Logs
Below are the requested logs. I will update on performance once I restart. Thank you so much.
Malwarebytes' Anti-Malware 1.28
Database version: 1268
Windows 5.1.2600 Service Pack 3
10/14/2008 12:00:46 PM
mbam-log-2008-10-14 (12-00-46).txt
Scan type: Full Scan (C:\|)
Objects scanned: 165121
Time elapsed: 46 minute(s), 22 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Unloaded process successfully.
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{87255c51-cd7d-4506-b9ad-97606daf53f3} (Adware.Coupons) -> Quarantined and deleted successfully.
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Tasks\SysFile.brk (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\svchost.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\RECYCLER\ADAPT_Installer.exe (Heuristics.Malware) -> Quarantined and deleted successfully.
Logfile of random's system information tool 1.04 (written by random/random)
Run by Big Stan at 2008-10-14 12:06:40
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 7 GB (10%) free of 71 GB
Total RAM: 2047 MB (69% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:06:58 PM, on 10/14/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe
C:\WINDOWS\System32\nvraidservice.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe
C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe
C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\CAPPActiveProtection.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.exe
C:\Program Files\OpenOffice.org 2.4\program\soffice.BIN
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
C:\WINDOWS\System32\wbem\unsecapp.exe
C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Big Stan\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Big Stan.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.rr.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Road Runner High Speed Online
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost;<local>;*.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\System32\nvraidservice.exe
O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe"
O4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"
O4 - HKLM\..\Run: [QOELOADER] "C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe"
O4 - HKLM\..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe -cl
O4 - HKLM\..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe
O4 - HKLM\..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - Startup: OpenOffice.org 2.4.lnk = C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01111C00-3E00-11D2-8470-0060089874ED} (Support.com ActionRunner Class) -
http://www.help.rr.com/Foundrysdccommon/download/tgctlar.cab
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) -
http://supportcenter.rr.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
https://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe
O23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe
O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\System32\lxbxcoms.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe
O23 - Service: SupportSoft Sprocket Service (medicsp2) (sprtsvc_medicsp2) - SupportSoft, Inc. - C:\Program Files\twc\medicsp2\bin\sprtsvc.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\supportsoft\bin\ssrc.exe
O23 - Service: HIPS Event Manager (UmxAgent) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe
O23 - Service: HIPS Configuration Interpreter (UmxCfg) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe
O23 - Service: HIPS Firewall Helper (UmxFwHlp) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe
O23 - Service: HIPS Policy Manager (UmxPol) - CA - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe
O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe
--
End of file - 7725 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Big Stan at 11 46 AM.job
C:\WINDOWS\tasks\Uniblue SpeedUpMyPC Nag.job
C:\WINDOWS\tasks\Uniblue SpeedUpMyPC.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NVRaidService"=C:\WINDOWS\System32\nvraidservice.exe [2004-11-03 84480]
"CAVRID"=C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\CAVRID.exe [2007-08-20 230664]
"cctray"=C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe [2007-08-16 177416]
"QOELOADER"=C:\Program Files\CA\eTrust EZ Armor\eTrust Anti-Spam\QSP-5.1.18.0\QOELoader.exe [2008-05-16 14088]
"cafwc"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe [2008-07-31 1193200]
"capfasem"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe [2008-07-31 173296]
""= []
"capfupgrade"=C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe [2008-07-31 259312]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2007-09-11 8491008]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2008-09-10 289576]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zone Labs Client]
C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Firewall\ca.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech SetPoint.lnk]
C:\PROGRA~1\Logitech\SetPoint\SetPoint.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VETMSGNT"=2
"vsmon"=2
"usnjsvc"=3
C:\Documents and Settings\Big Stan\Start Menu\Programs\Startup
OpenOffice.org 2.4.lnk - C:\Program Files\OpenOffice.org 2.4\program\quickstart.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\PFW]
C:\WINDOWS\system32\UmxWnp.Dll [2007-05-18 79368]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-03-15 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-13 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:World of Warcraft"
"C:\Program Files\AvRack\rtlrack.exe"="C:\Program Files\AvRack\rtlrack.exe:*:Enabled:AvRack"
"C:\Program Files\twc\medicsp2\bin\sprtsvc.exe"="C:\Program Files\twc\medicsp2\bin\sprtsvc.exe:*:Enabled:sprtsvc.exe"
"C:\Program Files\HERACTSTG\smartaccess\bcont.exe"="C:\Program Files\HERACTSTG\smartaccess\bcont.exe:*:Enabled:bcont.exe"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Mozilla Firefox"
"C:\Program Files\Maxis\SimCity 3000 Unlimited\Apps\Updater\UPDATER.EXE"="C:\Program Files\Maxis\SimCity 3000 Unlimited\Apps\Updater\UPDATER.EXE:*

isabled:SC3UpdaterMFC"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\Minions of Mirth\bin\MinionsOfMirth.exe"="C:\Program Files\Minions of Mirth\bin\MinionsOfMirth.exe:*:Enabled:MinionsOfMirth"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype. Take a deep breath "
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\Minions of Mirth\bin\MinionsOfMirth.exe"="C:\Program Files\Minions of Mirth\bin\MinionsOfMirth.exe:*:Enabled:MinionsOfMirth"
======List of files/folders created in the last 3 months======
2008-10-14 12:06:40 ----D---- C:\rsit
2008-10-14 11:10:06 ----D---- C:\Documents and Settings\Big Stan\Application Data\Malwarebytes
2008-10-14 11:10:03 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-10-14 11:10:02 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-14 02:39:47 ----D---- C:\Program Files\ProcessExplorer
2008-10-14 01:30:04 ----D---- C:\Program Files\Trend Micro
2008-10-13 22:44:06 ----A---- C:\WINDOWS\svchost.exe
2008-10-13 20:34:02 ----A---- C:\WINDOWS\1.ini
2008-10-13 16:59:19 ----A---- C:\WINDOWS\wininit.ini
2008-10-13 16:07:19 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2008-10-13 16:07:19 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2008-10-13 14:24:32 ----D---- C:\Documents and Settings\Big Stan\Application Data\MSN6
2008-10-13 14:11:07 ----A---- C:\WINDOWS\system32\atlcom829_127.dll
2008-10-01 18:04:46 ----D---- C:\Program Files\Common Files\Skype
2008-09-17 08:47:18 ----D---- C:\Program Files\iPod
2008-09-17 08:47:17 ----D---- C:\Program Files\iTunes
2008-09-17 08:47:17 ----D---- C:\Documents and Settings\All Users\Application Data\{3276BE95_AF08_429F_A64F_CA64CB79BCF6}
2008-09-17 08:42:34 ----D---- C:\Program Files\Bonjour
2008-09-17 08:41:59 ----D---- C:\Program Files\QuickTime
2008-09-15 14:30:03 ----A---- C:\WINDOWS\system32\DEBUG_LOG.txt
2008-09-15 03:05:10 ----D---- C:\Program Files\World of Warcraft Public Test
2008-09-14 17:24:54 ----D---- C:\Documents and Settings\All Users\Application Data\Blizzard
2008-09-13 17:06:19 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-09-13 14:06:01 ----D---- C:\WINDOWS\system32\Adobe
2008-09-10 05:06:35 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-08-29 10:18:58 ----A---- C:\WINDOWS\system32\dns-sd.exe
2008-08-29 09:53:50 ----A---- C:\WINDOWS\system32\dnssd.dll
2008-08-21 10:57:50 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-08-20 17:54:16 ----D---- C:\WINDOWS\Prefetch
2008-08-20 17:51:33 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2008-08-20 17:50:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-08-20 17:49:41 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-08-20 17:48:43 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-08-20 17:47:45 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-08-20 17:46:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-08-20 17:45:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-08-20 17:44:39 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-08-20 17:43:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-08-20 17:42:45 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-08-20 17:41:46 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2008-08-20 17:40:46 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-08-20 17:38:23 ----A---- C:\WINDOWS\setuplog.txt
2008-08-20 17:37:11 ----D---- C:\WINDOWS\system32\en-us
2008-08-20 17:37:09 ----D---- C:\WINDOWS\system32\scripting
2008-08-20 17:37:08 ----D---- C:\WINDOWS\l2schemas
2008-08-20 17:37:07 ----D---- C:\WINDOWS\system32\en
2008-08-20 17:31:28 ----D---- C:\WINDOWS\network diagnostic
2008-08-19 13:37:41 ----D---- C:\Program Files\MSXML 6.0
2008-08-19 13:36:24 ----N---- C:\WINDOWS\system32\xmllite.dll
2008-08-19 13:36:22 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-19 13:36:20 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-19 13:36:18 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-19 13:36:18 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-19 13:36:11 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-19 13:36:11 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-19 13:36:02 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-19 13:35:58 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-19 13:35:57 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-19 13:35:56 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-19 13:35:55 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-19 13:35:55 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-19 13:35:55 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-19 13:35:54 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-19 13:35:51 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-19 13:35:44 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-19 13:35:44 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-19 13:35:44 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-19 13:35:41 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-19 13:35:41 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-19 13:35:33 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-19 13:35:33 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-19 13:35:33 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-19 13:35:32 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-19 13:35:27 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-19 13:35:26 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-19 13:35:26 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-19 13:35:26 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-19 13:35:26 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-19 13:35:25 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-19 13:35:16 ----A---- C:\WINDOWS\005459_.tmp
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-19 13:35:15 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-19 13:35:13 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-19 13:35:12 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-19 13:35:12 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-19 13:35:11 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-19 13:35:10 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-19 13:35:07 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-19 13:35:06 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-19 13:35:00 ----N---- C:\WINDOWS\system32\aaclient.dll
2008-08-18 09:28:09 ----D---- C:\Documents and Settings\Big Stan\Application Data\OpenOffice.org2
2008-08-18 09:21:51 ----D---- C:\Program Files\OpenOffice.org 2.4
2008-08-18 09:21:33 ----A---- C:\WINDOWS\system32\javaws.exe
2008-08-18 09:21:33 ----A---- C:\WINDOWS\system32\javaw.exe
2008-08-18 09:21:33 ----A---- C:\WINDOWS\system32\java.exe
2008-08-14 06:38:17 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$
2008-08-14 06:38:10 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$
2008-08-14 06:38:02 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$
2008-08-14 06:37:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$
2008-08-14 06:36:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-08-14 06:36:12 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$
2008-08-14 06:36:04 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$
2008-08-14 06:35:43 ----HDC---- C:\WINDOWS\$NtUninstallKB953838_0$
2008-08-04 12:40:46 ----D---- C:\Program Files\Wrath of the Lich King Beta
2008-08-04 03:43:38 ----A---- C:\WINDOWS\MegaManager.INI
2008-07-17 21:47:29 ----D---- C:\Documents and Settings\Big Stan\Application Data\Uniblue
======List of files/folders modified in the last 3 months======
2008-10-14 12:00:48 ----D---- C:\WINDOWS
2008-10-14 12:00:46 ----SD---- C:\WINDOWS\Tasks
2008-10-14 11:56:11 ----D---- C:\WINDOWS\CAVTemp
2008-10-14 11:46:56 ----D---- C:\WINDOWS\system32\CatRoot2
2008-10-14 11:11:04 ----D---- C:\WINDOWS\system32\drivers
2008-10-14 11:10:02 ----D---- C:\Program Files
2008-10-14 11:08:23 ----D---- C:\WINDOWS\system32
2008-10-14 11:05:34 ----D---- C:\WINDOWS\Temp
2008-10-14 04:50:21 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-10-13 22:27:03 ----A---- C:\WINDOWS\ntbtlog.txt
2008-10-13 16:11:56 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-10-13 16:11:44 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-10-13 16:05:30 ----D---- C:\Documents and Settings\Big Stan\Application Data\Mozilla
2008-10-13 15:54:39 ----D---- C:\Program Files\NoAdware4
2008-10-13 15:42:13 ----D---- C:\Program Files\Mozilla Firefox
2008-10-13 15:01:15 ----HD---- C:\WINDOWS\inf
2008-10-13 15:00:56 ----SHD---- C:\WINDOWS\Installer
2008-10-13 14:59:30 ----D---- C:\Documents and Settings\Big Stan\Application Data\Apple Computer
2008-10-13 14:15:04 ----D---- C:\Program Files\Full Tilt Poker
2008-10-11 12:15:20 ----D---- C:\Program Files\World of Warcraft
2008-10-10 05:41:04 ----D---- C:\Documents and Settings\Big Stan\Application Data\Skype
2008-10-09 21:07:45 ----D---- C:\Documents and Settings\Big Stan\Application Data\skypePM
2008-10-09 17:27:21 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-10-09 14:12:34 ----D---- C:\Program Files\Warcraft III
2008-10-09 11:34:14 ----D---- C:\WINDOWS\system32\Macromed
2008-10-09 10:18:48 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-01 18:04:46 ----D---- C:\Program Files\Common Files
2008-09-20 00:07:41 ----D---- C:\Documents and Settings\Big Stan\Application Data\Adobe
2008-09-20 00:07:40 ----D---- C:\Program Files\Adobe
2008-09-17 08:47:30 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-09-17 08:42:02 ----D---- C:\Program Files\Common Files\Apple
2008-09-15 03:23:17 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2008-09-13 17:06:24 ----SHD---- C:\RECYCLER
2008-09-10 05:06:35 ----D---- C:\WINDOWS\WinSxS
2008-09-05 16:26:01 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-09-04 21:15:20 ----D---- C:\WINDOWS\Help
2008-08-26 13:28:12 ----A---- C:\WINDOWS\system32\MRT.exe
2008-08-21 10:58:00 ----A---- C:\WINDOWS\imsins.BAK
2008-08-21 10:19:59 ----HD---- C:\WINDOWS\$hf_mig$
2008-08-20 23:11:23 ----D---- C:\Program Files\Apple Software Update
2008-08-20 17:56:19 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-08-20 17:55:24 ----AC---- C:\WINDOWS\OEWABLog.txt
2008-08-20 17:53:54 ----D---- C:\WINDOWS\system32\Setup
2008-08-20 17:53:53 ----RSD---- C:\WINDOWS\Fonts
2008-08-20 17:53:53 ----D---- C:\WINDOWS\system32\wbem
2008-08-20 17:53:53 ----D---- C:\WINDOWS\AppPatch
2008-08-20 17:51:47 ----D---- C:\WINDOWS\system32\CatRoot
2008-08-20 17:41:00 ----D---- C:\Program Files\Messenger
2008-08-20 17:40:17 ----D---- C:\WINDOWS\security
2008-08-20 17:37:28 ----D---- C:\WINDOWS\ime
2008-08-20 17:37:10 ----D---- C:\WINDOWS\system32\usmt
2008-08-20 17:37:08 ----D---- C:\Program Files\Internet Explorer
2008-08-20 17:37:06 ----D---- C:\WINDOWS\system32\bits
2008-08-20 17:37:06 ----D---- C:\WINDOWS\peernet
2008-08-20 17:37:06 ----D---- C:\Program Files\Movie Maker
2008-08-20 17:33:47 ----D---- C:\WINDOWS\system32\Restore
2008-08-20 17:33:46 ----D---- C:\WINDOWS\system32\npp
2008-08-20 17:33:44 ----D---- C:\WINDOWS\msagent
2008-08-20 17:33:42 ----D---- C:\WINDOWS\srchasst
2008-08-20 17:33:39 ----D---- C:\Program Files\NetMeeting
2008-08-20 17:33:37 ----D---- C:\WINDOWS\system32\Com
2008-08-20 17:33:35 ----D---- C:\Program Files\Windows Media Player
2008-08-20 17:33:34 ----D---- C:\Program Files\Windows NT
2008-08-20 17:33:34 ----D---- C:\Program Files\Outlook Express
2008-08-20 17:33:31 ----D---- C:\Program Files\Common Files\System
2008-08-20 17:33:11 ----D---- C:\WINDOWS\system32\oobe
2008-08-20 17:33:09 ----D---- C:\WINDOWS\system
2008-08-20 17:30:28 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-08-20 17:30:22 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-08-20 17:28:20 ----D---- C:\WINDOWS\EHome
2008-08-19 13:17:04 ----D---- C:\WINDOWS\Debug
2008-08-18 09:22:25 ----RSD---- C:\WINDOWS\assembly
2008-08-18 09:21:33 ----D---- C:\Program Files\Java
2008-08-01 12:34:36 ----A---- C:\caisslog.txt
2008-07-18 22:10:48 ----A---- C:\WINDOWS\system32\cdm.dll
2008-07-18 22:10:42 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-07-18 22:10:40 ----A---- C:\WINDOWS\system32\wups2.dll
2008-07-18 22:10:24 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-07-18 22:10:20 ----A---- C:\WINDOWS\system32\wups.dll
2008-07-18 22:09:46 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-07-18 22:09:44 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-07-18 22:09:44 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-07-18 22:09:42 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-07-18 22:09:42 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-07-18 22:08:34 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-07-16 23:26:01 ----D---- C:\Documents and Settings\Big Stan\Application Data\BitTorrent
2008-07-16 05:53:45 ----D---- C:\Documents and Settings\Big Stan\Application Data\DivX
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-13 14592]
R1 KmxAgent;KmxAgent; C:\WINDOWS\System32\DRIVERS\kmxagent.sys [2008-06-24 63504]
R1 KmxFile;KmxFile; C:\WINDOWS\System32\DRIVERS\KmxFile.sys [2008-06-24 45584]
R1 KmxFw;KmxFw; C:\WINDOWS\System32\DRIVERS\kmxfw.sys [2008-06-24 115216]
R1 Tcpip6;Microsoft IPv6 Protocol Driver; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225856]
R1 VETEFILE;VET File Scan Engine; C:\WINDOWS\system32\drivers\VETEFILE.sys [2008-06-04 880560]
R1 VETFDDNT;VET Floppy Boot Sector Monitor; C:\WINDOWS\system32\drivers\VETFDDNT.sys [2007-08-20 21512]
R1 VET-FILT;VET File System Filter; C:\WINDOWS\system32\drivers\VET-FILT.sys [2007-08-20 26376]
R1 VETMONNT;VET File Monitor; C:\WINDOWS\system32\drivers\VETMONNT.sys [2007-08-20 32264]
R1 VET-REC;VET File System Recognizer; C:\WINDOWS\system32\drivers\VET-REC.sys [2007-08-20 21128]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2003-03-31 12032]
R2 KmxCF;KmxCF; C:\WINDOWS\System32\DRIVERS\KmxCF.sys [2008-06-24 134648]
R2 KmxSbx;KmxSbx; C:\WINDOWS\System32\DRIVERS\KmxSbx.sys [2008-06-24 66576]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2004-11-17 2297664]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 btaudio;Bluetooth Audio Device; C:\WINDOWS\system32\drivers\btaudio.sys [2004-10-28 17024]
R3 BTDriver;Bluetooth Virtual Communications Driver; C:\WINDOWS\System32\DRIVERS\btport.sys [2004-10-28 30299]
R3 btwhid;btwhid; C:\WINDOWS\System32\DRIVERS\btwhid.sys [2004-10-28 44003]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-04-17 15464]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 Iviaspi;IVI ASPI Shell; C:\WINDOWS\system32\drivers\iviaspi.sys [2003-09-10 21060]
R3 KmxCfg;KmxCfg; C:\WINDOWS\System32\DRIVERS\kmxcfg.sys [2008-06-24 88816]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944]
R3 MTsensor;ATK0110 ACPI UTILITY; C:\WINDOWS\System32\DRIVERS\ASACPI.sys [2004-08-13 5810]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2007-09-11 6852864]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\System32\DRIVERS\NVENETFD.sys [2004-11-10 33408]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\System32\DRIVERS\nvnetbus.sys [2004-11-10 12928]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2007-04-28 47360]
R3 Pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-09-19 10368]
R3 tunmp;Microsoft Tun Miniport Adapter Driver; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-13 12288]
R3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 VETEBOOT;VET Boot Scan Engine; C:\WINDOWS\system32\drivers\VETEBOOT.sys [2008-06-04 108368]
R3 vsbus;Virtual Serial Bus Enumerator; C:\WINDOWS\System32\DRIVERS\vsb.sys [2004-09-03 18167]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\System32\DRIVERS\yk51x86.sys [2007-09-20 265856]
S3 BRIDGE;MAC Bridge; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BridgeMP;MAC Bridge Miniport; C:\WINDOWS\System32\DRIVERS\bridge.sys [2008-04-13 71552]
S3 BTWUSB;WIDCOMM USB Bluetooth Driver; C:\WINDOWS\System32\Drivers\btwusb.sys [2004-10-28 54488]
S3 iviudf;iviudf; C:\WINDOWS\system32\drivers\IviUdf.sys [2005-01-12 116224]
S3 LMouKE;Logitech SetPoint Mouse Filter Driver; C:\WINDOWS\System32\Drivers\LMouKE.sys []
S3 USB_RNDIS;USB Remote NDIS Network Device Driver; C:\WINDOWS\system32\DRIVERS\usb8023.sys [2008-04-13 12800]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 vserial;ELTIMA Virtual Serial Ports Driver; C:\WINDOWS\System32\DRIVERS\vserial.sys [2004-09-03 47104]
S4 atapi;atapi; C:\WINDOWS\system32\drivers\atapi.sys [2008-04-13 96512]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 6to4;IPv6 Helper Service; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
R2 CAISafe;CAISafe; C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\ISafe.exe [2007-08-20 144960]
R2 ITMRTSVC;CA Pest Patrol Realtime Protection Service; C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe [2007-01-04 280080]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2007-09-11 155716]
R2 SimpTcp;Simple TCP/IP Services; C:\WINDOWS\System32\tcpsvcs.exe [2003-03-31 19456]
R2 sprtsvc_medicsp2;SupportSoft Sprocket Service (medicsp2); C:\Program Files\twc\medicsp2\bin\sprtsvc.exe [2007-03-07 202280]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 UmxAgent;HIPS Event Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe [2007-10-18 1010192]
R2 UmxCfg;HIPS Configuration Interpreter; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe [2007-10-18 801296]
R2 UmxFwHlp;HIPS Firewall Helper; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe [2007-10-18 145936]
R2 UmxPol;HIPS Policy Manager; C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe [2008-06-24 281104]
R2 VETMSGNT;VET Message Service; C:\Program Files\CA\eTrust EZ Armor\eTrust EZ Antivirus\VetMsg.exe [2007-08-20 242952]
R2 wowsystemcode;Remote TCP/IPv6; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
R3 CaCCProvSP;CaCCProvSP; C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe [2007-08-16 214280]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-09-10 536872]
R3 PPCtlPriv;PPCtlPriv; C:\Program Files\CA\eTrust EZ Armor\eTrust PestPatrol\PPCtlPriv.exe [2007-08-16 189704]
S1 udffsrec;udffsrec; C:\WINDOWS\system32\drivers\udffsrec.sys [2004-12-19 5248]
S3 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-09-10 116040]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-08-29 238888]
S3 btwdins;Bluetooth Service; C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe [2004-10-28 163840]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 lxbx_device;lxbx_device; C:\WINDOWS\System32\lxbxcoms.exe [2005-01-06 462848]
S3 p2pgasvc;Peer Networking Group Authentication; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 p2pimsvc;Peer Networking Identity Manager; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 p2psvc;Peer Networking; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 PNRPSvc;Peer Name Resolution Protocol; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 SupportSoft RemoteAssist;SupportSoft RemoteAssist; C:\Program Files\Common Files\supportsoft\bin\ssrc.exe [2008-07-15 394608]
-----------------EOF-----------------
info.txt logfile of random's system information tool 1.04 2008-10-14 12:07:00
======Uninstall list======
-->"C:\Program Files\InstallShield Installation Information\{2FCE4FC5-6930-40E7-A4F1-F862207424EF}\setup.exe" REMOVEALL
-->"C:\Program Files\InstallShield Installation Information\{96BF9A2A-1835-4DEE-A94F-9EA4F77976BF}\setup.exe" --u:{96BF9A2A-1835-4DEE-A94F-9EA4F77976BF}
-->"C:\Program Files\InstallShield Installation Information\{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}\setup.exe" --u:{F366D0C4-18F2-44A6-A4E7-7ED2DD37F3D3}
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40602E2C-AB5C-4887-8093-3BFE5B8B95B3}\setup.exe" REMOVEALL
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player-->C:\WINDOWS\system32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Apple Mobile Device Support-->MsiExec.exe /I{AA9768AA-FF0B-4C66-A085-31E934F77841}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Bonjour-->MsiExec.exe /I{8A25392D-C5D2-4E79-A2BD-C15DDC5B0959}
CA Internet Security Suite-->"C:\Program Files\CA\CA Internet Security Suite\caunst.exe" /u
Combined Community Codec Pack 2006-12-15-->"C:\Program Files\Combined Community Codec Pack\unins000.exe"
ConvertXtoDVD 2.1.18.242-->"C:\Program Files\VSO\ConvertXtoDVD\unins000.exe"
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
EVGA Display Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BEF3EFE7-5159-436D-9BF0-CCC633179EB4}\Setup.exe" -l0x9 -removeonly
Full Tilt Poker-->"C:\Program Files\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x0009 -removeonly
Fung Wan Online-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{334098FE-8BD9-4B60-B0C3-07D39EE0F870}\Setup.exe" -l0x9
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe"
InterActual Player-->C:\Program Files\InterActual\InterActual Player\inuninst.exe
InterVideo Launcher-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{8AEEE6D6-C95D-465A-B8D3-B7AE2FA7B8B4}\setup.exe" REMOVEALL
iTunes-->MsiExec.exe /I{41B9E2CF-0B3F-442A-B5B3-592A4A355634}
J2SE Runtime Environment 5.0 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060}
Java(TM) 6 Update 4-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160040}
Java(TM) 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
Java(TM) 6 Update 7-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070}
Lexmark 7100 Series-->C:\WINDOWS\System32\spool\drivers\w32x86\3\lxbxUNST.EXE -NOLICENSE
Logitech Desktop Messenger-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}\SETUP.EXE" -l0x9 UNINSTALL
Macromedia Flash Player 8-->RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Marvell Miniport Driver-->MsiExec.exe /X{C950420B-4182-49EA-850A-A6A2ABF06C6B}
MediaLife -->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{362BFFCD-8274-11D8-97C8-000129760CBE}\setup.exe" -uninstall
Microsoft .NET Framework 1.1 Hotfix (KB928366)-->"C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\hotfix.exe" "C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\Updates\M928366\M928366Uninstall.msp"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28}
Mozilla Firefox (3.0.3)-->C:\Documents and Settings\Big Stan\Desktop\Mozilla Firefox\uninstall\helper.exe
MS Access 97 SP2-->C:\Program Files\Microsoft Office\setup\setup.exe
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 6.0 Parser (KB933579)-->MsiExec.exe /I{0A869A65-8C94-4F7C-A5C7-972D3C8CED9E}
NVIDIA Drivers-->C:\WINDOWS\system32\nvudisp.exe UninstallGUI
OpenOffice.org 2.4-->MsiExec.exe /I{2CD2C0DB-81C3-416B-9FA6-589B9235359B}
PowerDVD-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}\setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{8DC42D05-680B-41B0-8878-6C14D24602DB}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE
Road Runner Medic 6.1-->"C:\Program Files\twc\medicsp2\unins000.exe"
RoadRunner-->MsiExec.exe /I{A73EFA95-4872-4AE3-8EE9-10D2E2D713CF}
Security Update for Windows Media Player 10 (KB911565)-->"C:\WINDOWS\$NtUninstallKB911565$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB917734)-->"C:\WINDOWS\$NtUninstallKB917734_WMP10$\spuninst\spuninst.exe"
Security Update for Windows Media Player 10 (KB936782)-->"C:\WINDOWS\$NtUninstallKB936782_WMP10$\spuninst\spuninst.exe"
Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe"
Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe"
Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950759)-->"C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950760)-->"C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe"
Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376)-->"C:\WINDOWS\$NtUninstallKB951376$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe"
Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe"
Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe"
Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe"
Skype™ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
Spybot - Search & Destroy 1.4-->"C:\Program Files\Spybot - Search & Destroy\unins000.exe"
Spybot - Search & Destroy-->"C:\Program Files\Spybot - Search & Destroy\unins001.exe"
TWC Customer Controls-->MsiExec.exe /I{F8722041-B63A-47FB-82A8-5F0977E1CF45}
Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe"
Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe"
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
ViewSonic Monitor Drivers-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B4FEA924-630D-11D4-B78E-005004566E4D}\Setup.exe" -l0x9
Warcraft II BNE-->C:\WINDOWS\W2BNEUnin.exe C:\WINDOWS\W2BNEUnin.dat
WIDCOMM Bluetooth Software-->MsiExec.exe /X{90535871-81B9-4D99-8A13-A7EE97F2D7FE}
WinAce Archiver-->"C:\Program Files\WinAce\SXUNINST.EXE" "C:\Program Files\WinAce\SXUNINST.INI"
Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Player 10-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 9 Hotfix [See KB885492 for more information]-->C:\WINDOWS\$NtUninstallKB885492$\spuninst\spuninst.exe
Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe"
World of Warcraft Public Test-->C:\Program Files\Common Files\Blizzard Entertainment\Burning Crusade-PTR\Uninstall.exe
World of Warcraft-->C:\Program Files\Common Files\Blizzard Entertainment\World of Warcraft\Uninstall.exe
Wrath of the Lich King Beta-->C:\Program Files\Common Files\Blizzard Entertainment\Wrath of the Lich King\Uninstall.exe
=====HijackThis Backups=====
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - (no file)
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - (no file)
======Hosts File======
127.0.0.1
www.007guard.com
127.0.0.1 007guard.com
127.0.0.1 008i.com
127.0.0.1
www.008k.com
127.0.0.1 008k.com
127.0.0.1
www.00hq.com
127.0.0.1 00hq.com
127.0.0.1 010402.com
127.0.0.1
www.032439.com
127.0.0.1 032439.com
======Security center information======
AV: CA Anti-Virus
FW: CA Personal Firewall
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\QuickTime\QTSystem\
"windir"=%SystemRoot%
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 35 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2302
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"FP_NO_HOST_CHECK"=NO
"CLASSPATH"=.;C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
"QTJAVA"=C:\Program Files\Java\jre1.6.0_07\lib\ext\QTJava.zip
-----------------EOF-----------------