Logfile of random's system information tool 1.08 (written by random/random)
Run by Ben at 2010-08-04 20:15:10
Microsoft Windows XP Professional Service Pack 3
System drive C: has 131 GB (88%) free of 150 GB
Total RAM: 3326 MB (80% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:15:19 PM, on 4/08/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Microsoft SQL Server\MSSQL$INGAUSTRALIA\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe
C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
C:\WINDOWS\System32\vssvc.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\TeamViewer\Version5\TeamViewer.exe
C:\WINDOWS\system32\vsnapvss.exe
C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe
C:\Program Files\eFax Messenger 4.4\J2GTray.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\ProToolbarUpdate.exe
C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
C:\Program Files\Trend Micro\BM\TMBMSRV.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\PlatformDependent\ProToolbarComm.exe
C:\Program Files\Trend Micro\TrendSecure\TSCFPlatformCOMSvr.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Documents and Settings\Ben\desktop\rsit.exe
C:\Program Files\trend micro\Ben.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Trend Micro Toolbar BHO - {43C6D902-A1C5-45c9-91F6-FD9E90337E18} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O3 - Toolbar: Trend Micro Toolbar - {CCAC5586-44D7-4c43-B64A-F042461A97D2} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKCU\..\Run: [eFax 4.4] "C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe" /R
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_7 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [OE] "C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe"
O4 - Startup: eFax 4.4.lnk = C:\Program Files\eFax Messenger 4.4\J2GTray.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: Append Link Target to Existing PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Append to Existing PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert to Adobe PDF -
res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/Shar ... vSniff.cabO16 - DPF: {5BCC24A7-7D3F-4CC9-AC86-4380FCD68D1E} (PCInfoOcxEN Control) -
http://esupport.trendmicro.com/_layouts ... PCInfo.cabO16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/Shar ... /cabsa.cabO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 9880923000O18 - Protocol: tmtb - {04EAF3FB-4BAC-4B5A-A37D-A1CF210A5A42} - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (SfCtlCom) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe
O23 - Service: ShadowProtect Service (ShadowProtectSvc) - StorageCraft Technology Corporation - C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe
O23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe
O23 - Service: Trend Micro Unauthorized Change Prevention Service (TMBMServer) - Trend Micro Inc. - C:\Program Files\Trend Micro\BM\TMBMSRV.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (TmProxy) - Trend Micro Inc. - C:\Program Files\Trend Micro\Internet Security\TmProxy.exe
O23 - Service: StorageCraft Shadow Copy Provider (VSNAPVSS) - StorageCraft Technology Corporation - C:\WINDOWS\system32\vsnapvss.exe
--
End of file - 8637 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}]
Adobe PDF Reader Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2010-06-19 61888]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2010-06-19 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{43C6D902-A1C5-45c9-91F6-FD9E90337E18}]
TSToolbarBHO - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll [2009-07-27 148816]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE7CD045-E861-484f-8273-0445EE161910}]
Adobe PDF Conversion Toolbar Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-06-19 349640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F4971EE7-DAA0-4053-9964-665D8EE6A077}]
SmartSelect Class - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-06-19 349640]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{CCAC5586-44D7-4c43-B64A-F042461A97D2} - Trend Micro Toolbar - C:\Program Files\Trend Micro\TrendSecure\TISProToolbar\TSToolbar.dll [2009-07-27 148816]
{47833539-D0C5-4125-9FA8-0819E2EAAC93} - Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2010-06-19 349640]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NeroFilterCheck"=C:\WINDOWS\system32\NeroCheck.exe [2001-07-09 155648]
"RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2009-03-27 17567744]
"NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2009-09-27 13918208]
"NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2009-09-27 86016]
"UfSeAgnt.exe"=C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe [2010-01-26 1020248]
"Adobe Acrobat Speed Launcher"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe [2010-06-19 38840]
""= []
"Acrobat Assistant 8.0"=C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe [2010-06-19 640440]
"Adobe ARM"=C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-06-09 976832]
"Scheduler"= []
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"eFax 4.4"=C:\Program Files\eFax Messenger 4.4\J2GDllCmd.exe [2010-07-03 95744]
"updateMgr"=C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe [2005-10-24 307200]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360]
"OE"=C:\Program Files\Trend Micro\Internet Security\TMAS_OE\TMAS_OEMon.exe [2010-07-05 492808]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Documents and Settings\Ben\Start Menu\Programs\Startup
eFax 4.4.lnk - C:\Program Files\eFax Messenger 4.4\J2GTray.exe
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=1
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE"="C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE:*:Enabled:Microsoft Office Outlook"
"C:\Program Files\TeamViewer\Version5\TeamViewer.exe"="C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
======List of files/folders created in the last 1 months======
2010-08-03 20:50:42 ----D---- C:\rsit
2010-08-03 18:52:45 ----D---- C:\WINDOWS\system32\NtmsData
2010-08-03 16:09:49 ----HDC---- C:\WINDOWS\$NtUninstallKB2286198$
2010-07-27 19:14:14 ----D---- C:\WINDOWS\system32\Service
2010-07-24 07:50:21 ----D---- C:\WINDOWS\system32\appmgmt
2010-07-23 23:54:12 ----A---- C:\WINDOWS\system32\mucltui.dll.mui
2010-07-23 23:54:12 ----A---- C:\WINDOWS\system32\mucltui.dll
2010-07-23 22:20:42 ----D---- C:\WINDOWS\pss
2010-07-23 22:02:41 ----D---- C:\Program Files\Microsoft Silverlight
2010-07-23 21:58:08 ----D---- C:\Documents and Settings\All Users\Application Data\Office Genuine Advantage
2010-07-23 21:57:58 ----D---- C:\Documents and Settings\Ben\Application Data\Office Genuine Advantage
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\zh-TW
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\zh-HK
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\tr-TR
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\sv-SE
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\pt-BR
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\nl-NL
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\nb-NO
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\ko-KR
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\it-IT
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\he-IL
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\fr-FR
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\fi-FI
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\es-ES
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\el-GR
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\de-DE
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\da-DK
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\ar-SA
2010-07-23 20:09:30 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$
2010-07-23 20:09:04 ----HDC---- C:\WINDOWS\$NtUninstallKB954154_WM11$
2010-07-23 20:09:00 ----HDC---- C:\WINDOWS\$NtUninstallKB929399$
2010-07-23 20:08:48 ----HDC---- C:\WINDOWS\$NtUninstallKB939683$
2010-07-23 20:08:35 ----HDC---- C:\WINDOWS\$NtUninstallKB941569$
2010-07-23 20:07:35 ----D---- C:\WINDOWS\system32\URTTEMP
2010-07-23 19:14:59 ----D---- C:\Program Files\Microsoft.NET
2010-07-23 19:13:47 ----HDC---- C:\WINDOWS\$NtUninstallKB971513$
2010-07-23 19:10:12 ----D---- C:\WINDOWS\system32\XPSViewer
2010-07-23 19:10:10 ----D---- C:\Program Files\MSBuild
2010-07-23 19:10:04 ----D---- C:\Program Files\Reference Assemblies
2010-07-23 19:09:39 ----N---- C:\WINDOWS\system32\xpssvcs.dll
2010-07-23 19:09:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll
2010-07-23 19:09:39 ----N---- C:\WINDOWS\system32\prntvpt.dll
2010-07-23 19:09:05 ----RSD---- C:\WINDOWS\assembly
2010-07-23 19:08:37 ----D---- C:\WINDOWS\Microsoft.NET
2010-07-23 19:07:10 ----N---- C:\WINDOWS\system32\spmsg.dll
2010-07-23 19:07:09 ----HDC---- C:\WINDOWS\$NtUninstallMSCompPackV1$
2010-07-23 19:06:52 ----D---- C:\Program Files\Windows Media Connect 2
2010-07-23 19:06:42 ----HDC---- C:\WINDOWS\$NtUninstallwmp11$
2010-07-23 19:06:04 ----HDC---- C:\WINDOWS\$NtUninstallWMFDist11$
2010-07-23 19:05:47 ----D---- C:\WINDOWS\system32\drivers\UMDF
2010-07-23 19:05:43 ----HDC---- C:\WINDOWS\$NtUninstallWudf01000$
2010-07-23 18:52:56 ----HDC---- C:\WINDOWS\$NtUninstallKB2229593$
2010-07-12 10:11:16 ----D---- C:\Program Files\CCleaner
2010-07-12 09:53:54 ----D---- C:\Documents and Settings\Ben\Application Data\Malwarebytes
2010-07-12 09:53:48 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
2010-07-12 09:53:47 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2010-07-12 09:53:47 ----A---- C:\WINDOWS\system32\drivers\mbam.sys
2010-07-12 09:53:44 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-07-12 08:44:39 ----D---- C:\Program Files\ING Illustrator
2010-07-09 14:04:12 ----D---- C:\Documents and Settings\All Users\Application Data\FLEXnet
2010-07-09 14:02:18 ----D---- C:\Program Files\Common Files\Macrovision Shared
2010-07-09 14:01:57 ----RA---- C:\WINDOWS\system32\AdobePDFUI.dll
2010-07-09 14:01:57 ----A---- C:\WINDOWS\system32\AdobePDF.dll
2010-07-09 09:28:33 ----D---- C:\Program Files\Acro Software
2010-07-07 22:12:48 ----D---- C:\WINDOWS\system32\LogFiles
2010-07-06 09:17:45 ----D---- C:\Documents and Settings\Ben\Application Data\AdobeUM
2010-07-06 08:05:11 ----D---- C:\Documents and Settings\Ben\Application Data\j2 Global
2010-07-06 08:01:38 ----D---- C:\Documents and Settings\Ben\Application Data\eFax Messenger
2010-07-06 08:01:28 ----D---- C:\Documents and Settings\All Users\Application Data\eFax Messenger 4.4 Output
2010-07-06 08:00:57 ----D---- C:\Program Files\eFax Messenger 4.4
2010-07-06 07:24:34 ----A---- C:\WINDOWS\openrda.ini
2010-07-06 07:24:29 ----D---- C:\MYOBODBC
2010-07-06 07:22:54 ----D---- C:\myob17
2010-07-06 07:12:34 ----D---- C:\Program Files\MYOB
2010-07-06 07:12:34 ----D---- C:\myob15
2010-07-06 07:05:32 ----A---- C:\WINDOWS\SwDrvs.ini
2010-07-06 07:05:32 ----A---- C:\WINDOWS\MYOBP.INI
2010-07-06 07:05:32 ----A---- C:\WINDOWS\MYOB.INI
2010-07-06 06:59:19 ----A---- C:\WINDOWS\drvxl32.INI
2010-07-06 06:59:17 ----A---- C:\WINDOWS\drvwd32.INI
2010-07-06 06:59:15 ----A---- C:\WINDOWS\drvwp32.INI
2010-07-06 06:56:27 ----D---- C:\myob12
2010-07-06 06:37:50 ----D---- C:\Documents and Settings\Ben\Application Data\Windows Search
2010-07-05 14:46:39 ----A---- C:\WINDOWS\system32\XceedSco.dll
2010-07-05 14:46:19 ----N---- C:\WINDOWS\system32\dao360.dll
2010-07-05 14:46:19 ----A---- C:\WINDOWS\system32\msxml4a.dll
2010-07-05 14:45:43 ----D---- C:\Program Files\Common Files\Adobe
2010-07-05 14:45:39 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2010-07-05 14:45:33 ----D---- C:\Program Files\Adobe
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\XcedZip5.dll
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\txobj32.dll
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\tx_word.dll
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\tx_rtf32.dll
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\tx_htm32.dll
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\ic32.ini
2010-07-05 14:41:09 ----A---- C:\WINDOWS\system32\ic32.dll
2010-07-05 14:41:08 ----A---- C:\WINDOWS\system32\wndtls32.dll
2010-07-05 14:41:08 ----A---- C:\WINDOWS\system32\txtls32.dll
2010-07-05 14:41:07 ----A---- C:\WINDOWS\system32\Tx32.dll
2010-07-05 14:41:07 ----A---- C:\WINDOWS\system32\MSBIND.DLL
2010-07-05 14:41:05 ----N---- C:\WINDOWS\system32\rtfexpt.dll
2010-07-05 14:41:05 ----A---- C:\WINDOWS\system32\VCFIWZ5.dll
2010-07-05 14:41:05 ----A---- C:\WINDOWS\system32\textexpt.dll
2010-07-05 14:41:04 ----A---- C:\WINDOWS\system32\pdfexpt.dll
2010-07-05 14:41:04 ----A---- C:\WINDOWS\system32\actrpt2.dll
2010-07-05 14:41:04 ----A---- C:\WINDOWS\system32\actrpt.dll
2010-07-05 14:41:01 ----A---- C:\WINDOWS\system32\ssr2c.dll
2010-07-05 14:41:01 ----A---- C:\WINDOWS\system32\ssprn32.dll
2010-07-05 14:41:01 ----A---- C:\WINDOWS\system32\ssmedt32.dll
2010-07-05 14:41:00 ----A---- C:\WINDOWS\system32\Olemsg32.dll
2010-07-05 14:40:53 ----A---- C:\WINDOWS\system32\msxml3a.dll
2010-07-05 14:38:18 ----A---- C:\WINDOWS\system32\dbmsqlgc.dll
2010-07-05 14:38:18 ----A---- C:\WINDOWS\system32\dbmsgnet.dll
2010-07-05 14:37:59 ----A---- C:\WINDOWS\IsUninst.exe
2010-07-05 14:37:23 ----D---- C:\Program Files\Microsoft SQL Server
2010-07-05 14:36:49 ----A---- C:\WINDOWS\system32\Vb5db.dll
2010-07-05 14:36:49 ----A---- C:\WINDOWS\system32\Odbctl32.dll
2010-07-05 14:36:49 ----A---- C:\WINDOWS\system32\Msrepl35.dll
2010-07-05 14:36:49 ----A---- C:\WINDOWS\system32\Msrd2x35.dll
2010-07-05 14:36:48 ----A---- C:\WINDOWS\system32\Msjter35.dll
2010-07-05 14:36:48 ----A---- C:\WINDOWS\system32\Msjint35.dll
2010-07-05 14:36:48 ----A---- C:\WINDOWS\system32\Msjet35.dll
2010-07-05 14:34:42 ----D---- C:\PP5
2010-07-05 14:05:05 ----A---- C:\WINDOWS\system32\drivers\tmevtmgr.sys
2010-07-05 14:05:05 ----A---- C:\WINDOWS\system32\drivers\tmcomm.sys
2010-07-05 14:05:05 ----A---- C:\WINDOWS\system32\drivers\tmactmon.sys
2010-07-05 14:04:46 ----D---- C:\Documents and Settings\All Users\Application Data\Trend Micro
2010-07-05 14:04:38 ----D---- C:\Program Files\Trend Micro
2010-07-05 14:03:58 ----A---- C:\WINDOWS\system32\drivers\vsapint.sys
2010-07-05 14:03:58 ----A---- C:\WINDOWS\system32\drivers\tmxpflt.sys
2010-07-05 14:03:58 ----A---- C:\WINDOWS\system32\drivers\tmtdi.sys
2010-07-05 14:03:58 ----A---- C:\WINDOWS\system32\drivers\tmpreflt.sys
2010-07-05 14:03:58 ----A---- C:\WINDOWS\system32\drivers\TM_CFW.sys
2010-07-05 14:00:41 ----D---- C:\Documents and Settings\Ben\Application Data\uTorrent
2010-07-05 13:49:24 ----D---- C:\Documents and Settings\Ben\Application Data\TeamViewer
2010-07-05 13:49:16 ----D---- C:\Program Files\TeamViewer
2010-07-05 13:48:21 ----A---- C:\WINDOWS\system32\drivers\usbscan.sys
2010-07-05 13:46:37 ----D---- C:\WINDOWS\system32\Lang
2010-07-05 13:42:17 ----D---- C:\WINDOWS\system32\AGEIA
2010-07-05 13:42:17 ----D---- C:\Program Files\AGEIA Technologies
2010-07-05 13:42:13 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-07-05 13:42:12 ----D---- C:\Documents and Settings\All Users\Application Data\NVIDIA Corporation
2010-07-05 13:41:56 ----D---- C:\Program Files\NVIDIA Corporation
2010-07-05 13:41:40 ----A---- C:\WINDOWS\system32\nvoglnt.dll
2010-07-05 13:41:40 ----A---- C:\WINDOWS\system32\nvcuvid.dll
2010-07-05 13:41:40 ----A---- C:\WINDOWS\system32\nvcuvenc.dll
2010-07-05 13:41:40 ----A---- C:\WINDOWS\system32\nvcuda.dll
2010-07-05 13:41:39 ----A---- C:\WINDOWS\system32\nvcodins.dll
2010-07-05 13:41:39 ----A---- C:\WINDOWS\system32\nvcod.dll
2010-07-05 13:41:39 ----A---- C:\WINDOWS\system32\nvapi.dll
2010-07-05 13:41:38 ----A---- C:\WINDOWS\system32\nv4_disp.dll
2010-07-05 13:41:38 ----A---- C:\WINDOWS\system32\drivers\nv4_mini.sys
2010-07-05 13:37:57 ----D---- C:\temp
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\ltkrn12n.dll
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\ltimg12n.dll
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\ltfil12n.DLL
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\lftif12n.dll
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\lffax12n.dll
2010-07-05 13:34:45 ----N---- C:\WINDOWS\system32\LFCMP12n.DLL
2010-07-05 13:34:45 ----N---- C:\WINDOWS\rmreg.exe
2010-07-05 13:34:45 ----N---- C:\WINDOWS\CM3.INI
2010-07-05 13:34:45 ----D---- C:\AV220
2010-07-05 13:32:07 ----SHD---- C:\RECYCLER
2010-07-05 13:27:56 ----D---- C:\Program Files\EPSON
2010-07-05 13:27:54 ----A---- C:\WINDOWS\system32\E_SL2404.DLL
2010-07-05 13:25:42 ----A---- C:\WINDOWS\system32\drivers\splitter.sys
2010-07-05 13:25:40 ----A---- C:\WINDOWS\system32\drivers\wdmaud.sys
2010-07-05 13:25:39 ----A---- C:\WINDOWS\system32\drivers\DMusic.sys
2010-07-05 13:25:37 ----A---- C:\WINDOWS\system32\drivers\swmidi.sys
2010-07-05 13:25:35 ----A---- C:\WINDOWS\system32\drivers\aec.sys
2010-07-05 13:25:34 ----A---- C:\WINDOWS\system32\drivers\kmixer.sys
2010-07-05 13:25:32 ----A---- C:\WINDOWS\system32\drivers\drmkaud.sys
2010-07-05 13:25:30 ----A---- C:\WINDOWS\system32\drivers\sysaudio.sys
2010-07-05 13:25:29 ----A---- C:\WINDOWS\system32\drivers\MSKSSRV.sys
2010-07-05 13:25:27 ----A---- C:\WINDOWS\system32\drivers\MSPQM.sys
2010-07-05 13:25:25 ----A---- C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2010-07-05 13:22:30 ----D---- C:\WINDOWS\system32\RTCOM
2010-07-05 13:22:28 ----A---- C:\WINDOWS\system32\ksuser.dll
2010-07-05 13:22:28 ----A---- C:\WINDOWS\system32\drivers\portcls.sys
2010-07-05 13:22:28 ----A---- C:\WINDOWS\system32\drivers\drmk.sys
2010-07-05 13:22:24 ----A---- C:\WINDOWS\vncutil.exe
2010-07-05 13:22:24 ----A---- C:\WINDOWS\SOUNDMAN.EXE
2010-07-05 13:22:24 ----A---- C:\WINDOWS\SkyTel.exe
2010-07-05 13:22:23 ----A---- C:\WINDOWS\system32\RtkCoInstXP.dll
2010-07-05 13:22:23 ----A---- C:\WINDOWS\system32\drivers\RtkHDAud.sys
2010-07-05 13:22:23 ----A---- C:\WINDOWS\system32\drivers\Monfilt.sys
2010-07-05 13:22:23 ----A---- C:\WINDOWS\RtlUpd.exe
2010-07-05 13:22:23 ----A---- C:\WINDOWS\RTLCPL.EXE
2010-07-05 13:22:23 ----A---- C:\WINDOWS\RtkAudioService.exe
2010-07-05 13:22:23 ----A---- C:\WINDOWS\RTHDCPL.EXE
2010-07-05 13:22:22 ----A---- C:\WINDOWS\system32\drivers\Ambfilt.sys
2010-07-05 13:22:22 ----A---- C:\WINDOWS\MicCal.exe
2010-07-05 13:22:22 ----A---- C:\WINDOWS\ALCWZRD.EXE
2010-07-05 13:22:22 ----A---- C:\WINDOWS\ALCMTR.EXE
2010-07-05 13:21:59 ----A---- C:\WINDOWS\RtlExUpd.dll
2010-07-05 13:21:56 ----D---- C:\Program Files\Common Files\InstallShield
2010-07-05 13:14:05 ----A---- C:\WINDOWS\system32\drivers\sbmount.sys
2010-07-05 13:13:59 ----A---- C:\WINDOWS\system32\drivers\stcvsm.sys
2010-07-05 13:13:49 ----A---- C:\WINDOWS\system32\vsnapvss.exe
2010-07-05 13:13:43 ----D---- C:\Program Files\StorageCraft
2010-07-05 13:13:43 ----A---- C:\WINDOWS\system32\stcsnap.dll
2010-07-05 13:13:14 ----D---- C:\Documents and Settings\Ben\Application Data\InstallShield
2010-07-05 13:03:44 ----A---- C:\WINDOWS\system32\hidserv.dll
2010-07-05 13:03:40 ----A---- C:\WINDOWS\system32\drivers\kbdhid.sys
2010-07-05 12:57:45 ----A---- C:\WINDOWS\system32\drivers\usbprint.sys
2010-07-05 12:57:41 ----A---- C:\WINDOWS\system32\drivers\usbccgp.sys
2010-07-05 08:17:01 ----HDC---- C:\WINDOWS\$NtUninstallKB971737$
2010-07-05 08:16:58 ----HDC---- C:\WINDOWS\$NtUninstallKB970430$
2010-07-05 06:05:31 ----A---- C:\WINDOWS\system32\h323log.txt
2010-07-05 02:56:38 ----A---- C:\WINDOWS\system32\drivers\audstub.sys
2010-07-05 02:56:11 ----A---- C:\WINDOWS\system32\drivers\redbook.sys
2010-07-05 02:55:23 ----A---- C:\WINDOWS\system32\drivers\enum1394.sys
2010-07-05 02:55:02 ----A---- C:\WINDOWS\system32\usbui.dll
2010-07-05 02:54:02 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2010-07-05 02:54:01 ----SHD---- C:\WINDOWS\Installer
2010-07-05 02:54:01 ----D---- C:\Program Files\Common Files\ODBC
2010-07-05 02:54:01 ----A---- C:\WINDOWS\ODBCINST.INI
2010-07-05 02:53:58 ----D---- C:\Program Files\Common Files\SpeechEngines
2010-07-05 02:53:57 ----RD---- C:\Program Files
2010-07-05 02:53:57 ----D---- C:\Program Files\Common Files\Microsoft Shared
2010-07-05 02:53:57 ----D---- C:\Program Files\Common Files
2010-07-05 02:53:53 ----RA---- C:\WINDOWS\system32\kbdtuq.dll
2010-07-05 02:53:53 ----RA---- C:\WINDOWS\system32\kbdtuf.dll
2010-07-05 02:53:53 ----RA---- C:\WINDOWS\system32\kbdazel.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbduzb.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbdtat.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbdmon.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbdkyr.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbdkaz.dll
2010-07-05 02:53:51 ----RA---- C:\WINDOWS\system32\kbdaze.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdycc.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdur.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdru1.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdru.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdbu.dll
2010-07-05 02:53:50 ----RA---- C:\WINDOWS\system32\kbdblr.dll
2010-07-05 02:53:48 ----RA---- C:\WINDOWS\system32\kbdhept.dll
2010-07-05 02:53:48 ----RA---- C:\WINDOWS\system32\kbdhela3.dll
2010-07-05 02:53:48 ----RA---- C:\WINDOWS\system32\kbdhela2.dll
2010-07-05 02:53:48 ----RA---- C:\WINDOWS\system32\kbdhe319.dll
2010-07-05 02:53:48 ----RA---- C:\WINDOWS\system32\kbdhe220.dll
2010-07-05 02:53:47 ----RA---- C:\WINDOWS\system32\kbdhe.dll
2010-07-05 02:53:47 ----RA---- C:\WINDOWS\system32\kbdgkl.dll
2010-07-05 02:53:45 ----RA---- C:\WINDOWS\system32\kbdlv1.dll
2010-07-05 02:53:45 ----RA---- C:\WINDOWS\system32\kbdlv.dll
2010-07-05 02:53:45 ----RA---- C:\WINDOWS\system32\kbdlt1.dll
2010-07-05 02:53:45 ----RA---- C:\WINDOWS\system32\kbdlt.dll
2010-07-05 02:53:45 ----RA---- C:\WINDOWS\system32\kbdest.dll
2010-07-05 02:53:43 ----RA---- C:\WINDOWS\system32\kbdsl1.dll
2010-07-05 02:53:43 ----RA---- C:\WINDOWS\system32\kbdsl.dll
2010-07-05 02:53:43 ----RA---- C:\WINDOWS\system32\kbdro.dll
2010-07-05 02:53:43 ----RA---- C:\WINDOWS\system32\kbdpl1.dll
2010-07-05 02:53:43 ----RA---- C:\WINDOWS\system32\kbdpl.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdycl.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdhu1.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdhu.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdcz2.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdcz1.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdcz.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\kbdcr.dll
2010-07-05 02:53:42 ----RA---- C:\WINDOWS\system32\KBDAL.DLL
2010-07-05 02:53:40 ----A---- C:\WINDOWS\system32\spxcoins.dll
2010-07-05 02:53:40 ----A---- C:\WINDOWS\system32\irclass.dll
2010-07-05 02:53:40 ----A---- C:\WINDOWS\system32\dgsetup.dll
2010-07-05 02:53:40 ----A---- C:\WINDOWS\system32\dgrpsetu.dll
2010-07-05 02:53:39 ----A---- C:\WINDOWS\system32\EqnClass.Dll
2010-07-05 02:53:37 ----A---- C:\WINDOWS\TASKMAN.EXE
2010-07-05 02:53:37 ----A---- C:\WINDOWS\system32\drivers\irenum.sys
2010-07-05 02:53:36 ----A---- C:\WINDOWS\system32\batt.dll
2010-07-05 02:53:36 ----A---- C:\WINDOWS\NOTEPAD.EXE
2010-07-05 02:53:35 ----A---- C:\WINDOWS\system32\storprop.dll
2010-07-05 02:53:28 ----ASH---- C:\Documents and Settings\All Users\Application Data\desktop.ini
2010-07-05 02:53:16 ----D---- C:\WINDOWS\system32\CatRoot2
2010-07-05 02:53:16 ----D---- C:\WINDOWS\system32\CatRoot
2010-07-05 02:53:11 ----SD---- C:\Documents and Settings\All Users\Application Data\Microsoft
2010-07-05 02:50:27 ----SHD---- C:\System Volume Information
2010-07-05 02:50:27 ----D---- C:\Documents and Settings
2010-07-05 02:49:43 ----SH---- C:\boot.ini
2010-07-05 02:44:39 ----RSHDC---- C:\WINDOWS\system32\dllcache
2010-07-05 02:44:39 ----RSD---- C:\WINDOWS\Fonts
2010-07-05 02:44:39 ----RD---- C:\WINDOWS\Web
2010-07-05 02:44:39 ----HD---- C:\WINDOWS\inf
2010-07-05 02:44:39 ----D---- C:\WINDOWS\WinSxS
2010-07-05 02:44:39 ----D---- C:\WINDOWS\twain_32
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Temp
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\wins
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\wbem
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\usmt
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\spool
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\ShellExt
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\Setup
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\scripting
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\ras
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\oobe
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\npp
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\mui
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\inetsrv
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\IME
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\icsxml
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\ias
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\export
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\en
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\drivers\etc
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\drivers\disdn
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\drivers
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\dhcp
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\config
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\3com_dmi
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\3076
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\2052
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1054
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1042
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1041
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1037
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1033
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1031
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1028
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32\1025
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system32
2010-07-05 02:44:39 ----D---- C:\WINDOWS\system
2010-07-05 02:44:39 ----D---- C:\WINDOWS\security
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Resources
2010-07-05 02:44:39 ----D---- C:\WINDOWS\repair
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Provisioning
2010-07-05 02:44:39 ----D---- C:\WINDOWS\PeerNet
2010-07-05 02:44:39 ----D---- C:\WINDOWS\pchealth
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Network Diagnostic
2010-07-05 02:44:39 ----D---- C:\WINDOWS\mui
2010-07-05 02:44:39 ----D---- C:\WINDOWS\msapps
2010-07-05 02:44:39 ----D---- C:\WINDOWS\msagent
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Media
2010-07-05 02:44:39 ----D---- C:\WINDOWS\L2Schemas
2010-07-05 02:44:39 ----D---- C:\WINDOWS\java
2010-07-05 02:44:39 ----D---- C:\WINDOWS\ime
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Help
2010-07-05 02:44:39 ----D---- C:\WINDOWS\ehome
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Driver Cache
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Debug
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Cursors
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Connection Wizard
2010-07-05 02:44:39 ----D---- C:\WINDOWS\Config
2010-07-05 02:44:39 ----D---- C:\WINDOWS\AppPatch
2010-07-05 02:44:39 ----D---- C:\WINDOWS\addins
2010-07-05 02:44:39 ----D---- C:\WINDOWS
2010-07-05 02:44:39 ----ASH---- C:\pagefile.sys
2010-07-05 00:10:41 ----HDC---- C:\WINDOWS\$NtUninstallKB982381$
2010-07-05 00:10:37 ----HDC---- C:\WINDOWS\$NtUninstallKB979559$
2010-07-05 00:10:08 ----HDC---- C:\WINDOWS\$NtUninstallKB975562$
2010-07-05 00:10:06 ----HDC---- C:\WINDOWS\$NtUninstallKB979482$
2010-07-05 00:10:03 ----HDC---- C:\WINDOWS\$NtUninstallKB980195$
2010-07-05 00:10:00 ----HDC---- C:\WINDOWS\$NtUninstallKB980218$
2010-07-05 00:09:56 ----HDC---- C:\WINDOWS\$NtUninstallKB978542$
2010-07-05 00:09:53 ----HDC---- C:\WINDOWS\$NtUninstallKB978601$
2010-07-05 00:09:50 ----HDC---- C:\WINDOWS\$NtUninstallKB979402_WM9$
2010-07-05 00:09:48 ----HDC---- C:\WINDOWS\$NtUninstallKB981349$
2010-07-05 00:09:44 ----HDC---- C:\WINDOWS\$NtUninstallKB979683$
2010-07-05 00:09:40 ----HDC---- C:\WINDOWS\$NtUninstallKB978338$
2010-07-05 00:09:37 ----HDC---- C:\WINDOWS\$NtUninstallKB977816$
2010-07-05 00:09:34 ----HDC---- C:\WINDOWS\$NtUninstallKB980232$
2010-07-05 00:09:31 ----HDC---- C:\WINDOWS\$NtUninstallKB975561$
2010-07-05 00:09:28 ----HDC---- C:\WINDOWS\$NtUninstallKB978706$
2010-07-05 00:09:25 ----HDC---- C:\WINDOWS\$NtUninstallKB971468$
2010-07-05 00:09:22 ----HDC---- C:\WINDOWS\$NtUninstallKB977914$
2010-07-05 00:09:19 ----HDC---- C:\WINDOWS\$NtUninstallKB975560$
2010-07-05 00:09:15 ----HDC---- C:\WINDOWS\$NtUninstallKB978037$
2010-07-05 00:09:12 ----HDC---- C:\WINDOWS\$NtUninstallKB975713$
2010-07-05 00:09:09 ----HDC---- C:\WINDOWS\$NtUninstallKB972270$
2010-07-05 00:09:05 ----HDC---- C:\WINDOWS\$NtUninstallKB955759$
2010-07-05 00:09:02 ----HDC---- C:\WINDOWS\$NtUninstallKB974392$
2010-07-05 00:08:59 ----HDC---- C:\WINDOWS\$NtUninstallKB974318$
2010-07-05 00:08:56 ----HDC---- C:\WINDOWS\$NtUninstallKB975467$
2010-07-05 00:08:52 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$
2010-07-05 00:08:49 ----HDC---- C:\WINDOWS\$NtUninstallKB969059$
2010-07-05 00:08:47 ----HDC---- C:\WINDOWS\$NtUninstallKB958869$
2010-07-05 00:08:44 ----HDC---- C:\WINDOWS\$NtUninstallKB974112$
2010-07-05 00:08:41 ----HDC---- C:\WINDOWS\$NtUninstallKB974571$
2010-07-05 00:08:38 ----HDC---- C:\WINDOWS\$NtUninstallKB975025$
2010-07-05 00:08:35 ----HDC---- C:\WINDOWS\$NtUninstallKB954155_WM9$
2010-07-05 00:08:32 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$
2010-07-05 00:08:13 ----D---- C:\WINDOWS\ie8updates
2010-07-05 00:08:05 ----D---- C:\WINDOWS\WBEM
2010-07-05 00:06:55 ----HDC---- C:\WINDOWS\ie8
2010-07-05 00:06:29 ----A---- C:\WINDOWS\system32\MRT.exe
2010-07-05 00:00:54 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$
2010-07-05 00:00:51 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$
2010-07-05 00:00:48 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$
2010-07-05 00:00:45 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$
2010-07-05 00:00:41 ----HDC---- C:\WINDOWS\$NtUninstallKB956744$
2010-07-05 00:00:37 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9$
2010-07-05 00:00:34 ----HDC---- C:\WINDOWS\$NtUninstallKB963093$
2010-07-05 00:00:26 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$
2010-07-05 00:00:23 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$
2010-07-05 00:00:20 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$
2010-07-05 00:00:17 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$
2010-07-05 00:00:13 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$
2010-07-05 00:00:09 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$
2010-07-05 00:00:05 ----HDC---- C:\WINDOWS\$NtUninstallKB967715$
2010-07-05 00:00:02 ----HDC---- C:\WINDOWS\$NtUninstallKB960225$
======List of files/folders modified in the last 1 months======
2010-08-04 20:15:17 ----D---- C:\WINDOWS\Prefetch
2010-08-04 19:57:13 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2010-08-04 19:54:46 ----A---- C:\WINDOWS\SchedLgU.Txt
2010-08-03 18:54:53 ----D---- C:\WINDOWS\Registration
2010-08-03 14:51:26 ----HD---- C:\WINDOWS\$hf_mig$
2010-08-03 08:54:25 ----A---- C:\WINDOWS\NeroDigital.ini
2010-07-29 20:03:47 ----SD---- C:\WINDOWS\Downloaded Program Files
2010-07-27 19:34:46 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help
2010-07-27 19:31:55 ----A---- C:\WINDOWS\win.ini
2010-07-27 16:30:35 ----A---- C:\WINDOWS\system32\shell32.dll
2010-07-24 07:50:20 ----SD---- C:\WINDOWS\Tasks
2010-07-23 22:21:46 ----N---- C:\WINDOWS\system.ini
2010-07-23 21:48:46 ----D---- C:\WINDOWS\system32\en-US
2010-07-23 21:46:55 ----D---- C:\Program Files\Microsoft Works
2010-07-23 19:08:43 ----D---- C:\Program Files\Internet Explorer
2010-07-23 19:06:52 ----D---- C:\Program Files\Windows Media Player
2010-07-09 14:07:07 ----D---- C:\Documents and Settings\Ben\Application Data\Adobe
2010-07-08 09:35:31 ----SD---- C:\Documents and Settings\Ben\Application Data\Microsoft
2010-07-06 07:16:55 ----HD---- C:\Program Files\InstallShield Installation Information
2010-07-05 14:38:16 ----HD---- C:\Program Files\Uninstall Information
2010-07-05 13:22:22 ----D---- C:\Program Files\Realtek
2010-07-05 08:10:19 ----D---- C:\Program Files\Outlook Express
2010-07-05 02:53:28 ----SH---- C:\Documents and Settings\Ben\Application Data\desktop.ini
2010-07-05 00:09:33 ----D---- C:\Program Files\Movie Maker
2010-07-05 00:00:36 ----D---- C:\Program Files\Windows Desktop Search
2010-07-05 00:00:00 ----HDC---- C:\WINDOWS\$NtUninstallKB956803$
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 ohci1394;VIA OHCI Compliant IEEE 1394 Host Controller; C:\WINDOWS\system32\DRIVERS\ohci1394.sys [2008-04-14 61696]
R0 stcvsm;stcvsm; C:\WINDOWS\system32\drivers\stcvsm.sys [2010-04-21 182048]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 36352]
R1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592]
R1 sbmount;StorageCraft Image Mount Driver; C:\WINDOWS\system32\drivers\sbmount.sys [2010-04-21 102560]
R1 tmtdi;Trend Micro TDI Driver; C:\WINDOWS\system32\DRIVERS\tmtdi.sys [2010-07-05 89872]
R2 tmcomm;tmcomm; \??\C:\WINDOWS\system32\drivers\tmcomm.sys []
R2 tmpreflt;tmpreflt; C:\WINDOWS\system32\DRIVERS\tmpreflt.sys [2009-12-05 36368]
R2 tmxpflt;tmxpflt; C:\WINDOWS\system32\DRIVERS\tmxpflt.sys [2009-12-05 230928]
R2 vsapint;vsapint; C:\WINDOWS\system32\DRIVERS\vsapint.sys [2009-12-05 1322680]
R3 Arp1394;1394 ARP Client Protocol; C:\WINDOWS\system32\DRIVERS\arp1394.sys [2008-04-14 60800]
R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384]
R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2009-03-30 5063168]
R3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160]
R3 NIC1394;1394 Net Driver; C:\WINDOWS\system32\DRIVERS\nic1394.sys [2008-04-14 61824]
R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2009-09-28 7655872]
R3 RTLE8023xp;Realtek 10/100/1000 PCI-E NIC Family NDIS XP Driver; C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys [2009-05-25 142336]
R3 tmactmon;tmactmon; \??\C:\WINDOWS\system32\drivers\tmactmon.sys []
R3 tmcfw;Trend Micro Common Firewall Service; C:\WINDOWS\system32\DRIVERS\TM_CFW.sys [2010-07-05 339984]
R3 tmevtmgr;tmevtmgr; \??\C:\WINDOWS\system32\drivers\tmevtmgr.sys []
R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128]
R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856]
R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104]
R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\system32\DRIVERS\usbuhci.sys [2008-04-14 20608]
S3 Ambfilt;Ambfilt; C:\WINDOWS\system32\drivers\Ambfilt.sys [2008-08-05 1684736]
S3 Monfilt;Monfilt; C:\WINDOWS\system32\drivers\Monfilt.sys [2006-01-04 1389056]
S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568]
S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe [2006-10-26 335872]
R2 MSSQL$INGAUSTRALIA;MSSQL$INGAUSTRALIA; C:\Program Files\Microsoft SQL Server\MSSQL$INGAUSTRALIA\Binn\sqlservr.exe [2002-12-17 7520337]
R2 MSSQLSERVER;MSSQLSERVER; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlservr.exe [2002-12-17 7520337]
R2 nvsvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2009-09-27 172100]
R2 SfCtlCom;Trend Micro Central Control Component; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [2010-01-26 715368]
R2 ShadowProtectSvc;ShadowProtect Service; C:\Program Files\StorageCraft\ShadowProtect\ShadowProtectSvc.exe [2010-04-21 1649184]
R2 SQLSERVERAGENT;SQLSERVERAGENT; C:\Program Files\Microsoft SQL Server\MSSQL\Binn\sqlagent.EXE [2002-12-17 311872]
R2 TeamViewer5;TeamViewer 5; C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe [2010-06-28 173352]
R2 VSNAPVSS;StorageCraft Shadow Copy Provider; C:\WINDOWS\system32\vsnapvss.exe [2010-04-21 67616]
R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808]
R3 TMBMServer;Trend Micro Unauthorized Change Prevention Service; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [2010-07-05 345352]
R3 TmPfw;Trend Micro Personal Firewall; C:\Program Files\Trend Micro\Internet Security\TmPfw.exe [2010-07-05 497008]
R3 TmProxy;Trend Micro Proxy Service; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [2010-07-05 689416]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-07-09 651720]
S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104]
S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664]
S3 MSSQLServerADHelper;MSSQLServerADHelper; C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe [2002-12-17 66112]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S3 SQLAgent$INGAUSTRALIA;SQLAgent$INGAUSTRALIA; C:\Program Files\Microsoft SQL Server\MSSQL$INGAUSTRALIA\Binn\sqlagent.EXE [2002-12-17 311872]
S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0; C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336]
S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096]
-----------------EOF-----------------