I posted earlier but it was eaten.
Stuff has been uninstalled. Windowblinds had to be reinstalled and uninstalled due to uninstaller not working.
AVG and Windows Live Onecare are currently disabled (the latter hasn't been used in months, the former I opted to disable because of the memory issue).
C:\WINDOWS\cfplogvw.INI was clean - it was shown to be a simple initialisation file. Presumably it's used by Comodo to remember the dimensions of the log viewer window.
File cfplogvw.INI received on 2009.08.19 22:20:10 (UTC)
Current status: finished
Result: 0/41 (0.00%)
Antivirus Version Last Update Result
a-squared 4.5.0.24 2009.08.19 -
AhnLab-V3 5.0.0.2 2009.08.19 -
AntiVir 7.9.1.3 2009.08.19 -
Antiy-AVL 2.0.3.7 2009.08.18 -
Authentium 5.1.2.4 2009.08.19 -
Avast 4.8.1335.0 2009.08.19 -
AVG 8.5.0.406 2009.08.19 -
BitDefender 7.2 2009.08.19 -
CAT-QuickHeal 10.00 2009.08.19 -
ClamAV 0.94.1 2009.08.19 -
Comodo 2027 2009.08.20 -
DrWeb 5.0.0.12182 2009.08.19 -
eSafe 7.0.17.0 2009.08.19 -
eTrust-Vet 31.6.6688 2009.08.19 -
F-Prot 4.4.4.56 2009.08.19 -
F-Secure 8.0.14470.0 2009.08.19 -
Fortinet 3.120.0.0 2009.08.19 -
GData 19 2009.08.19 -
Ikarus T3.1.1.68.0 2009.08.19 -
Jiangmin 11.0.800 2009.08.19 -
K7AntiVirus 7.10.822 2009.08.19 -
Kaspersky 7.0.0.125 2009.08.19 -
McAfee 5714 2009.08.19 -
McAfee+Artemis 5714 2009.08.19 -
McAfee-GW-Edition 6.8.5 2009.08.19 -
Microsoft 1.4903 2009.08.19 -
NOD32 4349 2009.08.19 -
Norman 6.01.09 2009.08.19 -
nProtect 2009.1.8.0 2009.08.19 -
Panda 10.0.0.14 2009.08.19 -
PCTools 4.4.2.0 2009.08.19 -
Prevx 3.0 2009.08.20 -
Rising 21.43.24.00 2009.08.19 -
Sophos 4.44.0 2009.08.19 -
Sunbelt 3.2.1858.2 2009.08.19 -
Symantec 1.4.4.12 2009.08.19 -
TheHacker 6.3.4.3.383 2009.08.13 -
TrendMicro 8.950.0.1094 2009.08.19 -
VBA32 3.12.10.9 2009.08.19 -
ViRobot 2009.8.19.1891 2009.08.19 -
VirusBuster 4.6.5.0 2009.08.19 -
Additional information
File size: 130 bytes
MD5 : 86e73d9f4c4e2d9b4bd7eb2505a24a8a
SHA1 : 352659834f038fbe30b0314aefeea2edf8646364
SHA256: 95bee9fb817e74adc936c8d8b8b0cea6d3402e57b1421529de8d0a8af7bad2a7
TrID : File type identification
Generic INI configuration (100.0%)
ssdeep: 3:sFzJKjXcykUQo5jkkkkkkkntWt111111FkkhiingWk4Vn:sFMjIUQoOYH91hHgjcn
PEiD : -
RDS : NSRL Reference Data Set
-
The GMER rootkit scan is too long to post as a reply (932KB) so I have submitted it as a ZIP'd attachment. I hope that's okay. There was a warning about a rootkit after the scan, and an entry for Explorer.EXE was highlighted in red if that helps.
The GMER autostart scan is as follows:
GMER 1.0.15.15077 -
http://www.gmer.net
Autostart scan 2009-08-20 00:51:11
Windows 5.1.2600 Service Pack 2
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon >>>
@UserinitC:\WINDOWS\system32\userinit.exe, = C:\WINDOWS\system32\userinit.exe,
@UIHostC:\WINDOWS\system32\logonuiX.exe = C:\WINDOWS\system32\logonuiX.exe
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
WBSrv@DLLName = C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Windows@AppInit_DLLs = wbsys.dll ,C:\DOCUME~1\MARVIN~1.OMN\LOCALS~1\Temp\35138mja.dll C:\WINDOWS\system32\guard32.dll
HKLM\SYSTEM\CurrentControlSet\Services\ >>>
aswUpdSv@ = "C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe"
ATI Smart@ = C:\WINDOWS\system32\ati2sgag.exe
avast! Antivirus@ = "C:\Program Files\Alwil Software\Avast4\ashServ.exe"
cmdAgent@ = "C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe"
Lavasoft Ad-Aware Service@ = "C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe"
ThreatFire@ = C:\Program Files\ThreatFire\TFService.exe service /*file not found*/
UMWdf@ = C:\WINDOWS\system32\wdfmgr.exe
WinTabService@ = "%SystemRoot%\System32\Drivers\WTSRV.EXE"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@ScanSoft OmniPage SE 4.0-reminder"C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini" /*file not found*/ = "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini" /*file not found*/
@COMODO Internet Security"C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h = "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
@avast!C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe = C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
@WTClientWTClient.exe = WTClient.exe
@WinampAgent"C:\Program Files\Winamp\winampa.exe" = "C:\Program Files\Winamp\winampa.exe"
@ThreatFireC:\Program Files\ThreatFire\TFTray.exe = C:\Program Files\ThreatFire\TFTray.exe
@CTxfiHlpCTXFIHLP.EXE = CTXFIHLP.EXE
@Arucerrundll32 C:\WINDOWS\system32\Arucer.dll,Arucer = rundll32 C:\WINDOWS\system32\Arucer.dll,Arucer
@Adobe Reader Speed Launcher"C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" = "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
@Ad-WatchC:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe = C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run >>>
@AtiTrayTools"C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe" = "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
@WindowBlindsC:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WBInstall32.exe /*file not found*/ = C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WBInstall32.exe /*file not found*/
@DAEMON Tools Lite"C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun = "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
@Boinc"C:\Program Files\BOINC\boincmgr.exe" /s = "C:\Program Files\BOINC\boincmgr.exe" /s
@AlcoholAutomount"C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount = "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Display Panning CPL Extension*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Previous Versions Property Page*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Previous Versions*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG8 Shell Extension*/C:\Program Files\AVG\AVG8\avgse.dll = C:\Program Files\AVG\AVG8\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG8 Find Extension*/(null) =
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/C:\WINDOWS\system32\dfshim.dll = C:\WINDOWS\system32\dfshim.dll
@{AECB9170-4C86-11D2-972E-00A024A82FF3} /*Turnpike*/D:\Turnpike\TURNPIKE.DLL = D:\Turnpike\TURNPIKE.DLL
@{B8323370-FF27-11D2-97B6-204C4F4F5020} /*SmartFTP Shell Extension DLL*/C:\Program Files\SmartFTP Client 2.0\smarthook.dll = C:\Program Files\SmartFTP Client 2.0\smarthook.dll
@{EA5A76F7-8138-4B53-B0F5-ADCC730CAFBD} /*SmartFTP Drop ShellIconOverlayHandler*/C:\Program Files\SmartFTP Client\sfShellTools.dll = C:\Program Files\SmartFTP Client\sfShellTools.dll
@{40FDFA48-5F4E-4627-A78E-6A49A3D4492F} /*SmartFTP ShellDropHandler*/C:\Program Files\SmartFTP Client\sfShellTools.dll = C:\Program Files\SmartFTP Client\sfShellTools.dll
@{F87DED31-303F-4ED1-9BCE-D360FBC74E0A} /*SmartFTP ContextMenu*/C:\Program Files\SmartFTP Client\sfShellTools.dll = C:\Program Files\SmartFTP Client\sfShellTools.dll
@{39DD67E0-73B6-4a11-AF55-49E1EBBF72BE} /*SmartFTP Favorites Namespace*/C:\Program Files\SmartFTP Client\sfFavoritesShellExtension.dll = C:\Program Files\SmartFTP Client\sfFavoritesShellExtension.dll
@{82AA9188-44E0-40B9-B956-43A10C315B4F} /*SmartFTP Shell Namespace Extension*/C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll = C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll
@{2ED7FD81-CBA6-45E5-A49A-5E84889A94E2} /*SmartFTP Drop Handler*/C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll = C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll
@{EB5EE1F3-041A-4c03-9D51-2BEC6715FB00} /*SmartFTP Search Shell Namespace Extension*/C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll = C:\Program Files\SmartFTP Client\sfFTPShellExtension.dll
@{2F5AC606-70CF-461C-BFE1-734234536262} /*WindowBlinds CPL Extension*/C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbui.dll /*file not found*/ = C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbui.dll /*file not found*/
@{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396} /*OpenOffice.org Column Handler*/(null) =
@{087B3AE3-E237-4467-B8DB-5A38AB959AC9} /*OpenOffice.org Infotip Handler*/(null) =
@{63542C48-9552-494A-84F7-73AA6A7C99C1} /*OpenOffice.org Property Sheet Handler*/(null) =
@{3B092F0C-7696-40E3-A80F-68D74DA84210} /*OpenOffice.org Thumbnail Viewer*/(null) =
@{472083B0-C522-11CF-8763-00608CC02F24} /*avast*/C:\Program Files\Alwil Software\Avast4\ashShell.dll = C:\Program Files\Alwil Software\Avast4\ashShell.dll
HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Program Files\Alwil Software\Avast4\ashShell.dll
AVG8 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\AVG\AVG8\avgse.dll
FencesShellExt@{1984DD45-52CF-49cd-AB77-18F378FEA264} =
LavasoftShellExt@{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F} = C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll
SmartFTP@{F87DED31-303F-4ED1-9BCE-D360FBC74E0A} = C:\Program Files\SmartFTP Client\sfShellTools.dll
HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
FencesShellExt@{1984DD45-52CF-49cd-AB77-18F378FEA264} =
SmartFTP@{F87DED31-303F-4ED1-9BCE-D360FBC74E0A} = C:\Program Files\SmartFTP Client\sfShellTools.dll
HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
avast@{472083B0-C522-11CF-8763-00608CC02F24} = C:\Program Files\Alwil Software\Avast4\ashShell.dll
AVG8 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = C:\Program Files\AVG\AVG8\avgse.dll
FencesShellExt@{1984DD45-52CF-49cd-AB77-18F378FEA264} =
LavasoftShellExt@{DCE027F7-16A4-4BEE-9BE7-74F80EE3738F} = C:\Program Files\Lavasoft\Ad-Aware\ShellExt.dll
MBAMShlExt@{57CE581A-0CB6-4266-9CA0-19364C90A0B3} = C:\Program Files\Malwarebytes' Anti-Malware\mbamext.dll
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{18DF081C-E8AD-4283-A596-FA578C2EBDC3}C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll = C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
@{53707962-6F74-2D53-2644-206D7942484F}C:\PROGRA~1\SPYBOT~1\SDHelper.dll = C:\PROGRA~1\SPYBOT~1\SDHelper.dll
@{C333CF63-767F-4831-94AC-E683D962C63C}C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll = C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
@{DBC80044-A445-435b-BC74-9C25C1C588A9}C:\Program Files\Java\jre6\bin\jp2ssv.dll = C:\Program Files\Java\jre6\bin\jp2ssv.dll
@{E7E6F031-17CE-4C07-BC86-EABFE594F69C}C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll = C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome =
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start
Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home =
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pageabout:blank = about:blank
@Local PageC:\WINDOWS\system32\blank.htm = C:\WINDOWS\system32\blank.htm
HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = C:\WINDOWS\system32\msvidctl.dll
its@CLSID = C:\WINDOWS\system32\itss.dll
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-help@CLSID = C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
ms-its@CLSID = C:\WINDOWS\system32\itss.dll
tv@CLSID = C:\WINDOWS\system32\msvidctl.dll
HKLM\Software\Classes\PROTOCOLS\Handler\wia@CLSID = C:\WINDOWS\system32\wiascr.dll
---- EOF - GMER 1.0.15 ----
Finally a fresh RSIT scan.
Logfile of random's system information tool 1.06 (written by random/random)
Run by [removed] at 2009-08-20 01:24:42
Microsoft Windows XP Professional Service Pack 2
System drive C: has 8 GB (28%) free of 30 GB
Total RAM: 1023 MB (41% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:25:01, on 20/08/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ThreatFire\TFService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\System32\Drivers\WTSRV.EXE
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\WTClient.exe
C:\Program Files\Winamp\winampa.exe
C:\Program Files\ThreatFire\TFTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe
C:\Program Files\DAEMON Tools Lite\daemon.exe
D:\Applications\Mozilla Firefox\firefox.exe
J:\My Downloads\RSIT.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Program Files\Trend Micro\HijackThis\Marvin Kosh.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [ScanSoft OmniPage SE 4.0-reminder] "C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini"
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WTClient] WTClient.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Arucer] rundll32 C:\WINDOWS\system32\Arucer.dll,Arucer
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
O4 - HKCU\..\Run: [AtiTrayTools] "C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe"
O4 - HKCU\..\Run: [WindowBlinds] C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WBInstall32.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [Boinc] "C:\Program Files\BOINC\boincmgr.exe" /s
O4 - HKCU\..\Run: [AlcoholAutomount] "C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe" /automount
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://a248.e.akamai.net
O15 - Trusted Zone: http://*.bitedefender.co.uk
O15 - Trusted Zone: http://ssl-hints.netflame.cc
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resources/scanner/sources/en/scan8/oscan8.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase5483.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1250555413093
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1250555332988
O20 - AppInit_DLLs: wbsys.dll ,C:\DOCUME~1\MARVIN~1.OMN\LOCALS~1\Temp\35138mja.dll C:\WINDOWS\system32\guard32.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe
O23 - Service: WinTab Service (WinTabService) - Tablet Driver - C:\WINDOWS\System32\Drivers\WTSRV.EXE
--
End of file - 6944 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Ad-Aware Update (Daily).job
C:\WINDOWS\tasks\Check e-mail.job
C:\WINDOWS\tasks\DefragC.job
C:\WINDOWS\tasks\DefragD.job
C:\WINDOWS\tasks\DefragE.job
C:\WINDOWS\tasks\DefragH.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C333CF63-767F-4831-94AC-E683D962C63C}]
CoTGT_BHO Class - C:\Program Files\TGTSoft\StyleXP\TGT_BHO.dll [2006-05-10 65536]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-18 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-18 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ScanSoft OmniPage SE 4.0-reminder"=C:\Program Files\ScanSoft\OmniPageSE4.0\Ereg\Ereg.exe -r C:\Documents and Settings\All Users.WINDOWS\Application Data\ScanSoft\OmniPageSE4.0\Ereg\ereg.ini []
"COMODO Internet Security"=C:\Program Files\COMODO\COMODO Internet Security\cfp.exe [2009-08-13 1793808]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-02-05 81000]
"WTClient"=C:\WINDOWS\system32\WTClient.exe [2007-04-11 40960]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe [2009-07-01 37888]
"ThreatFire"=C:\Program Files\ThreatFire\TFTray.exe [2009-06-19 259344]
"CTxfiHlp"=C:\WINDOWS\system32\CTXFIHLP.EXE [2006-08-11 18944]
"Arucer"=rundll32 C:\WINDOWS\system32\Arucer.dll,Arucer []
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696]
"Ad-Watch"=C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe [2009-08-16 520024]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"AtiTrayTools"=C:\Program Files\Ray Adams\ATI Tray Tools\atitray.exe [2007-05-22 521128]
"WindowBlinds"=C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WBInstall32.exe []
"DAEMON Tools Lite"=C:\Program Files\DAEMON Tools Lite\daemon.exe [2009-04-23 691656]
"Boinc"=C:\Program Files\BOINC\boincmgr.exe [2007-07-04 3846912]
"AlcoholAutomount"=C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe [2009-04-02 203416]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-06-23 1948440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTHelper]
C:\WINDOWS\system32\CTHELPER.EXE [2008-06-27 19456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CtxfiReg]
CTXFIREG.exe /FAIL1 []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Email Notifier]
D:\Applications\NT Email Notifier\NTEmailNotifier.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\OpwareSE4]
C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\qttask.exe [2008-09-06 413696]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartException]
C:\Program Files\Stardock\SmartException\SmartEx.exe [2006-11-14 87728]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SSBkgdUpdate]
C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe [2006-09-28 185896]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\STYLEXP]
C:\Program Files\TGTSoft\StyleXP\StyleXP.exe [2006-05-24 1372160]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-18 148888]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Marvin Kosh.OMNILOTH^Start Menu^Programs^Startup^BOINC Manager.lnk]
C:\PROGRA~1\BOINC\boincmgr.exe [2007-07-04 3846912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Marvin Kosh.OMNILOTH^Start Menu^Programs^Startup^ImpulseNow.lnk]
C:\PROGRA~1\Stardock\Impulse\Now\IMPULS~1.EXE [2009-08-19 464176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^Marvin Kosh.OMNILOTH^Start Menu^Programs^Startup^UltraMon.lnk]
C:\Documents and Settings\Marvin Kosh.OMNILOTH\Application Data\Microsoft\Installer\{1C94C999-15D2-4C75-9A73-BCC8A677D42E}\IcoUltraMon.ico /auto []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"CiSvc"=3
"JavaQuickStarterService"=2
"Ati HotKey Poller"=2
"SQLWriter"=3
"MSSQL$SQLEXPRESS"=3
"avg8wd"=2
"avg8emc"=2
"wuauserv"=2
"WebClient"=2
"VSS"=3
"UPS"=3
"TrkWks"=2
"TermService"=3
"StyleXPService"=3
"SharedAccess"=2
"SCardSvr"=3
"RDSessMgr"=3
"RasMan"=3
"RasAuto"=3
"mnmsrvc"=3
"LmHosts"=2
"lanmanserver"=2
"FastUserSwitchingCompatibility"=3
"Browser"=3
"BITS"=2
"aspnet_state"=3
"Alerter"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="wbsys.dll ,C:\DOCUME~1\MARVIN~1.OMN\LOCALS~1\Temp\35138mja.dll C:\WINDOWS\system32\guard32.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-09-24 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WBSrv]
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\wbsrv.dll []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Lavasoft Ad-Aware Service]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"ForceStartMenuLogOff"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Grisoft\AVG Free\avginet.exe"="C:\Program Files\Grisoft\AVG Free\avginet.exe:*:Enabled:avginet.exe"
"C:\Program Files\Grisoft\AVG Free\avgamsvr.exe"="C:\Program Files\Grisoft\AVG Free\avgamsvr.exe:*:Enabled:avgamsvr.exe"
"C:\Program Files\Grisoft\AVG Free\avgcc.exe"="C:\Program Files\Grisoft\AVG Free\avgcc.exe:*:Enabled:avgcc.exe"
"H:\Games\Neverwinter Nights 2\nwn2main.exe"="H:\Games\Neverwinter Nights 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"H:\Games\Neverwinter Nights 2\nwn2main_amdxp.exe"="H:\Games\Neverwinter Nights 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"H:\Games\Neverwinter Nights 2\nwupdate.exe"="H:\Games\Neverwinter Nights 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"H:\Games\Neverwinter Nights 2\nwn2server.exe"="H:\Games\Neverwinter Nights 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"C:\Program Files\uTorrent\uTorrent.exe"="C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent"
"C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe"="C:\Program Files\SmartFTP Client 2.0\SmartFTP.exe:*:Enabled:SmartFTP Client 2.0"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\SmartFTP Client\SmartFTP.exe"="C:\Program Files\SmartFTP Client\SmartFTP.exe:*:Enabled:SmartFTP Client 3.0"
"H:\Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe"="H:\Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword"
"H:\Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe"="H:\Games\Sid Meier's Civilization 4\Beyond the Sword\Civ4BeyondSword_PitBoss.exe:*:Enabled:Sid Meier's Civilization 4 Beyond the Sword Pitboss"
"H:\Games\Battle for Middle-earth II\game.dat"="H:\Games\Battle for Middle-earth II\game.dat:*:Enabled:The Battle for Middle-earth(tm) II"
"J:\Games\NWN 2\nwn2main.exe"="J:\Games\NWN 2\nwn2main.exe:*:Enabled:Neverwinter Nights 2 Main"
"J:\Games\NWN 2\nwn2main_amdxp.exe"="J:\Games\NWN 2\nwn2main_amdxp.exe:*:Enabled:Neverwinter Nights 2 AMD"
"J:\Games\NWN 2\nwupdate.exe"="J:\Games\NWN 2\nwupdate.exe:*:Enabled:Neverwinter Nights 2 Updater"
"J:\Games\NWN 2\nwn2server.exe"="J:\Games\NWN 2\nwn2server.exe:*:Enabled:Neverwinter Nights 2 Server"
"D:\Applications\Ventrilo\Ventrilo.exe"="D:\Applications\Ventrilo\Ventrilo.exe:*:Enabled:Ventrilo.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{559954fe-a061-11dc-8e02-00000000a666}]
shell\AutoRun\command - I:\autorun.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{559954ff-a061-11dc-8e02-00000000a666}]
shell\AutoRun\command - J:\Autorun.exe
======List of files/folders created in the last 1 months======
2009-08-19 22:47:17 ----SHD---- C:\Config.Msi
2009-08-19 06:21:07 ----HDC---- C:\WINDOWS\$NtUninstallKB961371-v2$
2009-08-19 06:20:42 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$
2009-08-19 06:20:18 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2009-08-19 06:19:53 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$
2009-08-19 06:19:11 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$
2009-08-19 06:15:25 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2009-08-19 06:14:57 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$
2009-08-19 06:13:21 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$
2009-08-19 06:07:26 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$
2009-08-19 06:03:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2009-08-19 06:03:27 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2009-08-19 05:59:27 ----HDC---- C:\WINDOWS\$NtUninstallKB972260$
2009-08-19 05:59:00 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$
2009-08-19 05:58:32 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$
2009-08-19 05:54:41 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2009-08-19 05:50:38 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2009-08-19 05:46:20 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$
2009-08-19 05:41:08 ----HDC---- C:\WINDOWS\$NtUninstallKB957579$
2009-08-19 05:35:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2009-08-19 05:34:25 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2009-08-19 05:30:39 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2009-08-19 05:26:20 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2009-08-19 05:26:09 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2009-08-19 05:22:27 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-08-19 05:22:25 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$
2009-08-19 05:21:49 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$
2009-08-19 05:18:14 ----HDC---- C:\WINDOWS\$NtUninstallKB958690$
2009-08-19 05:14:43 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
2009-08-19 05:11:11 ----HDC---- C:\WINDOWS\$NtUninstallKB959252-v2$
2009-08-19 05:10:35 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2009-08-19 05:07:16 ----HDC---- C:\WINDOWS\$NtUninstallKB958687$
2009-08-19 05:06:48 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2009-08-19 05:03:14 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2009-08-19 04:58:41 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2009-08-19 04:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2009-08-19 04:50:54 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2009-08-19 04:47:28 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2009-08-19 04:43:55 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2009-08-19 04:38:36 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2009-08-19 04:35:23 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2009-08-19 04:31:42 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2009-08-19 04:22:55 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2009-08-19 04:22:30 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2009-08-19 04:21:56 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2009-08-19 04:17:24 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2009-08-19 04:06:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2009-08-18 01:32:24 ----A---- C:\WINDOWS\system32\wups2.dll
2009-08-18 01:32:23 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2009-08-18 01:32:17 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2009-08-18 01:32:12 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2009-08-17 22:26:12 ----D---- C:\rsit
2009-08-16 10:55:38 ----HDC---- C:\Documents and Settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
2009-08-15 18:08:02 ----D---- C:\Documents and Settings\Marvin Kosh.OMNILOTH\Application Data\Malwarebytes
2009-08-15 18:07:07 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2009-08-15 18:06:56 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-08-15 17:05:55 ----D---- C:\WINDOWS\BDOSCAN8
2009-08-14 12:13:43 ----D---- C:\Program Files\Lavasoft
2009-08-14 12:13:43 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
2009-08-13 16:44:22 ----D---- C:\Program Files\Process Monitor
2009-08-13 11:48:32 ----A---- C:\WINDOWS\system32\MFC71.dll
2009-08-13 11:48:32 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-08-13 11:48:22 ----D---- C:\Program Files\Alwil Software
2009-08-13 09:12:18 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Comodo
2009-08-13 09:12:16 ----A---- C:\WINDOWS\system32\guard32.dll
2009-08-13 03:01:35 ----A---- C:\WINDOWS\cfplogvw.INI
2009-08-13 02:43:24 ----D---- C:\Program Files\ThreatFire
2009-08-13 02:32:56 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2009-08-13 02:32:42 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Tools
2009-08-13 02:00:47 ----A---- C:\WINDOWS\system32\MRT.exe
2009-08-12 23:02:23 ----D---- C:\Program Files\Trend Micro
2009-08-12 09:31:37 ----D---- C:\Program Files\DAEMON Tools Toolbar
======List of files/folders modified in the last 1 months======
2009-08-20 01:24:44 ----D---- C:\WINDOWS\Temp
2009-08-20 01:03:53 ----D---- C:\Program Files\BOINC
2009-08-20 01:02:45 ----D---- C:\WINDOWS\system32\CatRoot2
2009-08-20 01:01:35 ----D---- C:\Program Files\Common Files\Stardock
2009-08-20 00:59:59 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-08-19 22:54:59 ----RSD---- C:\WINDOWS\assembly
2009-08-19 22:47:19 ----SHD---- C:\WINDOWS\Installer
2009-08-19 22:40:16 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-08-19 22:40:11 ----D---- C:\WINDOWS\system32
2009-08-19 22:38:29 ----D---- C:\Program Files\GIMP-2.2
2009-08-19 22:38:25 ----D---- C:\WINDOWS\Prefetch
2009-08-19 22:38:11 ----D---- C:\Program Files\Common Files
2009-08-19 22:13:33 ----A---- C:\WINDOWS\LogonStudio.ini
2009-08-19 06:46:17 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-08-19 06:42:11 ----D---- C:\WINDOWS
2009-08-19 06:40:31 ----SH---- C:\boot.ini
2009-08-19 06:40:31 ----A---- C:\WINDOWS\win.ini
2009-08-19 06:40:31 ----A---- C:\WINDOWS\system.ini
2009-08-19 06:21:11 ----HD---- C:\WINDOWS\inf
2009-08-19 06:21:02 ----HD---- C:\WINDOWS\$hf_mig$
2009-08-19 06:20:47 ----A---- C:\WINDOWS\imsins.BAK
2009-08-19 06:19:56 ----D---- C:\Program Files\Outlook Express
2009-08-19 06:14:59 ----D---- C:\WINDOWS\ServicePackFiles
2009-08-19 06:09:05 ----D---- C:\WINDOWS\system32\Setup
2009-08-19 06:09:05 ----D---- C:\WINDOWS\system32\drivers
2009-08-19 05:59:35 ----D---- C:\Program Files\Internet Explorer
2009-08-19 05:27:26 ----D---- C:\WINDOWS\AppPatch
2009-08-19 05:23:37 ----D---- C:\WINDOWS\system32\wbem
2009-08-19 04:54:37 ----D---- C:\WINDOWS\system32\CatRoot
2009-08-19 04:21:59 ----D---- C:\Program Files\Messenger
2009-08-18 01:35:06 ----D---- C:\WINDOWS\SoftwareDistribution
2009-08-18 01:32:27 ----D---- C:\WINDOWS\Help
2009-08-18 01:30:33 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-08-17 14:57:13 ----SHD---- C:\System Volume Information
2009-08-16 23:16:15 ----RD---- C:\Program Files
2009-08-16 11:09:29 ----A---- C:\WINDOWS\WININIT.INI
2009-08-16 10:59:07 ----SD---- C:\WINDOWS\Tasks
2009-08-14 15:34:22 ----D---- C:\WINDOWS\security
2009-08-14 12:18:44 ----SHD---- C:\WINDOWS\CSC
2009-08-14 12:17:35 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-08-14 12:15:34 ----HD---- C:\$AVG8.VAULT$
2009-08-13 22:11:05 ----D---- C:\Documents and Settings
2009-08-13 16:26:32 ----D---- C:\WINDOWS\system32\config
2009-08-13 09:12:09 ----D---- C:\Program Files\COMODO
2009-08-13 02:00:48 ----D---- C:\WINDOWS\Debug
2009-08-13 00:19:27 ----D---- C:\Documents and Settings\Marvin Kosh.OMNILOTH\Application Data\Comodo
2009-08-12 22:19:20 ----D---- C:\Documents and Settings\Marvin Kosh.OMNILOTH\Application Data\DAEMON Tools Lite
2009-08-12 09:31:37 ----D---- C:\Program Files\DAEMON Tools Lite
2009-08-11 23:27:59 ----A---- C:\moduleName.txt
2009-08-09 08:08:46 ----D---- C:\Program Files\Spybot - Search & Destroy
2009-08-05 10:11:47 ----A---- C:\WINDOWS\system32\mswebdvd.dll
2009-08-03 07:04:41 ----D---- C:\Program Files\Winamp
2009-07-29 10:23:16 ----A---- C:\WINDOWS\system32\t2embed.dll
2009-07-29 05:53:14 ----A---- C:\WINDOWS\system32\fontsub.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2009-02-05 26944]
R1 AmdK7;AMD K7 Processor Driver; C:\WINDOWS\system32\DRIVERS\amdk7.sys [2004-08-04 37376]
R1 aswSP;avast! Self Protection; C:\WINDOWS\system32\drivers\aswSP.sys [2009-02-05 114768]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2009-02-05 51376]
R1 atitray;atitray; \??\C:\Program Files\Ray Adams\ATI Tray Tools\atitray.sys []
R1 AvgLdx86;AVG AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-07-18 335752]
R1 AvgMfx86;AVG On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-06-23 27784]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-05-07 108552]
R1 cmdGuard;COMODO Internet Security Sandbox Driver; C:\WINDOWS\System32\DRIVERS\cmdguard.sys [2009-08-13 132040]
R1 cmdHlp;COMODO Internet Security Helper Driver; C:\WINDOWS\System32\DRIVERS\cmdhlp.sys [2009-08-13 25160]
R1 StyleXPHelper;StyleXPHelper; \??\C:\Program Files\TGTSoft\StyleXP\StyleXPHelper.exe []
R2 aswFsBlk;aswFsBlk; C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys [2009-02-05 20560]
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2009-02-05 94032]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2004-08-04 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2009-02-05 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-09-24 3331072]
R3 COMMONFX.SYS;COMMONFX.SYS; C:\WINDOWS\System32\drivers\COMMONFX.SYS [2008-06-27 99352]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2008-07-07 511000]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2008-07-07 532376]
R3 CTAUDFX.SYS;CTAUDFX.SYS; C:\WINDOWS\System32\drivers\CTAUDFX.SYS [2008-06-27 555032]
R3 ctgame;Game Port; C:\WINDOWS\system32\DRIVERS\ctgame.sys [2008-07-07 18840]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2008-07-07 14360]
R3 CTSBLFX.SYS;CTSBLFX.SYS; C:\WINDOWS\System32\drivers\CTSBLFX.SYS [2008-06-27 566296]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2008-07-07 157208]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2008-07-07 92696]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2008-07-07 797720]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2008-07-07 162840]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2004-08-04 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2004-08-04 61824]
R3 NVENET;NVIDIA nForce MCP Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENET.sys [2002-11-27 80896]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2008-07-07 127512]
R3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2004-08-04 17024]
R3 XBCD;XBCD Kernel Module; C:\WINDOWS\System32\Drivers\xbcd.sys [2005-05-13 19212]
S3 a7fd7wqu;a7fd7wqu; C:\WINDOWS\system32\drivers\a7fd7wqu.sys []
S3 amvadfcs;amvadfcs; C:\WINDOWS\system32\drivers\amvadfcs.sys []
S3 COMMONFX;COMMONFX; C:\WINDOWS\system32\drivers\COMMONFX.SYS [2008-06-27 99352]
S3 CTAUDFX;CTAUDFX; C:\WINDOWS\system32\drivers\CTAUDFX.SYS [2008-06-27 555032]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2008-07-07 347080]
S3 CTERFXFX.SYS;CTERFXFX.SYS; C:\WINDOWS\System32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTERFXFX;CTERFXFX; C:\WINDOWS\system32\drivers\CTERFXFX.SYS [2008-06-27 100888]
S3 CTSBLFX;CTSBLFX; C:\WINDOWS\system32\drivers\CTSBLFX.SYS [2008-06-27 566296]
S3 GMSIPCI;GMSIPCI; \??\G:\INSTALL\GMSIPCI.SYS []
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2008-07-07 189464]
S3 Tablet2k;Serial Tablet Port Driver; C:\WINDOWS\System32\Drivers\Tablet2k.sys []
S3 TClass2k;Tablet Class Driver; C:\WINDOWS\system32\DRIVERS\TClass2k.sys [2007-04-23 18432]
S3 UCharger;Usb Charger Driver; C:\WINDOWS\System32\Drivers\UCharger.sys [2007-05-15 13765]
S3 UCTblHid;HID Tablet Port Driver; C:\WINDOWS\system32\DRIVERS\UCTblHid.sys [2007-05-31 12800]
S3 UKS11LDR;M-Audio USB Keystation Loader; C:\WINDOWS\system32\drivers\uks11ldr.sys [2008-09-20 13504]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBKT1X1;M-Audio USB Keystation; C:\WINDOWS\system32\drivers\usbkt1x1.sys [2008-09-20 22304]
S3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2004-08-03 25856]
S3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2004-08-03 15104]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-04 26496]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
S4 sr;System Restore Filter Driver; C:\WINDOWS\system32\DRIVERS\sr.sys [2004-08-04 73472]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-02-05 18752]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-02-05 138680]
R2 cmdAgent;COMODO Internet Security Helper Service; C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe [2009-08-13 707152]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe [2009-08-16 1029456]
R2 ThreatFire;ThreatFire; C:\Program Files\ThreatFire\TFService.exe [2009-06-19 70928]
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 WinTabService;WinTab Service; C:\WINDOWS\System32\Drivers\WTSRV.EXE [2007-05-31 53248]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-02-05 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-02-05 352920]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2008-09-23 593920]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632]
S4 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-09-24 581632]
S4 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2009-07-18 907032]
S4 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-06-23 298776]
S4 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-18 152984]
S4 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 28768528]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 msvsmon80;Visual Studio 2005 Remote Debugger; D:\Applications\Microsoft Visual Studio 8\Common7\IDE\Remote Debugger\x86\msvsmon.exe [2005-09-23 2799808]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2005-10-14 239320]
S4 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2005-10-14 87768]
S4 StyleXPService;StyleXPService; C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe [2006-05-24 372736]
-----------------EOF-----------------