Here is the text from the maximized log:
Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2008-12-20 09:34:17
Microsoft Windows XP Professional Service Pack 2
System drive C: has 22 GB (57%) free of 38 GB
Total RAM: 247 MB (19% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:34:53 AM, on 12/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\Windows\System32\smss.exe
C:\Windows\system32\winlogon.exe
C:\Windows\system32\services.exe
C:\Windows\system32\lsass.exe
C:\Windows\system32\svchost.exe
C:\Windows\System32\svchost.exe
C:\Windows\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Windows\system32\spoolsv.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\COMPAQ\ACLIENT\ACLIENT.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
C:\Windows\Cpqdiag\Cpqdfwag.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
C:\Windows\system32\UAService7.exe
C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
C:\Compaq\EAKDRV\EAUSBKBD.EXE
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
C:\Windows\system32\ltmsg.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Windows\System32\spool\drivers\w32x86\3\hpztsb05.exe
C:\Windows\System32\hphmon04.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Program Files\Java\j2re1.4.2_05\bin\jucheck.exe
C:\Program Files\TomTom HOME 2\HOMERunner.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Location Finder\LocationFinder.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\Palm\HOTSYNC.EXE
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Compaq\Easy Access Button Support\CPQEAKSYSTEMTRAY.EXE
C:\Program Files\Compaq\Easy Access Button Support\CPQEADM.EXE
C:\PROGRA~1\Compaq\EASYAC~1\BttnServ.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Administrator.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,Search = About:Blank
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = About:Blank
R1 - HKLM\Software\Microsoft\Internet Explorer,Search =
http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = About:Blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = About:Blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = About:Blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.ndnation.com/index.phpR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://red.clientapps.yahoo.com/customi ... earch.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = About:Blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = About:Blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://red.clientapps.yahoo.com/customi ... .yahoo.comR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sas.r21.mchsi.com:8000
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.r21.mchsi.com
F1 - win.ini: run=fntldr.exe C:\Windows\..\PROGRA~1\COMMON~1\MICROS~1\MSInfo\msinfo.exe
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: XNetIEObj Class - {1808648B-3102-4293-8AD3-06AF71D3321B} - C:\Program Files\Endeavors\AppExpress\bho_2_5_5_17070\bho.dll (file missing)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [CPQEASYACC] C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ChkAdmin] C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE
O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\Windows\System32\spool\drivers\w32x86\3\hpztsb05.exe
O4 - HKLM\..\Run: [HPHmon04] C:\Windows\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe" -s
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunServices: [CPQDFWAG] C:\Windows\Cpqdiag\CpqDfwAg.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Microsoft Location Finder] "C:\Program Files\Microsoft Location Finder\LocationFinder.exe"
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKUS\S-1-5-18\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ALUAlert] C:\Program Files\Symantec\LiveUpdate\ALUNotify.exe (User 'Default user')
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O4 - Startup: HotSync Manager.lnk = C:\Program Files\Palm\HOTSYNC.EXE
O4 - Startup: PowerReg Scheduler.exe
O4 - Global Startup: DataViz Messenger.lnk = C:\WINDOWS\DvzCommon\DvzMsgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Windows\System32\msjava.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: *.coolwwwsearch.com
O15 - Trusted Zone:
http://*.mcafee.comO15 - Trusted Zone: *.msn.com
O16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) -
http://download.mcafee.com/molbin/iss-l ... cfscan.cabO16 - DPF: {EF99BD32-C1FB-11D2-892F-0090271D4F88} -
http://us.dl1.yimg.com/download.compani ... _1_6_0.cabO18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O19 - User stylesheet: C:\Windows\Web\tips.ini (file missing)
O19 - User stylesheet: C:\Windows\hh.htt (file missing) (HKLM)
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - C:\COMPAQ\ACLIENT\ACLIENT.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Compaq Local Alerter (CPQALERT) - Compaq Computer Corporation - C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe
O23 - Service: Compaq Remote Diagnostics Enabling Agent (CpqDfwWebAgent) - Compaq Computer Corporation - C:\Windows\Cpqdiag\Cpqdfwag.exe
O23 - Service: cpqdmi - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe
O23 - Service: Compaq DMI Web Agent (cpqWebDmi) - Compaq Computer Corporation - C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Intel(R) NMS (NMSSvc) - Intel Corporation - C:\Windows\System32\NMSSvc.exe
O23 - Service: Pml Driver HPH11 - HP - C:\Windows\System32\HPHipm11.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\Windows\system32\UAService7.exe
O23 - Service: Win32Sl (WIN32SL) - Intel - C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe
--
End of file - 10190 bytes
======Scheduled tasks folder======
C:\Windows\tasks\AppleSoftwareUpdate.job
C:\Windows\tasks\WebReg 20030718060826.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1808648B-3102-4293-8AD3-06AF71D3321B}]
XNetIEObj Class - C:\Program Files\Endeavors\AppExpress\bho_2_5_5_17070\bho.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-12-12 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-12-12 2055960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2007-10-03 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2007-10-03 2403392]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-12-12 2055960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Smapp"=C:\Program Files\Analog Devices\SoundMAX\Smtray.exe [2002-01-31 81920]
"CPQEASYACC"=C:\Program Files\COMPAQ\Easy Access Button Support\StartEAK.exe [2001-12-14 32768]
"AdaptecDirectCD"=C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe [2002-08-01 684032]
"ChkAdmin"=C:\PROGRA~1\Compaq\COMPAQ~1\CHKADMIN.EXE [2002-01-25 81920]
"LTWinModem1"=ltmsg.exe 9 []
"LtMoh"=C:\Program Files\ltmoh\Ltmoh.exe [2002-04-02 155648]
"HPDJ Taskbar Utility"=C:\Windows\System32\spool\drivers\w32x86\3\hpztsb05.exe [2002-05-24 188416]
"HPHmon04"=C:\Windows\System32\hphmon04.exe [2002-06-20 339968]
"HPHUPD04"=C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe []
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-04-17 196608]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-04-13 69632]
"SunJavaUpdateSched"=C:\Program Files\Java\j2re1.4.2_05\bin\jusched.exe [2004-06-03 32881]
"HP Software Update"=C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd2.exe [2004-09-13 49152]
"TomTomHOME.exe"=C:\Program Files\TomTom HOME 2\HOMERunner.exe [2007-10-31 378784]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-12-12 1261336]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=C:\Program Files\Messenger\msmsgs.exe [2004-10-13 1694208]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet []
"Microsoft Location Finder"=C:\Program Files\Microsoft Location Finder\LocationFinder.exe [2005-08-24 101080]
"AdobeUpdater"=C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe [2007-03-01 2321600]
"eFax 4.4"=C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe [2008-10-07 95744]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
DataViz Messenger.lnk - C:\WINDOWS\DvzCommon\DvzMsgr.exe
C:\Documents and Settings\Administrator\Start Menu\Programs\Startup
eFax 4.4.lnk - C:\Program Files\eFax Messenger 4.4\J2GTray.exe
HotSync Manager.lnk - C:\Program Files\Palm\HOTSYNC.EXE
PowerReg Scheduler.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WRNotifier]
WRLogonNTF.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\Windows\system32\upnpui.dll [2004-08-04 239616]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE"="C:\Program Files\Microsoft ActiveSync\WCESCOMM.EXE:*:Enabled:Connection Manager"
"C:\Program Files\ACT\ACT for Win 7\Act7.exe"="C:\Program Files\ACT\ACT for Win 7\Act7.exe:*:Enabled:ACT! 7.x/2005"
"C:\Program Files\Microsoft ActiveSync\WCESMGR.EXE"="C:\Program Files\Microsoft ActiveSync\WCESMGR.EXE:*:Enabled:ActiveSync Application"
"C:\Program Files\Nevo\NevoMedia Player\NevoMediaPlayer.exe"="C:\Program Files\Nevo\NevoMedia Player\NevoMediaPlayer.exe:*:Enabled:NevoMedia Player 2.0"
"C:\Program Files\Nevo\NevoMedia Server\NevoMediaServer.exe"="C:\Program Files\Nevo\NevoMedia Server\NevoMediaServer.exe:*:Enabled:NevoMedia Server 2.0"
"C:\Program Files\LapLink Gold\laplink.exe"="C:\Program Files\LapLink Gold\laplink.exe:*:Enabled:LAPLINK Core Component"
"C:\WINDOWS\system32\mshta.exe"="C:\WINDOWS\system32\mshta.exe:*:Enabled:Microsoft (R) HTML Application host"
"C:\Program Files\Palm\HOTSYNC.EXE"="C:\Program Files\Palm\HOTSYNC.EXE:*:Enabled:HotSync® Manager Application"
"C:\Program Files\EA GAMES\MOHAA\MOHAA.exe"="C:\Program Files\EA GAMES\MOHAA\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault"
"C:\Program Files\Internet Explorer\iexplore.exe"="C:\Program Files\Internet Explorer\iexplore.exe:*:Enabled:Internet Explorer"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Windows Explorer"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{86117936-a7b0-11d7-abda-000bcd65c1fc}]
shell\AutoRun\command - E:\setupSNK.exe
======List of files/folders created in the last 1 months======
2008-12-20 09:34:17 ----D---- C:\rsit
2008-12-19 03:55:14 ----HDC---- C:\Windows\$NtUninstallKB960714$
2008-12-13 12:54:05 ----D---- C:\Program Files\Trend Micro
2008-12-13 09:49:02 ----D---- C:\Program Files\Lavasoft
2008-12-13 09:49:01 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-12-13 09:47:41 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-12 15:50:34 ----HD---- C:\$AVG8.VAULT$
2008-12-12 11:47:40 ----A---- C:\Windows\system32\avgrsstx.dll
2008-12-12 11:47:20 ----D---- C:\Documents and Settings\Administrator\Application Data\AVGTOOLBAR
2008-12-12 11:47:02 ----D---- C:\Program Files\AVG
2008-12-12 11:47:01 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2008-12-12 11:10:47 ----RA---- C:\Windows\system32\kbdarmw.dll
2008-12-12 11:10:47 ----RA---- C:\Windows\system32\kbdarme.dll
2008-12-12 11:10:47 ----A---- C:\Windows\system32\Thawbrkr.dll
2008-12-12 11:10:46 ----RA---- C:\Windows\system32\kbdgeo.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdintel.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdintam.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdinpun.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdinmar.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdinkan.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdinhin.dll
2008-12-12 11:10:45 ----RA---- C:\Windows\system32\kbdinguj.dll
2008-12-12 11:10:44 ----RA---- C:\Windows\system32\kbdindev.dll
2008-12-12 11:10:44 ----A---- C:\Windows\system32\c_iscii.dll
2008-12-12 11:10:43 ----RA---- C:\Windows\system32\kbdvntc.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbdurdu.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbdsyr2.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbdsyr1.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbdfa.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbddiv2.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbddiv1.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbda3.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbda2.dll
2008-12-12 11:10:41 ----RA---- C:\Windows\system32\kbda1.dll
2008-12-12 11:10:41 ----A---- C:\Windows\system32\kbdusa.dll
2008-12-12 11:10:39 ----RA---- C:\Windows\system32\kbdheb.dll
2008-12-12 11:10:33 ----RA---- C:\Windows\system32\kbdth3.dll
2008-12-12 11:10:33 ----RA---- C:\Windows\system32\kbdth2.dll
2008-12-12 11:10:33 ----RA---- C:\Windows\system32\kbdth1.dll
2008-12-12 11:10:33 ----RA---- C:\Windows\system32\kbdth0.dll
2008-12-12 11:10:32 ----A---- C:\Windows\system32\ftlx041e.dll
2008-12-10 03:02:41 ----HDC---- C:\Windows\$NtUninstallKB952069_WM9$
2008-12-10 03:02:34 ----HDC---- C:\Windows\$NtUninstallKB955839$
2008-12-10 03:01:39 ----HDC---- C:\Windows\$NtUninstallKB958215$
2008-12-10 03:01:18 ----HDC---- C:\Windows\$NtUninstallKB954600$
2008-12-10 03:00:53 ----HDC---- C:\Windows\$NtUninstallKB956802$
2008-12-04 09:39:40 ----D---- C:\Documents and Settings\Administrator\Application Data\McAfee
2008-12-03 20:05:41 ----D---- C:\Documents and Settings\All Users\Application Data\McAfee
2008-12-03 16:56:50 ----D---- C:\Windows\McAfee.com
======List of files/folders modified in the last 1 months======
2008-12-20 09:34:53 ----D---- C:\Windows\Temp
2008-12-20 09:34:22 ----D---- C:\Windows\Prefetch
2008-12-19 06:58:53 ----D---- C:\WINDOWS
2008-12-19 06:56:57 ----D---- C:\Windows\system32
2008-12-19 03:55:19 ----RSHD---- C:\Windows\system32\dllcache
2008-12-19 03:54:37 ----HD---- C:\Windows\inf
2008-12-19 03:54:27 ----HD---- C:\Windows\$hf_mig$
2008-12-19 03:54:23 ----D---- C:\Windows\system32\CatRoot2
2008-12-13 12:54:05 ----RD---- C:\Program Files
2008-12-13 09:50:31 ----SHD---- C:\Windows\Installer
2008-12-13 09:49:02 ----D---- C:\Windows\system32\drivers
2008-12-13 09:47:41 ----D---- C:\Program Files\Common Files
2008-12-12 11:50:21 ----A---- C:\Windows\SchedLgU.Txt
2008-12-12 11:46:47 ----D---- C:\Windows\WinSxS
2008-12-12 11:46:47 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-12-12 11:33:23 ----A---- C:\Windows\system32\mshtml.dll
2008-12-12 11:10:47 ----RSD---- C:\Windows\Fonts
2008-12-12 11:10:42 ----D---- C:\Windows\Help
2008-12-12 11:05:22 ----HD---- C:\Program Files\InstallShield Installation Information
2008-12-12 11:01:30 ----SD---- C:\Windows\Tasks
2008-12-12 10:58:53 ----D---- C:\Documents and Settings
2008-12-12 10:15:30 ----D---- C:\Windows\system32\Restore
2008-12-12 10:15:29 ----SHD---- C:\System Volume Information
2008-12-10 03:02:47 ----A---- C:\Windows\imsins.BAK
2008-12-10 03:01:55 ----D---- C:\Program Files\Internet Explorer
2008-12-05 03:02:41 ----D---- C:\Windows\system32\CatRoot
2008-12-04 09:46:31 ----RAH---- C:\Windows\system32\cdplayer.exe.manifest
2008-12-04 09:40:11 ----SD---- C:\Windows\Downloaded Program Files
2008-12-03 20:35:13 ----RD---- C:\Windows\Web
2008-12-01 09:16:34 ----D---- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
2008-11-23 18:39:21 ----D---- C:\Program Files\Common Files\System
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\Windows\System32\Drivers\avgldx86.sys [2008-12-12 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\Windows\System32\Drivers\avgmfx86.sys [2008-12-12 26824]
R1 Cdr4_xp;Cdr4_xp; C:\Windows\system32\drivers\Cdr4_xp.sys [2004-04-02 43392]
R1 Cdralw2k;Cdralw2k; C:\Windows\system32\drivers\Cdralw2k.sys [2004-04-02 24576]
R1 cdudf_xp;cdudf_xp; C:\Windows\system32\drivers\cdudf_xp.sys [2002-08-14 240128]
R1 ClntMgmt;Compaq Client Management Driver; C:\Windows\System32\Drivers\ClntMgmt.sys [2002-01-16 54222]
R1 EAWDMFD;EAWDMFD; C:\Windows\System32\DRIVERS\eawdmfd.sys [1999-10-29 24348]
R1 intelppm;Intel Processor Driver; C:\Windows\System32\DRIVERS\intelppm.sys [2004-08-03 36096]
R1 n_bg;n_bg; \??\C:\Program Files\Common Files\System\n_bg32.dll []
R1 pwd_2k;pwd_2k; C:\Windows\system32\drivers\pwd_2k.sys [2002-08-01 132058]
R1 UdfReadr_xp;UdfReadr_xp; C:\Windows\system32\drivers\UdfReadr_xp.sys [2002-08-01 206464]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\Windows\System32\Drivers\avgtdix.sys [2008-12-12 76040]
R2 cpqdfw;Compaq Diagnostics Driver; \??\C:\Windows\System32\drivers\cpqdfw.sys []
R2 cq_mem;Compaq Diagnostics Memory Driver; \??\C:\Windows\System32\drivers\cq_mem.sys []
R2 cqcpu;Compaq Diagnostics CPU Driver; \??\C:\Windows\System32\drivers\cqcpu.sys []
R3 {6080A529-897E-4629-A488-ABA0C29B635E};Intel(R) Graphics Platform (SoftBIOS) Driver; C:\Windows\system32\drivers\ialmsbw.sys [2002-03-27 87648]
R3 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91};Intel(R) Graphics Chipset (KCH) Driver; C:\Windows\system32\drivers\ialmkchw.sys [2002-03-27 69472]
R3 E100B;Intel(R) PRO Adapter Driver; C:\Windows\System32\DRIVERS\e100b325.sys [2002-02-25 139776]
R3 eaps2kbd;Compaq Easy Access PS2 Internet Keyboard (Win2K); C:\Windows\System32\DRIVERS\eaps2kbd.sys [2001-12-28 24035]
R3 ialm;ialm; C:\Windows\System32\DRIVERS\ialmnt5.sys [2002-03-27 77181]
R3 ltmodem5;Lucent Modem Driver; C:\Windows\System32\DRIVERS\ltmdmxp.sys [2002-04-10 625105]
R3 mmc_2K;mmc_2K; C:\Windows\system32\drivers\mmc_2K.sys [2002-08-01 30246]
R3 smwdm;smwdm; C:\Windows\system32\drivers\smwdm.sys [2002-04-03 459944]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\Windows\System32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\Windows\System32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbprint;Microsoft USB PRINTER Class; C:\Windows\System32\DRIVERS\usbprint.sys [2004-08-04 25856]
R3 USBSTOR;USB Mass Storage Driver; C:\Windows\System32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\Windows\System32\DRIVERS\usbuhci.sys [2004-08-04 20480]
S1 kbdhid;Keyboard HID Driver; C:\Windows\System32\DRIVERS\kbdhid.sys [2004-08-03 14848]
S1 P3;Intel PentiumIII Processor Driver; C:\Windows\System32\DRIVERS\p3.sys [2004-08-03 42496]
S3 ac97intc;Intel(r) 82801 Audio Driver Install Service (WDM); C:\Windows\system32\drivers\ac97intc.sys [2001-08-17 96256]
S3 CpqDtct;CpqDtct; \??\C:\Windows\System32\Drivers\Cpqdtct.sys []
S3 Dot4 HPH11;Dot4 HPH11; C:\Windows\System32\DRIVERS\hphid411.sys [2002-05-24 50896]
S3 Dot4Print HPH11;Print Class Driver for IEEE-1284.4 HPH11; C:\Windows\System32\DRIVERS\hphipr11.sys [2002-05-24 16112]
S3 Dot4Usb HPH11;Dot4Usb HPH11; C:\Windows\System32\drivers\hphius11.sys [2002-05-24 18928]
S3 dvd_2K;dvd_2K; C:\Windows\system32\drivers\dvd_2K.sys [2002-08-01 25578]
S3 HidUsb;Microsoft HID Class Driver; C:\Windows\System32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 i81x;i81x; C:\Windows\System32\DRIVERS\i81xnt5.sys [2004-08-03 161020]
S3 iAimFP0;iAimFP0; C:\Windows\System32\DRIVERS\wADV01nt.sys [2004-08-03 12415]
S3 iAimFP1;iAimFP1; C:\Windows\System32\DRIVERS\wADV02NT.sys [2004-08-03 12127]
S3 iAimFP2;iAimFP2; C:\Windows\System32\DRIVERS\wADV05NT.sys [2004-08-03 11775]
S3 iAimFP3;iAimFP3; C:\Windows\System32\DRIVERS\wSiINTxx.sys [2004-08-03 12063]
S3 iAimFP4;iAimFP4; C:\Windows\System32\DRIVERS\wVchNTxx.sys [2004-08-03 19455]
S3 iAimTV0;iAimTV0; C:\Windows\System32\DRIVERS\wATV01nt.sys [2004-08-03 29311]
S3 iAimTV1;iAimTV1; C:\Windows\System32\DRIVERS\wATV02NT.sys [2004-08-03 19551]
S3 iAimTV2;iAimTV2; C:\Windows\System32\DRIVERS\wATV03nt.sys []
S3 iAimTV3;iAimTV3; C:\Windows\System32\DRIVERS\wATV04nt.sys [2004-08-03 33599]
S3 iAimTV4;iAimTV4; C:\Windows\System32\DRIVERS\wCh7xxNT.sys [2004-08-03 23615]
S3 mouhid;Mouse HID Driver; C:\Windows\System32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 NPF;Netgroup Packet Filter; \??\C:\Windows\system32\drivers\packet.sys []
S3 PalmUSBD;PalmUSBD; C:\Windows\system32\drivers\PalmUSBD.sys [2003-09-25 16509]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\Windows\System32\DRIVERS\usbccgp.sys [2004-08-04 31616]
S3 wceusbsh;Windows CE USB Serial Host Driver; C:\Windows\System32\DRIVERS\wceusbsh.sys [2003-12-22 104064]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-09-10 611664]
R2 AClient;Altiris Client Service; C:\COMPAQ\ACLIENT\ACLIENT.exe [2001-12-18 1953868]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-12-12 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-12-12 231704]
R2 CPQALERT;Compaq Local Alerter; C:\Program Files\Compaq\Compaq Management Agents\cpqalert.exe [2002-01-24 512000]
R2 CpqDfwWebAgent;Compaq Remote Diagnostics Enabling Agent; C:\Windows\Cpqdiag\Cpqdfwag.exe [2001-10-25 212992]
R2 cpqdmi;cpqdmi; C:\PROGRA~1\Compaq\COMPAQ~1\cpqdmi.exe [2002-01-25 20480]
R2 cpqWebDmi;Compaq DMI Web Agent; C:\PROGRA~1\Compaq\COMPAQ~1\CPQWEB~1\WebDmi.exe [2002-01-25 24576]
R2 UMWdf;Windows User Mode Driver Framework; C:\Windows\system32\wdfmgr.exe [2004-08-11 38912]
R2 UserAccess7;SecuROM User Access Service (V7); C:\Windows\system32\UAService7.exe [2006-12-31 126976]
R2 WIN32SL;Win32Sl; C:\Program Files\Compaq\Compaq Management Agents\Dmi\Win32\bin\Win32sl.exe [2001-04-11 215552]
S2 NMSSvc;Intel(R) NMS; C:\Windows\System32\NMSSvc.exe [2002-03-04 1118208]
S3 aspnet_state;ASP.NET State Service; C:\Windows\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe [2004-07-15 32768]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2007-10-03 138168]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 Pml Driver HPH11;Pml Driver HPH11; C:\Windows\System32\HPHipm11.exe [2002-05-24 77824]
-----------------EOF-----------------