Alrighty....
Here's the OTMoveIt3 log========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\system32\system130917.exe moved successfully.
File/Folder C:\WINDOWS\system32\MreadfeB.dll not found.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\Neill\LOCALS~1\Temp\etilqs_ARtjhZcEnSQLqo00zuz1 scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\ib10 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ib11 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ib7 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ib8 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ib9 scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_8c.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.5.0 log created on 10202008_203108
Files moved on Reboot...
File C:\DOCUME~1\Neill\LOCALS~1\Temp\etilqs_ARtjhZcEnSQLqo00zuz1 not found!
File C:\WINDOWS\temp\ib10 not found!
File C:\WINDOWS\temp\ib11 not found!
File C:\WINDOWS\temp\ib7 not found!
File C:\WINDOWS\temp\ib8 not found!
File C:\WINDOWS\temp\ib9 not found!
File C:\WINDOWS\temp\Perflib_Perfdata_8c.dat not found!
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\Neill\Local Settings\Application Data\Mozilla\Firefox\Profiles\u6yvctxw.default\XUL.mfl moved successfully.
And here's the log.txt file from RSITLogfile of random's system information tool 1.04 (written by random/random)
Run by Neill at 2008-10-20 20:40:03
Microsoft Windows XP Professional Service Pack 3
System drive C: has 22 GB (20%) free of 114 GB
Total RAM: 1023 MB (52% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:40:12 p.m., on 20/10/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Apache Group\Apache\Apache.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Apache Group\Apache\Apache.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\mysql\bin\mysqld-nt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\UAService7.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\LogMeIn\LogMeInSystray.exe
C:\WINDOWS\system32\TCAUDIAG.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Neill\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Neill.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.co.nz/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll (file missing)
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\LogMeInSystray.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [OPSE reminder] "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe" -r "C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\ereg.ini"
O4 - HKLM\..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.exe -on
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre6\bin\npjpi160_10.dll
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) -
http://go.microsoft....k/?linkid=39204O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Apache - Unknown owner - C:\Program Files\Apache Group\Apache\Apache.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: MySQL4 - Unknown owner - C:\mysql\bin\mysqld-nt (file missing)
O23 - Service: O&O Defrag (OODefrag) - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - NetGroup - Politecnico di Torino - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\system32\UAService7.exe
--
End of file - 7426 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\AppleSoftwareUpdate.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-23 62080]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2008-10-15 455960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2008-10-12 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-10-15 2055960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A5366673-E8CA-11D3-9CD9-0090271D075B}]
IeCatch2 Class - C:\PROGRA~1\FlashGet\jccatch.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2008-10-12 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2008-10-12 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{E0E899AB-F487-11D5-8D29-0050BA6940E3} - FlashGet Bar - C:\PROGRA~1\FlashGet\fgiebar.dll [2005-06-07 86016]
{327C2873-E90D-4c37-AA9D-10AC9BABA46C} - Easy-WebPrint - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll [2004-08-26 405504]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2008-10-15 2055960]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LogMeIn GUI"=C:\Program Files\LogMeIn\LogMeInSystray.exe [2005-12-15 295664]
"TkBellExe"=C:\Program Files\Common Files\Real\Update_OB\realsched.exe [2005-03-15 180269]
"OPSE reminder"=C:\Program Files\ScanSoft\OmniPageSE2.0\EregEng\Ereg.exe [2003-07-07 729088]
"AppleSyncNotifier"=C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2008-07-10 116040]
"TCASUTIEXE"=TCAUDIAG.exe -on []
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2008-10-15 1234712]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2008-10-12 136600]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2008-09-03 1576176]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"iPodService"=3
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLS"="avgrsstx.dll"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-07-23 352256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent]
C:\WINDOWS\system32\Ati2evxx.dll [2005-01-20 61440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\LMIinit]
C:\WINDOWS\system32\LMIinit.dll [2005-12-15 10472]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2007-04-10 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{BA0A0B68-6F3C-51D2-B901-E381E036D21A}"=C:\WINDOWS\system32\KcrnaDrv.dll []
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=
"NoDrives"=
"NoDriveAutoRun"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Games\Dawn of War\w40k.exe"="C:\Games\Dawn of War\w40k.exe:*:Enabled:W40K"
"C:\Games\Wolfenstein - Enemy Territory\ET.exe"="C:\Games\Wolfenstein - Enemy Territory\ET.exe:*:Enabled:ET"
"C:\Games\Mohaa\MOHAA.exe"="C:\Games\Mohaa\MOHAA.exe:*:Enabled:Medal of Honor Allied Assault"
"C:\Games\Worms\WWP.EXE"="C:\Games\Worms\WWP.EXE:*:Enabled:Worms World Party"
"C:\Games\Warcraft III\Warcraft III.exe"="C:\Games\Warcraft III\Warcraft III.exe:*:Enabled:Warcraft III"
"C:\Games\Warcraft III\war3.exe"="C:\Games\Warcraft III\war3.exe:*:Enabled:Warcraft III"
"C:\Program Files\Mozilla Firefox\firefox.exe"="C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox"
"C:\Games\TmSunriseDemoMag\TmSunriseDemoMag.exe"="C:\Games\TmSunriseDemoMag\TmSunriseDemoMag.exe:*:Enabled:TmSunriseDemoMag"
"C:\Games\Doomsday\Bin\Doomsday.exe"="C:\Games\Doomsday\Bin\Doomsday.exe:*:Enabled:Doomsday"
"C:\Games\Legacy\Legacy.exe"="C:\Games\Legacy\Legacy.exe:*:Enabled:Legacy"
"C:\Program Files (x86)\rmDC++0.403D\StrongDC.exe"="C:\Program Files (x86)\rmDC++0.403D\StrongDC.exe:*:Enabled:StrongDC++"
"C:\Games\TOTALA\totala.exe"="C:\Games\TOTALA\totala.exe:*:Enabled:Total Annihilation"
"C:\Program Files\Google\Google Talk\googletalk.exe"="C:\Program Files\Google\Google Talk\googletalk.exe:*:Enabled:Google Talk"
"C:\Games\Dawn of War\W40kWA.exe"="C:\Games\Dawn of War\W40kWA.exe:*:Enabled:W40kWA"
"C:\Program Files (x86)\Skype\Phone\Skype.exe"="C:\Program Files (x86)\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Games\Command & Conquer Generals Zero Hour\game.dat"="C:\Games\Command & Conquer Generals Zero Hour\game.dat:*:Enabled:game"
"C:\Program Files (x86)\rmDC++0.403D\CZDCPlusPlus.exe"="C:\Program Files (x86)\rmDC++0.403D\CZDCPlusPlus.exe:*:Enabled:CZDC++"
"C:\Program Files\Java\jdk1.5.0_05\bin\java.exe"="C:\Program Files\Java\jdk1.5.0_05\bin\java.exe:*:Enabled:Java 2 Platform Standard Edition binary"
"C:\WINDOWS\system32\javaw.exe"="C:\WINDOWS\system32\javaw.exe:*:Enabled:Java 2 Platform Standard Edition binary"
"C:\Program Files (x86)\Xfire\Xfire.exe"="C:\Program Files (x86)\Xfire\Xfire.exe:*:Enabled:Xfire"
"C:\Games\UT2004\System\UT2004.exe"="C:\Games\UT2004\System\UT2004.exe:*:Enabled:UT2004"
"C:\Program Files\Apache Group\Apache\Apache.exe"="C:\Program Files\Apache Group\Apache\Apache.exe:*:Enabled:Apache"
"C:\Games\TrackMania Nations ESWC\TmNationsESWC.exe"="C:\Games\TrackMania Nations ESWC\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\Program Files\World of Warcraft\BackgroundDownloader.exe"="C:\Program Files\World of Warcraft\BackgroundDownloader.exe:*:Enabled:Blizzard Downloader"
"C:\Games\Dawn of War\Dawn of War - Dark Crusade\DarkCrusade.exe"="C:\Games\Dawn of War\Dawn of War - Dark Crusade\DarkCrusade.exe:*:Enabled:DarkCrusade"
"C:\Program Files\Skype\Phone\Skype.exe"="C:\Program Files\Skype\Phone\Skype.exe:*:Enabled:Skype"
"C:\Program Files\Bonjour\mDNSResponder.exe"="C:\Program Files\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour"
"C:\Program Files\iTunes\iTunes.exe"="C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes"
"C:\Program Files\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe"="C:\Program Files\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:*:Enabled:Blizzard Downloader"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\AVG\AVG8\avgemc.exe"="C:\Program Files\AVG\AVG8\avgemc.exe:*:Enabled:avgemc.exe"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 2 months======
2008-10-20 20:31:08 ----D---- C:\_OTMoveIt
2008-10-20 00:20:57 ----D---- C:\Program Files\Oberon Media
2008-10-20 00:20:57 ----D---- C:\Program Files\MSN Games
2008-10-19 20:39:42 ----D---- C:\rsit
2008-10-19 16:46:02 ----D---- C:\Program Files\DOSBox-0.72
2008-10-17 00:32:05 ----HDC---- C:\WINDOWS\$NtUninstallKB951978$
2008-10-16 13:27:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-10-16 13:25:07 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-10-16 13:23:08 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-10-16 12:52:43 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-10-16 12:50:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-10-16 12:24:14 ----HDC---- C:\WINDOWS\$NtUninstallKB953155$
2008-10-16 12:22:13 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2008-10-16 09:40:57 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Blizzard
2008-10-15 13:31:09 ----D---- C:\Program Files\Trend Micro
2008-10-15 13:28:26 ----D---- C:\Documents and Settings\Neill\Application Data\Help
2008-10-15 13:07:47 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\SecTaskMan
2008-10-15 13:07:38 ----D---- C:\Program Files\Security Task Manager
2008-10-15 12:54:05 ----HD---- C:\$AVG8.VAULT$
2008-10-15 12:22:01 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-10-15 12:21:57 ----D---- C:\Documents and Settings\Neill\Application Data\AVGTOOLBAR
2008-10-15 12:21:48 ----D---- C:\Program Files\AVG
2008-10-15 12:17:53 ----SHD---- C:\RECYCLER
2008-10-15 12:17:14 ----A---- C:\ComboFix.txt
2008-10-15 12:03:38 ----D---- C:\ComboFix
2008-10-15 09:40:25 ----D---- C:\Program Files\Kaspersky Anti-Virus
2008-10-15 08:56:03 ----HDC---- C:\WINDOWS\$NtUninstallKB953838$
2008-10-15 08:55:56 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-10-15 08:55:50 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-10-15 08:55:44 ----HDC---- C:\WINDOWS\$NtUninstallKB951748$
2008-10-15 08:55:38 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-10-15 08:55:32 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-10-15 08:55:26 ----HDC---- C:\WINDOWS\$NtUninstallKB951376$
2008-10-15 08:55:19 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-10-15 08:55:13 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-10-15 08:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-10-15 08:55:01 ----HDC---- C:\WINDOWS\$NtUninstallKB950759$
2008-10-15 08:54:55 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-10-15 08:54:49 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-10-15 08:49:42 ----D---- C:\WINDOWS\system32\en-us
2008-10-15 08:49:41 ----D---- C:\WINDOWS\system32\scripting
2008-10-15 08:49:40 ----D---- C:\WINDOWS\l2schemas
2008-10-15 08:49:39 ----D---- C:\WINDOWS\system32\en
2008-10-15 08:49:39 ----D---- C:\WINDOWS\system32\bits
2008-10-15 08:45:51 ----D---- C:\WINDOWS\network diagnostic
2008-10-13 14:21:49 ----D---- C:\Program Files\World of Warcraft
2008-10-13 11:23:57 ----RA---- C:\WINDOWS\system32\UpdDrv2K.exe
2008-10-13 11:23:57 ----RA---- C:\WINDOWS\system32\UN3CDiag.exe
2008-10-13 11:23:57 ----RA---- C:\WINDOWS\system32\sk98nt4.ini
2008-10-13 11:23:57 ----RA---- C:\WINDOWS\system32\InstInfo.ini
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\TDInst2K.exe
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\tcauprot.dll
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\tcaum998.dll
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\tcaudvar.txt
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\TCAUDIAG.EXE
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\TCAMHWAC.DLL
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\ROBOEX32.DLL
2008-10-13 11:23:03 ----A---- C:\WINDOWS\system32\INETWH32.dll
2008-10-13 11:22:59 ----D---- C:\3com
2008-10-13 10:59:47 ----D---- C:\Program Files\PC Drivers HeadQuarters
2008-10-13 10:59:47 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\PC Drivers HeadQuarters
2008-10-13 10:18:57 ----D---- C:\WINDOWS\Performance
2008-10-13 10:18:46 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft Corporation
2008-10-13 10:18:16 ----D---- C:\Program Files\Microsoft Windows Vista Upgrade Advisor
2008-10-13 00:25:24 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\SiteAdvisor
2008-10-13 00:06:21 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\McAfee
2008-10-12 23:26:23 ----A---- C:\log2.txt
2008-10-12 23:26:23 ----A---- C:\log1.txt
2008-10-12 22:43:37 ----D---- C:\Documents and Settings\Neill\Application Data\True Sword
2008-10-12 22:43:31 ----D---- C:\Program Files\True Sword 5
2008-10-12 15:38:46 ----A---- C:\WINDOWS\1.ini
2008-10-12 15:14:28 ----A---- C:\WINDOWS\system32\locate.com
2008-10-12 15:13:09 ----D---- C:\MGtools
2008-10-12 14:54:45 ----A---- C:\Boot.bak
2008-10-12 14:54:38 ----D---- C:\cmdcons
2008-10-12 14:53:13 ----A---- C:\WINDOWS\zip.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\VFIND.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\SWXCACLS.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\SWSC.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\SWREG.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\sed.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\NIRCMD.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\grep.exe
2008-10-12 14:53:13 ----A---- C:\WINDOWS\fdsv.exe
2008-10-12 14:51:59 ----D---- C:\WINDOWS\ERDNT
2008-10-12 14:51:59 ----D---- C:\Qoobox
2008-10-12 14:26:17 ----D---- C:\Documents and Settings\Neill\Application Data\Malwarebytes
2008-10-12 14:26:13 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-10-12 14:26:13 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Malwarebytes
2008-10-12 13:54:49 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-10-12 13:54:49 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
2008-10-12 12:13:09 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\SUPERAntiSpyware.com
2008-10-12 12:13:04 ----D---- C:\Program Files\SUPERAntiSpyware
2008-10-12 12:13:04 ----D---- C:\Documents and Settings\Neill\Application Data\SUPERAntiSpyware.com
2008-10-12 12:06:42 ----A---- C:\MGtools.exe
2008-10-12 11:50:11 ----D---- C:\Program Files\CCleaner
2008-10-12 11:44:59 ----A---- C:\WINDOWS\system32\javaws.exe
2008-10-12 11:44:59 ----A---- C:\WINDOWS\system32\javaw.exe
2008-10-12 11:44:59 ----A---- C:\WINDOWS\system32\java.exe
2008-10-12 11:44:59 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-10-12 11:16:46 ----A---- C:\Program Files\unst0_0.exe
2008-10-12 11:16:44 ----A---- C:\Program Files\Program Files.ini
2008-10-12 11:02:30 ----D---- C:\Program Files\Uninstall Plus v4.1
2008-10-06 04:37:03 ----D---- C:\Program Files\Common Files\plugin
2008-09-17 09:27:39 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\K7 Computing
2008-09-10 16:32:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464_0$
2008-09-05 09:17:31 ----AD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
2008-09-04 09:09:21 ----N---- C:\WINDOWS\system32\pxsfs.dll
2008-09-04 09:09:21 ----N---- C:\WINDOWS\system32\pxafs.dll
2008-08-26 22:33:45 ----N---- C:\WINDOWS\system32\xmllite.dll
2008-08-26 22:33:34 ----N---- C:\WINDOWS\system32\wmphoto.dll
2008-08-26 22:33:25 ----N---- C:\WINDOWS\system32\wlanapi.dll
2008-08-26 22:33:21 ----N---- C:\WINDOWS\system32\windowscodecsext.dll
2008-08-26 22:33:21 ----N---- C:\WINDOWS\system32\windowscodecs.dll
2008-08-26 22:33:06 ----N---- C:\WINDOWS\system32\tspkg.dll
2008-08-26 22:33:06 ----N---- C:\WINDOWS\system32\tsgqec.dll
2008-08-26 22:32:37 ----N---- C:\WINDOWS\system32\setupn.exe
2008-08-26 22:32:30 ----N---- C:\WINDOWS\system32\rhttpaa.dll
2008-08-26 22:32:27 ----N---- C:\WINDOWS\system32\rasqec.dll
2008-08-26 22:32:26 ----N---- C:\WINDOWS\system32\qutil.dll
2008-08-26 22:32:23 ----N---- C:\WINDOWS\system32\qcliprov.dll
2008-08-26 22:32:23 ----N---- C:\WINDOWS\system32\qagentrt.dll
2008-08-26 22:32:22 ----N---- C:\WINDOWS\system32\qagent.dll
2008-08-26 22:32:20 ----N---- C:\WINDOWS\system32\photometadatahandler.dll
2008-08-26 22:32:14 ----N---- C:\WINDOWS\system32\onex.dll
2008-08-26 22:31:52 ----N---- C:\WINDOWS\system32\napstat.exe
2008-08-26 22:31:52 ----N---- C:\WINDOWS\system32\napmontr.dll
2008-08-26 22:31:52 ----N---- C:\WINDOWS\system32\napipsec.dll
2008-08-26 22:31:43 ----N---- C:\WINDOWS\system32\msshavmsg.dll
2008-08-26 22:31:43 ----N---- C:\WINDOWS\system32\mssha.dll
2008-08-26 22:31:07 ----N---- C:\WINDOWS\system32\mmcperf.exe
2008-08-26 22:31:07 ----N---- C:\WINDOWS\system32\mmcfxcommon.dll
2008-08-26 22:31:07 ----N---- C:\WINDOWS\system32\mmcex.dll
2008-08-26 22:31:07 ----N---- C:\WINDOWS\system32\microsoft.managementconsole.dll
2008-08-26 22:30:39 ----N---- C:\WINDOWS\system32\l2gpstore.dll
2008-08-26 22:30:30 ----N---- C:\WINDOWS\system32\kmsvc.dll
2008-08-26 22:30:30 ----N---- C:\WINDOWS\system32\kbdpash.dll
2008-08-26 22:30:30 ----N---- C:\WINDOWS\system32\kbdnepr.dll
2008-08-26 22:30:30 ----N---- C:\WINDOWS\system32\kbdiultn.dll
2008-08-26 22:30:30 ----N---- C:\WINDOWS\system32\kbdbhc.dll
2008-08-26 22:29:28 ----A---- C:\WINDOWS\005782_.tmp
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eapsvc.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eapqec.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eappprxy.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eapphost.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eappgnui.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eappcfg.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eapp3hst.dll
2008-08-26 22:29:26 ----N---- C:\WINDOWS\system32\eapolqec.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3ui.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3svc.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3msm.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3gpclnt.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3dlg.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3cfg.dll
2008-08-26 22:29:22 ----N---- C:\WINDOWS\system32\dot3api.dll
2008-08-26 22:29:19 ----N---- C:\WINDOWS\system32\dimsroam.dll
2008-08-26 22:29:19 ----N---- C:\WINDOWS\system32\dimsntfy.dll
2008-08-26 22:29:19 ----N---- C:\WINDOWS\system32\dhcpqec.dll
2008-08-26 22:29:16 ----N---- C:\WINDOWS\system32\credssp.dll
2008-08-26 22:29:10 ----N---- C:\WINDOWS\system32\bitsprx4.dll
2008-08-26 22:29:09 ----N---- C:\WINDOWS\system32\azroles.dll
2008-08-26 22:28:59 ----N---- C:\WINDOWS\system32\aaclient.dll
======List of files/folders modified in the last 2 months======
2008-10-20 20:40:08 ----D---- C:\WINDOWS\Temp
2008-10-20 20:36:53 ----D---- C:\WINDOWS\system32\inetsrv
2008-10-20 20:36:07 ----D---- C:\Program Files\Mozilla Firefox
2008-10-20 20:36:03 ----D---- C:\WINDOWS\Prefetch
2008-10-20 20:32:19 ----A---- C:\WINDOWS\SchedLgU.Txt
2008-10-20 20:31:10 ----D---- C:\WINDOWS\system32
2008-10-20 20:26:30 ----SHD---- C:\WINDOWS\Installer
2008-10-20 20:26:20 ----D---- C:\Program Files\Java
2008-10-20 13:49:09 ----D---- C:\Documents and Settings\Neill\Application Data\OpenOffice.org2
2008-10-20 12:03:38 ----D---- C:\WINDOWS\system32\CatRoot2
2008-10-20 11:54:36 ----D---- C:\WINDOWS\system32\drivers
2008-10-20 08:06:07 ----D---- C:\WINDOWS
2008-10-20 00:22:00 ----SD---- C:\Documents and Settings\All Users.WINDOWS\Application Data\Microsoft
2008-10-20 00:20:57 ----D---- C:\Program Files
2008-10-17 00:32:11 ----HD---- C:\WINDOWS\inf
2008-10-17 00:32:08 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-10-16 22:52:51 ----HD---- C:\WINDOWS\$hf_mig$
2008-10-16 14:58:47 ----D---- C:\WINDOWS\Debug
2008-10-15 13:55:33 ----D---- C:\WINDOWS\system32\appmgmt
2008-10-15 13:55:33 ----D---- C:\Documents and Settings
2008-10-15 12:21:48 ----D---- C:\Documents and Settings\All Users.WINDOWS\Application Data\avg8
2008-10-15 12:10:49 ----N---- C:\WINDOWS\system.ini
2008-10-15 12:06:11 ----D---- C:\WINDOWS\AppPatch
2008-10-15 12:06:11 ----D---- C:\Program Files\Common Files
2008-10-15 09:31:56 ----SD---- C:\Documents and Settings\Neill\Application Data\Microsoft
2008-10-15 09:01:28 ----AC---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-10-15 08:58:59 ----D---- C:\WINDOWS\system32\Setup
2008-10-15 08:58:58 ----D---- C:\WINDOWS\system32\wbem
2008-10-15 08:58:58 ----D---- C:\Program Files\Internet Explorer
2008-10-15 08:58:57 ----RSD---- C:\WINDOWS\Fonts
2008-10-15 08:56:06 ----D---- C:\WINDOWS\system32\CatRoot
2008-10-15 08:54:57 ----D---- C:\Program Files\Messenger
2008-10-15 08:54:31 ----D---- C:\WINDOWS\security
2008-10-15 08:50:07 ----D---- C:\WINDOWS\WinSxS
2008-10-15 08:50:01 ----D---- C:\Program Files\Windows Media Player
2008-10-15 08:49:50 ----D---- C:\WINDOWS\ime
2008-10-15 08:49:50 ----D---- C:\WINDOWS\Help
2008-10-15 08:49:42 ----D---- C:\WINDOWS\system32\usmt
2008-10-15 08:49:39 ----D---- C:\WINDOWS\peernet
2008-10-15 08:49:39 ----D---- C:\Program Files\Movie Maker
2008-10-15 08:47:14 ----D---- C:\WINDOWS\system32\Restore
2008-10-15 08:47:14 ----D---- C:\WINDOWS\system32\npp
2008-10-15 08:47:13 ----D---- C:\WINDOWS\mui
2008-10-15 08:47:13 ----D---- C:\WINDOWS\msagent
2008-10-15 08:47:12 ----D---- C:\WINDOWS\srchasst
2008-10-15 08:47:11 ----D---- C:\Program Files\NetMeeting
2008-10-15 08:47:10 ----D---- C:\WINDOWS\system32\Com
2008-10-15 08:47:08 ----D---- C:\Program Files\Windows NT
2008-10-15 08:47:08 ----D---- C:\Program Files\Outlook Express
2008-10-15 08:47:06 ----D---- C:\Program Files\Common Files\System
2008-10-15 08:46:55 ----D---- C:\WINDOWS\system32\oobe
2008-10-15 08:46:54 ----D---- C:\WINDOWS\system
2008-10-15 08:44:44 ----D---- C:\WINDOWS\system32\ReinstallBackups
2008-10-15 08:44:32 ----HDC---- C:\WINDOWS\$NtServicePackUninstall$
2008-10-15 08:41:42 ----D---- C:\WINDOWS\EHome
2008-10-14 22:43:02 ----D---- C:\WINDOWS\Minidump
2008-10-14 10:19:17 ----SD---- C:\WINDOWS\Downloaded Program Files
2008-10-13 21:09:12 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2008-10-13 11:00:41 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-13 11:00:37 ----RSD---- C:\WINDOWS\assembly
2008-10-13 02:24:47 ----AC---- C:\WINDOWS\NeroDigital.ini
2008-10-13 01:04:47 ----SD---- C:\WINDOWS\Tasks
2008-10-12 15:38:02 ----D---- C:\Documents and Settings\Neill\Application Data\Mozilla
2008-10-12 15:24:25 ----D---- C:\Program Files\Mozilla Thunderbird
2008-10-12 15:24:22 ----AC---- C:\WINDOWS\WININIT.INI
2008-10-12 14:58:13 ----D---- C:\WINDOWS\system32\config
2008-10-12 14:56:07 ----D---- C:\Program Files\LogMeIn
2008-10-12 14:54:45 ----RASH---- C:\boot.ini
2008-10-12 14:24:09 ----D---- C:\WINDOWS\wt
2008-10-12 12:12:40 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-12 11:15:09 ----D---- C:\Inetpub
2008-10-12 11:14:09 ----D---- C:\WTK23
2008-10-12 11:14:09 ----D---- C:\WTK22
2008-10-12 11:14:09 ----D---- C:\Temp
2008-10-12 11:14:09 ----D---- C:\Program Files\Winamp
2008-10-12 11:14:09 ----D---- C:\Program Files\SQLyog
2008-10-12 11:14:09 ----D---- C:\Program Files\MUSHclient
2008-10-12 11:14:09 ----D---- C:\Program Files\IsoBuster
2008-10-12 11:14:09 ----D---- C:\Program Files\GameSpy Arcade
2008-10-12 11:14:09 ----D---- C:\PHP
2008-10-12 11:14:09 ----D---- C:\MinGW
2008-10-12 11:14:08 ----D---- C:\cygwin
2008-10-08 08:19:40 ----AC---- C:\WINDOWS\system32\MRT.exe
2008-09-22 09:40:44 ----D---- C:\Games
2008-09-22 09:39:16 ----D---- C:\Program Files\Common Files\InstallShield
2008-09-19 19:43:17 ----D---- C:\Program Files\D-Tools
2008-09-17 19:00:38 ----D---- C:\Program Files\FlashGet
2008-09-05 13:39:30 ----C---- C:\WINDOWS\win.ini
2008-09-04 10:37:39 ----D---- C:\Documents and Settings\Neill\Application Data\Apple Computer
2008-09-04 09:11:11 ----D---- C:\WINDOWS\RegisteredPackages
2008-08-28 20:46:02 ----A---- C:\WINDOWS\system32\win32spl.dll
2008-08-28 20:46:02 ----A---- C:\WINDOWS\system32\msw3prt.dll
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2008-10-15 97928]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2008-10-15 26824]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 prodrv06;StarForce Protection Environment Driver v6; C:\WINDOWS\System32\drivers\prodrv06.sys [2003-10-11 52128]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2002-08-30 12032]
R2 AvgTdiX;AVG Free8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2008-10-15 76040]
R2 enodpl;enodpl; C:\WINDOWS\System32\drivers\enodpl.sys [2003-03-02 7552]
R2 LMIInfo;LogMeIn Kernel Information Provider; \??\C:\Program Files\LogMeIn\RaInfo.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-08-03 11868]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkipx.sys [2008-04-14 88320]
R2 NwlnkNb;NWLink NetBIOS; C:\WINDOWS\system32\DRIVERS\nwlnknb.sys [2002-08-30 63232]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINDOWS\system32\DRIVERS\nwlnkspx.sys [2002-08-30 55936]
R2 tandpl;tandpl; C:\WINDOWS\System32\drivers\tandpl.sys [2003-04-19 4736]
R2 tcaicchg;tcaicchg; \??\C:\WINDOWS\system32\tcaicchg.sys []
R2 TCAITDI;TCAITDI Protocol; C:\WINDOWS\system32\DRIVERS\TCAITDI.sys [2001-09-04 19534]
R3 ati2mtag;ati2mtag; C:\WINDOWS\System32\DRIVERS\ati2mtag.sys [2005-01-20 965632]
R3 EL2000;3Com 3C2000x EtherLink XL Adapter; C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys [2003-06-03 147328]
R3 Envy24HFS;ICE Envy24 Family Audio Controller WDM; C:\WINDOWS\system32\drivers\Envy24HF.sys [2004-11-26 577664]
R3 GEARAspiWDM;GEAR CDRom Filter; C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys [2008-01-29 16168]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 LMImirr;LMImirr; C:\WINDOWS\system32\DRIVERS\LMImirr.sys [2005-12-15 7400]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2002-08-30 12160]
R3 ms_mpu401;Microsoft MPU-401 MIDI UART Driver; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-18 2944]
R3 pfc;Padus ASPI Shell; C:\WINDOWS\system32\drivers\pfc.sys [2003-12-05 10368]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-14 20608]
R3 Winachcf;Winachcf; C:\WINDOWS\system32\DRIVERS\winachcf.sys [2001-08-15 737975]
S3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\System32\DRIVERS\arp1394.sys [2008-04-14 60800]
S3 ctljystk;Creative SBLive! Gameport; C:\WINDOWS\System32\DRIVERS\ctljystk.sys [2001-08-18 3712]
S3 emu10k;Creative SB Live! (WDM); C:\WINDOWS\system32\drivers\emu10k1m.sys [2001-08-18 283904]
S3 emu10k1;Creative Interface Manager Driver (WDM); C:\WINDOWS\system32\drivers\ctlfacem.sys [2001-08-18 6912]
S3 HCF_MSFT;HCF_MSFT; C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys [2001-08-17 907456]
S3 HSF_DP;HSF_DP; C:\WINDOWS\system32\DRIVERS\HSFDPSP2.sys [2004-08-03 1041536]
S3 HSFHWBS2;HSFHWBS2; C:\WINDOWS\system32\DRIVERS\HSFBS2S2.sys [2004-08-03 220032]
S3 ipw_mdfl;Wireless Broadband Modem Filter; C:\WINDOWS\system32\DRIVERS\ipw_mdfl.sys []
S3 ipw_mdm;Wireless Broadband Modem (WDM); C:\WINDOWS\system32\DRIVERS\ipw_mdm.sys []
S3 krdpdre;krdpdre; \??\C:\DOCUME~1\Neill\LOCALS~1\Temp\krdpdre.sys []
S3 NIC1394;1394 Net Driver; C:\WINDOWS\System32\DRIVERS\nic1394.sys [2008-04-14 61824]
S3 nm;Network Monitor Driver; C:\WINDOWS\system32\DRIVERS\NMnt.sys [2008-04-14 40320]
S3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys []
S3 P2k;Motorola USB Device; C:\WINDOWS\system32\DRIVERS\P2k.sys [2005-07-20 36480]
S3 sfman;Creative SoundFont Manager Driver (WDM); C:\WINDOWS\system32\drivers\sfmanm.sys [2001-08-18 36480]
S3 sony_ssm.sys;sony_ssm.sys; \??\C:\DOCUME~1\Neill\LOCALS~1\Temp\sony_ssm.sys []
S3 SONYPVU1;Sony USB Filter Driver (SONYPVU1); C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS [2001-08-17 7552]
S3 usbser;Motorola USB Modem Driver; C:\WINDOWS\system32\DRIVERS\usbser.sys [2008-04-14 26112]
S3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSFCXTS2.sys [2004-08-03 685056]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apache;Apache; C:\Program Files\Apache Group\Apache\Apache.exe [2005-10-18 20545]
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2008-07-10 116040]
R2 avg8emc;AVG Free8 E-mail Scanner; C:\PROGRA~1\AVG\AVG8\avgemc.exe [2008-10-15 875288]
R2 avg8wd;AVG Free8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2008-10-15 231704]
R2 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2007-07-24 229376]
R2 IISADMIN;IIS Admin; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15360]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2008-10-12 147456]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-03-19 335872]
R2 MySQL4;MySQL4; C:\mysql\bin\mysqld-nt --defaults-file=C:\mysql\my.ini MySQL4 []
R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\system32\wdfmgr.exe [2005-01-28 38912]
R2 UserAccess7;SecuROM User Access Service (V7); C:\WINDOWS\system32\UAService7.exe [2007-12-20 122880]
S2 ATI Smart;ATI Smart; C:\WINDOWS\system32\ati2sgag.exe [2005-01-19 516096]
S2 OODefrag;O&O Defrag; C:\WINDOWS\system32\oodag.exe [2002-01-18 263168]
S2 systemdown;Remote Access; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S2 wowsystemcode;Remote TCP/IPv6; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2008-07-10 532264]
S3 MSSQL$SQLEXPRESS;SQL Server (SQLEXPRESS); C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2005-10-14 28768528]
S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2004-10-29 86016]
S3 SQLWriter;SQL Server VSS Writer; C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2005-10-14 87768]
S3 W3SVC;World Wide Web Publishing; C:\WINDOWS\system32\inetsrv\inetinfo.exe [2008-04-14 15360]
S4 Ati HotKey Poller;Ati HotKey Poller; C:\WINDOWS\system32\Ati2evxx.exe [2005-01-20 344064]
S4 LMIMaint;LogMeIn Maintenance Service; C:\Program Files\LogMeIn\RaMaint.exe []
S4 LogMeIn;LogMeIn; C:\Program Files\LogMeIn\LogMeIn.exe [2005-12-15 1610480]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; C:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2005-10-14 45272]
S4 SQLBrowser;SQL Server Browser; C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2005-10-14 239320]
-----------------EOF-----------------