the performance of my computer doesn't seem any different at all. I did not experience slow load times or anything after contracting the infections, but was having security breaches to sensitive personal information including banking information. This is where my concern lies since I did have some money stolen from my accounts. I did get this resolved with the banks, but I assumed that the same software that has allowed people onto my PC is what allowed my banking information to be compromised. Thank you and I hope this answers your question.
Here is the seperate post of the long version of the RSIT scan that generated the log.txt file:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Owner at 2010-11-02 21:13:36
Microsoft® Windows Vista™ Home Premium Service Pack 2
System drive C: has 13 GB (18%) free of 71 GB
Total RAM: 1790 MB (53% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 9:14:00 PM, on 11/2/2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v7.00 (7.00.6002.18005)
Boot mode: Normal
Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\ehome\ehtray.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Skype\Toolbars\Shared\SkypeNames2.exe
C:\Users\Owner\Downloads\RSIT.exe
C:\Program Files\trend micro\Owner.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://search.conduit.com?SearchSource= ... =CT2077543R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://en.us.acer.yahoo.comR1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.com/customize/ycomp/ ... .yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Windows\system32\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: E&xport to Microsoft Excel -
res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
--
End of file - 3636 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
&Yahoo! Toolbar Helper - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-09-05 816400]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897}]
Yahoo! IE Services Button - C:\Program Files\Yahoo!\Common\yiesrvc.dll [2006-10-31 198136]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - Acer eDataSecurity Management - C:\Windows\system32\eDStoolbar.dll [2007-04-25 151552]
{EF99BD32-C1FB-11D2-892F-0090271D4F88} - Yahoo! Toolbar - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll [2007-09-05 816400]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"Yahoo! Pager"=C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]
"ehTray.exe"=C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Assist Launcher]
C:\Program Files\Acer Assist\launcher.exe [2007-02-02 1261568]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Product Registration]
C:\Program Files\Acer Registration\ACE1.exe [2007-02-02 3383296]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Acer Tour Reminder]
C:\Acer\AcerTour\Reminder.exe [2007-05-22 151552]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe ARM]
C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2010-09-21 932288]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-12-22 35760]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
C:\Program Files\Apoint2K\Apoint.exe [2007-06-06 159744]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eAudio]
C:\Acer\Empowering Technology\eAudio\eAudio.exe [2007-06-11 1286144]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\eDataSecurity Loader]
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe [2007-04-25 457216]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ehTray.exe]
C:\Windows\ehome\ehTray.exe [2008-01-19 125952]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper]
C:\Program Files\iTunes\iTunesHelper.exe [2009-09-21 305440]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LManager]
C:\PROGRA~1\LAUNCH~1\LManager.exe [2007-06-27 752136]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSSE]
C:\Program Files\Microsoft Security Essentials\msseces.exe [2010-09-15 1094224]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
C:\Windows\system32\NvCpl.dll [2009-01-30 13605408]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
C:\Windows\system32\NvMcTray.dll [2009-01-30 92704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PLFSet]
C:\Windows\PLFSet.dll [2007-04-24 45056]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
C:\Program Files\QuickTime\QTTask.exe [2009-09-05 417792]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RtHDVCpl]
C:\Windows\RtHDVCpl.exe [2007-05-18 4468736]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skytel]
C:\Windows\Skytel.exe [2007-05-18 1826816]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched]
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\tbhSystray]
C:\Program Files\tbh\base\bin\tbhSystray.exe [2010-10-29 492840]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Windows Defender]
C:\Program Files\Windows Defender\MSASCui.exe [2008-01-19 1008184]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WMPNSCFG]
C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Yahoo! Pager]
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe [2007-08-30 4670704]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Empowering Technology Launcher.lnk]
C:\Acer\EMPOWE~1\EAPLAU~1.EXE [2007-04-14 535336]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MsMpSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-11-02 21:13:36 ----D---- C:\rsit
2010-11-01 22:51:23 ----A---- C:\Windows\system32\drivers\mbamswissarmy.sys
2010-11-01 22:51:20 ----A---- C:\Windows\system32\drivers\mbam.sys
2010-11-01 22:51:19 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2010-10-30 18:09:30 ----D---- C:\ProgramData\SUPERAntiSpyware.com
2010-10-29 18:23:10 ----A---- C:\Windows\system32\gameux.dll
2010-10-29 18:23:00 ----A---- C:\Windows\system32\Apphlpdm.dll
2010-10-29 18:22:59 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll
2010-10-17 15:35:30 ----D---- C:\Program Files\Windows Portable Devices
2010-10-17 15:20:26 ----A---- C:\Windows\system32\UIAnimation.dll
2010-10-17 15:20:24 ----A---- C:\Windows\system32\UIRibbonRes.dll
2010-10-17 15:20:24 ----A---- C:\Windows\system32\UIRibbon.dll
2010-10-17 15:19:34 ----A---- C:\Windows\system32\WMPhoto.dll
2010-10-17 15:19:32 ----A---- C:\Windows\system32\drivers\dxgkrnl.sys
2010-10-17 15:19:32 ----A---- C:\Windows\system32\cdd.dll
2010-10-17 15:19:30 ----A---- C:\Windows\system32\printfilterpipelineprxy.dll
2010-10-17 15:19:30 ----A---- C:\Windows\system32\d3d10warp.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\XpsRasterService.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\XpsGdiConverter.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\WindowsCodecsExt.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\WindowsCodecs.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\PhotoMetadataHandler.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\dxdiagn.dll
2010-10-17 15:19:29 ----A---- C:\Windows\system32\d2d1.dll
2010-10-17 15:19:28 ----A---- C:\Windows\system32\XpsPrint.dll
2010-10-17 15:19:28 ----A---- C:\Windows\system32\printfilterpipelinesvc.exe
2010-10-17 15:19:28 ----A---- C:\Windows\system32\OpcServices.dll
2010-10-17 15:19:28 ----A---- C:\Windows\system32\dxdiag.exe
2010-10-17 15:19:27 ----A---- C:\Windows\system32\xpsservices.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\FntCache.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\DWrite.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\d3d11.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\d3d10level9.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\d3d10core.dll
2010-10-17 15:19:26 ----A---- C:\Windows\system32\d3d10_1core.dll
2010-10-17 15:19:25 ----A---- C:\Windows\system32\dxgi.dll
2010-10-17 15:19:25 ----A---- C:\Windows\system32\d3d10_1.dll
2010-10-17 15:19:25 ----A---- C:\Windows\system32\d3d10.dll
2010-10-17 15:18:23 ----A---- C:\Windows\system32\WPDShextAutoplay.exe
2010-10-17 15:18:22 ----A---- C:\Windows\system32\wpdbusenum.dll
2010-10-17 15:18:22 ----A---- C:\Windows\system32\BthMtpContextHandler.dll
2010-10-17 15:18:09 ----A---- C:\Windows\system32\PortableDeviceConnectApi.dll
2010-10-17 15:17:56 ----A---- C:\Windows\system32\WpdConns.dll
2010-10-17 15:17:55 ----A---- C:\Windows\system32\WpdMtpUS.dll
2010-10-17 15:17:55 ----A---- C:\Windows\system32\drivers\WpdUsb.sys
2010-10-17 15:17:46 ----A---- C:\Windows\system32\WPDShServiceObj.dll
2010-10-17 15:17:46 ----A---- C:\Windows\system32\wpdshext.dll
2010-10-17 15:17:46 ----A---- C:\Windows\system32\WpdMtp.dll
2010-10-17 15:17:46 ----A---- C:\Windows\system32\wpd_ci.dll
2010-10-17 15:17:46 ----A---- C:\Windows\system32\PortableDeviceTypes.dll
2010-10-17 15:17:45 ----A---- C:\Windows\system32\PortableDeviceApi.dll
2010-10-17 15:17:44 ----A---- C:\Windows\system32\WPDSp.dll
2010-10-17 15:17:44 ----A---- C:\Windows\system32\PortableDeviceWMDRM.dll
2010-10-17 15:17:44 ----A---- C:\Windows\system32\PortableDeviceClassExtension.dll
2010-10-17 15:14:25 ----A---- C:\Windows\system32\oleaccrc.dll
2010-10-17 15:14:23 ----A---- C:\Windows\system32\UIAutomationCore.dll
2010-10-17 15:14:23 ----A---- C:\Windows\system32\oleacc.dll
2010-10-14 15:39:24 ----D---- C:\ProgramData\WindowsSearch
2010-10-13 12:44:55 ----D---- C:\Windows\system32\eu-ES
2010-10-13 12:44:55 ----D---- C:\Windows\system32\ca-ES
2010-10-13 12:44:54 ----D---- C:\Windows\system32\vi-VN
2010-10-12 18:44:03 ----A---- C:\Windows\system32\srvsvc.dll
2010-10-12 18:44:02 ----A---- C:\Windows\system32\drivers\srvnet.sys
2010-10-12 18:44:02 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-10-12 18:44:02 ----A---- C:\Windows\system32\drivers\srv.sys
2010-10-12 18:44:01 ----A---- C:\Windows\system32\netevent.dll
2010-10-12 18:43:54 ----A---- C:\Windows\system32\mfc40.dll
2010-10-12 18:43:53 ----A---- C:\Windows\system32\mfc40u.dll
2010-10-12 18:38:19 ----A---- C:\Windows\system32\ieframe.dll
2010-10-12 18:38:17 ----A---- C:\Windows\system32\msfeeds.dll
2010-10-12 18:38:15 ----A---- C:\Windows\system32\mshtml.dll
2010-10-12 18:38:15 ----A---- C:\Windows\system32\ieapfltr.dll
2010-10-12 18:38:14 ----A---- C:\Windows\system32\mshtmled.dll
2010-10-12 18:38:13 ----A---- C:\Windows\system32\urlmon.dll
2010-10-12 18:38:12 ----A---- C:\Windows\system32\wininet.dll
2010-10-12 18:38:11 ----A---- C:\Windows\system32\iepeers.dll
2010-10-12 18:38:11 ----A---- C:\Windows\system32\ieencode.dll
2010-10-12 18:37:55 ----A---- C:\Windows\system32\wmp.dll
2010-10-12 18:37:52 ----A---- C:\Windows\system32\wmploc.DLL
2010-10-12 18:37:12 ----A---- C:\Windows\system32\schannel.dll
2010-10-12 18:37:09 ----A---- C:\Windows\system32\ole32.dll
2010-10-12 18:37:04 ----A---- C:\Windows\system32\t2embed.dll
2010-10-12 18:13:25 ----A---- C:\Windows\system32\comctl32.dll
2010-10-12 17:41:36 ----A---- C:\Windows\system32\win32k.sys
2010-10-12 17:35:07 ----A---- C:\Windows\system32\wmpmde.dll
2010-10-12 13:37:18 ----D---- C:\Windows\system32\EventProviders
======List of files/folders modified in the last 1 months======
2010-11-02 21:14:00 ----D---- C:\Program Files\Trend Micro
2010-11-02 21:13:38 ----D---- C:\Windows\temp
2010-11-02 21:08:10 ----D---- C:\Users\Owner\AppData\Roaming\Skype
2010-11-02 16:46:06 ----D---- C:\Users\Owner\AppData\Roaming\skypePM
2010-11-01 22:52:35 ----D---- C:\Windows\System32
2010-11-01 22:52:35 ----D---- C:\Windows\inf
2010-11-01 22:52:35 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-11-01 22:51:23 ----D---- C:\Windows\system32\drivers
2010-11-01 22:51:19 ----RD---- C:\Program Files
2010-11-01 21:57:41 ----SHD---- C:\System Volume Information
2010-11-01 21:56:45 ----D---- C:\Program Files\Mozilla Firefox
2010-11-01 21:50:53 ----SHD---- C:\Windows\Installer
2010-11-01 21:50:44 ----D---- C:\Program Files\Common Files
2010-11-01 20:46:46 ----D---- C:\Windows\Logs
2010-10-30 18:09:30 ----D---- C:\ProgramData
2010-10-30 12:21:09 ----D---- C:\Windows\winsxs
2010-10-30 12:21:08 ----D---- C:\Windows\AppPatch
2010-10-29 20:11:06 ----D---- C:\Windows\pss
2010-10-29 18:42:48 ----A---- C:\Windows\ntbtlog.txt
2010-10-26 15:30:35 ----D---- C:\Windows\system32\catroot2
2010-10-26 15:30:35 ----D---- C:\Windows\system32\catroot
2010-10-19 16:51:33 ----N---- C:\Windows\system32\MpSigStub.exe
2010-10-17 15:54:52 ----D---- C:\Windows\rescache
2010-10-17 15:39:57 ----D---- C:\Windows\system32\Tasks
2010-10-17 15:35:40 ----D---- C:\Windows
2010-10-17 15:35:31 ----D---- C:\Windows\system32\en-US
2010-10-17 15:35:30 ----D---- C:\Windows\system32\wbem
2010-10-17 15:35:30 ----D---- C:\Windows\system32\drivers\en-US
2010-10-17 15:35:28 ----D---- C:\Windows\system32\zh-TW
2010-10-17 15:35:28 ----D---- C:\Windows\system32\zh-HK
2010-10-17 15:35:28 ----D---- C:\Windows\system32\zh-CN
2010-10-17 15:35:28 ----D---- C:\Windows\system32\uk-UA
2010-10-17 15:35:28 ----D---- C:\Windows\system32\tr-TR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\th-TH
2010-10-17 15:35:28 ----D---- C:\Windows\system32\sv-SE
2010-10-17 15:35:28 ----D---- C:\Windows\system32\sr-Latn-CS
2010-10-17 15:35:28 ----D---- C:\Windows\system32\sl-SI
2010-10-17 15:35:28 ----D---- C:\Windows\system32\sk-SK
2010-10-17 15:35:28 ----D---- C:\Windows\system32\ru-RU
2010-10-17 15:35:28 ----D---- C:\Windows\system32\ro-RO
2010-10-17 15:35:28 ----D---- C:\Windows\system32\pt-PT
2010-10-17 15:35:28 ----D---- C:\Windows\system32\pt-BR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\pl-PL
2010-10-17 15:35:28 ----D---- C:\Windows\system32\nl-NL
2010-10-17 15:35:28 ----D---- C:\Windows\system32\nb-NO
2010-10-17 15:35:28 ----D---- C:\Windows\system32\lv-LV
2010-10-17 15:35:28 ----D---- C:\Windows\system32\lt-LT
2010-10-17 15:35:28 ----D---- C:\Windows\system32\ko-KR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\ja-JP
2010-10-17 15:35:28 ----D---- C:\Windows\system32\it-IT
2010-10-17 15:35:28 ----D---- C:\Windows\system32\hu-HU
2010-10-17 15:35:28 ----D---- C:\Windows\system32\hr-HR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\he-IL
2010-10-17 15:35:28 ----D---- C:\Windows\system32\fr-FR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\fi-FI
2010-10-17 15:35:28 ----D---- C:\Windows\system32\et-EE
2010-10-17 15:35:28 ----D---- C:\Windows\system32\es-ES
2010-10-17 15:35:28 ----D---- C:\Windows\system32\el-GR
2010-10-17 15:35:28 ----D---- C:\Windows\system32\de-DE
2010-10-17 15:35:28 ----D---- C:\Windows\system32\da-DK
2010-10-17 15:35:28 ----D---- C:\Windows\system32\cs-CZ
2010-10-17 15:35:28 ----D---- C:\Windows\system32\bg-BG
2010-10-17 15:35:28 ----D---- C:\Windows\system32\ar-SA
2010-10-17 15:35:14 ----D---- C:\Windows\system32\drivers\UMDF
2010-10-14 16:54:40 ----D---- C:\Windows\Minidump
2010-10-14 07:31:52 ----D---- C:\Windows\Microsoft.NET
2010-10-14 07:31:50 ----RSD---- C:\Windows\assembly
2010-10-13 12:55:22 ----SHD---- C:\Boot
2010-10-13 12:45:34 ----D---- C:\Program Files\Windows Sidebar
2010-10-13 12:45:34 ----D---- C:\Program Files\Windows Mail
2010-10-13 12:45:34 ----D---- C:\Program Files\Windows Calendar
2010-10-13 12:45:34 ----D---- C:\Program Files\Movie Maker
2010-10-13 12:45:34 ----D---- C:\Program Files\Internet Explorer
2010-10-13 12:45:33 ----D---- C:\Program Files\Windows Media Player
2010-10-13 12:45:33 ----D---- C:\Program Files\Windows Journal
2010-10-13 12:45:33 ----D---- C:\Program Files\Windows Collaboration
2010-10-13 12:45:33 ----D---- C:\Program Files\Common Files\System
2010-10-13 12:45:32 ----D---- C:\Program Files\Windows Photo Gallery
2010-10-13 12:45:31 ----D---- C:\Windows\servicing
2010-10-13 12:45:31 ----D---- C:\Windows\ehome
2010-10-13 12:45:31 ----D---- C:\Program Files\Windows Defender
2010-10-13 12:45:26 ----D---- C:\Windows\IME
2010-10-13 12:45:25 ----D---- C:\Windows\system32\XPSViewer
2010-10-13 12:45:23 ----D---- C:\Windows\system32\oobe
2010-10-13 12:45:23 ----D---- C:\Windows\system32\migration
2010-10-13 12:45:21 ----D---- C:\Windows\system32\SLUI
2010-10-13 12:45:21 ----D---- C:\Windows\system32\setup
2010-10-13 12:45:21 ----D---- C:\Windows\system32\AdvancedInstallers
2010-10-13 12:45:20 ----D---- C:\Windows\system32\manifeststore
2010-10-13 12:45:20 ----D---- C:\Windows\system32\en
2010-10-13 12:45:16 ----D---- C:\Windows\system32\migwiz
2010-10-13 12:45:02 ----RSD---- C:\Windows\Fonts
2010-10-13 12:44:54 ----D---- C:\Windows\system32\Boot
2010-10-13 12:42:07 ----D---- C:\Windows\system32\RTCOM
2010-10-13 12:28:08 ----A---- C:\Windows\fonts\GlobalUserInterface.CompositeFont
2010-10-13 03:13:54 ----D---- C:\ProgramData\Microsoft Help
2010-10-13 03:04:10 ----A---- C:\Windows\system32\mrt.exe
2010-10-12 19:05:13 ----HD---- C:\Windows\system32\GroupPolicy
2010-10-12 13:52:27 ----D---- C:\Program Files\Microsoft Security Essentials
2010-10-04 19:57:56 ----D---- C:\Program Files\Common Files\Blizzard Entertainment
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 phylock;phylock; C:\Windows\system32\drivers\phylock.sys [2006-12-18 18848]
R0 PSDFilter;PSDFilter; C:\Windows\system32\DRIVERS\psdfilter.sys [2007-04-25 20776]
R0 PSDNServ;PSDNSERVER; C:\Windows\system32\drivers\PSDNServ.sys [2007-04-25 16680]
R0 psdvdisk;psdvdisk; C:\Windows\system32\drivers\psdvdisk.sys [2007-04-25 60712]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 MpFilter;Microsoft Malware Protection Driver; C:\Windows\system32\DRIVERS\MpFilter.sys [2010-03-25 151216]
R2 int15;int15; \??\C:\Acer\Empowering Technology\eRecovery\int15.sys [2006-12-07 76584]
R2 mdmxsdk;mdmxsdk; C:\Windows\system32\DRIVERS\mdmxsdk.sys [2007-05-16 12672]
R2 rimmptsk;rimmptsk; C:\Windows\system32\DRIVERS\rimmptsk.sys [2007-02-24 39936]
R2 rimsptsk;rimsptsk; C:\Windows\system32\DRIVERS\rimsptsk.sys [2007-01-23 42496]
R2 rismxdp;Ricoh xD-Picture Card Driver; C:\Windows\system32\DRIVERS\rixdptsk.sys [2007-03-22 37376]
R2 XAudio;XAudio; C:\Windows\system32\DRIVERS\xaudio.sys [2007-05-16 8192]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2007-06-13 154624]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2007-06-18 737280]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [2007-05-16 32256]
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\System32\Drivers\GEARAspiWDM.sys [2009-05-18 26600]
R3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\HSX_DPV.sys [2007-05-16 985600]
R3 HSXHWAZL;HSXHWAZL; C:\Windows\system32\DRIVERS\HSXHWAZL.sys [2007-05-16 207360]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2007-05-18 1775712]
R3 MpNWMon;Microsoft Malware Protection Network Driver; C:\Windows\system32\DRIVERS\MpNWMon.sys [2010-03-25 42368]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2007-08-07 6144]
R3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvmfdx32.sys [2007-05-16 1059112]
R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [2009-01-30 7544832]
R3 nvsmu;nvsmu; C:\Windows\system32\DRIVERS\nvsmu.sys [2007-05-16 12032]
R3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [2009-04-11 89088]
R3 SNP2UVC;USB2.0 PC Camera (SNP2UVC); C:\Windows\system32\DRIVERS\snp2uvc.sys [2007-02-07 1729152]
R3 winachsf;winachsf; C:\Windows\system32\DRIVERS\HSX_CNXT.sys [2007-05-16 659968]
S3 catchme;catchme; \??\C:\Users\Owner\AppData\Local\Temp\catchme.sys []
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-19 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL3.SYS [2006-11-02 200704]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-19 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-19 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-19 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-19 6016]
S3 USBAAPL;Apple Mobile USB Driver; C:\Windows\System32\Drivers\usbaapl.sys [2009-08-28 40448]
S3 WpdUsb;WpdUsb; C:\Windows\system32\DRIVERS\wpdusb.sys [2009-09-30 40448]
S3 WSVD;WSVD; \??\C:\Windows\system32\drivers\WSVD.sys [2006-09-19 80744]
S3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-19 83328]
S4 UIUSys;Conexant Setup API; C:\Windows\system32\DRIVERS\UIUSYS.SYS []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 MsMpSvc;Microsoft Antimalware Service; C:\Program Files\Microsoft Security Essentials\MsMpEng.exe [2010-03-25 17904]
S2 CLTNetCnService;Symantec Lic NetConnect service; C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe /h ccCommon []
S3 FontCache;@%systemroot%\system32\FntCache.dll,-100; C:\Windows\system32\svchost.exe [2008-01-19 21504]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184]
S4 ALaunchService;ALaunch Service; C:\Acer\ALaunch\ALaunchSvc.exe [2007-01-26 50688]
S4 Apple Mobile Device;Apple Mobile Device; C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe [2009-08-28 144672]
S4 Bonjour Service;Bonjour Service; C:\Program Files\Bonjour\mDNSResponder.exe [2008-12-12 238888]
S4 eDataSecurity Service;eDataSecurity Service; C:\Acer\Empowering Technology\eDataSecurity\eDSService.exe [2007-04-25 457512]
S4 eLockService;eLock Service; C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe [2007-04-23 24576]
S4 eNet Service;eNet Service; C:\Acer\Empowering Technology\eNet\eNet Service.exe [2007-06-13 135168]
S4 eRecoveryService;eRecovery Service; C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe [2007-07-03 53248]
S4 eSettingsService;eSettings Service; C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe [2007-06-28 24576]
S4 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2009-09-21 545568]
S4 LightScribeService;LightScribeService Direct Disc Labeling Service; C:\Program Files\Common Files\LightScribe\LSSrvc.exe [2007-01-17 61440]
S4 MobilityService;MobilityService; C:\Acer\Mobility Center\MobilityService.exe [2006-11-24 107008]
S4 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [2009-01-30 203296]
S4 tbhMonitor.exe;The Browser Highlighter Monitor; C:\Program Files\tbh\monitor\bin\tbhMonitor.exe [2009-10-22 70952]
S4 WMIService;ePower Service; C:\Acer\Empowering Technology\ePower\ePowerSvc.exe [2007-06-13 167936]
S4 XAudioService;XAudioService; C:\Windows\system32\DRIVERS\xaudio.exe [2007-05-16 386560]
-----------------EOF-----------------