========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== FILES ==========
File/Folder C:\WINDOWS\system32\bozuhanu.dll not found.
File/Folder c:\windows\system32\mubayito.dll not found.
File/Folder C:\WINDOWS\system32\prnet.tmp not found.
File/Folder C:\Documents and Settings\LordSnoop\Application Data\Twain not found.
File/Folder C:\WINDOWS\system32\batuviko.dll not found.
C:\WINDOWS\system32\loader49.exe moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\29fd146a\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CPM2ace27f6\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\prnet\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Twain\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\vapumoluji\\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"avgrsstx.dll" /E : value set successfully!
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\\"Authentication Packages"|hex(7):6d,73,76,31,5f,30,00,00 /E : value set successfully!
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51EB.tmp scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51F0.tmp scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[10].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[3].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[4].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[5].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[6].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[7].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[8].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[9].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\topic114351[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\msb.dll scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\nsrbgxod.bak scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04292009_015116
Files moved on Reboot...
File C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51EB.tmp not found!
File C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\~DF51F0.tmp not found!
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[10].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[3].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[4].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[5].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[6].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[7].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[8].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\iframe[9].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\Content.IE5\F4BT67ZT\topic114351[1].htm moved successfully.
C:\Documents and Settings\LordSnoop\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
DllUnregisterServer procedure not found in C:\WINDOWS\temp\msb.dll
C:\WINDOWS\temp\msb.dll NOT unregistered.
C:\WINDOWS\temp\msb.dll moved successfully.
C:\WINDOWS\temp\nsrbgxod.bak moved successfully.
Logfile of random's system information tool 1.06 (written by random/random)
Run by LordSnoop at 2009-04-29 01:58:07
Microsoft Windows XP Professional Service Pack 3
System drive C: has 134 GB (73%) free of 182 GB
Total RAM: 958 MB (50% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:58:11 AM, on 29/04/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16827)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\Program Files\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\arservice.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LordSnoop\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\LordSnoop.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ca.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a...&pf=desktopR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://ca.yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 212.19.6.237:80
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [autochk] rundll32.exe C:\DOCUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 (User 'Default user')
O4 - S-1-5-18 Startup: ChkDisk.dll (User 'SYSTEM')
O4 - S-1-5-18 Startup: ChkDisk.lnk = ? (User 'SYSTEM')
O4 - S-1-5-18 Startup: ChkDisk.lnk.disabled (User 'SYSTEM')
O4 - .DEFAULT Startup: ChkDisk.dll (User 'Default user')
O4 - .DEFAULT Startup: ChkDisk.lnk = ? (User 'Default user')
O4 - .DEFAULT Startup: ChkDisk.lnk.disabled (User 'Default user')
O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')
O4 - Startup: ChkDisk.dll
O4 - Startup: ChkDisk.lnk = ?
O4 - Startup: ChkDisk.lnk.disabled
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O9 - Extra button: Download with YouTube Clip Extractor - {073fe43a-def1-4955-96e2-f0a401b5b111} - C:\Program Files\YouTube Clip Extractor\ClipExtractor.exe
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O15 - Trusted Zone:
http://*.trymedia.com (HKLM)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) -
http://upload.facebook.com/controls/2008.1...toUploader5.cabO16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/SCRABBLE/Images/stg_drm.ocx
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) -
http://www.nvidia.com/content/DriverDownlo.../sysreqlab3.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) -
http://gfx1.mail.live.com/mail/w1/resources/MSNPUpld.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://game08.zylom.com/activex/zylomgamesplayer.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/bingame/popcaploader_v10.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{1F0282A5-D3BD-4560-A8C8-7731EC98D8A2}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{3822AE64-4077-4FF4-A42D-4A2D58FCEE32}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{892900FC-9814-4488-99C0-81491C1EE93D}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{ACAA9C68-C07E-4B5B-816E-12B0A8E6A891}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D0FAE5AC-025C-46F2-8229-0E953B1135CE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1EB76A5-63EF-4F10-925C-D517E92E7EEE}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CCS\Services\Tcpip\..\{E70E84A3-13C3-4458-BFB6-29EC6D0B3107}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS1\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O17 - HKLM\System\CS2\Services\Tcpip\..\{031AECE2-CFA9-4C9D-8192-79C896617DF3}: NameServer = 218.93.202.110,218.93.202.111
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Filter: x-sdch - {B1759355-3EEC-4C1E-B0F1-B719FE26E377} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_A8904FB862BD9564.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
--
End of file - 9015 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
C:\WINDOWS\tasks\Google Software Updater.job
C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
C:\WINDOWS\tasks\User_Feed_Synchronization-{9F05BCD9-6060-4C10-90CE-5237A0979E0B}.job
C:\WINDOWS\tasks\{F897AA24-BDC3-11D1-B85B-00C04FB93981}_L33T_Betty Fiddler.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-02-01 1968920]
{21FA44EF-376D-4D53-9B0F-8A89D3229068} - &Windows Live Toolbar - C:\Program Files\Windows Live\Toolbar\wltcore.dll [2009-02-06 1068904]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-04-27 259696]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]
"autochk"=C:\WINDOWS\system32\autochk.dll [2009-04-29 24064]
"MSConfig"=C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe [2008-04-13 169984]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\autochk]
C:\WINDOWS\system32\autochk.dll [2009-04-29 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-02-01 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Babylon Client]
C:\Program Files\Babylon\Babylon-Pro\Babylon.exe -AutoStart []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent DNA]
C:\Program Files\DNA\btdna.exe [2009-03-31 321344]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HP Software Update]
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe [2006-02-19 49152]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ImgTask]
C:\DOCUME~1\LORDSN~1\LOCALS~1\Temp\Imgtask.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechCommunicationsManager]
C:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LogitechQuickCamRibbon]
C:\Program Files\Logitech\QuickCam\Quickcam.exe [2008-12-20 2656528]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
C:\Program Files\Messenger\msmsgs.exe [2008-04-13 1695232]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\msnmsgr]
C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-02-06 3885408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nod32kui]
C:\Program Files\Eset\nod32kui.exe /WAITSERVICE []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\WINDOWS\system32\NvCpl.dll [2009-03-27 13684736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\WINDOWS\system32\NvMcTray.dll [2009-03-27 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
nwiz.exe /install []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2006-10-25 282624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmileboxTray]
C:\Documents and Settings\Betty Fiddler\Application Data\Smilebox\SmileboxTray.exe [2009-01-29 254600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam]
c:\steam\steam.exe [2009-03-06 1410296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-08 136600]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2007-06-16 68856]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Synchronization Manager]
C:\WINDOWS\system32\mobsync.exe [2008-04-13 143360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\VeohPlugin]
C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WeatherEye]
C:\Program Files\TheWeatherNetwork\WeatherEye\WeatherEye []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent]
C:\Program Files\Winamp\winampa.exe [2009-03-09 37888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe -quiet []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
C:\PROGRA~1\HP\DIGITA~1\bin\hpqtra08.exe [2006-02-19 288472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
C:\PROGRA~1\MICROS~4\Office10\OSA.EXE [2001-02-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^QuickBooks Update Agent.lnk]
C:\PROGRA~1\COMMON~1\Intuit\QUICKB~1\QBUpdate\qbupdate.exe [2007-11-23 967960]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^WirelessLAN USB Utility.lnk]
C:\PROGRA~1\WIRELE~1.11G\Wlan.exe [2004-06-09 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.dll]
C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup\ChkDisk.dll [2009-04-28 24064]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ChkDisk.lnk]
C:\DOCUME~1\LORDSN~1\STARTM~1\Programs\Startup\ChkDisk.dll,_IWMPEvents@16 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^LordSnoop^Start Menu^Programs^Startup^ERUNT AutoBackup.lnk]
C:\PROGRA~1\ERUNT\AUTOBACK.EXE [2005-10-20 38912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"NOD32krn"=2
"iPod Service"=3
"usnjsvc"=3
"WMPNetworkSvc"=3
"SeaPort"=2
"QuickBooksDB17"=2
"QBFCService"=3
"QBCFMonitorService"=2
"npkcmsvc"=2
"MDM"=2
"LVPrcSrv"=2
"LightScribeService"=2
"JavaQuickStarterService"=2
"IDriverT"=3
"gusvc"=2
"gupdate1c95d4a8527714c"=2
"fsssvc"=3
"CCALib8"=2
"Lavasoft Ad-Aware Service"=2
"avg8wd"=2
C:\Documents and Settings\LordSnoop\Start Menu\Programs\Startup
ChkDisk.dll
ChkDisk.lnk - C:\WINDOWS\system32\rundll32.exe
ChkDisk.lnk.disabled - C:\WINDOWS\system32\rundll32.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"InstallVisualStyle"=C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"=C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoFolderOptions"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
"NoSetActiveDesktop"=
"NoActiveDesktopChanges"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe"="C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Disabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG Free\avgcc.exe"="C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Disabled:avgcc.exe"
"C:\Program Files\Grisoft\AVG Free\avginet.exe"="C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Disabled:avginet.exe"
"C:\Program Files\DISC\DISCover.exe"="C:\Program Files\DISC\DISCover.exe:*:Disabled:DISCover Drop & Play System"
"C:\Program Files\DISC\myFTP.exe"="C:\Program Files\DISC\myFTP.exe:*:Disabled:DISCover FTP"
"C:\Program Files\DISC\DiscStreamHub.exe"="C:\Program Files\DISC\DiscStreamHub.exe:*:Disabled:DISCover Stream Hub"
"C:\Program Files\EarthLink TotalAccess\TaskPanl.exe"="C:\Program Files\EarthLink TotalAccess\TaskPanl.exe:*:Disabled:Earthlink"
"C:\WINDOWS\Network Diagnostic\xpnetdiag.exe"="C:\WINDOWS\Network Diagnostic\xpnetdiag.exe:*:Disabled:@xpsp3res.dll,-20000"
"C:\WINDOWS\system32\sessmgr.exe"="C:\WINDOWS\system32\sessmgr.exe:*:Disabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Disabled:Updates from HP"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Disabled:Windows Messenger"
"C:\Program Files\Yahoo!\Messenger\YServer.exe"="C:\Program Files\Yahoo!\Messenger\YServer.exe:*:Disabled:Yahoo! FT Server"
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Disabled:Yahoo! Messenger"
"C:\Program Files\Steam\steam.exe"="C:\Program Files\Steam\steam.exe:*:Enabled:Steam"
"C:\Program Files\PPMate\ppmnet.exe"="C:\Program Files\PPMate\ppmnet.exe:*:Disabled:PPMate"
"C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe"="C:\Documents and Settings\HP_Administrator\Application Data\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\SopCast\SopCast.exe"="C:\Program Files\SopCast\SopCast.exe:*:Disabled:SopCast Main Application"
"C:\Program Files\TVUPlayer\TVUPlayer.exe"="C:\Program Files\TVUPlayer\TVUPlayer.exe:*:Disabled:TVU Player Component"
"C:\My Games\JEOPARDY!\JEOPARDY!.exe"="C:\My Games\JEOPARDY!\JEOPARDY!.exe:*:Disabled:JEOPARDY!"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Action_Quake2_Standalone~\nocheat.exe:*:Enabled:nocheat"
"C:\Quake2\aq2.exe"="C:\Quake2\aq2.exe:*:Disabled:aq2"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Disabled:avgupd.exe"
"C:\Program Files\Bos Wars\boswars.exe"="C:\Program Files\Bos Wars\boswars.exe:*:Disabled:boswars"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civclient.exe:*:Disabled:civclient"
"C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe"="C:\Documents and Settings\LordSnoop\Desktop\Freeciv-2.1.9-gtk2\civserver.exe:*:Disabled:civserver"
"C:\Program Files\DNA\btdna.exe"="C:\Program Files\DNA\btdna.exe:*:Disabled:DNA"
"C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\source sdk base\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\half-life 2 deathmatch\hl2.exe:*:Disabled:hl2"
"C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe"="C:\Program Files\Steam\steamapps\coanza@hotmail.com\counter-strike source\hl2.exe:*:Disabled:hl2"
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Disabled:hpfccopy.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Disabled:hpoews01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Disabled:hpofxm08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe"="C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Disabled:hposfx08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe"="C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Disabled:hposid01.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Disabled:hpqcopy.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Disabled:hpqdia.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqkygrp.exe:*:Disabled:hpqkygrp.exe"
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe"="C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Disabled:hpqphunl.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqscnvw.exe:*:Disabled:hpqscnvw.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqste08.exe:*:Disabled:hpqste08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe"="C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe:*:Disabled:hpqtra08.exe"
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe"="C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Disabled:hpzwiz01.exe"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Disabled:Internet Explorer"
"C:\Program Files\UrbanTerror\ioUrbanTerror.exe"="C:\Program Files\UrbanTerror\ioUrbanTerror.exe:*:Disabled:ioUrbanTerror"
"C:\Program Files\LimeWire\LimeWire.exe"="C:\Program Files\LimeWire\LimeWire.exe:*:Disabled:LimeWire"
"C:\StubInstaller.exe"="C:\StubInstaller.exe:*:Disabled:LimeWire swarmed installer"
"C:\Program Files\mIRC\mirc.exe"="C:\Program Files\mIRC\mirc.exe:*:Disabled:mIRC"
"C:\Quake2\nocheat.exe"="C:\Quake2\nocheat.exe:*:Disabled:nocheat"
"C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe"="C:\Documents and Settings\LordSnoop\Desktop\Emulator\Action_Quake2_Standalone~\nocheat.exe:*:Disabled:nocheat"
"C:\Program Files\Pando Networks\Media Booster\PMB.exe"="C:\Program Files\Pando Networks\Media Booster\PMB.exe:*:Disabled:Pando Media Booster"
"C:\Program Files\PPMate\ppmate.exe"="C:\Program Files\PPMate\ppmate.exe:*:Disabled:PPMate"
"C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe"="C:\Program Files\Intuit\QuickBooks 2008\QBDBMgrN.exe:*:Disabled:QuickBooks 2008 Data Manager"
"C:\WINDOWS\system32\services.exe"="C:\WINDOWS\system32\services.exe:*:Disabled:services"
"C:\Program Files\SopCast\adv\SopAdver.exe"="C:\Program Files\SopCast\adv\SopAdver.exe:*:Disabled:SopCast Adver"
"C:\Program Files\Battle of Survival\stratagus.exe"="C:\Program Files\Battle of Survival\stratagus.exe:*:Disabled:stratagus"
"C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe"="C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe:*:Disabled:Veoh Web Player "
"C:\Program Files\VideoLAN\VLC\vlc.exe"="C:\Program Files\VideoLAN\VLC\vlc.exe:*:Disabled:VLC media player"
"C:\Program Files\Warcraft III\Warcraft III.exe"="C:\Program Files\Warcraft III\Warcraft III.exe:*:Disabled:Warcraft III"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Disabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Disabled:Windows Live Messenger"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Disabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Disabled:Windows Live Sync"
"C:\Program Files\World of Warcraft\Launcher.exe"="C:\Program Files\World of Warcraft\Launcher.exe:*:Disabled:World of Warcraft"
"C:\Program Files\The All-Seeing Eye\eye.exe"="C:\Program Files\The All-Seeing Eye\eye.exe:*:Disabled:Yahoo! All-Seeing Eye"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Disabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe"="C:\Program Files\Updates from HP\9972322\Program\Updates from HP.exe:*:Enabled:Updates from HP"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{e68b79f6-288d-11de-9a8f-0017310e91a5}]
shell\AutoRun\command - J:\DigitalPhotoViewer.exe
======List of files/folders created in the last 3 months======
2009-04-29 01:51:16 ----D---- C:\_OTMoveIt
2009-04-28 22:42:30 ----ASH---- C:\WINDOWS\system32\autochk.dll
2009-04-28 22:42:28 ----A---- C:\WINDOWS\system32\lmppcsetup.exe
2009-04-28 18:25:36 ----D---- C:\rsit
2009-04-28 17:07:12 ----D---- C:\WINDOWS\ERDNT
2009-04-28 17:06:32 ----D---- C:\Program Files\ERUNT
2009-04-28 13:14:00 ----A---- C:\WINDOWS\ntbtlog.txt
2009-04-28 00:22:09 ----A---- C:\WINDOWS\iconeasl.ini
2009-04-28 00:22:09 ----A---- C:\WINDOWS\easyicon.ini
2009-04-28 00:22:07 ----D---- C:\Program Files\EasyApps XP
2009-04-27 00:31:36 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Malwarebytes
2009-04-27 00:31:26 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-04-27 00:31:25 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-04-26 12:00:15 ----D---- C:\Program Files\TeaTimer (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\SDHelper (Spybot - Search & Destroy)
2009-04-26 12:00:14 ----D---- C:\Program Files\Misc. Support Library (Spybot - Search & Destroy)
2009-04-26 12:00:13 ----D---- C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
2009-04-26 02:52:34 ----D---- C:\Program Files\Trend Micro
2009-04-26 00:56:26 ----D---- C:\Documents and Settings\All Users\Application Data\Azureus
2009-04-26 00:56:24 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Azureus
2009-04-26 00:46:46 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sun
2009-04-26 00:20:02 ----D---- C:\Program Files\Enterbrain
2009-04-19 20:21:01 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Sonic
2009-04-19 20:20:54 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Leadertech
2009-04-18 01:02:31 ----D---- C:\Documents and Settings\LordSnoop\Application Data\.freeciv
2009-04-16 03:11:33 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-04-16 03:11:19 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-04-16 03:04:22 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-04-16 03:03:43 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-04-16 03:03:05 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-04-16 03:02:37 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-04-15 22:37:00 ----N---- C:\WINDOWS\system32\xpsp4res.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\d3dx10_41.dll
2009-04-10 16:25:32 ----A---- C:\WINDOWS\system32\D3DCompiler_41.dll
2009-04-10 16:25:31 ----A---- C:\WINDOWS\system32\D3DX9_41.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAudio2_4.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\XAPOFX1_3.dll
2009-04-10 16:25:30 ----A---- C:\WINDOWS\system32\xactengine3_4.dll
2009-04-10 16:25:29 ----A---- C:\WINDOWS\system32\X3DAudio1_6.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\d3dx10_40.dll
2009-04-10 16:25:28 ----A---- C:\WINDOWS\system32\D3DCompiler_40.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAudio2_3.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\XAPOFX1_2.dll
2009-04-10 16:25:27 ----A---- C:\WINDOWS\system32\D3DX9_40.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\xactengine3_3.dll
2009-04-10 16:25:26 ----A---- C:\WINDOWS\system32\X3DAudio1_5.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAudio2_2.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\XAPOFX1_1.dll
2009-04-10 16:25:25 ----A---- C:\WINDOWS\system32\xactengine3_2.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\d3dx10_39.dll
2009-04-10 16:25:24 ----A---- C:\WINDOWS\system32\D3DCompiler_39.dll
2009-04-10 16:25:23 ----A---- C:\WINDOWS\system32\D3DX9_39.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAudio2_1.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\XAPOFX1_0.dll
2009-04-10 16:25:22 ----A---- C:\WINDOWS\system32\xactengine3_1.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\X3DAudio1_4.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\d3dx10_38.dll
2009-04-10 16:25:21 ----A---- C:\WINDOWS\system32\D3DCompiler_38.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\XAudio2_0.dll
2009-04-10 16:25:20 ----A---- C:\WINDOWS\system32\D3DX9_38.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\xactengine3_0.dll
2009-04-10 16:25:19 ----A---- C:\WINDOWS\system32\X3DAudio1_3.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\d3dx10_37.dll
2009-04-10 16:25:18 ----A---- C:\WINDOWS\system32\D3DCompiler_37.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\xactengine2_10.dll
2009-04-10 16:25:17 ----A---- C:\WINDOWS\system32\D3DX9_37.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\d3dx10_36.dll
2009-04-10 16:25:16 ----A---- C:\WINDOWS\system32\D3DCompiler_36.dll
2009-04-10 16:25:15 ----A---- C:\WINDOWS\system32\d3dx9_36.dll
2009-04-10 16:25:14 ----A---- C:\WINDOWS\system32\xactengine2_9.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\d3dx10_35.dll
2009-04-10 16:25:13 ----A---- C:\WINDOWS\system32\D3DCompiler_35.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\xactengine2_8.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\X3DAudio1_2.dll
2009-04-10 16:25:12 ----A---- C:\WINDOWS\system32\d3dx9_35.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx9_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\d3dx10_34.dll
2009-04-10 16:25:11 ----A---- C:\WINDOWS\system32\D3DCompiler_34.dll
2009-04-10 16:25:10 ----A---- C:\WINDOWS\system32\xinput1_3.dll
2009-04-10 16:25:08 ----A---- C:\WINDOWS\system32\xactengine2_7.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\d3dx10_33.dll
2009-04-10 16:25:06 ----A---- C:\WINDOWS\system32\D3DCompiler_33.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\xactengine2_6.dll
2009-04-10 16:25:04 ----A---- C:\WINDOWS\system32\d3dx9_33.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_5.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\xactengine2_4.dll
2009-04-10 16:25:03 ----A---- C:\WINDOWS\system32\x3daudio1_1.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xinput1_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_3.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\xactengine2_2.dll
2009-04-10 16:25:02 ----A---- C:\WINDOWS\system32\d3dx9_31.dll
2009-04-10 16:25:01 ----A---- C:\WINDOWS\system32\xinput1_1.dll
2009-04-10 16:25:00 ----A---- C:\WINDOWS\system32\xactengine2_1.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\xactengine2_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\x3daudio1_0.dll
2009-04-10 16:24:57 ----A---- C:\WINDOWS\system32\d3dx9_30.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\xinput9_1_0.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_29.dll
2009-04-10 16:24:56 ----A---- C:\WINDOWS\system32\d3dx9_28.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_27.dll
2009-04-10 16:24:55 ----A---- C:\WINDOWS\system32\d3dx9_26.dll
2009-04-10 16:24:54 ----A---- C:\WINDOWS\system32\d3dx9_25.dll
2009-04-10 16:24:52 ----A---- C:\WINDOWS\system32\d3dx9_24.dll
2009-04-10 16:19:20 ----HD---- C:\WINDOWS\msdownld.tmp
2009-04-10 16:19:13 ----D---- C:\WINDOWS\Logs
2009-04-10 03:01:14 ----D---- C:\Program Files\Microsoft CAPICOM 2.1.0.2
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\muweb.dll
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2009-04-09 20:26:31 ----A---- C:\WINDOWS\system32\mucltui.dll
2009-04-09 09:48:22 ----D---- C:\Program Files\Microsoft Sync Framework
2009-04-09 09:47:41 ----A---- C:\WINDOWS\system32\d3dx9_32.dll
2009-04-09 09:47:30 ----D---- C:\Program Files\Microsoft SQL Server Compact Edition
2009-04-09 09:47:09 ----HDC---- C:\WINDOWS\$NtUninstallKB954708$
2009-04-09 09:45:25 ----D---- C:\Program Files\Microsoft
2009-04-09 09:45:07 ----D---- C:\Program Files\Windows Live SkyDrive
2009-04-09 09:44:37 ----D---- C:\Program Files\Windows Live
2009-04-09 09:36:01 ----D---- C:\Program Files\Common Files\Windows Live
2009-04-07 03:01:46 ----D---- C:\Program Files\SystemRequirementsLab
2009-04-04 20:16:40 ----D---- C:\Program Files\UrbanTerror
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\ltclr13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lftif13n.dll
2009-04-02 10:50:53 ----A---- C:\WINDOWS\system32\lffax13n.dll
2009-03-31 04:04:08 ----D---- C:\Program Files\DNA
2009-03-31 04:04:08 ----D---- C:\Program Files\BitTorrent
2009-03-31 04:04:08 ----D---- C:\Documents and Settings\LordSnoop\Application Data\DNA
2009-03-27 19:08:49 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HP
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcuda.dll
2009-03-25 12:01:26 ----D---- C:\tmp
2009-03-23 19:56:07 ----D---- C:\Program Files\Python26
2009-03-23 12:18:53 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Yahoo!
2009-03-22 20:14:56 ----D---- C:\Program Files\Veoh Networks
2009-03-22 12:09:59 ----D---- C:\Documents and Settings\LordSnoop\Application Data\HPQ
2009-03-21 16:25:45 ----D---- C:\Documents and Settings\LordSnoop\Application Data\ZoomBrowser EX
2009-03-21 16:25:20 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CameraWindowDC
2009-03-21 16:25:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\CANON INC
2009-03-20 03:03:33 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2009-03-20 03:03:06 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2009-03-20 03:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB959772_WM11$
2009-03-20 03:02:19 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2009-03-20 03:01:57 ----HDC---- C:\WINDOWS\$NtUninstallKB936782_WMP11$
2009-03-19 20:33:39 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-03-19 20:33:38 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-03-19 20:32:59 ----D---- C:\Program Files\Windows Media Connect 2
2009-03-19 20:32:46 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-03-19 20:31:14 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-03-19 20:30:07 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-03-19 20:28:52 ----HDC---- C:\WINDOWS\$NtUninstallKB925766$
2009-03-18 19:59:38 ----D---- C:\Program Files\Microsoft Silverlight
2009-03-18 17:30:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AdobeUM
2009-03-18 13:10:37 ----D---- C:\Documents and Settings\LordSnoop\Application Data\vlc
2009-03-18 13:08:29 ----D---- C:\Program Files\VideoLAN
2009-03-16 14:16:42 ----D---- C:\Documents and Settings\LordSnoop\Application Data\LimeWire
2009-03-16 13:52:27 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Media Player Classic
2009-03-16 13:51:56 ----A---- C:\WINDOWS\system32\unrar.dll
2009-03-16 12:55:30 ----A---- C:\Documents and Settings\LordSnoop\Application Data\ClipExtractor-UpdatePerformed.txt
2009-03-16 12:55:22 ----D---- C:\Program Files\YouTube Clip Extractor
2009-03-15 16:23:14 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Mozilla
2009-03-15 16:22:13 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Macromedia
2009-03-15 16:22:02 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Adobe
2009-03-15 16:21:32 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Google
2009-03-15 16:19:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\AVGTOOLBAR
2009-03-15 16:19:19 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Subversion
2009-03-15 16:18:32 ----ASH---- C:\Documents and Settings\LordSnoop\Application Data\desktop.ini
2009-03-15 16:18:29 ----SD---- C:\Documents and Settings\LordSnoop\Application Data\Microsoft
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Real
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Intuit
2009-03-15 16:18:29 ----D---- C:\Documents and Settings\LordSnoop\Application Data\Identities
2009-03-14 20:15:27 ----A---- C:\WINDOWS\system32\lvci11901262.dll
2009-03-14 20:12:48 ----D---- C:\Program Files\Logitech
2009-03-11 00:51:52 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-03-11 00:51:47 ----HDC---- C:\WINDOWS\$NtUninstallKB938464-v2$
2009-03-11 00:51:34 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaws.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\javaw.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\java.exe
2009-03-08 20:42:23 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-03-08 03:50:31 ----D---- C:\zv
2009-03-06 21:25:42 ----D---- C:\Steam
2009-02-25 22:49:04 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2009-02-11 01:16:44 ----HDC---- C:\WINDOWS\$NtUninstallKB960715$
2009-02-06 18:52:40 ----A---- C:\WINDOWS\system32\sirenacm.dll
======List of files/folders modified in the last 3 months======
2009-04-29 01:55:40 ----RASH---- C:\boot.ini
2009-04-29 01:55:40 ----A---- C:\WINDOWS\win.ini
2009-04-29 01:55:40 ----A---- C:\WINDOWS\system.ini
2009-04-29 01:54:54 ----D---- C:\WINDOWS\Temp
2009-04-29 01:54:54 ----D---- C:\WINDOWS\system32
2009-04-29 01:54:11 ----D---- C:\WINDOWS\Registration
2009-04-29 01:54:04 ----AD---- C:\WINDOWS
2009-04-29 01:52:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-28 23:52:33 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-28 22:28:20 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2009-04-28 22:27:24 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-04-28 22:27:02 ----D---- C:\WINDOWS\system32\drivers
2009-04-28 22:27:02 ----D---- C:\Program Files
2009-04-28 22:12:00 ----D---- C:\WINDOWS\Prefetch
2009-04-28 22:01:24 ----D---- C:\WINDOWS\pss
2009-04-28 21:36:46 ----D---- C:\WINDOWS\system32\Lang
2009-04-28 19:43:23 ----HD---- C:\WINDOWS\inf
2009-04-28 19:42:18 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-28 18:21:49 ----RSHD---- C:\WINDOWS\system32\dllcache
2009-04-28 18:18:51 ----D---- C:\Program Files\Mozilla Firefox
2009-04-28 16:53:55 ----SD---- C:\WINDOWS\Tasks
2009-04-28 02:05:42 ----HD---- C:\$AVG8.VAULT$
2009-04-27 23:59:39 ----D---- C:\Program Files\mIRC
2009-04-27 21:13:19 ----SHD---- C:\WINDOWS\Installer
2009-04-27 19:35:17 ----SHD---- C:\WINDOWS\CSC
2009-04-27 19:35:14 ----D---- C:\WINDOWS\Minidump
2009-04-27 19:06:02 ----D---- C:\WINDOWS\system32\FxsTmp
2009-04-27 18:02:28 ----A---- C:\WINDOWS\ModemLog_Agere Systems PCI-SV92PP Soft Modem.txt
2009-04-27 07:57:02 ----A---- C:\WINDOWS\system32\userinit.exe
2009-04-27 07:42:12 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-04-26 21:06:45 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-26 15:23:59 ----D---- C:\Program Files\Common Files
2009-04-26 13:46:28 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2009-04-26 03:34:21 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-26 02:01:05 ----HD---- C:\Config.Msi
2009-04-26 01:54:57 ----D---- C:\Program Files\Yahoo!
2009-04-26 01:07:57 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-04-25 13:39:32 ----D---- C:\Program Files\PokerStars
2009-04-24 18:49:29 ----A---- C:\WINDOWS\system32\lsdelete.exe
2009-04-21 07:30:54 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-04-16 03:47:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-16 03:39:39 ----D---- C:\Program Files\Internet Explorer
2009-04-16 03:39:38 ----D---- C:\WINDOWS\system32\wbem
2009-04-16 03:39:38 ----D---- C:\WINDOWS\AppPatch
2009-04-16 03:11:24 ----A---- C:\WINDOWS\imsins.BAK
2009-04-16 03:10:44 ----D---- C:\WINDOWS\system32\en-US
2009-04-16 03:10:15 ----D---- C:\WINDOWS\ie7updates
2009-04-13 03:35:06 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-04-10 16:25:34 ----D---- C:\WINDOWS\system32\DirectX
2009-04-10 16:25:00 ----RSD---- C:\WINDOWS\assembly
2009-04-10 16:24:49 ----D---- C:\WINDOWS\Microsoft.NET
2009-04-09 23:46:53 ----D---- C:\Program Files\Common Files\InstallShield
2009-04-09 09:48:23 ----D---- C:\WINDOWS\WinSxS
2009-04-09 09:45:50 ----D---- C:\Program Files\MSN Messenger
2009-04-09 09:44:47 ----SD---- C:\WINDOWS\Fonts
2009-04-07 03:21:15 ----D---- C:\WINDOWS\nview
2009-04-07 03:13:41 ----D---- C:\WINDOWS\Help
2009-04-07 03:11:56 ----D---- C:\NVIDIA
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nwiz.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwimg.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvwddi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvvitvs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvudisp.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvshell.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmobls.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmctray.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccss.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvmccs.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nview.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvgames.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvdisps.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcplui.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcpl.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcolor.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcodins.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvcod.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvappbar.exe
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nvapi.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2009-03-27 10:03:00 ----A---- C:\WINDOWS\system32\keystone.exe
2009-03-27 08:14:42 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2009-03-23 12:42:25 ----D---- C:\Quake2
2009-03-21 15:35:33 ----D---- C:\Program Files\Winamp
2009-03-21 08:06:58 ----N---- C:\WINDOWS\system32\kernel32.dll
2009-03-20 03:04:28 ----D---- C:\WINDOWS\system32\CatRoot
2009-03-19 21:10:36 ----D---- C:\Program Files\Windows Media Player
2009-03-19 20:30:13 ----D---- C:\WINDOWS\system32\LogFiles
2009-03-19 20:28:59 ----AD---- C:\WINDOWS\ehome
2009-03-16 13:52:08 ----D---- C:\Program Files\K-Lite Codec Pack
2009-03-15 22:02:02 ----A---- C:\WINDOWS\ODBC.INI
2009-03-15 16:22:14 ----D---- C:\Program Files\Google
2009-03-15 16:21:40 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2009-03-15 16:19:21 ----SHD---- C:\RECYCLER
2009-03-15 16:18:45 ----A---- C:\WINDOWS\OEWABLog.txt
2009-03-15 16:18:28 ----D---- C:\Documents and Settings
2009-03-14 20:16:21 ----D---- C:\Program Files\Common Files\logishrd
2009-03-14 20:12:53 ----D---- C:\Documents and Settings\All Users\Application Data\Logishrd
2009-03-10 12:13:36 ----D---- C:\Program Files\MSN
2009-03-08 20:42:48 ----D---- C:\Program Files\LimeWire
2009-03-08 20:41:59 ----D---- C:\Program Files\Java
2009-03-08 14:46:13 ----D---- C:\Program Files\SopCast
2009-03-06 08:22:18 ----N---- C:\WINDOWS\system32\pdh.dll
2009-03-02 18:18:25 ----A---- C:\WINDOWS\system32\wininet.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\webcheck.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\urlmon.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\url.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\pngfilt.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\occache.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mstime.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\msrating.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\mshtmled.dll
2009-02-20 12:09:38 ----A---- C:\WINDOWS\system32\ieencode.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\msfeeds.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\jsproxy.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iertutil.dll
2009-02-20 12:09:37 ----A---- C:\WINDOWS\system32\iernonce.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieframe.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\iedkcs32.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieaksie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\ieakeng.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\icardie.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\extmgr.dll
2009-02-20 12:09:36 ----A---- C:\WINDOWS\system32\dxtrans.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2009-02-20 12:09:35 ----A---- C:\WINDOWS\system32\advpack.dll
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ieudinit.exe
2009-02-20 04:20:49 ----A---- C:\WINDOWS\system32\ie4uinit.exe
2009-02-19 23:14:12 ----A---- C:\WINDOWS\system32\ieakui.dll
2009-02-09 06:10:49 ----N---- C:\WINDOWS\system32\lsasrv.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\ntdll.dll
2009-02-09 06:10:48 ----N---- C:\WINDOWS\system32\advapi32.dll
2009-02-09 06:10:48 ----A---- C:\WINDOWS\system32\rpcss.dll
2009-02-07 19:02:58 ----A---- C:\WINDOWS\system32\ntkrnlpa.exe
2009-02-06 12:35:56 ----A---- C:\WINDOWS\system32\LegitCheckControl.DLL
2009-02-06 05:11:05 ----N---- C:\WINDOWS\system32\services.exe
2009-02-06 05:08:19 ----A---- C:\WINDOWS\system32\ntoskrnl.exe
2009-02-06 04:39:08 ----N---- C:\WINDOWS\system32\sc.exe
2009-02-03 13:59:07 ----A---- C:\WINDOWS\system32\secur32.dll
2009-02-01 09:31:14 ----A---- C:\WINDOWS\system32\avgrsstx.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-02-01 325128]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-02-01 27656]
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2004-08-09 12032]
R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-02-06 55152]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-13 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2004-08-09 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2004-08-09 55936]
R3 AgereSoftModem;Agere Systems Soft Modem; C:\WINDOWS\system32\DRIVERS\AGRSM.sys [2005-10-20 1095009]
R3 aracpi;aracpi; C:\WINDOWS\system32\DRIVERS\aracpi.sys [2005-08-02 22784]
R3 arhidfltr;MS Ar HID Filter Driver; C:\WINDOWS\system32\DRIVERS\arhidfltr.sys [2005-08-02 19200]
R3 arkbcfltr;Microsoft PS2 Keyboard Filter; C:\WINDOWS\system32\DRIVERS\arkbcfltr.sys [2005-08-02 5376]
R3 armoucfltr;Microsoft PS2 Mouse Filter; C:\WINDOWS\system32\DRIVERS\armoucfltr.sys [2005-08-02 4992]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-13 60800]
R3 ARPolicy;ARPolicy; C:\WINDOWS\system32\DRIVERS\arpolicy.sys [2005-08-02 10112]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-13 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2006-01-23 4145152]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-13 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-03-27 6280416]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-07-29 34048]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-07-29 12928]
R3 Ps2;PS2; C:\WINDOWS\system32\DRIVERS\PS2.sys [2005-12-12 19072]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-13 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-13 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S2 npkcrypt;npkcrypt; \??\C:\Nexon\Mabinogi\npkcrypt.sys []
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-13 17024]
S3 HPZid412;IEEE-1284.4 Driver HPZid412; C:\WINDOWS\system32\DRIVERS\HPZid412.sys [2005-03-08 51120]
S3 HPZipr12;Print Class Driver for IEEE-1284.4 HPZipr12; C:\WINDOWS\system32\DRIVERS\HPZipr12.sys [2005-03-08 16496]
S3 HPZius12;USB to IEEE-1284.4 Translation Driver HPZius12; C:\WINDOWS\system32\DRIVERS\HPZius12.sys [2005-03-08 21744]
S3 LVPr2Mon;LVPr2Mon Driver; C:\WINDOWS\system32\Drivers\LVPr2Mon.sys [2008-12-16 25624]
S3 LVRS;Logitech RightSound Filter Driver; C:\WINDOWS\system32\DRIVERS\lvrs.sys [2008-12-17 768024]
S3 LVUSBSta;Logitech USB Monitor Filter; C:\WINDOWS\system32\drivers\LVUSBSta.sys [2008-12-17 41752]
S3 MHNDRV;MHN driver; C:\WINDOWS\system32\DRIVERS\mhndrv.sys [2004-08-09 11008]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-13 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-13 85248]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-13 10880]
S3 pepifilter;Volume Adapter; C:\WINDOWS\system32\DRIVERS\lv302af.sys [2008-12-16 13848]
S3 PID_PEPI;Logitech QuickCam IM(PID_PEPI); C:\WINDOWS\system32\DRIVERS\LV302V32.SYS [2008-12-16 2686104]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\system32\DRIVERS\RTL8139.SYS [2004-08-03 20992]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-13 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-13 15232]
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-13 60032]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-13 32128]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-13 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-13 15104]
S3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S3 WpdUsb;WpdUsb; C:\WINDOWS\system32\DRIVERS\wpdusb.sys [2006-10-18 38528]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-13 19200]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S3 ZD1211U(WirelessLAN);Wireless IEEE 802.11g Wireless LAN Driver (USB)(WirelessLAN); C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-04-24 210944]
S3 ZDPNDIS5;ZDPNDIS5 NDIS Protocol Driver; \??\C:\WINDOWS\system32\ZDPNDIS5.SYS []
S4 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-13 36352]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 ARSVC;ARSVC; C:\WINDOWS\arservice.exe [2005-08-02 58880]
R2 ehRecvr;Media Center Receiver Service; C:\WINDOWS\eHome\ehRecvr.exe [2005-10-11 237568]
R2 ehSched;Media Center Scheduler Service; C:\WINDOWS\eHome\ehSched.exe [2005-08-05 102912]
R2 McrdSvc;Media Center Extender Service; C:\WINDOWS\ehome\mcrdsvc.exe [2005-08-05 99328]
R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-03-27 163908]
R2 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-13 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-04-13 33632]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-04-13 68952]
S3 Fax;Fax; C:\WINDOWS\system32\fxssvc.exe [2008-04-13 267776]
S3 MHN;MHN; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S3 usprserv;User Privilege Service; C:\WINDOWS\System32\svchost.exe [2008-04-13 14336]
S4 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-02-01 298264]
S4 CCALib8;Canon Camera Access Library 8; C:\Program Files\Canon\CAL\CALMAIN.exe [2007-01-31 96370]
S4 fsssvc;Windows Live Family Safety; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-02-06 533360]
S4 gupdate1c95d4a8527714c;Google Update Service (gupdate1c95d4a8527714c); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-02-15 133104]
S4 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-03-28 183280]
S4 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-08 152984]
S4 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-04-24 953168]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2005-12-18 73728]
S4 LVPrcSrv;Process Monitor; C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe [2008-12-16 150040]
S4 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE [2003-06-20 322120]
S4 npkcmsvc;npkcmsvc; C:\Nexon\Mabinogi\npkcmsvc.exe [2007-08-02 80528]
S4 Pml Driver HPZ12;Pml Driver HPZ12; C:\WINDOWS\C:\WINDOWS\system32\HPZipm12.exe []
S4 QBCFMonitorService;QuickBooks Database Manager Service; C:\Program Files\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe [2007-11-23 20480]
S4 QBFCService;Intuit QuickBooks FCS; C:\Program Files\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe [2006-10-09 71184]
S4 QuickBooksDB17;QuickBooksDB17; C:\PROGRA~1\Intuit\QUICKB~1\QBDBMgrN.exe [2007-11-23 128280]
S4 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2009-01-14 226656]
S4 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
-----------------EOF-----------------