Logfile of random's system information tool 1.06 (written by random/random)
Run by Gitem at 2009-11-15 12:29:02
Microsoft® Windows Vista™ Édition Familiale Premium Service Pack 1
System drive C: has 78 GB (65%) free of 119 GB
Total RAM: 2814 MB (57% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:29:06, on 15/11/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18319)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe
C:\Program Files\ATK Hotkey\HControlUser.exe
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\SmartLogon\sensorsrv.exe
C:\Program Files\ATKOSD2\ATKOSD2.exe
C:\Windows\System32\rundll32.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Windows\AsScrPro.exe
C:\Program Files\ASUS\ASUS Live Update\ALU.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Free Download Manager\fdm.exe
C:\Program Files\Software Informer\softinfo.exe
C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\system32\wuauclt.exe
C:\Windows\system32\conime.exe
C:\Windows\Explorer.EXE
C:\Users\Gitem\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Gitem\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Gitem\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Gitem\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Gitem\Documents\Downloads\RSIT.exe
C:\Program Files\trend micro\Gitem.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cooxer.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Aide pour le lien d'Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Programme d'aide de l'Assistant de connexion Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [P2Go_Menu] "C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [HControlUser] "C:\Program Files\ATK Hotkey\HcontrolUser.exe"
O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden
O4 - HKCU\..\Run: [Google Update] "C:\Users\Gitem\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Free Download Manager] "C:\Program Files\Free Download Manager\fdm.exe" -autorun
O4 - HKCU\..\Run: [Software Informer] "C:\Program Files\Software Informer\softinfo.exe" -autorun
O4 - HKCU\..\Run: [AutoStartNPSAgent] C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVICE LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVICE RÉSEAU')
O4 - HKUS\S-1-5-18\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe (User 'Default user')
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Tout télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Télécharger avec Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: Télécharger la sélection avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Télécharger la vidéo avec Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Service Bonjour (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: FsUsbExService - Teruten - C:\Windows\system32\FsUsbExService.Exe
O23 - Service: Service Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Service de l’iPod (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe
End of file - 9276 bytes
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2160623534-1964146674-4074589558-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2160623534-1964146674-4074589558-1000UA.job
C:\Windows\tasks\User_Feed_Synchronization-{66CF1926-44AB-4733-A9D7-5839006ED91E}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Aide pour le lien d'Adobe PDF Reader - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Programme d'aide de l'Assistant de connexion Windows Live - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{CC59E0F9-7E43-44FA-9FAA-8377850BF205}]
FDMIECookiesBHO Class - C:\Program Files\Free Download Manager\iefdm2.dll [2008-12-30 98304]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-04 41760]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"CLMLServer"=C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [2008-07-19 104936]
"P2Go_Menu"=C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [2008-06-14 210216]
"HControlUser"=C:\Program Files\ATK Hotkey\HcontrolUser.exe [2008-01-12 98304]
"ATKOSD2"=C:\Program Files\ATKOSD2\ATKOSD2.exe [2008-01-23 7766016]
"NvCplDaemon"=C:\Windows\system32\NvCpl.dll [2008-07-25 13548064]
"NvMediaCenter"=C:\Windows\system32\NvMcTray.dll [2008-07-25 92704]
"RtHDVCpl"=C:\Windows\RtHDVCpl.exe [2008-08-12 6265376]
"SynTPStart"=C:\Program Files\Synaptics\SynTP\SynTPStart.exe [2007-08-17 102400]
"ASUS Screen Saver Protector"=C:\Windows\AsScrPro.exe [2008-10-03 3054136]
"ASUS Camera ScreenSaver"=C:\Windows\AsScrProlog.exe [2008-10-03 47672]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-10-15 39792]
"Kernel and Hardware Abstraction Layer"=C:\Windows\KHALMNPR.EXE [2007-04-11 56080]
"QuickTime Task"=C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-10-04 149280]
"iTunesHelper"=C:\Program Files\iTunes\iTunesHelper.exe [2009-10-28 141600]
"NPSStartup"= []
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2009-09-15 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-01-21 1233920]
"LightScribe Control Panel"=C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe [2008-06-09 2363392]
"Google Update"=C:\Users\Gitem\AppData\Local\Google\Update\GoogleUpdate.exe [2009-05-15 133104]
"msnmsgr"=C:\Program Files\Windows Live\Messenger\msnmsgr.exe [2009-07-26 3883856]
"Free Download Manager"=C:\Program Files\Free Download Manager\fdm.exe [2009-01-31 3399727]
"Software Informer"=C:\Program Files\Software Informer\softinfo.exe [2009-09-17 1933381]
"fsm"= []
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-08-27 106904]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup
Logitech Desktop Messenger.lnk - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2009-11-15 12:29:02 ----D---- C:\rsit
2009-11-15 11:16:59 ----D---- C:\GenProc
2009-11-14 23:29:17 ----D---- C:\Users\Gitem\AppData\Roaming\Malwarebytes
2009-11-14 23:29:12 ----D---- C:\ProgramData\Malwarebytes
2009-11-14 23:29:11 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-11-14 23:04:31 ----A---- C:\cleannavi.txt
2009-11-14 23:04:12 ----D---- C:\Program Files\Navilog1
2009-11-14 22:41:36 ----D---- C:\Program Files\Trend Micro
2009-11-14 12:14:17 ----A---- C:\Windows\system32\aswBoot.exe
2009-11-11 15:54:55 ----A---- C:\Windows\system32\WSDApi.dll
2009-11-08 12:27:04 ----D---- C:\Users\Gitem\AppData\Roaming\PC Suite
2009-11-08 12:27:04 ----D---- C:\ProgramData\PC Suite
2009-11-08 12:26:17 ----A---- C:\Windows\system32\DIFxAPI.dll
2009-11-08 12:26:10 ----A---- C:\Windows\system32\nmwcdcls.dll
2009-11-08 12:24:16 ----D---- C:\Windows\system32\Samsung_USB_Drivers
2009-11-08 12:24:15 ----D---- C:\Program Files\DIFX
2009-11-08 12:23:42 ----A---- C:\Windows\system32\FsUsbExService.Exe
2009-11-08 12:23:42 ----A---- C:\Windows\system32\FsUsbExDevice.Dll
2009-11-08 12:23:35 ----D---- C:\Users\Gitem\AppData\Roaming\Samsung
2009-11-08 12:22:38 ----D---- C:\Program Files\MarkAny
2009-11-08 12:22:36 ----D---- C:\Program Files\PC Connectivity Solution
2009-11-08 12:21:57 ----D---- C:\Program Files\Samsung
2009-11-08 12:07:58 ----SHD---- C:\found.000
2009-11-04 13:39:30 ----A---- C:\Windows\ntbtlog.txt
2009-11-04 11:02:58 ----A---- C:\Windows\system32\mshtml.dll
2009-10-31 11:27:24 ----D---- C:\ProgramData\Pinnacle
2009-10-30 23:27:50 ----D---- C:\Program Files\Movie Maker 2.6
2009-10-30 22:32:19 ----D---- C:\ProgramData\AVS4YOU
2009-10-30 22:32:05 ----D---- C:\Users\Gitem\AppData\Roaming\AVS4YOU
2009-10-30 22:30:38 ----D---- C:\Program Files\Common Files\AVSMedia
2009-10-30 22:30:34 ----D---- C:\Program Files\AVS4YOU
2009-10-30 22:30:34 ----A---- C:\Windows\system32\msxml3a.dll
2009-10-30 22:30:34 ----A---- C:\Windows\system32\msvcr70.dll
2009-10-30 22:30:34 ----A---- C:\Windows\system32\msvcp70.dll
2009-10-30 22:30:34 ----A---- C:\Windows\system32\mfc70.dll
2009-10-30 22:30:34 ----A---- C:\Windows\system32\GdiPlus.dll
2009-10-30 22:24:52 ----D---- C:\Program Files\AIST
2009-10-30 16:54:41 ----D---- C:\Program Files\iPod
2009-10-30 16:54:37 ----D---- C:\Program Files\iTunes
2009-10-30 16:39:45 ----A---- C:\Windows\system32\wups2.dll
2009-10-30 16:39:45 ----A---- C:\Windows\system32\wucltux.dll
2009-10-30 16:39:45 ----A---- C:\Windows\system32\wuaueng.dll
2009-10-30 16:39:45 ----A---- C:\Windows\system32\wuauclt.exe
2009-10-30 16:39:09 ----A---- C:\Windows\system32\wups.dll
2009-10-30 16:39:09 ----A---- C:\Windows\system32\wudriver.dll
2009-10-30 16:39:09 ----A---- C:\Windows\system32\wuapi.dll
2009-10-30 16:38:52 ----A---- C:\Windows\system32\wuwebv.dll
2009-10-30 16:38:52 ----A---- C:\Windows\system32\wuapp.exe
2009-10-28 18:19:35 ----A---- C:\Windows\system32\wmp.dll
2009-10-28 18:19:34 ----A---- C:\Windows\system32\unregmp2.exe
2009-10-28 18:19:30 ----A---- C:\Windows\system32\wmploc.DLL
2009-10-28 13:16:27 ----D---- C:\Users\Gitem\AppData\Roaming\Yahoo!
2009-10-27 21:44:22 ----D---- C:\ProgramData\Norton
2009-10-27 21:44:20 ----D---- C:\ProgramData\NortonInstaller
2009-10-27 14:00:08 ----D---- C:\Windows\system32\Adobe
2009-10-25 11:35:53 ----D---- C:\Program Files\Crux Calculator v5
2009-10-25 11:32:38 ----D---- C:\ProgramData\WinZip
2009-10-25 11:32:34 ----D---- C:\Program Files\WinZip
2009-10-16 19:06:54 ----A---- C:\Windows\system32\msv1_0.dll
2009-10-16 19:06:40 ----A---- C:\Windows\system32\occache.dll
2009-10-16 19:06:39 ----A---- C:\Windows\system32\wininet.dll
2009-10-16 19:06:38 ----A---- C:\Windows\system32\urlmon.dll
2009-10-16 19:06:37 ----A---- C:\Windows\system32\ieframe.dll
2009-10-16 19:06:34 ----A---- C:\Windows\system32\iertutil.dll
2009-10-16 19:06:34 ----A---- C:\Windows\system32\ieapfltr.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\mstime.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\msfeeds.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\jsproxy.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\ieUnatt.exe
2009-10-16 19:06:33 ----A---- C:\Windows\system32\ieencode.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\iedkcs32.dll
2009-10-16 19:06:33 ----A---- C:\Windows\system32\ieaksie.dll
2009-10-16 19:06:16 ----A---- C:\Windows\system32\ntkrnlpa.exe
2009-10-16 19:06:15 ----A---- C:\Windows\system32\ntoskrnl.exe
2009-10-16 19:05:52 ----A---- C:\Windows\system32\EncDec.dll
2009-10-16 19:05:50 ----A---- C:\Windows\system32\psisdecd.dll
2009-10-16 19:04:43 ----A---- C:\Windows\system32\msasn1.dll
2009-10-16 19:04:31 ----A---- C:\Windows\system32\WMSPDMOD.DLL
======List of files/folders modified in the last 1 months======
2009-11-15 12:29:05 ----D---- C:\Windows\Temp
2009-11-15 12:26:40 ----D---- C:\Users\Gitem\AppData\Roaming\Free Download Manager
2009-11-15 10:29:08 ----SHD---- C:\Windows\Installer
2009-11-15 10:28:50 ----HD---- C:\ProgramData
2009-11-15 10:28:32 ----D---- C:\Windows\winsxs
2009-11-15 10:28:29 ----RD---- C:\Program Files
2009-11-15 10:28:29 ----D---- C:\Program Files\Common Files
2009-11-15 10:28:19 ----RSD---- C:\Windows\Fonts
2009-11-15 10:28:01 ----D---- C:\Windows\System32
2009-11-15 10:23:47 ----SHD---- C:\System Volume Information
2009-11-15 10:20:30 ----D---- C:\Users\Gitem\AppData\Roaming\Software Informer
2009-11-14 23:33:31 ----A---- C:\Windows\system32\acovcnt.exe
2009-11-14 23:29:13 ----D---- C:\Windows\system32\drivers
2009-11-14 23:09:02 ----D---- C:\Windows\Prefetch
2009-11-14 12:52:29 ----D---- C:\Windows\inf
2009-11-14 12:52:29 ----A---- C:\Windows\system32\PerfStringBackup.INI
2009-11-14 11:55:32 ----D---- C:\Users\Gitem\AppData\Roaming\LimeWire
2009-11-13 21:43:52 ----D---- C:\Windows\system32\catroot2
2009-11-12 07:43:20 ----D---- C:\Windows\system32\catroot
2009-11-12 07:37:18 ----D---- C:\Program Files\Windows Mail
2009-11-12 07:34:59 ----D---- C:\ProgramData\Microsoft Help
2009-11-11 14:23:32 ----D---- C:\Downloads
2009-11-10 11:23:45 ----D---- C:\Users\Gitem\AppData\Roaming\dvdcss
2009-11-08 15:21:00 ----D---- C:\Windows
2009-11-08 12:26:05 ----DC---- C:\Windows\system32\DRVSTORE
2009-11-08 12:23:12 ----HD---- C:\Program Files\InstallShield Installation Information
2009-11-05 18:36:21 ----A---- C:\Windows\system32\mrt.exe
2009-11-04 17:13:10 ----D---- C:\Program Files\LimeWire
2009-11-04 12:13:40 ----D---- C:\Windows\rescache
2009-11-04 11:57:00 ----D---- C:\Windows\system32\fr-FR
2009-11-02 20:42:06 ----N---- C:\Windows\system32\MpSigStub.exe
2009-11-01 20:59:28 ----D---- C:\Program Files\Yahoo!
2009-11-01 20:59:17 ----D---- C:\Program Files\Logitech
2009-11-01 20:59:13 ----SD---- C:\Users\Gitem\AppData\Roaming\Microsoft
2009-10-31 23:14:42 ----D---- C:\Windows\Tasks
2009-10-30 23:26:33 ----D---- C:\Windows\system32\Tasks
2009-10-30 18:00:44 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-10-30 16:54:39 ----D---- C:\Program Files\Common Files\Apple
2009-10-29 10:33:22 ----D---- C:\Program Files\Windows Media Player
2009-10-27 21:44:22 ----D---- C:\ProgramData\Symantec
2009-10-27 14:00:50 ----D---- C:\Windows\system32\Macromed
2009-10-25 14:28:16 ----D---- C:\Program Files\SeekService
2009-10-25 12:21:06 ----D---- C:\Windows\system32\config
2009-10-25 12:20:50 ----D---- C:\Windows\system32\spool
2009-10-25 12:20:50 ----D---- C:\Windows\system32\CodeIntegrity
2009-10-25 12:20:49 ----D---- C:\Users\Gitem\AppData\Roaming\vlc
2009-10-25 12:20:48 ----D---- C:\ProgramData\P4G
2009-10-25 12:20:47 ----D---- C:\Windows\registration
2009-10-25 12:09:50 ----D---- C:\ProgramData\SeekService
2009-10-25 12:05:47 ----D---- C:\Windows\system32\Msdtc
2009-10-25 11:22:00 ----D---- C:\Windows\system32\wbem
2009-10-17 09:38:46 ----D---- C:\Windows\Microsoft.NET
2009-10-17 09:38:27 ----RSD---- C:\Windows\assembly
2009-10-17 07:53:49 ----D---- C:\Program Files\Internet Explorer
2009-10-17 07:53:44 ----D---- C:\Windows\ehome
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2009-09-15 23152]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2009-09-15 114768]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2009-09-15 52368]
R2 ASMMAP;ASMMAP; \??\C:\Program Files\ATKGFNEX\ASMMAP.sys [2007-07-24 13880]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2009-09-15 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2009-09-15 53328]
R2 ghaio;ghaio; \??\C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [2007-08-03 20936]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-04-06 908800]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [2008-01-21 14208]
R3 CRFILTER;USB Mass Storage Filter; C:\Windows\system32\DRIVERS\CRFILTER.sys [2008-04-07 6656]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-08-24 36608]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys [2009-05-18 26600]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2008-08-12 2159384]
R3 kbfiltr;Keyboard Filter; C:\Windows\system32\DRIVERS\kbfiltr.sys [2008-06-03 15928]
R3 LHidFilt;Logitech SetPoint KMDF HID Filter Driver; C:\Windows\system32\DRIVERS\LHidFilt.Sys [2007-04-11 34832]
R3 LMouFilt;Logitech SetPoint KMDF Mouse Filter Driver; C:\Windows\system32\DRIVERS\LMouFilt.Sys [2007-04-11 36112]
R3 MTsensor;ATK0100 ACPI UTILITY; C:\Windows\system32\DRIVERS\ATKACPI.sys [2006-12-14 7680]
R3 NVENETFD;NVIDIA nForce 10/100/1000 Mbps Ethernet ; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2008-07-08 1050656]
R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda32v.sys [2008-06-25 44064]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2008-07-25 7547552]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2008-07-22 15872]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2008-04-01 1807744]
R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [2007-08-17 190512]
R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [2008-01-21 11264]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 BthEnum;Pilote de bloc de demande Bluetooth; C:\Windows\system32\DRIVERS\BthEnum.sys [2008-01-21 19456]
S3 BthPan;Périphérique Bluetooth (réseau personnel); C:\Windows\system32\DRIVERS\bthpan.sys [2008-01-21 92160]
S3 BTHPORT;Pilote de port Bluetooth; C:\Windows\System32\Drivers\BTHport.sys [2008-04-29 220160]
S3 BTHUSB;Pilote USB radio Bluetooth; C:\Windows\System32\Drivers\BTHUSB.sys [2008-04-29 29184]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 EverestDriver;Lavalys EVEREST Kernel Driver; \??\C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt []
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\Windows\system32\drivers\mbamswissarmy.sys [2009-09-10 38224]
S3 mbr;mbr; \??\C:\Users\Gitem\AppData\Local\Temp\mbr.sys []
S3 mod7700;DiBcom DIB7700 based TV tuner device; C:\Windows\System32\Drivers\dvb7700all.sys [2007-07-02 466176]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 RFCOMM;Périphérique Bluetooth (TDI protocole RFCOMM); C:\Windows\system32\DRIVERS\rfcomm.sys [2008-01-21 49664]
S3 smserial;smserial; C:\Windows\system32\DRIVERS\smserial.sys [2006-11-02 1010560]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [2008-01-21 134016]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-21 39936]
S3 yukonwlh;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller; C:\Windows\system32\DRIVERS\yk60x86.sys [2006-11-02 194048]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
S4 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2008-01-21 88576]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-05-29 144712]
R2 ASLDRService;ASLDR Service; C:\Program Files\ATK Hotkey\ASLDRSrv.exe [2007-10-03 94208]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2009-09-15 18752]
R2 ATKGFNEXSrv;ATKGFNEX Service; C:\Program Files\ATKGFNEX\GFNEXSrv.exe [2007-08-08 94208]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2009-09-15 138680]
R2 Bonjour Service;Service Bonjour; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
R2 BthServ;@%SystemRoot%\System32\bthserv.dll,-101; C:\Windows\system32\svchost.exe [2008-01-21 21504]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-08-27 237984]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2008-06-09 73728]
R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2008-07-25 196608]
R2 spmgr;spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [2007-08-03 125496]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2009-09-15 254040]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2009-09-15 352920]
R3 iPod Service;Service de l’iPod; C:\Program Files\iPod\bin\iPodService.exe [2009-10-28 545568]
S2 gupdate;Service Google Update (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-09-20 133104]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-27 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
-----------------EOF-----------------