Rsit log
Logfile of random's system information tool 1.06 (written by random/random)
Run by Bonnie at 2009-09-24 13:37:19
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 150 GB (63%) free of 238 GB
Total RAM: 2559 MB (70% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:37:29 PM, on 9/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\PROGRA~1\ROADRU~2\PHOTOS~1\data\Xtras\mssysmgr.exe
C:\Program Files\IncrediMail\bin\IMApp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe
C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\IncrediMail\bin\IncMail.exe
C:\Documents and Settings\Bonnie.BONNIE-FM4OD1WD\My Documents\Downloads\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Bonnie.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://mystart.incredigames.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [YSearchProtection] "C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\RunOnce: [GrpConv] grpconv -o
O4 - HKLM\..\RunOnce: [ccube_TrustList] "C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /trustlist
O4 - HKCU\..\Run: [IncrediMail] C:\Program Files\IncrediMail\bin\IncMail.exe /c
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [Search Protection] C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - HKCU\..\Run: [Road Runner PhotoShow Media Manager] C:\PROGRA~1\ROADRU~2\PHOTOS~1\data\Xtras\mssysmgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe
--
End of file - 7289 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Bonnie at 6 46 PM.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2009-07-30 909040]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn2\YTSingleInstance.dll [2009-07-30 159472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn2\yt.dll [2009-07-30 909040]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"CTSysVol"=C:\Program Files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe [2002-10-29 49152]
"CTDVDDet"=C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE [2002-09-30 45056]
"CTHelper"=C:\WINDOWS\system32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"=REGSVR32.EXE /S CTASIO.DLL []
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"BCMSMMSG"=C:\WINDOWS\BCMSMMSG.exe [2003-08-29 122880]
"YSearchProtection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 111856]
"cctray"=C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe [2009-09-16 177392]
"QOELOADER"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe [2009-09-16 14088]
"CAVRID"=C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe [2009-09-16 230664]
"cafwc"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2009-09-23 1193200]
"capfasem"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2009-09-23 173296]
"capfupgrade"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe [2009-09-23 259312]
"Malwarebytes Anti-Malware (reboot)"=C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce]
""= []
"GrpConv"=grpconv -o []
"ccube_TrustList"=C:\Program Files\CA\CA Internet Security Suite\caunst.exe [2009-09-16 529648]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"IncrediMail"=C:\Program Files\IncrediMail\bin\IncMail.exe [2009-08-10 251264]
"Messenger (Yahoo!)"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2009-05-26 4351216]
"Search Protection"=C:\Program Files\Yahoo!\Search Protection\SearchProtection.exe [2009-02-23 111856]
"MoneyAgent"=C:\Program Files\Microsoft Money\System\mnyexpr.exe [2003-06-18 200704]
"Road Runner PhotoShow Media Manager"=C:\PROGRA~1\ROADRU~2\PHOTOS~1\data\Xtras\mssysmgr.exe [2008-05-09 361976]
C:\Documents and Settings\All Users.WINDOWS\Start Menu\Programs\Startup
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
C:\WINDOWS\system32\UmxWnp.Dll [2007-05-18 79368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\IncrediMail\bin\IncMail.exe"="C:\Program Files\IncrediMail\bin\IncMail.exe:*:Enabled:IncrediMail"
"C:\Program Files\IncrediMail\bin\ImApp.exe"="C:\Program Files\IncrediMail\bin\ImApp.exe:*:Enabled:IncrediMail"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-09-24 11:01:39 ----A---- C:\ComboFix.txt
2009-09-24 10:47:42 ----D---- C:\ComboFix
2009-09-23 16:42:34 ----D---- C:\Program Files\ESET
2009-09-23 16:32:46 ----A---- C:\WINDOWS\_MSRSTRT.EXE
2009-09-22 15:38:06 ----A---- C:\Boot.bak
2009-09-22 15:37:48 ----RASHD---- C:\cmdcons
2009-09-22 15:36:43 ----A---- C:\WINDOWS\zip.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\SWSC.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\SWREG.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\sed.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\PEV.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\NIRCMD.exe
2009-09-22 15:36:43 ----A---- C:\WINDOWS\grep.exe
2009-09-22 15:36:37 ----D---- C:\WINDOWS\ERDNT
2009-09-22 15:36:26 ----D---- C:\Qoobox
2009-09-22 14:02:50 ----D---- C:\Documents and Settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Malwarebytes
2009-09-22 14:02:41 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-09-22 14:02:40 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-09-22 09:53:17 ----D---- C:\rsit
2009-09-19 13:48:09 ----DC---- C:\Documents and Settings\All Users.WINDOWS\Application Data\{C4C0E335-EDDF-46A0-A57D-F3802AE44275}
2009-09-19 13:42:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-09-19 13:42:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-09-19 13:42:38 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-09-19 13:42:38 ----D---- C:\234563fc4a7886848891d2c7
2009-09-19 13:30:00 ----RD---- C:\AHCache
2009-09-18 18:59:00 ----D---- C:\Program Files\Trend Micro
2009-09-17 11:29:04 ----D---- C:\WINDOWS\Prefetch
2009-09-16 21:28:17 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-09-16 21:27:43 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-09-16 21:27:10 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-09-16 21:26:38 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-09-16 21:25:59 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-09-16 21:25:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-09-16 21:24:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-09-16 21:24:21 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-09-16 21:23:49 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-09-16 21:23:14 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-09-16 21:22:41 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$
2009-09-16 21:22:09 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-09-16 21:21:36 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-09-16 21:21:03 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-09-16 21:20:30 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-09-16 21:19:58 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-09-16 21:19:24 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-09-16 21:18:50 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-09-16 21:18:17 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-09-16 21:17:45 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-09-16 21:17:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2009-09-16 21:16:40 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-09-16 21:16:08 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-09-16 21:15:28 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-09-16 21:14:53 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-09-16 21:14:20 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-09-16 21:13:45 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2009-09-16 21:13:06 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-09-16 21:12:34 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-09-16 21:11:57 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-09-16 21:11:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-09-16 21:10:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-09-16 21:10:12 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-09-16 21:09:39 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-09-16 21:09:06 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-09-16 21:08:31 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-09-16 20:15:42 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2009-09-16 20:14:32 ----D---- C:\Program Files\Common Files\Oberon Media
2009-09-16 20:14:31 ----D---- C:\Program Files\IncrediGames
2009-09-16 18:46:50 ----A---- C:\WINDOWS\system32\vetredir.dll
2009-09-16 18:46:50 ----A---- C:\WINDOWS\system32\isafprod.dll
2009-09-16 18:46:50 ----A---- C:\WINDOWS\system32\isafeif.dll
2009-09-16 18:46:16 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\CA
2009-09-16 17:29:00 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Road Runner
2009-09-16 17:27:31 ----N---- C:\WINDOWS\system32\pxsfs.dll
2009-09-16 17:27:31 ----N---- C:\WINDOWS\system32\pxinsa64.exe
2009-09-16 17:27:31 ----N---- C:\WINDOWS\system32\pxhpinst.exe
2009-09-16 17:27:31 ----N---- C:\WINDOWS\system32\pxcpya64.exe
2009-09-16 17:26:30 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Simple Star Shared
2009-09-16 17:26:26 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Simple Star
2009-09-16 17:01:22 ----D---- C:\Documents and Settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Simple Star
2009-09-16 17:01:22 ----D---- C:\Documents and Settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Road Runner
2009-09-16 14:49:37 ----D---- C:\Documents and Settings\Bonnie.BONNIE-FM4OD1WD\Application Data\Sun
2009-09-14 22:10:58 ----A---- C:\WINDOWS\TaxACT06.ini
2009-09-13 03:06:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2_0$
2009-09-13 03:05:50 ----HDC---- C:\WINDOWS\$NtUninstallKB972260$
2009-09-13 03:04:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956844_0$
2009-09-13 03:04:45 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2_0$
2009-09-13 03:04:40 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$
2009-09-13 03:04:19 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2009-09-13 03:02:12 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$
2009-09-13 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2009-09-13 03:01:05 ----D---- C:\Program Files\MSXML 4.0
2009-09-13 03:00:56 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-09-13 03:00:44 ----HDC---- C:\WINDOWS\$NtUninstallKB926247$
2009-09-12 17:40:55 ----N---- C:\WINDOWS\system32\wmphoto.dll
2009-09-12 17:40:54 ----N---- C:\WINDOWS\system32\wlanapi.dll
2009-09-12 17:40:53 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2009-09-12 17:40:53 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2009-09-12 17:40:51 ----N---- C:\WINDOWS\system32\tspkg.dll
2009-09-12 17:40:51 ----N---- C:\WINDOWS\system32\tsgqec.dll
2009-09-12 17:40:47 ----N---- C:\WINDOWS\system32\setupn.exe
2009-09-12 17:40:46 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\rasqec.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\qutil.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\qcliprov.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\qagentrt.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\qagent.dll
2009-09-12 17:40:45 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2009-09-12 17:40:44 ----N---- C:\WINDOWS\system32\onex.dll
2009-09-12 17:40:42 ----N---- C:\WINDOWS\system32\napstat.exe
2009-09-12 17:40:42 ----N---- C:\WINDOWS\system32\napmontr.dll
2009-09-12 17:40:42 ----N---- C:\WINDOWS\system32\napipsec.dll
2009-09-12 17:40:41 ----N---- C:\WINDOWS\system32\msxml6r.dll
2009-09-12 17:40:41 ----N---- C:\WINDOWS\system32\msxml6.dll
2009-09-12 17:40:40 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2009-09-12 17:40:40 ----N---- C:\WINDOWS\system32\mssha.dll
2009-09-12 17:40:36 ----N---- C:\WINDOWS\system32\mmcperf.exe
2009-09-12 17:40:36 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2009-09-12 17:40:36 ----N---- C:\WINDOWS\system32\mmcex.dll
2009-09-12 17:40:36 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2009-09-12 17:40:33 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2009-09-12 17:40:32 ----N---- C:\WINDOWS\system32\kmsvc.dll
2009-09-12 17:40:32 ----N---- C:\WINDOWS\system32\kbdpash.dll
2009-09-12 17:40:32 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2009-09-12 17:40:32 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2009-09-12 17:40:32 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2009-09-12 17:40:31 ----N---- C:\WINDOWS\system32\ieencode.dll
2009-09-12 17:40:29 ----A---- C:\WINDOWS\005143_.tmp
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eapsvc.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eapqec.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eappprxy.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eapphost.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eappgnui.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eappcfg.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2009-09-12 17:40:28 ----N---- C:\WINDOWS\system32\eapolqec.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3ui.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3svc.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3msm.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dot3api.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dimsroam.dll
2009-09-12 17:40:27 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2009-09-12 17:40:26 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2009-09-12 17:40:25 ----N---- C:\WINDOWS\system32\credssp.dll
2009-09-12 17:40:22 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2009-09-12 17:40:22 ----N---- C:\WINDOWS\system32\azroles.dll
2009-09-12 17:40:20 ----N---- C:\WINDOWS\system32\aaclient.dll
2009-09-12 15:45:37 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-09-12 15:45:22 ----N---- C:\WINDOWS\system32\tzchange.exe
2009-09-12 11:09:51 ----HDC---- C:\WINDOWS\$NtUninstallKB924496$
2009-09-12 11:09:36 ----HDC---- C:\WINDOWS\$NtUninstallKB924191$
2009-09-12 11:09:22 ----HDC---- C:\WINDOWS\$NtUninstallKB923414$
2009-09-12 11:09:08 ----HDC---- C:\WINDOWS\$NtUninstallKB923191$
2009-09-12 11:08:53 ----HDC---- C:\WINDOWS\$NtUninstallKB922819$
2009-09-12 11:08:34 ----HDC---- C:\WINDOWS\$NtUninstallKB922616$
2009-09-12 11:08:19 ----HDC---- C:\WINDOWS\$NtUninstallKB921883$
2009-09-12 11:08:04 ----HDC---- C:\WINDOWS\$NtUninstallKB921398$
2009-09-12 11:07:49 ----HDC---- C:\WINDOWS\$NtUninstallKB920685$
2009-09-12 11:07:34 ----HDC---- C:\WINDOWS\$NtUninstallKB920683$
2009-09-12 11:07:18 ----HDC---- C:\WINDOWS\$NtUninstallKB920670$
2009-09-12 11:07:03 ----HDC---- C:\WINDOWS\$NtUninstallKB919007$
2009-09-12 11:06:48 ----HDC---- C:\WINDOWS\$NtUninstallKB917953$
2009-09-12 11:06:33 ----HDC---- C:\WINDOWS\$NtUninstallKB917422$
2009-09-12 11:06:17 ----HDC---- C:\WINDOWS\$NtUninstallKB917344$
2009-09-12 11:06:03 ----HDC---- C:\WINDOWS\$NtUninstallKB914389$
2009-09-12 11:05:47 ----HDC---- C:\WINDOWS\$NtUninstallKB914388$
2009-09-12 11:05:31 ----HDC---- C:\WINDOWS\$NtUninstallKB913580$
2009-09-12 11:05:15 ----HDC---- C:\WINDOWS\$NtUninstallKB912919$
2009-09-12 11:04:59 ----HDC---- C:\WINDOWS\$NtUninstallKB911927$
2009-09-12 11:04:44 ----HDC---- C:\WINDOWS\$NtUninstallKB911562$
2009-09-12 11:04:29 ----HDC---- C:\WINDOWS\$NtUninstallKB911280$
2009-09-12 11:04:13 ----HDC---- C:\WINDOWS\$NtUninstallKB910437$
2009-09-12 11:03:56 ----HDC---- C:\WINDOWS\$NtUninstallKB908531$
2009-09-12 11:03:29 ----HDC---- C:\WINDOWS\$NtUninstallKB908519$
2009-09-12 11:03:15 ----HDC---- C:\WINDOWS\$NtUninstallKB905749$
2009-09-12 11:02:58 ----HDC---- C:\WINDOWS\$NtUninstallKB905414$
2009-09-12 11:02:41 ----HDC---- C:\WINDOWS\$NtUninstallKB904706$
2009-09-12 11:02:21 ----HDC---- C:\WINDOWS\$NtUninstallKB902400$
2009-09-12 11:02:05 ----HDC---- C:\WINDOWS\$NtUninstallKB901214$
2009-09-12 11:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB901017$
2009-09-12 11:01:31 ----HDC---- C:\WINDOWS\$NtUninstallKB900725$
2009-09-12 11:01:15 ----HDC---- C:\WINDOWS\$NtUninstallKB899591$
2009-09-12 11:00:59 ----HDC---- C:\WINDOWS\$NtUninstallKB899587$
2009-09-12 11:00:42 ----HDC---- C:\WINDOWS\$NtUninstallKB896428$
2009-09-12 11:00:25 ----HDC---- C:\WINDOWS\$NtUninstallKB896424$
2009-09-12 11:00:07 ----HDC---- C:\WINDOWS\$NtUninstallKB896423$
2009-09-12 10:59:50 ----HDC---- C:\WINDOWS\$NtUninstallKB896358$
2009-09-12 10:59:32 ----HDC---- C:\WINDOWS\$NtUninstallKB893756$
2009-09-12 10:59:17 ----HDC---- C:\WINDOWS\$NtUninstallKB891781$
2009-09-12 10:58:43 ----HDC---- C:\WINDOWS\$NtUninstallKB890859$
2009-09-12 10:58:21 ----HDC---- C:\WINDOWS\$NtUninstallKB890046$
2009-09-12 10:51:26 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-09-12 08:57:55 ----A---- C:\WINDOWS\ODBC.INI
2009-09-12 02:38:51 ----N---- C:\WINDOWS\system32\spnpinst.exe
2009-09-10 15:45:28 ----HDC---- C:\WINDOWS\$NtUninstallKB899587_0$
2009-09-10 15:42:39 ----HDC---- C:\WINDOWS\$NtUninstallKB901017_0$
2009-09-10 15:42:29 ----HDC---- C:\WINDOWS\$NtUninstallKB899591_0$
2009-09-10 15:42:07 ----HDC---- C:\WINDOWS\$NtUninstallKB896424_0$
2009-09-10 15:41:57 ----HDC---- C:\WINDOWS\$NtUninstallKB893756_0$
2009-09-10 15:41:27 ----HDC---- C:\WINDOWS\$NtUninstallKB896423_0$
2009-09-10 15:41:21 ----A---- C:\WINDOWS\system32\MRT.INI
2009-09-10 15:40:12 ----A---- C:\WINDOWS\system32\MRT.exe
2009-09-10 15:39:28 ----HDC---- C:\WINDOWS\$NtUninstallKB925486-IE6SP1-20060918.120000$