Thanks so much for taking the time to help. Between your post and my initial post I ran MAB once already, which turned up a number of problems which I removed. Here's the initial log from 1-20-09
:
Malwarebytes' Anti-Malware 1.33
Database version: 1668
Windows 5.1.2600 Service Pack 3
1/20/2009 3:26:42 AM
mbam-log-2009-01-20 (03-26-42).txt
Scan type: Full Scan (C:\|)
Objects scanned: 154851
Time elapsed: 1 hour(s), 1 minute(s), 58 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 11
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 18
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ModuleUsage\c:/windows/downloaded program files/popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\TypeLib\{c9c5deaf-0a1f-4660-8279-9edfad6fefe1} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{e4e3e0f8-cd30-4380-8ce9-b96904bdefca} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{fe8a736f-4124-4d9c-b4b1-3b12381efabe} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{df780f87-ff2b-4df8-92d0-73db16a1543a} (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\popcaploader.popcaploaderctrl2.1 (Adware.PopCap) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{42f2c9ba-614f-47c0-b3e3-ecfd34eed658} (Adware.ISTBar) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{8fcdf9d9-a28b-480f-8c3d-581f119a8ab8} (Adware.180Solutions) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kevin O'Dell\Local Settings\Temporary Internet Files\Content.IE5\Y3WTI9XR\load[1].exe (Trojan.Waledac) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kevin O'Dell\Local Settings\Temporary Internet Files\Content.IE5\YLWJHKUF\index[1] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kevin O'Dell\Local Settings\Temporary Internet Files\Content.IE5\YLWJHKUF\upd105320[2] (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1298\A0134398.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1298\A0134399.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1301\A0134533.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1305\A0134587.exe (Trojan.Waledac) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0134890.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0134891.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135124.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135125.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135198.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135199.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135209.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135210.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1308\A0135219.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Documents and Settings\Kevin O'Dell\Local Settings\Temporary Internet Files\ijjistarter2FxB.exe (Trojan.Agent) -> Quarantined and deleted successfully.
After your post I followed your instructions, installed Avast anti-virus, and ran MAB once again, which turned up a clean log as follows (1-24);
Malwarebytes' Anti-Malware 1.33
Database version: 1668
Windows 5.1.2600 Service Pack 3
1/24/2009 10:03:18 PM
mbam-log-2009-01-24 (22-03-18).txt
Scan type: Full Scan (C:\|)
Objects scanned: 156853
Time elapsed: 1 hour(s), 1 minute(s), 50 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
I then installed and ran RSIT as you instructed. Here is log.txt and info.txt:
Logfile of random's system information tool 1.05 (written by random/random)
Run by Kevin at 2009-01-24 23:36:42
Microsoft Windows XP Home Edition Service Pack 3
System drive C: has 9 GB (12%) free of 73 GB
Total RAM: 2558 MB (77% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:36:46 PM, on 1/24/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\Rundll32.exe
C:\Program Files\Dell\Media Experience\PCMService.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\AIM+\AIM+.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\AIM95\aim.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Opera\Opera.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Kevin\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kevin.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://google.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
O3 - Toolbar: (no name) - {BA52B914-B692-46c4-B683-905236F6F655} - (no file)
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [CTSysVol] C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe /r
O4 - HKLM\..\Run: [P17Helper] Rundll32 P17.dll,P17Helper
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [Dell Photo AIO Printer 922] "C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe"
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [AIM] "C:\Program Files\AIM+\AIM+.exe" -cnetwait.odl
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: Monitor.lnk = C:\Program Files\802.11g Wireless LAN\Monitor.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Microsoft Windows.hta
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRA~1\AIM95\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: MUSICMATCH MX Web Player - {d81ca86b-ef63-42af-bee3-4502d9a03c2d} -
http://wwws.musicmatch.com/mmz/openWebRadio.html (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4E218431-2F07-40BD-A9D3-035324C1F13F} (DyynoX Class) -
http://webserver.dyyno.com/DyynoClient/DyynoCAB.CAB
O16 - DPF: {58172624-85DD-4482-9E64-02ADCA637E96} (shizmoo Class) -
http://shizmoo.com/activex/web665.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) -
http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) -
http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) -
http://chat.yahoo.com/cab/yuplapp.cab
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} (shizmoo Class) -
http://playroom.icq.com/odyssey_web11.cab
O16 - DPF: {ADCC68D4-AAEA-4338-817D-1F261D9FB759} (ENetLauncher Control) -
http://www.dragongemworld.com/Active_X/ENetLauncher.cab
O16 - DPF: {CEA3052D-65B9-44E2-A501-5E14024BC66F} (TricksterActiveX Control) -
http://www.tricksteronline.com/control/tricksterActiveX.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {D7A4D8FB-83F0-40E5-954F-88F48D15AE96} (ICQVideoWindow Class) -
http://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
O16 - DPF: {D88C7675-7CEE-4C9A-BDD4-7A43EED7794D} (Logout Class) -
http://www.tricksteronline.com/control/KALogoutComponent.cab
O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) -
http://xtraz.icq.com/xtraz/activex/MISBH.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: dlbt_device - Dell - C:\WINDOWS\system32\dlbtcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPodService - Unknown owner - C:\Program Files\iPod\bin\iPodService.exe (file missing)
O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe
--
End of file - 9596 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\bokvgjei.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-01-28 1554256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}]
DriveLetterAccess - C:\WINDOWS\system32\dla\tfswshx.dll [2004-08-13 118842]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDD3B846-8D59-4ffb-8758-209B6AD74ACC}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{BA52B914-B692-46c4-B683-905236F6F655}
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe [2008-06-10 144784]
"ATIPTA"=C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe [2004-05-25 335872]
"CTSysVol"=C:\Program Files\Creative\Sound Blaster Live! 24-bit\Surround Mixer\CTSysVol.exe [2003-09-17 57344]
"P17Helper"=Rundll32 P17.dll []
"UpdReg"=C:\WINDOWS\UpdReg.EXE [2000-05-11 90112]
"PCMService"=C:\Program Files\Dell\Media Experience\PCMService.exe [2004-04-11 290816]
"DVDLauncher"=C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe [2004-08-23 57344]
"UpdateManager"=C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe [2004-01-07 110592]
"dla"=C:\WINDOWS\system32\dla\tfswctrl.exe [2004-08-13 122939]
"Dell Photo AIO Printer 922"=C:\Program Files\Dell Photo AIO Printer 922\dlbtbmgr.exe [2004-03-29 290816]
"Microsoft Works Update Detection"=C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe [2003-12-05 50688]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2004-12-10 180269]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"StartCCC"=C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [2008-08-29 61440]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AIM"=C:\Program Files\AIM+\AIM+.exe [2002-06-10 309760]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2005-12-24 155648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TkBellExe]
C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2004-12-10 180269]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
C:\PROGRA~1\Adobe\ACROBA~2.0\Reader\READER~1.EXE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"VSS"=3
"MCVSRte"=2
"mcupdmgr.exe"=3
"McShield"=3
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE
Microsoft Windows.hta
C:\Documents and Settings\Kevin\Start Menu\Programs\Startup
Monitor.lnk - C:\Program Files\802.11g Wireless LAN\Monitor.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wbsys.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-12-01 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll [2005-11-28 106496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2006-06-19 702768]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"C:\Program Files\WinMX\WinMX.exe"="C:\Program Files\WinMX\WinMX.exe:*:Enabled:WinMX Application"
"C:\Program Files\SmartFTP\SmartFTP.exe"="C:\Program Files\SmartFTP\SmartFTP.exe:*:Enabled:SmartFTP Client"
"C:\Program Files\BitTorrent\btdownloadgui.exe"="C:\Program Files\BitTorrent\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\Program Files\Liero Xtreme\LieroX.exe"="C:\Program Files\Liero Xtreme\LieroX.exe:*:Enabled:LieroX"
"C:\Program Files\Soldat\Soldat.exe"="C:\Program Files\Soldat\Soldat.exe:*:Enabled:Soldat"
"C:\Program Files\LimeWire\LimeWire 4.2.3\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire 4.2.3\LimeWire.exe:*:Enabled:LimeWire"
"C:\Program Files\ZSNES\ZSNESW.EXE"="C:\Program Files\ZSNES\ZSNESW.EXE:*:Enabled:ZSNESW"
"C:\Program Files\AIM95\aim.exe"="C:\Program Files\AIM95\aim.exe:*:Enabled:AOL Instant Messenger (SM)"
"C:\Program Files\AIM95\AIM95_c1\aim.exe"="C:\Program Files\AIM95\AIM95_c1\aim.exe:*:Enabled:AOL Instant Messenger (SM)"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Enabled:mIRC"
"C:\Program Files\Atari-Infogrames\RiskII\RiskII.exe"="C:\Program Files\Atari-Infogrames\RiskII\RiskII.exe:*:Enabled:Risk II"
"C:\Program Files\Yahoo!\Messenger\YPager.exe"="C:\Program Files\Yahoo!\Messenger\YPager.exe:*:Enabled:Yahoo! Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Enabled:Yahoo! FT Server"
"C:\Program Files\Soldat2\Soldat.exe"="C:\Program Files\Soldat2\Soldat.exe:*:Enabled:Soldat"
"C:\Program Files\BROOD\StarCraft.exe"="C:\Program Files\BROOD\StarCraft.exe:*:Enabled:Starcraft"
"C:\Documents and Settings\Kevin\My Documents\TriviaBot\trivbot2001v2\MIRC32.EXE"="C:\Documents and Settings\Kevin\My Documents\TriviaBot\trivbot2001v2\MIRC32.EXE:*:Enabled:Internet Relay Chat Client"
"C:\Program Files\Soulseek\slsk.exe"="C:\Program Files\Soulseek\slsk.exe:*:Enabled:SoulSeek Client"
"C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule"
"C:\Program Files\MAME32k\kaillerasrv.exe"="C:\Program Files\MAME32k\kaillerasrv.exe:*:Enabled:kaillerasrv"
"C:\Program Files\BitTornado\btdownloadgui.exe"="C:\Program Files\BitTornado\btdownloadgui.exe:*:Enabled:btdownloadgui"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Program Files\Kazaa Lite K++\KazaaLite.kpp"="C:\Program Files\Kazaa Lite K++\KazaaLite.kpp:*:Enabled:KazaaLite"
"C:\Documents and Settings\Kevin\Local Settings\Temp\~AceTemp\zsnesw142\zsnesw.exe"="C:\Documents and Settings\Kevin\Local Settings\Temp\~AceTemp\zsnesw142\zsnesw.exe:*:Enabled:zsnesw"
"C:\Program Files\AIM95\AIM95_c0\aim.exe"="C:\Program Files\AIM95\AIM95_c0\aim.exe:*:Enabled:AOL Instant Messenger (SM)"
"C:\Program Files\RealVNC\VNC4\winvnc4.exe"="C:\Program Files\RealVNC\VNC4\winvnc4.exe:*:Enabled:VNC Server Free Edition for Win32"
"C:\Program Files\TetriNET\TETRINET.EXE"="C:\Program Files\TetriNET\TETRINET.EXE:*:Enabled:TETRINET"
"C:\Program Files\eXeem\eXeem.exe"="C:\Program Files\eXeem\eXeem.exe:*:Enabled:eXeem"
"C:\Program Files\Internet Explorer\IEXPLORE.EXE"="C:\Program Files\Internet Explorer\IEXPLORE.EXE:*:Enabled:Internet Explorer"
"C:\Program Files\MAIET\Gunz\Gunz.exe"="C:\Program Files\MAIET\Gunz\Gunz.exe:*:Enabled:Gunz"
"C:\Program Files\MAIET\Gunz\GunzLauncher.exe"="C:\Program Files\MAIET\Gunz\GunzLauncher.exe:*:Enabled:NewApp MFC ?? ????"
"C:\Program Files\MAIET\Gunz\BAReport.exe"="C:\Program Files\MAIET\Gunz\BAReport.exe:*:Enabled:BAReport MFC ?? ????"
"C:\Program Files\softnyx\GunboundWC\GunBound.gme"="C:\Program Files\softnyx\GunboundWC\GunBound.gme:*:Enabled:GunBound"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\ProgramFiles\Soldat2\Soldat.exe"="C:\ProgramFiles\Soldat2\Soldat.exe:*:Enabled:Soldat"
"C:\Program Files\softnyx\Rakion\Bin\Rakion.bin"="C:\Program Files\softnyx\Rakion\Bin\Rakion.bin:*:Enabled:Rakion"
"C:\Program Files\GooGrid\GooWatcherWindow.exe"="C:\Program Files\GooGrid\GooWatcherWindow.exe:*:Enabled:GooWatcherWindow"
"C:\Program Files\GooGrid\GooSpeciesEditor.exe"="C:\Program Files\GooGrid\GooSpeciesEditor.exe:*:Enabled:GooSpeciesEditor"
"C:\Program Files\Mexican Motor Mafia\FlatEngine.exe"="C:\Program Files\Mexican Motor Mafia\FlatEngine.exe:*:Enabled:FlatEngine"
"C:\Program Files\BitComet\BitComet.exe"="C:\Program Files\BitComet\BitComet.exe:*:Enabled:BitComet - a BitTorrent Client"
"C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Program Files\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\WINDOWS\SYSTEM32\DPVSETUP.EXE"="C:\WINDOWS\SYSTEM32\DPVSETUP.EXE:*:Enabled:Microsoft DirectPlay Voice Test"
"C:\Documents and Settings\Kevin\Desktop\VBA\vbaserver.exe"="C:\Documents and Settings\Kevin\Desktop\VBA\vbaserver.exe:*:Enabled:vbaserver"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Enabled:World of Warcraft"
"C:\Program Files\Curse\CurseClient.exe"="C:\Program Files\Curse\CurseClient.exe:*:Enabled:Curse Client"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled

xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled

xpsp3res.dll,-20000"
======List of files/folders created in the last 1 months======
2009-01-24 23:36:42 ----DC---- C:\rsit
2009-01-24 23:34:59 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-01-24 23:34:57 ----D---- C:\Program Files\Alwil Software
2009-01-20 18:40:10 ----DC---- C:\Documents and Settings\All Users\Application Data\ATI
2009-01-20 18:40:10 ----D---- C:\Documents and Settings\Kevin\Application Data\ATI
2009-01-20 18:36:12 ----N---- C:\WINDOWS\system32\ati2sgag.exe
2009-01-20 18:34:20 ----DC---- C:\ATI
2009-01-20 03:07:14 ----D---- C:\Program Files\Trend Micro
2009-01-20 02:22:49 ----D---- C:\Documents and Settings\Kevin\Application Data\Malwarebytes
2009-01-20 02:22:44 ----DC---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-20 02:22:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-19 13:16:28 ----D---- C:\Program Files\World of Warcraft
2009-01-19 02:31:21 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2009-01-19 02:31:21 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2009-01-19 02:31:20 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2009-01-19 02:31:20 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2009-01-19 02:31:20 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2009-01-19 02:31:19 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2009-01-19 02:31:19 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2009-01-19 02:31:18 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-01-19 02:31:18 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-01-19 02:31:18 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-01-19 02:31:17 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-01-19 02:31:17 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-01-19 02:31:17 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-01-19 02:31:16 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-01-19 02:31:16 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-01-19 02:31:16 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-01-19 02:31:15 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-01-19 02:31:14 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-01-19 02:31:14 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-01-19 02:31:14 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-01-19 02:31:13 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-01-19 02:31:13 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-01-19 02:31:12 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-01-19 02:31:12 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-01-19 02:31:12 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-01-19 02:31:11 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-01-19 02:31:11 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-01-19 02:31:10 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-01-19 02:31:10 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-01-19 02:31:10 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-01-19 02:31:08 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-01-19 02:31:08 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-01-19 02:31:08 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-01-19 02:31:08 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-01-19 02:31:07 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-01-19 02:31:07 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-01-19 02:31:07 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-01-19 02:31:07 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-01-19 02:31:06 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-01-19 02:31:06 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-01-19 02:31:05 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-01-19 02:31:04 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-01-19 02:31:04 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-01-19 02:31:01 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-01-19 02:31:01 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-01-19 02:31:01 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-01-19 02:31:00 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-01-19 02:31:00 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-01-19 02:31:00 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-01-19 02:31:00 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2009-01-19 02:31:00 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-01-19 02:30:59 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-01-19 02:30:59 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-01-19 02:30:59 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-01-19 02:30:58 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-01-19 02:30:55 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-01-19 02:30:55 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-01-19 02:30:55 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-01-19 02:30:54 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-01-19 02:30:54 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-01-19 02:30:53 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-01-19 02:30:53 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-01-19 02:30:53 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-01-19 02:30:52 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-01-19 02:30:51 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-01-19 02:04:26 ----HD---- C:\WINDOWS\msdownld.tmp
2009-01-19 02:04:20 ----D---- C:\WINDOWS\Logs
2009-01-18 22:14:16 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2009-01-18 22:12:59 ----HDC---- C:\WINDOWS\$NtUninstallKB954459$
2009-01-18 14:02:41 ----DC---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-01-18 13:49:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-01-18 09:38:21 ----D---- C:\WINDOWS\Prefetch
2009-01-18 03:53:37 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2009-01-18 03:53:31 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-01-18 03:53:25 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-01-18 03:53:18 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-01-18 03:53:12 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-01-18 03:53:05 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-01-18 03:52:57 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-01-18 03:52:51 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-01-18 03:52:45 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-01-18 03:52:38 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-01-18 03:52:32 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2009-01-18 03:52:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-01-18 03:52:20 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2009-01-18 03:52:14 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-01-18 03:52:08 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2009-01-18 03:52:00 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2009-01-18 03:51:53 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-01-18 03:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2009-01-18 03:51:41 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-01-18 03:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2009-01-18 03:43:00 ----D---- C:\WINDOWS\system32\scripting
2009-01-18 03:42:59 ----D---- C:\WINDOWS\l2schemas
2009-01-18 03:42:58 ----D---- C:\WINDOWS\system32\en
2009-01-18 03:42:57 ----D---- C:\WINDOWS\system32\bits
2009-01-18 03:38:31 ----D---- C:\WINDOWS\ServicePackFiles
2009-01-18 03:25:28 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2009-01-18 03:25:23 ----D---- C:\WINDOWS\EHome
2009-01-18 03:16:45 ----DC---- C:\VundoFix Backups
2009-01-18 03:13:48 ----HDC---- C:\WINDOWS\$NtUninstallKB885884$
2009-01-18 02:52:55 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-01-18 02:50:09 ----DC---- C:\Documents and Settings\All Users\Application Data\Adobe(2)
2009-01-17 23:31:30 ----AC---- C:\VundoFix.txt
2009-01-17 23:09:16 ----AC---- C:\WINDOWS\system32\javaws.exe
2009-01-17 23:09:16 ----AC---- C:\WINDOWS\system32\javaw.exe
2009-01-17 23:09:16 ----AC---- C:\WINDOWS\system32\java.exe
2009-01-17 21:31:54 ----D---- C:\Documents and Settings\Kevin\Application Data\dyyno-vlc
2009-01-17 21:19:00 ----D---- C:\Program Files\Dyyno
2009-01-12 00:05:48 ----A---- C:\WINDOWS\system32\57603872-.txt
======List of files/folders modified in the last 1 months======
2009-01-24 23:35:22 ----D---- C:\WINDOWS\system32\DRIVERS
2009-01-24 23:35:19 ----D---- C:\WINDOWS\system32\CONFIG
2009-01-24 23:35:19 ----D---- C:\WINDOWS\SYSTEM32
2009-01-24 23:34:57 ----RD---- C:\Program Files
2009-01-24 18:16:32 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-23 10:13:57 ----A---- C:\WINDOWS\system32\msupdate.cmd
2009-01-23 10:13:50 ----D---- C:\WINDOWS\Temp
2009-01-23 10:13:46 ----A---- C:\WINDOWS\ModemLog_Conexant D850 56K V.9x DFVc Modem.txt
2009-01-23 02:46:36 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-20 18:40:24 ----SHD---- C:\WINDOWS\Installer
2009-01-20 18:40:23 ----DC---- C:\Config.Msi
2009-01-20 18:40:14 ----D---- C:\WINDOWS
2009-01-20 18:37:39 ----D---- C:\Program Files\ATI Technologies
2009-01-20 18:37:37 ----RSD---- C:\WINDOWS\ASSEMBLY
2009-01-20 18:37:27 ----D---- C:\WINDOWS\WinSxS
2009-01-20 18:36:28 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-20 18:35:55 ----RSHD---- C:\WINDOWS\system32\DLLCACHE
2009-01-20 18:35:48 ----HD---- C:\WINDOWS\INF
2009-01-20 10:13:25 ----SD---- C:\WINDOWS\Tasks
2009-01-20 03:26:42 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-20 02:06:33 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2009-01-19 02:31:23 ----D---- C:\WINDOWS\system32\DirectX
2009-01-18 22:13:47 ----A---- C:\WINDOWS\imsins.BAK
2009-01-18 22:04:46 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-18 14:02:22 ----D---- C:\Program Files\Common Files\Adobe
2009-01-18 13:47:16 ----AC---- C:\WINDOWS\OEWABLog.txt
2009-01-18 09:42:42 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-18 09:38:26 ----AC---- C:\WINDOWS\setuplog.txt
2009-01-18 09:37:47 ----D---- C:\WINDOWS\system32\Setup
2009-01-18 09:37:46 ----D---- C:\WINDOWS\system32\WBEM
2009-01-18 09:37:46 ----D---- C:\WINDOWS\AppPatch
2009-01-18 09:37:45 ----RSD---- C:\WINDOWS\Fonts
2009-01-18 09:37:12 ----D---- C:\WINDOWS\SECURITY
2009-01-18 03:53:38 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-18 03:51:42 ----D---- C:\Program Files\Messenger
2009-01-18 03:43:33 ----D---- C:\WINDOWS\network diagnostic
2009-01-18 03:43:33 ----D---- C:\WINDOWS\IME
2009-01-18 03:43:33 ----D---- C:\WINDOWS\Help
2009-01-18 03:43:02 ----D---- C:\WINDOWS\system32\USMT
2009-01-18 03:43:02 ----D---- C:\WINDOWS\system32\en-US
2009-01-18 03:42:57 ----D---- C:\WINDOWS\PeerNet
2009-01-18 03:42:56 ----D---- C:\Program Files\Movie Maker
2009-01-18 03:38:19 ----D---- C:\WINDOWS\system32\Restore
2009-01-18 03:38:18 ----D---- C:\WINDOWS\system32\NPP
2009-01-18 03:38:15 ----D---- C:\WINDOWS\MSAGENT
2009-01-18 03:38:12 ----D---- C:\WINDOWS\SRCHASST
2009-01-18 03:38:07 ----D---- C:\Program Files\NetMeeting
2009-01-18 03:38:04 ----D---- C:\WINDOWS\system32\Com
2009-01-18 03:37:59 ----D---- C:\Program Files\Windows Media Player
2009-01-18 03:37:58 ----D---- C:\Program Files\Windows NT
2009-01-18 03:37:58 ----D---- C:\Program Files\Outlook Express
2009-01-18 03:37:52 ----D---- C:\Program Files\Common Files\System
2009-01-18 03:37:14 ----D---- C:\WINDOWS\system32\OOBE
2009-01-18 03:37:10 ----D---- C:\WINDOWS\SYSTEM
2009-01-18 03:32:15 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-01-18 02:57:15 ----D---- C:\WINDOWS\Registration
2009-01-18 02:55:44 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-01-18 02:53:29 ----D---- C:\Program Files\Adobe
2009-01-18 02:52:55 ----D---- C:\Program Files\Common Files
2009-01-18 02:45:41 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-17 23:08:18 ----D---- C:\Program Files\Java
2009-01-09 20:35:28 ----A---- C:\WINDOWS\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\system32\DRIVERS\omci.sys [2002-11-08 17217]
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-07-14 5627]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-07-14 23545]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-08-13 40544]
R2 dsunidrv;DellSupport UniDriver; C:\WINDOWS\system32\DRIVERS\dsunidrv.sys [2007-02-25 5376]
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-08-13 25723]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-08-13 34843]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-08-13 4123]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-08-13 2239]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-08-13 86202]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-08-13 14715]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-08-13 6363]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-08-13 98714]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-08-13 100603]
R3 aeaudio;aeaudio; C:\WINDOWS\system32\drivers\aeaudio.sys [2002-04-01 4816]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-12-01 3452928]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys [2003-09-22 130192]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSF_DP.sys [2003-11-17 1042432]
R3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFHWBS2.sys [2003-11-17 212224]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\DRIVERS\ctoss2k.sys [2003-09-22 178672]
R3 P17;Sound Blaster Live! 24-bit; C:\WINDOWS\system32\drivers\P17.sys [2004-06-09 840960]
R3 rt2500usb;RT2500 USB Wireless LAN Driver; C:\WINDOWS\system32\DRIVERS\rt2500usb.sys [2005-01-07 147328]
R3 smwdm;smwdm; C:\WINDOWS\system32\drivers\smwdm.sys [2004-04-09 612352]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
R3 wanatw;WAN Miniport (ATW); C:\WINDOWS\system32\DRIVERS\wanatw4.sys [2003-01-10 33588]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2003-11-17 680704]
S1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-11-26 26944]
S1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-11-26 111184]
S1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-11-26 50864]
S2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
S2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-11-26 94032]
S3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-11-26 23152]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\system32\drivers\bvrp_pci.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 DSproct;DSproct; \??\C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys []
S3 dtscsi;dtscsi; C:\WINDOWS\System32\Drivers\dtscsi.sys [2006-07-15 223128]
S3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2004-02-10 154112]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 npkcrypt;npkcrypt; \??\C:\Program Files\aeRO Gaming\aeRO Full Install\npkcrypt.sys []
S3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408]
S3 QCDonner;Logitech QuickCam Express; C:\WINDOWS\system32\DRIVERS\OVCD.sys [2001-08-17 28032]
S3 RT73;Belkin USB Network Adapter; C:\WINDOWS\system32\DRIVERS\rt73.sys [2005-08-02 232192]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 XTrapD12;XTrapD12; \??\C:\Program Files\MAIET\Gunz\XTrap\XTrapD12.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AOL ACS;AOL Connectivity Service; C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe [2003-08-06 1376360]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-12-01 598016]
R2 Creative Service for CDROM Access;Creative Service for CDROM Access; C:\WINDOWS\system32\CTsvcCDA.EXE [1999-12-13 44032]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2004-09-15 38912]
R2 WANMiniportService;WAN Miniport (ATW) Service; C:\WINDOWS\wanmpsvc.exe [2003-01-10 65536]
R2 WMDM PMSP Service;WMDM PMSP Service; C:\WINDOWS\system32\MsPMSPSv.exe [2000-06-26 53520]
S2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]
S2 ATI Smart;ATI Smart; C:\WINDOWS\SYSTEM32\ati2sgag.exe [2008-12-01 593920]
S2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 dlbt_device;dlbt_device; C:\WINDOWS\system32\dlbtcoms.exe [2004-03-16 421888]
S3 DSBrokerService;DSBrokerService; C:\Program Files\DellSupport\brkrsvc.exe [2007-03-07 76848]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 iPodService;iPodService; C:\Program Files\iPod\bin\iPodService.exe []
S3 NetSvc;Intel NCS NetService; C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exe [2003-12-17 143360]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S4 MCVSRte;McAfee.com VirusScan Online Realtime Engine; c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe /Embedding []
-----------------EOF-----------------