![]() |
|
#1
| |||
| |||
| Avast just stated they found a trojan namily a worm. I moved it to the chest is there anything else I need to do? Many thanks, MPenney |
|
#2
| |||
| |||
| Let's have a closer look. Download random's system information tool (RSIT) by random/random from and save it to your Desktop.
|
|
#3
| |||
| |||
| Logfile of random's system information tool 1.04 (written by random/random) Run by Movie Mode at 2008-10-25 15:10:09 Microsoft Windows XP Professional Service Pack 3 System drive C: has 38 GB (49%) free of 76 GB Total RAM: 1023 MB (19% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:10:51 PM, on 10/25/2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Alwil Software\Avast4\ashServ.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\IoctlSvc.exe C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe C:\Program Files\Alwil Software\Avast4\ashWebSv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\NETGEAR\WN111\wn111.exe C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Program Files\Internet Explorer\IEXPLORE.EXE C:\Program Files\dvdSanta\dvdSanta.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\FREEDO~1\fdm.exe C:\Documents and Settings\Movie Mode\Desktop\RSIT.exe C:\Program Files\trend micro\Movie Mode.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe" O4 - HKLM\..\Run: [CPMonitor] "C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe" O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - Global Startup: NETGEAR WN111 Smart Wizard.lnk = C:\Program Files\NETGEAR\WN111\wn111.exe O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - https://fpdownload.macromedia.com/ge...sh/swflash.cab O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: Roxio UPnP Renderer 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe O23 - Service: Roxio Upnp Server 11 - Sonic Solutions - C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe O23 - Service: LiveShare P2P Server 11 (RoxLiveShare11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe O23 - Service: RoxMediaDB11 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe O23 - Service: Roxio Hard Drive Watcher 11 (RoxWatch11) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe -- End of file - 7221 bytes ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2007-09-20 328752] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-10-15 2403392] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-10-24 737776] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}] FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-06-18 94208] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-10-15 2403392] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-07-19 78008] "Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672] "NeroFilterCheck"=C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe [2008-06-19 570664] "NBKeyScan"=C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352] ""= [] "RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatchTray11.exe [2008-08-14 240112] "CPMonitor"=C:\Program Files\Roxio Creator 2009\5.0\CPMonitor.exe [2008-08-10 80368] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424] "swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-10-24 68856] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360] C:\Documents and Settings\All Users\Start Menu\Programs\Startup NETGEAR WN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WN111\wn111.exe [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Program Files\eMule\emule.exe"="C:\Program Files\eMule\emule.exe:*:Enabled:eMule" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eeda0cb5-98e2-11dd-81bd-001e2a494297}] shell\AutoRun\command - E:\LaunchU3.exe -a [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{eeda0cb7-98e2-11dd-81bd-001e2a494297}] shell\AutoRun\command - H:\LaunchU3.exe -a ======List of files/folders created in the last 1 months====== 2008-10-25 15:10:12 ----D---- C:\Program Files\trend micro 2008-10-25 15:10:09 ----D---- C:\rsit 2008-10-24 23:19:22 ----D---- C:\Documents and Settings\Movie Mode\Application Data\ImgBurn 2008-10-24 20:41:00 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Free Download Manager 2008-10-24 20:40:32 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Free Upload Manager 2008-10-24 17:03:28 ----D---- C:\Documents and Settings\Movie Mode\Application Data\WinRAR 2008-10-24 16:16:50 ----D---- C:\WINDOWS\system32\NtmsData 2008-10-24 03:01:28 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$ 2008-10-24 03:00:48 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$ 2008-10-23 23:11:52 ----D---- C:\Documents and Settings\All Users\Application Data\Apple Computer 2008-10-23 23:11:39 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Roxio 2008-10-23 23:05:28 ----D---- C:\Documents and Settings\All Users\Application Data\Uninstall 2008-10-23 23:04:01 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Macromedia 2008-10-23 22:58:57 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Adobe 2008-10-23 22:58:51 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Google 2008-10-23 22:49:59 ----D---- C:\Program Files\Roxio 2008-10-23 22:47:23 ----D---- C:\Documents and Settings\Movie Mode\Application Data\U3 2008-10-23 22:47:23 ----D---- C:\Documents and Settings\All Users\Application Data\InstallShield 2008-10-23 22:44:50 ----D---- C:\Program Files\Windows Sidebar 2008-10-23 22:43:31 ----D---- C:\Documents and Settings\All Users\Application Data\Roxio 2008-10-23 22:43:15 ----D---- C:\Program Files\Common Files\Sonic Shared 2008-10-23 22:40:53 ----D---- C:\Documents and Settings\All Users\Application Data\Sonic 2008-10-23 22:40:37 ----D---- C:\Program Files\Common Files\Roxio Shared 2008-10-23 22:40:33 ----D---- C:\Program Files\Roxio Creator 2009 2008-10-23 22:40:10 ----D---- C:\Documents and Settings\All Users\Application Data\SmartSound Software Inc 2008-10-23 22:40:09 ----D---- C:\Program Files\SmartSound Software 2008-10-23 22:39:58 ----D---- C:\Program Files\Common Files\InstallShield 2008-10-23 22:39:44 ----A---- C:\WINDOWS\system32\xactengine2_10.dll 2008-10-23 22:39:43 ----A---- C:\WINDOWS\system32\d3dx10_36.dll 2008-10-23 22:39:43 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll 2008-10-23 22:39:42 ----A---- C:\WINDOWS\system32\d3dx9_36.dll 2008-10-23 22:39:41 ----A---- C:\WINDOWS\system32\xactengine2_9.dll 2008-10-23 22:39:40 ----A---- C:\WINDOWS\system32\d3dx9_35.dll 2008-10-23 22:39:40 ----A---- C:\WINDOWS\system32\d3dx10_35.dll 2008-10-23 22:39:40 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll 2008-10-23 22:39:39 ----A---- C:\WINDOWS\system32\xactengine2_8.dll 2008-10-23 22:39:39 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll 2008-10-23 22:39:38 ----A---- C:\WINDOWS\system32\d3dx10_34.dll 2008-10-23 22:39:38 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll 2008-10-23 22:39:37 ----A---- C:\WINDOWS\system32\d3dx9_34.dll 2008-10-23 22:39:36 ----A---- C:\WINDOWS\system32\xinput1_3.dll 2008-10-23 22:39:34 ----A---- C:\WINDOWS\system32\xactengine2_7.dll 2008-10-23 22:39:31 ----A---- C:\WINDOWS\system32\d3dx10_33.dll 2008-10-23 22:39:31 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll 2008-10-23 22:39:29 ----A---- C:\WINDOWS\system32\d3dx9_33.dll 2008-10-23 22:39:28 ----A---- C:\WINDOWS\system32\xactengine2_6.dll 2008-10-23 22:39:28 ----A---- C:\WINDOWS\system32\xactengine2_5.dll 2008-10-23 22:39:27 ----A---- C:\WINDOWS\system32\d3dx9_32.dll 2008-10-23 22:39:26 ----A---- C:\WINDOWS\system32\xactengine2_4.dll 2008-10-23 22:39:26 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll 2008-10-23 22:39:26 ----A---- C:\WINDOWS\system32\d3dx9_31.dll 2008-10-23 22:39:25 ----A---- C:\WINDOWS\system32\xinput1_2.dll 2008-10-23 22:39:25 ----A---- C:\WINDOWS\system32\xactengine2_3.dll 2008-10-23 22:39:24 ----A---- C:\WINDOWS\system32\xinput1_1.dll 2008-10-23 22:39:24 ----A---- C:\WINDOWS\system32\xactengine2_2.dll 2008-10-23 22:39:24 ----A---- C:\WINDOWS\system32\xactengine2_1.dll 2008-10-23 22:39:13 ----A---- C:\WINDOWS\system32\xactengine2_0.dll 2008-10-23 22:39:13 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll 2008-10-23 22:39:12 ----A---- C:\WINDOWS\system32\d3dx9_29.dll 2008-10-23 22:39:11 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll 2008-10-23 22:39:11 ----A---- C:\WINDOWS\system32\d3dx9_27.dll 2008-10-23 22:39:10 ----A---- C:\WINDOWS\system32\d3dx9_26.dll 2008-10-23 22:39:09 ----A---- C:\WINDOWS\system32\d3dx9_25.dll 2008-10-23 22:39:09 ----A---- C:\WINDOWS\system32\d3dx9_24.dll 2008-10-23 22:37:20 ----D---- C:\Program Files\MSBuild 2008-10-23 22:37:15 ----D---- C:\WINDOWS\system32\XPSViewer 2008-10-23 22:37:10 ----D---- C:\Program Files\Reference Assemblies 2008-10-23 22:36:36 ----N---- C:\WINDOWS\system32\spmsg2.dll 2008-10-23 22:35:42 ----RSD---- C:\WINDOWS\assembly 2008-10-23 22:35:01 ----D---- C:\WINDOWS\Microsoft.NET 2008-10-23 22:27:40 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Nero 2008-10-23 22:26:50 ----D---- C:\WINDOWS\Prefetch 2008-10-23 18:33:13 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$ 2008-10-23 18:33:04 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$ 2008-10-23 18:32:56 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$ 2008-10-23 18:32:47 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$ 2008-10-23 18:32:37 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$ 2008-10-23 18:32:29 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$ 2008-10-23 18:32:21 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$ 2008-10-23 18:32:13 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$ 2008-10-23 18:32:06 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$ 2008-10-23 18:31:57 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$ 2008-10-23 18:31:49 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$ 2008-10-23 18:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$ 2008-10-23 18:31:35 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$ 2008-10-23 18:31:28 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$ 2008-10-23 18:27:43 ----D---- C:\WINDOWS\system32\scripting 2008-10-23 18:27:42 ----D---- C:\WINDOWS\l2schemas 2008-10-23 18:27:41 ----D---- C:\WINDOWS\system32\en 2008-10-23 18:27:41 ----D---- C:\WINDOWS\system32\bits 2008-10-23 18:25:21 ----D---- C:\WINDOWS\ServicePackFiles 2008-10-23 18:21:38 ----D---- C:\WINDOWS\system32\ReinstallBackups 2008-10-23 18:17:45 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$ 2008-10-21 03:00:57 ----D---- C:\Program Files\MSXML 4.0 2008-10-20 03:01:19 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$ 2008-10-20 03:00:58 ----HDC---- C:\WINDOWS\$NtUninstallKB923689$ 2008-10-19 16:02:12 ----A---- C:\WINDOWS\NeroDigital.ini 2008-10-19 15:03:12 ----D---- C:\Program Files\PeerGuardian2 2008-10-19 00:49:53 ----A---- C:\WINDOWS\system32\MsiExec.exe.log 2008-10-19 00:47:29 ----D---- C:\Program Files\Nero 2008-10-19 00:47:29 ----D---- C:\Documents and Settings\All Users\Application Data\Nero 2008-10-19 00:47:28 ----D---- C:\Program Files\Common Files\Nero 2008-10-19 00:46:03 ----D---- C:\WINDOWS\RegisteredPackages 2008-10-19 00:45:14 ----A---- C:\WINDOWS\system32\d3dx9_30.dll 2008-10-19 00:45:11 ----A---- C:\WINDOWS\system32\d3dx9_28.dll 2008-10-16 21:06:07 ----D---- C:\Program Files\eMule 2008-10-15 20:04:27 ----D---- C:\Documents and Settings\All Users\Application Data\Google 2008-10-15 20:04:20 ----D---- C:\Program Files\Google 2008-10-15 20:03:58 ----D---- C:\Documents and Settings\All Users\Application Data\NOS 2008-10-15 20:03:57 ----D---- C:\Program Files\NOS 2008-10-15 20:02:14 ----D---- C:\Program Files\Common Files\Adobe AIR 2008-10-15 20:01:34 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe 2008-10-15 20:01:26 ----D---- C:\Program Files\Common Files\Adobe 2008-10-15 20:01:26 ----D---- C:\Program Files\Adobe 2008-10-15 19:04:17 ----D---- C:\Program Files\Lavasoft 2008-10-15 19:04:17 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft 2008-10-15 19:03:32 ----D---- C:\Program Files\Common Files\Wise Installation Wizard 2008-10-14 22:54:59 ----HDC---- C:\WINDOWS\$NtUninstallKB956803_0$ 2008-10-14 22:54:44 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$ 2008-10-14 22:54:39 ----HDC---- C:\WINDOWS\$NtUninstallKB957095_0$ 2008-10-14 22:54:17 ----HDC---- C:\WINDOWS\$NtUninstallKB954211_0$ 2008-10-14 22:53:51 ----HDC---- C:\WINDOWS\$NtUninstallKB956841_0$ 2008-10-14 22:52:55 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$ 2008-10-14 19:47:41 ----A---- C:\WINDOWS\system32\hidserv.dll 2008-10-14 15:26:23 ----A---- C:\WINDOWS\system32\muweb.dll 2008-10-14 15:26:23 ----A---- C:\WINDOWS\system32\mucltui.dll.mui 2008-10-14 15:26:23 ----A---- C:\WINDOWS\system32\mucltui.dll 2008-10-14 15:00:44 ----D---- C:\Documents and Settings\All Users\Application Data\SlySoft 2008-10-14 14:59:21 ----D---- C:\Program Files\SlySoft 2008-10-14 14:19:03 ----A---- C:\WINDOWS\system32\aswBoot.exe 2008-10-14 14:19:02 ----D---- C:\Program Files\Alwil Software 2008-10-14 14:18:23 ----D---- C:\Program Files\CCleaner 2008-10-14 14:06:00 ----D---- C:\WINDOWS\ie7updates 2008-10-14 14:05:25 ----D---- C:\WINDOWS\WBEM 2008-10-14 14:05:24 ----D---- C:\WINDOWS\system32\en-US 2008-10-14 14:04:19 ----HDC---- C:\WINDOWS\ie7 2008-10-14 14:04:04 ----HDC---- C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$ 2008-10-14 14:03:46 ----HDC---- C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$ 2008-10-14 14:03:27 ----HDC---- C:\WINDOWS\$NtUninstallKB915865$ 2008-10-14 14:03:24 ----N---- C:\WINDOWS\system32\xmllite.dll 2008-10-14 14:02:08 ----A---- C:\WINDOWS\system32\MRT.exe 2008-10-14 14:02:04 ----D---- C:\WINDOWS\network diagnostic 2008-10-14 14:02:03 ----HDC---- C:\WINDOWS\$NtUninstallKB914440$ 2008-10-14 14:01:55 ----HDC---- C:\WINDOWS\$NtUninstallKB904942$ 2008-10-14 13:54:15 ----D---- C:\04d78fb1a5b9721890cded0fff 2008-10-14 13:52:17 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller 2008-10-14 13:51:52 ----D---- C:\Program Files\Windows Live 2008-10-14 13:51:43 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller 2008-10-14 11:27:29 ----HDC---- C:\WINDOWS\$MSI31Uninstall_KB893803v2$ 2008-10-14 11:04:56 ----D---- C:\Documents and Settings\All Users\Application Data\DVD Shrink 2008-10-14 11:04:54 ----D---- C:\Program Files\DVD Shrink 2008-10-14 11:01:12 ----D---- C:\Program Files\QuickTime 2008-10-14 11:01:12 ----A---- C:\WINDOWS\system32\WNASPI32.DLL 2008-10-14 11:01:11 ----A---- C:\temp.txt 2008-10-14 08:59:28 ----A---- C:\WINDOWS\dvdSanta.INI 2008-10-14 07:23:42 ----D---- C:\Program Files\ImgBurn 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\xvidvfw.dll 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\xvidcore.dll 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\vorbisenc.dll 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\vorbis.dll 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\OggDS.dll 2008-10-14 07:21:39 ----A---- C:\WINDOWS\system32\ogg.dll 2008-10-14 07:21:38 ----D---- C:\Program Files\dvdSanta 2008-10-14 07:21:31 ----SHD---- C:\RECYCLER 2008-10-14 03:02:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2_0$ 2008-10-14 03:02:00 ----HDC---- C:\WINDOWS\$NtUninstallKB952954_0$ 2008-10-14 03:01:54 ----HDC---- C:\WINDOWS\$NtUninstallKB946648_0$ 2008-10-14 03:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB953839$ 2008-10-14 03:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950974_0$ 2008-10-14 03:01:37 ----HDC---- C:\WINDOWS\$NtUninstallKB951698_0$ 2008-10-14 03:01:32 ----HDC---- C:\WINDOWS\$NtUninstallKB950762_0$ 2008-10-14 03:01:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$ 2008-10-14 03:01:20 ----HDC---- C:\WINDOWS\$NtUninstallKB952287_0$ 2008-10-14 03:01:14 ----HDC---- C:\WINDOWS\$NtUninstallKB951066_0$ 2008-10-14 03:01:00 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$ 2008-10-14 03:00:52 ----HDC---- C:\WINDOWS\$NtUninstallKB951748_0$ 2008-10-14 03:00:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950749$ 2008-10-14 03:00:37 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$ 2008-10-14 03:00:25 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$ 2008-10-13 18:58:40 ----D---- C:\TempDVD 2008-10-13 18:58:40 ----D---- C:\dvdsanta 2008-10-13 18:56:41 ----D---- C:\Program Files\Xilisoft 2008-10-13 18:51:47 ----D---- C:\Documents and Settings\Movie Mode\Application Data\Identities 2008-10-13 18:51:35 ----SD---- C:\Documents and Settings\Movie Mode\Application Data\Microsoft 2008-10-13 18:51:35 ----ASH---- C:\Documents and Settings\Movie Mode\Application Data\desktop.ini 2008-10-13 12:12:29 ----N---- C:\WINDOWS\system32\wmphoto.dll 2008-10-13 12:12:26 ----N---- C:\WINDOWS\system32\wlanapi.dll 2008-10-13 12:12:25 ----N---- C:\WINDOWS\system32\windowscodecsext.dll 2008-10-13 12:12:25 ----N---- C:\WINDOWS\system32\windowscodecs.dll 2008-10-13 12:12:23 ----N---- C:\WINDOWS\system32\verclsid.exe 2008-10-13 12:12:19 ----N---- C:\WINDOWS\system32\tspkg.dll 2008-10-13 12:12:19 ----N---- C:\WINDOWS\system32\tsgqec.dll 2008-10-13 12:12:14 ----N---- C:\WINDOWS\system32\spupdwxp.exe 2008-10-13 12:12:13 ----A---- C:\WINDOWS\system32\spdwnwxp.exe 2008-10-13 12:12:11 ----N---- C:\WINDOWS\system32\slserv.exe 2008-10-13 12:12:11 ----N---- C:\WINDOWS\system32\slrundll.exe 2008-10-13 12:12:11 ----N---- C:\WINDOWS\system32\slgen.dll 2008-10-13 12:12:11 ----N---- C:\WINDOWS\system32\slextspk.dll 2008-10-13 12:12:11 ----N---- C:\WINDOWS\system32\slcoinst.dll 2008-10-13 12:12:11 ----N---- C:\WINDOWS\slrundll.exe 2008-10-13 12:12:09 ----N---- C:\WINDOWS\system32\setupn.exe 2008-10-13 12:12:07 ----N---- C:\WINDOWS\system32\s3gnb.dll 2008-10-13 12:12:06 ----N---- C:\WINDOWS\system32\rhttpaa.dll 2008-10-13 12:12:05 ----N---- C:\WINDOWS\system32\rasqec.dll 2008-10-13 12:12:04 ----N---- C:\WINDOWS\system32\qutil.dll 2008-10-13 12:12:04 ----N---- C:\WINDOWS\system32\qcliprov.dll 2008-10-13 12:12:04 ----N---- C:\WINDOWS\system32\qagentrt.dll 2008-10-13 12:12:04 ----N---- C:\WINDOWS\system32\qagent.dll 2008-10-13 12:12:02 ----N---- C:\WINDOWS\system32\photometadatahandler.dll 2008-10-13 12:12:00 ----N---- C:\WINDOWS\system32\onex.dll 2008-10-13 12:11:55 ----N---- C:\WINDOWS\system32\napstat.exe 2008-10-13 12:11:55 ----N---- C:\WINDOWS\system32\napmontr.dll 2008-10-13 12:11:55 ----N---- C:\WINDOWS\system32\napipsec.dll 2008-10-13 12:11:54 ----N---- C:\WINDOWS\system32\mtxparhd.dll 2008-10-13 12:11:53 ----N---- C:\WINDOWS\system32\msxml6r.dll 2008-10-13 12:11:53 ----N---- C:\WINDOWS\system32\msxml6.dll 2008-10-13 12:11:52 ----N---- C:\WINDOWS\system32\msshavmsg.dll 2008-10-13 12:11:52 ----N---- C:\WINDOWS\system32\mssha.dll 2008-10-13 12:11:42 ----N---- C:\WINDOWS\system32\mmcperf.exe 2008-10-13 12:11:42 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll 2008-10-13 12:11:42 ----N---- C:\WINDOWS\system32\mmcex.dll 2008-10-13 12:11:42 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll 2008-10-13 12:11:41 ----N---- C:\WINDOWS\system32\mdmxsdk.dll 2008-10-13 12:11:37 ----N---- C:\WINDOWS\system32\l2gpstore.dll 2008-10-13 12:11:37 ----N---- C:\WINDOWS\system32\kmsvc.dll 2008-10-13 12:11:37 ----N---- C:\WINDOWS\system32\kbdpash.dll 2008-10-13 12:11:37 ----N---- C:\WINDOWS\system32\kbdnepr.dll 2008-10-13 12:11:37 ----N---- C:\WINDOWS\system32\kbdiultn.dll 2008-10-13 12:11:36 ----N---- C:\WINDOWS\system32\kbdbhc.dll 2008-10-13 12:11:34 ----N---- C:\WINDOWS\system32\smtpapi.dll 2008-10-13 12:11:34 ----N---- C:\WINDOWS\system32\rwnh.dll 2008-10-13 12:11:32 ----N---- C:\WINDOWS\system32\comsdupd.exe 2008-10-13 12:11:31 ----N---- C:\WINDOWS\system32\hsfcisp2.dll 2008-10-13 12:11:31 ----N---- C:\WINDOWS\system32\hccoin.dll 2008-10-13 12:11:30 ----N---- C:\WINDOWS\system32\faxpatch.exe 2008-10-13 12:11:30 ----A---- C:\WINDOWS\002883_.tmp 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eapsvc.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eapqec.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eappprxy.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eapphost.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eappgnui.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eappcfg.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eapp3hst.dll 2008-10-13 12:11:29 ----N---- C:\WINDOWS\system32\eapolqec.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3ui.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3svc.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3msm.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3dlg.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3cfg.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dot3api.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dimsroam.dll 2008-10-13 12:11:28 ----N---- C:\WINDOWS\system32\dimsntfy.dll 2008-10-13 12:11:27 ----N---- C:\WINDOWS\system32\dhcpqec.dll 2008-10-13 12:11:27 ----N---- C:\WINDOWS\system32\credssp.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\bitsprx4.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\azroles.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\ativvaxx.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\ativtmxx.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\ati3duag.dll 2008-10-13 12:11:25 ----N---- C:\WINDOWS\system32\ati3d1ag.dll 2008-10-13 12:11:24 ----N---- C:\WINDOWS\system32\ati2dvag.dll 2008-10-13 12:11:24 ----N---- C:\WINDOWS\system32\ati2dvaa.dll 2008-10-13 12:11:24 ----N---- C:\WINDOWS\system32\ati2cqag.dll 2008-10-13 12:11:23 ----N---- C:\WINDOWS\system32\aaclient.dll 2008-10-13 03:00:18 ----D---- C:\WINDOWS\system32\PreInstall 2008-10-13 03:00:17 ----A---- C:\WINDOWS\system32\spupdsvc.exe 2008-10-13 03:00:16 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$ 2008-10-13 00:47:49 ----D---- C:\Downloads 2008-10-13 00:43:16 ----D---- C:\Program Files\WinRAR 2008-10-13 00:43:10 ----D---- C:\Program Files\Software Informer 2008-10-13 00:43:06 ----D---- C:\Program Files\Free Download Manager 2008-10-13 00:43:06 ----D---- C:\Documents and Settings\All Users\Application Data\FreeDownloadManager.ORG 2008-10-13 00:31:02 ----D---- C:\WINDOWS\system32\SoftwareDistribution 2008-10-13 00:29:37 ----D---- C:\Program Files\InstallShield Installation Information 2008-10-13 00:28:45 ----D---- C:\OEMSettings 2008-10-13 00:28:21 ----D---- C:\Program Files\NETGEAR 2008-10-13 00:00:04 ----A---- C:\WINDOWS\system32\msonpmon.dll 2008-10-12 23:59:39 ----D---- C:\Program Files\Microsoft Works 2008-10-12 23:59:30 ----D---- C:\Program Files\Common Files\DESIGNER 2008-10-12 23:57:56 ----D---- C:\WINDOWS\SHELLNEW 2008-10-12 23:57:40 ----D---- C:\Program Files\Microsoft Office 2008-10-12 23:57:39 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2008-10-12 23:57:14 ----RHD---- C:\MSOCache 2008-10-12 23:53:54 ----HD---- C:\Program Files\Uninstall Information 2008-10-12 23:52:25 ----D---- C:\WINDOWS\SoftwareDistribution 2008-10-12 23:52:23 ----SD---- C:\WINDOWS\system32\Microsoft 2008-10-12 23:52:23 ----A---- C:\WINDOWS\SchedLgU.Txt 2008-10-12 23:48:15 ----D---- C:\WINDOWS\system32\xircom 2008-10-12 23:48:15 ----D---- C:\Program Files\xerox 2008-10-12 23:48:15 ----D---- C:\Program Files\microsoft frontpage 2008-10-12 23:48:01 ----N---- C:\WINDOWS\system32\spmsg.dll 2008-10-12 23:48:00 ----HD---- C:\WINDOWS\$hf_mig$ 2008-10-12 23:47:58 ----A---- C:\WINDOWS\system32\xpsp3res.dll 2008-10-12 23:47:47 ----A---- C:\WINDOWS\control.ini 2008-10-12 23:47:47 ----A---- C:\AUTOEXEC.BAT 2008-10-12 23:47:37 ----A---- C:\WINDOWS\OEWABLog.txt 2008-10-12 23:47:33 ----A---- C:\WINDOWS\system32\mapi32.dll 2008-10-12 23:46:42 ----SD---- C:\WINDOWS\Downloaded |
|
#4
| |||
| |||
| Program Files 2008-10-12 23:46:42 ----RD---- C:\WINDOWS\Offline Web Pages 2008-10-12 23:46:42 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest 2008-10-12 23:46:35 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest 2008-10-12 23:46:31 ----HD---- C:\Program Files\WindowsUpdate 2008-10-12 23:46:03 ----D---- C:\WINDOWS\system32\DirectX 2008-10-12 23:45:28 ----A---- C:\WINDOWS\system32\atrace.dll 2008-10-12 23:45:23 ----A---- C:\WINDOWS\system32\desktop.ini 2008-10-12 23:45:23 ----A---- C:\WINDOWS\desktop.ini 2008-10-12 23:45:12 ----A---- C:\WINDOWS\system32\nmevtmsg.dll 2008-10-12 23:45:10 ----A---- C:\WINDOWS\system32\acctres.dll 2008-10-12 23:45:09 ----D---- C:\Program Files\Common Files\Services 2008-10-12 23:45:05 ----SD---- C:\WINDOWS\Tasks 2008-10-12 23:45:05 ----A---- C:\WINDOWS\system32\icfgnt5.dll 2008-10-12 23:45:03 ----D---- C:\Program Files\Common Files\MSSoap 2008-10-12 23:44:56 ----D---- C:\WINDOWS\srchasst 2008-10-12 23:44:54 ----D---- C:\WINDOWS\system32\Macromed 2008-10-12 23:44:49 ----A---- C:\WINDOWS\system32\wuweb.dll 2008-10-12 23:44:49 ----A---- C:\WINDOWS\system32\wucltui.dll 2008-10-12 23:44:48 ----A---- C:\WINDOWS\system32\wups.dll 2008-10-12 23:44:48 ----A---- C:\WINDOWS\system32\wuauserv.dll 2008-10-12 23:44:48 ----A---- C:\WINDOWS\system32\wuaueng1.dll 2008-10-12 23:44:48 ----A---- C:\WINDOWS\system32\wuaueng.dll 2008-10-12 23:44:47 ----A---- C:\WINDOWS\system32\wuauclt1.exe 2008-10-12 23:44:47 ----A---- C:\WINDOWS\system32\wuauclt.exe 2008-10-12 23:44:47 ----A---- C:\WINDOWS\system32\wuapi.dll 2008-10-12 23:44:47 ----A---- C:\WINDOWS\system32\bitsprx3.dll 2008-10-12 23:44:47 ----A---- C:\WINDOWS\system32\bitsprx2.dll 2008-10-12 23:44:46 ----A---- C:\WINDOWS\system32\qmgrprxy.dll 2008-10-12 23:44:46 ----A---- C:\WINDOWS\system32\qmgr.dll 2008-10-12 23:44:39 ----D---- C:\Program Files\Movie Maker 2008-10-12 23:44:33 ----A---- C:\WINDOWS\system32\safrslv.dll 2008-10-12 23:44:33 ----A---- C:\WINDOWS\system32\safrdm.dll 2008-10-12 23:44:33 ----A---- C:\WINDOWS\system32\safrcdlg.dll 2008-10-12 23:44:33 ----A---- C:\WINDOWS\system32\racpldlg.dll 2008-10-12 23:44:26 ----A---- C:\WINDOWS\system32\fltlib.dll 2008-10-12 23:44:25 ----D---- C:\WINDOWS\system32\Restore 2008-10-12 23:44:25 ----A---- C:\WINDOWS\system32\srrstr.dll 2008-10-12 23:44:25 ----A---- C:\WINDOWS\system32\fltmc.exe 2008-10-12 23:44:24 ----A---- C:\WINDOWS\system32\srsvc.dll 2008-10-12 23:44:24 ----A---- C:\WINDOWS\system32\srclient.dll 2008-10-12 23:44:23 ----A---- C:\WINDOWS\system32\mnmdd.dll 2008-10-12 23:44:23 ----A---- C:\WINDOWS\system32\isrdbg32.dll 2008-10-12 23:44:23 ----A---- C:\WINDOWS\system32\ils.dll 2008-10-12 23:44:22 ----A---- C:\WINDOWS\system32\nmmkcert.dll 2008-10-12 23:44:22 ----A---- C:\WINDOWS\system32\msconf.dll 2008-10-12 23:44:22 ----A---- C:\WINDOWS\system32\mnmsrvc.exe 2008-10-12 23:44:17 ----D---- C:\Program Files\NetMeeting 2008-10-12 23:44:17 ----A---- C:\WINDOWS\system32\msoert2.dll 2008-10-12 23:44:17 ----A---- C:\WINDOWS\system32\msoeacct.dll 2008-10-12 23:44:15 ----A---- C:\WINDOWS\system32\inetres.dll 2008-10-12 23:44:14 ----A---- C:\WINDOWS\system32\inetcomm.dll 2008-10-12 23:44:11 ----D---- C:\Program Files\Outlook Express 2008-10-12 23:44:11 ----A---- C:\WINDOWS\system32\schedsvc.dll 2008-10-12 23:44:11 ----A---- C:\WINDOWS\system32\mstinit.exe 2008-10-12 23:44:10 ----A---- C:\WINDOWS\system32\mstask.dll 2008-10-12 23:44:10 ----A---- C:\WINDOWS\system32\icwphbk.dll 2008-10-12 23:44:09 ----A---- C:\WINDOWS\system32\isign32.dll 2008-10-12 23:44:09 ----A---- C:\WINDOWS\system32\inetcfg.dll 2008-10-12 23:44:09 ----A---- C:\WINDOWS\system32\icwdial.dll 2008-10-12 23:43:59 ----D---- C:\Program Files\Common Files\System 2008-10-12 23:43:57 ----D---- C:\Program Files\Internet Explorer 2008-10-12 23:43:23 ----D---- C:\Program Files\ComPlus Applications 2008-10-12 23:43:21 ----A---- C:\WINDOWS\vbaddin.ini 2008-10-12 23:43:21 ----A---- C:\WINDOWS\vb.ini 2008-10-12 23:43:17 ----D---- C:\WINDOWS\Registration 2008-10-12 23:43:11 ----D---- C:\Program Files\Windows Media Player 2008-10-12 23:43:11 ----D---- C:\Program Files\Online Services 2008-10-12 23:43:05 ----D---- C:\Program Files\Messenger 2008-10-12 23:42:58 ----D---- C:\Program Files\MSN Gaming Zone 2008-10-12 23:42:58 ----A---- C:\WINDOWS\system32\write.exe 2008-10-12 23:42:44 ----A---- C:\WINDOWS\system32\sndvol32.exe 2008-10-12 23:42:44 ----A---- C:\WINDOWS\system32\hticons.dll 2008-10-12 23:42:44 ----A---- C:\WINDOWS\system32\avwav.dll 2008-10-12 23:42:43 ----A---- C:\WINDOWS\system32\avtapi.dll 2008-10-12 23:42:43 ----A---- C:\WINDOWS\system32\avmeter.dll 2008-10-12 23:42:42 ----A---- C:\WINDOWS\system32\winchat.exe 2008-10-12 23:42:31 ----A---- C:\WINDOWS\system32\getuname.dll 2008-10-12 23:42:30 ----A---- C:\WINDOWS\system32\charmap.exe 2008-10-12 23:42:30 ----A---- C:\WINDOWS\system32\calc.exe 2008-10-12 23:42:29 ----A---- C:\WINDOWS\system32\winmine.exe 2008-10-12 23:42:29 ----A---- C:\WINDOWS\system32\sol.exe 2008-10-12 23:42:28 ----A---- C:\WINDOWS\system32\reset.exe 2008-10-12 23:42:28 ----A---- C:\WINDOWS\system32\mshearts.exe 2008-10-12 23:42:28 ----A---- C:\WINDOWS\system32\freecell.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\usrlogon.cmd 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\tsshutdn.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\tslabels.ini 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\tskill.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\tsdiscon.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\tscon.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\shadow.exe 2008-10-12 23:42:27 ----A---- C:\WINDOWS\system32\rwinsta.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\regini.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\rdpcfgex.dll 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\qwinsta.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\qappsrv.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\msg.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\logoff.exe 2008-10-12 23:42:26 ----A---- C:\WINDOWS\system32\cdmodem.dll 2008-10-12 23:42:25 ----A---- C:\WINDOWS\system32\msdtcprf.ini 2008-10-12 23:42:24 ----A---- C:\WINDOWS\system32\mtxlegih.dll 2008-10-12 23:42:24 ----A---- C:\WINDOWS\system32\mtxex.dll 2008-10-12 23:42:24 ----A---- C:\WINDOWS\system32\mtxdm.dll 2008-10-12 23:42:24 ----A---- C:\WINDOWS\system32\dcomcnfg.exe 2008-10-12 23:42:23 ----A---- C:\WINDOWS\system32\stclient.dll 2008-10-12 23:42:23 ----A---- C:\WINDOWS\system32\comsnap.dll 2008-10-12 23:42:23 ----A---- C:\WINDOWS\system32\comrepl.dll 2008-10-12 23:42:23 ----A---- C:\WINDOWS\system32\comaddin.dll 2008-10-12 23:42:15 ----A---- C:\WINDOWS\system32\wmimgmt.msc 2008-10-12 23:41:50 ----D---- C:\Program Files\MSN 2008-10-12 23:41:48 ----A---- C:\WINDOWS\system32\sndrec32.exe 2008-10-12 23:41:48 ----A---- C:\WINDOWS\system32\accwiz.exe 2008-10-12 23:41:47 ----A---- C:\WINDOWS\system32\mplay32.exe 2008-10-12 23:41:47 ----A---- C:\WINDOWS\system32\hypertrm.dll 2008-10-12 23:41:46 ----D---- C:\Program Files\Windows NT 2008-10-12 23:41:46 ----A---- C:\WINDOWS\system32\mspaint.exe 2008-10-12 23:41:45 ----A---- C:\WINDOWS\system32\spider.exe 2008-10-12 23:41:45 ----A---- C:\WINDOWS\system32\clipbrd.exe 2008-10-12 23:41:44 ----A---- C:\WINDOWS\system32\tscfgwmi.dll 2008-10-12 23:41:43 ----A---- C:\WINDOWS\system32\remotepg.dll 2008-10-12 23:41:43 ----A---- C:\WINDOWS\system32\rdshost.exe 2008-10-12 23:41:43 ----A---- C:\WINDOWS\system32\rdsaddin.exe 2008-10-12 23:41:43 ----A---- C:\WINDOWS\system32\mstscax.dll 2008-10-12 23:41:43 ----A---- C:\WINDOWS\system32\mstsc.exe 2008-10-12 23:41:42 ----A---- C:\WINDOWS\system32\tscupgrd.exe 2008-10-12 23:41:42 ----A---- C:\WINDOWS\system32\termsrv.dll 2008-10-12 23:41:42 ----A---- C:\WINDOWS\system32\sessmgr.exe 2008-10-12 23:41:42 ----A---- C:\WINDOWS\system32\rdchost.dll 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\rdpwsx.dll 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\rdpsnd.dll 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\rdpclip.exe 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\qprocess.exe 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\icaapi.dll 2008-10-12 23:41:41 ----A---- C:\WINDOWS\system32\cfgbkend.dll 2008-10-12 23:41:40 ----D---- C:\WINDOWS\system32\MsDtc 2008-10-12 23:41:40 ----A---- C:\WINDOWS\system32\mtxoci.dll 2008-10-12 23:41:40 ----A---- C:\WINDOWS\system32\msdtcuiu.dll 2008-10-12 23:41:40 ----A---- C:\WINDOWS\system32\msdtcprx.dll 2008-10-12 23:41:39 ----A---- C:\WINDOWS\system32\xolehlp.dll 2008-10-12 23:41:39 ----A---- C:\WINDOWS\system32\msdtctm.dll 2008-10-12 23:41:38 ----A---- C:\WINDOWS\system32\msdtclog.dll 2008-10-12 23:41:38 ----A---- C:\WINDOWS\system32\msdtc.exe 2008-10-12 23:41:37 ----D---- C:\WINDOWS\system32\Com 2008-10-12 23:41:37 ----A---- C:\WINDOWS\system32\colbact.dll 2008-10-12 23:41:37 ----A---- C:\WINDOWS\system32\catsrvps.dll 2008-10-12 23:41:36 ----A---- C:\WINDOWS\system32\clbcatex.dll 2008-10-12 23:41:36 ----A---- C:\WINDOWS\system32\catsrvut.dll 2008-10-12 23:41:35 ----A---- C:\WINDOWS\system32\catsrv.dll 2008-10-12 23:41:34 ----A---- C:\WINDOWS\system32\comuid.dll 2008-10-12 23:41:34 ----A---- C:\WINDOWS\system32\comsvcs.dll 2008-10-12 23:41:33 ----A---- C:\WINDOWS\system32\clbcatq.dll 2008-10-12 23:41:23 ----A---- C:\WINDOWS\system32\servdeps.dll 2008-10-12 23:41:23 ----A---- C:\WINDOWS\system32\mmfutil.dll 2008-10-12 23:41:23 ----A---- C:\WINDOWS\system32\licwmi.dll 2008-10-12 23:41:23 ----A---- C:\WINDOWS\system32\cmprops.dll 2008-10-12 18:36:37 ----A---- C:\WINDOWS\system32\h323log.txt 2008-10-12 18:33:32 ----A---- C:\WINDOWS\system32\ksuser.dll 2008-10-12 18:33:29 ----A---- C:\WINDOWS\system32\nv4_disp.dll 2008-10-12 18:33:01 ----A---- C:\WINDOWS\system32\usbui.dll 2008-10-12 18:31:56 ----A---- C:\WINDOWS\imsins.BAK 2008-10-12 18:31:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2008-10-12 18:31:53 ----SHD---- C:\WINDOWS\Installer 2008-10-12 18:31:53 ----D---- C:\Program Files\Common Files\ODBC 2008-10-12 18:31:53 ----A---- C:\WINDOWS\ODBCINST.INI 2008-10-12 18:31:48 ----D---- C:\Program Files\Common Files\SpeechEngines 2008-10-12 18:31:47 ----D---- C:\Program Files\Common Files\Microsoft Shared 2008-10-12 18:31:46 ----RD---- C:\Program Files 2008-10-12 18:31:46 ----D---- C:\Program Files\Common Files 2008-10-12 18:31:42 ----RA---- C:\WINDOWS\system32\kbdtuq.dll 2008-10-12 18:31:42 ----RA---- C:\WINDOWS\system32\kbdtuf.dll 2008-10-12 18:31:42 ----RA---- C:\WINDOWS\system32\kbdazel.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbduzb.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbdtat.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbdmon.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbdkyr.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbdkaz.dll 2008-10-12 18:31:39 ----RA---- C:\WINDOWS\system32\kbdaze.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdycc.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdur.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdru1.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdru.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdbu.dll 2008-10-12 18:31:38 ----RA---- C:\WINDOWS\system32\kbdblr.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhept.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhela3.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhela2.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhe319.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhe220.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdhe.dll 2008-10-12 18:31:35 ----RA---- C:\WINDOWS\system32\kbdgkl.dll 2008-10-12 18:31:32 ----RA---- C:\WINDOWS\system32\kbdlv1.dll 2008-10-12 18:31:32 ----RA---- C:\WINDOWS\system32\kbdlv.dll 2008-10-12 18:31:32 ----RA---- C:\WINDOWS\system32\kbdlt1.dll 2008-10-12 18:31:32 ----RA---- C:\WINDOWS\system32\kbdlt.dll 2008-10-12 18:31:32 ----RA---- C:\WINDOWS\system32\kbdest.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdsl1.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdsl.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdro.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdpl1.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdpl.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdhu1.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdhu.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdcz2.dll 2008-10-12 18:31:28 ----RA---- C:\WINDOWS\system32\kbdcz1.dll 2008-10-12 18:31:27 ----RA---- C:\WINDOWS\system32\kbdycl.dll 2008-10-12 18:31:27 ----RA---- C:\WINDOWS\system32\kbdcz.dll 2008-10-12 18:31:27 ----RA---- C:\WINDOWS\system32\kbdcr.dll 2008-10-12 18:31:27 ----RA---- C:\WINDOWS\system32\KBDAL.DLL 2008-10-12 18:31:24 ----A---- C:\WINDOWS\system32\irclass.dll 2008-10-12 18:31:24 ----A---- C:\WINDOWS\system32\dgsetup.dll 2008-10-12 18:31:24 ----A---- C:\WINDOWS\system32\dgrpsetu.dll 2008-10-12 18:31:23 ----A---- C:\WINDOWS\system32\spxcoins.dll 2008-10-12 18:31:23 ----A---- C:\WINDOWS\system32\EqnClass.Dll 2008-10-12 18:31:20 ----A---- C:\WINDOWS\TASKMAN.EXE 2008-10-12 18:31:19 ----N---- C:\WINDOWS\system32\CONFIG.TMP 2008-10-12 18:31:19 ----A---- C:\WINDOWS\system32\batt.dll 2008-10-12 18:31:18 ----A---- C:\WINDOWS\notepad.exe 2008-10-12 18:31:17 ----A---- C:\WINDOWS\system32\storprop.dll 2008-10-12 18:31:10 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini 2008-10-12 18:31:07 ----RA---- C:\WINDOWS\SET29.tmp 2008-10-12 18:31:02 ----RA---- C:\WINDOWS\SET8.tmp 2008-10-12 18:31:01 ----RA---- C:\WINDOWS\SET4.tmp 2008-10-12 18:31:00 ----RA---- C:\WINDOWS\SET3.tmp 2008-10-12 18:30:53 ----D---- C:\WINDOWS\system32\CatRoot2 2008-10-12 18:30:53 ----D---- C:\WINDOWS\system32\CatRoot 2008-10-12 18:30:48 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft 2008-10-12 18:30:14 ----A---- C:\WINDOWS\setuplog.txt 2008-10-12 18:30:11 ----SHD---- C:\System Volume Information 2008-10-12 18:30:11 ----D---- C:\Documents and Settings 2008-10-12 18:28:49 ----SH---- C:\boot.ini 2008-10-12 18:22:19 ----RSHDC---- C:\WINDOWS\system32\dllcache 2008-10-12 18:22:19 ----RSD---- C:\WINDOWS\Fonts 2008-10-12 18:22:19 ----RD---- C:\WINDOWS\Web 2008-10-12 18:22:19 ----HD---- C:\WINDOWS\inf 2008-10-12 18:22:19 ----D---- C:\WINDOWS\WinSxS 2008-10-12 18:22:19 ----D---- C:\WINDOWS\twain_32 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Temp 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\wins 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\wbem 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\usmt 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\spool 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\ShellExt 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\Setup 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\ras 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\oobe 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\npp 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\mui 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\inetsrv 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\IME 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\icsxml 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\ias 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\export 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\drivers 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\dhcp 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\config 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\3com_dmi 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\3076 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\2052 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1054 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1042 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1041 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1037 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1033 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1031 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1028 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32\1025 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system32 2008-10-12 18:22:19 ----D---- C:\WINDOWS\system 2008-10-12 18:22:19 ----D---- C:\WINDOWS\security 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Resources 2008-10-12 18:22:19 ----D---- C:\WINDOWS\repair 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Provisioning 2008-10-12 18:22:19 ----D---- C:\WINDOWS\PeerNet 2008-10-12 18:22:19 ----D---- C:\WINDOWS\pchealth 2008-10-12 18:22:19 ----D---- C:\WINDOWS\mui 2008-10-12 18:22:19 ----D---- C:\WINDOWS\msapps 2008-10-12 18:22:19 ----D---- C:\WINDOWS\msagent 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Media 2008-10-12 18:22:19 ----D---- C:\WINDOWS\java 2008-10-12 18:22:19 ----D---- C:\WINDOWS\ime 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Help 2008-10-12 18:22:19 ----D---- C:\WINDOWS\ehome 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Driver Cache 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Debug 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Cursors 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Connection Wizard 2008-10-12 18:22:19 ----D---- C:\WINDOWS\Config 2008-10-12 18:22:19 ----D---- C:\WINDOWS\AppPatch 2008-10-12 18:22:19 ----D---- C:\WINDOWS\addins 2008-10-12 18:22:19 ----AD---- C:\WINDOWS ======List of files/folders modified in the last 1 months====== 2008-10-15 11:34:24 ----A---- C:\WINDOWS\system32\netapi32.dll 2008-10-12 23:47:47 ----A---- C:\WINDOWS\win.ini 2008-10-12 18:31:46 ----A---- C:\WINDOWS\system.ini 2008-10-03 12:41:15 ----A---- C:\WINDOWS\system32\ieframe.dll ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2008-07-19 26944] R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2008-07-19 78416] R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2008-07-19 42912] R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2008-07-21 24392] R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352] R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-13 14592] R2 Aspi32;Aspi32; C:\WINDOWS\System32\drivers\aspi32.sys [2007-09-17 16512] R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2008-07-19 20560] R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2008-07-19 94416] R3 AnyDVD;AnyDVD; C:\WINDOWS\System32\Drivers\AnyDVD.sys [2008-09-04 99648] R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2008-07-19 23152] R3 E100B;Intel(R) PRO Adapter Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2001-08-17 117760] R3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2001-08-17 40704] R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368] R3 MRVW245;Marvell TOPDOG 802.11n WLAN Driver for Windows XP (USB8x); C:\WINDOWS\system32\DRIVERS\MRVW245.sys [2007-11-18 461952] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2004-08-03 1897408] R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128] R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520] R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368] R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608] S4 RxFilter;RxFilter; C:\WINDOWS\system32\DRIVERS\RxFilter.sys [2008-08-11 57328] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-10-15 611664] R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-07-19 16056] R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-07-19 147640] R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864] R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912] R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-07-19 250040] R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-07-23 348344] R3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864] R3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe [2008-06-24 537896] S2 Roxio Upnp Server 11;Roxio Upnp Server 11; C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUpnpService11.exe [2008-08-14 367088] S2 RoxLiveShare11;LiveShare P2P Server 11; C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxLiveShare11.exe [2008-08-14 309744] S2 RoxWatch11;Roxio Hard Drive Watcher 11; C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxWatch11.exe [2008-08-14 170480] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-10-15 138168] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 Roxio UPnP Renderer 11;Roxio UPnP Renderer 11; C:\Program Files\Roxio Creator 2009\Digital Home 11\RoxioUPnPRenderer11.exe [2008-08-14 313840] S3 RoxMediaDB11;RoxMediaDB11; C:\Program Files\Common Files\Roxio Shared\11.0\SharedCOM\RoxMediaDB11.exe [2008-08-14 1124848] S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880] -----------------EOF----------------- info.txt logfile of random's system information tool 1.04 2008-10-25 15:11:03 ======Uninstall list====== -->C:\Program Files\Nero\Nero8\\nero\uninstall\UNNERO.exe /UNINSTALL -->C:\WINDOWS\system32\\MSIEXEC.EXE /x {7B91CBFD-0671-4819-9724-CABE3014E886} -->C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL -->C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL -->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL -->C:\WINDOWS\UNNeroVision.exe /UNINSTALL -->C:\WINDOWS\UNRecode.exe /UNINSTALL -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1 Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07} Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF} Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F} Adobe Flash Player ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001} AnyDVD-->"C:\Program Files\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Program Files\SlySoft\AnyDVD" avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe" DirectX 9 Runtime-->MsiExec.exe /I{AF9E97C1-7431-426D-A8D5-ABE40995C0B1} DVD Creator3-->C:\Program Files\Xilisoft\DVD Creator3\Uninstall.exe DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe" dvdSanta 4.50-->"C:\Program Files\dvdSanta\unins000.exe" EMC 11 Content-->MsiExec.exe /X{21ABEA96-CCAB-4C40-8699-6BDFEC5FD63C} eMule-->"C:\Program Files\eMule\Uninstall.exe" Free Download Manager 2.5-->"C:\Program Files\Free Download Manager\unins000.exe" Google Toolbar for Internet Explorer-->MsiExec.exe /I{DBEA1034-5882-4A88-8033-81C4EF0CFA29} Google Toolbar for Internet Explorer-->regsvr32 /u /s "c:\program files\google\googletoolbar1.dll" HijackThis 2.0.2-->"C:\Program Files\trend micro\HijackThis.exe" /uninstall Hotfix for Windows XP (KB952287)-->"C:\WINDOWS\$NtUninstallKB952287$\spuninst\spuninst.exe" ImgBurn-->"C:\Program Files\ImgBurn\uninstall.exe" Microsoft .NET Framework 2.0 Service Pack 1-->MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} Microsoft .NET Framework 3.0 Service Pack 1-->MsiExec.exe /I{2BA00471-0328-3743-93BD-FA813353A783} Microsoft .NET Framework 3.5-->C:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5\setup.exe Microsoft .NET Framework 3.5-->MsiExec.exe /I{2FC099BD-AC9B-33EB-809C-D332E1B27C40} Microsoft Internationalized Domain Names Mitigation APIs-->"C:\WINDOWS\$NtServicePackUninstallIDNMitigationAPIs$\spuninst\spuninst.exe" Microsoft National Language Support Downlevel APIs-->"C:\WINDOWS\$NtServicePackUninstallNLSDownlevelMapping$\spuninst\spuninst.exe" Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE} Microsoft Office Home and Student 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall HOMESTUDENTR /dll OSETUP.DLL Microsoft Office Home and Student 2007-->MsiExec.exe /X{91120000-002F-0000-0000-0000000FF1CE} Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE} Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE} Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE} Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE} Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE} Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE} Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE} Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE} Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE} MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} Nero 8-->MsiExec.exe /X{6D45EF03-E8EE-4355-81C3-F918CBCF1033} neroxml-->MsiExec.exe /I{56C049BE-79E9-4502-BEA7-9754A3E60F9B} NETGEAR WN111 wireless USB 2.0 adapter-->C:\Program Files\InstallShield Installation Information\{AFCE4D19-D385-4232-9B0E-809D85A25A10}\setup.exe -runfromtemp -l0x0409 PeerGuardian 2.0-->"C:\Program Files\PeerGuardian2\unins000.exe" Roxio Activation Module-->MsiExec.exe /I{1D53B6F9-E66E-42D8-A221-4FF8AC134FD7} Roxio BackOnTrack-->MsiExec.exe /I{5A06423A-210C-49FB-950E-CB0EB8C5CEC7} Roxio CinePlayer Decoder Pack-->MsiExec.exe /I{C0FE37FA-0886-4B66-B01B-76CF70FB77AB} Roxio CinePlayer-->MsiExec.exe /I{AA749D64-3741-4D5F-B804-B0BC05D179D1} Roxio Creator 2009-->C:\Documents and Settings\All Users\Application Data\Uninstall\{7919D8D9-69FB-4E94-B330-04C4AF251867}\setup.exe /x {7919D8D9-69FB-4E94-B330-04C4AF251867} Roxio Creator 2009-->MsiExec.exe /I{3383136B-4F86-4F05-8612-DD4BB16A1EAE} Roxio Creator 2009-->MsiExec.exe /I{7A7B3764-7F17-4AB1-A1D3-3B01F5F07445} Roxio File Backup-->MsiExec.exe /I{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB} Security Update for 2007 Microsoft Office System (KB951944)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {797AE457-BA17-4BBC-B501-25FB3A0103C7} Security Update for 2007 Microsoft Office System (KB955936)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {1D94099C-2BBA-440E-BD5E-093BBDF8F028} Security Update for Microsoft Office Excel 2007 (KB955470)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {6E8637D8-10D6-4568-AA06-E2706F31685E} Security Update for Microsoft Office OneNote 2007 (KB950130)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {F1B2401C-B610-4BF2-AA1C-52C55827A8F4} Security Update for Microsoft Office PowerPoint 2007 (KB951338)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {558B709B-821B-4FC5-90FC-9A8890641E77} Security Update for Microsoft Office system 2007 (KB951808)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {8F375E11-4FD6-4B89-9E2B-A76D48B51E00} Security Update for Microsoft Office system 2007 (KB954326)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {5F7F6FFF-395D-480E-8450-64F385D82C5F} Security Update for Microsoft Office Word 2007 (KB950113)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {AD72BABE-C733-4FCF-9674-4314466191B9} Security Update for Windows Internet Explorer 7 (KB938127)-->"C:\WINDOWS\ie7updates\KB938127-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB938127-v2)-->"C:\WINDOWS\ie7updates\KB938127-v2-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB953838)-->"C:\WINDOWS\ie7updates\KB953838-IE7\spuninst\spuninst.exe" Security Update for Windows Internet Explorer 7 (KB956390)-->"C:\WINDOWS\ie7updates\KB956390-IE7\spuninst\spuninst.exe" Security Update for Windows XP (KB923789)-->C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB923789.inf Security Update for Windows XP (KB938464)-->"C:\WINDOWS\$NtUninstallKB938464$\spuninst\spuninst.exe" Security Update for Windows XP (KB941569)-->"C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Security Update for Windows XP (KB946648)-->"C:\WINDOWS\$NtUninstallKB946648$\spuninst\spuninst.exe" Security Update for Windows XP (KB950762)-->"C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Security Update for Windows XP (KB950974)-->"C:\WINDOWS\$NtUninstallKB950974$\spuninst\spuninst.exe" Security Update for Windows XP (KB951066)-->"C:\WINDOWS\$NtUninstallKB951066$\spuninst\spuninst.exe" Security Update for Windows XP (KB951376-v2)-->"C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Security Update for Windows XP (KB951698)-->"C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Security Update for Windows XP (KB951748)-->"C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" Security Update for Windows XP (KB952954)-->"C:\WINDOWS\$NtUninstallKB952954$\spuninst\spuninst.exe" Security Update for Windows XP (KB953838)-->"C:\WINDOWS\$NtUninstallKB953838$\spuninst\spuninst.exe" Security Update for Windows XP (KB953839)-->"C:\WINDOWS\$NtUninstallKB953839$\spuninst\spuninst.exe" Security Update for Windows XP (KB954211)-->"C:\WINDOWS\$NtUninstallKB954211$\spuninst\spuninst.exe" Security Update for Windows XP (KB956391)-->"C:\WINDOWS\$NtUninstallKB956391$\spuninst\spuninst.exe" Security Update for Windows XP (KB956803)-->"C:\WINDOWS\$NtUninstallKB956803$\spuninst\spuninst.exe" Security Update for Windows XP (KB956841)-->"C:\WINDOWS\$NtUninstallKB956841$\spuninst\spuninst.exe" Security Update for Windows XP (KB957095)-->"C:\WINDOWS\$NtUninstallKB957095$\spuninst\spuninst.exe" Security Update for Windows XP (KB958644)-->"C:\WINDOWS\$NtUninstallKB958644$\spuninst\spuninst.exe" SmartSound Quicktracks Plugin-->C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E} Software Informer 1.0 BETA-->"C:\Program Files\Software Informer\unins000.exe" Update for Office 2007 (KB934391)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {B3091818-7C56-4C45-BE7D-CA23027A5EA5} Update for Office 2007 (KB946691)-->msiexec /package {91120000-002F-0000-0000-0000000FF1CE} /uninstall {A420F522-7395-4872-9882-C591B4B92278} Update for Windows XP (KB951072-v2)-->"C:\WINDOWS\$NtUninstallKB951072-v2$\spuninst\spuninst.exe" Update for Windows XP (KB951978)-->"C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe" VCRedistSetup-->MsiExec.exe /I{3921A67A-5AB1-4E48-9444-C71814CF3027} Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320} Windows Live Mail-->MsiExec.exe /I{184E7118-0295-43C4-B72C-1D54AA75AAF7} Windows Live Sign-in Assistant-->MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} Windows Media Format Runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll Windows XP Service Pack 3-->"C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe Xilisoft DVD Ripper Ultimate-->C:\Program Files\Xilisoft\DVD Ripper Ultimate 5\Uninstall.exe ======Security center information====== AV: avast! antivirus 4.8.1229 [VPS 081025-1] ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\DLLShared\;C:\Program Files\Common Files\Roxio Shared\11.0\DLLShared\ "windir"=%SystemRoot% "FP_NO_HOST_CHECK"=NO "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=15 "PROCESSOR_IDENTIFIER"=x86 Family 15 Model 2 Stepping 7, GenuineIntel "PROCESSOR_REVISION"=0207 "NUMBER_OF_PROCESSORS"=2 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "RCAUTOPLAY"=C:\Program Files\Roxio Creator 2009\Roxio Central 4\ "EMC_AUTOPLAY"=C:\Program Files\Common Files\Roxio Shared\ -----------------EOF----------------- Both files. To large so I had to split into two posts. This is also after installing SP3. Thanks in advance, MPenney |
|
#5
| |||
| |||
| Use the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator. Click on SCAN NOW Click on the Accept button and install any components it needs.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. If needed this animation will guide you through the process. |
|
#6
| |||
| |||
| It's being blocked. message about verifying the sorrce. Will not let me install the active x controler either.. Thanks in advance, MPenney |
|
#7
| |||
| |||
| its also saying i need java 1.5 or higher I googled Java and at this site, http://java.sun.com/javase/downloads/index_jdk5.jsp, I'm not sure which one I need. Many thanks |
|
#8
| |||
| |||
| |
|
#9
| |||
| |||
| The report came up completely empty |
|
#10
| |||
| |||
| I didn't see anything in the log to worry about either. Looks like you are malware free. Use the Secunia Software Inspector to check for out of date software. Out of date software has security vulnerabilities that malware can exploit.
Go to Microsoft Windows Update and get all critical updates. ---------- Check out Keeping Yourself safe On The Web for tips and free tools to keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
![]() |
|
Similar Threads | ||||
| Thread | Thread Starter | Forum | Replies | Last Post |
| Virus Log Please Help | antbann | Virus, Spyware & Security | 5 | 3rd Oct 2009 09:04 |
| Virus Question - Can anyone tell me if i may have a virus | billozz | Virus, Spyware & Security | 1 | 2nd Apr 2009 13:58 |
| My friends MAC has a virus...umm...yeah...a Virus... | cheesepuff | Virus, Spyware & Security | 3 | 29th Oct 2008 12:58 |
| Virus help | jam90 | Virus, Spyware & Security | 1 | 28th Jul 2008 07:26 |
| Virus | lolli_pop | Virus, Spyware & Security | 13 | 17th Nov 2007 09:42 |
| Thread Tools | |
| |