RSIT LOG
Logfile of random's system information tool 1.05 (written by random/random)
Run by Kester Hector at 2009-01-06 14:45:14
Microsoft Windows XP Home Edition Service Pack 1
System drive C: has 15 GB (44%) free of 35 GB
Total RAM: 1279 MB (68% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:45:29 PM, on 1/6/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\INITIO\Button Manager v1.874\inihid.exe
C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
C:\Program Files\palmOne\Hotsync.exe
C:\Program Files\RMClient\PMCTray.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Kester Hector\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Kester Hector.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKUS\S-1-5-18\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVGFRE~1\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [Symantec NetDriver Warning] C:\PROGRA~1\SYMNET~1\SNDWarn.exe (User 'Default user')
O4 - S-1-5-18 Startup: HotSync Manager.LNK = C:\Program Files\palmOne\Hotsync.exe (User 'SYSTEM')
O4 - .DEFAULT Startup: HotSync Manager.LNK = C:\Program Files\palmOne\Hotsync.exe (User 'Default user')
O4 - Startup: HotSync Manager.LNK = C:\Program Files\palmOne\Hotsync.exe
O4 - Global Startup: Button Manager v1.874.lnk = ?
O4 - Global Startup: Desktop Manager.lnk = C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
O4 - Global Startup: SmartNetMonitor for Client.lnk = C:\Program Files\RMClient\PMClient.exe
O4 - Global Startup: TotalMedia Backup Monitor.lnk = C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .tif: C:\Program Files\Internet Explorer\PLUGINS\npqtplugin7.dll
O16 - DPF: {1663ed61-23eb-11d2-b92f-008048fdd814} (MeadCo ScriptX Advanced) -
http://w3.gliconline.com/common/scripts/smsx.cabO16 - DPF: {21D817CE-B22E-11D2-B514-00C04F930B5E} (GuardianDownload.Download) -
http://w3.gliconline.com/Common/Scripts/GuardianDownload.CABO16 - DPF: {2E764AF3-8311-11D2-B4EC-00C04F930B5E} (prjDownloadHelp.ctlDownloadHelp_2) -
http://w3.gliconline.com/GuardianHelp/Scri...nloadHelp_2.CABO16 - DPF: {2F01ABF9-0799-11D2-B771-00C04F930B5E} (prjShowHelp_3.ctlShowHelp_3) -
http://w3.gliconline.com/GuardianHelp/scri...lshowHelp_3.CABO16 - DPF: {3C648A72-C49A-48EF-9F90-68EF13293F97} (Cacher Class) -
http://www.priv.njmls.xmlsweb.com/XMLSearch/XMLCache.CABO16 - DPF: {3E755E01-BB38-11D4-B44C-00105A0D610A} (VbpCommonControls.ctlCommonControls) -
http://w3.gliconline.com/Common/Cabs/ctlCommonControls.CABO16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) -
http://dl.tvunetworks.com/TVUAx.cabO16 - DPF: {8EB7A892-8135-11D1-842A-00A02495BC15} (AppLauncherCtrl2 Class) -
http://w3.gliconline.com/scripts/AppLauncher2.cabO16 - DPF: {8FEFF364-6A5F-4966-A917-A3AC28411659} (SopCore Control) -
http://download.sopcast.com/download/SOPCORE.CABO16 - DPF: {9E4A8277-58D1-11D4-8E62-00C04F6F3010} (VbRuntime.RuntimeControls) -
http://w3.gliconline.com/Common/Cabs/GDL_VbRuntime.CABO16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) -
http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cabO16 - DPF: {E7DE712F-FC5D-11D4-B58B-00C04F584B78} (Pal2AXControl.Pal2DeleteExpiredFiles) -
https://www6.glic.com/gol/palinforcedownloa...l2AXControl.CABO20 - AppInit_DLLs: c:\windows\system32\jepafuzi.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Tivoli Endpoint (lcfd) - Unknown owner - C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: TuneUp Drive Defrag Service (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe
--
End of file - 8096 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\1-Click Maintenance.job
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
C:\WINDOWS\tasks\Norton AntiVirus - Scan my computer - Kester Hector.job
C:\WINDOWS\tasks\Symantec NetDetect.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FDAD4DA1-61A2-4FD8-9C17-86F7AC245081}]
SingleInstance Class - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll [2008-07-28 160496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll [2008-07-28 882416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"QuickTime Task"=C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
"RoxWatchTray"=C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe [2007-08-16 236016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ekrn"=2
"EhttpSrv"=3
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Button Manager v1.874.lnk - C:\Program Files\INITIO\Button Manager v1.874\inihid.exe
Desktop Manager.lnk - C:\Program Files\Research In Motion\BlackBerry\DesktopMgr.exe
SmartNetMonitor for Client.lnk - C:\Program Files\RMClient\PMClient.exe
TotalMedia Backup Monitor.lnk - C:\Program Files\ArcSoft\TotalMedia Backup & Record\uBBMonitor.exe
C:\Documents and Settings\Kester Hector\Start Menu\Programs\Startup
HotSync Manager.LNK - C:\Program Files\palmOne\Hotsync.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"=" c:\windows\system32\jepafuzi.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2004-06-10 86016]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableLUA"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 3 months======
2009-01-06 14:45:14 ----D---- C:\rsit
2009-01-06 14:10:58 ----SH---- C:\WINDOWS\System32\eganayat.ini
2009-01-06 13:23:49 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Malwarebytes
2009-01-06 13:23:39 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-06 13:23:39 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-05 10:19:33 ----A---- C:\WINDOWS\IE4 Error Log.txt
2009-01-05 09:43:51 ----SH---- C:\WINDOWS\System32\ayaposus.ini
2009-01-04 00:02:36 ----SH---- C:\WINDOWS\System32\upodotit.ini
2009-01-02 14:59:54 ----SHD---- C:\RECYCLER
2009-01-02 14:37:04 ----D---- C:\WINDOWS\System32\NtmsData
2009-01-02 14:34:36 ----A---- C:\WINDOWS\MusicRip.ini
2009-01-02 14:30:29 ----D---- C:\Program Files\INITIO
2009-01-02 14:30:29 ----A---- C:\Program Files\ReadMe.txt
2009-01-02 14:28:22 ----A---- C:\WINDOWS\System32\wstdecod.dll
2009-01-02 14:28:21 ----A---- C:\WINDOWS\System32\psisdecd.dll
2009-01-02 14:28:21 ----A---- C:\WINDOWS\System32\msyuv.dll
2009-01-02 14:28:21 ----A---- C:\WINDOWS\System32\msvidctl.dll
2009-01-02 14:28:20 ----A---- C:\WINDOWS\System32\qedwipes.dll
2009-01-02 14:28:20 ----A---- C:\WINDOWS\System32\ksuser.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\quartz.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\qedit.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\qdvd.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\qdv.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\mswebdvd.dll
2009-01-02 14:28:19 ----A---- C:\WINDOWS\System32\msdmo.dll
2009-01-02 14:28:18 ----A---- C:\WINDOWS\System32\qcap.dll
2009-01-02 14:28:18 ----A---- C:\WINDOWS\System32\mciqtz32.dll
2009-01-02 14:28:18 ----A---- C:\WINDOWS\System32\encapi.dll
2009-01-02 14:28:18 ----A---- C:\WINDOWS\System32\devenum.dll
2009-01-02 14:28:18 ----A---- C:\WINDOWS\System32\amstream.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dxdiagn.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dxdiag.exe
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dswave.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmusic.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmsynth.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmstyle.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmscript.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmloader.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmime.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmcompos.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\dmband.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\d3d9.dll
2009-01-02 14:28:15 ----A---- C:\WINDOWS\System32\d3d8.dll
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dxdllreg.exe
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dsdmoprp.dll
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dsdmo.dll
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dpvvox.dll
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dpvsetup.exe
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dpvoice.dll
2009-01-02 14:28:14 ----A---- C:\WINDOWS\System32\dpvacm.dll
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnsvr.exe
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnlobby.dll
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnhupnp.dll
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnhpast.dll
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnet.dll
2009-01-02 14:28:13 ----A---- C:\WINDOWS\System32\dpnaddr.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dx8vb.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dx7vb.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dsound3d.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dsound.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dpwsockx.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dpmodemx.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dplayx.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\dplaysvr.exe
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\ddrawex.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\ddraw.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\d3dim700.dll
2009-01-02 14:28:12 ----A---- C:\WINDOWS\System32\d3d8thk.dll
2009-01-02 14:01:55 ----D---- C:\WINDOWS\temp
2009-01-02 14:01:53 ----A---- C:\ComboFix.txt
2009-01-02 13:49:19 ----A---- C:\Boot.bak
2009-01-02 13:49:06 ----RASHD---- C:\cmdcons
2009-01-02 13:41:31 ----A---- C:\WINDOWS\SWREG.exe
2009-01-02 13:41:31 ----A---- C:\WINDOWS\NIRCMD.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\zip.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\VFIND.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\SWXCACLS.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\SWSC.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\sed.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\grep.exe
2009-01-02 13:41:30 ----A---- C:\WINDOWS\fdsv.exe
2009-01-02 13:41:20 ----D---- C:\WINDOWS\ERDNT
2009-01-02 13:41:20 ----D---- C:\Qoobox
2008-11-24 12:36:23 ----D---- C:\Program Files\Common Files\ODBC
2008-11-21 16:01:21 ----D---- C:\Program Files\Trend Micro
2008-11-21 15:48:22 ----D---- C:\Program Files\Lavasoft
2008-11-21 15:48:22 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-11-21 15:05:41 ----D---- C:\Downloads
2008-11-21 14:28:26 ----A---- C:\WINDOWS\msoffice.ini
2008-10-08 08:47:11 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Roxio
2008-10-07 13:39:47 ----A---- C:\WINDOWS\System32\mdimon.dll
2008-10-07 13:37:41 ----D---- C:\Program Files\Microsoft ActiveSync
2008-10-07 13:36:47 ----D---- C:\Program Files\Common Files\DESIGNER
2008-10-07 13:35:49 ----D---- C:\Program Files\Microsoft.NET
2008-10-07 13:35:49 ----D---- C:\Program Files\Microsoft Office
2008-10-07 12:51:45 ----RHD---- C:\MSOCache
17576-30713-30709 35386:30709:16 ----ASH---- C:\WINDOWS\System32\yibabofi.dll
17576-30713-30709 35386:30709:16 ----ASH---- C:\WINDOWS\System32\nufeduta.dll.tmp
======List of files/folders modified in the last 3 months======
2009-01-06 14:44:49 ----D---- C:\WINDOWS\Prefetch
2009-01-06 14:43:27 ----A---- C:\WINDOWS\ModemLog_Standard Modem.txt
2009-01-06 14:43:22 ----A---- C:\WINDOWS\ModemLog_BCM V.92 56K Modem.txt
2009-01-06 14:43:03 ----D---- C:\WINDOWS\Debug
2009-01-06 14:42:02 ----D---- C:\WINDOWS\SYSTEM32
2009-01-06 14:41:59 ----D---- C:\WINDOWS\System32\DRIVERS
2009-01-06 14:41:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-06 13:23:39 ----AD---- C:\Program Files
2009-01-06 12:42:36 ----A---- C:\WINDOWS\hpbafd.ini
2009-01-06 11:24:18 ----SD---- C:\Documents and Settings\Kester Hector\Application Data\Microsoft
2009-01-05 10:19:33 ----D---- C:\WINDOWS
2009-01-04 00:03:33 ----D---- C:\FDPXL32
2009-01-02 14:39:22 ----D---- C:\WINDOWS\System32\CatRoot2
2009-01-02 14:37:25 ----HD---- C:\WINDOWS\INF
2009-01-02 14:37:20 ----D---- C:\WINDOWS\REPAIR
2009-01-02 14:37:02 ----D---- C:\WINDOWS\Registration
2009-01-02 14:34:12 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Arcsoft
2009-01-02 14:30:29 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-02 14:29:28 ----RSHD---- C:\WINDOWS\System32\DLLCACHE
2009-01-02 14:29:22 ----D---- C:\WINDOWS\RegisteredPackages
2009-01-02 14:29:21 ----D---- C:\WINDOWS\LastGood
2009-01-02 14:29:15 ----D---- C:\WINDOWS\Help
2009-01-02 14:28:06 ----D---- C:\WINDOWS\System32\DirectX
2009-01-02 14:27:32 ----D---- C:\Program Files\ArcSoft
2009-01-02 13:59:28 ----A---- C:\WINDOWS\system.ini
2009-01-02 13:56:38 ----D---- C:\WINDOWS\System32\CONFIG
2009-01-02 13:54:19 ----D---- C:\WINDOWS\AppPatch
2009-01-02 13:54:19 ----D---- C:\Program Files\Common Files
2009-01-02 13:52:31 ----D---- C:\temp
2009-01-02 13:52:30 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-02 13:49:19 ----RASH---- C:\BOOT.INI
2009-01-02 13:41:14 ----D---- C:\Documents and Settings\Kester Hector\Application Data\U3
2008-12-29 14:25:33 ----SHD---- C:\WINDOWS\Installer
2008-12-29 14:25:30 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-12-24 13:03:54 ----D---- C:\Documents and Settings\Kester Hector\Application Data\AVG7
2008-12-22 16:10:56 ----A---- C:\WINDOWS\FDPV.INI
2008-12-16 13:30:33 ----A---- C:\WINDOWS\WIN.INI
2008-12-15 13:27:27 ----D---- C:\Documents and Settings\Kester Hector\Application Data\AdobeUM
2008-12-02 11:31:35 ----D---- C:\WINDOWS\WinSxS
2008-12-02 11:31:34 ----RSD---- C:\WINDOWS\assembly
2008-12-01 19:45:07 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Skype
2008-11-21 15:47:37 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-21 15:43:49 ----D---- C:\DELL
2008-11-21 15:42:02 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-21 15:42:02 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Lavasoft
2008-11-21 15:13:52 ----D---- C:\Documents and Settings
2008-11-21 15:11:53 ----RSD---- C:\WINDOWS\Fonts
2008-11-21 15:11:50 ----D---- C:\WINDOWS\ShellNew
2008-11-21 14:28:52 ----D---- C:\Program Files\Common Files\aolshare
2008-11-21 14:28:45 ----D---- C:\Program Files\Common Files\AOL
2008-11-21 14:10:16 ----D---- C:\Documents and Settings\Kester Hector\Application Data\AOL
2008-11-21 14:09:47 ----D---- C:\Documents and Settings\All Users\Application Data\AOL
2008-11-21 13:57:40 ----D---- C:\Program Files\Windows Media Player
2008-11-21 13:57:35 ----D---- C:\Program Files\QuickTime
2008-11-21 13:57:35 ----D---- C:\Program Files\palmOne
2008-11-21 13:57:30 ----D---- C:\Program Files\Modem Helper
2008-11-21 13:57:17 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-11-20 23:10:16 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Avant Browser
2008-11-20 22:40:13 ----D---- C:\WINDOWS\Java
2008-11-12 13:40:09 ----D---- C:\Documents and Settings\Kester Hector\Application Data\Move Networks
2008-11-10 16:09:24 ----D---- C:\WINDOWS\NAVITEMP
2008-10-28 14:07:07 ----A---- C:\WINDOWS\brwmark.ini
2008-10-27 09:23:53 ----A---- C:\WINDOWS\System32\PerfStringBackup.INI
2008-10-16 10:17:56 ----D---- C:\WINDOWS\Minidump
2008-10-07 13:41:52 ----D---- C:\WINDOWS\System32\WBEM
2008-10-07 13:40:01 ----A---- C:\WINDOWS\ODBC.INI
2008-10-07 13:36:04 ----D---- C:\Program Files\Common Files\System
2008-10-07 13:35:35 ----D---- C:\WINDOWS\Media
2008-10-07 12:51:56 ----D---- C:\WINDOWS\SYSTEM
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Avg7Core;AVG7 Kernel; C:\WINDOWS\System32\Drivers\avg7core.sys [2007-10-25 821856]
R1 Avg7RsW;AVG7 Wrap Driver; C:\WINDOWS\System32\Drivers\avg7rsw.sys [2007-04-11 4224]
R1 Avg7RsXP;AVG7 Resident Driver XP; C:\WINDOWS\System32\Drivers\avg7rsxp.sys [2007-04-11 27776]
R1 AvgClean;AVG Clean Driver; C:\WINDOWS\system32\drivers\avgclean.sys [2007-12-20 10760]
R1 omci;OMCI WDM Device Driver; C:\WINDOWS\System32\DRIVERS\omci.sys [2004-02-13 17153]
R1 SAVRT;SAVRT; \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRT.SYS []
R1 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVRTPEL.SYS []
R1 sscdbhk5;sscdbhk5; C:\WINDOWS\system32\drivers\sscdbhk5.sys [2004-01-14 5621]
R1 ssrtln;ssrtln; C:\WINDOWS\system32\drivers\ssrtln.sys [2004-01-14 23219]
R1 SYMTDI;SYMTDI; C:\WINDOWS\System32\Drivers\SYMTDI.SYS [2004-06-29 263968]
R2 ASCTRM;ASCTRM; C:\WINDOWS\System32\drivers\ASCTRM.sys [2006-02-11 8552]
R2 AvgTdi;AVG Network Redirector; C:\WINDOWS\System32\Drivers\avgtdi.sys [2007-04-11 4960]
R2 drvnddm;drvnddm; C:\WINDOWS\system32\drivers\drvnddm.sys [2004-02-27 40480]
R2 MDC8021X;AEGIS Protocol (IEEE 802.1x) v2.3.1.7; C:\WINDOWS\System32\DRIVERS\mdc8021x.sys [2004-10-01 15781]
R2 tfsnboio;tfsnboio; C:\WINDOWS\system32\dla\tfsnboio.sys [2004-03-15 25685]
R2 tfsncofs;tfsncofs; C:\WINDOWS\system32\dla\tfsncofs.sys [2004-03-15 34837]
R2 tfsndrct;tfsndrct; C:\WINDOWS\system32\dla\tfsndrct.sys [2004-03-15 4117]
R2 tfsndres;tfsndres; C:\WINDOWS\system32\dla\tfsndres.sys [2004-03-15 2233]
R2 tfsnifs;tfsnifs; C:\WINDOWS\system32\dla\tfsnifs.sys [2004-03-15 85972]
R2 tfsnopio;tfsnopio; C:\WINDOWS\system32\dla\tfsnopio.sys [2004-03-15 14229]
R2 tfsnpool;tfsnpool; C:\WINDOWS\system32\dla\tfsnpool.sys [2004-03-15 6357]
R2 tfsnudf;tfsnudf; C:\WINDOWS\system32\dla\tfsnudf.sys [2004-03-15 98580]
R2 tfsnudfa;tfsnudfa; C:\WINDOWS\system32\dla\tfsnudfa.sys [2004-03-15 100597]
R3 Afc;PPdus ASPI Shell; C:\WINDOWS\system32\drivers\Afc.sys [2005-02-23 11776]
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINDOWS\System32\DRIVERS\Apfiltr.sys [2005-09-28 113847]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2004-06-10 746496]
R3 b57w2k;Broadcom 570x Gigabit Integrated Controller; C:\WINDOWS\System32\DRIVERS\b57xp32.sys [2003-05-21 175360]
R3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINDOWS\System32\DRIVERS\bcmwl5.sys [2004-02-20 312960]
R3 BCMModem;BCM V.92 56K Modem; C:\WINDOWS\System32\DRIVERS\BCMSM.sys [2003-08-29 1101696]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\System32\DRIVERS\CmBatt.sys [2002-08-29 13184]
R3 GEARAspiWDM;GEARAspiWDM; C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys [2006-09-19 15664]
R3 gv3;Intel GV3 Processor Driver; C:\WINDOWS\System32\DRIVERS\gv3.sys [2002-11-18 30976]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050301.008\NAVENG.Sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20050301.008\NavEx15.Sys []
R3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINDOWS\System32\DRIVERS\ozscr.sys [2003-12-11 91395]
R3 RimVSerPort;RIM Virtual Serial Port v2; C:\WINDOWS\System32\DRIVERS\RimSerial.sys [2007-01-18 26496]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINDOWS\System32\Drivers\RootMdm.sys [2002-08-29 5888]
R3 STAC97;Audio Driver (WDM) - SigmaTel CODEC; C:\WINDOWS\system32\drivers\stac97.sys [2004-05-12 258704]
R3 SYMDNS;SYMDNS; C:\WINDOWS\System32\Drivers\SYMDNS.SYS [2004-06-29 11008]
R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
R3 SYMFW;SYMFW; C:\WINDOWS\System32\Drivers\SYMFW.SYS [2004-06-29 166048]
R3 SYMIDS;SYMIDS; C:\WINDOWS\System32\Drivers\SYMIDS.SYS [2004-06-29 46528]
R3 SYMIDSCO;SYMIDSCO; C:\WINDOWS\System32\Drivers\SYMIDSCO.SYS [2004-06-29 170208]
R3 SYMNDIS;SYMNDIS; C:\WINDOWS\System32\Drivers\SYMNDIS.SYS [2004-06-29 51552]
R3 SYMREDRV;SYMREDRV; C:\WINDOWS\System32\Drivers\SYMREDRV.SYS [2004-06-29 16288]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2004-04-10 25216]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2004-04-10 53120]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2004-04-10 19328]
S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\System32\DRIVERS\kbdhid.sys [2001-08-17 13952]
S1 P3;Intel PentiumIII Processor Driver; C:\WINDOWS\System32\DRIVERS\p3.sys [2002-11-25 37632]
S3 bvrp_pci;bvrp_pci; C:\WINDOWS\System32\drivers\bvrp_pci.sys []
S3 Dot4;MS IEEE-1284.4 Driver; C:\WINDOWS\System32\DRIVERS\Dot4.sys [2001-08-17 205056]
S3 Dot4Print;Print Class Driver for IEEE-1284.4; C:\WINDOWS\System32\DRIVERS\Dot4Prt.sys [2001-08-17 12928]
S3 dot4usb;Dot4USB Filter Dot4USB Filter; C:\WINDOWS\System32\DRIVERS\dot4usb.sys [2001-08-17 23808]
S3 EL90XBC;3Com EtherLink XL 90XB/C Adapter Driver; C:\WINDOWS\System32\DRIVERS\el90xbc5.sys [2001-08-17 66591]
S3 hamachi;Hamachi Network Interface; C:\WINDOWS\System32\DRIVERS\hamachi.sys [2006-06-28 10578]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 i81x;i81x; C:\WINDOWS\System32\DRIVERS\i81xnt5.sys [2001-08-17 138240]
S3 iAimFP0;iAimFP0; C:\WINDOWS\System32\DRIVERS\wADV01nt.sys [2001-08-17 12672]
S3 iAimFP1;iAimFP1; C:\WINDOWS\System32\DRIVERS\wADV02NT.sys [2001-08-17 12288]
S3 iAimFP2;iAimFP2; C:\WINDOWS\System32\DRIVERS\wADV05NT.sys [2001-08-17 12032]
S3 iAimFP3;iAimFP3; C:\WINDOWS\System32\DRIVERS\wSiINTxx.sys [2001-08-17 12160]
S3 iAimFP4;iAimFP4; C:\WINDOWS\System32\DRIVERS\wVchNTxx.sys [2001-08-17 18688]
S3 iAimTV0;iAimTV0; C:\WINDOWS\System32\DRIVERS\wATV01nt.sys [2001-08-17 29440]
S3 iAimTV1;iAimTV1; C:\WINDOWS\System32\DRIVERS\wATV02NT.sys [2001-08-17 19456]
S3 iAimTV2;iAimTV2; C:\WINDOWS\System32\DRIVERS\wATV03nt.sys [2001-08-17 44928]
S3 iAimTV3;iAimTV3; C:\WINDOWS\System32\DRIVERS\wATV04nt.sys [2001-08-17 31104]
S3 iAimTV4;iAimTV4; C:\WINDOWS\System32\DRIVERS\wCh7xxNT.sys [2001-08-17 23680]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 MREMPR5;MREMPR5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MREMPR5.SYS []
S3 MRENDIS5;MRENDIS5 NDIS Protocol Driver; \??\C:\PROGRA~1\COMMON~1\Motive\MRENDIS5.SYS []
S3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2002-08-28 891711]
S3 PalmUSBD;PalmUSBD; C:\WINDOWS\system32\drivers\PalmUSBD.sys [2006-01-10 16694]
S3 RimUsb;BlackBerry Smartphone; C:\WINDOWS\System32\Drivers\RimUsb.sys [2007-05-31 22656]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\System32\DRIVERS\usbccgp.sys [2004-04-10 30464]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2002-08-29 24960]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\System32\DRIVERS\usbscan.sys [2002-08-29 14208]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760]
S3 wanatw;WAN Miniport (ATW); C:\WINDOWS\System32\DRIVERS\wanatw4.sys []
S4 agpCPQ;Compaq AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\agpCPQ.sys [2001-08-17 29056]
S4 alim1541;ALI AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\alim1541.sys [2001-08-17 27648]
S4 amdagp;AMD AGP Bus Filter Driver; C:\WINDOWS\System32\DRIVERS\amdagp.sys [2001-08-17 27648]
S4 cbidf;cbidf; C:\WINDOWS\System32\DRIVERS\cbidf2k.sys [2001-08-17 13952]
S4 sisagp;SIS AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\sisagp.sys [2001-08-17 26112]
S4 viaagp;VIA AGP Bus Filter; C:\WINDOWS\System32\DRIVERS\viaagp.sys [2001-08-17 27392]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\System32\Ati2evxx.exe [2004-06-10 376832]
R2 Avg7Alrt;AVG7 Alert Manager Server; C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe [2007-10-25 418816]
R2 Avg7UpdSvc;AVG7 Update Service; C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe [2007-04-11 49664]
R2 AVGEMS;AVG E-mail Scanner; C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe [2007-12-20 406528]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-09-14 255096]
R2 ccProxy;Symantec Network Proxy; C:\Program Files\Common Files\Symantec Shared\ccProxy.exe [2004-09-14 218232]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-09-14 234616]
R2 EPSON_PM_RPCV4_01;EPSON V3 Service4(01); C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXE [2007-01-11 113664]
R2 lcfd;Tivoli Endpoint; C:\Program Files\Tivoli\lcf\bin\w32-ix86\mrt\LCFD.EXE [2001-03-15 110592]
R2 navapsvc;Norton AntiVirus Auto Protect Service; C:\Program Files\Norton Internet Security\Norton AntiVirus\navapsvc.exe [2003-12-04 158664]
R2 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2004-06-29 193760]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912]
R2 UxTuneUp;TuneUp Theme Extension; C:\WINDOWS\System32\svchost.exe [2002-08-29 12800]
S2 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2002-08-29 250368]
S2 RoxLiveShare9;LiveShare P2P Server 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe [2007-08-16 309744]
S2 RoxWatch9;Roxio Hard Drive Watcher 9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe [2007-08-16 166384]
S2 SBService;ScriptBlocking Service; C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe [2003-06-24 66784]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S3 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-09-14 87160]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-01-27 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2006-10-30 492608]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
S3 RoxMediaDB9;RoxMediaDB9; C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe [2007-08-16 1092080]
S3 TuneUp.Defrag;TuneUp Drive Defrag Service; C:\WINDOWS\System32\TuneUpDefragService.exe [2008-03-14 306432]
S4 Multi-user Cleanup Service;Multi-user Cleanup Service; c:\notes\ntmulti.exe [2004-01-09 57393]
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe [2004-01-23 65536]
S4 Roxio UPnP Renderer 9;Roxio UPnP Renderer 9; C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe [2007-07-24 88560]
S4 Roxio Upnp Server 9;Roxio Upnp Server 9; C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe [2007-07-24 358896]
S4 SAVScan;SAVScan; C:\Program Files\Norton Internet Security\Norton AntiVirus\SAVScan.exe [2003-12-04 193816]
S4 WLTRYSVC;WLTRYSVC; C:\WINDOWS\System32\WLTRYSVC.EXE [2004-02-20 45056]
-----------------EOF-----------------