Please download the OTMoveIt3 by OldTimer
If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.
Run RSIT again.. Post these logs in your next reply..
1. OTMoveIt3
2. RSIT log.txt
OTmoveIt3========== PROCESSES ==========
Process explorer.exe killed successfully.
========== FILES ==========
C:\WINDOWS\tasks\hsajwzct.job moved successfully.
File/Folder C:\WINDOWS\system32\yxkdkwfg.dll not found.
File/Folder C:\WINDOWS\system32\yeneriho.dll not found.
LoadLibrary failed for C:\WINDOWS\system32\satevowa.dll
C:\WINDOWS\system32\satevowa.dll NOT unregistered.
C:\WINDOWS\system32\satevowa.dll moved successfully.
LoadLibrary failed for C:\WINDOWS\system32\nefavega.dll
C:\WINDOWS\system32\nefavega.dll NOT unregistered.
C:\WINDOWS\system32\nefavega.dll moved successfully.
C:\WINDOWS\system32\orokarur.ini moved successfully.
C:\WINDOWS\system32\iwazetir.ini moved successfully.
C:\WINDOWS\system32\rtdnkqug.ini moved successfully.
C:\Documents and Settings\User\Application Data\Twain moved successfully.
C:\WINDOWS\system32\bgwcqcub.ini moved successfully.
C:\WINDOWS\system32\13c46898-.txt moved successfully.
========== REGISTRY ==========
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\18e7ace6\\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nohemipola\\ deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\"AppInit_DLLS"|"" /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ljJYPGVo\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\E\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{713f6d9f-485c-11dd-85e0-b9c070adaee2}\\ deleted successfully.
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{d06ed8f5-bd99-11dd-bf56-00166f8c33f9}\\ deleted successfully.
========== COMMANDS ==========
File delete failed. C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_53y0O2D1pwokJenUcAgV scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_G4dNs77mx8mMbeZoOJ8e scheduled to be deleted on reboot.
File delete failed. C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_G4dNs77mx8mMbeZoOJ8e-journal scheduled to be deleted on reboot.
User's Temp folder emptied.
User's Temporary Internet Files folder emptied.
User's Internet Explorer cache folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\a1eb68cf-30be-41ef-a230-c4c1ce0fc330.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\d91033e4-3503-42bc-9a4f-75a3e7a11059.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_a8.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\OfflineCache\index.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_001_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_002_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_003_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\urlclassifier3.sqlite scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\XUL.mfl scheduled to be deleted on reboot.
FireFox cache emptied.
Temp folders emptied.
Explorer started successfully
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 01052009_154309
Files moved on Reboot...
C:\DOCUME~1\User\LOCALS~1\Temp\Temporary Directory 1 for gmer.zip\gmer.exe moved successfully.
File C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_53y0O2D1pwokJenUcAgV not found!
File C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_G4dNs77mx8mMbeZoOJ8e not found!
File C:\DOCUME~1\User\LOCALS~1\Temp\etilqs_G4dNs77mx8mMbeZoOJ8e-journal not found!
File move failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot.
C:\WINDOWS\temp\a1eb68cf-30be-41ef-a230-c4c1ce0fc330.tmp moved successfully.
C:\WINDOWS\temp\d91033e4-3503-42bc-9a4f-75a3e7a11059.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_a8.dat not found!
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\OfflineCache\index.sqlite moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_001_ moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_002_ moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_003_ moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\Cache\_CACHE_MAP_ moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\urlclassifier3.sqlite moved successfully.
C:\Documents and Settings\User\Local Settings\Application Data\Mozilla\Firefox\Profiles\d4ng09zv.default\XUL.mfl moved successfully.
RSITLogfile of random's system information tool 1.05 (written by random/random)
Run by User at 2009-01-05 15:54:24
Microsoft Windows XP Professional Service Pack 2
System drive C: has 31 GB (82%) free of 38 GB
Total RAM: 1015 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:54:32 PM, on 1/5/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\notepad.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Documents and Settings\User\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\User.exe
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKUS\S-1-5-19\..\Run: [nohemipola] Rundll32.exe "C:\WINDOWS\system32\yeneriho.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [nohemipola] Rundll32.exe "C:\WINDOWS\system32\yeneriho.dll",s (User 'NETWORK SERVICE')
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel® PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
--
End of file - 3616 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\Norton Security Scan for User.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll [2009-01-03 1078552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
Java Plug-In SSV Helper - C:\Program Files\Java\jre6\bin\ssv.dll [2009-01-03 320920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A057A204-BACC-4D26-9990-79A187E2698E}]
AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-01-03 1968920]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2008-11-28 657904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-01-03 34816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-01-03 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{A057A204-BACC-4D26-9990-79A187E2698E} - AVG Security Toolbar - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL [2009-01-03 1968920]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-01-03 136600]
"AVG8_TRAY"=C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-01-03 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AVG8_TRAY]
C:\PROGRA~1\AVG\AVG8\avgtray.exe [2009-01-03 1601304]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\cdloader]
C:\Documents and Settings\User\Application Data\mjusbsp\cdloader2.exe [2008-08-22 50520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxhkcmd]
C:\WINDOWS\system32\hkcmd.exe [2006-09-15 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxpers]
C:\WINDOWS\system32\igfxpers.exe [2006-09-15 118784]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igfxtray]
C:\WINDOWS\system32\igfxtray.exe [2006-09-15 94208]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2007-02-21 970752]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig]
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe [2007-02-21 819200]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe [2007-09-25 132496]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-11-28 39408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^User^Start Menu^Programs^Startup^OpenOffice.org 2.3.lnk]
C:\PROGRA~1\OPENOF~1.3\program\QUICKS~1.EXE [2007-08-17 393216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"WLANKEEPER"=2
"sdCoreService"=3
"sdAuxService"=2
"gusvc"=2
"BAsfIpM"=2
"avg8wd"=2
"avg8emc"=2
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\avgrsstarter]
C:\WINDOWS\system32\avgrsstx.dll [2009-01-03 10520]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINDOWS\system32\igfxdev.dll [2006-09-15 139264]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\AVG\AVG8\avgupd.exe"="C:\Program Files\AVG\AVG8\avgupd.exe:*:Enabled:avgupd.exe"
"C:\Documents and Settings\User\Application Data\mjusbsp\magicJack.exe"="C:\Documents and Settings\User\Application Data\mjusbsp\magicJack.exe:*:Enabled:magicJack"
"C:\WINDOWS\explorer.exe"="C:\WINDOWS\explorer.exe:*:Enabled:Explorer"
"C:\WINDOWS\system32\winlogon.exe"="C:\WINDOWS\system32\winlogon.exe:*:Enabled:winlogon"
"C:\Program Files\AVG\AVG8\avgrsx.exe"="C:\Program Files\AVG\AVG8\avgrsx.exe:*:Enabled:avgrsx"
"C:\Program Files\AVG\AVG8\avgnsx.exe"="C:\Program Files\AVG\AVG8\avgnsx.exe:*:Enabled:avgnsx.exe"
"C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe"="C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe:*:Enabled:S24EvMon"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 3 months======
2009-01-05 15:43:09 ----D---- C:\_OTMoveIt
2009-01-05 15:04:52 ----A---- C:\WINDOWS\gmer.ini
2009-01-05 15:04:51 ----A---- C:\WINDOWS\gmer_uninstall.cmd
2009-01-05 15:04:50 ----RA---- C:\WINDOWS\gmer.exe
2009-01-05 15:04:50 ----A---- C:\WINDOWS\gmer.dll
2009-01-04 15:43:46 ----D---- C:\rsit
2009-01-04 14:59:16 ----D---- C:\Documents and Settings\User\Application Data\Malwarebytes
2009-01-04 14:59:06 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-01-04 14:59:06 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-01-03 22:16:28 ----D---- C:\Documents and Settings\User\Application Data\AVGTOOLBAR
2009-01-03 21:56:54 ----D---- C:\WINDOWS\Internet Logs
2009-01-03 20:08:01 ----A---- C:\WINDOWS\system32\javaws.exe
2009-01-03 20:08:01 ----A---- C:\WINDOWS\system32\deploytk.dll
2009-01-03 20:08:00 ----A---- C:\WINDOWS\system32\javaw.exe
2009-01-03 20:08:00 ----A---- C:\WINDOWS\system32\java.exe
2009-01-02 19:09:26 ----D---- C:\WINDOWS\pss
2009-01-02 17:43:44 ----D---- C:\Program Files\Trend Micro
2009-01-02 15:55:30 ----D---- C:\WINDOWS\system32\LogFiles
2008-12-27 12:48:55 ----HD---- C:\$AVG8.VAULT$
2008-12-27 08:49:41 ----D---- C:\WINDOWS\system32\WunderPhoto Screensaver dir
2008-12-21 20:08:28 ----D---- C:\WINDOWS\system32\IOSUBSYS
2008-12-20 19:19:41 ----HDC---- C:\WINDOWS\$NtUninstallKB960714$
2008-12-13 14:09:34 ----D---- C:\WINDOWS\Sun
2008-12-11 10:00:04 ----HDC---- C:\WINDOWS\$NtUninstallKB952069_WM9$
2008-12-11 09:59:58 ----HDC---- C:\WINDOWS\$NtUninstallKB955839$
2008-12-11 09:59:29 ----HDC---- C:\WINDOWS\$NtUninstallKB958215$
2008-12-11 09:59:15 ----HDC---- C:\WINDOWS\$NtUninstallKB954600$
2008-12-11 09:59:01 ----HDC---- C:\WINDOWS\$NtUninstallKB956802$
2008-12-07 11:57:52 ----D---- C:\Documents and Settings\User\Application Data\Macromedia
2008-12-03 13:09:59 ----D---- C:\Documents and Settings\User\Application Data\Help
2008-12-01 12:44:00 ----D---- C:\Documents and Settings\User\Application Data\OpenOffice.org2
2008-12-01 12:24:36 ----D---- C:\Documents and Settings\User\Application Data\Adobe
2008-11-30 03:04:36 ----HDC---- C:\WINDOWS\$NtUninstallKB951376-v2$
2008-11-30 03:04:27 ----HDC---- C:\WINDOWS\$NtUninstallKB952954$
2008-11-30 03:04:19 ----HDC---- C:\WINDOWS\$NtUninstallKB946648$
2008-11-30 03:04:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
2008-11-30 03:04:02 ----HDC---- C:\WINDOWS\$NtUninstallKB956391$
2008-11-30 03:03:54 ----HDC---- C:\WINDOWS\$NtUninstallKB957095$
2008-11-30 03:03:45 ----HDC---- C:\WINDOWS\$NtUninstallKB950974$
2008-11-30 03:03:35 ----HDC---- C:\WINDOWS\$NtUninstallKB951698$
2008-11-30 03:03:25 ----HDC---- C:\WINDOWS\$NtUninstallKB954211$
2008-11-30 03:03:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956841$
2008-11-30 03:02:55 ----D---- C:\Program Files\MSXML 6.0
2008-11-30 03:02:43 ----HDC---- C:\WINDOWS\$NtUninstallKB950762$
2008-11-30 03:02:34 ----HDC---- C:\WINDOWS\$NtUninstallKB957097$
2008-11-30 03:02:25 ----HDC---- C:\WINDOWS\$NtUninstallKB951072-v2$
2008-11-30 03:02:13 ----HDC---- C:\WINDOWS\$NtUninstallKB952287$
2008-11-30 03:02:03 ----HDC---- C:\WINDOWS\$NtUninstallKB951066$
2008-11-30 03:01:55 ----HDC---- C:\WINDOWS\$NtUninstallKB938464$
2008-11-30 03:01:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958644$
2008-11-30 03:01:36 ----HDC---- C:\WINDOWS\$NtUninstallKB955069$
2008-11-30 03:01:10 ----HDC---- C:\WINDOWS\$NtUninstallKB956390$
2008-11-30 03:00:31 ----HDC---- C:\WINDOWS\$NtUninstallKB944338-v2$
2008-11-29 18:39:40 ----A---- C:\WINDOWS\system32\wmpns.dll
2008-11-29 14:30:41 ----D---- C:\Documents and Settings\User\Application Data\Mozilla
2008-11-29 03:03:50 ----D---- C:\WINDOWS\system32\CatRoot_bak
2008-11-29 03:00:29 ----D---- C:\WINDOWS\system32\PreInstall
2008-11-29 03:00:28 ----A---- C:\WINDOWS\system32\spupdsvc.exe
2008-11-29 03:00:27 ----HDC---- C:\WINDOWS\$NtUninstallKB898461$
2008-11-28 16:34:50 ----D---- C:\Program Files\Spyware Doctor
2008-11-28 16:34:50 ----D---- C:\Documents and Settings\User\Application Data\PC Tools
2008-11-28 16:34:48 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2008-11-28 16:33:37 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2008-11-28 16:33:33 ----D---- C:\Program Files\Common Files\Adobe
2008-11-28 16:33:33 ----D---- C:\Program Files\Adobe
2008-11-28 16:31:49 ----D---- C:\Program Files\Mozilla Firefox
2008-11-28 16:31:39 ----D---- C:\temp
2008-11-28 16:31:19 ----D---- C:\Program Files\Common Files\Symantec Shared
2008-11-28 16:31:14 ----D---- C:\Program Files\Norton Security Scan
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\vxblock.dll
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\pxwave.dll
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\pxmas.dll
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\pxhpinst.exe
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\pxdrv.dll
2008-11-28 16:30:45 ----A---- C:\WINDOWS\system32\px.dll
2008-11-28 16:30:01 ----D---- C:\WINDOWS\system32\runtime
2008-11-28 16:29:59 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2008-11-28 16:29:25 ----D---- C:\Documents and Settings\All Users\Application Data\Google Updater
2008-11-28 16:29:22 ----D---- C:\Program Files\Google
2008-11-28 16:21:10 ----D---- C:\Documents and Settings\User\Application Data\mjusbsp
2008-11-28 16:12:32 ----D---- C:\WINDOWS\system32\SoftwareDistribution
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wups2.dll
2008-10-16 14:09:40 ----A---- C:\WINDOWS\system32\wucltui.dll.mui
2008-10-16 14:07:44 ----A---- C:\WINDOWS\system32\wuapi.dll.mui
2008-10-16 14:07:14 ----A---- C:\WINDOWS\system32\wuaueng.dll.mui
2008-10-15 09:27:11 ----D---- C:\Documents and Settings\User\Application Data\AVS4YOU
2008-10-15 09:27:07 ----D---- C:\Documents and Settings\All Users\Application Data\AVS4YOU
2008-10-15 09:27:03 ----SHD---- C:\RECYCLER
2008-10-14 15:23:34 ----D---- C:\Program Files\Burn4Free
2008-10-14 15:22:44 ----D---- C:\Program Files\OpenOffice.org 2.3
2008-10-14 15:22:09 ----D---- C:\Program Files\Java
2008-10-14 15:22:08 ----D---- C:\Program Files\Common Files\Java
2008-10-14 15:21:41 ----A---- C:\WINDOWS\system32\avgrsstx.dll.install_backup
2008-10-14 15:21:41 ----A---- C:\WINDOWS\system32\avgrsstx.dll
2008-10-14 15:21:30 ----D---- C:\Program Files\AVG
2008-10-14 15:21:29 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2008-10-14 15:20:54 ----D---- C:\Documents and Settings\User\Application Data\Sun
2008-10-14 15:20:41 ----D---- C:\Program Files\Common Files\AVSMedia
2008-10-14 15:20:33 ----A---- C:\WINDOWS\system32\xvidvfw.dll
2008-10-14 15:20:33 ----A---- C:\WINDOWS\system32\xvidcore.dll
2008-10-14 15:20:33 ----A---- C:\WINDOWS\system32\mpg4c32.dll
2008-10-14 15:20:33 ----A---- C:\WINDOWS\system32\mcdvd_32.dll
2008-10-14 15:20:33 ----A---- C:\WINDOWS\system32\divx.dll
2008-10-14 15:20:32 ----A---- C:\WINDOWS\system32\msxml3a.dll
2008-10-14 15:20:32 ----A---- C:\WINDOWS\system32\msvcp70.dll
2008-10-14 15:20:32 ----A---- C:\WINDOWS\system32\mfc70.dll
2008-10-14 15:20:32 ----A---- C:\WINDOWS\system32\GdiPlus.dll
2008-10-14 15:20:31 ----D---- C:\Program Files\AVS4YOU
2008-10-14 15:20:31 ----A---- C:\WINDOWS\system32\msvcr70.dll
2008-10-14 15:19:30 ----D---- C:\Program Files\Spybot - Search & Destroy
2008-10-14 15:19:30 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
======List of files/folders modified in the last 3 months======
2009-01-05 15:52:40 ----D---- C:\WINDOWS\Temp
2009-01-05 15:48:39 ----D---- C:\WINDOWS\Prefetch
2009-01-05 15:46:11 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-01-05 15:44:46 ----D---- C:\WINDOWS\system32
2009-01-05 15:43:09 ----SD---- C:\WINDOWS\Tasks
2009-01-05 15:04:52 ----D---- C:\WINDOWS
2009-01-05 15:04:51 ----D---- C:\WINDOWS\system32\drivers
2009-01-04 15:27:06 ----RD---- C:\Program Files
2009-01-03 21:18:07 ----D---- C:\WINDOWS\SoftwareDistribution
2009-01-03 20:08:29 ----SHD---- C:\WINDOWS\Installer
2009-01-03 20:02:43 ----D---- C:\WINDOWS\system32\CatRoot2
2009-01-02 19:10:38 ----SH---- C:\boot.ini
2009-01-02 19:10:38 ----N---- C:\WINDOWS\system.ini
2009-01-02 19:10:38 ----A---- C:\WINDOWS\win.ini
2008-12-27 13:18:36 ----HD---- C:\WINDOWS\inf
2008-12-27 12:48:58 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-12-20 19:19:50 ----RSHDC---- C:\WINDOWS\system32\dllcache
2008-12-20 19:19:10 ----HD---- C:\WINDOWS\$hf_mig$
2008-12-12 11:33:23 ----A---- C:\WINDOWS\system32\mshtml.dll
2008-12-11 10:00:09 ----A---- C:\WINDOWS\imsins.BAK
2008-12-11 09:59:39 ----D---- C:\Program Files\Internet Explorer
2008-12-03 13:09:59 ----D---- C:\WINDOWS\Help
2008-11-30 03:04:21 ----D---- C:\Program Files\Messenger
2008-11-30 03:01:57 ----D---- C:\WINDOWS\WinSxS
2008-11-29 18:42:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2008-11-29 16:16:17 ----SD---- C:\Documents and Settings\User\Application Data\Microsoft
2008-11-29 03:19:19 ----D---- C:\WINDOWS\system32\CatRoot
2008-11-29 03:03:50 ----D---- C:\WINDOWS\Debug
2008-11-28 16:33:33 ----D---- C:\Program Files\Common Files
2008-11-07 18:32:20 ----A---- C:\WINDOWS\system32\WMVCore.dll
2008-10-23 07:01:36 ----A---- C:\WINDOWS\system32\gdi32.dll
2008-10-22 03:47:07 ----A---- C:\WINDOWS\system32\tzchange.exe
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuweb.dll
2008-10-16 14:13:40 ----A---- C:\WINDOWS\system32\wuaueng.dll
2008-10-16 14:12:22 ----A---- C:\WINDOWS\system32\wucltui.dll
2008-10-16 14:12:20 ----A---- C:\WINDOWS\system32\wuapi.dll
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\wuauclt.exe
2008-10-16 14:09:44 ----A---- C:\WINDOWS\system32\cdm.dll
2008-10-16 14:08:58 ----A---- C:\WINDOWS\system32\wups.dll
2008-10-16 04:37:04 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-10-16 04:37:04 ----A---- C:\WINDOWS\system32\browseui.dll
2008-10-16 04:37:03 ----A---- C:\WINDOWS\system32\wininet.dll
2008-10-16 04:37:03 ----A---- C:\WINDOWS\system32\shlwapi.dll
2008-10-16 04:37:03 ----A---- C:\WINDOWS\system32\shdocvw.dll
2008-10-16 04:37:03 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-10-16 04:37:03 ----A---- C:\WINDOWS\system32\jsproxy.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\mstime.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\msrating.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\inseng.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\iepeers.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\extmgr.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\danim.dll
2008-10-16 04:37:02 ----A---- C:\WINDOWS\system32\cdfview.dll
2008-10-15 10:57:55 ----A---- C:\WINDOWS\system32\netapi32.dll
2008-10-15 08:00:41 ----A---- C:\WINDOWS\system32\xpsp3res.dll
2008-10-14 15:23:06 ----RSD---- C:\WINDOWS\Fonts
2008-10-14 15:20:40 ----D---- C:\Program Files\Common Files\Microsoft Shared
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 AvgLdx86;AVG Free AVI Loader Driver x86; C:\WINDOWS\System32\Drivers\avgldx86.sys [2009-01-03 324872]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86; C:\WINDOWS\System32\Drivers\avgmfx86.sys [2009-01-03 27656]
R1 AvgTdiX;AVG8 Network Redirector; C:\WINDOWS\System32\Drivers\avgtdix.sys [2009-01-03 107272]
R1 IKSysFlt;System Filter Driver; C:\WINDOWS\system32\drivers\iksysflt.sys [2008-11-28 66952]
R1 IKSysSec;System Security Driver; C:\WINDOWS\system32\drivers\iksyssec.sys [2008-11-28 81288]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2004-08-04 36096]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.6.0.0; C:\WINDOWS\system32\DRIVERS\AegisP.sys [2008-07-02 21425]
R2 BASFND;BASFND; \??\C:\WINDOWS\system32\Drivers\BASFND.sys []
R2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys [2004-03-17 13059]
R2 s24trans;WLAN Transport; C:\WINDOWS\system32\DRIVERS\s24trans.sys [2007-02-21 12416]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R3 b57w2k;Broadcom NetXtreme Gigabit Ethernet; C:\WINDOWS\system32\DRIVERS\b57xp32.sys [2006-05-10 156160]
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2004-08-03 14080]
R3 GTIPCI21;GTIPCI21; C:\WINDOWS\system32\DRIVERS\gtipci21.sys [2006-04-06 88192]
R3 HSF_DPV;HSF_DPV; C:\WINDOWS\system32\DRIVERS\HSF_DPV.SYS [2005-05-03 1033728]
R3 HSFHWICH;HSFHWICH; C:\WINDOWS\system32\DRIVERS\HSFHWICH.sys [2005-05-03 208384]
R3 ialm;ialm; C:\WINDOWS\system32\DRIVERS\ialmnt5.sys [2006-09-15 1173468]
R3 STAC97;SigmaTel C-Major Audio; C:\WINDOWS\system32\drivers\STAC97.sys [2005-03-10 273168]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2004-08-04 26624]
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2004-08-04 57600]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2004-08-04 20480]
R3 w29n51;Intel® PRO/Wireless 2915ABG Network Connection Driver for Windows XP; C:\WINDOWS\system32\DRIVERS\w29n51.sys [2007-02-08 2209408]
R3 winachsf;winachsf; C:\WINDOWS\system32\DRIVERS\HSF_CNXT.sys [2005-05-03 705408]
S3 gmer;gmer; C:\WINDOWS\System32\DRIVERS\gmer.sys [2009-01-05 85969]
S3 HidUsb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2001-08-17 9600]
S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-17 12160]
S3 UIUSys;Conexant Setup API; C:\WINDOWS\system32\drivers\UIUSys.sys []
S3 usbaudio;USB Audio Driver (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2004-08-03 59264]
S3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2004-08-03 31616]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2004-08-03 26496]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 avg8wd;AVG8 WatchDog; C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe [2009-01-03 298264]
R2 EvtEng;Intel® PROSet/Wireless Event Log; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2007-02-21 643072]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-01-03 152984]
R2 RegSrvc;Intel® PROSet/Wireless Registry Service; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2007-02-21 327680]
R2 S24EventMonitor;Intel® PROSet/Wireless Service; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2007-02-21 983040]
S4 BAsfIpM;Broadcom ASF IP monitoring service v6.0.4; C:\WINDOWS\system32\basfipm.exe [2004-04-01 77824]
S4 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-11-28 168432]
S4 sdAuxService;PC Tools Auxiliary Service; C:\Program Files\Spyware Doctor\pctsAuxs.exe [2008-06-13 356920]
S4 sdCoreService;PC Tools Security Service; C:\Program Files\Spyware Doctor\pctsSvc.exe [2008-11-28 1079176]
S4 WLANKEEPER;Intel® PROSet/Wireless SSO Service; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2007-02-21 294912]
-----------------EOF-----------------
Thank you!