Logfile of random's system information tool 1.05 (written by random/random)
Run by ADMIN at 2008-12-25 08:37:48
Microsoft® Windows Vista™ Home Premium Service Pack 1
System drive C: has 99 GB (65%) free of 153 GB
Total RAM: 3070 MB (75% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:38, on 2008-12-25
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\System32\wpcumi.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Users\ADMIN\Desktop\Clean System\RSIT.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\Trend Micro\HijackThis\ADMIN.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O4 - HKLM\..\Run: [WPCUMI] C:\Windows\system32\WpcUmi.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: &Search - ?p=ZJman000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\wpclsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\cwalsp.dll
O13 - Gopher Prefix:
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files/Turbo%20Pizza/Images/stg_drm.ocx
O16 - DPF: {CC450D71-CC90-424C-8638-1F2DBAC87A54} (ArmHelper Control) - file:///C:/Program%20Files/Pastry%20Passion/Images/armhelper.ocx
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: ContentWatch (CwAltaService20) - ContentWatch, Inc. - C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: stllssvr - Unknown owner - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
--
End of file - 5568 bytes
======Scheduled tasks folder======
C:\Windows\tasks\User_Feed_Synchronization-{5ABF9491-355D-425D-982E-507CAA06DBC9}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll [2006-01-12 63128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}]
Spybot-S&D IE Protection - C:\PROGRA~1\SPYBOT~1\SDHelper.dll [2008-09-15 1562960]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll [2008-02-22 509328]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"WPCUMI"=C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2008-11-26 81000]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2008-12-04 1809648]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cwcptray]
C:\Program Files\ContentWatch\Internet Protection\cwtray.exe [2007-10-17 403456]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\FullScreen]
c:\hp\bin\spawn.exe [2000-04-08 28672]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\hpsysdrv]
c:\hp\support\hpsysdrv.exe [2006-09-28 65536]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Mouse Suite 98 Daemon]
C:\Windows\system32\ICO.EXE [2006-10-23 56128]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\Windows\system32\NvCpl.dll [2007-11-06 8530464]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\Windows\system32\NvMcTray.dll [2007-11-06 81920]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvSvc]
C:\Windows\system32\nvsvc.dll [2007-11-06 86016]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ProcessLogger]
c:\hp\bin\ProcessLogger /m:1000 /v []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2007-10-25 4702208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe [2008-09-16 1833296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe [2008-02-22 144784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2006-03-30 313472]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WPCUMI]
C:\Windows\system32\WpcUmi.exe [2006-11-02 176128]
C:\Users\ADMIN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
ERUNT AutoBackup.lnk - C:\Program Files\ERUNT\AUTOBACK.EXE
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-03 352256]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\PSEXESVC]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\PSEXESVC]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"LogonHoursAction"=2
"DontDisplayLogonHoursWarnings"=1
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{a4959ca6-813c-11dd-b209-806e6f6e6963}]
shell\AutoRun\command - D:\Launch.exe
======List of files/folders created in the last 3 months======
2008-12-25 08:37:48 ----D---- C:\rsit
2008-12-22 21:41:56 ----D---- C:\inetpub
2008-12-22 21:22:35 ----D---- C:\Windows\Minidump
2008-12-22 21:15:25 ----A---- C:\Windows\PSEXESVC.EXE
2008-12-22 21:15:15 ----D---- C:\Windows\temp
2008-12-22 21:13:28 ----D---- C:\ComboFix
2008-12-22 21:13:27 ----A---- C:\Windows\system32\CF349.exe
2008-12-22 21:13:23 ----A---- C:\Windows\system32\swsc.exe
2008-12-22 20:37:58 ----A---- C:\Windows\zip.exe
2008-12-22 20:37:58 ----A---- C:\Windows\VFIND.exe
2008-12-22 20:37:58 ----A---- C:\Windows\SWXCACLS.exe
2008-12-22 20:37:58 ----A---- C:\Windows\SWSC.exe
2008-12-22 20:37:58 ----A---- C:\Windows\SWREG.exe
2008-12-22 20:37:58 ----A---- C:\Windows\sed.exe
2008-12-22 20:37:58 ----A---- C:\Windows\NIRCMD.exe
2008-12-22 20:37:58 ----A---- C:\Windows\grep.exe
2008-12-22 20:37:58 ----A---- C:\Windows\fdsv.exe
2008-12-22 20:37:52 ----D---- C:\Qoobox
2008-12-21 21:25:21 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2008-12-21 21:25:02 ----D---- C:\Users\ADMIN\AppData\Roaming\SUPERAntiSpyware.com
2008-12-21 21:25:02 ----D---- C:\Program Files\SUPERAntiSpyware
2008-12-21 09:08:57 ----D---- C:\Program Files\Trend Micro
2008-12-21 03:00:22 ----A---- C:\Windows\system32\mshtml.dll
2008-12-20 20:51:25 ----D---- C:\Users\ADMIN\AppData\Roaming\Malwarebytes
2008-12-20 20:51:21 ----D---- C:\ProgramData\Malwarebytes
2008-12-20 20:51:21 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2008-12-20 20:50:17 ----D---- C:\Windows\ERDNT
2008-12-20 20:49:21 ----D---- C:\Program Files\ERUNT
2008-12-20 19:30:10 ----A---- C:\Windows\system32\aswBoot.exe
2008-12-20 18:28:37 ----D---- C:\Windows\E80F62FF5D3C4A1984099721F2928206.TMP
2008-12-20 18:21:22 ----D---- C:\ProgramData\PCSettings
2008-12-20 18:21:20 ----D---- C:\ProgramData\Norton
2008-12-20 18:09:53 ----D---- C:\ProgramData\NortonInstaller
2008-12-20 12:56:59 ----D---- C:\Program Files\Alwil Software
2008-12-10 03:02:06 ----A---- C:\Windows\system32\tzres.dll
2008-12-09 16:17:15 ----A---- C:\Windows\system32\urlmon.dll
2008-12-09 16:17:14 ----A---- C:\Windows\system32\wininet.dll
2008-12-09 16:17:14 ----A---- C:\Windows\system32\mstime.dll
2008-12-09 16:17:14 ----A---- C:\Windows\system32\ieframe.dll
2008-12-09 16:17:13 ----A---- C:\Windows\system32\jsproxy.dll
2008-12-09 16:17:13 ----A---- C:\Windows\system32\iertutil.dll
2008-12-09 16:16:53 ----A---- C:\Windows\system32\WMVCORE.DLL
2008-12-09 16:16:53 ----A---- C:\Windows\system32\mf.dll
2008-12-09 16:16:52 ----A---- C:\Windows\system32\WMNetMgr.dll
2008-12-09 16:16:52 ----A---- C:\Windows\system32\logagent.exe
2008-12-09 16:16:33 ----A---- C:\Windows\system32\shell32.dll
2008-12-09 16:16:29 ----A---- C:\Windows\explorer.exe
2008-12-09 16:12:30 ----A---- C:\Windows\system32\gdi32.dll
2008-12-09 16:12:19 ----A---- C:\Windows\system32\Apphlpdm.dll
2008-12-09 16:12:18 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2008-11-25 16:54:36 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2008-11-25 16:54:28 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2008-11-25 16:54:27 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2008-11-25 16:54:27 ----A---- C:\Windows\system32\WindowsCodecs.dll
2008-11-25 16:54:21 ----A---- C:\Windows\system32\connect.dll
2008-11-14 06:40:49 ----A---- C:\Windows\system32\wups2.dll
2008-11-14 06:40:49 ----A---- C:\Windows\system32\wucltux.dll
2008-11-14 06:40:49 ----A---- C:\Windows\system32\wuaueng.dll
2008-11-14 06:40:49 ----A---- C:\Windows\system32\wuauclt.exe
2008-11-14 06:40:43 ----A---- C:\Windows\system32\wups.dll
2008-11-14 06:40:42 ----A---- C:\Windows\system32\wudriver.dll
2008-11-14 06:40:42 ----A---- C:\Windows\system32\wuapi.dll
2008-11-14 06:40:41 ----A---- C:\Windows\system32\wuwebv.dll
2008-11-14 06:40:41 ----A---- C:\Windows\system32\wuapp.exe
2008-11-13 07:14:55 ----D---- C:\World of Warcraft
2008-11-12 18:49:29 ----A---- C:\Windows\system32\msxml3.dll
2008-11-12 18:49:19 ----A---- C:\Windows\system32\msxml6.dll
2008-11-08 17:38:12 ----D---- C:\ProgramData\Blizzard
2008-10-31 14:22:00 ----A---- C:\Windows\system32\EncDec.dll
2008-10-31 14:21:59 ----A---- C:\Windows\system32\psisdecd.dll
2008-10-29 06:53:21 ----A---- C:\Windows\system32\wersvc.dll
2008-10-29 06:53:21 ----A---- C:\Windows\system32\Faultrep.dll
2008-10-29 06:53:13 ----A---- C:\Windows\system32\win32spl.dll
2008-10-23 21:47:02 ----A---- C:\Windows\system32\netapi32.dll
2008-10-15 21:42:01 ----A---- C:\Windows\system32\ntoskrnl.exe
2008-10-15 21:42:01 ----A---- C:\Windows\system32\ntkrnlpa.exe
2008-10-11 11:02:05 ----D---- C:\Windows\Sun
2008-10-10 19:42:12 ----D---- C:\ProgramData\Spybot - Search & Destroy
2008-10-10 19:42:12 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-10-01 17:43:31 ----D---- C:\Users\ADMIN\AppData\Roaming\Leadertech
2008-10-01 17:42:57 ----D---- C:\Program Files\Disney Interactive
2008-10-01 17:42:30 ----A---- C:\Windows\disney.ini
2008-09-30 16:43:34 ----A---- C:\Windows\system32\msxml4.dll
======List of files/folders modified in the last 3 months======
2008-12-25 08:37:59 ----D---- C:\Windows\Prefetch
2008-12-25 08:32:51 ----D---- C:\Windows\System32
2008-12-25 08:32:51 ----D---- C:\Windows\inf
2008-12-25 08:32:51 ----A---- C:\Windows\system32\PerfStringBackup.INI
2008-12-22 22:23:13 ----RSD---- C:\Windows\assembly
2008-12-22 22:23:13 ----D---- C:\Windows\Microsoft.NET
2008-12-22 22:21:29 ----D---- C:\Windows\rescache
2008-12-22 22:15:22 ----SHD---- C:\System Volume Information
2008-12-22 22:15:22 ----D---- C:\Windows\Logs
2008-12-22 22:06:26 ----D---- C:\Windows\winsxs
2008-12-22 22:05:55 ----D---- C:\Windows\system32\inetsrv
2008-12-22 22:04:08 ----D---- C:\Windows\system32\en-US
2008-12-22 22:04:08 ----D---- C:\Windows\system32\0409
2008-12-22 21:43:05 ----D---- C:\Windows
2008-12-22 21:42:00 ----D---- C:\Windows\system32\wbem
2008-12-22 21:42:00 ----D---- C:\Windows\system32\migration
2008-12-22 21:42:00 ----D---- C:\Windows\system32\drivers
2008-12-22 21:37:15 ----SHD---- C:\Windows\Installer
2008-12-22 21:35:22 ----RD---- C:\Program Files
2008-12-22 21:35:22 ----D---- C:\Program Files\Internet Explorer
2008-12-22 21:15:27 ----A---- C:\Windows\system.ini
2008-12-22 21:14:41 ----D---- C:\Windows\AppPatch
2008-12-22 21:14:41 ----D---- C:\Program Files\Common Files
2008-12-22 20:39:56 ----SD---- C:\Windows\Downloaded Program Files
2008-12-22 19:36:30 ----D---- C:\Windows\Debug
2008-12-21 21:25:21 ----HD---- C:\ProgramData
2008-12-21 21:25:13 ----SD---- C:\Users\ADMIN\AppData\Roaming\Microsoft
2008-12-21 21:24:29 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2008-12-21 17:53:11 ----D---- C:\Program Files\Warcraft III
2008-12-21 03:00:32 ----D---- C:\Windows\system32\catroot
2008-12-21 03:00:31 ----D---- C:\Windows\system32\catroot2
2008-12-20 20:47:33 ----D---- C:\Windows\system32\restore
2008-12-20 18:47:46 ----D---- C:\Program Files\Norton Security Scan
2008-12-20 18:43:07 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-12-20 18:28:36 ----D---- C:\Program Files\Symantec
2008-12-20 18:28:32 ----D---- C:\ProgramData\Symantec
2008-12-20 18:22:39 ----D---- C:\Windows\Tasks
2008-12-20 17:16:13 ----D---- C:\Program Files\Yahoo!
2008-12-20 17:13:34 ----D---- C:\Users\ADMIN\AppData\Roaming\Move Networks
2008-12-10 03:08:35 ----D---- C:\Program Files\Windows Mail
2008-12-02 15:26:30 ----A---- C:\Windows\system32\mrt.exe
2008-11-11 20:13:20 ----A---- C:\Windows\ntbtlog.txt
2008-11-08 17:54:58 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
2008-11-01 02:00:19 ----D---- C:\Windows\ehome
2008-10-11 10:33:08 ----D---- C:\Windows\Registration
2008-10-11 10:29:58 ----D---- C:\Windows\system32\Tasks
2008-10-01 17:46:50 ----HD---- C:\Program Files\InstallShield Installation Information
2008-10-01 17:43:21 ----RSD---- C:\Windows\Fonts
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 aswRdr;aswRdr; C:\Windows\system32\drivers\aswRdr.sys [2008-11-26 23152]
R1 aswSP;avast! Self Protection; C:\Windows\system32\drivers\aswSP.sys [2008-11-26 111184]
R1 aswTdi;avast! Network Shield Support; C:\Windows\system32\drivers\aswTdi.sys [2008-11-26 50864]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [2008-12-04 8944]
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys [2008-12-04 55024]
R2 aswFsBlk;aswFsBlk; C:\Windows\system32\DRIVERS\aswFsBlk.sys [2008-11-26 20560]
R2 aswMonFlt;aswMonFlt; C:\Windows\system32\DRIVERS\aswMonFlt.sys [2008-11-26 51792]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-05-07 767488]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-10-25 2015192]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-05-04 1065384]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2007-11-06 8230496]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS [2008-12-04 7408]
S3 catchme;catchme; \??\C:\Users\ADMIN\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-18 5632]
S3 EagleNT;EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [2008-05-13 448384]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-18 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-18 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-18 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-18 6016]
S3 pelmouse;Mouse Suite Driver; C:\Windows\system32\DRIVERS\pelmouse.sys [2007-04-17 18944]
S3 pelusblf;USB Mouse Low Filter Driver; C:\Windows\system32\DRIVERS\pelusblf.sys [2007-04-11 17920]
S3 SymIMMP;SymIMMP; C:\Windows\system32\DRIVERS\SymIM.sys []
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2008-01-19 39936]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-18 83328]
S4 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\drivers\wmiacpi.sys [2006-11-02 11264]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2008-11-26 18752]
R2 Automatic LiveUpdate Scheduler;Automatic LiveUpdate Scheduler; C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe [2008-02-09 238968]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2008-11-26 155160]
R2 CwAltaService20;ContentWatch; C:\Program Files\ContentWatch\Internet Protection\cwsvc.exe [2007-10-17 1223168]
R2 LightScribeService;LightScribeService Direct Disc Labeling Service; c:\Program Files\Common Files\LightScribe\LSSrvc.exe [2006-10-19 61440]
R2 SBSDWSCService;SBSD Security Center Service; C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
S3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2008-11-26 254040]
S3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2008-11-26 352920]
S3 IDriverT;InstallDriver Table Manager; c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728]
S3 LiveUpdate;LiveUpdate; C:\Program Files\Symantec\LiveUpdate\LuComServer_3_4.EXE [2008-08-04 3220856]
S3 stllssvr;stllssvr; c:\Program Files\Common Files\SureThing Shared\stllssvr.exe []
-----------------EOF-----------------
Thanks again for your help!!