.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\sndvol32.exe
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\hticons.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avwav.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avtapi.dll
    2008-09-30 12:02:30 ----A---- C:\WINDOWS\system32\avmeter.dll
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\winmine.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\sol.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\getuname.dll
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\charmap.exe
    2008-09-30 12:02:25 ----A---- C:\WINDOWS\system32\calc.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\usrlogon.cmd
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tsshutdn.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tslabels.ini
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tskill.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tsdiscon.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\tscon.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\shadow.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\rwinsta.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\reset.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\regini.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\qwinsta.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\qappsrv.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\mshearts.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\msg.exe
    2008-09-30 12:02:24 ----A---- C:\WINDOWS\system32\freecell.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxlegih.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxex.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\mtxdm.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\msdtcprf.ini
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\logoff.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\comrepl.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\comaddin.dll
    2008-09-30 12:02:23 ----A---- C:\WINDOWS\system32\cdmodem.dll
    2008-09-30 12:02:22 ----A---- C:\WINDOWS\system32\stclient.dll
    2008-09-30 12:02:22 ----A---- C:\WINDOWS\system32\comsnap.dll
    2008-09-30 12:02:19 ----A---- C:\WINDOWS\system32\wmimgmt.msc
    2008-09-30 12:02:11 ----D---- C:\Program Files\MSN
    2008-09-30 12:02:10 ----D---- C:\Program Files\Windows NT
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\sndrec32.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\mspaint.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\mplay32.exe
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\hypertrm.dll
    2008-09-30 12:02:10 ----A---- C:\WINDOWS\system32\accwiz.exe
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\spider.exe
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\mstscax.dll
    2008-09-30 12:02:09 ----A---- C:\WINDOWS\system32\clipbrd.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\tscupgrd.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\termsrv.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\sessmgr.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\remotepg.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdshost.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdsaddin.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpwsx.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpsnd.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdpclip.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\rdchost.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\qprocess.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\mstsc.exe
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\icaapi.dll
    2008-09-30 12:02:08 ----A---- C:\WINDOWS\system32\cfgbkend.dll
    2008-09-30 12:02:07 ----D---- C:\WINDOWS\system32\MsDtc
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\xolehlp.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\mtxoci.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtctm.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtcprx.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtclog.dll
    2008-09-30 12:02:07 ----A---- C:\WINDOWS\system32\msdtc.exe
    2008-09-30 12:02:06 ----D---- C:\WINDOWS\system32\Com
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\comsvcs.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\colbact.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\clbcatex.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrvut.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrvps.dll
    2008-09-30 12:02:06 ----A---- C:\WINDOWS\system32\catsrv.dll
    2008-09-30 12:02:05 ----A---- C:\WINDOWS\system32\comuid.dll
    2008-09-30 12:02:05 ----A---- C:\WINDOWS\system32\clbcatq.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\servdeps.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\mmfutil.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\licwmi.dll
    2008-09-30 12:02:01 ----A---- C:\WINDOWS\system32\cmprops.dll
    2008-09-30 05:55:54 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
    2008-09-30 05:55:50 ----RA---- C:\WINDOWS\SET2B.tmp
    2008-09-30 05:55:48 ----RA---- C:\WINDOWS\SET1F.tmp
    2008-09-30 05:55:47 ----RA---- C:\WINDOWS\SET1C.tmp
    2008-09-30 05:55:29 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
    2008-09-30 05:00:45 ----A---- C:\WINDOWS\system32\h323log.txt
    2008-09-30 04:58:21 ----A---- C:\WINDOWS\system32\mdmxsdk.dll
    2008-09-30 04:58:21 ----A---- C:\WINDOWS\system32\HSFCISP2.dll
    2008-09-30 04:58:06 ----A---- C:\WINDOWS\system32\usbui.dll
    2008-09-30 04:57:23 ----A---- C:\WINDOWS\imsins.BAK
    2008-09-30 04:57:21 ----SHD---- C:\WINDOWS\Installer
    2008-09-30 04:57:21 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
    2008-09-30 04:57:20 ----D---- C:\Program Files\Common Files\ODBC
    2008-09-30 04:57:20 ----A---- C:\WINDOWS\ODBCINST.INI
    2008-09-30 04:57:18 ----D---- C:\Program Files\Common Files\SpeechEngines
    2008-09-30 04:57:17 ----RD---- C:\Program Files
    2008-09-30 04:57:17 ----D---- C:\Program Files\Common Files\Microsoft Shared
    2008-09-30 04:57:17 ----D---- C:\Program Files\Common Files
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
    2008-09-30 04:57:15 ----RA---- C:\WINDOWS\system32\kbdazel.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdycc.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbduzb.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdur.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdtat.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdru1.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdru.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdmon.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdbu.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdblr.dll
    2008-09-30 04:57:14 ----RA---- C:\WINDOWS\system32\kbdaze.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhept.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdhe.dll
    2008-09-30 04:57:12 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlv.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdlt.dll
    2008-09-30 04:57:11 ----RA---- C:\WINDOWS\system32\kbdest.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdycl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdsl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdro.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdpl.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdhu.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcz.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\kbdcr.dll
    2008-09-30 04:57:10 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\spxcoins.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\irclass.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\EqnClass.Dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\dgsetup.dll
    2008-09-30 04:57:08 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\TASKMAN.EXE
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\system32\CONFIG.TMP
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\system32\batt.dll
    2008-09-30 04:57:06 ----A---- C:\WINDOWS\NOTEPAD.EXE
    2008-09-30 04:57:05 ----A---- C:\WINDOWS\system32\storprop.dll
    2008-09-30 04:56:56 ----RA---- C:\WINDOWS\SET8.tmp
    2008-09-30 04:56:54 ----RA---- C:\WINDOWS\SET4.tmp
    2008-09-30 04:56:53 ----RA---- C:\WINDOWS\SET3.tmp
    2008-09-30 04:56:49 ----D---- C:\WINDOWS\system32\CatRoot2
    2008-09-30 04:56:49 ----D---- C:\WINDOWS\system32\CatRoot
    2008-09-30 04:56:30 ----A---- C:\WINDOWS\setuplog.txt
    2008-09-30 04:56:27 ----SHD---- C:\System Volume Information
    2008-09-30 04:56:27 ----D---- C:\Documents and Settings
    2008-09-30 04:52:11 ----RSHDC---- C:\WINDOWS\system32\dllcache
    2008-09-30 04:52:11 ----RSD---- C:\WINDOWS\Fonts
    2008-09-30 04:52:11 ----RD---- C:\WINDOWS\Web
    2008-09-30 04:52:11 ----HD---- C:\WINDOWS\inf
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\WinSxS
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\twain_32
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\wins
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\wbem
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\usmt
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\spool
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ShellExt
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\Setup
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ras
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\oobe
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\npp
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\mui
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\inetsrv
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\IME
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\icsxml
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\ias
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\export
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\drivers
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\dhcp
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\config
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\3com_dmi
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\3076
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\2052
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1054
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1042
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1041
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1037
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1033
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1031
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1028
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32\1025
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system32
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\system
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\security
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Resources
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\repair
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Provisioning
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\PeerNet
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\pchealth
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\mui
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\msapps
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\msagent
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Media
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\java
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\ime
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Help
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\ehome
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Driver Cache
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Debug
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Cursors
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Connection Wizard
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\Config
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\AppPatch
    2008-09-30 04:52:11 ----D---- C:\WINDOWS\addins
    2008-09-30 04:52:11 ----D---- C:\WINDOWS
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
    2008-09-15 16:12:54 ----A---- C:\WINDOWS\system32\ssldivx.dll
    2008-09-15 16:12:54 ----A---- C:\WINDOWS\system32\libdivx.dll
    2008-09-09 22:37:22 ----A---- C:\WINDOWS\system32\frapsvid.dll

    ======List of files/folders modified in the last 3 months======

    2008-10-06 15:24:55 ----A---- C:\WINDOWS\system.ini
    2008-09-30 23:06:47 ----A---- C:\WINDOWS\win.ini
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nwiz.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwss.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvshell.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nview.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvgames.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvcod.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nvapi.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
    2008-09-17 08:55:00 ----A---- C:\WINDOWS\system32\keystone.exe

    ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R1 AsIO;AsIO; C:\WINDOWS\system32\drivers\AsIO.sys [2006-10-17 12664]
    R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
    R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-06-27 75072]
    R1 cmdGuard;COMODO Firewall Pro Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2008-11-09 99856]
    R1 cmdHlp;COMODO Firewall Pro Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2008-11-09 31504]
    R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-03 36096]
    R1 SCDEmu;SCDEmu; C:\WINDOWS\system32\drivers\SCDEmu.sys [2008-07-06 56108]
    R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
    R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
    R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
    R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-09-30 25280]
    R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2005-01-07 138752]
    R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
    R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
    R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2007-03-01 4484608]
    R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2005-09-20 10368]
    R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
    R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-09-17 6132576]
    R3 SiSGbeXP;SiS191/SiS190 Ethernet Device NDIS 5.1 Driver; C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys [2006-12-19 41600]
    R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-03 26624]
    R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
    R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-03 17024]
    R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
    S3 catchme;catchme; \??\C:\ComboFix\catchme.sys []
    S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
    S3 PCASp50;PCASp50 NDIS Protocol Driver; C:\WINDOWS\System32\Drivers\PCASp50.sys []
    S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
    S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
    S3 usbscan;Usbscan; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
    S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
    S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []

    ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======

    R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-04 611664]
    R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-25 68865]
    R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-25 151297]
    R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Program Files\Bonjour\mDNSResponder.exe [2006-02-28 229376]
    R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\Firewall\cmdagent.exe [2008-11-09 614136]
    R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-09-17 163908]
    R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
    S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-03 654848]
    S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]

    -----------------EOF-----------------

  10. #10
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Please download the OTMoveIt3 by OldTimer.
    • Save it to your desktop.
    • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
    • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):

      Code:
      :files
      C:\Program Files\BitComet
      
      :reg
      [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
      "C:\Program Files\BitComet\BitComet.exe"=-
      
      :commands
      [EmptyTemp]
    • Return to OTMoveIt3, right click in the "Paste List of Files/Folders to Move" window (under the yellow bar) and choose Paste.
    • Click the red Moveit! button.
    • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
    • Close OTMoveIt3

    Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

    Re-run rsit.

    Post:

    - otmoveit3 log
    - rsit log (only log.txt will appear this time)
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •