richyyrich06
New member
thank you. here are the logs you requested
========== FILES ==========
C:\WINDOWS\tasks\petmtrbc.job moved successfully.
File/Folder C:\Program Files\BitTorrent not found.
File/Folder C:\Program Files\LimeWire not found.
C:\Program Files\uTorrent moved successfully.
C:\WINDOWS\system32\upazarut.tmp moved successfully.
C:\WINDOWS\system32\2336eee1-.txt moved successfully.
C:\Documents and Settings\Administrator\Application Data\uTorrent moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e440f213-1585-4087-80c8-8273e90a5443}\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\BitTorrent\bittorrent.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\LimeWire\LimeWire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\uTorrent\uTorrent.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\C:\Program Files\BitTorrent\bittorrent.exe deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_1qmFUsQTSnPu7FvyoKbE scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\02af1caa-f0fe-42f9-9d65-63166cca7d33.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\1b996f71-90b0-4659-8fcc-28c881803375.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\1d114dbf-a33c-425c-86a2-b5b9a003c145.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\26965851-5a50-4f7d-80a1-2d70a6f858a2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\45ae589a-4175-4e98-ab4e-0476905c5e18.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\598402fc-6126-48a2-9f99-c817484da3e2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\65c326b7-4684-435f-a620-7130527c4157.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\6c3289bc-eea7-4d2a-8583-ccd57ded513c.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\8a3c7454-cb14-4e80-8eb4-bde45e11c3bb.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\9016d35c-7440-40ba-a0b3-59381928566f.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a0a9d041-2dde-4147-b4c1-0c8406f2499d.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a6102f6e-d079-4d26-ba40-9bb6d07134a9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\b4364064-60a7-4f4c-a131-0a54241da3b2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\bf5f0bd1-d2c5-4d51-9381-882cc657b5de.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\c86b3fba-ceb2-4766-b11b-2c79872eb4de.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cc834b5d-578c-406a-8060-c72da10297e1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\d746a95c-defd-40e7-afed-debd3ed08cf5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\f546894d-c9b2-4018-88cf-63dc4636cc0b.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\f9be42b1-1f92-46c1-ae6b-9b0780caf9b9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite-journal scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01112009_090724
Files moved on Reboot...
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_1qmFUsQTSnPu7FvyoKbE not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\02af1caa-f0fe-42f9-9d65-63166cca7d33.tmp not found!
File C:\WINDOWS\temp\1b996f71-90b0-4659-8fcc-28c881803375.tmp not found!
File C:\WINDOWS\temp\1d114dbf-a33c-425c-86a2-b5b9a003c145.tmp not found!
File C:\WINDOWS\temp\26965851-5a50-4f7d-80a1-2d70a6f858a2.tmp not found!
File C:\WINDOWS\temp\45ae589a-4175-4e98-ab4e-0476905c5e18.tmp not found!
File C:\WINDOWS\temp\598402fc-6126-48a2-9f99-c817484da3e2.tmp not found!
File C:\WINDOWS\temp\65c326b7-4684-435f-a620-7130527c4157.tmp not found!
File C:\WINDOWS\temp\6c3289bc-eea7-4d2a-8583-ccd57ded513c.tmp not found!
File C:\WINDOWS\temp\8a3c7454-cb14-4e80-8eb4-bde45e11c3bb.tmp not found!
File C:\WINDOWS\temp\9016d35c-7440-40ba-a0b3-59381928566f.tmp not found!
File C:\WINDOWS\temp\a0a9d041-2dde-4147-b4c1-0c8406f2499d.tmp not found!
File C:\WINDOWS\temp\a6102f6e-d079-4d26-ba40-9bb6d07134a9.tmp not found!
File C:\WINDOWS\temp\b4364064-60a7-4f4c-a131-0a54241da3b2.tmp not found!
File C:\WINDOWS\temp\bf5f0bd1-d2c5-4d51-9381-882cc657b5de.tmp not found!
File C:\WINDOWS\temp\c86b3fba-ceb2-4766-b11b-2c79872eb4de.tmp not found!
File C:\WINDOWS\temp\cc834b5d-578c-406a-8060-c72da10297e1.tmp not found!
C:\WINDOWS\temp\d746a95c-defd-40e7-afed-debd3ed08cf5.tmp moved successfully.
C:\WINDOWS\temp\f546894d-c9b2-4018-88cf-63dc4636cc0b.tmp moved successfully.
File C:\WINDOWS\temp\f9be42b1-1f92-46c1-ae6b-9b0780caf9b9.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat not found!
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite moved successfully.
File C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite-journal not found!
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\XUL.mfl moved successfully.
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2009-01-11 09:17:09
Microsoft Windows XP Professional Service Pack 2
System drive C: has 31 GB (41%) free of 76 GB
Total RAM: 1014 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:17, on 2009-01-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon FiOS Installer.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.36.3/ttinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\Software\..\Telephony: DomainName = VFHQ.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = VFHQ.local
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Radialpoint Unicorn Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Verizon\PC Security Checkup\rpsupdaterR.exe
--
End of file - 4899 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GlaryInitialize.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ca2f312-6f6e-4b53-a66e-4e65e497c8c0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-01-08 1078552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 1135968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2004-08-04 143360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-01-08 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM2b261903]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fevarezuha]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP]
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe [2006-03-23 1591808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-31 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
C:\WINDOWS\system32\mobsync.exe [2004-08-04 143360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Verizon_McciTrayApp]
C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
C:\PROGRA~1\SYMANT~1\VPTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe [2003-05-15 217193]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SideACT!.lnk]
C:\PROGRA~1\ACT\SideACT.exe [2003-04-24 278589]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3
"Apple Mobile Device"=2
"aawservice"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-01-08 10520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-09-20 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-02-08 219664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Documents and Settings\Administrator\Application Data\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\Administrator\Application Data\SopCast\adv\SopAdver.exe:*
isabled:SopCast Adver"
"C:\Program Files\Wolfenstein - Enemy Territory\ET.exe"="C:\Program Files\Wolfenstein - Enemy Territory\ET.exe:*:Enabled:ET"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\AVG\AVG8\avgam.exe"="C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled
xpsp2res.dll,-22019"
"C:\Program Files\Trillian\trillian.exe"="C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
======List of files/folders created in the last 1 months======
2009-01-11 09:07:24 ----D---- C:\_OTMoveIt
2009-01-10 14:12:20 ----D---- C:\rsit
2009-01-10 12:49:22 ----D---- C:\combo-fix
2009-01-10 12:49:22 ----A---- C:\WINDOWS\system32\CF7723.exe
2009-01-10 12:42:51 ----D---- C:\ComboFix
2009-01-10 12:42:50 ----A---- C:\WINDOWS\system32\CF6450.exe
2009-01-10 12:41:13 ----A---- C:\WINDOWS\system32\CF6136.exe
2009-01-10 12:40:41 ----A---- C:\WINDOWS\system32\CF6016.exe
2009-01-10 12:34:17 ----A---- C:\WINDOWS\PSEXESVC.EXE
2009-01-10 12:29:11 ----A---- C:\WINDOWS\system32\CF3769.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\zip.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\VFIND.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWSC.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWREG.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\sed.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\grep.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\fdsv.exe
2009-01-10 12:16:28 ----D---- C:\WINDOWS\ERDNT
2009-01-10 12:16:28 ----D---- C:\Qoobox
2009-01-05 23:02:31 ----D---- C:\Program Files\Google
2009-01-03 23:52:28 ----HD---- C:\$AVG8.VAULT$
2009-01-03 23:47:10 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-01-03 23:45:15 ----D---- C:\Program Files\AVG
2009-01-03 23:45:15 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-01-03 23:45:15 ----A---- C:\WINDOWS\system32\avgfwdx.dll
2009-01-03 23:25:11 ----D---- C:\Program Files\Kaspersky Lab
2009-01-03 21:07:24 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-01-03 17:54:54 ----A---- C:\WINDOWS\system32\nokye.exe
2009-01-03 17:50:06 ----SHD---- C:\WINDOWS\system32\twain32
2009-01-03 17:48:55 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-03 16:31:39 ----D---- C:\Program Files\SpeedFan
2009-01-03 16:22:30 ----D---- C:\Program Files\Motherboard Monitor 5
2009-01-03 15:40:43 ----D---- C:\Documents and Settings\Administrator\Application Data\GlarySoft
2009-01-03 15:37:05 ----D---- C:\Program Files\Glary Utilities
2009-01-03 15:30:59 ----D---- C:\Program Files\YourWare Solutions
2009-01-03 15:00:02 ----A---- C:\WINDOWS\ntbtlog.txt
2009-01-02 18:27:44 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-01-02 18:27:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-02 18:27:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\java.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-27 22:27:45 ----SHD---- C:\Config.Msi
2008-12-27 19:33:13 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-12-27 19:29:59 ----D---- C:\Program Files\Trend Micro
2008-12-25 14:32:20 ----D---- C:\Documents and Settings\Administrator\Application Data\Home Sweet Home 2
2008-12-24 20:36:45 ----D---- C:\Documents and Settings\Administrator\Application Data\Home Sweet Home Christmas
2008-12-21 22:36:46 ----D---- C:\Documents and Settings\Administrator\Application Data\CatmoonGames
2008-12-17 20:11:46 ----D---- C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-12-16 20:00:41 ----D---- C:\Documents and Settings\All Users\Application Data\HipSoft
======List of files/folders modified in the last 1 months======
2009-01-11 09:17:18 ----D---- C:\WINDOWS\Prefetch
2009-01-11 09:16:50 ----D---- C:\WINDOWS\Temp
2009-01-11 09:13:53 ----D---- C:\Program Files\Mozilla Firefox
2009-01-11 09:12:28 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-11 09:11:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-11 09:07:24 ----SD---- C:\WINDOWS\Tasks
2009-01-11 09:07:24 ----RD---- C:\Program Files
2009-01-11 09:07:24 ----D---- C:\WINDOWS\system32
2009-01-10 13:04:41 ----D---- C:\WINDOWS\system32\drivers
2009-01-10 13:00:42 ----SHD---- C:\WINDOWS\CSC
2009-01-10 12:34:29 ----D---- C:\WINDOWS\system32\config
2009-01-10 12:34:17 ----D---- C:\WINDOWS
2009-01-10 12:32:05 ----D---- C:\WINDOWS\AppPatch
2009-01-10 12:32:05 ----D---- C:\Program Files\Common Files
2009-01-10 12:23:38 ----RASH---- C:\boot.ini
2009-01-10 12:23:38 ----A---- C:\WINDOWS\win.ini
2009-01-10 12:23:38 ----A---- C:\WINDOWS\system.ini
2009-01-10 12:23:29 ----D---- C:\WINDOWS\pss
2009-01-10 10:35:07 ----SHD---- C:\WINDOWS\Installer
2009-01-09 11:22:19 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-01-09 11:22:02 ----A---- C:\WINDOWS\system32\svchost.exe
2009-01-04 10:07:17 ----HD---- C:\WINDOWS\inf
2009-01-03 23:47:31 ----D---- C:\Documents and Settings
2009-01-03 23:42:24 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-03 17:52:49 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-03 17:51:17 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 17:14:17 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-01-03 17:13:18 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-01-03 17:09:04 ----D---- C:\Program Files\vPod
2009-01-03 17:08:58 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-01-03 17:07:01 ----D---- C:\Program Files\SopCast
2009-01-03 17:05:22 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-01-03 17:03:53 ----D---- C:\Program Files\Dell
2009-01-03 17:00:55 ----D---- C:\Program Files\THQ
2009-01-03 16:56:35 ----D---- C:\Program Files\VstPlugins
2009-01-03 16:55:06 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-03 16:54:56 ----D---- C:\Program Files\Electronic Arts
2009-01-03 16:54:34 ----D---- C:\Program Files\DivX
2009-01-03 16:53:51 ----A---- C:\WINDOWS\disney.ini
2009-01-03 16:53:07 ----A---- C:\WINDOWS\hegames.ini
2009-01-03 16:52:14 ----D---- C:\Documents and Settings\All Users\Application Data\America's Army Deploy Client
2009-01-03 13:04:29 ----D---- C:\Program Files\Winamp Remote
2009-01-02 14:26:39 ----D---- C:\Program Files\PetLuvSpaResort
2008-12-31 12:04:00 ----D---- C:\Program Files\Java
2008-12-28 02:36:26 ----D---- C:\WINDOWS\Registration
2008-12-27 19:26:45 ----D---- C:\WINDOWS\Debug
2008-12-26 21:19:25 ----A---- C:\WINDOWS\wininit.ini
2008-12-25 19:36:52 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-16 20:04:05 ----D---- C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-12-16 20:04:05 ----D---- C:\Documents and Settings\Administrator\Application Data\PlayFirst
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgldx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-01-08 324872]
R1 avgmfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-01-08 27656]
R1 avgtdix;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-01-08 107272]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R2 CSS DVP;Dynamic Virus Protection; C:\WINDOWS\system32\DRIVERS\css-dvp.sys [2007-04-04 839880]
R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2004-05-17 41984]
R2 MCSTRM;MCSTRM; C:\WINDOWS\system32\drivers\MCSTRM.sys [2007-11-03 8413]
R2 npkcrypt;npkcrypt; \??\C:\Nexon\MapleStory\npkcrypt.sys []
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 avgfwdx;avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-01-03 29208]
R3 b57w2k;Broadcom NetXtreme 57xx Gigabit Controller; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-04-01 132608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-09-20 1302332]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 senfilt;senfilt; C:\WINDOWS\system32\drivers\senfilt.sys [2004-09-17 732928]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2005-01-27 260352]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-10-25 27264]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 8abdeee6;8abdeee6; C:\WINDOWS\System32\drivers\8abdeee6.sys []
S1 f542623;f542623; C:\WINDOWS\System32\drivers\f542623.sys []
S3 avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-01-03 29208]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-04 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2008-05-21 34576]
S3 npkcusb;npkcusb; \??\C:\Nexon\MapleStory\npkcusb.sys []
S3 npkycryp;npkycryp; \??\C:\Nexon\MapleStory\npkycryp.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2007-10-31 30464]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 42240]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-01-08 298264]
R2 avgfws8;AVG8 Firewall; C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2009-01-08 1339600]
R2 dvpapi;DvpApi; C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe [2007-04-04 177672]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-31 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Radialpoint Security Services;Radialpoint Security Services; C:\WINDOWS\system32\dllhost.exe [2004-08-04 5120]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2008-05-21 92792]
S3 RPSUpdaterR;Radialpoint Unicorn Update Service; C:\Program Files\Verizon\PC Security Checkup\rpsupdaterR.exe [2008-03-17 99056]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2009-01-09 14336]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
S4 ipod service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
-----------------EOF-----------------
========== FILES ==========
C:\WINDOWS\tasks\petmtrbc.job moved successfully.
File/Folder C:\Program Files\BitTorrent not found.
File/Folder C:\Program Files\LimeWire not found.
C:\Program Files\uTorrent moved successfully.
C:\WINDOWS\system32\upazarut.tmp moved successfully.
C:\WINDOWS\system32\2336eee1-.txt moved successfully.
C:\Documents and Settings\Administrator\Application Data\uTorrent moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{e440f213-1585-4087-80c8-8273e90a5443}\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\BitTorrent\bittorrent.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\LimeWire\LimeWire.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list\\C:\Program Files\uTorrent\uTorrent.exe deleted successfully.
Registry value HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list\\C:\Program Files\BitTorrent\bittorrent.exe deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_1qmFUsQTSnPu7FvyoKbE scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\02af1caa-f0fe-42f9-9d65-63166cca7d33.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\1b996f71-90b0-4659-8fcc-28c881803375.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\1d114dbf-a33c-425c-86a2-b5b9a003c145.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\26965851-5a50-4f7d-80a1-2d70a6f858a2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\45ae589a-4175-4e98-ab4e-0476905c5e18.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\598402fc-6126-48a2-9f99-c817484da3e2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\65c326b7-4684-435f-a620-7130527c4157.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\6c3289bc-eea7-4d2a-8583-ccd57ded513c.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\8a3c7454-cb14-4e80-8eb4-bde45e11c3bb.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\9016d35c-7440-40ba-a0b3-59381928566f.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a0a9d041-2dde-4147-b4c1-0c8406f2499d.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\a6102f6e-d079-4d26-ba40-9bb6d07134a9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\b4364064-60a7-4f4c-a131-0a54241da3b2.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\bf5f0bd1-d2c5-4d51-9381-882cc657b5de.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\c86b3fba-ceb2-4766-b11b-2c79872eb4de.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cc834b5d-578c-406a-8060-c72da10297e1.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\d746a95c-defd-40e7-afed-debd3ed08cf5.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\f546894d-c9b2-4018-88cf-63dc4636cc0b.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\f9be42b1-1f92-46c1-ae6b-9b0780caf9b9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite-journal scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01112009_090724
Files moved on Reboot...
File C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\etilqs_1qmFUsQTSnPu7FvyoKbE not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
File C:\WINDOWS\temp\02af1caa-f0fe-42f9-9d65-63166cca7d33.tmp not found!
File C:\WINDOWS\temp\1b996f71-90b0-4659-8fcc-28c881803375.tmp not found!
File C:\WINDOWS\temp\1d114dbf-a33c-425c-86a2-b5b9a003c145.tmp not found!
File C:\WINDOWS\temp\26965851-5a50-4f7d-80a1-2d70a6f858a2.tmp not found!
File C:\WINDOWS\temp\45ae589a-4175-4e98-ab4e-0476905c5e18.tmp not found!
File C:\WINDOWS\temp\598402fc-6126-48a2-9f99-c817484da3e2.tmp not found!
File C:\WINDOWS\temp\65c326b7-4684-435f-a620-7130527c4157.tmp not found!
File C:\WINDOWS\temp\6c3289bc-eea7-4d2a-8583-ccd57ded513c.tmp not found!
File C:\WINDOWS\temp\8a3c7454-cb14-4e80-8eb4-bde45e11c3bb.tmp not found!
File C:\WINDOWS\temp\9016d35c-7440-40ba-a0b3-59381928566f.tmp not found!
File C:\WINDOWS\temp\a0a9d041-2dde-4147-b4c1-0c8406f2499d.tmp not found!
File C:\WINDOWS\temp\a6102f6e-d079-4d26-ba40-9bb6d07134a9.tmp not found!
File C:\WINDOWS\temp\b4364064-60a7-4f4c-a131-0a54241da3b2.tmp not found!
File C:\WINDOWS\temp\bf5f0bd1-d2c5-4d51-9381-882cc657b5de.tmp not found!
File C:\WINDOWS\temp\c86b3fba-ceb2-4766-b11b-2c79872eb4de.tmp not found!
File C:\WINDOWS\temp\cc834b5d-578c-406a-8060-c72da10297e1.tmp not found!
C:\WINDOWS\temp\d746a95c-defd-40e7-afed-debd3ed08cf5.tmp moved successfully.
C:\WINDOWS\temp\f546894d-c9b2-4018-88cf-63dc4636cc0b.tmp moved successfully.
File C:\WINDOWS\temp\f9be42b1-1f92-46c1-ae6b-9b0780caf9b9.tmp not found!
File C:\WINDOWS\temp\Perflib_Perfdata_1d8.dat not found!
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite moved successfully.
File C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\urlclassifier3.sqlite-journal not found!
C:\Documents and Settings\Administrator\Local Settings\Application Data\Mozilla\Firefox\Profiles\ptmed5ub.default\XUL.mfl moved successfully.
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2009-01-11 09:17:09
Microsoft Windows XP Professional Service Pack 2
System drive C: has 31 GB (41%) free of 76 GB
Total RAM: 1014 MB (54% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:17, on 2009-01-11
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cox.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - C:\Program Files\AVG\AVG8\avgssie.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files\Winamp Toolbar\winamptb.dll
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobsync.exe /logon
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Documents and Settings\All Users\Application Data\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommon/download/FIOS/Verizon FiOS Installer.cab
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=67633
O16 - DPF: {C02226EB-A5D7-4B1F-BD7E-635E46C2288D} (Toontown Installer ActiveX Control) - http://a.download.toontown.com/sv1.0.36.3/ttinst.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\Software\..\Telephony: DomainName = VFHQ.local
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = VFHQ.local
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: Domain = VFHQ.local
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Radialpoint Unicorn Update Service (RPSUpdaterR) - Radialpoint Inc. - C:\Program Files\Verizon\PC Security Checkup\rpsupdaterR.exe
--
End of file - 4899 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\GlaryInitialize.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3ca2f312-6f6e-4b53-a66e-4e65e497c8c0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-01-08 1078552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll [2003-05-15 147456]
{EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - Winamp Toolbar - C:\Program Files\Winamp Toolbar\winamptb.dll [2007-10-04 1135968]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Synchronization Manager"=C:\WINDOWS\system32\mobsync.exe [2004-08-04 143360]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-01-08 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BM2b261903]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
C:\Program Files\Common Files\Symantec Shared\ccApp.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\fevarezuha]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FreeRAM XP]
C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe [2006-03-23 1591808]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-10-01 289576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-31 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
C:\WINDOWS\system32\mobsync.exe [2004-08-04 143360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UserFaultCheck]
C:\WINDOWS\system32\dumprep 0 -u []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VerizonServicepoint.exe]
C:\Program Files\Verizon\VSP\VerizonServicepoint.exe [2008-02-13 2065648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Verizon_McciTrayApp]
C:\Program Files\Verizon\McciTrayApp.exe [2007-09-28 936960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vptray]
C:\PROGRA~1\SYMANT~1\VPTray.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Administrator^Start Menu^Programs^Startup^PowerReg Scheduler.exe]
[]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Acrobat Assistant.lnk]
C:\PROGRA~1\Adobe\ACROBA~1.0\Distillr\acrotray.exe [2003-05-15 217193]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~2\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^SideACT!.lnk]
C:\PROGRA~1\ACT\SideACT.exe [2003-04-24 278589]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPod Service"=3
"Apple Mobile Device"=2
"aawservice"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-01-08 10520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2005-09-20 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-02-08 219664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\procexp90.Sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

"C:\Program Files\Common Files\AOL\Loader\aolload.exe"="C:\Program Files\Common Files\AOL\Loader\aolload.exe:*:Enabled:AOL Loader"
"C:\Program Files\AIM\aim.exe"="C:\Program Files\AIM\aim.exe:*:Enabled:AOL Instant Messenger"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Enabled:SopCast Main Application"
"C:\Documents and Settings\Administrator\Application Data\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\Administrator\Application Data\SopCast\adv\SopAdver.exe:*

"C:\Program Files\Wolfenstein - Enemy Territory\ET.exe"="C:\Program Files\Wolfenstein - Enemy Territory\ET.exe:*:Enabled:ET"
"C:\Program Files\Winamp Remote\bin\Orb.exe"="C:\Program Files\Winamp Remote\bin\Orb.exe:*:Enabled:Orb"
"C:\Program Files\Winamp Remote\bin\OrbTray.exe"="C:\Program Files\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray"
"C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\AVG\AVG8\avgam.exe"="C:\Program Files\AVG\AVG8\avgam.exe:*:Enabled:avgam.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

"C:\Program Files\Trillian\trillian.exe"="C:\Program Files\Trillian\trillian.exe:*:Enabled:Trillian"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Windows Media Player\wmplayer.exe"="C:\Program Files\Windows Media Player\wmplayer.exe:*:Enabled:Windows Media Player"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
======List of files/folders created in the last 1 months======
2009-01-11 09:07:24 ----D---- C:\_OTMoveIt
2009-01-10 14:12:20 ----D---- C:\rsit
2009-01-10 12:49:22 ----D---- C:\combo-fix
2009-01-10 12:49:22 ----A---- C:\WINDOWS\system32\CF7723.exe
2009-01-10 12:42:51 ----D---- C:\ComboFix
2009-01-10 12:42:50 ----A---- C:\WINDOWS\system32\CF6450.exe
2009-01-10 12:41:13 ----A---- C:\WINDOWS\system32\CF6136.exe
2009-01-10 12:40:41 ----A---- C:\WINDOWS\system32\CF6016.exe
2009-01-10 12:34:17 ----A---- C:\WINDOWS\PSEXESVC.EXE
2009-01-10 12:29:11 ----A---- C:\WINDOWS\system32\CF3769.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\zip.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\VFIND.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWSC.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\SWREG.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\sed.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\grep.exe
2009-01-10 12:22:01 ----A---- C:\WINDOWS\fdsv.exe
2009-01-10 12:16:28 ----D---- C:\WINDOWS\ERDNT
2009-01-10 12:16:28 ----D---- C:\Qoobox
2009-01-05 23:02:31 ----D---- C:\Program Files\Google
2009-01-03 23:52:28 ----HD---- C:\$AVG8.VAULT$
2009-01-03 23:47:10 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2009-01-03 23:45:15 ----D---- C:\Program Files\AVG
2009-01-03 23:45:15 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-01-03 23:45:15 ----A---- C:\WINDOWS\system32\avgfwdx.dll
2009-01-03 23:25:11 ----D---- C:\Program Files\Kaspersky Lab
2009-01-03 21:07:24 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-01-03 17:54:54 ----A---- C:\WINDOWS\system32\nokye.exe
2009-01-03 17:50:06 ----SHD---- C:\WINDOWS\system32\twain32
2009-01-03 17:48:55 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
2009-01-03 16:31:39 ----D---- C:\Program Files\SpeedFan
2009-01-03 16:22:30 ----D---- C:\Program Files\Motherboard Monitor 5
2009-01-03 15:40:43 ----D---- C:\Documents and Settings\Administrator\Application Data\GlarySoft
2009-01-03 15:37:05 ----D---- C:\Program Files\Glary Utilities
2009-01-03 15:30:59 ----D---- C:\Program Files\YourWare Solutions
2009-01-03 15:00:02 ----A---- C:\WINDOWS\ntbtlog.txt
2009-01-02 18:27:44 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-01-02 18:27:31 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-02 18:27:31 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\java.exe
2008-12-31 12:04:46 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-27 22:27:45 ----SHD---- C:\Config.Msi
2008-12-27 19:33:13 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-12-27 19:29:59 ----D---- C:\Program Files\Trend Micro
2008-12-25 14:32:20 ----D---- C:\Documents and Settings\Administrator\Application Data\Home Sweet Home 2
2008-12-24 20:36:45 ----D---- C:\Documents and Settings\Administrator\Application Data\Home Sweet Home Christmas
2008-12-21 22:36:46 ----D---- C:\Documents and Settings\Administrator\Application Data\CatmoonGames
2008-12-17 20:11:46 ----D---- C:\Documents and Settings\All Users\Application Data\Sandlot Games
2008-12-16 20:00:41 ----D---- C:\Documents and Settings\All Users\Application Data\HipSoft
======List of files/folders modified in the last 1 months======
2009-01-11 09:17:18 ----D---- C:\WINDOWS\Prefetch
2009-01-11 09:16:50 ----D---- C:\WINDOWS\Temp
2009-01-11 09:13:53 ----D---- C:\Program Files\Mozilla Firefox
2009-01-11 09:12:28 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-11 09:11:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-11 09:07:24 ----SD---- C:\WINDOWS\Tasks
2009-01-11 09:07:24 ----RD---- C:\Program Files
2009-01-11 09:07:24 ----D---- C:\WINDOWS\system32
2009-01-10 13:04:41 ----D---- C:\WINDOWS\system32\drivers
2009-01-10 13:00:42 ----SHD---- C:\WINDOWS\CSC
2009-01-10 12:34:29 ----D---- C:\WINDOWS\system32\config
2009-01-10 12:34:17 ----D---- C:\WINDOWS
2009-01-10 12:32:05 ----D---- C:\WINDOWS\AppPatch
2009-01-10 12:32:05 ----D---- C:\Program Files\Common Files
2009-01-10 12:23:38 ----RASH---- C:\boot.ini
2009-01-10 12:23:38 ----A---- C:\WINDOWS\win.ini
2009-01-10 12:23:38 ----A---- C:\WINDOWS\system.ini
2009-01-10 12:23:29 ----D---- C:\WINDOWS\pss
2009-01-10 10:35:07 ----SHD---- C:\WINDOWS\Installer
2009-01-09 11:22:19 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-01-09 11:22:02 ----A---- C:\WINDOWS\system32\svchost.exe
2009-01-04 10:07:17 ----HD---- C:\WINDOWS\inf
2009-01-03 23:47:31 ----D---- C:\Documents and Settings
2009-01-03 23:42:24 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-03 17:52:49 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-03 17:51:17 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-01-03 17:14:17 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-01-03 17:13:18 ----D---- C:\Documents and Settings\All Users\Application Data\Symantec
2009-01-03 17:09:04 ----D---- C:\Program Files\vPod
2009-01-03 17:08:58 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-01-03 17:07:01 ----D---- C:\Program Files\SopCast
2009-01-03 17:05:22 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-01-03 17:03:53 ----D---- C:\Program Files\Dell
2009-01-03 17:00:55 ----D---- C:\Program Files\THQ
2009-01-03 16:56:35 ----D---- C:\Program Files\VstPlugins
2009-01-03 16:55:06 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-03 16:54:56 ----D---- C:\Program Files\Electronic Arts
2009-01-03 16:54:34 ----D---- C:\Program Files\DivX
2009-01-03 16:53:51 ----A---- C:\WINDOWS\disney.ini
2009-01-03 16:53:07 ----A---- C:\WINDOWS\hegames.ini
2009-01-03 16:52:14 ----D---- C:\Documents and Settings\All Users\Application Data\America's Army Deploy Client
2009-01-03 13:04:29 ----D---- C:\Program Files\Winamp Remote
2009-01-02 14:26:39 ----D---- C:\Program Files\PetLuvSpaResort
2008-12-31 12:04:00 ----D---- C:\Program Files\Java
2008-12-28 02:36:26 ----D---- C:\WINDOWS\Registration
2008-12-27 19:26:45 ----D---- C:\WINDOWS\Debug
2008-12-26 21:19:25 ----A---- C:\WINDOWS\wininit.ini
2008-12-25 19:36:52 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-12-16 20:04:05 ----D---- C:\Documents and Settings\All Users\Application Data\PlayFirst
2008-12-16 20:04:05 ----D---- C:\Documents and Settings\Administrator\Application Data\PlayFirst
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgldx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-01-08 324872]
R1 avgmfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-01-08 27656]
R1 avgtdix;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-01-08 107272]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys []
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2004-08-03 14848]
R1 mbmiodrvr;mbmiodrvr; \??\C:\WINDOWS\system32\mbmiodrvr.sys []
R2 CSS DVP;Dynamic Virus Protection; C:\WINDOWS\system32\DRIVERS\css-dvp.sys [2007-04-04 839880]
R2 DgiVecp;Team MFP Comm Driver; C:\WINDOWS\System32\Drivers\DgiVecp.sys [2004-05-17 41984]
R2 MCSTRM;MCSTRM; C:\WINDOWS\system32\drivers\MCSTRM.sys [2007-11-03 8413]
R2 npkcrypt;npkcrypt; \??\C:\Nexon\MapleStory\npkcrypt.sys []
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 avgfwdx;avgfwdx; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-01-03 29208]
R3 b57w2k;Broadcom NetXtreme 57xx Gigabit Controller; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2005-04-01 132608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2005-09-20 1302332]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 senfilt;senfilt; C:\WINDOWS\system32\drivers\senfilt.sys [2004-09-17 732928]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2005-01-27 260352]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2005-10-25 27264]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-03 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-03 20480]
S1 8abdeee6;8abdeee6; C:\WINDOWS\System32\drivers\8abdeee6.sys []
S1 f542623;f542623; C:\WINDOWS\System32\drivers\f542623.sys []
S3 avgfwfd;AVG network filter service; C:\WINDOWS\system32\DRIVERS\avgfwdx.sys [2009-01-03 29208]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2004-08-04 40320]
S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2008-05-21 34576]
S3 npkcusb;npkcusb; \??\C:\Nexon\MapleStory\npkcusb.sys []
S3 npkycryp;npkycryp; \??\C:\Nexon\MapleStory\npkycryp.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\WINDOWS\system32\DRIVERS\s616bus.sys [2007-04-03 83208]
S3 s616mdfl;Sony Ericsson Device 616 USB WMC Modem Filter; C:\WINDOWS\system32\DRIVERS\s616mdfl.sys [2007-04-03 15112]
S3 s616mdm;Sony Ericsson Device 616 USB WMC Modem Driver; C:\WINDOWS\system32\DRIVERS\s616mdm.sys [2007-04-03 108680]
S3 s616mgmt;Sony Ericsson Device 616 USB WMC Device Management Drivers (WDM); C:\WINDOWS\system32\DRIVERS\s616mgmt.sys [2007-04-03 100360]
S3 s616nd5;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (NDIS); C:\WINDOWS\system32\DRIVERS\s616nd5.sys [2007-04-03 23176]
S3 s616obex;Sony Ericsson Device 616 USB WMC OBEX Interface; C:\WINDOWS\system32\DRIVERS\s616obex.sys [2007-04-03 98568]
S3 s616unic;Sony Ericsson Device 616 USB Ethernet Emulation SEMC616 (WDM); C:\WINDOWS\system32\DRIVERS\s616unic.sys [2007-04-03 99080]
S3 USBAAPL;Apple Mobile USB Driver; C:\WINDOWS\System32\Drivers\usbaapl.sys [2007-10-31 30464]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 agp440;Intel AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agp440.sys [2004-08-03 42368]
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\agpCPQ.sys [2004-08-03 44928]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\alim1541.sys [2004-08-03 42752]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\system32\DRIVERS\amdagp.sys [2004-08-03 43008]
S4 cbidf;cbidf; C:\WINDOWS\system32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\DRIVERS\intelide.sys [2004-08-03 5504]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\sisagp.sys [2004-08-03 41088]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\system32\DRIVERS\viaagp.sys [2004-08-03 42240]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-04 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-01-08 298264]
R2 avgfws8;AVG8 Firewall; C:\PROGRA~1\AVG\AVG8\avgfws8.exe [2009-01-08 1339600]
R2 dvpapi;DvpApi; C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exe [2007-04-04 177672]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-31 152984]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2009-01-09 14336]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2004-08-04 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 Radialpoint Security Services;Radialpoint Security Services; C:\WINDOWS\system32\dllhost.exe [2004-08-04 5120]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2008-05-21 92792]
S3 RPSUpdaterR;Radialpoint Unicorn Update Service; C:\Program Files\Verizon\PC Security Checkup\rpsupdaterR.exe [2008-03-17 99056]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2009-01-09 14336]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-10-01 116040]
S4 ipod service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-10-01 536872]
-----------------EOF-----------------