Logfile of random's system information tool 1.06 (written by random/random)
Run by BBc04 at 2009-04-28 15:56:10
Microsoft Windows XP Professional Service Pack 3
System drive C: has 105 GB (92%) free of 114 GB
Total RAM: 1791 MB (53% free)
HijackThis download failed
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C}]
IEVkbdBHO Class - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\ievkbd.dll [2008-07-29 62728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{af83e43c-dd2b-4787-826b-31b17dee52ed} - QT Breadcrumbs Address Bar - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{d2bf470e-ed1c-487f-a333-2bd8835eb6ce} - QT TabBar - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{D2BF470E-ED1C-487F-A666-2BD8835EB6CE} - QT Tab Standard Buttons - C:\WINDOWS\system32\mscoree.dll [2008-07-25 282112]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\ESAP 3\Windows 7 - Styler\TB\StylerTB.dll [2006-05-02 102400]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-04-10 16861184]
"Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632]
"AVP"=C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe [2009-04-27 206088]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\CTFMON.EXE [2008-04-14 15360]
"Dock"=C:\Program Files\ESAP 3\Windows 7 - Dock\Dock.exe [2009-02-18 689664]
"DIcon"=C:\Program Files\ESAP 3\Windows 7 - Drive Icon\DrvIcon.exe []
"Styler"=C:\Program Files\ESAP 3\Windows 7 - Styler\Styler.exe [2007-04-15 307200]
"Visplore"=C:\Program Files\ESAP 3\Windows 7 - ViSplore\ViSplore.exe [2008-11-12 688128]
"Vistart"=C:\Program Files\ESAP 3\Windows 7 - 7Start\7Start.exe [2009-01-06 1281996]
"TaskTip"=C:\Program Files\ESAP 3\Windows 7 - VisualTaskTips\VisualTaskTips.exe [2008-06-22 65536]
"TT"=C:\Program Files\ESAP 3\Windows 7 - TrueTransparency\TrueTransparency.exe [2008-06-24 372224]
"Peek"=C:\Program Files\ESAP 3\Windows 7 - AeroPeek\AeroPeek.exe [2009-01-03 788992]
"MsnMsgr"=C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe [2007-10-18 5724184]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll,C:\PROGRA~1\KASPER~1\KASPER~1\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1\kloehk.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2008-12-01 143360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\klogon]
C:\WINDOWS\system32\klogon.dll [2008-07-29 218376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-01-08 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2009-01-08 133632]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoUserNameInStartMenu"=1
"ForceClassicControlPanel"=1
"NoSMHelp"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger"
"C:\Program Files\Windows Live\Messenger\livecall.exe"="C:\Program Files\Windows Live\Messenger\livecall.exe:*:Enabled:Windows Live Messenger (Phone)"
======List of files/folders created in the last 1 months======
2009-04-28 15:56:11 ----D---- C:\Program Files\trend micro
2009-04-28 15:56:10 ----D---- C:\rsit
2009-04-28 05:12:49 ----D---- C:\Program Files\Aspell
2009-04-28 00:25:28 ----D---- C:\Documents and Settings\BBc04\Application Data\Opera
2009-04-28 00:25:22 ----D---- C:\Program Files\Opera
2009-04-27 23:28:12 ----A---- C:\WINDOWS\system32\h323log.txt
2009-04-27 23:27:58 ----DC---- C:\WINDOWS\system32\DRVSTORE
2009-04-27 23:26:06 ----SHDC---- C:\Program Files\Common Files\WindowsLiveInstaller
2009-04-27 23:26:02 ----D---- C:\Program Files\Windows Live
2009-04-27 23:25:52 ----D---- C:\Documents and Settings\All Users\Application Data\WLInstaller
2009-04-27 23:23:42 ----D---- C:\WINDOWS\system32\RTCOM
2009-04-27 23:23:41 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-04-27 23:23:18 ----A---- C:\WINDOWS\system32\hidserv.dll
2009-04-27 23:20:42 ----A---- C:\WINDOWS\system32\usbui.dll
2009-04-27 23:18:22 ----D---- C:\Documents and Settings\BBc04\Application Data\WinRAR
2009-04-27 23:18:11 ----SHD---- C:\WINDOWS\Installer
2009-04-27 23:18:11 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-04-27 23:18:10 ----D---- C:\Program Files\Common Files\ODBC
2009-04-27 23:18:10 ----A---- C:\WINDOWS\ODBCINST.INI
2009-04-27 23:18:07 ----RD---- C:\Program Files
2009-04-27 23:18:07 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-04-27 23:18:07 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-04-27 23:18:07 ----D---- C:\Program Files\Common Files
2009-04-27 23:18:03 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-04-27 23:18:03 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-04-27 23:18:02 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-04-27 23:18:01 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-04-27 23:18:00 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-04-27 23:18:00 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-04-27 23:18:00 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-04-27 23:18:00 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-04-27 23:18:00 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-04-27 23:17:59 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-04-27 23:17:58 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-04-27 23:17:57 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-04-27 23:17:57 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-04-27 23:17:57 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-04-27 23:17:57 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-04-27 23:17:57 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-04-27 23:17:55 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-04-27 23:17:50 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-04-27 23:17:50 ----A---- C:\WINDOWS\system32\irclass.dll
2009-04-27 23:17:50 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-04-27 23:17:50 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-04-27 23:17:50 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-04-27 23:17:47 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-04-27 23:17:47 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-04-27 23:17:47 ----A---- C:\WINDOWS\system32\batt.dll
2009-04-27 23:17:46 ----A---- C:\WINDOWS\system32\storprop.dll
2009-04-27 23:17:46 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-04-27 23:17:39 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-04-27 23:17:33 ----RA---- C:\WINDOWS\SET8.tmp
2009-04-27 23:17:30 ----RA---- C:\WINDOWS\SET4.tmp
2009-04-27 23:17:29 ----RA---- C:\WINDOWS\SET3.tmp
2009-04-27 23:17:25 ----D---- C:\WINDOWS\system32\CatRoot2
2009-04-27 23:17:25 ----D---- C:\WINDOWS\system32\CatRoot
2009-04-27 23:17:19 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-04-27 23:17:04 ----A---- C:\WINDOWS\setuplog.txt
2009-04-27 23:17:03 ----A---- C:\DPsFnshr.exe
2009-04-27 23:16:08 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2009-04-27 23:16:08 ----A---- C:\WINDOWS\SkyTel.exe
2009-04-27 23:16:08 ----A---- C:\WINDOWS\RtlUpd.exe
2009-04-27 23:16:08 ----A---- C:\WINDOWS\RTLCPL.EXE
2009-04-27 23:16:07 ----A---- C:\WINDOWS\RtkUpd.exe
2009-04-27 23:16:07 ----A---- C:\WINDOWS\RTHDCPL.EXE
2009-04-27 23:16:07 ----A---- C:\WINDOWS\MicCal.exe
2009-04-27 23:16:06 ----A---- C:\WINDOWS\ALCWZRD.EXE
2009-04-27 23:16:06 ----A---- C:\WINDOWS\ALCMTR.EXE
2009-04-27 23:15:42 ----A---- C:\WINDOWS\system32\ykx32mpcoinst.dll
2009-04-27 23:13:35 ----A---- C:\WINDOWS\system32\Oemdspif.dll
2009-04-27 23:13:30 ----D---- C:\Documents and Settings\BBc04\Application Data\Macromedia
2009-04-27 23:13:30 ----D---- C:\Documents and Settings\BBc04\Application Data\Adobe
2009-04-27 23:13:28 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2009-04-27 23:13:28 ----A---- C:\WINDOWS\system32\ativcoxx.dll
2009-04-27 23:13:28 ----A---- C:\WINDOWS\system32\atitvo32.dll
2009-04-27 23:13:28 ----A---- C:\WINDOWS\system32\atipdlxx.dll
2009-04-27 23:13:28 ----A---- C:\WINDOWS\system32\atiok3x2.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\atioglxx.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\atikvmag.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\atiiiexx.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ATIDEMGX.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ATIDDC.DLL
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\atibrtmon.exe
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\atiadlxx.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati3duag.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\Ati2mdxx.exe
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati2evxx.exe
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati2evxx.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati2edxx.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\amdpcom32.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\amdcalrt.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\Amdcaldd.dll
2009-04-27 23:13:27 ----A---- C:\WINDOWS\system32\amdcalcl.dll
2009-04-27 23:12:57 ----D---- C:\D
2009-04-27 23:12:45 ----SHD---- C:\System Volume Information
2009-04-27 23:12:45 ----D---- C:\Documents and Settings
2009-04-27 23:11:44 ----SH---- C:\boot.ini
2009-04-27 23:08:29 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-04-27 23:08:29 ----RSD---- C:\WINDOWS\Fonts
2009-04-27 23:08:29 ----RD---- C:\WINDOWS\Web
2009-04-27 23:08:29 ----HD---- C:\WINDOWS\inf
2009-04-27 23:08:29 ----D---- C:\WINDOWS\WinSxS
2009-04-27 23:08:29 ----D---- C:\WINDOWS\WBEM
2009-04-27 23:08:29 ----D---- C:\WINDOWS\twain_32
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Temp
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\wins
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\wbem
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\usmt
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\spool
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\ShellExt
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\Setup
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\scripting
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\ras
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\PreInstall
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\oobe
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\npp
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\mui
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\Macromed
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\inetsrv
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\IME
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\icsxml
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\ias
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\export
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\en-US
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\en
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\drivers
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\dhcp
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\config
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\3com_dmi
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\3076
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\2052
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1054
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1042
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1041
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1037
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1033
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1031
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1028
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32\1025
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system32
2009-04-27 23:08:29 ----D---- C:\WINDOWS\system
2009-04-27 23:08:29 ----D---- C:\WINDOWS\SoftwareDistribution
2009-04-27 23:08:29 ----D---- C:\WINDOWS\security
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Resources
2009-04-27 23:08:29 ----D---- C:\WINDOWS\repair
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Provisioning
2009-04-27 23:08:29 ----D---- C:\WINDOWS\PeerNet
2009-04-27 23:08:29 ----D---- C:\WINDOWS\pchealth
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Offline Web Pages
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Network Diagnostic
2009-04-27 23:08:29 ----D---- C:\WINDOWS\mui
2009-04-27 23:08:29 ----D---- C:\WINDOWS\msapps
2009-04-27 23:08:29 ----D---- C:\WINDOWS\msagent
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Media
2009-04-27 23:08:29 ----D---- C:\WINDOWS\L2Schemas
2009-04-27 23:08:29 ----D---- C:\WINDOWS\java
2009-04-27 23:08:29 ----D---- C:\WINDOWS\ime
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Help
2009-04-27 23:08:29 ----D---- C:\WINDOWS\ehome
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Driver Cache
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Debug
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Cursors
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Connection Wizard
2009-04-27 23:08:29 ----D---- C:\WINDOWS\Config
2009-04-27 23:08:29 ----D---- C:\WINDOWS\AppPatch
2009-04-27 23:08:29 ----D---- C:\WINDOWS\addins
2009-04-27 23:08:29 ----D---- C:\WINDOWS
2009-04-27 23:05:32 ----SHD---- C:\RECYCLER
2009-04-27 23:02:19 ----D---- C:\Documents and Settings\BBc04\Application Data\ViSplore
2009-04-27 23:02:16 ----D---- C:\Documents and Settings\BBc04\Application Data\ViStart
2009-04-27 23:02:15 ----D---- C:\Program Files\ViSplore
2009-04-27 23:02:14 ----D---- C:\Documents and Settings\BBc04\Application Data\Styler
2009-04-27 23:02:13 ----D---- C:\WINDOWS\system32\Lang
2009-04-27 23:01:52 ----D---- C:\Documents and Settings\BBc04\Application Data\Identities
2009-04-27 23:01:46 ----HD---- C:\Program Files\Uninstall Information
2009-04-27 23:00:17 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-04-27 23:00:03 ----ASH---- C:\Documents and Settings\BBc04\Application Data\desktop.ini
2009-04-27 23:00:03 ----A---- C:\Documents and Settings\BBc04\Application Data\inst.exe
2009-04-27 22:59:55 ----SD---- C:\Documents and Settings\BBc04\Application Data\Microsoft
2009-04-27 22:59:55 ----D---- C:\Documents and Settings\BBc04\Application Data\Vso
2009-04-27 22:59:55 ----D---- C:\Documents and Settings\BBc04\Application Data\Real
2009-04-27 22:59:55 ----D---- C:\Documents and Settings\BBc04\Application Data\Notepad++
2009-04-27 22:57:12 ----D---- C:\WINDOWS\Prefetch
2009-04-27 22:57:12 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-04-27 22:55:13 ----D---- C:\Program Files\Common Files\Nero
2009-04-27 22:55:01 ----D---- C:\Program Files\Nero 9
2009-04-27 22:54:36 ----A---- C:\WINDOWS\system32\bass.dll
2009-04-27 22:54:33 ----D---- C:\Program Files\CyberWareZ.iNFO & Jcberry526
2009-04-27 22:54:28 ----D---- C:\Program Files\ESAP 3
2009-04-27 22:52:32 ----HDC---- C:\WINDOWS\ie8
2009-04-27 22:52:10 ----D---- C:\Program Files\TsMuxeR
2009-04-27 22:52:10 ----D---- C:\Program Files\Smlabs.Net
2009-04-27 22:52:07 ----D---- C:\Program Files\Universal Extractor
2009-04-27 22:52:05 ----D---- C:\Program Files\UltraISO
2009-04-27 22:52:05 ----D---- C:\Program Files\Common Files\EZB Systems
2009-04-27 22:51:59 ----RD---- C:\Program Files\Skype
2009-04-27 22:51:59 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2009-04-27 22:51:43 ----D---- C:\Program Files\Quizo
2009-04-27 22:51:42 ----D---- C:\Program Files\WinSnap
2009-04-27 22:51:41 ----D---- C:\Program Files\WinRAR
2009-04-27 22:51:34 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-04-27 22:51:32 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-04-27 22:51:18 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-04-27 22:50:54 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-04-27 22:50:37 ----D---- C:\WINDOWS\system32\LogFiles
2009-04-27 22:50:36 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-04-27 22:50:13 ----D---- C:\Program Files\VideoLAN
2009-04-27 22:50:01 ----D---- C:\Documents and Settings\All Users\Application Data\DVD Shrink
2009-04-27 22:50:00 ----D---- C:\Program Files\DVD Shrink
2009-04-27 22:49:51 ----A---- C:\WINDOWS\system32\drv43260.dll
2009-04-27 22:49:51 ----A---- C:\WINDOWS\system32\drv33260.dll
2009-04-27 22:49:51 ----A---- C:\WINDOWS\system32\drv23260.dll
2009-04-27 22:49:51 ----A---- C:\WINDOWS\system32\cook3260.dll
2009-04-27 22:49:51 ----A---- C:\WINDOWS\gdiplus.dll
2009-04-27 22:49:49 ----D---- C:\Program Files\VSO
2009-04-27 22:49:46 ----D---- C:\Program Files\CCleaner
2009-04-27 22:49:43 ----D---- C:\Documents and Settings\All Users\Application Data\CyberLink
2009-04-27 22:49:38 ----D---- C:\Program Files\InstallShield Installation Information
2009-04-27 22:49:38 ----D---- C:\Program Files\Common Files\CyberLink
2009-04-27 22:49:20 ----D---- C:\Program Files\CyberLink
2009-04-27 22:49:08 ----A---- C:\WINDOWS\system32\msxml3a.dll
2009-04-27 22:48:02 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-04-27 22:48:02 ----A---- C:\WINDOWS\system32\pndx5032.dll
2009-04-27 22:48:02 ----A---- C:\WINDOWS\system32\pndx5016.dll
2009-04-27 22:48:02 ----A---- C:\WINDOWS\system32\pncrt.dll
2009-04-27 22:48:01 ----A---- C:\WINDOWS\system32\unrar.dll
2009-04-27 22:48:01 ----A---- C:\WINDOWS\avisplitter.ini
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\yv12vfw.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\xvidcore.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\x264vfw.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\vp7vfw.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\vp6vfw.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\qt-dx331.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\huffyuv.dll
2009-04-27 22:48:00 ----A---- C:\WINDOWS\system32\dpl100.dll
2009-04-27 22:47:59 ----A---- C:\WINDOWS\system32\ff_vfw.dll.manifest
2009-04-27 22:47:59 ----A---- C:\WINDOWS\system32\ff_vfw.dll
2009-04-27 22:47:59 ----A---- C:\WINDOWS\system32\divx.dll
2009-04-27 22:47:58 ----D---- C:\Program Files\K-Lite Codec Pack
2009-04-27 22:47:58 ----D---- C:\Documents and Settings\All Users\Application Data\Real
2009-04-27 22:47:51 ----D---- C:\Program Files\Notepad++
2009-04-27 22:47:49 ----D---- C:\Program Files\Nulled Network Security
2009-04-27 22:47:49 ----D---- C:\Program Files\NNS Genuine!
2009-04-27 22:47:41 ----SD---- C:\WINDOWS\system32\Microsoft
2009-04-27 22:47:02 ----D---- C:\Program Files\Kaspersky Lab
2009-04-27 22:47:02 ----D---- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2009-04-27 22:46:13 ----D---- C:\Program Files\Foxit Reader
2009-04-27 22:43:44 ----D---- C:\WINDOWS\system32\XPSViewer
2009-04-27 22:43:44 ----D---- C:\Program Files\MSBuild
2009-04-27 22:43:41 ----D---- C:\Program Files\Reference Assemblies
2009-04-27 22:43:32 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-04-27 22:41:21 ----RSD---- C:\WINDOWS\assembly
2009-04-27 22:41:21 ----D---- C:\WINDOWS\Microsoft.NET
2009-04-27 22:41:19 ----D---- C:\WINDOWS\system32\URTTemp
2009-04-27 22:41:13 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2009-04-27 22:41:13 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2009-04-27 22:41:07 ----N---- C:\WINDOWS\system32\prntvpt.dll
2009-04-27 22:40:26 ----D---- C:\WINDOWS\system32\Adobe
2009-04-27 22:40:26 ----A---- C:\WINDOWS\system32\msvcr71.dll
2009-04-27 22:40:26 ----A---- C:\WINDOWS\system32\msvcp71.dll
2009-04-27 22:39:53 ----HD---- C:\WINDOWS\$hf_mig$
2009-04-27 22:39:41 ----A---- C:\WINDOWS\control.ini
2009-04-27 22:39:41 ----A---- C:\AUTOEXEC.BAT
2009-04-27 22:39:29 ----A---- C:\WINDOWS\OEWABLog.txt
2009-04-27 22:39:25 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-04-27 22:39:24 ----D---- C:\WINDOWS\system32\dllcache
2009-04-27 22:38:18 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-04-27 22:38:15 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-04-27 22:38:10 ----HD---- C:\Program Files\WindowsUpdate
2009-04-27 22:37:52 ----D---- C:\WINDOWS\system32\DirectX
2009-04-27 22:37:45 ----A---- C:\WINDOWS\system32\atrace.dll
2009-04-27 22:37:43 ----A---- C:\WINDOWS\system32\desktop.ini
2009-04-27 22:37:43 ----A---- C:\WINDOWS\desktop.ini
2009-04-27 22:37:29 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2009-04-27 22:37:28 ----A---- C:\WINDOWS\system32\acctres.dll
2009-04-27 22:37:27 ----D---- C:\Program Files\Common Files\Services
2009-04-27 22:37:25 ----SD---- C:\WINDOWS\Tasks
2009-04-27 22:37:25 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-04-27 22:37:24 ----D---- C:\Program Files\Common Files\MSSoap
2009-04-27 22:37:20 ----D---- C:\WINDOWS\srchasst
2009-04-27 22:37:18 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-04-27 22:37:18 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-04-27 22:37:18 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-04-27 22:37:18 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\wups.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-04-27 22:37:17 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-04-27 22:37:16 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-04-27 22:37:16 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-04-27 22:37:13 ----D---- C:\Program Files\Movie Maker
2009-04-27 22:36:53 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-04-27 22:36:53 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-04-27 22:36:53 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-04-27 22:36:53 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-04-27 22:36:50 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-04-27 22:36:50 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-04-27 22:36:49 ----D---- C:\WINDOWS\system32\Restore
2009-04-27 22:36:49 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-04-27 22:36:49 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-04-27 22:36:49 ----A---- C:\WINDOWS\system32\srclient.dll
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\msconf.dll
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\mnmdd.dll
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2009-04-27 22:36:48 ----A---- C:\WINDOWS\system32\ils.dll
2009-04-27 22:36:45 ----D---- C:\Program Files\NetMeeting
2009-04-27 22:36:45 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-04-27 22:36:45 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-04-27 22:36:44 ----A---- C:\WINDOWS\system32\inetres.dll
2009-04-27 22:36:44 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-04-27 22:36:42 ----D---- C:\Program Files\Outlook Express
2009-04-27 22:36:42 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-04-27 22:36:42 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-04-27 22:36:42 ----A---- C:\WINDOWS\system32\mstask.dll
2009-04-27 22:36:41 ----A---- C:\WINDOWS\system32\isign32.dll
2009-04-27 22:36:41 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-04-27 22:36:41 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-04-27 22:36:41 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-04-27 22:36:35 ----D---- C:\Program Files\Common Files\System
2009-04-27 22:36:33 ----D---- C:\Program Files\Internet Explorer
2009-04-27 22:35:55 ----D---- C:\Program Files\ComPlus Applications
2009-04-27 22:35:53 ----A---- C:\WINDOWS\vbaddin.ini
2009-04-27 22:35:53 ----A---- C:\WINDOWS\vb.ini
2009-04-27 22:35:49 ----D---- C:\WINDOWS\Registration
2009-04-27 22:35:42 ----D---- C:\Program Files\Online Services
2009-04-27 22:35:30 ----D---- C:\Program Files\CPU-Z
2009-04-27 22:35:24 ----D---- C:\Program Files\Windows Media Connect 2
2009-04-27 22:35:23 ----D---- C:\Program Files\Windows Media Player
2009-04-27 22:35:22 ----D---- C:\Program Files\Messenger
2009-04-27 22:35:19 ----D---- C:\Program Files\MSN Gaming Zone
2009-04-27 22:35:19 ----A---- C:\WINDOWS\system32\write.exe
2009-04-27 22:35:10 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-04-27 22:35:10 ----A---- C:\WINDOWS\system32\hticons.dll
2009-04-27 22:35:09 ----A---- C:\WINDOWS\system32\winchat.exe
2009-04-27 22:35:09 ----A---- C:\WINDOWS\system32\avwav.dll
2009-04-27 22:35:09 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-04-27 22:35:09 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-04-27 22:35:02 ----A---- C:\WINDOWS\system32\getuname.dll
2009-04-27 22:35:01 ----A---- C:\WINDOWS\system32\winmine.exe
2009-04-27 22:35:01 ----A---- C:\WINDOWS\system32\sol.exe
2009-04-27 22:35:01 ----A---- C:\WINDOWS\system32\charmap.exe
2009-04-27 22:35:01 ----A---- C:\WINDOWS\system32\calc.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\tskill.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\tscon.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\reset.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\mshearts.exe
2009-04-27 22:35:00 ----A---- C:\WINDOWS\system32\freecell.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\shadow.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\regini.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\msg.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\logoff.exe
2009-04-27 22:34:59 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-04-27 22:34:53 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-04-27 22:34:45 ----D---- C:\Program Files\MSN
2009-04-27 22:34:45 ----A---- C:\WINDOWS\system32\sndrec32.exe
2009-04-27 22:34:45 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-04-27 22:34:44 ----D---- C:\Program Files\Windows NT
2009-04-27 22:34:44 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-04-27 22:34:44 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-04-27 22:34:44 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-04-27 22:34:43 ----A---- C:\WINDOWS\system32\spider.exe
2009-04-27 22:34:43 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-04-27 22:34:42 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-04-27 22:34:42 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-04-27 22:34:42 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-04-27 22:34:42 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-04-27 22:34:41 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-04-27 22:34:40 ----D---- C:\WINDOWS\system32\MsDtc
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-04-27 22:34:40 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-04-27 22:34:39 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-04-27 22:34:38 ----D---- C:\WINDOWS\system32\Com
2009-04-27 22:34:38 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-04-27 22:34:38 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-04-27 22:34:38 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-04-27 22:34:38 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-04-27 22:34:38 ----A---- C:\WINDOWS\system32\colbact.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\stclient.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-04-27 22:34:37 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-04-27 22:34:36 ----A---- C:\WINDOWS\system32\comuid.dll
2009-04-27 22:34:36 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-04-27 22:34:36 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-04-27 22:34:36 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-04-27 22:34:31 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-04-27 22:34:30 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-04-27 22:34:30 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-04-27 22:34:30 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-03-30 19:16:12 ----A---- C:\WINDOWS\system32\syssetup.dll
2009-03-29 17:29:42 ----A---- C:\WINDOWS\system32\msgina.dll
2009-03-29 17:08:16 ----A---- C:\WINDOWS\system32\logonui.exe
======List of files/folders modified in the last 1 months======
2009-04-28 00:02:00 ----A---- C:\WINDOWS\system.ini
2009-04-27 22:49:04 ----A---- C:\WINDOWS\system32\msxml3r.dll
2009-04-27 22:39:39 ----A---- C:\WINDOWS\win.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2006-06-19 36864]
R1 ISODrive;ISO DVD/CD-ROM Device Driver; \??\C:\Program Files\UltraISO\drivers\ISODrive.sys []
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 KLIF;Kaspersky Lab Driver; C:\WINDOWS\system32\DRIVERS\klif.sys [2009-04-27 213520]
R2 {FE4C91E7-22C2-4D0C-9F6B-82F1B7742054};{FE4C91E7-22C2-4D0C-9F6B-82F1B7742054}; \??\C:\Program Files\CyberLink\PowerDVD8\000.fcl []
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2009-01-08 62848]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2009-01-08 60800]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-12-01 3452928]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-13 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-04-17 4707328]
R3 KLFLTDEV;Kaspersky Lab KLFltDev; C:\WINDOWS\system32\DRIVERS\klfltdev.sys [2008-03-13 26640]
R3 klim5;Kaspersky Anti-Virus NDIS Filter; C:\WINDOWS\system32\DRIVERS\klim5.sys [2008-04-30 24592]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2009-01-08 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2009-01-08 61824]
R3 pcouffin;VSO Software pcouffin; C:\WINDOWS\System32\Drivers\pcouffin.sys [2009-04-27 47360]
R3 RTHDMIAzAudService;Service for HDMI; C:\WINDOWS\system32\drivers\RtHDMI.sys [2007-05-14 3526464]
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2009-01-08 30336]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2009-01-08 17152]
R3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 yukonwxp;NDIS5.1 Miniport Driver for Marvell Yukon Ethernet Controller; C:\WINDOWS\system32\DRIVERS\yk51x86.sys [2008-12-09 296448]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2009-01-08 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2009-01-08 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2008-12-01 598016]
R2 AVP;Kaspersky Internet Security; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 2009\avp.exe [2009-04-27 206088]
R3 usnjsvc;Service Messenger Sharing Folders USN Journal Reader; C:\Program Files\Windows Live\Messenger\usnsvc.exe [2007-10-18 98328]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-30 46104]
S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-30 881664]
S3 WLSetupSvc;Windows Live Setup Service; C:\Program Files\Windows Live\installer\WLSetupSvc.exe [2007-10-25 266240]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\wmpnetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-30 132096]
-----------------EOF-----------------
voila pour le log.txt
et voila pour le info.txt
info.txt logfile of random's system information tool 1.06 2009-04-28 15:56:44
======Uninstall list======
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
7Start 3.0.2-->C:\Program Files\CyberWareZ.iNFO & Jcberry526\7Start\Uninstall.exe
Adobe Flash Player 10 ActiveX-->C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Flash Player 10 Plugin-->C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Shockwave Player 11-->C:\WINDOWS\system32\adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\system32\Adobe\SHOCKW~1\Install.log
Aspell French Dictionary-0.50-3-->"C:\Program Files\Aspell\unins000.exe"
ATI Display Driver-->rundll32 C:\WINDOWS\system32\atiiiexx.dll,_InfEngUnInstallINFFile_RunDLL@16 -force_restart -flags:0x2010001 -inf_class:DISPLAY -clean
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
ConvertXtoDVD 3.1.3.40-->"C:\Program Files\VSO\ConvertX\3\unins000.exe"
CPU-Z 1.48-->rundll32.exe advpack.dll,LaunchINFSection Cpuz.inf,UnInstall
CyberLink PowerDVD 8-->"C:\Program Files\InstallShield Installation Information\{2BF2E31F-B8BB-40A7-B650-98D28E0F7D47}\setup.exe" /z-uninstall
DVD Shrink 3.2-->"C:\Program Files\DVD Shrink\unins000.exe"
Extreme Seven Addon Pack 4.04-->C:\Program Files\CyberWareZ.iNFO & Jcberry526\Extreme Seven Addon Pack\Uninstall.exe
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\WINDOWS\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
Kaspersky Internet Security 2009-->MsiExec.exe /I{8CB14A64-CEF4-4C8F-B1C8-1C3B8752CB55}
K-Lite Mega Codec Pack 4.3.1-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Microsoft .NET Framework 1.1-->msiexec.exe /X {CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 1.1-->MsiExec.exe /X{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}
Microsoft .NET Framework 2.0 Service Pack 2-->MsiExec.exe /I{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}
Microsoft .NET Framework 3.0 Service Pack 2-->MsiExec.exe /I{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}
Microsoft .NET Framework 3.5 SP1-->c:\WINDOWS\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Nero 9.0.9.4 Lite-->"C:\Program Files\Nero 9\unins000.exe"
NNS Genuine! 2.5-->C:\Program Files\Nulled Network Security\NNS Genuine!\Uninstall.exe
Notepad++-->C:\Program Files\Notepad++\uninstall.exe
Opera 9.64-->MsiExec.exe /X{E1BBBAC5-2857-4155-82A6-54492CE88620}
Realtek High Definition Audio Driver-->RtkUpd.exe -r -m
Skype™ 4.0-->MsiExec.exe /X{24D753CA-6AE9-4E30-8F5F-EFC93E08BF3D}
TsMuxeR 1.84-->C:\Program Files\Smlabs.Net\TsMuxeR\Uninstall.exe
UltraISO Premium V9.33-->"C:\Program Files\UltraISO\unins000.exe"
Universal Extractor 1.6-->"C:\Program Files\Universal Extractor\unins000.exe"
ViSplore-->C:\Program Files\ViSplore\KillMe.exe
VLC media player 0.9.2-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Internet Explorer 8-->"C:\WINDOWS\ie8\spuninst\spuninst.exe"
Windows Live installer-->MsiExec.exe /X{FD44E544-E7D0-4DBA-9FA0-8AE1A1300390}
Windows Live Messenger-->MsiExec.exe /X{BADF6744-3787-48F6-B8C9-4C4995401D65}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WinSnap-->C:\Program Files\WinSnap\uninst.exe
======Security center information======
AV: Kaspersky Internet Security
FW: Kaspersky Internet Security
======System event log======
Computer Name: GHOSTBBC04
Event Code: 10005
Message: DCOM got error "%1083" attempting to start the service wuauserv with arguments ""
in order to run the server:
{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
Record Number: 32
Source Name: DCOM
Time Written: 20090427225220.000000+060
Event Type: error
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 10005
Message: DCOM got error "%1083" attempting to start the service wuauserv with arguments ""
in order to run the server:
{9B1F122C-2982-4E91-AA8B-E071D54F2A4D}
Record Number: 31
Source Name: DCOM
Time Written: 20090427225218.000000+060
Event Type: error
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 20
Message: Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.
Record Number: 14
Source Name: Print
Time Written: 20090427224334.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 20
Message: Printer Driver Microsoft XPS Document Writer for Windows NT x86 Version-3 was added or updated. Files:- mxdwdrv.dll, unidrvui.dll, mxdwdui.gpd, unidrv.hlp, mxdwdui.dll, mxdwdui.ini, stddtype.gdl, stdnames.gpd, stdschem.gdl, stdschmx.gdl, unidrv.dll, unires.dll, XpsSvcs.dll.
Record Number: 13
Source Name: Print
Time Written: 20090427224333.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: MACHINENAME
Event Code: 15
Message:
Record Number: 3
Source Name: ahci6xx
Time Written: 20090427231302.000000+060
Event Type: error
User:
=====Application event log=====
Computer Name: GHOSTBBC04
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 15
Source Name: WinMgmt
Time Written: 20090427223619.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 5603
Message: A provider, Rsop Planning Mode Provider, has been registered in the WMI namespace, root\RSOP, but did not specify the HostingModel property. This provider will be run using the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests. Ensure that provider has been reviewed for security behavior and update the HostingModel property of the provider registration to an account with the least privileges possible for the required functionality.
Record Number: 14
Source Name: WinMgmt
Time Written: 20090427223619.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 13
Source Name: WinMgmt
Time Written: 20090427223619.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 63
Message: A provider, CmdTriggerConsumer, has been registered in the WMI namespace, Root\cimv2, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 12
Source Name: WinMgmt
Time Written: 20090427223619.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
Computer Name: GHOSTBBC04
Event Code: 63
Message: A provider, HiPerfCooker_v1, has been registered in the WMI namespace, Root\WMI, to use the LocalSystem account. This account is privileged and the provider may cause a security violation if it does not correctly impersonate user requests.
Record Number: 11
Source Name: WinMgmt
Time Written: 20090427223617.000000+060
Event Type: warning
User: NT AUTHORITY\SYSTEM
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;C:\Program Files\Universal Extractor;C:\Program Files\Universal Extractor\bin
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 107 Stepping 1, AuthenticAMD
"PROCESSOR_REVISION"=6b01
"NUMBER_OF_PROCESSORS"=2
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
-----------------EOF-----------------