I cannot ever get rid of these lines when in normal mode, but they don't seem to appear when I boot in Safe Mode.
Here are the logs
log.txt: Logfile of random's system information tool 1.05 (written by random/random)
Run by Jason at 2009-02-07 23:53:58
Microsoft Windows XP Professional Service Pack 3
System drive C: has 92 GB (80%) free of 114 GB
Total RAM: 511 MB (20% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:54:07, on 07/02/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.20815)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\LClock\LClock.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Styler\Styler.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Jason\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\Jason.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://uk.yahoo.com/?p=usR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft....k/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft....k/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft....k/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft....k/?LinkId=69157O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll
O4 - HKLM\..\Run: [LClock] C:\Program Files\LClock\LClock.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')
O4 - Startup: Styler.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 6293 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}]
Groove GFS Browser Helper - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-17 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-17 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-17 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - StylerToolBar - C:\Program Files\Styler\TB\StylerTB.dll [2006-05-02 102400]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LClock"=C:\Program Files\LClock\LClock.exe [2004-09-19 65536]
"UnlockerAssistant"=C:\Program Files\Unlocker\UnlockerAssistant.exe [2006-09-07 15872]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-17 136600]
"avast!"=C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe [2007-12-04 79224]
"GrooveMonitor"=C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [2006-10-27 31016]
"CTHelper"=C:\WINDOWS\CTHELPER.EXE [2006-08-11 17920]
"CTxfiHlp"=C:\WINDOWS\system32\CTXFIHLP.EXE [2006-08-11 18944]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"Sidebar"=C:\Program Files\Windows Sidebar\sidebar.exe [2008-03-22 1271808]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-01-24 1830128]
C:\Documents and Settings\Jason\Start Menu\Programs\Startup
Styler.lnk - C:\Documents and Settings\Jason\Application Data\Microsoft\Installer\{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}\_585b207a.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-06-19 236928]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
"{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL [2006-10-27 2210608]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\Microsoft Office\Office12\GROOVE.EXE"="C:\Program Files\Microsoft Office\Office12\GROOVE.EXE:*:Enabled:Microsoft Office Groove"
"C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2009-02-07 23:53:58 ----D---- C:\rsit
2009-02-07 11:40:50 ----A---- C:\WINDOWS\ntbtlog.txt
2009-02-02 22:18:49 ----D---- C:\Program Files\Guild Wars
2009-01-31 13:58:20 ----D---- C:\Program Files\Trend Micro
2009-01-25 20:33:42 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-01-25 20:32:54 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-01-25 20:32:18 ----D---- C:\Program Files\Common Files\Adobe
2009-01-25 20:32:18 ----D---- C:\Program Files\Adobe
2009-01-25 20:24:20 ----D---- C:\Program Files\NOS
2009-01-25 20:24:20 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-01-18 11:32:20 ----D---- C:\WINDOWS\Sun
2009-01-18 01:08:16 ----A---- C:\WINDOWS\{00000002-00000000-00000000-00001102-00000004-10031102}.BAK
2009-01-18 01:04:15 ----D---- C:\WINDOWS\system32\Defaults
2009-01-18 01:03:19 ----A---- C:\WINDOWS\system32\wrap_oal.dll
2009-01-18 01:03:19 ----A---- C:\WINDOWS\system32\OpenAL32.dll
2009-01-18 01:03:14 ----D---- C:\Documents and Settings\Jason\Application Data\Creative
2009-01-18 01:02:53 ----D---- C:\WINDOWS\system32\Data
2009-01-18 01:02:53 ----A---- C:\WINDOWS\system32\instwdm.ini
2009-01-18 01:02:53 ----A---- C:\WINDOWS\system32\ctzapxx.ini
2009-01-18 01:02:53 ----A---- C:\WINDOWS\INRES.DLL
2009-01-18 01:02:53 ----A---- C:\WINDOWS\CTXFIRES.DLL
2009-01-18 01:02:53 ----A---- C:\WINDOWS\CTDCRES.DLL
2009-01-18 01:02:52 ----D---- C:\Program Files\Creative
2009-01-18 01:02:32 ----HD---- C:\Program Files\InstallShield Installation Information
2009-01-18 01:02:26 ----D---- C:\Program Files\Common Files\InstallShield
2009-01-18 00:40:39 ----D---- C:\Documents and Settings\Jason\Application Data\Macromedia
2009-01-18 00:39:39 ----D---- C:\Documents and Settings\Jason\Application Data\Adobe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\javaws.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\javaw.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\java.exe
2009-01-17 00:27:01 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-01-16 21:18:30 ----SHD---- C:\RECYCLER
2009-01-16 20:24:46 ----D---- C:\Program Files\Xilisoft
2009-01-16 20:14:46 ----D---- C:\Documents and Settings\Jason\Application Data\vlc
2009-01-16 20:14:06 ----D---- C:\Program Files\VideoLAN
2009-01-16 20:13:43 ----D---- C:\Program Files\CCleaner
2009-01-16 20:11:53 ----D---- C:\Program Files\VS Revo Group
2009-01-16 20:06:39 ----A---- C:\WINDOWS\system32\msonpmon.dll
2009-01-16 20:04:54 ----D---- C:\Program Files\Microsoft Works
2009-01-16 20:04:44 ----D---- C:\Program Files\MSBuild
2009-01-16 20:04:24 ----D---- C:\Program Files\Microsoft Visual Studio
2009-01-16 20:04:24 ----D---- C:\Program Files\Common Files\DESIGNER
2009-01-16 20:01:05 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00:39 ----D---- C:\Program Files\SUPERAntiSpyware
2009-01-16 20:00:39 ----D---- C:\Documents and Settings\Jason\Application Data\SUPERAntiSpyware.com
2009-01-16 20:00:38 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-01-16 20:00:27 ----A---- C:\WINDOWS\system32\MSSTDFMT.DLL
2009-01-16 20:00:26 ----D---- C:\Program Files\SpywareBlaster
2009-01-16 19:59:45 ----D---- C:\WINDOWS\SHELLNEW
2009-01-16 19:59:23 ----D---- C:\Program Files\Microsoft Office
2009-01-16 19:59:23 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2009-01-16 19:59:02 ----RHD---- C:\MSOCache
2009-01-16 19:57:08 ----D---- C:\WINDOWS\system32\PreInstall
2009-01-16 19:57:07 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2009-01-16 19:57:07 ----HD---- C:\WINDOWS\$hf_mig$
2009-01-16 19:23:48 ----D---- C:\Program Files\Lavasoft
2009-01-16 19:23:47 ----D---- C:\Documents and Settings\All Users\Application Data\Lavasoft
2009-01-16 19:23:30 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-01-16 19:18:11 ----D---- C:\WINDOWS\system32\NtmsData
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MSVCR71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MSVCP71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\MFC71.dll
2009-01-16 18:53:46 ----A---- C:\WINDOWS\system32\aswBoot.exe
2009-01-16 18:53:41 ----D---- C:\Program Files\Alwil Software
2009-01-16 18:51:39 ----D---- C:\Documents and Settings\Jason\Application Data\Styler
2009-01-16 18:51:23 ----D---- C:\Documents and Settings\Jason\Application Data\Identities
2009-01-16 18:51:21 ----HD---- C:\Program Files\Uninstall Information
2009-01-16 18:50:19 ----D---- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
2009-01-16 18:50:10 ----ASH---- C:\Documents and Settings\Jason\Application Data\desktop.ini
2009-01-16 18:50:03 ----SD---- C:\Documents and Settings\Jason\Application Data\Microsoft
2009-01-16 18:50:03 ----D---- C:\Documents and Settings\Jason\Application Data\WinRAR
2009-01-16 18:50:03 ----D---- C:\Documents and Settings\Jason\Application Data\Sun
2009-01-16 18:49:12 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2009-01-16 18:39:28 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-16 18:39:15 ----SD---- C:\WINDOWS\system32\Microsoft
2009-01-16 18:39:15 ----D---- C:\WINDOWS\Prefetch
2009-01-16 18:39:15 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-16 18:37:47 ----N---- C:\WINDOWS\system32\spmsg.dll
2009-01-16 18:37:46 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2009-01-16 18:37:35 ----A---- C:\WINDOWS\system32\wmpns.dll
2009-01-16 18:37:32 ----D---- C:\Program Files\Windows Media Connect 2
2009-01-16 18:37:26 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2009-01-16 18:36:59 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2009-01-16 18:36:40 ----D---- C:\WINDOWS\system32\LogFiles
2009-01-16 18:36:37 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2009-01-16 18:35:41 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2009-01-16 18:35:29 ----D---- C:\Program Files\Alky for Applications
2009-01-16 18:34:42 ----D---- C:\Program Files\Kristanix
2009-01-16 18:34:41 ----D---- C:\WINDOWS\Resource Hacker 3.4.0
2009-01-16 18:34:41 ----D---- C:\Program Files\Resource Hacker 3.4.0
2009-01-16 18:33:51 ----D---- C:\Program Files\Java
2009-01-16 18:33:50 ----D---- C:\Program Files\Common Files\Java
2009-01-16 18:27:30 ----A---- C:\WINDOWS\control.ini
2009-01-16 18:27:30 ----A---- C:\AUTOEXEC.BAT
2009-01-16 18:27:18 ----A---- C:\WINDOWS\OEWABLog.txt
2009-01-16 18:27:13 ----D---- C:\WINDOWS\system32\dllcache
2009-01-16 18:27:13 ----A---- C:\WINDOWS\system32\mapi32.dll
2009-01-16 18:26:14 ----RAH---- C:\WINDOWS\system32\logonui.exe.manifest
2009-01-16 18:26:09 ----RAH---- C:\WINDOWS\system32\cdplayer.exe.manifest
2009-01-16 18:26:04 ----HD---- C:\Program Files\WindowsUpdate
2009-01-16 18:25:59 ----D---- C:\Program Files\Online Services
2009-01-16 18:25:45 ----A---- C:\WINDOWS\system32\desktop.ini
2009-01-16 18:25:45 ----A---- C:\WINDOWS\system32\atrace.dll
2009-01-16 18:25:45 ----A---- C:\WINDOWS\desktop.ini
2009-01-16 18:25:41 ----A---- C:\WINDOWS\system32\acctres.dll
2009-01-16 18:25:40 ----D---- C:\Program Files\Common Files\Services
2009-01-16 18:25:38 ----SD---- C:\WINDOWS\Tasks
2009-01-16 18:25:38 ----A---- C:\WINDOWS\system32\icfgnt5.dll
2009-01-16 18:25:37 ----D---- C:\Program Files\Common Files\MSSoap
2009-01-16 18:25:34 ----D---- C:\WINDOWS\srchasst
2009-01-16 18:25:33 ----D---- C:\WINDOWS\system32\Macromed
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuweb.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wups.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wucltui.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauserv.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng1.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng.dll.wusetup.633250.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaueng.dll
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuaucpl.cpl.wusetup.633187.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt1.exe
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt.exe.wusetup.633078.bak
2009-01-16 18:25:31 ----A---- C:\WINDOWS\system32\wuauclt.exe
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\wuapi.dll.wusetup.633015.bak
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\wuapi.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\qmgrprxy.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\qmgr.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx4.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx3.dll
2009-01-16 18:25:30 ----A---- C:\WINDOWS\system32\bitsprx2.dll
2009-01-16 18:25:27 ----D---- C:\Program Files\Movie Maker
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrslv.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrdm.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\safrcdlg.dll
2009-01-16 18:25:11 ----A---- C:\WINDOWS\system32\racpldlg.dll
2009-01-16 18:25:07 ----D---- C:\WINDOWS\system32\Restore
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srsvc.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srrstr.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\srclient.dll
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\fltMc.exe
2009-01-16 18:25:07 ----A---- C:\WINDOWS\system32\fltlib.dll
2009-01-16 18:25:06 ----A---- C:\WINDOWS\system32\msoert2.dll
2009-01-16 18:25:06 ----A---- C:\WINDOWS\system32\msoeacct.dll
2009-01-16 18:25:05 ----A---- C:\WINDOWS\system32\inetres.dll
2009-01-16 18:25:05 ----A---- C:\WINDOWS\system32\inetcomm.dll
2009-01-16 18:25:04 ----D---- C:\Program Files\Outlook Express
2009-01-16 18:25:04 ----A---- C:\WINDOWS\system32\schedsvc.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\mstinit.exe
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\mstask.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\isign32.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\inetcfg.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\icwphbk.dll
2009-01-16 18:25:03 ----A---- C:\WINDOWS\system32\icwdial.dll
2009-01-16 18:24:58 ----D---- C:\Program Files\Common Files\System
2009-01-16 18:24:18 ----D---- C:\Program Files\ComPlus Applications
2009-01-16 18:24:16 ----A---- C:\WINDOWS\vbaddin.ini
2009-01-16 18:24:16 ----A---- C:\WINDOWS\vb.ini
2009-01-16 18:24:12 ----D---- C:\WINDOWS\Registration
2009-01-16 18:24:04 ----D---- C:\Program Files\Windows Media Player
2009-01-16 18:23:56 ----A---- C:\WINDOWS\system32\advpack.dll.mui
2009-01-16 18:23:53 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-01-16 18:23:53 ----RD---- C:\WINDOWS\Offline Web Pages
2009-01-16 18:23:53 ----A---- C:\WINDOWS\system32\winfxdocobj.exe
2009-01-16 18:23:52 ----A---- C:\WINDOWS\system32\msfeedssync.exe
2009-01-16 18:23:51 ----D---- C:\WINDOWS\wbem
2009-01-16 18:23:51 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2009-01-16 18:23:50 ----A---- C:\WINDOWS\system32\ieframe.dll.mui
2009-01-16 18:23:48 ----D---- C:\Program Files\Internet Explorer
2009-01-16 18:21:54 ----D---- C:\Program Files\VistaExperience.org
2009-01-16 18:20:09 ----D---- C:\Program Files\Windows Sidebar
2009-01-16 18:20:00 ----D---- C:\Program Files\Styler
2009-01-16 18:19:44 ----A---- C:\WINDOWS\system32\msvcr80.dll
2009-01-16 18:19:43 ----A---- C:\WINDOWS\system32\engine.dll
2009-01-16 18:19:41 ----D---- C:\Program Files\Desktop
2009-01-16 18:19:40 ----A---- C:\WINDOWS\system32\CabTool.exe
2009-01-16 18:18:53 ----D---- C:\Program Files\WinRAR
2009-01-16 18:18:45 ----D---- C:\Program Files\LClock
2009-01-16 18:18:43 ----D---- C:\Program Files\HashTab Shell Extension
2009-01-16 18:18:42 ----D---- C:\Program Files\Unlocker
2009-01-16 18:18:42 ----D---- C:\Program Files\Microsoft PowerToys
2009-01-16 18:18:42 ----A---- C:\WINDOWS\system32\write.exe
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\sndvol32.exe
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\hticons.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avwav.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avtapi.dll
2009-01-16 18:18:41 ----A---- C:\WINDOWS\system32\avmeter.dll
2009-01-16 18:18:40 ----A---- C:\WINDOWS\system32\winchat.exe
2009-01-16 18:18:39 ----A---- C:\WINDOWS\system32\getuname.dll
2009-01-16 18:18:39 ----A---- C:\WINDOWS\system32\charmap.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\usrlogon.cmd
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tsshutdn.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tslabels.ini
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tskill.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tsdiscon.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\tscon.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\shadow.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\rwinsta.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\reset.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\regini.exe
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\rdpcfgex.dll
2009-01-16 18:18:38 ----A---- C:\WINDOWS\system32\calc.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\qwinsta.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\qappsrv.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\msg.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\msdtcprf.ini
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\logoff.exe
2009-01-16 18:18:37 ----A---- C:\WINDOWS\system32\cdmodem.dll
2009-01-16 18:18:33 ----A---- C:\WINDOWS\system32\wmimgmt.msc
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\mplay32.exe
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\hypertrm.dll
2009-01-16 18:18:32 ----A---- C:\WINDOWS\system32\accwiz.exe
2009-01-16 18:18:31 ----D---- C:\WINDOWS\system32\en-US
2009-01-16 18:18:31 ----D---- C:\Program Files\Windows NT
2009-01-16 18:18:31 ----A---- C:\WINDOWS\system32\mspaint.exe
2009-01-16 18:18:31 ----A---- C:\WINDOWS\system32\clipbrd.exe
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\tsgqec.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\tscfgwmi.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\rhttpaa.dll
2009-01-16 18:18:30 ----A---- C:\WINDOWS\system32\aaclient.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\termsrv.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\sessmgr.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\remotepg.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdshost.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdsaddin.exe
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\rdchost.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\mstscax.dll
2009-01-16 18:18:29 ----A---- C:\WINDOWS\system32\mstsc.exe
2009-01-16 18:18:28 ----D---- C:\WINDOWS\system32\MsDtc
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpwsx.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpsnd.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\rdpclip.exe
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\qprocess.exe
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\mtxoci.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\msdtcuiu.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\msdtcprx.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\icaapi.dll
2009-01-16 18:18:28 ----A---- C:\WINDOWS\system32\cfgbkend.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\xolehlp.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtctm.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtclog.dll
2009-01-16 18:18:27 ----A---- C:\WINDOWS\system32\msdtc.exe
2009-01-16 18:18:26 ----D---- C:\WINDOWS\system32\Com
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\stclient.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxlegih.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxex.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\mtxdm.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\dcomcnfg.exe
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\comrepl.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\comaddin.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\colbact.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\clbcatex.dll
2009-01-16 18:18:26 ----A---- C:\WINDOWS\system32\catsrvps.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comuid.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comsvcs.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\comsnap.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\clbcatq.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\catsrvut.dll
2009-01-16 18:18:25 ----A---- C:\WINDOWS\system32\catsrv.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\servdeps.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\mmfutil.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\licwmi.dll
2009-01-16 18:18:20 ----A---- C:\WINDOWS\system32\cmprops.dll
2009-01-16 18:15:00 ----A---- C:\WINDOWS\system32\h323log.txt
2009-01-16 17:59:59 ----A---- C:\WINDOWS\system32\ksuser.dll
2009-01-16 17:59:03 ----A---- C:\WINDOWS\system32\ativvaxx.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati3duag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati3d1ag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati2dvag.dll
2009-01-16 17:59:02 ----A---- C:\WINDOWS\system32\ati2cqag.dll
2009-01-16 17:58:31 ----A---- C:\WINDOWS\system32\usbui.dll
2009-01-16 17:56:28 ----A---- C:\WINDOWS\imsins.BAK
2009-01-16 17:56:25 ----SHD---- C:\WINDOWS\Installer
2009-01-16 17:56:25 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-01-16 17:56:24 ----D---- C:\Program Files\Common Files\ODBC
2009-01-16 17:56:24 ----A---- C:\WINDOWS\ODBCINST.INI
2009-01-16 17:56:21 ----D---- C:\Program Files\Common Files\SpeechEngines
2009-01-16 17:56:20 ----RD---- C:\Program Files
2009-01-16 17:56:20 ----D---- C:\Program Files\Common Files\Microsoft Shared
2009-01-16 17:56:20 ----D---- C:\Program Files\Common Files
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2009-01-16 17:56:17 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdur.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdru.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2009-01-16 17:56:15 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2009-01-16 17:56:13 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2009-01-16 17:56:12 ----RA---- C:\WINDOWS\system32\kbdest.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdro.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2009-01-16 17:56:10 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\irclass.dll
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\dgsetup.dll
2009-01-16 17:56:05 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2009-01-16 17:56:04 ----A---- C:\WINDOWS\system32\spxcoins.dll
2009-01-16 17:56:04 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2009-01-16 17:56:02 ----N---- C:\WINDOWS\system32\CONFIG.TMP
2009-01-16 17:56:02 ----A---- C:\WINDOWS\TASKMAN.EXE
2009-01-16 17:56:01 ----A---- C:\WINDOWS\system32\storprop.dll
2009-01-16 17:56:01 ----A---- C:\WINDOWS\system32\batt.dll
2009-01-16 17:56:01 ----A---- C:\WINDOWS\NOTEPAD.EXE
2009-01-16 17:55:52 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2009-01-16 17:55:44 ----RA---- C:\WINDOWS\SET8.tmp
2009-01-16 17:55:41 ----RA---- C:\WINDOWS\SET4.tmp
2009-01-16 17:55:40 ----RA---- C:\WINDOWS\SET3.tmp
2009-01-16 17:55:35 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-16 17:55:35 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-16 17:55:29 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2009-01-16 17:55:15 ----A---- C:\WINDOWS\setuplog.txt
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\NicInst.dll
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\NicCo2.dll
2009-01-16 17:54:02 ----A---- C:\WINDOWS\system32\e100bmsg.dll
2009-01-16 17:53:28 ----D---- C:\Documents and Settings
2009-01-16 17:53:27 ----SHD---- C:\System Volume Information
2009-01-16 17:53:02 ----SH---- C:\boot.ini
2009-01-16 17:49:39 ----RSD---- C:\WINDOWS\Fonts
2009-01-16 17:49:39 ----RD---- C:\WINDOWS\Web
2009-01-16 17:49:39 ----HD---- C:\WINDOWS\inf
2009-01-16 17:49:39 ----D---- C:\WINDOWS\WinSxS
2009-01-16 17:49:39 ----D---- C:\WINDOWS\twain_32
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Temp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\wins
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\wbem
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\usmt
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\spool
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ShellExt
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\Setup
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\scripting
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ras
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\oobe
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\npp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\mui
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\inetsrv
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\IME
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\icsxml
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\ias
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\export
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\en
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\drivers
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\dhcp
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\config
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\3com_dmi
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\3076
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\2052
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1054
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1042
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1041
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1037
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1033
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1031
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1028
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32\1025
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system32
2009-01-16 17:49:39 ----D---- C:\WINDOWS\system
2009-01-16 17:49:39 ----D---- C:\WINDOWS\security
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Resources
2009-01-16 17:49:39 ----D---- C:\WINDOWS\repair
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Provisioning
2009-01-16 17:49:39 ----D---- C:\WINDOWS\PeerNet
2009-01-16 17:49:39 ----D---- C:\WINDOWS\pchealth
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Network Diagnostic
2009-01-16 17:49:39 ----D---- C:\WINDOWS\mui
2009-01-16 17:49:39 ----D---- C:\WINDOWS\msapps
2009-01-16 17:49:39 ----D---- C:\WINDOWS\msagent
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Media
2009-01-16 17:49:39 ----D---- C:\WINDOWS\L2Schemas
2009-01-16 17:49:39 ----D---- C:\WINDOWS\java
2009-01-16 17:49:39 ----D---- C:\WINDOWS\ime
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Help
2009-01-16 17:49:39 ----D---- C:\WINDOWS\ehome
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Driver Cache
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Debug
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Cursors
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Connection Wizard
2009-01-16 17:49:39 ----D---- C:\WINDOWS\Config
2009-01-16 17:49:39 ----D---- C:\WINDOWS\AppPatch
2009-01-16 17:49:39 ----D---- C:\WINDOWS\addins
2009-01-16 17:49:39 ----D---- C:\WINDOWS
2009-01-08 03:14:40 ----A---- C:\WINDOWS\system32\rmoc3260.dll
2009-01-08 03:14:40 ----A---- C:\WINDOWS\system32\pncrt.dll
======List of files/folders modified in the last 1 months======
2009-01-16 20:00:00 ----A---- C:\WINDOWS\win.ini
2009-01-16 17:56:20 ----A---- C:\WINDOWS\system.ini
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Aavmker4;avast! Asynchronous Virus Monitor; C:\WINDOWS\system32\drivers\Aavmker4.sys [2007-12-04 26624]
R1 aswTdi;avast! Network Shield Support; C:\WINDOWS\system32\drivers\aswTdi.sys [2007-12-04 42912]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R2 aswMon2;avast! Standard Shield Support; C:\WINDOWS\system32\drivers\aswMon2.sys [2007-12-04 94544]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-06-19 60800]
R3 aswRdr;aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [2007-12-04 23152]
R3 ati2mtag;ati2mtag; C:\WINDOWS\system32\DRIVERS\ati2mtag.sys [2008-04-14 701440]
R3 BCMModem;BCM V.90 56K Modem; C:\WINDOWS\system32\DRIVERS\BCMDM.sys [2001-08-17 871388]
R3 ctac32k;Creative AC3 Software Decoder; C:\WINDOWS\system32\drivers\ctac32k.sys [2006-08-11 502272]
R3 ctaud2k;Creative Audio Driver (WDM); C:\WINDOWS\system32\drivers\ctaud2k.sys [2006-08-11 499584]
R3 ctprxy2k;Creative Proxy Driver; C:\WINDOWS\system32\drivers\ctprxy2k.sys [2006-08-11 7168]
R3 ctsfm2k;Creative SoundFont Management Device Driver; C:\WINDOWS\system32\drivers\ctsfm2k.sys [2006-08-11 143872]
R3 E100B;Intel® PRO Network Connection Driver; C:\WINDOWS\system32\DRIVERS\e100b325.sys [2007-11-16 165496]
R3 emupia;E-mu Plug-in Architecture Driver; C:\WINDOWS\system32\drivers\emupia2k.sys [2006-08-11 78336]
R3 ha10kx2k;Creative Hardware Abstract Layer Driver; C:\WINDOWS\system32\drivers\ha10kx2k.sys [2006-08-11 766976]
R3 hap16v2k;Creative P16V HAL Driver; C:\WINDOWS\system32\drivers\hap16v2k.sys [2006-08-11 154112]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-06-19 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-06-19 61824]
R3 ossrv;Creative OS Services Driver; C:\WINDOWS\system32\drivers\ctoss2k.sys [2006-08-11 116224]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 ctdvda2k;Creative DVD-Audio Device Driver; C:\WINDOWS\system32\drivers\ctdvda2k.sys [2005-11-10 340704]
S3 hap17v2k;Creative P17V HAL Driver; C:\WINDOWS\system32\drivers\hap17v2k.sys [2006-08-11 180224]
S3 usbstor;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-05-12 611664]
R2 aswUpdSv;avast! iAVS4 Control Service; C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe [2007-12-04 17272]
R2 avast! Antivirus;avast! Antivirus; C:\Program Files\Alwil Software\Avast4\ashServ.exe [2007-12-04 140664]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-17 152984]
R3 avast! Mail Scanner;avast! Mail Scanner; C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe [2007-12-04 247160]
R3 avast! Web Scanner;avast! Web Scanner; C:\Program Files\Alwil Software\Avast4\ashWebSv.exe [2007-12-04 345464]
S3 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe [2006-10-27 65824]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2006-10-26 441136]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
-----------------EOF-----------------
info.txt:info.txt logfile of random's system information tool 1.05 2009-02-07 23:54:09
======Uninstall list======
-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9
-->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf
Acrobat.com-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe -uninstall com.adobe.mauby 4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
Acrobat.com-->MsiExec.exe /I{77DCDCE3-2DED-62F3-8154-05E745472D07}
Ad-Aware-->MsiExec.exe /I{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}
Adobe AIR-->C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Adobe AIR Updater.exe -arp:uninstall
Adobe AIR-->MsiExec.exe /I{00203668-8170-44A0-BE44-B632FA4D780F}
Adobe Reader 9-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A90000000001}
Alky for Applications (Windows XP)-->MsiExec.exe /X{BB05D173-9681-4812-A7FA-BD4042A3DA00}
avast! Antivirus-->rundll32 C:\PROGRA~1\ALWILS~1\Avast4\Setup\setiface.dll,RunSetup
CCleaner (remove only)-->"C:\Program Files\CCleaner\uninst.exe"
Creative Audio Console-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{7B9AE66C-2A8F-4FB2-85D7-416AFFAE8408}\setup.exe" -l0x9 /remove
[bleep] NFO Viewer v2.10.0032.RC3 (Remove Only)-->rundll32.exe advpack.dll,LaunchINFSection DamnNFO.inf,DefaultUninstall
Guild Wars-->"C:\Program Files\Guild Wars\Gw.exe" -uninstall
HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Java 6 Update 11-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216011FF}
Java 6 Update 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160060}
LClock-->C:\Program Files\LClock\Uninstall.exe
Microsoft Compression Client Pack 1.0 for Windows XP-->"C:\WINDOWS\$NtUninstallMSCompPackV1$\spuninst\spuninst.exe"
Microsoft Office 2007 Recent Documents Gadget-->MsiExec.exe /X{90120000-008A-0409-0000-0000000FF1CE}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft User-Mode Driver Framework Feature Pack 1.0-->"C:\WINDOWS\$NtUninstallWudf01000$\spuninst\spuninst.exe"
Microsoft Visual C++ 2005 SP1 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30304-->MsiExec.exe /X{C9B26742-06BE-3B75-B1DE-7B91B5956A04}
Resource Hacker 3.4.0-->"C:\WINDOWS\Resource Hacker 3.4.0\uninstall.exe" "/U:C:\Program Files\Resource Hacker 3.4.0\Uninstall\uninstall.xml"
Revo Uninstaller 1.75-->C:\Program Files\VS Revo Group\Revo Uninstaller\uninst.exe
Right Click Image Converter-->"C:\Program Files\Kristanix\Right Click Image Converter\uninstall.exe"
SpywareBlaster 4.1-->"C:\Program Files\SpywareBlaster\unins000.exe"
Styler-->MsiExec.exe /I{E9ECF354-2422-4FDB-9ABF-D8ADAC0EF941}
SUPERAntiSpyware Free Edition-->MsiExec.exe /X{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}
Unlocker 1.8.5-->C:\Program Files\Unlocker\uninst.exe
Update for Windows XP (KB898461)-->"C:\WINDOWS\$NtUninstallKB898461$\spuninst\spuninst.exe"
VideoLAN VLC media player 0.8.6i-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Media Format 11 runtime-->"C:\Program Files\Windows Media Player\wmsetsdk.exe" /UninstallAll
Windows Media Format 11 runtime-->"C:\WINDOWS\$NtUninstallWMFDist11$\spuninst\spuninst.exe"
Windows Media Player 11-->"C:\Program Files\Windows Media Player\Setup_wm.exe" /Uninstall
Windows Media Player 11-->"C:\WINDOWS\$NtUninstallwmp11$\spuninst\spuninst.exe"
Windows Sidebar-->RUNDLL32 advpack.dll,LaunchINFSection Sidebar.inf,UnInstall
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
Xilisoft Video Converter Ultimate-->C:\Program Files\Xilisoft\Video Converter Ultimate\Uninstall.exe
======Security center information======
AV: avast! antivirus 4.7.1098 [VPS 090207-0]
System event log
Computer Name: DOWNSTAIRS
Event Code: 15007
Message: Reservation for namespace identified by URL prefix
http://*:2869/ was successfully added.
Record Number: 5
Source Name: HTTP
Time Written: 20090116182602.000000+000
Event Type: information
User:
Computer Name: DOWNSTAIRS
Event Code: 6011
Message: The NetBIOS name and DNS host name of this machine have been changed from MACHINENAME to DOWNSTAIRS.
Record Number: 4
Source Name: EventLog
Time Written: 20090116181520.000000+000
Event Type: information
User:
Computer Name: MACHINENAME
Event Code: 2
Message: While validating that \Device\Serial0 was really a serial port, a fifo was detected. The fifo will be used.
Record Number: 3
Source Name: Serial
Time Written: 20090116175352.000000+000
Event Type: information
User:
Computer Name: MACHINENAME
Event Code: 6005
Message: The Event log service was started.
Record Number: 2
Source Name: EventLog
Time Written: 20090116175335.000000+000
Event Type: information
User:
Computer Name: MACHINENAME
Event Code: 6009
Message: Microsoft ® Windows ® 5.01. 2600 Service Pack 3 Multiprocessor Free.
Record Number: 1
Source Name: EventLog
Time Written: 20090116175335.000000+000
Event Type: information
User:
Application event log
Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the MSDTC (MSDTC) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 5
Source Name: LoadPerf
Time Written: 20090116182407.000000+000
Event Type: information
User:
Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the TermService (Terminal Services) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 4
Source Name: LoadPerf
Time Written: 20090116182404.000000+000
Event Type: information
User:
Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the RemoteAccess (Routing and Remote Access) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Record Number: 3
Source Name: LoadPerf
Time Written: 20090116181608.000000+000
Event Type: information
User:
Computer Name: DOWNSTAIRS
Event Code: 1000
Message: Performance counters for the PSched (PSched) service were loaded successfully.
The Record Data contains the new index values assigned
to this service.
Rest of info.txt in next post
Edited by Jason1230, 07 February 2009 - 06:03 PM.