log.txt:
Logfile of random's system information tool 1.06 (written by random/random)
Run by Philip at 2009-10-23 20:24:09
WIN_XP Service Pack 3
System drive C: has 834 GB (87%) free of 954 GB
Total RAM: 3582 MB (88% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:24:14 PM, on 10/23/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe
C:\Program Files\Avanquest\PowerDesk\PDExplo.exe
C:\Documents and Settings\Philip\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Philip.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) -
http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1215360418046
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: acaptuser32.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
--
End of file - 4221 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-07-25 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-07-25 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2009-02-27 349576]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-14 169984]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2009-09-04 935288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-10-03 35696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-10-17 2025752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
C:\WINDOWS\system32\CTHELPER.EXE [2007-04-09 19456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTxfiHlp]
C:\WINDOWS\system32\CTXFIHLP.EXE [2007-04-09 19968]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LanguageShortcut]
C:\Program Files\CyberLink\PowerDVD\Language\Language.exe [2007-01-08 52256]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2008-05-02 13529088]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2008-05-02 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl]
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe [2007-03-14 71216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-07-25 149280]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Service Manager.lnk]
C:\PROGRA~1\MI6841~1\80\Tools\Binn\sqlmangr.exe [2005-05-03 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Philip^Start Menu^Programs^Startup^Adobe Gamma.lnk]
C:\PROGRA~1\COMMON~1\Adobe\CALIBR~1\ADOBEG~1.EXE [1999-11-04 113664]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Philip^Start Menu^Programs^Startup^Dialog Helper.lnk]
C:\PROGRA~1\AVANQU~1\POWERD~1\pddlghlp.exe [2008-04-22 46336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Philip^Start Menu^Programs^Startup^MagicDisc.lnk]
C:\PROGRA~1\MAGICD~1\MAGICD~1.EXE [2009-02-23 576000]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"xmlprov"=3
"WZCSVC"=2
"WudfSvc"=3
"wuauserv"=2
"wscsvc"=2
"WMPNetworkSvc"=3
"WmiApSrv"=3
"Wmi"=3
"WmdmPmSN"=3
"winmgmt"=2
"WebClient"=2
"W3SVC"=2
"W32Time"=2
"VSS"=3
"UPS"=3
"upnphost"=3
"TrkWks"=2
"Themes"=2
"TermService"=3
"TapiSrv"=3
"SysmonLog"=3
"SwPrv"=3
"stisvc"=2
"SSDPSRV"=3
"srservice"=2
"SQLSERVERAGENT"=3
"Spooler"=2
"SMTPSVC"=2
"ShellHWDetection"=2
"SharedAccess"=2
"SENS"=2
"seclogon"=2
"Schedule"=2
"SCardSvr"=3
"SamSs"=2
"RSVP"=3
"RichVideo"=2
"RemoteRegistry"=2
"RDSessMgr"=3
"RasAuto"=3
"ProtectedStorage"=2
"PolicyAgent"=2
"PlugPlay"=2
"ose"=3
"NVSvc"=2
"NtmsSvc"=3
"NtLmSsp"=3
"NMIndexingService"=3
"Nla"=3
"Netman"=3
"Netlogon"=3
"napagent"=3
"MSSQLSERVER"=3
"MSIServer"=3
"MSDTC"=3
"mnmsrvc"=3
"MDM"=2
"LmHosts"=2
"lanmanworkstation"=2
"lanmanserver"=2
"JavaQuickStarterService"=2
"ImapiService"=3
"IISADMIN"=2
"idsvc"=3
"HTTPFilter"=3
"hkmsvc"=3
"helpsvc"=2
"FontCache3.0.0.0"=3
"FLEXnet Licensing Service"=3
"FastUserSwitchingCompatibility"=3
"EventSystem"=3
"Eventlog"=2
"ERSvc"=2
"EapHost"=3
"Dot3svc"=3
"Dnscache"=2
"dmserver"=2
"dmadmin"=3
"Dhcp"=2
"CryptSvc"=3
"COMSysApp"=3
"clr_optimization_v2.0.50727_32"=3
"CiSvc"=3
"CCALib8"=3
"Browser"=2
"BITS"=3
"avg8wd"=2
"AudioSrv"=2
"aspnet_state"=2
"AppMgmt"=3
"ALG"=3
"Adobe LM Service"=3
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="acaptuser32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-08-28 11952]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"DisableTaskMgr"=0
"DisableCMD"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoSetActiveDesktop"=0
"NoActiveDesktopChanges"=0
"NoFolderOptions"=0
"NoRun"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=
"NoFolderOptions"=
"NoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe"="C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe:*:Enabled:CyberLink PowerDVD"
"D:\CDS\Nero\Installation\SetupX.exe"="D:\CDS\Nero\Installation\SetupX.exe:*:Enabled:Nero ProductSetup"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"\\Hipserv\FamilyLibrary\FamilyDocuments\D&D\4e\700_DDI_CB-Beta.exe"="\\Hipserv\FamilyLibrary\FamilyDocuments\D&D\4e\700_DDI_CB-Beta.exe:*:Enabled

D Insider"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
======File associations======
.vbs - open - %WINDIR%\System32\CScript.exe //nologo "%1" %*
======List of files/folders created in the last 1 months======
2009-10-23 20:11:10 ----D---- C:\rsit
2009-10-23 16:35:40 ----A---- C:\regkey.txt
2009-10-22 09:59:16 ----SHD---- C:\Config.Msi
2009-10-21 16:52:51 ----D---- C:\Program Files\Trend Micro
2009-10-21 16:50:49 ----D---- C:\Program Files\ERUNT
2009-10-21 11:19:59 ----A---- C:\WINDOWS\entpack.ini
2009-10-20 13:28:26 ----D---- C:\WINDOWS\CSC
2009-10-20 13:28:19 ----A---- C:\WINDOWS\ntbtlog.txt
2009-10-20 12:55:35 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-10-20 12:31:29 ----D---- C:\WINDOWS\pss
2009-10-20 12:24:15 ----D---- C:\Program Files\Windows Live Safety Center
2009-10-20 11:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-10-20 02:27:51 ----D---- C:\Program Files\Spybot - Search & Destroy.bar
2009-10-20 02:03:08 ----HD---- C:\WINDOWS\PIF
2009-10-20 01:47:03 ----A---- C:\WINDOWS\comp.INI
2009-10-20 01:44:37 ----D---- C:\Program Files\Port80
2009-10-17 16:09:07 ----D---- C:\Documents and Settings\Philip\Application Data\com.fox.dollhouse.VirtualEcho.8DB2FB41E3AF9617470F9C3E78FDAAA51EF66383.1
2009-10-17 16:09:03 ----D---- C:\Program Files\VirtualEcho
2009-10-17 16:09:01 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-10-17 02:00:56 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2009-10-17 02:00:53 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-10-17 02:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2009-10-17 02:00:28 ----D---- C:\WINDOWS\$SQLUninstallSQL2000-KB960082-v8.00.2055-x86-ENU$
2009-10-17 02:00:06 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2009-10-17 02:00:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2009-10-17 01:59:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2009-10-17 01:59:16 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2009-10-17 01:58:10 ----HDC---- C:\WINDOWS\$NtUninstallKB971486$
2009-10-17 01:58:03 ----HDC---- C:\WINDOWS\$NtUninstallKB973525$
2009-10-17 01:57:23 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2009-10-17 01:57:15 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2009-10-15 12:25:40 ----D---- C:\bwinPoker
2009-10-14 18:21:55 ----A---- C:\WINDOWS\system32\dbmsqlgc.dll
2009-10-14 18:21:55 ----A---- C:\WINDOWS\system32\dbmsgnet.dll
2009-10-13 23:55:33 ----A---- C:\WINDOWS\system32\insrepim.exe
2009-10-13 23:55:25 ----A---- C:\WINDOWS\system32\mdt2fw95.dll
2009-10-13 23:55:15 ----A---- C:\WINDOWS\system32\dbmslpcn.dll
2009-10-13 23:44:32 ----D---- C:\WINDOWS\Install
2009-10-13 23:41:36 ----D---- C:\WINDOWS\Cluster
2009-10-13 23:21:03 ----A---- C:\WINDOWS\system32\msrpjt40.dll
2009-10-13 23:20:49 ----A---- C:\WINDOWS\system32\ntwdblib.dll
2009-10-13 23:20:47 ----A---- C:\WINDOWS\system32\dbmsshrn.dll
2009-10-13 18:08:12 ----A---- C:\WINDOWS\system32\athprxy.dll
2009-10-13 13:17:38 ----D---- C:\Program Files\Common Files\Merge Modules
2009-10-13 13:16:59 ----D---- C:\Program Files\Microsoft ACT
2009-10-13 13:16:58 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-10-13 01:11:15 ----HDC---- C:\WINDOWS\$NtUninstallKB970483$
2009-10-13 01:11:12 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2009-10-13 01:05:37 ----A---- C:\WINDOWS\frontpg.ini
2009-10-13 01:03:36 ----D---- C:\WINDOWS\IIS Temporary Compressed Files
2009-10-13 01:03:23 ----D---- C:\WINDOWS\system32\Cache
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\snprfdll.dll
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\smtpctrs.ini
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\smtpctrs.dll
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\regtrace.exe
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\ntfsdrct.ini
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\fcachdll.dll
2009-10-13 01:03:19 ----A---- C:\WINDOWS\system32\adsiisex.dll
2009-10-13 01:03:03 ----A---- C:\WINDOWS\system32\w3svapi.dll
2009-10-13 01:03:03 ----A---- C:\WINDOWS\system32\w3ctrs.ini
2009-10-13 01:03:03 ----A---- C:\WINDOWS\system32\w3ctrs.dll
2009-10-13 01:03:03 ----A---- C:\WINDOWS\system32\axperf.ini
2009-10-13 01:03:03 ----A---- C:\WINDOWS\system32\aspperf.dll
2009-10-13 01:03:00 ----A---- C:\WINDOWS\system32\iisrstap.dll
2009-10-13 01:03:00 ----A---- C:\WINDOWS\system32\iisreset.exe
2009-10-13 01:03:00 ----A---- C:\WINDOWS\system32\ftpsapi2.dll
2009-10-13 01:02:59 ----A---- C:\WINDOWS\system32\wamregps.dll
2009-10-13 01:02:59 ----A---- C:\WINDOWS\system32\inetsloc.dll
2009-10-13 01:02:59 ----A---- C:\WINDOWS\system32\iismui.dll
2009-10-13 01:02:58 ----A---- C:\WINDOWS\system32\infoctrs.ini
2009-10-13 01:02:58 ----A---- C:\WINDOWS\system32\infoctrs.dll
2009-10-13 01:02:58 ----A---- C:\WINDOWS\system32\convlog.exe
2009-10-13 01:02:58 ----A---- C:\WINDOWS\system32\admxprox.dll
2009-10-13 00:57:58 ----D---- C:\Program Files\MagicDisc
2009-10-04 00:22:11 ----D---- C:\Program Files\Pappocom
2009-10-04 00:22:05 ----D---- C:\Program Files\Common Files\MimarSinan
======List of files/folders modified in the last 1 months======
2009-10-23 20:19:46 ----D---- C:\WINDOWS\system32\inetsrv
2009-10-23 20:19:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-10-23 20:19:39 ----A---- C:\WINDOWS\{00000003-00000000-00000007-00001102-00000008-10211102}.BAK
2009-10-23 20:19:21 ----SH---- C:\boot.ini
2009-10-23 20:19:21 ----A---- C:\WINDOWS\win.ini
2009-10-23 20:19:21 ----A---- C:\WINDOWS\system.ini
2009-10-23 20:18:01 ----D---- C:\Program Files\FireFox
2009-10-23 20:17:55 ----D---- C:\WINDOWS\Temp
2009-10-23 20:17:48 ----D---- C:\WINDOWS
2009-10-23 20:11:15 ----D---- C:\WINDOWS\Prefetch
2009-10-23 16:55:38 ----D---- C:\Program Files\PokerStars.NET
2009-10-23 16:37:35 ----SHD---- C:\System Volume Information
2009-10-23 16:37:35 ----D---- C:\WINDOWS\system32\Restore
2009-10-23 11:03:55 ----D---- C:\WINDOWS\Registration
2009-10-22 18:19:14 ----SHD---- C:\WINDOWS\Installer
2009-10-22 18:19:13 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-10-22 09:59:11 ----D---- C:\WINDOWS\system32
2009-10-21 23:30:53 ----HD---- C:\WINDOWS\inf
2009-10-21 23:30:51 ----D---- C:\WINDOWS\system32\CatRoot2
2009-10-21 16:52:51 ----RD---- C:\Program Files
2009-10-21 16:52:42 ----D---- C:\Downloads
2009-10-21 11:28:21 ----A---- C:\WINDOWS\lviewpro.ini
2009-10-21 11:11:54 ----D---- C:\Documents and Settings
2009-10-20 15:00:40 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-10-20 15:00:23 ----D---- C:\Program Files\Internet Explorer
2009-10-20 14:35:53 ----D---- C:\Program Files\Spybot - Search & Destroy.foo
2009-10-20 14:25:08 ----D---- C:\WINDOWS\system32\en-us
2009-10-20 14:16:17 ----SD---- C:\WINDOWS\Tasks
2009-10-20 12:55:44 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-10-20 12:24:16 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-10-20 11:21:26 ----D---- C:\WINDOWS\Media
2009-10-20 11:21:26 ----D---- C:\WINDOWS\Help
2009-10-20 11:03:51 ----HD---- C:\WINDOWS\$hf_mig$
2009-10-20 11:03:47 ----A---- C:\WINDOWS\imsins.BAK
2009-10-20 03:09:32 ----HD---- C:\$AVG8.VAULT$
2009-10-20 01:12:30 ----D---- C:\WINDOWS\system32\config
2009-10-20 01:12:30 ----D---- C:\WINDOWS\SxsCaPendDel
2009-10-20 01:12:30 ----D---- C:\WINDOWS\Connection Wizard
2009-10-20 01:12:30 ----D---- C:\WINDOWS\Config
2009-10-20 01:12:30 ----D---- C:\WINDOWS\addins
2009-10-17 20:10:20 ----D---- C:\WINSOCK
2009-10-17 16:09:07 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-10-17 16:09:01 ----D---- C:\Program Files\Common Files
2009-10-17 16:08:35 ----D---- C:\Documents and Settings\Philip\Application Data\Adobe
2009-10-17 10:06:40 ----D---- C:\WINDOWS\Microsoft.NET
2009-10-17 10:06:39 ----RSD---- C:\WINDOWS\assembly
2009-10-17 02:02:51 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-10-17 02:02:27 ----D---- C:\WINDOWS\WinSxS
2009-10-17 01:57:17 ----D---- C:\WINDOWS\system32\drivers
2009-10-17 01:32:30 ----D---- C:\keep
2009-10-14 13:44:18 ----SD---- C:\Documents and Settings\Philip\Application Data\Microsoft
2009-10-13 23:41:32 ----D---- C:\Program Files\Common Files\System
2009-10-13 23:20:47 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-10-13 23:20:22 ----HD---- C:\Program Files\Uninstall Information
2009-10-13 16:32:46 ----D---- C:\Program Files\MSDN
2009-10-13 13:16:59 ----D---- C:\Program Files\Microsoft Visual Studio .NET 2003
2009-10-13 00:59:52 ----D---- C:\WINDOWS\security
2009-10-02 11:01:58 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-08-28 335240]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-08-28 27784]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R3 AR5416;Atheros AR5008 Wireless Network Adapter Service; C:\WINDOWS\system32\DRIVERS\athw.sys [2008-04-03 1333152]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 COMMONFX.DLL;COMMONFX.DLL; C:\WINDOWS\system32\COMMONFX.DLL [2007-04-18 98600]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2007-04-10 511272]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2007-04-10 520488]
R3 CTAUDFX.DLL;CTAUDFX.DLL; C:\WINDOWS\system32\CTAUDFX.DLL [2007-04-12 546048]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2007-04-10 14632]
R3 CTSBLFX.DLL;CTSBLFX.DLL; C:\WINDOWS\system32\CTSBLFX.DLL [2007-04-12 560384]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2007-04-10 157480]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2007-04-10 92968]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2007-04-10 797992]
R3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2007-04-10 189736]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-11-15 4225920]
R3 mcdbus;Driver for MagicISO SCSI Host Controller; C:\WINDOWS\system32\DRIVERS\mcdbus.sys [2009-02-24 116736]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\system32\DRIVERS\ASACPI.sys [2004-08-12 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-05-02 6554496]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2007-04-10 126760]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 CT20XUT.DLL;CT20XUT.DLL; C:\WINDOWS\system32\CT20XUT.DLL [2007-04-12 164608]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2007-04-10 347128]
S3 CTEAPSFX.DLL;CTEAPSFX.DLL; C:\WINDOWS\system32\CTEAPSFX.DLL [2007-04-12 168192]
S3 CTEDSPFX.DLL;CTEDSPFX.DLL; C:\WINDOWS\system32\CTEDSPFX.DLL [2007-04-12 280320]
S3 CTEDSPIO.DLL;CTEDSPIO.DLL; C:\WINDOWS\system32\CTEDSPIO.DLL [2007-04-12 128768]
S3 CTEDSPSY.DLL;CTEDSPSY.DLL; C:\WINDOWS\system32\CTEDSPSY.DLL [2007-04-12 323328]
S3 CTERFXFX.DLL;CTERFXFX.DLL; C:\WINDOWS\system32\CTERFXFX.DLL [2007-04-12 94976]
S3 CTEXFIFX.DLL;CTEXFIFX.DLL; C:\WINDOWS\system32\CTEXFIFX.DLL [2007-04-12 1317632]
S3 CTHWIUT.DLL;CTHWIUT.DLL; C:\WINDOWS\system32\CTHWIUT.DLL [2007-04-12 66816]
S3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2007-04-10 163112]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
S4 Adobe LM Service;Adobe LM Service; C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [2008-10-11 72704]
S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-08-28 297752]
S4 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe []
S4 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S4 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2009-03-01 651720]
S4 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S4 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S4 IISADMIN;IIS Admin; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15360]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-07-25 153376]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-03-19 335872]
S4 MSSQLSERVER;MSSQLSERVER; C:\PROGRA~1\MI6841~1\MSSQL\binn\sqlservr.exe [2008-12-18 9158656]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
S4 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896]
S4 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-05-02 159812]
S4 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S4 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files\CyberLink\Shared Files\RichVideo.exe [2007-05-13 272024]
S4 SMTPSVC;Simple Mail Transfer Protocol (SMTP); C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15360]
S4 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\binn\sqlagent.exe [2005-05-03 323584]
S4 W3SVC;World Wide Web Publishing; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15360]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S4 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------