Options
msn problem
my msn is sending messages to my contacts whether I am online or not and whether I am log on MSN or not, also it is doing it from every computer I log on
I have formatted my computer and it didn't resolve a problem, so I don't know what to do
please help
thanx
here is my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:09:58, on 15.12.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WinFast\WFTVFM\WFTV.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Host Services (SVCHOSTS32) - Unknown owner - C:\WINDOWS\system\svchost.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VMwareService - Unknown owner - C:\WINDOWS\system\VMwareService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINDOWS\system32\csrsc.exe (file missing)
--
End of file - 6669 bytes
I have formatted my computer and it didn't resolve a problem, so I don't know what to do
please help
thanx
here is my hijackthis log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 22:09:58, on 15.12.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\WinFast\WFTVFM\WFTV.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Host Services (SVCHOSTS32) - Unknown owner - C:\WINDOWS\system\svchost.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VMwareService - Unknown owner - C:\WINDOWS\system\VMwareService.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINDOWS\system32\csrsc.exe (file missing)
--
End of file - 6669 bytes
0
Comments
Step 1:
Please download tools to your desktop:
Step 2:
Run Malwarebytes' Anti-Malware
Reboot your computer after the scan!
Step 3:
Run Random's System Iformation Tool
Database version: 1528
Windows 5.1.2600 Service Pack 2
21.12.2008 23:39:14
mbam-log-2008-12-21 (23-39-14).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 105561
Time elapsed: 47 minute(s), 44 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Program Files\WinRAR\Patch [ WinRAR 3.60 Beta 4 ].exe (Trojan.Downloader) -> Quarantined and deleted successfully.
======Uninstall list======
-->MsiExec.exe /X{E9F81423-211E-46B6-9AE0-38568BC5CF6F}
-->C:\Program Files\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL
-->C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL
-->C:\WINDOWS\UNRecode.exe /UNINSTALL
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{9D5DFD1A-5B25-48B7-B4D5-E04778BDC676}\Setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
ACDSee Pro-->MsiExec.exe /I{F99F74B4-972B-4B06-B893-6B3B0DB0128B}
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe Reader 7.0.7-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70700000002}
Athlon 64 Processor Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C151CE54-E7EA-4804-854B-F515368B0798}\setup.exe" -l0x9
AVG Free 8.0-->C:\Program Files\AVG\AVG8\setup.exe /UNINSTALL
BSPlayer-->"C:\Program Files\Webteh\BSplayerPro\uninstall.exe"
CIF USB Camera (2110A)-->C:\WINDOWS\CleanDev.exe C:\WINDOWS\DC2110a.ini
ffdshow-->"C:\Program Files\ffdshow\uninstall.exe"
Google Talk Plugin-->MsiExec.exe /I{DFB48451-4F78-33DC-BC42-8C403C74939F}
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java(TM) 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Malwarebytes' Anti-Malware-->"C:\Program Files\Malwarebytes' Anti-Malware\unins000.exe"
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0.0 (Pre-Release 5348)-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Mozilla Firefox (3.0.5)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
Nero 7 Ultra Edition-->MsiExec.exe /I{F14B8ECC-BDA0-4987-9201-D7B7DBE11033}
Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" -l0x9 -removeonly
Scientific-Atlanta WebSTAR 2000 series Cable Modem-->UNDPX2A.EXE
Skypeâ„¢ 3.8-->MsiExec.exe /X{5C82DAE5-6EB0-4374-9254-BE3319BA4E82}
SpeedSim-->C:\Program Files\SpeedSim\uninst.exe
Subtitle Workshop 2.51-->"C:\Program Files\URUSoft\Subtitle Workshop\uninstall.exe"
Total Commander (Remove or Repair)-->C:\Program Files\totalcmd\tcuninst.exe
VC 9.0 Runtime-->MsiExec.exe /I{A040AC77-C1AA-4CC9-8931-9F648AF178F6}
Winamp-->"C:\Program Files\Winamp\UninstWA.exe"
Windows Live Messenger-->MsiExec.exe /I{571700F0-DB9D-4B3A-B03D-35A14BB5939F}
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
WinFast Entertainment Center-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BE4AA694-815A-4045-BD49-C94F2BED7458}\setup.exe"
WinFast PVR-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{C882DE6B-1482-42D6-A7C2-A9F946EDBAF6}\setup.exe"
WinFast(R) Display Driver-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F69FD33C-8815-46BF-9134-A643DE68F3C0}\setup.exe" -l0x1a -removeonly
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Wisdom-soft ScreenHunter 5.0 Free-->C:\PROGRA~1\WISDOM~1\UNWISE.EXE C:\PROGRA~1\WISDOM~1\INSTALL.LOG
YouTube Movie Ripper-->C:\WINDOWS\system32\GKSUI20.EXE C:\Program Files\YouTube Movie Ripper V1.1\Uninstall8AEC.DAT
ZoneAlarm-->C:\Program Files\Zone Labs\ZoneAlarm\zauninst.exe
======Security center information======
AV: AVG Anti-Virus Free
FW: ZoneAlarm Firewall
System event log
Computer Name: IC
Event Code: 7035
Message: The AVG7 Alert Manager Server service was successfully sent a start control.
Record Number: 222
Source Name: Service Control Manager
Time Written: 20081123170713.000000+060
Event Type: information
User: IC\Ivana
Computer Name: IC
Event Code: 7035
Message: The AVG7 Clean Driver service was successfully sent a start control.
Record Number: 221
Source Name: Service Control Manager
Time Written: 20081123170713.000000+060
Event Type: information
User: IC\Ivana
Computer Name: IC
Event Code: 7035
Message: The AVG Network Redirector service was successfully sent a start control.
Record Number: 220
Source Name: Service Control Manager
Time Written: 20081123170713.000000+060
Event Type: information
User: IC\Ivana
Computer Name: IC
Event Code: 7035
Message: The AVG7 Resident Driver XP service was successfully sent a start control.
Record Number: 219
Source Name: Service Control Manager
Time Written: 20081123170713.000000+060
Event Type: information
User: IC\Ivana
Computer Name: IC
Event Code: 7035
Message: The AVG7 Wrap Driver service was successfully sent a start control.
Record Number: 218
Source Name: Service Control Manager
Time Written: 20081123170713.000000+060
Event Type: information
User: IC\Ivana
Application event log
Computer Name: IC
Event Code: 1800
Message: The Windows Security Center Service has started.
Record Number: 5
Source Name: SecurityCenter
Time Written: 20081220152306.000000+060
Event Type: information
User:
Computer Name: IC
Event Code: 1800
Message: The Windows Security Center Service has started.
Record Number: 4
Source Name: SecurityCenter
Time Written: 20081220100301.000000+060
Event Type: information
User:
Computer Name: IC
Event Code: 1800
Message: The Windows Security Center Service has started.
Record Number: 3
Source Name: SecurityCenter
Time Written: 20081220012046.000000+060
Event Type: information
User:
Computer Name: IC
Event Code: 1800
Message: The Windows Security Center Service has started.
Record Number: 2
Source Name: SecurityCenter
Time Written: 20081219231309.000000+060
Event Type: information
User:
Computer Name: IC
Event Code: 1800
Message: The Windows Security Center Service has started.
Record Number: 1
Source Name: SecurityCenter
Time Written: 20081219194222.000000+060
Event Type: information
User:
======Environment variables======
"ComSpec"=%SystemRoot%\system32\cmd.exe
"Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem
"windir"=%SystemRoot%
"FP_NO_HOST_CHECK"=NO
"OS"=Windows_NT
"PROCESSOR_ARCHITECTURE"=x86
"PROCESSOR_LEVEL"=15
"PROCESSOR_IDENTIFIER"=x86 Family 15 Model 47 Stepping 2, AuthenticAMD
"PROCESSOR_REVISION"=2f02
"NUMBER_OF_PROCESSORS"=1
"PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH
"TEMP"=%SystemRoot%\TEMP
"TMP"=%SystemRoot%\TEMP
"tvdumpflags"=8
EOF
Run by Ivana at 2008-12-21 23:41:51
Microsoft Windows XP Professional Service Pack 2
System drive C: has 16 GB (64%) free of 25 GB
Total RAM: 1023 MB (35% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:42:07, on 21.12.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Update\GoogleUpdate.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\WinFast\WFTVFM\WFTV.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\MSN Messenger\usnsvc.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Documents and Settings\Ivana\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Ivana.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [WinFast Schedule] C:\Program Files\WinFast\WFTVFM\WFWIZ.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: WinFast(R) Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
O23 - Service: Windows Host Services (SVCHOSTS32) - Unknown owner - C:\WINDOWS\system\svchost.exe (file missing)
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: VMwareService - Unknown owner - C:\WINDOWS\system\VMwareService.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Windows Spool Services (WinSpoolSvc) - Unknown owner - C:\WINDOWS\system32\csrsc.exe (file missing)
--
End of file - 7103 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\flgjcldz.job
C:\WINDOWS\tasks\GoogleUpdateTaskUser.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
AcroIEHlprObj Class - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-11-26 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java(tm) Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-12-03 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-12-03 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-12-03 73728]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SoundMan"=C:\WINDOWS\SOUNDMAN.EXE [2006-01-11 577536]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2005-12-14 7323648]
"nwiz"=nwiz.exe /install []
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2005-12-14 86016]
"WinFast Schedule"=C:\Program Files\WinFast\WFTVFM\WFWIZ.exe [2005-12-21 331776]
"NeroFilterCheck"=C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe [2006-01-12 155648]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"WinampAgent"=C:\Program Files\Winamp\winampa.exe []
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-11-28 1261336]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-12-03 136600]
"ZoneAlarm Client"=C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe [2008-11-13 981904]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360]
"BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe [2006-10-09 139264]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2008-11-18 21633320]
"Google Update"=C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2008-12-17 133104]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-04-19 52224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
"{B215471C-28A3-4D25-92C4-5A6AD0256C6B}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\WINDOWS\system\svchost.exe"="C:\WINDOWS\system\svchost.exe:*:Enabled:Microsoft Enabled"
"C:\WINDOWS\system32\y.exe"="C:\WINDOWS\system32\y.exe:*:Enabled:Microsoft Enabled"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
"C:\WINDOWS\system32\csrsc.exe"="C:\WINDOWS\system32\csrsc.exe:*:Enabled:Microsoft Enabled"
"C:\WINDOWS\System32\x.exe"="C:\WINDOWS\System32\x.exe:*:Enabled:Microsoft Enabled"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\WINDOWS\system\VMwareService.exe"="C:\WINDOWS\system\VMwareService.exe:*:Enabled:Microsoft Enabled"
"G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe"="G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe:*:Enabled:Microsoft Enabled"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll"="C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin"
"C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe"="C:\Documents and Settings\Ivana\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\MSN Messenger\msnmsgr.exe"="C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\Program Files\MSN Messenger\livecall.exe"="C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{6a311620-c0a6-11dd-b23f-0016e668be49}]
shell\AutoRun\command - G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
shell\open\command - G:\RECYCLER\S-1-6-21-2434476501-1644491937-600003330-1213\autorunme.exe
======List of files/folders created in the last 3 months======
2008-12-21 23:41:51 ----D---- C:\rsit
2008-12-15 22:08:30 ----D---- C:\Program Files\Trend Micro
2008-12-15 21:02:44 ----D---- C:\MSNCleaner
2008-12-07 18:22:43 ----A---- C:\WINDOWS\system32\zlcommdb.dll
2008-12-07 18:22:43 ----A---- C:\WINDOWS\system32\zlcomm.dll
2008-12-07 18:22:35 ----A---- C:\WINDOWS\system32\zpeng25.dll
2008-12-05 21:27:23 ----A---- C:\WINDOWS\system32\mfc71.dll
2008-12-03 18:45:24 ----D---- C:\WINDOWS\Sun
2008-12-03 18:43:34 ----A---- C:\WINDOWS\system32\javaws.exe
2008-12-03 18:43:34 ----A---- C:\WINDOWS\system32\javaw.exe
2008-12-03 18:43:34 ----A---- C:\WINDOWS\system32\java.exe
2008-12-03 18:43:20 ----D---- C:\Program Files\Java
2008-12-03 18:28:24 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-03 18:27:19 ----D---- C:\Documents and Settings\Ivana\Application Data\Sun
2008-11-30 01:57:36 ----D---- C:\WINDOWS\Minidump
2008-11-29 21:12:35 ----D---- C:\Program Files\directx
2008-11-29 21:12:29 ----D---- C:\WINDOWS\Options
2008-11-29 21:12:29 ----D---- C:\Program Files\ODM
2008-11-29 21:12:29 ----A---- C:\WINDOWS\select.exe
2008-11-29 21:12:29 ----A---- C:\WINDOWS\Pcamr800.exe
2008-11-29 21:12:29 ----A---- C:\WINDOWS\JPGL.DLL
2008-11-29 21:12:29 ----A---- C:\WINDOWS\DIV_IYUV.DLL
2008-11-29 21:12:29 ----A---- C:\WINDOWS\Clement.exe
2008-11-29 21:10:37 ----D---- C:\Program Files\gecam
2008-11-29 20:46:15 ----D---- C:\Documents and Settings\Ivana\Application Data\SpeedSim
2008-11-29 20:46:08 ----D---- C:\Program Files\SpeedSim
2008-11-26 01:16:43 ----HD---- C:\$AVG8.VAULT$
2008-11-26 01:01:31 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-11-26 01:01:19 ----D---- C:\Program Files\AVG
2008-11-26 01:01:19 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2008-11-26 00:03:28 ----D---- C:\Documents and Settings\All Users\Application Data\PrevxCSI
2008-11-25 23:03:07 ----D---- C:\Program Files\Wisdom-soft ScreenHunter 5 Free
2008-11-25 22:59:18 ----D---- C:\Documents and Settings\Ivana\Application Data\Malwarebytes
2008-11-25 22:59:11 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-11-25 22:59:11 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-11-25 08:06:22 ----D---- C:\Documents and Settings\Ivana\Application Data\skypePM
2008-11-25 07:09:35 ----SHD---- C:\RECYCLER
2008-11-25 02:48:54 ----D---- C:\Documents and Settings\Ivana\Application Data\ACD Systems
2008-11-25 02:19:53 ----D---- C:\Program Files\Google
2008-11-25 01:34:09 ----D---- C:\Program Files\Lavasoft
2008-11-25 01:34:09 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-11-25 01:33:19 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-11-25 01:26:20 ----D---- C:\Documents and Settings\Ivana\Application Data\Skype
2008-11-25 01:26:10 ----D---- C:\Program Files\Skype
2008-11-25 01:26:09 ----D---- C:\Program Files\Common Files\Skype
2008-11-25 01:25:54 ----D---- C:\Documents and Settings\All Users\Application Data\Skype
2008-11-25 00:47:25 ----D---- C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-11-25 00:47:12 ----A---- C:\WINDOWS\zllsputility.exe
2008-11-25 00:47:12 ----A---- C:\WINDOWS\system32\SpOrder.dll
2008-11-25 00:46:54 ----A---- C:\WINDOWS\system32\vsregexp.dll
2008-11-25 00:46:54 ----A---- C:\WINDOWS\system32\libeay32_0.9.6l.dll
2008-11-25 00:46:48 ----A---- C:\WINDOWS\system32\vswmi.dll
2008-11-25 00:46:47 ----A---- C:\WINDOWS\system32\vsxml.dll
2008-11-25 00:46:46 ----D---- C:\WINDOWS\system32\ZoneLabs
2008-11-25 00:46:46 ----D---- C:\Program Files\Zone Labs
2008-11-25 00:46:46 ----A---- C:\WINDOWS\system32\vspubapi.dll
2008-11-25 00:46:46 ----A---- C:\WINDOWS\system32\vsmonapi.dll
2008-11-25 00:45:05 ----D---- C:\WINDOWS\Internet Logs
2008-11-25 00:45:05 ----A---- C:\WINDOWS\system32\vsutil.dll
2008-11-25 00:45:05 ----A---- C:\WINDOWS\system32\vsinit.dll
2008-11-25 00:45:05 ----A---- C:\WINDOWS\system32\vsdata.dll
2008-11-23 21:18:30 ----D---- C:\Documents and Settings\Ivana\Application Data\Ahead
2008-11-23 21:18:14 ----A---- C:\WINDOWS\NeroDigital.ini
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\vxblock.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxwave.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxsfs.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxmas.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxinsa64.exe
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxhpinst.exe
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxdrv.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxcpya64.exe
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\pxafs.dll
2008-11-23 20:45:15 ----A---- C:\WINDOWS\system32\px.dll
2008-11-23 20:45:13 ----D---- C:\Program Files\Winamp
2008-11-23 20:45:13 ----D---- C:\Documents and Settings\Ivana\Application Data\Winamp
2008-11-23 18:38:10 ----RA---- C:\WINDOWS\UNDPX2A.exe
2008-11-23 18:23:30 ----D---- C:\Documents and Settings\Ivana\Application Data\AdobeUM
2008-11-23 18:18:28 ----D---- C:\Documents and Settings\Ivana\Application Data\Adobe
2008-11-23 18:11:23 ----D---- C:\WINDOWS\system32\DX9
2008-11-23 18:06:21 ----A---- C:\WINDOWS\system32\vfwwdm32.dll
2008-11-23 17:57:05 ----D---- C:\Program Files\URUSoft
2008-11-23 17:55:14 ----A---- C:\WINDOWS\system32\GkSui20.EXE
2008-11-23 17:55:12 ----D---- C:\Program Files\YouTube Movie Ripper V1.1
2008-11-23 17:53:43 ----D---- C:\Program Files\WinRAR
2008-11-23 17:48:08 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2008-11-23 17:47:54 ----D---- C:\WINDOWS\system32\LogFiles
2008-11-23 17:47:50 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2008-11-23 17:47:23 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2008-11-23 17:47:21 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2008-11-23 17:46:57 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2008-11-23 17:44:20 ----D---- C:\Program Files\Alcohol Soft
2008-11-23 17:41:55 ----D---- C:\Documents and Settings\Ivana\Application Data\Mozilla
2008-11-23 17:41:10 ----D---- C:\Program Files\Mozilla Firefox
2008-11-23 17:36:07 ----D---- C:\Program Files\totalcmd
2008-11-23 17:36:07 ----A---- C:\WINDOWS\wincmd.ini
2008-11-23 17:33:15 ----A---- C:\WINDOWS\system32\msonpmon.dll
2008-11-23 17:32:22 ----D---- C:\Program Files\Microsoft Works
2008-11-23 17:32:16 ----D---- C:\Program Files\MSBuild
2008-11-23 17:32:02 ----D---- C:\Program Files\Microsoft Visual Studio
2008-11-23 17:32:02 ----D---- C:\Program Files\Common Files\DESIGNER
2008-11-23 17:29:46 ----D---- C:\WINDOWS\SHELLNEW
2008-11-23 17:29:28 ----D---- C:\Program Files\Microsoft Office
2008-11-23 17:29:28 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2008-11-23 17:29:15 ----RHD---- C:\MSOCache
2008-11-23 17:24:15 ----D---- C:\Program Files\Nero
2008-11-23 17:24:15 ----D---- C:\Program Files\Common Files\Ahead
2008-11-23 17:14:14 ----DC---- C:\WINDOWS\system32\DRVSTORE
2008-11-23 17:13:56 ----D---- C:\Program Files\MSN Messenger
2008-11-23 17:12:30 ----D---- C:\Program Files\Common Files\ACD Systems
2008-11-23 17:12:30 ----D---- C:\Program Files\ACD Systems
2008-11-23 17:12:30 ----D---- C:\Documents and Settings\All Users\Application Data\ACD Systems
2008-11-23 17:10:07 ----D---- C:\WINDOWS\Downloaded Installations
2008-11-23 17:09:45 ----D---- C:\Program Files\Webteh
2008-11-23 17:09:17 ----D---- C:\Program Files\ffdshow
2008-11-23 17:07:07 ----D---- C:\Program Files\Grisoft
2008-11-23 17:07:07 ----D---- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-11-23 17:05:46 ----D---- C:\Program Files\Common Files\Adobe
2008-11-23 17:05:44 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-11-23 17:05:28 ----D---- C:\Program Files\Adobe
2008-11-23 13:07:27 ----A---- C:\WINDOWS\system32\l3codeca.acm.bak
2008-11-23 13:07:25 ----D---- C:\Program Files\Common Files\Ulead Systems
2008-11-23 13:06:34 ----D---- C:\Documents and Settings\All Users\Application Data\Ulead Systems
2008-11-23 13:06:31 ----A---- C:\WINDOWS\system32\TempDel.EXE
2008-11-23 13:06:24 ----D---- C:\Program Files\WinFast
2008-11-23 12:53:35 ----A---- C:\WINDOWS\system32\h323log.txt
2008-11-23 12:48:06 ----A---- C:\WINDOWS\system32\usbui.dll
2008-11-23 12:46:57 ----A---- C:\WINDOWS\imsins.BAK
2008-11-23 12:46:54 ----SHD---- C:\WINDOWS\Installer
2008-11-23 12:46:54 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-23 12:46:53 ----D---- C:\Program Files\Common Files\ODBC
2008-11-23 12:46:53 ----A---- C:\WINDOWS\ODBCINST.INI
2008-11-23 12:46:51 ----D---- C:\Program Files\Common Files\SpeechEngines
2008-11-23 12:46:50 ----RD---- C:\Program Files
2008-11-23 12:46:50 ----D---- C:\Program Files\Common Files\Microsoft Shared
2008-11-23 12:46:50 ----D---- C:\Program Files\Common Files
2008-11-23 12:46:40 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2008-11-23 12:46:40 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2008-11-23 12:46:40 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdur.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdru.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2008-11-23 12:46:37 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2008-11-23 12:46:35 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2008-11-23 12:46:33 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2008-11-23 12:46:33 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2008-11-23 12:46:33 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2008-11-23 12:46:33 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2008-11-23 12:46:33 ----RA---- C:\WINDOWS\system32\kbdest.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdro.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2008-11-23 12:46:30 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2008-11-23 12:46:23 ----A---- C:\WINDOWS\system32\irclass.dll
2008-11-23 12:46:23 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2008-11-23 12:46:22 ----A---- C:\WINDOWS\system32\spxcoins.dll
2008-11-23 12:46:22 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2008-11-23 12:46:22 ----A---- C:\WINDOWS\system32\dgsetup.dll
2008-11-23 12:46:20 ----A---- C:\WINDOWS\TASKMAN.EXE
2008-11-23 12:46:19 ----A---- C:\WINDOWS\system32\CONFIG.TMP
2008-11-23 12:46:19 ----A---- C:\WINDOWS\system32\batt.dll
2008-11-23 12:46:18 ----A---- C:\WINDOWS\system32\storprop.dll
2008-11-23 12:46:18 ----A---- C:\WINDOWS\NOTEPAD.EXE
2008-11-23 12:46:11 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2008-11-23 12:45:50 ----RA---- C:\WINDOWS\SET8.tmp
2008-11-23 12:45:48 ----RA---- C:\WINDOWS\SET4.tmp
2008-11-23 12:45:46 ----RA---- C:\WINDOWS\SET3.tmp
2008-11-23 12:45:41 ----D---- C:\WINDOWS\system32\CatRoot2
2008-11-23 12:45:41 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-23 12:45:35 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-11-23 12:45:08 ----A---- C:\WINDOWS\setuplog.txt
2008-11-23 12:45:05 ----D---- C:\Documents and Settings
2008-11-23 12:45:04 ----SHD---- C:\System Volume Information
2008-11-23 12:44:09 ----SH---- C:\boot.ini
2008-11-23 12:41:05 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-11-23 12:41:05 ----RSD---- C:\WINDOWS\Fonts
2008-11-23 12:41:05 ----RD---- C:\WINDOWS\Web
2008-11-23 12:41:05 ----HD---- C:\WINDOWS\inf
2008-11-23 12:41:05 ----D---- C:\WINDOWS\WinSxS
2008-11-23 12:41:05 ----D---- C:\WINDOWS\twain_32
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Temp
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\wins
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\wbem
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\usmt
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\spool
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\ShellExt
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\Setup
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\ras
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\PreInstall
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\oobe
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\npp
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\mui
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\Macromed
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\inetsrv
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\IME
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\icsxml
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\ias
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\export
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\en-us
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\en
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\drivers
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\dhcp
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\config
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\3com_dmi
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\3076
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\2052
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1054
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1042
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1041
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1037
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1033
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1031
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1028
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32\1025
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system32
2008-11-23 12:41:05 ----D---- C:\WINDOWS\system
2008-11-23 12:41:05 ----D---- C:\WINDOWS\SoftwareDistribution
2008-11-23 12:41:05 ----D---- C:\WINDOWS\security
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Resources
2008-11-23 12:41:05 ----D---- C:\WINDOWS\repair
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Provisioning
2008-11-23 12:41:05 ----D---- C:\WINDOWS\PeerNet
2008-11-23 12:41:05 ----D---- C:\WINDOWS\pchealth
2008-11-23 12:41:05 ----D---- C:\WINDOWS\NLDRV
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Network Diagnostic
2008-11-23 12:41:05 ----D---- C:\WINDOWS\mui
2008-11-23 12:41:05 ----D---- C:\WINDOWS\msapps
2008-11-23 12:41:05 ----D---- C:\WINDOWS\msagent
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Media
2008-11-23 12:41:05 ----D---- C:\WINDOWS\l2schemas
2008-11-23 12:41:05 ----D---- C:\WINDOWS\java
2008-11-23 12:41:05 ----D---- C:\WINDOWS\ime
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Help
2008-11-23 12:41:05 ----D---- C:\WINDOWS\ehome
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Driver Cache
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Debug
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Cursors
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Connection Wizard
2008-11-23 12:41:05 ----D---- C:\WINDOWS\Config
2008-11-23 12:41:05 ----D---- C:\WINDOWS\AppPatch
2008-11-23 12:41:05 ----D---- C:\WINDOWS\addins
2008-11-23 12:41:05 ----D---- C:\WINDOWS
2008-11-23 12:40:54 ----D---- C:\Documents and Settings\Ivana\Application Data\Macromedia
2008-11-23 12:27:00 ----D---- C:\WINDOWS\nview
2008-11-23 12:27:00 ----A---- C:\WINDOWS\system32\nvudisp.exe
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nwiz.exe
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrszht.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrszhc.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrstr.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrssv.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrssl.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrssk.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsru.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsptb.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrspt.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrspl.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsno.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsnl.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsko.dll
2008-11-23 12:26:54 ----A---- C:\WINDOWS\system32\nvwrsja.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsit.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrshu.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrshe.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsfr.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsfi.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsesm.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrses.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrseng.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsel.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsde.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsda.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrscs.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwrsar.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwimg.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwdmcpl.dll
2008-11-23 12:26:53 ----A---- C:\WINDOWS\system32\nvwddi.dll
2008-11-23 12:26:52 ----A---- C:\WINDOWS\system32\nvsvc32.exe
2008-11-23 12:26:52 ----A---- C:\WINDOWS\system32\nvshell.dll
2008-11-23 12:26:51 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2008-11-23 12:26:51 ----A---- C:\WINDOWS\system32\nvnt4cpl.dll
2008-11-23 12:26:51 ----A---- C:\WINDOWS\system32\nvmccsrs.dll
2008-11-23 12:26:51 ----A---- C:\WINDOWS\system32\nvmccs.dll
2008-11-23 12:26:51 ----A---- C:\WINDOWS\system32\nview.dll
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvhwvid.dll
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvdspsch.exe
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvcodins.dll
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvcod.dll
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvappbar.exe
2008-11-23 12:26:50 ----A---- C:\WINDOWS\system32\nvapi.dll
2008-11-23 12:26:49 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2008-11-23 12:26:49 ----A---- C:\WINDOWS\system32\keystone.exe
2008-11-23 12:26:48 ----A---- C:\WINDOWS\system32\nvmctray.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrszht.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrszhc.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrstr.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrssv.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrssl.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrssk.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrsru.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrsptb.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrspt.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrspl.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrsno.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvrsnl.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvcpl.dll
2008-11-23 12:26:47 ----A---- C:\WINDOWS\system32\nvcolor.exe
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsko.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsja.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsit.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrshu.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrshe.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsfr.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsfi.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsesm.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrses.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrseng.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsel.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsde.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsda.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrscs.dll
2008-11-23 12:26:46 ----A---- C:\WINDOWS\system32\nvrsar.dll
2008-11-23 12:26:43 ----D---- C:\WINDOWS\system32\WinFast
2008-11-23 12:25:13 ----D---- C:\WINDOWS\system32\WinFox
2008-11-23 12:18:22 ----A---- C:\WINDOWS\system32\nvuide.exe
2008-11-23 12:18:21 ----RA---- C:\WINDOWS\system32\NVCOI.DLL
2008-11-23 12:18:21 ----RA---- C:\WINDOWS\system32\idecoins.dll
2008-11-23 12:18:21 ----RA---- C:\WINDOWS\system32\idecoi.dll
2008-11-23 12:16:15 ----A---- C:\WINDOWS\system32\ChCfg.exe
2008-11-23 12:15:52 ----A---- C:\WINDOWS\system32\ksuser.dll
2008-11-23 12:15:49 ----D---- C:\Program Files\Realtek Sound Manager
2008-11-23 12:15:49 ----D---- C:\Program Files\AvRack
2008-11-23 12:15:49 ----A---- C:\WINDOWS\avrack.ini
2008-11-23 12:15:42 ----D---- C:\Program Files\Realtek AC97
2008-11-23 12:15:40 ----A---- C:\WINDOWS\system32\RTLCPL.exe
2008-11-23 12:15:40 ----A---- C:\WINDOWS\system32\RtlCPAPI.dll
2008-11-23 12:15:40 ----A---- C:\WINDOWS\soundman.exe
2008-11-23 12:15:39 ----A---- C:\WINDOWS\alcupd.exe
2008-11-23 12:15:39 ----A---- C:\WINDOWS\Alcrmv.exe
2008-11-23 12:14:17 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-11-23 12:14:14 ----HD---- C:\Program Files\InstallShield Installation Information
2008-11-23 12:14:14 ----D---- C:\Program Files\AMD
2008-11-23 12:11:31 ----RA---- C:\WINDOWS\system32\fdco1ins.dll
2008-11-23 12:11:31 ----RA---- C:\WINDOWS\system32\fdco1.dll
2008-11-23 12:11:29 ----A---- C:\WINDOWS\system32\nvunrm.exe
2008-11-23 12:11:28 ----RA---- C:\WINDOWS\system32\nvconrm.dll
2008-11-23 12:11:28 ----RA---- C:\WINDOWS\system32\bdco1ins.dll
2008-11-23 12:11:28 ----RA---- C:\WINDOWS\system32\bdco1.dll
2008-11-23 12:11:27 ----RA---- C:\WINDOWS\system32\nvusmb.exe
2008-11-23 12:11:23 ----A---- C:\WINDOWS\system32\NVUNINST.EXE
2008-11-23 12:11:15 ----D---- C:\Program Files\Common Files\InstallShield
2008-11-23 12:07:41 ----D---- C:\Documents and Settings\Ivana\Application Data\Identities
2008-11-23 12:07:40 ----HD---- C:\Program Files\Uninstall Information
2008-11-23 12:07:34 ----ASH---- C:\Documents and Settings\Ivana\Application Data\desktop.ini
2008-11-23 12:07:33 ----SD---- C:\Documents and Settings\Ivana\Application Data\Microsoft
2008-11-23 12:04:21 ----D---- C:\WINDOWS\Prefetch
2008-11-23 12:04:20 ----SD---- C:\WINDOWS\system32\Microsoft
2008-11-23 12:04:20 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-11-23 12:00:27 ----D---- C:\WINDOWS\system32\xircom
2008-11-23 12:00:27 ----D---- C:\Program Files\xerox
2008-11-23 12:00:27 ----D---- C:\Program Files\microsoft frontpage
2008-11-23 12:00:14 ----A---- C:\WINDOWS\control.ini
2008-11-23 12:00:14 ----A---- C:\AUTOEXEC.BAT
2008-11-23 12:00:05 ----A---- C:\WINDOWS\OEWABLog.txt
2008-11-23 12:00:02 ----A---- C:\WINDOWS\system32\mapi32.dll
2008-11-23 11:59:07 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-11-23 11:59:07 ----RD---- C:\WINDOWS\Offline Web Pages
2008-11-23 11:59:07 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2008-11-23 11:59:01 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2008-11-23 11:58:57 ----HD---- C:\Program Files\WindowsUpdate
2008-11-23 11:58:37 ----D---- C:\WINDOWS\system32\DirectX
2008-11-23 11:58:15 ----A---- C:\WINDOWS\system32\atrace.dll
2008-11-23 11:58:13 ----A---- C:\WINDOWS\system32\desktop.ini
2008-11-23 11:58:13 ----A---- C:\WINDOWS\desktop.ini
2008-11-23 11:58:05 ----A---- C:\WINDOWS\system32\nmevtmsg.dll
2008-11-23 11:58:04 ----A---- C:\WINDOWS\system32\acctres.dll
2008-11-23 11:58:03 ----D---- C:\Program Files\Common Files\Services
2008-11-23 11:58:00 ----SD---- C:\WINDOWS\Tasks
2008-11-23 11:58:00 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2008-11-23 11:57:59 ----D---- C:\Program Files\Common Files\MSSoap
2008-11-23 11:57:56 ----D---- C:\WINDOWS\srchasst
2008-11-23 11:57:52 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-11-23 11:57:52 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-11-23 11:57:52 ----A---- C:\WINDOWS\system32\wuauserv.dll
2008-11-23 11:57:52 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2008-11-23 11:57:52 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\wups.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\qmgr.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2008-11-23 11:57:51 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2008-11-23 11:57:47 ----D---- C:\Program Files\Movie Maker
2008-11-23 11:57:43 ----A---- C:\WINDOWS\system32\safrslv.dll
2008-11-23 11:57:43 ----A---- C:\WINDOWS\system32\safrdm.dll
2008-11-23 11:57:43 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2008-11-23 11:57:43 ----A---- C:\WINDOWS\system32\racpldlg.dll
2008-11-23 11:57:40 ----D---- C:\WINDOWS\system32\Restore
2008-11-23 11:57:40 ----A---- C:\WINDOWS\system32\srrstr.dll
2008-11-23 11:57:40 ----A---- C:\WINDOWS\system32\fltMc.exe
2008-11-23 11:57:40 ----A---- C:\WINDOWS\system32\fltlib.dll
2008-11-23 11:57:39 ----A---- C:\WINDOWS\system32\srsvc.dll
2008-11-23 11:57:39 ----A---- C:\WINDOWS\system32\srclient.dll
2008-11-23 11:57:39 ----A---- C:\WINDOWS\system32\mnmdd.dll
2008-11-23 11:57:39 ----A---- C:\WINDOWS\system32\isrdbg32.dll
2008-11-23 11:57:39 ----A---- C:\WINDOWS\system32\ils.dll
2008-11-23 11:57:38 ----A---- C:\WINDOWS\system32\nmmkcert.dll
2008-11-23 11:57:38 ----A---- C:\WINDOWS\system32\msconf.dll
2008-11-23 11:57:38 ----A---- C:\WINDOWS\system32\mnmsrvc.exe
2008-11-23 11:57:36 ----D---- C:\Program Files\NetMeeting
2008-11-23 11:57:36 ----A---- C:\WINDOWS\system32\msoert2.dll
2008-11-23 11:57:35 ----A---- C:\WINDOWS\system32\msoeacct.dll
2008-11-23 11:57:34 ----A---- C:\WINDOWS\system32\inetres.dll
2008-11-23 11:57:34 ----A---- C:\WINDOWS\system32\inetcomm.dll
2008-11-23 11:57:33 ----D---- C:\Program Files\Outlook Express
2008-11-23 11:57:33 ----A---- C:\WINDOWS\system32\schedsvc.dll
2008-11-23 11:57:33 ----A---- C:\WINDOWS\system32\mstinit.exe
2008-11-23 11:57:33 ----A---- C:\WINDOWS\system32\mstask.dll
2008-11-23 11:57:32 ----A---- C:\WINDOWS\system32\isign32.dll
2008-11-23 11:57:32 ----A---- C:\WINDOWS\system32\inetcfg.dll
2008-11-23 11:57:32 ----A---- C:\WINDOWS\system32\icwphbk.dll
2008-11-23 11:57:32 ----A---- C:\WINDOWS\system32\icwdial.dll
2008-11-23 11:57:22 ----D---- C:\Program Files\Common Files\System
2008-11-23 11:57:20 ----D---- C:\Program Files\Internet Explorer
2008-11-23 11:56:52 ----D---- C:\Program Files\ComPlus Applications
2008-11-23 11:56:51 ----A---- C:\WINDOWS\vbaddin.ini
2008-11-23 11:56:51 ----A---- C:\WINDOWS\vb.ini
2008-11-23 11:56:47 ----D---- C:\WINDOWS\Registration
2008-11-23 11:56:43 ----D---- C:\Program Files\Online Services
2008-11-23 11:56:34 ----D---- C:\Program Files\Windows Media Player
2008-11-23 11:56:33 ----D---- C:\Program Files\Windows Media Connect 2
2008-11-23 11:56:31 ----D---- C:\Program Files\Messenger
2008-11-23 11:56:27 ----D---- C:\Program Files\MSN Gaming Zone
2008-11-23 11:56:27 ----A---- C:\WINDOWS\system32\write.exe
2008-11-23 11:56:16 ----A---- C:\WINDOWS\system32\sndvol32.exe
2008-11-23 11:56:16 ----A---- C:\WINDOWS\system32\hticons.dll
2008-11-23 11:56:16 ----A---- C:\WINDOWS\system32\avwav.dll
2008-11-23 11:56:16 ----A---- C:\WINDOWS\system32\avtapi.dll
2008-11-23 11:56:16 ----A---- C:\WINDOWS\system32\avmeter.dll
2008-11-23 11:56:15 ----A---- C:\WINDOWS\system32\winchat.exe
2008-11-23 11:56:07 ----A---- C:\WINDOWS\system32\getuname.dll
2008-11-23 11:56:07 ----A---- C:\WINDOWS\system32\charmap.exe
2008-11-23 11:56:06 ----A---- C:\WINDOWS\system32\winmine.exe
2008-11-23 11:56:06 ----A---- C:\WINDOWS\system32\sol.exe
2008-11-23 11:56:06 ----A---- C:\WINDOWS\system32\calc.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\tslabels.ini
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\tskill.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\tscon.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\reset.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\mshearts.exe
2008-11-23 11:56:05 ----A---- C:\WINDOWS\system32\freecell.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\shadow.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\rwinsta.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\regini.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\qwinsta.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\qappsrv.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\msg.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\logoff.exe
2008-11-23 11:56:04 ----A---- C:\WINDOWS\system32\cdmodem.dll
2008-11-23 11:56:03 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\stclient.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\mtxex.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\mtxdm.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\comsnap.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\comrepl.dll
2008-11-23 11:56:02 ----A---- C:\WINDOWS\system32\comaddin.dll
2008-11-23 11:55:56 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2008-11-23 11:55:48 ----D---- C:\Program Files\MSN
2008-11-23 11:55:48 ----A---- C:\WINDOWS\system32\accwiz.exe
2008-11-23 11:55:47 ----D---- C:\Program Files\Windows NT
2008-11-23 11:55:47 ----A---- C:\WINDOWS\system32\sndrec32.exe
2008-11-23 11:55:47 ----A---- C:\WINDOWS\system32\mspaint.exe
2008-11-23 11:55:47 ----A---- C:\WINDOWS\system32\mplay32.exe
2008-11-23 11:55:47 ----A---- C:\WINDOWS\system32\hypertrm.dll
2008-11-23 11:55:46 ----A---- C:\WINDOWS\system32\spider.exe
2008-11-23 11:55:46 ----A---- C:\WINDOWS\system32\clipbrd.exe
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\remotepg.dll
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\rdshost.exe
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\mstscax.dll
2008-11-23 11:55:45 ----A---- C:\WINDOWS\system32\mstsc.exe
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\tscupgrd.exe
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\termsrv.dll
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\sessmgr.exe
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\rdpclip.exe
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\rdchost.dll
2008-11-23 11:55:44 ----A---- C:\WINDOWS\system32\qprocess.exe
2008-11-23 11:55:43 ----D---- C:\WINDOWS\system32\MsDtc
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\mtxoci.dll
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\msdtctm.dll
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\icaapi.dll
2008-11-23 11:55:43 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2008-11-23 11:55:42 ----A---- C:\WINDOWS\system32\xolehlp.dll
2008-11-23 11:55:42 ----A---- C:\WINDOWS\system32\msdtclog.dll
2008-11-23 11:55:42 ----A---- C:\WINDOWS\system32\msdtc.exe
2008-11-23 11:55:41 ----D---- C:\WINDOWS\system32\Com
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\comuid.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\comsvcs.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\colbact.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\clbcatex.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\catsrvut.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\catsrvps.dll
2008-11-23 11:55:41 ----A---- C:\WINDOWS\system32\catsrv.dll
2008-11-23 11:55:40 ----A---- C:\WINDOWS\system32\clbcatq.dll
2008-11-23 11:55:31 ----A---- C:\WINDOWS\system32\servdeps.dll
2008-11-23 11:55:30 ----A---- C:\WINDOWS\system32\mmfutil.dll
2008-11-23 11:55:30 ----A---- C:\WINDOWS\system32\licwmi.dll
2008-11-23 11:55:30 ----A---- C:\WINDOWS\system32\cmprops.dll
2008-11-23 17:29:52 ----A---- C:\WINDOWS\win.ini
2008-11-23 12:37:15 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AmdK8;AMD Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdK8.sys [2005-03-09 36352]
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-11-26 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-11-26 26824]
R1 vsdatant;vsdatant; C:\WINDOWS\System32\vsdatant.sys [2008-11-13 353680]
R2 CX23880;WinFast CX2388x WDM Video Capture.; C:\WINDOWS\system32\drivers\cx88vid.sys [2005-06-28 163584]
R2 CXTUNE;WinFast CX2388x WDM TVTuner.; C:\WINDOWS\system32\drivers\CX88TUNE.sys [2005-06-28 30976]
R2 rspndr;Link-Layer Topology Discovery Responder; C:\WINDOWS\system32\DRIVERS\rspndr.sys [2007-04-22 62336]
R3 ALCXWDM;Service for Realtek AC97 Audio (WDM); C:\WINDOWS\system32\drivers\ALCXWDM.SYS [2006-01-13 3844288]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2007-04-22 60800]
R3 CXAVXBAR;WinFast CX2388x WDM Crossbar.; C:\WINDOWS\system32\drivers\cxavxbar.sys [2005-06-28 9728]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2004-08-04 9600]
R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys []
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2007-04-22 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2007-04-22 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2005-12-14 3580480]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2005-04-05 33536]
R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2005-04-05 12928]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2008-11-23 10368]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2007-04-22 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2007-04-22 59264]
R3 usbohci;Microsoft USB Open Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2007-04-22 17152]
R3 WFIOCTL;WFIOCTL; \??\C:\Program Files\WinFast\WFTVFM\WFIOCTL.SYS []
S3 CCCP106;CIF USB Camera (2110A); C:\WINDOWS\system32\DRIVERS\cccp106.sys [2003-04-28 227200]
S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2004-08-03 17024]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2004-08-03 5504]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2004-08-03 85376]
S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2004-08-03 10880]
S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2004-08-03 11136]
S3 streamip;BDA IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2004-08-03 15360]
S3 USBCM;Scientific-Atlanta USB Cable Modem Driver; C:\WINDOWS\system32\DRIVERS\Sacm2A.sys [2004-06-10 15429]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2004-08-03 19328]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-04-11 82944]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-04-11 87808]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-11-25 611664]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-11-26 231704]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-12-03 152984]
R2 NVSvc;WinFast(R) Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2005-12-14 143427]
R2 StarWindService;StarWind iSCSI Service; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe [2005-04-02 217600]
R2 UleadBurningHelper;Ulead Burning Helper; C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe [2004-12-13 49152]
R2 vsmon;TrueVector Internet Monitor; C:\WINDOWS\system32\ZoneLabs\vsmon.exe [2008-11-13 2405776]
R3 usnjsvc;Messenger Sharing Folders USN Journal Reader service; C:\Program Files\MSN Messenger\usnsvc.exe [2007-01-19 97136]
S2 SVCHOSTS32;Windows Host Services ; C:\WINDOWS\system\svchost.exe []
S2 VMwareService;VMwareService; C:\WINDOWS\system\VMwareService.exe []
S2 WinSpoolSvc;Windows Spool Services; C:\WINDOWS\system32\csrsc.exe []
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMConnectCDS;Windows Media Connect Service; C:\Program Files\Windows Media Connect 2\wmccds.exe [2005-10-06 855552]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-04-19 823808]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2004-08-04 14336]
EOF
I have msn on mail that doesn't work anymore....is there a chance to change password without mail?
Please see if this helps http://support.microsoft.com/kb/935255