Logfile of random's system information tool 1.08 (written by random/random) Run by [removed] at 2010-10-26 11:32:18 Microsoft Windows XP Professional Service Pack 3 System drive C: has 454 GB (95%) free of 477 GB Total RAM: 3583 MB (64% free) Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 11:33:59 AM, on 26/10/2010 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-547\acs.exe C:\Program Files\AVG\AVG10\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe C:\WINDOWS\system32\nvsvc32.exe C:\Program Files\Macrium\Reflect\ReflectService.exe C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\ThreatFire\TFService.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\WINDOWS\system32\SearchIndexer.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Program Files\AnalogX\CookieWall\cookie.exe C:\Program Files\ThreatFire\TFTray.exe C:\Program Files\Lexmark 6200 Series\ezprint.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Lexmark 6200 Series\lxbumon.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Program Files\Global Graphics\gDoc\DocCreatorClient.exe C:\Program Files\ClearCloud\ClearCloud DNS\SBCC_Utility_Tray.exe C:\WINDOWS\system32\rundll32.exe C:\Program Files\AVG\AVG10\avgtray.exe C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe C:\Program Files\Codebox\BitMeter\BitMeter2.exe C:\Program Files\AVG\AVG10\avgnsx.exe C:\Program Files\AVG\AVG10\avgemcx.exe C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-547\wirelesscm.exe C:\WINDOWS\system32\lxbucoms.exe C:\WINDOWS\system32\DCMessages.exe C:\WINDOWS\System32\alg.exe C:\Program Files\AVG\AVG10\Identity Protection\agent\bin\avgidsmonitor.exe C:\Program Files\AVG\AVG10\avgchsvx.exe C:\Program Files\AVG\AVG10\avgrsx.exe C:\Program Files\AVG\AVG10\avgcsrvx.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\internet explorer\iexplore.exe C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe C:\WINDOWS\system32\notepad.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\WINDOWS\system32\svchost.exe C:\Documents and Settings\Bernie\Local Settings\Temporary Internet Files\Content.IE5\SJOBNITT\RSIT[1].exe C:\WINDOWS\system32\wbem\wmiprvse.exe C:\Program Files\trend micro\Bernie.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: BigBetPoker.com - {1ca24684-a693-418e-a430-79d070271843} - C:\Documents and Settings\Bernie\Start Menu\Programs\BigBetPoker.com\BigBetPoker.com.lnk (HKCU) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{7D539699-A868-4923-8CC0-B75D1921A00A}: NameServer = 74.118.212.1,74.118.212.2,74.118.212.1,74.118.212.2, O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll O23 - Service: DCMessages - Global Graphics Software Ltd - C:\WINDOWS\system32\DCMessages.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- End of file - 6142 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\AWC AutoSweep.job C:\WINDOWS\tasks\AWC Update.job C:\WINDOWS\tasks\User_Feed_Synchronization-{12B33138-E22F-4378-A84B-C4F30D68D647}.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-12-21 75200] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] AVG Safe Search - C:\Program Files\AVG\AVG10\avgssie.dll [2010-10-20 2922848] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6EBF7485-159F-4bff-A14F-B9E3AAC4465B}] Search Helper - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll [2010-05-14 191792] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live ID Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-03-30 403824] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{90EFF544-3981-4d46-85C9-C0361D0931D6}] af0.Adblock.BHO - C:\WINDOWS\system32\mscoree.dll [2009-11-07 297808] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{A3BC75A2-1F87-4686-AA43-5347D756017C}] AVG Security Toolbar BHO - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-10-06 2475336] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-10-11 41760] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-10-11 73728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll [2010-10-06 2475336] {B24BA06E-FB7B-4757-95C2-DC01125F750E} - RefresherBand Class - C:\PROGRA~1\YREFRE~1\YREFRE~1.DLL [2001-08-03 45056] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "CookieWall"=C:\Program Files\AnalogX\CookieWall\cookie.exe [2009-09-28 151040] "ThreatFire"=C:\Program Files\ThreatFire\TFTray.exe [2010-01-14 378128] "EzPrint"=C:\Program Files\Lexmark 6200 Series\ezprint.exe [2004-09-17 61440] "LXBUCATS"=rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBUtime.dll,_RunDLLEntry@16 [] "lxbumon.exe"=C:\Program Files\Lexmark 6200 Series\lxbumon.exe [2004-09-22 188416] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-10-07 13574144] "nwiz"=nwiz.exe /install [] "NvMediaCenter"=C:\WINDOWS\system32\NvMcTray.dll [2008-10-07 86016] "DocCreatorClient"=C:\Program Files\Global Graphics\gDoc\DocCreatorClient.exe [2009-11-24 292248] "SSClearCloudTrayApp"=C:\Program Files\ClearCloud\ClearCloud DNS\SBCC_Utility_Tray.exe [2010-08-18 537936] "AVG_TRAY"=C:\Program Files\AVG\AVG10\avgtray.exe [2010-09-15 2745696] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce] "Malwarebytes' Anti-Malware"=C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe [2010-04-29 437584] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-14 15360] "SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2010-09-29 2424560] C:\Documents and Settings\All Users\Start Menu\Programs\Startup Bitmeter2.lnk - C:\Program Files\Codebox\BitMeter\BitMeter2.exe Wireless Connection Manager.lnk - C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-547\wirelesscm.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon] C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL [2009-09-04 548352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 239496] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{56F9679E-7826-4C84-81F3-532071A8BCC5}"=C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll [2009-05-24 304128] "{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-14 77824] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\{1a3e09be-1e45-494b-9174-d7385b45bbf5}] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=323 "NoDriveAutoRun"=67108863 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"=1 "NoDriveAutoRun"=67108863 "NoDriveTypeAutoRun"=323 "NoDrives"=0 "NoResolveSearch"=1 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\WINDOWS\system32\lxbucoms.exe"="C:\WINDOWS\system32\lxbucoms.exe:*:Disabled:6200 Series Server" "C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE"="C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:*:Enabled:Microsoft Office OneNote" "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync" "C:\WINDOWS\system32\mmc.exe"="C:\WINDOWS\system32\mmc.exe:*:Enabled:Microsoft Management Console" "C:\Program Files\AVG\AVG10\avgmfapx.exe"="C:\Program Files\AVG\AVG10\avgmfapx.exe:*:Enabled:AVG Installer" "C:\Program Files\AVG\AVG10\avgdiagex.exe"="C:\Program Files\AVG\AVG10\avgdiagex.exe:*:Enabled:AVG Diagnostics 2011" "C:\Program Files\AVG\AVG10\avgnsx.exe"="C:\Program Files\AVG\AVG10\avgnsx.exe:*:Enabled:Online Shield" "C:\Program Files\AVG\AVG10\avgemcx.exe"="C:\Program Files\AVG\AVG10\avgemcx.exe:*:Enabled:Personal E-mail Scanner" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Program Files\Windows Live\Messenger\wlcsdk.exe"="C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Program Files\Windows Live\Messenger\msnmsgr.exe"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" "C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe"="C:\Program Files\Windows Live\Sync\WindowsLiveSync.exe:*:Enabled:Windows Live Sync" ======List of files/folders created in the last 1 months====== 2010-10-26 11:32:18 ----D---- C:\rsit 2010-10-26 10:38:26 ----A---- C:\WINDOWS\system32\drivers\mbamswissarmy.sys 2010-10-26 10:38:22 ----A---- C:\WINDOWS\system32\drivers\mbam.sys 2010-10-26 10:38:10 ----D---- C:\Program Files\Malwarebytes' Anti-Malware 2010-10-19 11:01:38 ----D---- C:\Program Files\PecanPoker 2010-10-18 19:36:59 ----RA---- C:\WINDOWS\system32\drivers\EIO_XP.sys 2010-10-17 09:39:29 ----D---- C:\Documents and Settings\Bernie\Application Data\AVG10 2010-10-17 09:38:41 ----HD---- C:\Documents and Settings\All Users\Application Data\Common Files 2010-10-17 09:38:17 ----D---- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar 2010-10-17 09:35:00 ----D---- C:\WINDOWS\system32\drivers\AVG 2010-10-17 09:35:00 ----D---- C:\Documents and Settings\All Users\Application Data\AVG10 2010-10-17 09:01:28 ----D---- C:\Documents and Settings\All Users\Application Data\MFAData 2010-10-17 06:28:29 ----D---- C:\Documents and Settings\Bernie\Application Data\Bitmeter2 2010-10-17 06:28:29 ----D---- C:\Documents and Settings\All Users\Application Data\Bitmeter2 2010-10-16 17:05:23 ----D---- C:\Program Files\BigBetPoker.com 2010-10-15 02:51:26 ----D---- C:\Program Files\SpeedBit Video Accelerator 2010-10-15 02:51:08 ----D---- C:\Documents and Settings\Bernie\Application Data\Toolbar4 2010-10-15 02:51:04 ----D---- C:\Documents and Settings\All Users\Application Data\SpeedBit 2010-10-14 08:10:33 ----D---- C:\Documents and Settings\Bernie\Application Data\FreeFixer 2010-10-14 08:10:11 ----D---- C:\Program Files\FreeFixer 2010-10-13 05:45:20 ----HDC---- C:\WINDOWS\$NtUninstallKB2387149$ 2010-10-13 05:44:01 ----HDC---- C:\WINDOWS\$NtUninstallKB2279986$ 2010-10-13 05:42:41 ----HDC---- C:\WINDOWS\$NtUninstallKB2345886$ 2010-10-13 05:41:25 ----HDC---- C:\WINDOWS\$NtUninstallKB2296011$ 2010-10-13 05:39:51 ----HDC---- C:\WINDOWS\$NtUninstallKB2378111_WM9$ 2010-10-13 05:37:44 ----HDC---- C:\WINDOWS\$NtUninstallKB982132$ 2010-10-13 05:34:43 ----HDC---- C:\WINDOWS\$NtUninstallKB979687$ 2010-10-13 05:26:56 ----HDC---- C:\WINDOWS\$NtUninstallKB981957$ 2010-10-13 05:25:39 ----HDC---- C:\WINDOWS\$NtUninstallKB2360937$ 2010-10-12 05:21:54 ----A---- C:\WINDOWS\MyProgram.exe 2010-10-12 05:21:51 ----A---- C:\WINDOWS\unins000.exe 2010-10-08 06:17:37 ----D---- C:\Documents and Settings\Bernie\Application Data\ClearCloud 2010-10-08 06:17:37 ----D---- C:\Documents and Settings\All Users\Application Data\ClearCloud 2010-10-08 06:17:25 ----D---- C:\Program Files\ClearCloud 2010-10-05 10:14:02 ----A---- C:\WINDOWS\ntbtlog.txt 2010-10-05 10:11:24 ----ASH---- C:\pagefile.sys 2010-09-30 06:51:59 ----D---- C:\Program Files\YRefresher 2010-09-29 06:19:37 ----HDC---- C:\WINDOWS\$NtUninstallKB2158563$ ======List of files/folders modified in the last 1 months====== 2010-10-26 11:33:59 ----D---- C:\Program Files\Trend Micro 2010-10-26 11:29:54 ----D---- C:\WINDOWS 2010-10-26 10:39:48 ----D---- C:\WINDOWS\Temp 2010-10-26 10:38:31 ----D---- C:\WINDOWS\system32\drivers 2010-10-26 10:38:29 ----RD---- C:\Program Files 2010-10-26 10:20:38 ----RSHDC---- C:\WINDOWS\system32\dllcache 2010-10-26 09:57:20 ----SHD---- C:\WINDOWS\Installer 2010-10-26 09:51:40 ----D---- C:\WINDOWS\system32\CatRoot2 2010-10-26 09:48:27 ----D---- C:\WINDOWS\system32 2010-10-26 09:46:21 ----A---- C:\WINDOWS\SchedLgU.Txt 2010-10-26 09:37:25 ----D---- C:\WINDOWS\Prefetch 2010-10-26 06:13:27 ----D---- C:\Program Files\PokerStars 2010-10-25 15:19:22 ----D---- C:\Program Files\Mozilla Firefox 2010-10-24 08:31:39 ----D---- C:\Program Files\Full Tilt Poker 2010-10-20 13:29:51 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP 2010-10-20 13:29:42 ----D---- C:\Program Files\SpywareBlaster 2010-10-20 11:49:02 ----HD---- C:\WINDOWS\inf 2010-10-20 02:43:18 ----SHD---- C:\System Volume Information 2010-10-20 02:01:08 ----D---- C:\WINDOWS\Help 2010-10-20 01:55:09 ----SHD---- C:\WINDOWS\CSC 2010-10-18 19:45:01 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2010-10-18 19:44:24 ----D---- C:\WINDOWS\system32\ReinstallBackups 2010-10-18 19:43:05 ----HD---- C:\Program Files\InstallShield Installation Information 2010-10-17 09:29:16 ----SD---- C:\Documents and Settings\Bernie\Application Data\Microsoft 2010-10-17 09:29:08 ----D---- C:\Documents and Settings\All Users\Application Data\avg9 2010-10-17 09:28:51 ----D---- C:\Program Files\AVG 2010-10-17 09:28:44 ----D---- C:\WINDOWS\WinSxS 2010-10-17 06:28:14 ----D---- C:\Program Files\Codebox 2010-10-15 20:02:33 ----RASH---- C:\boot.ini 2010-10-15 20:02:33 ----A---- C:\WINDOWS\win.ini 2010-10-15 20:02:33 ----A---- C:\WINDOWS\system.ini 2010-10-14 04:51:21 ----D---- C:\temp 2010-10-14 04:49:56 ----D---- C:\Program Files\Bodog Poker 2010-10-13 07:26:30 ----D---- C:\Program Files\Internet Explorer 2010-10-13 05:45:16 ----HD---- C:\WINDOWS\$hf_mig$ 2010-10-13 05:45:10 ----A---- C:\WINDOWS\imsins.BAK 2010-10-13 05:39:37 ----D---- C:\Documents and Settings\All Users\Application Data\Microsoft Help 2010-10-13 05:31:25 ----D---- C:\WINDOWS\ie8updates 2010-10-13 05:28:10 ----A---- C:\WINDOWS\system32\MRT.exe 2010-10-11 08:50:16 ----D---- C:\Program Files\UltimateBet 2010-10-08 10:29:11 ----D---- C:\WINDOWS\Microsoft.NET 2010-10-08 10:28:46 ----RSD---- C:\WINDOWS\assembly 2010-10-05 11:51:25 ----D---- C:\Program Files\SUPERAntiSpyware 2010-10-05 11:41:19 ----D---- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy 2010-10-05 10:15:56 ----D---- C:\Documents and Settings\Bernie\Application Data\SUPERAntiSpyware.com 2010-10-05 10:15:07 ----D---- C:\Documents and Settings\Bernie\Application Data\U3 2010-09-29 14:36:12 ----D---- C:\Program Files\Microsoft Silverlight ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R0 AVGIDSEH;AVGIDSEH; C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys [2010-09-13 25680] R0 Avgrkx86;AVG Anti-Rootkit Driver; C:\WINDOWS\system32\DRIVERS\avgrkx86.sys [2010-09-07 26064] R0 nvata;nvata; C:\WINDOWS\system32\DRIVERS\nvata.sys [2006-10-18 105472] R0 pssnap;Paramount Software Snapshot Filter; C:\WINDOWS\system32\DRIVERS\pssnap.sys [2008-05-20 15328] R0 TfFsMon;TfFsMon; C:\WINDOWS\system32\drivers\TfFsMon.sys [2010-01-14 51984] R0 TfSysMon;TfSysMon; C:\WINDOWS\system32\drivers\TfSysMon.sys [2010-01-14 59664] R1 AmdPPM;AMD HwPState Processor Driver; C:\WINDOWS\system32\DRIVERS\AmdPPM.sys [2007-04-16 33792] R1 Avgldx86;AVG AVI Loader Driver; C:\WINDOWS\system32\DRIVERS\avgldx86.sys [2010-09-07 249424] R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield; C:\WINDOWS\system32\DRIVERS\avgmfx86.sys [2010-09-07 34384] R1 Avgtdix;AVG TDI Driver; C:\WINDOWS\system32\DRIVERS\avgtdix.sys [2010-09-07 298448] R1 EIO_XP;EIO_XP; \??\C:\WINDOWS\system32\drivers\EIO_XP.sys [] R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS [] R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS [] R2 fssfltr;FssFltr; C:\WINDOWS\system32\DRIVERS\fssfltr_tdi.sys [2009-08-05 54752] R2 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2009-10-21 50704] R3 AR5416;D-Link DWA-547 RangeBooster N650 Desktop Adapte Service; C:\WINDOWS\system32\DRIVERS\ar5416.sys [2007-01-31 1050784] R3 AVGIDSDriver;AVGIDSDriver; C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys [2010-08-19 123472] R3 AVGIDSFilter;AVGIDSFilter; C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys [2010-08-19 30288] R3 AVGIDSShim;AVGIDSShim; C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys [2010-08-19 26192] R3 HDAudBus;Microsoft UAA Bus Driver for High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384] R3 hidusb;Microsoft HID Class Driver; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-12-11 4959232] R3 MBAMSwissArmy;MBAMSwissArmy; \??\C:\WINDOWS\system32\drivers\mbamswissarmy.sys [] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-10-07 6133856] R3 nvnetbus;NVIDIA Network Bus Enumerator; C:\WINDOWS\system32\DRIVERS\nvnetbus.sys [2010-03-04 13824] R3 TfNetMon;TfNetMon; \??\C:\WINDOWS\system32\drivers\TfNetMon.sys [] R3 usbccgp;Microsoft USB Generic Parent Driver; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128] R3 usbprint;Microsoft USB PRINTER Class; C:\WINDOWS\system32\DRIVERS\usbprint.sys [2008-04-14 25856] R3 usbscan;USB Scanner Driver; C:\WINDOWS\system32\DRIVERS\usbscan.sys [2008-04-14 15104] R3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368] R3 WSIMD;wsimd Service; C:\WINDOWS\system32\DRIVERS\wsimd.sys [2006-07-20 54432] S1 kbdhid;Keyboard HID Driver; C:\WINDOWS\system32\DRIVERS\kbdhid.sys [2008-04-14 14592] S3 catchme;catchme; \??\C:\DOCUME~1\Bernie\LOCALS~1\Temp\catchme.sys [] S3 ENTECH;ENTECH; \??\C:\WINDOWS\system32\DRIVERS\ENTECH.sys [] S3 gdrv;gdrv; \??\C:\WINDOWS\gdrv.sys [] S3 mouhid;Mouse HID Driver; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2008-04-14 12160] S3 NVENETFD;NVIDIA nForce 10/100 Mbps Ethernet ; C:\WINDOWS\system32\DRIVERS\NVENETFD.sys [2010-03-04 70912] S3 Video3D;ASUS Video3D Service; C:\WINDOWS\System32\Drivers\Video3D32.sys [] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINDOWS\System32\drivers\ws2ifsl.sys [2008-04-14 12032] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ACS;Atheros Configuration Service; C:\Program Files\D-Link\D-Link RangeBooster N 650 DWA-547\acs.exe [2006-08-25 360532] R2 AVGIDSAgent;AVGIDSAgent; C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe [2010-10-11 6104656] R2 avgwd;AVG WatchDog; C:\Program Files\AVG\AVG10\avgwdsvc.exe [2010-09-10 265400] R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-10-11 153376] R2 NitroReaderDriverReadSpool;NitroPDFReaderDriverCreatorReadSpool; C:\Program Files\Nitro PDF\Reader\NitroPDFReaderDriverService.exe [2010-05-25 196912] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-10-07 163908] R2 ReflectService;Macrium Reflect Image Mounting Service; C:\Program Files\Macrium\Reflect\ReflectService.exe [2009-08-25 220128] R2 SeaPort;SeaPort; C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe [2010-05-14 249136] R2 ThreatFire;ThreatFire; C:\Program Files\ThreatFire\TFService.exe [2010-01-14 70928] R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2009-03-30 1533808] R2 WSearch;Windows Search; C:\WINDOWS\system32\SearchIndexer.exe [2008-05-26 439808] R3 DCMessages;DCMessages; C:\WINDOWS\system32\DCMessages.exe [2009-11-24 99720] R3 lxbu_device;lxbu_device; C:\WINDOWS\system32\lxbucoms.exe [2004-09-24 450560] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2008-07-25 34312] S3 AVG Security Toolbar Service;AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [2010-10-06 517448] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2008-07-25 69632] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe [2008-07-29 46104] S3 fsssvc;Windows Live Family Safety Service; C:\Program Files\Windows Live\Family Safety\fsssvc.exe [2009-08-05 704864] S3 IDriverT;InstallDriver Table Manager; C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 idsvc;Windows CardSpace; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2008-07-29 881664] S3 MatSvc;Microsoft Automated Troubleshooting Service; C:\Program Files\Microsoft Fix it Center\Matsvc.exe [2010-04-10 266544] S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712] S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Program Files\WinPcap\rpcapd.exe [2009-10-21 117264] S3 WMPNetworkSvc;Windows Media Player Network Sharing Service; C:\Program Files\Windows Media Player\WMPNetwk.exe [2006-10-18 913408] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-07-29 132096] -----------------EOF-----------------