Logfile of random's system information tool 1.06 (written by random/random) Run by Kris_2 at 2010-01-23 12:27:42 Microsoft® Windows Vista™ Home Premium Service Pack 2 System drive C: has 154 GB (67%) free of 228 GB Total RAM: 3316 MB (56% free)
Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 12:27:49, on 23/01/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18882) Boot mode: Normal
Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe C:\Program Files\Dell Photo AIO Printer 926\memcard.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Java\jre6\bin\jusched.exe C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\NETGEAR\WPN111\wpn111.exe C:\Program Files\Trusteer\Rapport\bin\RapportService.exe C:\Windows\system32\wbem\unsecapp.exe C:\Windows\system32\igfxsrvc.exe C:\Program Files\BitTorrent\bittorrent.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Windows\system32\Macromed\Flash\FlashUtil10d.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Windows Media Player\wmplayer.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Users\Kris_2\Desktop\RSIT.exe C:\Program Files\Trend Micro\HijackThis\Kris_2.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.bing.co.uk/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray O4 - HKLM\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot O4 - HKCU\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe" -startup O4 - HKCU\..\Run: [BullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe O4 - Global Startup: NETGEAR WPN111 Smart Wizard.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe O23 - Service: dlcx_device - - C:\Windows\system32\dlcxcoms.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
-- End of file - 4751 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-01-17 4907008] "ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2005-08-11 81920] "dlcxmon.exe"=C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe [2007-01-12 292336] "MemoryCardManager"=C:\Program Files\Dell Photo AIO Printer 926\memcard.exe [2006-11-04 304008] "HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-02-11 166424] "Persistence"=C:\Windows\system32\igfxpers.exe [2008-02-11 133656] "SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-11 149280] "IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-02-11 141848] "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-01-07 429392] "BullGuard"=C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe [2010-01-12 304464]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ISUSPM Startup"=C:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe [2005-08-11 249856] "BullGuard"=C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe [2010-01-12 304464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2007-03-01 153136]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe NETGEAR WPN111 Smart Wizard.lnk - C:\Program Files\NETGEAR\WPN111\wpn111.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\Windows\system32\igfxdev.dll [2008-02-11 204800]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\BgMainSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BgLiveSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\BgMainSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "BindDirectlyToPropertySetStorage"= "NoDrives"= "NoDriveTypeAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 3 months======
2010-01-22 12:26:17 ----A---- C:\avenger.txt 2010-01-22 10:54:16 ----A---- C:\Windows\system32\mshtml.dll 2010-01-22 10:54:15 ----A---- C:\Windows\system32\ieframe.dll 2010-01-22 10:54:14 ----A---- C:\Windows\system32\iertutil.dll 2010-01-22 10:54:13 ----A---- C:\Windows\system32\wininet.dll 2010-01-22 10:54:13 ----A---- C:\Windows\system32\urlmon.dll 2010-01-22 10:54:13 ----A---- C:\Windows\system32\occache.dll 2010-01-22 10:54:13 ----A---- C:\Windows\system32\msfeeds.dll 2010-01-22 10:54:12 ----A---- C:\Windows\system32\iedkcs32.dll 2010-01-22 10:54:11 ----A---- C:\Windows\system32\ieui.dll 2010-01-22 10:54:11 ----A---- C:\Windows\system32\iepeers.dll 2010-01-22 10:54:10 ----A---- C:\Windows\system32\msfeedssync.exe 2010-01-22 10:54:10 ----A---- C:\Windows\system32\msfeedsbs.dll 2010-01-22 10:54:10 ----A---- C:\Windows\system32\jsproxy.dll 2010-01-22 10:54:10 ----A---- C:\Windows\system32\ieUnatt.exe 2010-01-22 10:54:10 ----A---- C:\Windows\system32\iesysprep.dll 2010-01-22 10:54:10 ----A---- C:\Windows\system32\ie4uinit.exe 2010-01-22 10:54:09 ----A---- C:\Windows\system32\iesetup.dll 2010-01-22 10:54:09 ----A---- C:\Windows\system32\iernonce.dll 2010-01-19 14:50:18 ----D---- C:\Avenger 2010-01-18 01:46:41 ----A---- C:\Windows\system32\Regsearch1.txt 2010-01-16 14:09:42 ----D---- C:\rsit 2010-01-14 18:45:17 ----SHD---- C:\$RECYCLE.BIN 2010-01-14 18:31:09 ----A---- C:\Windows\SWXCACLS.exe 2010-01-12 23:52:44 ----A---- C:\Windows\system32\t2embed.dll 2010-01-12 23:52:44 ----A---- C:\Windows\system32\fontsub.dll 2010-01-12 23:49:03 ----A---- C:\Windows\system32\BGLsp.dll 2010-01-12 17:49:20 ----D---- C:\Program Files\BullGuard Ltd 2010-01-12 17:02:25 ----D---- C:\Users\Kris_2\AppData\Roaming\AVG8 2010-01-09 15:25:21 ----D---- C:\Windows\temp 2010-01-08 13:10:58 ----A---- C:\Windows\zip.exe 2010-01-08 13:10:58 ----A---- C:\Windows\SWSC.exe 2010-01-08 13:10:58 ----A---- C:\Windows\SWREG.exe 2010-01-08 13:10:58 ----A---- C:\Windows\sed.exe 2010-01-08 13:10:58 ----A---- C:\Windows\PEV.exe 2010-01-08 13:10:58 ----A---- C:\Windows\NIRCMD.exe 2010-01-08 13:10:58 ----A---- C:\Windows\MBR.exe 2010-01-08 13:10:58 ----A---- C:\Windows\grep.exe 2010-01-07 13:06:27 ----D---- C:\ProgramData\BullGuard 2010-01-07 13:06:26 ----D---- C:\Users\Kris_2\AppData\Roaming\BullGuard 2010-01-07 12:59:11 ----D---- C:\Users\Kris_2\AppData\Roaming\Tific 2010-01-06 10:48:39 ----D---- C:\Windows\Internet Logs 2010-01-05 15:24:38 ----D---- C:\Windows\ERDNT 2009-12-26 11:05:34 ----D---- C:\Program Files\Common Files\PC Tools 2009-12-26 10:20:35 ----D---- C:\Users\Kris_2\AppData\Roaming\Trusteer 2009-12-26 10:20:30 ----D---- C:\Program Files\Trusteer 2009-12-22 16:14:04 ----D---- C:\Program Files\Microsoft 2009-12-22 16:13:40 ----D---- C:\Program Files\Windows Live 2009-12-12 15:19:46 ----D---- C:\Program Files\CCleaner 2009-12-11 01:18:41 ----D---- C:\Users\Kris_2\AppData\Roaming\Malwarebytes 2009-12-11 01:18:34 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2009-12-11 00:53:15 ----D---- C:\Users\Kris_2\AppData\Roaming\BitTorrent 2009-12-11 00:51:44 ----D---- C:\Program Files\BitTorrent 2009-12-09 11:43:56 ----A---- C:\Windows\system32\nshhttp.dll 2009-12-09 11:43:55 ----A---- C:\Windows\system32\httpapi.dll 2009-12-09 11:24:34 ----A---- C:\Windows\system32\winhttp.dll 2009-12-09 11:23:43 ----A---- C:\Windows\system32\rastls.dll 2009-12-08 18:26:10 ----D---- C:\Users\Kris_2\AppData\Roaming\DivX 2009-12-08 18:16:40 ----D---- C:\ProgramData\Nero 2009-12-08 18:16:40 ----D---- C:\Program Files\Nero 2009-12-07 22:22:47 ----D---- C:\Users\Kris_2\AppData\Roaming\Ahead 2009-12-07 04:00:56 ----D---- C:\Program Files\Common Files\Ahead 2009-12-05 16:09:47 ----D---- C:\Program Files\Trend Micro 2009-12-04 17:41:35 ----D---- C:\Windows\pss 2009-12-04 03:02:30 ----D---- C:\dvdsanta 2009-12-03 01:38:24 ----A---- C:\Windows\NeroDigital.ini 2009-12-02 12:20:55 ----D---- C:\Program Files\AVG 2009-11-30 19:47:26 ----D---- C:\ProgramData\Malwarebytes 2009-11-25 13:39:36 ----A---- C:\Windows\system32\tzres.dll 2009-11-25 12:48:12 ----A---- C:\Windows\system32\msxml6.dll 2009-11-25 12:48:11 ----A---- C:\Windows\system32\msxml3.dll 2009-11-19 18:56:24 ----D---- C:\ProgramData\Office Genuine Advantage 2009-11-11 18:56:53 ----A---- C:\Windows\system32\WSDApi.dll 2009-11-09 20:39:42 ----A---- C:\Windows\system32\javaws.exe 2009-11-09 20:39:42 ----A---- C:\Windows\system32\javaw.exe 2009-11-09 20:39:42 ----A---- C:\Windows\system32\java.exe 2009-10-28 09:19:57 ----D---- C:\Program Files\Windows Portable Devices 2009-10-28 09:17:48 ----A---- C:\Windows\system32\UIAnimation.dll 2009-10-28 09:17:47 ----A---- C:\Windows\system32\UIRibbonRes.dll 2009-10-28 09:17:47 ----A---- C:\Windows\system32\UIRibbon.dll 2009-10-28 09:17:21 ----A---- C:\Windows\system32\WMPhoto.dll 2009-10-28 09:17:20 ----A---- C:\Windows\system32\cdd.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\XpsRasterService.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\XpsPrint.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\XpsGdiConverter.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\WindowsCodecsExt.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\WindowsCodecs.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe 2009-10-28 09:17:19 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\dxdiagn.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\dxdiag.exe 2009-10-28 09:17:19 ----A---- C:\Windows\system32\d3d10warp.dll 2009-10-28 09:17:19 ----A---- C:\Windows\system32\d2d1.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\xpsservices.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\OpcServices.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\FntCache.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\dxgi.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\DWrite.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d11.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d10level9.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d10core.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d10_1core.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d10_1.dll 2009-10-28 09:17:18 ----A---- C:\Windows\system32\d3d10.dll 2009-10-28 09:16:42 ----A---- C:\Windows\system32\WPDShextAutoplay.exe 2009-10-28 09:16:42 ----A---- C:\Windows\system32\wpdbusenum.dll 2009-10-28 09:16:42 ----A---- C:\Windows\system32\BthMtpContextHandler.dll 2009-10-28 09:16:37 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll 2009-10-28 09:16:35 ----A---- C:\Windows\system32\wpdshext.dll 2009-10-28 09:16:35 ----A---- C:\Windows\system32\WpdMtpUS.dll 2009-10-28 09:16:35 ----A---- C:\Windows\system32\WpdConns.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\WPDSp.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\WPDShServiceObj.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\WpdMtp.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\wpd_ci.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\PortableDeviceTypes.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll 2009-10-28 09:16:34 ----A---- C:\Windows\system32\PortableDeviceApi.dll 2009-10-28 09:15:40 ----A---- C:\Windows\system32\oleaccrc.dll 2009-10-28 09:15:36 ----A---- C:\Windows\system32\UIAutomationCore.dll 2009-10-28 09:15:36 ----A---- C:\Windows\system32\oleacc.dll 2009-10-28 09:06:46 ----A---- C:\Windows\system32\wmp.dll 2009-10-28 09:06:44 ----A---- C:\Windows\system32\unregmp2.exe 2009-10-28 09:06:43 ----A---- C:\Windows\system32\wmploc.DLL
======List of files/folders modified in the last 3 months======
2010-01-23 12:04:50 ----D---- C:\Windows\System32 2010-01-23 12:04:50 ----D---- C:\Windows\inf 2010-01-23 12:04:50 ----A---- C:\Windows\system32\PerfStringBackup.INI 2010-01-23 12:02:57 ----D---- C:\Windows\system32\drivers 2010-01-23 11:57:39 ----D---- C:\Windows\system32\catroot2 2010-01-22 21:19:44 ----D---- C:\Windows\Prefetch 2010-01-22 16:36:49 ----D---- C:\Windows\Minidump 2010-01-22 16:36:46 ----D---- C:\Windows 2010-01-22 12:14:12 ----D---- C:\Program Files\Microsoft Silverlight 2010-01-22 11:04:24 ----D---- C:\Windows\system32\migration 2010-01-22 11:04:24 ----D---- C:\Program Files\Internet Explorer 2010-01-22 10:56:10 ----D---- C:\Windows\winsxs 2010-01-22 10:55:37 ----SHD---- C:\Windows\Installer 2010-01-22 10:55:05 ----SHD---- C:\System Volume Information 2010-01-22 10:52:27 ----D---- C:\Windows\system32\catroot 2010-01-19 14:50:18 ----RD---- C:\Program Files 2010-01-18 01:23:31 ----SD---- C:\Windows\Downloaded Program Files 2010-01-14 18:45:14 ----A---- C:\Windows\system.ini 2010-01-13 13:33:56 ----D---- C:\Windows\Debug 2010-01-12 23:55:09 ----D---- C:\Program Files\Windows Mail 2010-01-12 23:53:39 ----D---- C:\Program Files\Common Files\microsoft shared 2010-01-12 17:06:44 ----SD---- C:\Users\Kris_2\AppData\Roaming\Microsoft 2010-01-12 17:06:39 ----D---- C:\ProgramData 2010-01-09 15:13:05 ----D---- C:\Windows\AppPatch 2010-01-09 15:08:03 ----D---- C:\Program Files\Common Files 2010-01-08 00:35:16 ----RSD---- C:\Windows\assembly 2010-01-07 12:18:34 ----D---- C:\Windows\system32\Tasks 2010-01-06 13:15:14 ----D---- C:\TempDVD 2010-01-05 16:02:32 ----AD---- C:\ProgramData\TEMP 2010-01-05 13:22:36 ----D---- C:\Windows\system32\config 2010-01-05 00:17:46 ----A---- C:\Windows\system32\mrt.exe 2010-01-04 15:28:13 ----RD---- C:\Users 2009-12-31 00:30:20 ----D---- C:\Windows\Cache 2009-12-27 19:44:50 ----SD---- C:\ProgramData\Microsoft 2009-12-17 15:36:00 ----D---- C:\Windows\system32\LogFiles 2009-12-09 12:42:30 ----D---- C:\Windows\rescache 2009-12-09 12:24:58 ----D---- C:\Windows\system32\en-US 2009-12-08 18:17:16 ----D---- C:\Windows\ehome 2009-12-05 16:31:03 ----D---- C:\Program Files\Common Files\Adobe 2009-12-05 16:31:03 ----D---- C:\Program Files\Adobe 2009-12-05 16:31:02 ----D---- C:\ProgramData\Adobe 2009-12-03 22:20:10 ----D---- C:\Windows\Downloaded Installations 2009-12-02 12:33:03 ----D---- C:\Windows\system32\spool 2009-11-30 23:09:47 ----D---- C:\Windows\system32\wbem 2009-11-30 23:08:49 ----D---- C:\Windows\Tasks 2009-11-30 23:08:49 ----D---- C:\Program Files\Windows Defender 2009-11-30 23:08:48 ----D---- C:\Windows\system32\Msdtc 2009-11-30 23:08:48 ----D---- C:\Windows\system32\CodeIntegrity 2009-11-30 23:08:47 ----D---- C:\Program Files\DivX 2009-11-30 23:08:46 ----D---- C:\Windows\registration 2009-11-30 23:08:46 ----D---- C:\Program Files\Common Files\DivX Shared 2009-11-19 18:07:59 ----D---- C:\Windows\system32\zh-TW 2009-11-19 18:07:59 ----D---- C:\Windows\system32\zh-HK 2009-11-19 18:07:59 ----D---- C:\Windows\system32\tr-TR 2009-11-19 18:07:59 ----D---- C:\Windows\system32\sv-SE 2009-11-19 18:07:59 ----D---- C:\Windows\system32\pt-BR 2009-11-19 18:07:59 ----D---- C:\Windows\system32\nl-NL 2009-11-19 18:07:59 ----D---- C:\Windows\system32\nb-NO 2009-11-19 18:07:59 ----D---- C:\Windows\system32\ko-KR 2009-11-19 18:07:59 ----D---- C:\Windows\system32\it-IT 2009-11-19 18:07:59 ----D---- C:\Windows\system32\he-IL 2009-11-19 18:07:59 ----D---- C:\Windows\system32\fr-FR 2009-11-19 18:07:59 ----D---- C:\Windows\system32\fi-FI 2009-11-19 18:07:59 ----D---- C:\Windows\system32\es-ES 2009-11-19 18:07:59 ----D---- C:\Windows\system32\el-GR 2009-11-19 18:07:59 ----D---- C:\Windows\system32\de-DE 2009-11-19 18:07:59 ----D---- C:\Windows\system32\da-DK 2009-11-19 18:07:59 ----D---- C:\Windows\system32\ar-SA 2009-11-09 20:39:40 ----D---- C:\Program Files\Java 2009-11-02 20:42:06 ----N---- C:\Windows\system32\MpSigStub.exe 2009-10-28 09:19:55 ----D---- C:\Windows\system32\zh-CN 2009-10-28 09:19:55 ----D---- C:\Windows\system32\uk-UA 2009-10-28 09:19:55 ----D---- C:\Windows\system32\th-TH 2009-10-28 09:19:55 ----D---- C:\Windows\system32\sr-Latn-CS 2009-10-28 09:19:55 ----D---- C:\Windows\system32\sl-SI 2009-10-28 09:19:55 ----D---- C:\Windows\system32\sk-SK 2009-10-28 09:19:55 ----D---- C:\Windows\system32\ru-RU 2009-10-28 09:19:55 ----D---- C:\Windows\system32\ro-RO 2009-10-28 09:19:55 ----D---- C:\Windows\system32\pt-PT 2009-10-28 09:19:55 ----D---- C:\Windows\system32\pl-PL 2009-10-28 09:19:55 ----D---- C:\Windows\system32\lv-LV 2009-10-28 09:19:55 ----D---- C:\Windows\system32\lt-LT 2009-10-28 09:19:55 ----D---- C:\Windows\system32\ja-JP 2009-10-28 09:19:55 ----D---- C:\Windows\system32\hu-HU 2009-10-28 09:19:55 ----D---- C:\Windows\system32\hr-HR 2009-10-28 09:19:55 ----D---- C:\Windows\system32\et-EE 2009-10-28 09:19:55 ----D---- C:\Windows\system32\cs-CZ 2009-10-28 09:19:55 ----D---- C:\Windows\system32\bg-BG 2009-10-28 09:19:46 ----D---- C:\Program Files\Windows Media Player
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 afw;Agnitum Firewall Driver; C:\Windows\system32\DRIVERS\afw.sys [2010-01-12 29208] R1 kl1;kl1; C:\Windows\system32\DRIVERS\kl1.sys [2009-09-01 128016] R1 RapportKELL;RapportKELL; \??\C:\Program Files\Trusteer\Rapport\bin\RapportKELL.sys [2009-12-15 58984] R1 RapportPG;RapportPG; \??\C:\Program Files\Trusteer\Rapport\bin\RapportPG.sys [2009-12-15 337000] R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\Windows\system32\DRIVERS\AegisP.sys [2008-04-13 17801] R2 BdFileSpy;BullGuard File Monitor Driver; \??\C:\Windows\system32\drivers\BdFileSpy.sys [2010-01-12 55504] R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2006-06-19 12672] R2 RMCAST;RMCAST (Pgm) Protocol Driver; C:\Windows\system32\DRIVERS\RMCAST.sys [2009-04-11 113664] R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2006-08-05 8192] R3 AfwCore;Agnitum Firewall Core Driver; \??\C:\Windows\system32\Drivers\AfwCore.sys [2010-01-12 305688] R3 e1express;Intel(R) PRO/1000 PCI Express Network Connection Driver; C:\Windows\system32\DRIVERS\e1e6032.sys [2007-04-29 228224] R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2006-10-18 986624] R3 HSXHWBS2;HSXHWBS2; C:\Windows\system32\DRIVERS\HSXHWBS2.sys [2006-10-18 258048] R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-02-11 2302976] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-01-24 2054872] R3 MBAMProtector;MBAMProtector; \??\C:\Windows\system32\drivers\mbam.sys [2010-01-07 19160] R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2006-10-18 659968] R3 WPN111;Wireless USB 2.0 Adapter with RangeMax Service; C:\Windows\system32\DRIVERS\WPN111v.sys [2008-08-04 904192] S3 AFGMp50;AFGMp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\AFGMp50.sys [] S3 AFGSp50;AFGSp50 NDIS Protocol Driver; C:\Windows\System32\Drivers\AFGSp50.sys [] S3 catchme;catchme; \??\C:\456out\catchme.sys [] S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632] S3 IntelDH;IntelDH Driver; C:\Windows\System32\Drivers\IntelDH.sys [2007-07-27 5504] S3 MRV6X32P;Vista 32-bits Native WiFi Driver; C:\Windows\system32\DRIVERS\MRVW13B.sys [2007-05-03 256000] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888] S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016] S3 NDISKIO;NDISKIO; \??\C:\Users\Kris_2\AppData\Local\Temp\00000e71.nmc\nse\bin\ndiskio.sys [] S3 nsak;nsak; \??\C:\Users\Kris_2\AppData\Local\Temp\00000e71.nmc\nse\bin\nsak.sys [] S3 Profos;Profos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\profos.sys [2010-01-12 14720] S3 R300;R300; C:\Windows\system32\DRIVERS\atikmdag.sys [2006-11-02 2028032] S3 Reconn;BullGuard Email Monitor; \??\C:\Program Files\BullGuard Ltd\BullGuard\Reconn.sys [2008-07-29 16984] S3 RT73;D-Link USB Wireless LAN Card Driver; C:\Windows\system32\DRIVERS\Dr71WU.sys [2005-11-03 245504] S3 RTL8023xp;Realtek 10/100 NIC Family NDIS x86 Driver; C:\Windows\system32\DRIVERS\Rtnicxp.sys [2006-11-02 47104] S3 s125bus;Sony Ericsson Device 125 driver (WDM); C:\Windows\system32\DRIVERS\s125bus.sys [2007-04-24 83336] S3 s125mdfl;Sony Ericsson Device 125 USB WMC Modem Filter; C:\Windows\system32\DRIVERS\s125mdfl.sys [2007-04-24 15112] S3 s125mdm;Sony Ericsson Device 125 USB WMC Modem Driver; C:\Windows\system32\DRIVERS\s125mdm.sys [2007-04-24 108680] S3 s125mgmt;Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM); C:\Windows\system32\DRIVERS\s125mgmt.sys [2007-04-24 100488] S3 s125obex;Sony Ericsson Device 125 USB WMC OBEX Interface; C:\Windows\system32\DRIVERS\s125obex.sys [2007-04-24 98696] S3 s616bus;Sony Ericsson Device 616 driver (WDM); C:\Windows\system32\DRIVERS\s616bus.sys [2007-04-03 83208] S3 ST330;ST330; C:\Windows\system32\drivers\st330.sys [2007-08-16 30464] S3 STBUS;STBUS; C:\Windows\system32\drivers\stbus.sys [2007-08-16 12672] S3 stppp;Speedtouch PPP Adapter Adapter; C:\Windows\system32\DRIVERS\stppp.sys [2007-08-16 35328] S3 Trufos;Trufos; \??\C:\Program Files\BullGuard Ltd\BullGuard\antirootkit\trufos.sys [2010-01-12 39808] S3 TSHWMDTCP;TSHWMDTCP; \??\C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\TSHWMDTCP.sys [] S3 UMPass;Microsoft UMPass Driver; C:\Windows\system32\DRIVERS\umpass.sys [2008-01-19 7680] S3 usbaudio;USB Audio Driver (WDM); C:\Windows\system32\drivers\usbaudio.sys [2009-04-11 73216] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-19 35328] S3 W8335XP;802.11g/b Driver for Windows XP ; C:\Windows\system32\DRIVERS\Mrvw125.sys [2007-06-19 282624] S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-10-01 40448] S4 iaStor;Intel AHCI Controller; C:\Windows\system32\drivers\iastor.sys [2007-04-26 304920] S4 sptd;sptd; C:\Windows\System32\Drivers\sptd.sys [] S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AERTFilters;Andrea RT Filters Service; C:\Windows\system32\AERTSrv.exe [2007-12-05 77824] R2 BgLiveSvc;BullGuard LiveUpdate; C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe [2010-01-12 300368] R2 BgMainSvc;BullGuard Main Service; C:\Windows\System32\svchost.exe [2008-01-19 21504] R2 BsFileScan;BullGuard File Scan Service; C:\Windows\System32\svchost.exe [2008-01-19 21504] R2 BsFire;BullGuard Firewall Service; C:\Windows\System32\svchost.exe [2008-01-19 21504] R2 BsMailProxy;BullGuard Email Monitoring Service; C:\Windows\System32\svchost.exe [2008-01-19 21504] R2 dlcx_device;dlcx_device; C:\Windows\system32\dlcxcoms.exe [2006-11-04 537480] R2 MBAMService;MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [2010-01-07 236368] R2 RapportMgmtService;Rapport Management Service; C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe [2009-12-15 972008] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808] R2 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2006-08-05 386560] S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 NMIndexingService;NMIndexingService; C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe [2007-06-27 279848] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136]
-----------------EOF----------------- |