It took quite awhile to scan my drives and it found alot more then expected.
mbam Log:
Malwarebytes' Anti-Malware 1.30
Database version: 1416
Windows 5.1.2600 Service Pack 3
11/23/2008 12:50:38 AM
mbam-log-2008-11-23 (00-50-37).txt
Scan type: Full Scan (A:\|C:\|D:\|E:\|F:\|G:\|H:\|I:\|)
Objects scanned: 970037
Time elapsed: 13 hour(s), 13 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 14
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 2
Files Infected: 17
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{73259091-9574-4ed8-a40f-7f65afc28634} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{502afdd6-0acf-4a67-b71e-9338f2f87a3e} (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{c900b400-cdfe-11d3-976a-00e02913a9e0} (Adware.WebHancer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c900b400-cdfe-11d3-976a-00e02913a9e0} (Adware.WebHancer) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\agadoo (Adware.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\xpre (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_NETWORK_MONITOR (Trojan.DNSChanger) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_CMDSERVICE (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\ptilinkk (Rootkit.Agent) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\ptilinkk (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ptilinkk (Rootkit.Agent) -> Delete on reboot.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{73259091-9574-4ed8-a40f-7f65afc28634} (Trojan.Vundo) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\WINDOWS\system32\x4 (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mp (Trojan.Agent) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\drivers\ptilinkk.sys (Rootkit.Agent.H) -> Delete on reboot.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP597\A0125732.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125775.exe (Adware.ZenoSearch) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125746.dll (Adware.CommAd) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125756.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125758.exe (Adware.CommAd) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125759.dll (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125761.dll (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125774.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP599\A0125777.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP601\A0126064.exe (Adware.Webhancer) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP602\A0126269.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP602\A0126271.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{2012F06E-9B38-420C-825B-FD8A62CD0D34}\RP602\A0126272.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\x4\WTE0V106.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\mp\kstamv3.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Delete on reboot.
Log:
Logfile of random's system information tool 1.04 (written by random/random)
Run by zEE at 2008-11-23 00:54:53
Microsoft Windows XP Professional Service Pack 3
System drive C: has 13 GB (7%) free of 191 GB
Total RAM: 3070 MB (83% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:55:15 AM, on 11/23/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16735)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\PnkBstrB.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\zEE\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\zEE.exe
C:\WINDOWS\system32\NOTEPAD.EXE
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.netflix.com/MemberHome
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Veoh Web Player Video Finder - {0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [EVGAPrecision] "C:\Program Files\EVGA Precision\EVGAPrecision.exe" /s
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htm
O8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htm
O8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\Program Files\BitComet\tools\BitCometBHO_1.1.8.30.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\WEB2~1\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: Poppit by pogo -
http://game1.pogo.com/v/8.1.2.12/applet/poppit2/poppit2-en_US.cab
O16 - DPF: Web-Based Email Tools -
http://email.secureserver.net/Download.CAB
O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) -
http://www.musicnotes.com/download/mnviewer.cab
O16 - DPF: {1C203F13-95AD-11D0-A84B-00A0247B735B} (Infragistics ActiveTreeView Control) -
https://employeetraining.compuware.com/cabs/SSTree.CAB
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {41E6DDD6-FBD6-4718-80F7-9B160533C2F5} (Infragistics UltraToolbars Control 5.0) -
https://employeetraining.compuware.com/cabs/IGToolbars50.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/win...ls/en/x86/client/wuweb_site.cab?1191554822781
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/mic...ls/en/x86/client/muweb_site.cab?1192875874203
O16 - DPF: {7FC1B346-83E6-4774-8D20-1A6B09B0E737} (Windows Live Photo Upload Control) -
http://patricklapointe.spaces.live.com/PhotoUpload/MsnPUpld.cab
O16 - DPF: {B3014671-7872-4671-BE73-5D05EB5B2AF5} (Infragistics UltraGrid Control 2.0) -
https://employeetraining.compuware.com/cabs/IGUltraGrid20.CAB
O16 - DPF: {B63EA811-FF25-4211-A6D2-58BF767432E1} (PictureLoader.Helpers) -
https://employeetraining.compuware.com/cabs/pictureloader.cab
O16 - DPF: {C2000000-FFFF-1100-8000-000000000004} (Infragistics Mask Edit Control) -
https://employeetraining.compuware.com/cabs/PVMASK.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F0D96671-A5CE-4854-AE49-6835742D232F} (Infragistics Panel Control 4.0) -
https://employeetraining.compuware.com/cabs/IGThreed40.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{78CF1A4E-84CB-4AA8-842B-D9F36D5C95E0}: NameServer = 192.168.2.1
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,xuydzx.dll,avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: Pure Networks Net2Go Service (nmraapache) - Pure Networks, Inc. - C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe
O23 - Service: Pure Networks Platform Service (nmservice) - Pure Networks, Inc. - C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe
O23 - Service: ForceWare user log service (nSvcLog) - NVIDIA - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\WINDOWS\system32\PnkBstrB.exe
--
End of file - 9675 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\User_Feed_Synchronization-{EC99AFDA-ED11-4890-A59B-27167DCED8F9}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
Yahoo! Toolbar Helper - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3049C3E9-B461-4BC5-8870-4C09146192CA}]
RealPlayer Download and Record Plugin for Internet Explorer - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll [2008-03-07 370296]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-11-21 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-07-07 1562448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll [2007-09-25 501136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-11-21 2055960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll [2006-10-26 440384]
{0FBB9689-D3D7-4f7a-A2E2-585B10099BFC} - Veoh Web Player Video Finder - C:\Program Files\Veoh Networks\VeohWebPlayer\VeohIEToolbar.dll [2008-10-09 463872]
{D0943516-5076-4020-A3B5-AEFAF26AB263} - Veoh Browser Plug-in - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll [2008-09-26 352256]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-11-21 2055960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"amd_dc_opt"=C:\Program Files\AMD\Dual-Core Optimizer\amd_dc_opt.exe [2008-07-22 77824]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
"EVGAPrecision"=C:\Program Files\EVGA Precision\EVGAPrecision.exe [2008-10-27 240656]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-21 1234712]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe [2007-03-09 63712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeCS4ServiceManager]
C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe [2008-08-14 611712]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}]
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-12-23 143360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools Lite]
C:\Program Files\DAEMON Tools Lite\daemon.exe [2008-08-08 490952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSPM Startup]
C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-04-17 196608]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ISUSScheduler]
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2008-03-30 267048]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Lexmark X74-X75]
C:\Program Files\Lexmark X74-X75\lxbbbmgr.exe [2002-10-14 57344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmapp]
C:\Program Files\Pure Networks\Network Magic\nmapp.exe [2008-01-18 451896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nmctxth]
C:\Program Files\Common Files\Pure Networks Shared\Platform\nmctxth.exe [2008-01-08 451896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nTrayFw]
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nTrayFw.exe [2006-02-17 270336]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OneCareUI]
C:\Program Files\Microsoft Windows OneCare Live\winssnotify.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-03-28 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SoundMan]
C:\WINDOWS\SOUNDMAN.EXE [2006-08-03 577536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\program files\steam\steam.exe [2008-10-08 1410296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2008-03-07 185896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Veoh]
C:\Program Files\Veoh Networks\Veoh\VeohClient.exe [2008-09-26 3660848]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe [2008-10-09 3502840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\{c7818b93-af45-6fb7-47a1-e7e2992c36ac}]
C:\WINDOWS\system32\rvpkpesxgwhpvxb.dll [2008-11-20 325120]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^NETGEAR WG111v2 Smart Wizard.lnk]
C:\PROGRA~1\NETGEAR\WG111v2\WG111v2.exe [2007-05-14 1261568]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Windows Desktop Search.lnk]
C:\PROGRA~1\WI459E~1\WINDOW~1.EXE [2007-02-05 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Wireless Configuration Utility HW.51.lnk]
C:\WINDOWS\Installer\{29F15D3F-5B37-44DB-BB89-390B3AD1404E}\NewShortcut1.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^hamachi.lnk]
C:\PROGRA~1\Hamachi\hamachi.exe [2008-10-07 625952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^Registration Assassin's Creed.LNK]
C:\PROGRA~1\Ubisoft\ASSASS~1\Register\REGIST~1.EXE -d 803509 -l english -r 7 -g Assassin's Creed -c us -i 3536 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^RocketDock.lnk]
C:\WINDOWS\BRICOP~1\VISTAI~1\ROCKET~1\ROCKET~1.EXE [2007-03-18 630784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^TransBar.lnk]
C:\WINDOWS\BRICOP~1\VISTAI~1\TransBar\TransBar.exe [2005-06-01 65536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^UberIcon.lnk]
C:\WINDOWS\BRICOP~1\VISTAI~1\UberIcon\UBERIC~1.EXE [2006-05-21 180224]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^zEE^Start Menu^Programs^Startup^Y'z Shadow.lnk]
C:\WINDOWS\BRICOP~1\VISTAI~1\YzShadow\YzShadow.exe [2006-05-21 155648]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\Program,Files\RelevantKnowledge\rlai.dll,C:\Program,Files\RelevantKnowledge\rlai.dll,xuydzx.dll,avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2007-02-05 294400]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
C:\WINDOWS\system32\nnnoOEtR
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\AT&T CallVantage Softphone\eyeBeam.exe"="C:\Program Files\AT&T CallVantage Softphone\eyeBeam.exe:*:Enabled:AT&T CallVantage Softphone"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
"C:\Program Files\Conference\Conference.dll"="C:\Program Files\Conference\Conference.dll:*:Enabled:Audio/Video Conference"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe"="C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\Apache.exe:*:Enabled:Apache HTTP Server"
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe"="C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax"
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe"="C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\LucasArts\Star Wars Empire at War Forces of Corruption\swfoc.exe"="C:\Program Files\LucasArts\Star Wars Empire at War Forces of Corruption\swfoc.exe:*:Enabled:Star Wars(TM): Empire at War(TM): Forces of Corruption(TM)"
"C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe"="C:\Program Files\Turbine\Turbine Download Manager\TurbineMessageService.exe:*:Enabled:TurbineMessageService"
"C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe"="C:\Program Files\Turbine\Turbine Download Manager\TurbineNetworkService.exe:*:Enabled:TurbineNetworkService"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\EA GAMES\Battlefield 2\BF2.exe"="C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:*:Enabled:Battlefield 2"
"C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe"="C:\Documents and Settings\All Users\Application Data\NexonUS\NGM\NGM.exe:*:Enabled:Nexon Game Manager"
"E:\Downloads\TryWoW.exe"="E:\Downloads\TryWoW.exe:*:Enabled:Blizzard Downloader"
"C:\Program Files\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"C:\WINDOWS\Temp\~os3.tmp\ossproxy.exe"="C:\WINDOWS\Temp\~os3.tmp\ossproxy.exe:*:Enabled

ssproxy.exe"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe"="C:\Program Files\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe:*:Enabled:Adobe CSI CS4"
"C:\Program Files\Microsoft Games\Halo 2\halo2.exe"="C:\Program Files\Microsoft Games\Halo 2\halo2.exe:*:Enabled:Halo 2"
"E:\Program Files\Microsoft Games\Freelancer\EXE\Freelancer.exe"="E:\Program Files\Microsoft Games\Freelancer\EXE\Freelancer.exe:*:Enabled:Freelancer"
"C:\Program Files\Steam\steamapps\zebes5\garrysmod\hl2.exe"="C:\Program Files\Steam\steamapps\zebes5\garrysmod\hl2.exe:*:Enabled:hl2"
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"="C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Enabled:Veoh Web Player "
"C:\Program Files\Sierra\FEARCombat\FEARMP.exe"="C:\Program Files\Sierra\FEARCombat\FEARMP.exe:*:Enabled:FEAR Combat"
"C:\Program Files\Xfire\xfire.exe"="C:\Program Files\Xfire\xfire.exe:*:Enabled:Xfire"
"E:\Backup\Raven\Star Trek Voyager Elite Force\stvoyHM.exe"="E:\Backup\Raven\Star Trek Voyager Elite Force\stvoyHM.exe:*:Enabled:stvoyHM"
"E:\Backup\Raven\Star Trek Voyager Elite Force\iostvoyHM-1.37.exe"="E:\Backup\Raven\Star Trek Voyager Elite Force\iostvoyHM-1.37.exe:*:Enabled:iostvoyHM-1.37"
"C:\Nexon\Combat Arms\CombatArms.exe"="C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Nexon\Combat Arms\Engine.exe"="C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"
"C:\Nexon\Combat Arms\NMService.exe"="C:\Nexon\Combat Arms\NMService.exe:*:Enabled:Nexon Messenger Core"
"C:\Program Files\Veoh Networks\Veoh\VeohClient.exe"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe:*:Enabled:Veoh Client"
"E:\Downloads\Call of Duty 4 Modern Warfare Full-Rip Skullptura\Call.of.Duty.4.Modern.Warfare.Full-Rip.Skullptura\Call of Duty 4 - Modern Warfare\iw3mp.exe"="E:\Downloads\Call of Duty 4 Modern Warfare Full-Rip Skullptura\Call.of.Duty.4.Modern.Warfare.Full-Rip.Skullptura\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:iw3mp"
"E:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe"="E:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:*:Enabled:Call of Duty(R) 4 - Modern Warfare(TM) "
"C:\Program Files\Steam\steamapps\common\left 4 dead demo\left4dead.exe"="C:\Program Files\Steam\steamapps\common\left 4 dead demo\left4dead.exe:*:Enabled:left4dead"
"C:\Program Files\Steam\steam.exe"="C:\Program Files\Steam\steam.exe:*:Enabled:Steam"
"C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled

nkBstrA"
"C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled

nkBstrB"
"C:\Program Files\GtkRadiant 1.5.0\GtkRadiant.exe"="C:\Program Files\GtkRadiant 1.5.0\GtkRadiant.exe:*:Enabled:GtkRadiant"
"C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe"="C:\Program Files\Sony\Station\LaunchPad\LaunchPad.exe:*:Enabled:LaunchPad"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\Activision\EF2\EF2.exe"="C:\Program Files\Activision\EF2\EF2.exe:*

isabled:Elite Force II"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
"C:\Nexon\Combat Arms\CombatArms.exe"="C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe"
"C:\Nexon\Combat Arms\Engine.exe"="C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6ddfd6e6-7ef2-11dc-9d18-00e04d1c6713}]
shell\AutoRun\command - F:\Setup.exe
======File associations======
.js - open - "C:\Program Files\Adobe\Adobe Dreamweaver CS4\Dreamweaver.exe","%1"
======List of files/folders created in the last 1 months======
2008-11-23 00:54:53 ----D---- C:\rsit
2008-11-22 11:32:09 ----D---- C:\Documents and Settings\zEE\Application Data\Malwarebytes
2008-11-22 11:32:05 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-22 11:32:05 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-22 02:12:50 ----D---- C:\Program Files\Trend Micro
2008-11-22 01:14:19 ----A---- C:\WINDOWS\ntbtlog.txt
2008-11-21 22:30:40 ----A---- C:\WINDOWS\Doom 3 Uninstall Log.txt
2008-11-21 17:40:30 ----A---- C:\WINDOWS\wininit.ini
2008-11-21 17:02:48 ----HD---- C:\$AVG8.VAULT$
2008-11-21 17:01:56 ----D---- C:\Program Files\Lavasoft
2008-11-21 17:01:53 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-11-21 16:58:05 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-11-21 16:57:56 ----D---- C:\Documents and Settings\zEE\Application Data\AVGTOOLBAR
2008-11-21 16:57:45 ----D---- C:\Program Files\AVG
2008-11-21 16:57:44 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2008-11-21 16:50:02 ----A---- C:\WINDOWS\system32\370e6e71-.txt
2008-11-21 16:49:18 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-11-21 16:49:18 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-21 16:44:40 ----A---- C:\WINDOWS\system32\ghnfqgsgloqqkzhss.exe
2008-11-21 16:44:36 ----SHD---- C:\WINDOWS\WmVl
2008-11-21 16:44:31 ----D---- C:\WINDOWS\system32\ID2
2008-11-21 16:44:31 ----D---- C:\WINDOWS\system32\gp2
2008-11-21 16:44:31 ----D---- C:\WINDOWS\system32\dim
2008-11-21 16:36:25 ----A---- C:\WINDOWS\EF2.INI
2008-11-20 12:47:52 ----D---- C:\Program Files\Red Orb
2008-11-18 02:20:59 ----A---- C:\WINDOWS\setup.ini
2008-11-18 02:20:58 ----D---- C:\WINDOWS\OvtCam
2008-11-18 02:20:57 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2008-11-17 16:02:20 ----D---- C:\Documents and Settings\zEE\Application Data\Apple Computer
2008-11-16 22:22:59 ----A---- C:\WINDOWS\system32\BReWErS.dll
2008-11-16 12:18:59 ----D---- C:\Documents and Settings\zEE\Application Data\RadiantSettings
2008-11-16 12:18:39 ----D---- C:\Program Files\GtkRadiant 1.5.0
2008-11-14 21:01:52 ----A---- C:\WINDOWS\system32\pbsvc.exe
2008-11-08 22:26:30 ----A---- C:\WINDOWS\fle.ini
2008-11-08 22:26:29 ----D---- C:\Program Files\Freelancer Explorer
2008-11-07 00:46:49 ----D---- C:\Program Files\Sierra
2008-11-06 00:56:28 ----D---- C:\Program Files\Audacity
2008-11-05 23:36:43 ----D---- C:\Program Files\Microsoft Visual Studio 8
2008-11-05 23:33:44 ----D---- C:\Program Files\Common Files\Nikon
2008-11-05 23:32:14 ----D---- C:\Program Files\Microsoft Expression
2008-11-05 20:54:30 ----D---- C:\Documents and Settings\zEE\Application Data\com.adobe.ExMan
2008-11-02 22:35:16 ----A---- C:\WINDOWS\system32\mf.dll
2008-11-02 22:06:07 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Games
2008-11-02 21:58:24 ----D---- C:\Documents and Settings\zEE\Application Data\Microsoft Game Studios
2008-11-01 23:30:31 ----D---- C:\Program Files\Veoh Networks
2008-10-31 23:52:50 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2008-10-31 23:45:11 ----D---- C:\Program Files\Adobe Media Player
2008-10-31 23:39:53 ----D---- C:\Program Files\Common Files\Adobe AIR
2008-10-31 23:38:17 ----D---- C:\Program Files\Common Files\Macrovision Shared
2008-10-31 03:39:35 ----D---- C:\Documents and Settings\zEE\Application Data\FileZilla
2008-10-31 03:39:28 ----D---- C:\Program Files\FileZilla FTP Client
2008-10-30 18:39:36 ----A---- C:\WINDOWS\BricoPackFoldersDelete.cmd
2008-10-30 18:25:01 ----D---- C:\WINDOWS\Prefetch
2008-10-30 18:13:32 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-10-30 18:13:28 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-30 18:13:23 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-30 18:13:19 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-30 18:13:13 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-30 18:13:08 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-30 18:13:04 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-30 18:13:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-10-30 18:12:55 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-10-30 18:12:51 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-30 18:12:47 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-10-30 18:12:42 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-30 18:12:38 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-30 18:12:34 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-10-30 18:12:29 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-30 18:12:26 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-10-30 18:08:58 ----D---- C:\WINDOWS\system32\scripting
2008-10-30 18:08:57 ----D---- C:\WINDOWS\l2schemas
2008-10-30 18:08:56 ----D---- C:\WINDOWS\system32\en
2008-10-30 18:06:28 ----D---- C:\WINDOWS\network diagnostic
2008-10-30 17:58:35 ----A---- C:\WINDOWS\system32\wlanapi.dll
2008-10-30 17:58:31 ----A---- C:\WINDOWS\system32\tspkg.dll
2008-10-30 17:58:31 ----A---- C:\WINDOWS\system32\tsgqec.dll
2008-10-30 17:58:25 ----A---- C:\WINDOWS\system32\setupn.exe
2008-10-30 17:58:24 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2008-10-30 17:58:23 ----A---- C:\WINDOWS\system32\rasqec.dll
2008-10-30 17:58:23 ----A---- C:\WINDOWS\system32\qutil.dll
2008-10-30 17:58:22 ----A---- C:\WINDOWS\system32\qcliprov.dll
2008-10-30 17:58:22 ----A---- C:\WINDOWS\system32\qagentrt.dll
2008-10-30 17:58:22 ----A---- C:\WINDOWS\system32\qagent.dll
2008-10-30 17:58:21 ----A---- C:\WINDOWS\system32\onex.dll
2008-10-30 17:58:17 ----A---- C:\WINDOWS\system32\napstat.exe
2008-10-30 17:58:17 ----A---- C:\WINDOWS\system32\napmontr.dll
2008-10-30 17:58:17 ----A---- C:\WINDOWS\system32\napipsec.dll
2008-10-30 17:58:16 ----A---- C:\WINDOWS\system32\msxml6r.dll
2008-10-30 17:58:15 ----A---- C:\WINDOWS\system32\msshavmsg.dll
2008-10-30 17:58:15 ----A---- C:\WINDOWS\system32\mssha.dll
2008-10-30 17:58:08 ----A---- C:\WINDOWS\system32\mmcperf.exe
2008-10-30 17:58:08 ----A---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-10-30 17:58:08 ----A---- C:\WINDOWS\system32\mmcex.dll
2008-10-30 17:58:08 ----A---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-10-30 17:58:03 ----A---- C:\WINDOWS\system32\l2gpstore.dll
2008-10-30 17:58:03 ----A---- C:\WINDOWS\system32\kmsvc.dll
2008-10-30 17:58:03 ----A---- C:\WINDOWS\system32\kbdpash.dll
2008-10-30 17:58:03 ----A---- C:\WINDOWS\system32\kbdnepr.dll
2008-10-30 17:58:02 ----A---- C:\WINDOWS\system32\kbdiultn.dll
2008-10-30 17:58:02 ----A---- C:\WINDOWS\system32\kbdbhc.dll
2008-10-30 17:57:58 ----A---- C:\WINDOWS\system32\smtpapi.dll
2008-10-30 17:57:57 ----A---- C:\WINDOWS\system32\rwnh.dll
2008-10-30 17:57:52 ----A---- C:\WINDOWS\006063_.tmp
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eapsvc.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eapqec.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eappprxy.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eapphost.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eappgnui.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eappcfg.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eapp3hst.dll
2008-10-30 17:57:51 ----A---- C:\WINDOWS\system32\eapolqec.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3ui.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3svc.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3msm.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3dlg.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3cfg.dll
2008-10-30 17:57:50 ----A---- C:\WINDOWS\system32\dot3api.dll
2008-10-30 17:57:49 ----A---- C:\WINDOWS\system32\dimsroam.dll
2008-10-30 17:57:49 ----A---- C:\WINDOWS\system32\dimsntfy.dll
2008-10-30 17:57:49 ----A---- C:\WINDOWS\system32\dhcpqec.dll
2008-10-30 17:57:47 ----A---- C:\WINDOWS\system32\credssp.dll
2008-10-30 17:57:44 ----A---- C:\WINDOWS\system32\azroles.dll
2008-10-30 17:57:42 ----A---- C:\WINDOWS\system32\aaclient.dll
2008-10-30 17:06:19 ----HDC---- C:\WINDOWS\$NtUninstallKB958644_0$
2008-10-30 17:05:54 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$
2008-10-30 17:05:45 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$
2008-10-30 17:05:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$
2008-10-30 17:05:35 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-30 17:05:30 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$
2008-10-30 17:02:00 ----HDC---- C:\WINDOWS\$NtUninstallKB954156_WM9L$
2008-10-29 19:24:22 ----A---- C:\WINDOWS\system32\xfcodec.dll
2008-10-28 22:45:53 ----D---- C:\Documents and Settings\All Users\Application Data\Fallout3
2008-10-28 22:45:48 ----D---- C:\Program Files\Bethesda Softworks
2008-10-27 21:14:09 ----D---- C:\Documents and Settings\zEE\Application Data\teamspeak2
2008-10-27 21:13:43 ----D---- C:\Program Files\Teamspeak2_RC2
2008-10-27 15:00:39 ----D---- C:\Program Files\EVGA Precision
2008-10-25 21:36:43 ----D---- C:\Program Files\Doom 3
2008-10-25 21:12:34 ----D---- C:\WINDOWS\Doom 3
2008-10-24 20:44:31 ----D---- C:\WINDOWS\UBISOFT
2008-10-24 19:40:06 ----D---- C:\Program Files\BreakPoint Software
======List of files/folders modified in the last 1 months======
2008-11-23 00:55:15 ----D---- C:\WINDOWS\Temp
2008-11-23 00:52:35 ----D---- C:\WINDOWS\system32\drivers
2008-11-23 00:51:39 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-23 00:50:37 ----D---- C:\WINDOWS\system32
2008-11-22 11:32:28 ----D---- C:\Program Files\Mozilla Firefox
2008-11-22 11:32:05 ----RD---- C:\Program Files
2008-11-22 01:14:19 ----D---- C:\WINDOWS
2008-11-21 21:48:31 ----D---- C:\WINDOWS\Minidump
2008-11-21 21:48:31 ----D---- C:\WINDOWS\Debug
2008-11-21 21:46:25 ----SHD---- C:\WINDOWS\Installer
2008-11-21 21:46:25 ----HD---- C:\Config.Msi
2008-11-21 21:46:25 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-21 21:02:16 ----RSH---- C:\boot.ini
2008-11-21 21:02:16 ----A---- C:\WINDOWS\win.ini
2008-11-21 21:02:16 ----A---- C:\WINDOWS\system.ini
2008-11-21 18:09:14 ----D---- C:\Program Files\GameSpy Arcade
2008-11-21 17:40:34 ----D---- C:\temp
2008-11-21 16:57:03 ----SD---- C:\Documents and Settings\zEE\Application Data\Microsoft
2008-11-21 16:44:34 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-21 16:42:24 ----D---- C:\Documents and Settings\zEE\Application Data\uTorrent
2008-11-21 16:40:54 ----D---- C:\Program Files\Activision
2008-11-21 01:18:00 ----D---- C:\Program Files\StarWarsGalaxies
2008-11-21 01:03:02 ----D---- C:\Documents and Settings\zEE\Application Data\Xfire
2008-11-21 01:02:37 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-21 00:51:18 ----D---- C:\Program Files\Ubisoft
2008-11-20 20:06:40 ----D---- C:\Documents and Settings\zEE\Application Data\gtk-2.0
2008-11-20 18:10:47 ----D---- C:\Program Files\Xfire
2008-11-20 16:48:10 ----D---- C:\Program Files\MP3MyMP3
2008-11-20 03:59:12 ----A---- C:\WINDOWS\system32\rvpkpesxgwhpvxb.dll
2008-11-19 01:27:09 ----A---- C:\WINDOWS\NeroDigital.ini
2008-11-18 16:56:54 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-11-18 16:55:06 ----D---- C:\Program Files\Steam
2008-11-18 16:31:19 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-11-18 15:03:31 ----D---- C:\Program Files\GtkRadiant-1.4
2008-11-18 02:21:45 ----HD---- C:\WINDOWS\inf
2008-11-18 02:20:58 ----D---- C:\WINDOWS\twain_32
2008-11-16 19:51:46 ----D---- C:\WINDOWS\system32\DirectX
2008-11-16 19:35:00 ----SD---- C:\WINDOWS\Tasks
2008-11-14 21:03:20 ----RSD---- C:\WINDOWS\assembly
2008-11-14 21:01:58 ----A---- C:\WINDOWS\system32\PnkBstrB.exe
2008-11-13 20:00:35 ----D---- C:\Documents and Settings\zEE\Application Data\Mozilla
2008-11-12 17:20:32 ----D---- C:\Documents and Settings\zEE\Application Data\dvdcss
2008-11-12 16:01:46 ----D---- C:\Documents and Settings\zEE\Application Data\Hamachi
2008-11-08 22:39:12 ----D---- C:\Program Files\Microsoft Games
2008-11-08 21:14:44 ----D---- C:\Documents and Settings\All Users\Application Data\NexonUS
2008-11-05 23:51:16 ----D---- C:\WINDOWS\Microsoft.NET
2008-11-05 23:37:23 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-11-05 23:36:22 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-11-05 23:36:10 ----RSD---- C:\WINDOWS\Fonts
2008-11-05 23:33:57 ----D---- C:\WINDOWS\WinSxS
2008-11-05 23:33:44 ----D---- C:\Program Files\Common Files
2008-11-05 23:32:14 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-05 20:54:30 ----D---- C:\Documents and Settings\zEE\Application Data\Adobe
2008-11-05 20:53:42 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-11-05 14:26:59 ----D---- C:\WINDOWS\Downloaded Installations
2008-11-03 23:34:41 ----D---- C:\WINDOWS\system32\config
2008-11-03 23:33:15 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-03 23:31:23 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-11-01 01:54:08 ----D---- C:\Documents and Settings
2008-10-31 23:45:32 ----D---- C:\Program Files\Adobe
2008-10-31 23:44:53 ----D---- C:\Program Files\Common Files\Adobe
2008-10-30 18:42:28 ----D---- C:\WINDOWS\Media
2008-10-30 18:42:28 ----D---- C:\WINDOWS\Cursors
2008-10-30 18:42:27 ----D---- C:\WINDOWS\system32\usmt
2008-10-30 18:42:27 ----D---- C:\Program Files\Outlook Express
2008-10-30 18:42:27 ----D---- C:\Program Files\Movie Maker
2008-10-30 18:40:58 ----A---- C:\WINDOWS\system32\uxtheme.dll
2008-10-30 18:40:58 ----A---- C:\WINDOWS\BricoPackUninst.txt
2008-10-30 18:40:58 ----A---- C:\WINDOWS\BricoPackUninst.cmd
2008-10-30 18:39:15 ----D---- C:\WINDOWS\BricoPacks
2008-10-30 18:24:35 ----D---- C:\WINDOWS\system32\Setup
2008-10-30 18:24:35 ----D---- C:\WINDOWS\ime
2008-10-30 18:24:35 ----D---- C:\WINDOWS\AppPatch
2008-10-30 18:24:34 ----D---- C:\WINDOWS\system32\wbem
2008-10-30 18:13:33 ----D---- C:\WINDOWS\system32\CatRoot
2008-10-30 18:12:30 ----D---- C:\Program Files\Messenger
2008-10-30 18:12:18 ----D---- C:\WINDOWS\security
2008-10-30 18:09:07 ----D---- C:\WINDOWS\system32\inetsrv
2008-10-30 18:09:06 ----D---- C:\WINDOWS\Help
2008-10-30 18:08:58 ----D---- C:\WINDOWS\system32\en-US
2008-10-30 18:08:56 ----D---- C:\WINDOWS\system32\bits
2008-10-30 18:08:56 ----D---- C:\WINDOWS\peernet
2008-10-30 18:07:25 ----D---- C:\WINDOWS\system32\Restore
2008-10-30 18:07:25 ----D---- C:\WINDOWS\system32\npp
2008-10-30 18:07:25 ----D---- C:\WINDOWS\mui
2008-10-30 18:07:24 ----D---- C:\WINDOWS\msagent
2008-10-30 18:07:23 ----D---- C:\WINDOWS\srchasst
2008-10-30 18:07:23 ----D---- C:\Program Files\NetMeeting
2008-10-30 18:07:22 ----D---- C:\WINDOWS\system32\Com
2008-10-30 18:07:21 ----D---- C:\Program Files\Windows Media Player
2008-10-30 18:07:20 ----D---- C:\Program Files\Windows NT
2008-10-30 18:07:19 ----D---- C:\Program Files\Common Files\System
2008-10-30 18:07:09 ----D---- C:\WINDOWS\system32\oobe
2008-10-30 18:07:08 ----D---- C:\WINDOWS\system
2008-10-30 18:05:44 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-10-30 18:04:09 ----D---- C:\WINDOWS\EHome
2008-10-30 17:31:43 ----D---- C:\Program Files\Microsoft Silverlight
2008-10-30 17:31:43 ----D---- C:\Program Files\Internet Explorer
2008-10-30 17:06:19 ----HD---- C:\WINDOWS\$hf_mig$
2008-10-29 16:15:55 ----D---- C:\Program Files\EA GAMES
2008-10-27 14:16:53 ----D---- C:\WINDOWS\nview
2008-10-27 14:13:31 ----D---- C:\Program Files\AGEIA Technologies
2008-10-25 23:59:35 ----A---- C:\WINDOWS\system32\CmdLineExt03.dll
2008-10-25 21:29:53 ----A---- C:\WINDOWS\system32\CmdLineExt.dll
2008-10-24 22:18:17 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-07-01 36864]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-11-21 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-11-21 26824]
R1 BIOS;BIOS; \??\C:\WINDOWS\System32\drivers\BIOS.sys []
R1 Cdr4_xp;Cdr4_xp; C:\WINDOWS\system32\drivers\Cdr4_xp.sys [2007-02-02 9336]
R1 Cdralw2k;Cdralw2k; C:\WINDOWS\system32\drivers\Cdralw2k.sys [2007-02-02 9464]
R1 oreans32;oreans32; \??\C:\WINDOWS\system32\drivers\oreans32.sys []
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.4.5.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2007-10-04 21035]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-11-21 76040]
R2 pnarp;Pure Networks Device Discovery Driver; C:\WINDOWS\system32\DRIVERS\pnarp.sys [2008-01-08 23992]
R2 purendis;Pure Networks Wireless Driver; C:\WINDOWS\system32\DRIVERS\purendis.sys [2008-01-08 25272]
R2 X4HSX32;X4HSX32; \??\C:\Program Files\GameTap\bin\Release\X4HSX32.Sys []
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-10-13 4022528]
R3 AmdLLD;AMD Low Level Device Driver; C:\WINDOWS\system32\DRIVERS\AmdLLD.sys [2007-06-29 34304]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2008-01-29 16168]
R3 hamachi;Hamachi Network Interface; C:\WINDOWS\system32\DRIVERS\hamachi.sys [2008-10-07 25280]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2006-02-17 34176]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2006-02-17 13056]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbohci.sys [2008-04-13 17152]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2008-04-13 14592]
S3 amjis7c1;amjis7c1; C:\WINDOWS\system32\drivers\amjis7c1.sys []
S3 bDMusicb;bDMusicb; \??\C:\DOCUME~1\zEE\LOCALS~1\Temp\bDMusicb.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 EagleNT;EagleNT; \??\C:\WINDOWS\system32\drivers\EagleNT.sys []
S3 HidCom;USB-HID -> COM Driver Service; C:\WINDOWS\system32\DRIVERS\BdHidCom.sys [2008-02-24 17408]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 OVT511Plus;D-Link USB Digital Video Camera; C:\WINDOWS\System32\Drivers\omcamvid.sys [2000-03-06 126882]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 USBNET_XP;Instant Wireless XP USB Network Adapter ver.2.6 Driver; C:\WINDOWS\system32\DRIVERS\netusbxp.sys [2002-02-20 72576]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S3 W8335XP;802.11g Wireless PC Card/PCI Adapter; C:\WINDOWS\system32\DRIVERS\MRV8335XP.sys []
S3 WpdUsb;WpdUsb; C:\WINDOWS\System32\Drivers\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 xnacc;Microsoft Common Controller For Windows Driver Service; C:\WINDOWS\system32\DRIVERS\xnacc.sys [2006-06-01 509440]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2002-08-29 12032]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-11-21 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-11-21 231704]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-19 322120]
R2 nmservice;Pure Networks Platform Service; C:\Program Files\Common Files\Pure Networks Shared\Platform\nmsrvc.exe [2008-01-08 451896]
R2 nSvcLog;ForceWare user log service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcLog.exe [2006-02-17 61503]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908]
R2 PnkBstrA;PnkBstrA; C:\WINDOWS\system32\PnkBstrA.exe [2008-08-15 66872]
R2 PnkBstrB;PnkBstrB; C:\WINDOWS\system32\PnkBstrB.exe [2008-11-14 107832]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-10-31 655624]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-03 69632]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-03-30 504104]
S3 LexBceS;LexBce Server; C:\WINDOWS\system32\LEXBCES.EXE [2002-10-14 303104]
S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2006-12-23 262144]
S3 nmraapache;Pure Networks Net2Go Service; C:\Program Files\Pure Networks\Network Magic\WebServer\bin\nmraapache.exe [2008-01-18 12800]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2007-02-05 300032]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-02-18 110592]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
S4 ForcewareWebInterface;Forceware Web Interface; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\Apache Group\Apache2\bin\apache.exe [2006-02-17 20543]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-12-14 61440]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880]
S4 nSvcIp;ForceWare IP service; C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin\nSvcIp.exe [2006-02-17 127035]
-----------------EOF-----------------
info will be in next post