Logfile of random's system information tool 1.04 (written by random/random) Run by [removed] at 2008-10-12 15:43:14 Microsoft� Windows Vista� Home Premium Service Pack 1 System drive C: has 186 GB (63%) free of 294 GB Total RAM: 4092 MB (56% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 3:43:21 PM, on 10/12/2008 Platform: Windows Vista SP1 (WinNT 6.00.1905) MSIE: Internet Explorer v7.00 (7.00.6001.18000) Boot mode: Normal Running processes: C:\Program Files (x86)\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe C:\Program Files (x86)\HP\Digital Imaging\bin\HpqSRmon.exe C:\Program Files (x86)\HP\HP Software Update\hpwuSchd2.exe C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe C:\Program Files (x86)\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE C:\Program Files (x86)\Hewlett-Packard\Shared\HpqToaster.exe C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE C:\Program Files (x86)\Microsoft Office\Office12\MSPUB.EXE C:\Users\Donna\AppData\Local\Google\Update\GoogleUpdate.exe C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE C:\Program Files (x86)\Microsoft Office\Office12\MSPUB.EXE C:\Program Files (x86)\Internet Explorer\ieuser.exe C:\Program Files (x86)\Internet Explorer\iexplore.exe C:\Users\Donna\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\Z1HNWQ93\RSIT[1].exe D:\Downloads\hj\Donna.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=en_us&c=83&bd=Pavilion&pf=cnnb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe" -osboot O17 - HKLM\System\CCS\Services\Tcpip\..\{326CADB9-69B0-4789-A7BA-0263DF2D535B}: NameServer = 66.174.92.14 69.78.96.14 O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe O23 - Service: Andrea ST Filters Service (AESTFilters) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\AESTSr64.exe (file missing) O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Unknown owner - C:\Windows\system32\agr64svc.exe (file missing) O23 - Service: Application Layer Gateway Service (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe O23 - Service: GoToAssist - Citrix Online, a division of Citrix Systems, Inc. - C:\Program Files (x86)\Citrix\GoToAssist\480\g2aservice.exe O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing) O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: Audio Service (STacSV) - Unknown owner - C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\STacSV64.exe (file missing) O23 - Service: Interactive Services Detection (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) -- End of file - 4883 bytes ======Scheduled tasks folder====== C:\Windows\tasks\GoogleUpdateTaskUser.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00C6482D-C502-44C8-8409-FCE54AD9C208}] SnagIt Toolbar Loader - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItBHO.dll [2008-05-15 66888] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}] XPL LinkScannerIE - C:\Program Files (x86)\Avanquest\SystemSuite\LinkScannerIE.dll [2008-08-21 402712] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{72853161-30C5-4D22-B7F9-0BBC1D38A37E}] Groove GFS Browser Helper - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}] Google Toolbar Helper - c:\program files (x86)\google\googletoolbar1.dll [2008-09-25 2403392] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856}] HP Smart BHO Class - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll [2008-03-14 501056] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - SnagIt - C:\Program Files (x86)\TechSmith\SnagIt 9\SnagItIEAddin.dll [2008-05-15 161096] {2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files (x86)\google\googletoolbar1.dll [2008-09-25 2403392] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "QlbCtrl.exe"=C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe [2008-03-14 202032] "hpqSRMon"=C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe [2008-06-02 80896] "Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-05-11 40048] "HP Software Update"=C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [2007-05-08 54840] "hpWirelessAssistant"=C:\Program Files (x86)\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe [2007-11-20 488752] "VirusScannerPro"=C:\PROGRA~2\AVANQU~1\SYSTEM~1\MemCheck.exe [2008-08-26 173312] "HP Health Check Scheduler"=c:\Program Files (x86)\Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe [2008-06-16 75008] "TkBellExe"=C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe [2008-09-25 185872] C:\Users\Donna\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup VZAccess Manager.lnk - C:\Program Files (x86)\Verizon Wireless\VZAccess Manager\VZAccess Manager.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}"=C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2007-08-24 2212224] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 "EnableUIADesktopToggle"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{834b8d68-8a86-11dd-9165-001eec8d3b01}] shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL CAISS/CAInstallationMenu.html [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{f118c367-8a1c-11dd-a6ca-806e6f6e6963}] shell\AutoRun\command - F:\EPSETUP.EXE ======List of files/folders created in the last 3 months====== 2008-10-12 15:43:14 ----D---- C:\rsit 2008-10-12 12:46:32 ----D---- C:\Windows\LastGood 2008-10-12 12:18:33 ----D---- C:\ProgramData\EPSON 2008-10-12 12:15:45 ----D---- C:\ProgramData\ArcSoft 2008-10-12 11:32:42 ----D---- C:\Program Files (x86)\CCleaner 2008-10-12 11:00:25 ----D---- C:\epson 2008-10-12 10:34:46 ----D---- C:\Users\Donna\AppData\Roaming\Leadertech 2008-10-12 10:34:44 ----D---- C:\EPSONREG 2008-10-12 10:32:10 ----D---- C:\Users\Donna\AppData\Roaming\ArcSoft 2008-10-12 10:32:07 ----D---- C:\Program Files (x86)\Common Files\ArcSoft 2008-10-12 10:32:07 ----A---- C:\Windows\system32\unicows.dll 2008-10-12 10:32:07 ----A---- C:\Windows\PCDLIB32.DLL 2008-10-12 10:31:54 ----D---- C:\Windows\system32\PhotoImpression Slideshow 2008-10-12 10:31:54 ----D---- C:\Program Files (x86)\ArcSoft 2008-10-12 10:31:15 ----A---- C:\Windows\system32\PICSDK2.dll 2008-10-12 10:31:15 ----A---- C:\Windows\system32\PICSDK.ini 2008-10-12 10:31:15 ----A---- C:\Windows\system32\PICSDK.dll 2008-10-12 10:31:15 ----A---- C:\Windows\system32\PICEntry.dll 2008-10-12 10:31:15 ----A---- C:\Windows\system32\EpPicPrt.dll 2008-10-12 10:31:15 ----A---- C:\Windows\system32\EpPicMgr.dll 2008-10-12 10:31:10 ----D---- C:\Users\Donna\AppData\Roaming\InstallShield 2008-10-12 10:30:07 ----D---- C:\Program Files (x86)\epson 2008-10-12 10:29:50 ----A---- C:\Windows\EPSCX9400Fax.ini 2008-10-08 19:01:58 ----D---- C:\Users\Donna\AppData\Roaming\ColorCop 2008-10-08 19:01:56 ----D---- C:\Program Files (x86)\Color_Cop 2008-10-08 15:23:42 ----A---- C:\Windows\system32\PerfStringBackup.INI 2008-10-08 09:52:29 ----D---- C:\Users\Donna\AppData\Roaming\WebEx 2008-10-08 09:51:51 ----D---- C:\ProgramData\WebEx 2008-10-05 19:51:16 ----D---- C:\Program Files (x86)\Sun 2008-10-05 19:50:43 ----A---- C:\Windows\system32\javaws.exe 2008-10-05 19:50:43 ----A---- C:\Windows\system32\javaw.exe 2008-10-05 19:50:43 ----A---- C:\Windows\system32\java.exe 2008-10-05 03:56:16 ----D---- C:\BOYS TOOLS 2008-10-05 03:19:41 ----A---- C:\Windows\system32\tsccvid.dll 2008-10-05 03:19:40 ----D---- C:\Windows\system32\QuickTime 2008-10-05 03:19:19 ----D---- C:\Program Files (x86)\Common Files\TechSmith Shared 2008-10-04 04:59:10 ----A---- C:\Windows\sttray64.exe 2008-10-04 04:40:37 ----D---- C:\Program Files (x86)\Microsoft Silverlight 2008-10-04 03:27:34 ----A---- C:\Windows\system32\XceedZip.dll 2008-10-02 17:37:12 ----D---- C:\Users\Donna\AppData\Roaming\HP 2008-10-02 17:37:10 ----D---- C:\Users\Donna\AppData\Roaming\CyberLink 2008-10-02 07:30:55 ----D---- C:\ProgramData\Applications 2008-09-30 03:15:11 ----D---- C:\HP-UPD4_5-PCL5-64 2008-09-29 21:22:53 ----D---- C:\ProgramData\BVRP Software 2008-09-29 21:22:30 ----RSHD---- C:\_Backup.RC 2008-09-29 21:22:27 ----HD---- C:\_Backup 2008-09-29 21:18:00 ----D---- C:\Users\Donna\AppData\Roaming\Avanquest 2008-09-29 21:17:59 ----D---- C:\ProgramData\Avanquest 2008-09-29 21:17:25 ----D---- C:\Program Files (x86)\Avanquest 2008-09-29 08:59:20 ----D---- C:\Users\Donna\AppData\Roaming\Template 2008-09-27 04:12:50 ----A---- C:\Windows\system32\MRT.exe 2008-09-27 04:08:38 ----D---- C:\Users\Donna\AppData\Roaming\ICAClient 2008-09-27 00:30:37 ----D---- C:\Users\Donna\AppData\Roaming\Document Systems, Inc 2008-09-27 00:28:01 ----D---- C:\Document Systems, Inc 2008-09-26 21:01:46 ----D---- C:\Program Files (x86)\QuickQualifier2008 2008-09-26 17:03:16 ----D---- C:\Users\Donna\AppData\Roaming\ePASS 2008-09-26 17:00:27 ----D---- C:\Users\Donna\AppData\Roaming\Encompass 2008-09-26 16:19:56 ----D---- C:\Program Files (x86)\Microsoft WSE 2008-09-26 16:19:43 ----D---- C:\Program Files (x86)\Ellie Mae 2008-09-26 16:19:43 ----D---- C:\Program Files (x86)\Common Files\Outlook Security Manager 2008-09-26 16:19:20 ----D---- C:\Program Files (x86)\Common Files\Wise Installation Wizard 2008-09-26 16:18:46 ----A---- C:\Windows\system32\cdintf251.dll 2008-09-26 16:13:41 ----D---- C:\Program Files (x86)\Citrix 2008-09-26 15:44:33 ----A---- C:\Windows\system32\Vb6stkit.dll 2008-09-26 15:44:33 ----A---- C:\Windows\system32\Vb5db.dll 2008-09-26 15:44:33 ----A---- C:\Windows\system32\Rdocurs.dll 2008-09-26 15:44:32 ----A---- C:\Windows\system32\Msrepl35.dll 2008-09-26 15:44:32 ----A---- C:\Windows\system32\Msrdo20.dll 2008-09-26 15:44:32 ----A---- C:\Windows\system32\Msrd2x35.dll 2008-09-26 15:44:31 ----A---- C:\Windows\system32\Msjter35.dll 2008-09-26 15:44:31 ----A---- C:\Windows\system32\Msjint35.dll 2008-09-26 15:44:31 ----A---- C:\Windows\system32\Msjet35.dll 2008-09-26 15:44:31 ----A---- C:\Windows\system32\Msbind.dll 2008-09-26 15:44:31 ----A---- C:\Windows\system32\Msadox.dll 2008-09-26 15:44:30 ----A---- C:\Windows\system32\Fnma_Export25.dll 2008-09-26 15:44:30 ----A---- C:\Windows\system32\Dao350.dll 2008-09-26 15:44:30 ----A---- C:\Windows\system32\bepprint.dll 2008-09-26 15:44:28 ----D---- C:\Program Files (x86)\QuickQualifier2006 2008-09-25 12:57:19 ----D---- C:\Windows\pss 2008-09-25 03:54:20 ----D---- C:\Users\Donna\AppData\Roaming\Google 2008-09-25 01:41:37 ----D---- C:\Program Files (x86)\Common Files\xing shared 2008-09-25 01:41:30 ----A---- C:\Windows\system32\rmoc3260.dll 2008-09-25 01:41:24 ----A---- C:\Windows\system32\pndx5032.dll 2008-09-25 01:41:24 ----A---- C:\Windows\system32\pndx5016.dll 2008-09-25 01:41:23 ----A---- C:\Windows\system32\pncrt.dll 2008-09-25 01:41:17 ----D---- C:\Users\Donna\AppData\Roaming\Real 2008-09-25 01:41:17 ----D---- C:\Program Files (x86)\Common Files\Real 2008-09-25 01:40:39 ----D---- C:\ProgramData\Google 2008-09-25 01:40:34 ----D---- C:\Program Files (x86)\Google 2008-09-24 22:23:58 ----D---- C:\Nmi_pos 2008-09-24 22:23:34 ----A---- C:\Windows\system32\poslibrary32.DLL 2008-09-24 22:14:02 ----D---- C:\Windows\Packages 2008-09-24 22:14:02 ----D---- C:\Program Files (x86)\LOG 2008-09-24 22:14:02 ----A---- C:\Windows\UNWISE32.EXE 2008-09-24 22:14:02 ----A---- C:\Windows\UNWISE.EXE 2008-09-24 14:15:17 ----D---- C:\ProgramData\TechSmith 2008-09-24 14:15:16 ----D---- C:\Program Files (x86)\TechSmith 2008-09-24 14:11:26 ----D---- C:\ProgramData\WinZip 2008-09-24 14:11:23 ----D---- C:\Program Files (x86)\WinZip 2008-09-24 08:00:11 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 2008-09-24 08:00:11 ----D---- C:\Program Files (x86)\Common Files\DESIGNER 2008-09-24 07:59:44 ----D---- C:\Windows\PCHEALTH 2008-09-24 07:59:44 ----D---- C:\Program Files (x86)\Microsoft.NET 2008-09-24 07:50:34 ----D---- C:\Program Files (x86)\Microsoft Visual Studio 8 2008-09-24 07:48:35 ----RD---- C:\MSOCache 2008-09-24 06:01:51 ----D---- C:\Program Files (x86)\Trend Micro 2008-09-24 05:54:18 ----D---- C:\Users\Donna\AppData\Roaming\Macromedia 2008-09-24 05:54:18 ----D---- C:\Users\Donna\AppData\Roaming\Adobe 2008-09-24 05:47:11 ----D---- C:\Program Files (x86)\MSXML 4.0 2008-09-24 05:43:55 ----D---- C:\Recorded TV 2008-09-24 05:34:16 ----A---- C:\Windows\system32\msshooks.dll 2008-09-24 05:34:16 ----A---- C:\Windows\system32\msscb.dll 2008-09-24 05:34:16 ----A---- C:\Windows\system32\mimefilt.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\thawbrkr.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\SearchFilterHost.exe 2008-09-24 05:34:14 ----A---- C:\Windows\system32\propsys.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\propdefs.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\offfilt.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\msstrc.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\mssprxy.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\mssitlb.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\msshsq.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\korwbrkr.dll 2008-09-24 05:34:14 ----A---- C:\Windows\system32\chsbrkr.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\xmlfilter.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\tquery.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\SearchProtocolHost.exe 2008-09-24 05:34:13 ----A---- C:\Windows\system32\SearchIndexer.exe 2008-09-24 05:34:13 ----A---- C:\Windows\system32\rtffilt.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\nlhtml.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\mssvp.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\mssrch.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\mssphtb.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\mssph.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\msscntrs.dll 2008-09-24 05:34:13 ----A---- C:\Windows\system32\chtbrkr.dll 2008-09-24 05:29:38 ----A---- C:\Windows\system32\tzres.dll 2008-09-24 05:25:02 ----A---- C:\Windows\system32\NlsLexicons0007.dll 2008-09-24 05:24:58 ----A---- C:\Windows\system32\NlsLexicons0009.dll 2008-09-24 05:24:44 ----A---- C:\Windows\system32\NaturalLanguage6.dll 2008-09-24 05:23:36 ----A---- C:\Windows\system32\psisdecd.dll 2008-09-24 05:23:36 ----A---- C:\Windows\system32\EncDec.dll 2008-09-24 05:23:29 ----A---- C:\Windows\system32\wshqos.dll 2008-09-24 05:23:29 ----A---- C:\Windows\system32\traffic.dll 2008-09-24 05:23:29 ----A---- C:\Windows\system32\rpcrt4.dll 2008-09-24 05:23:29 ----A---- C:\Windows\system32\pacerprf.dll 2008-09-24 05:23:27 ----A---- C:\Windows\system32\gdi32.dll 2008-09-24 05:23:21 ----A---- C:\Windows\system32\srclient.dll 2008-09-24 05:23:21 ----A---- C:\Windows\system32\kbd106n.dll 2008-09-24 05:22:51 ----A---- C:\Windows\system32\mshtml.dll 2008-09-24 05:22:51 ----A---- C:\Windows\system32\ieframe.dll 2008-09-24 05:22:50 ----A---- C:\Windows\system32\wininet.dll 2008-09-24 05:22:50 ----A---- C:\Windows\system32\urlmon.dll 2008-09-24 05:22:50 ----A---- C:\Windows\system32\mstime.dll 2008-09-24 05:22:50 ----A---- C:\Windows\system32\jsproxy.dll 2008-09-24 05:22:43 ----A---- C:\Windows\system32\inetcomm.dll 2008-09-24 05:22:36 ----A---- C:\Windows\system32\shell32.dll 2008-09-24 05:22:20 ----A---- C:\Windows\system32\winipsec.dll 2008-09-24 05:22:20 ----A---- C:\Windows\system32\polstore.dll 2008-09-24 05:22:20 ----A---- C:\Windows\system32\FwRemoteSvr.dll 2008-09-24 05:22:16 ----A---- C:\Windows\system32\Apphlpdm.dll 2008-09-24 05:22:15 ----A---- C:\Windows\system32\GameUXLegacyGDFs.dll 2008-09-24 05:22:15 ----A---- C:\Windows\system32\gameux.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\wshext.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\wscript.exe 2008-09-24 05:22:12 ----A---- C:\Windows\system32\vbscript.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\scrrun.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\scrobj.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\jscript.dll 2008-09-24 05:22:12 ----A---- C:\Windows\system32\cscript.exe 2008-09-24 05:21:37 ----A---- C:\Windows\system32\es.dll 2008-09-24 05:21:35 ----A---- C:\Windows\system32\quartz.dll 2008-09-24 05:21:01 ----A---- C:\Windows\system32\dataclen.dll 2008-09-24 05:20:57 ----A---- C:\Windows\system32\wmpeffects.dll 2008-09-24 05:20:56 ----A---- C:\Windows\system32\wshrm.dll 2008-09-24 05:09:00 ----A---- C:\Windows\system32\wups.dll 2008-09-24 05:09:00 ----A---- C:\Windows\system32\wudriver.dll 2008-09-24 05:09:00 ----A---- C:\Windows\system32\wuapi.dll 2008-09-24 05:08:48 ----A---- C:\Windows\system32\wuwebv.dll 2008-09-24 05:08:48 ----A---- C:\Windows\system32\wuapp.exe 2008-09-24 05:05:14 ----D---- C:\Users\Donna\AppData\Roaming\Smith Micro 2008-09-24 05:00:53 ----D---- C:\Program Files (x86)\Novatel Wireless 2008-09-24 05:00:40 ----D---- C:\Program Files (x86)\Verizon Wireless 2008-09-24 04:23:26 ----D---- C:\Users\Donna\AppData\Roaming\Hewlett-Packard 2008-09-24 04:22:41 ----D---- C:\Users\Donna\AppData\Roaming\Identities 2008-09-24 04:18:57 ----D---- C:\Users\Donna\AppData\Roaming\HP TCS 2008-09-24 04:18:15 ----D---- C:\ProgramData\Viewpoint 2008-09-24 04:18:15 ----D---- C:\Program Files (x86)\Viewpoint 2008-09-24 04:17:54 ----D---- C:\Program Files (x86)\Common Files\AOL 2008-09-24 04:17:54 ----D---- C:\Program Files (x86)\AIM6 2008-09-24 04:15:20 ----SD---- C:\Users\Donna\AppData\Roaming\Microsoft 2008-09-24 04:15:20 ----D---- C:\Users\Donna\AppData\Roaming\Media Center Programs 2008-09-24 03:10:42 ----SHD---- C:\System Volume Information 2008-09-24 02:40:06 ----D---- C:\ProgramData\NVIDIA 2008-09-24 02:39:58 ----SHD---- C:\$RECYCLE.BIN 2008-09-24 02:39:11 ----D---- C:\ProgramData\CyberLink 2008-09-24 02:26:41 ----A---- C:\Windows\system32\staco.dll 2008-09-24 02:26:33 ----D---- C:\Program Files (x86)\IDT 2008-09-24 02:26:27 ----A---- C:\Windows\xUninstall.bat 2008-09-24 02:25:38 ----D---- C:\Windows\JMCR_DIR 2008-09-24 02:25:21 ----A---- C:\Windows\system32\SynTPCOM.dll 2008-09-24 02:25:20 ----A---- C:\Windows\system32\SynCtrl.dll 2008-09-24 02:25:20 ----A---- C:\Windows\system32\SynCOM.dll 2008-09-24 02:24:58 ----D---- C:\Program Files (x86)\Realtek 2008-09-24 02:24:42 ----D---- C:\Windows\system32\HPMDP 2008-09-24 02:24:36 ----D---- C:\Windows\Driver Cache 2008-09-24 02:24:34 ----D---- C:\Program Files (x86)\AVerMedia 2008-09-24 02:22:10 ----D---- C:\Program Files (x86)\Intel 2008-09-24 02:22:10 ----A---- C:\Windows\system32\CSVer.dll 2008-09-24 02:21:57 ----D---- C:\Windows\SoftwareDistribution 2008-09-24 02:21:55 ----D---- C:\Intel 2008-09-24 02:20:14 -------- C:\Windows\system32\agrsmdel.exe 2008-09-24 02:20:14 -------- C:\Windows\system32\agrsco64.dll 2008-09-24 02:19:59 ----D---- C:\Windows\Options 2008-09-24 02:12:45 ----D---- C:\Windows\Prefetch 2008-08-21 17:48:14 ----A---- C:\Windows\system32\mxntdfg.exe ======List of files/folders modified in the last 3 months====== 2008-10-12 15:43:06 ----D---- C:\Windows\Temp 2008-10-12 14:43:07 ----D---- C:\Windows\System32 2008-10-12 14:43:07 ----D---- C:\Windows\inf 2008-10-12 12:59:58 ----D---- C:\Windows\rescache 2008-10-12 12:47:44 ----HD---- C:\ProgramData 2008-10-12 12:47:43 ----D---- C:\Windows\SysWOW64 2008-10-12 12:47:13 ----RD---- C:\Program Files 2008-10-12 12:46:44 ----HD---- C:\Program Files (x86)\InstallShield Installation Information 2008-10-12 12:46:32 ----D---- C:\WINDOWS 2008-10-12 12:46:26 ----D---- C:\Windows\twain_32 2008-10-12 12:41:57 ----D---- C:\Windows\Registration 2008-10-12 12:36:42 ----D---- C:\Windows\winsxs 2008-10-12 12:26:47 ----SHD---- C:\Windows\Installer 2008-10-12 12:26:46 ----RD---- C:\Program Files (x86) 2008-10-12 12:10:10 ----D---- C:\Windows\Debug 2008-10-12 11:13:37 ----SD---- C:\Windows\Downloaded Program Files 2008-10-12 10:32:10 ----D---- C:\Windows\system32\drivers 2008-10-12 10:32:07 ----D---- C:\Program Files (x86)\Common Files 2008-10-11 23:57:26 ----D---- C:\Windows\Tasks 2008-10-11 05:01:51 ----D---- C:\ProgramData\Microsoft Help 2008-10-07 16:55:38 ----D---- C:\Program Files (x86)\Java 2008-10-05 11:54:15 ----SD---- C:\ProgramData\Microsoft 2008-10-05 07:37:39 ----D---- C:\Windows\system32\config 2008-10-05 00:40:58 ----SHD---- C:\boot 2008-10-04 04:57:57 ----D---- C:\Windows\SMINST 2008-10-04 04:55:25 ----RSD---- C:\Windows\assembly 2008-10-04 04:55:20 ----D---- C:\Program Files (x86)\Hewlett-Packard 2008-10-04 04:53:42 ----D---- C:\SwSetup 2008-10-02 17:37:10 ----D---- C:\ProgramData\HP 2008-10-02 07:31:40 ----D---- C:\Program Files (x86)\Common Files\microsoft shared 2008-10-02 07:31:38 ----D---- C:\Program Files (x86)\Microsoft Office 2008-10-02 01:36:08 ----D---- C:\Windows\tapi 2008-09-26 17:11:09 ----D---- C:\Windows\Microsoft.NET 2008-09-25 01:40:45 ----D---- C:\Program Files (x86)\Internet Explorer 2008-09-24 16:29:16 ----D---- C:\Windows\Logs 2008-09-24 14:42:15 ----N---- C:\Windows\win.ini 2008-09-24 08:00:32 ----D---- C:\Program Files (x86)\MSBuild 2008-09-24 08:00:08 ----D---- C:\Windows\ShellNew 2008-09-24 07:59:50 ----RSD---- C:\Windows\Fonts 2008-09-24 07:50:03 ----D---- C:\Program Files (x86)\Common Files\System 2008-09-24 05:37:51 ----D---- C:\Windows\system32\en-US 2008-09-24 05:37:49 ----D---- C:\Windows\PolicyDefinitions 2008-09-24 05:37:47 ----D---- C:\Windows\ehome 2008-09-24 05:37:47 ----D---- C:\Windows\AppPatch 2008-09-24 05:37:46 ----D---- C:\Windows\system32\migration 2008-09-24 05:37:45 ----D---- C:\Program Files (x86)\Windows Mail 2008-09-24 05:04:59 ----D---- C:\Windows\ModemLogs 2008-09-24 05:00:49 ----D---- C:\Windows\Downloaded Installations 2008-09-24 04:35:43 ----D---- C:\Program Files (x86)\Yahoo! 2008-09-24 04:32:24 ----D---- C:\Program Files (x86)\Common Files\Symantec Shared 2008-09-24 04:22:28 ----D---- C:\Windows\system 2008-09-24 04:18:49 ----RD---- C:\Program Files (x86)\Online Services 2008-09-24 04:18:48 ----HD---- C:\HP 2008-09-24 04:17:04 ----HD---- C:\System.sav 2008-09-24 04:15:20 ----RD---- C:\Users 2008-09-24 02:42:06 ----D---- C:\Windows\panther 2008-09-24 02:38:03 ----D---- C:\Program Files (x86)\CyberLink 2008-09-24 02:30:12 ----D---- C:\ProgramData\Hewlett-Packard 2008-09-24 02:24:11 ----D---- C:\Windows\Help ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 {22D78859-9CE9-4B77-BF18-AC83E81A9263};{22D78859-9CE9-4B77-BF18-AC83E81A9263}; \??\C:\Program Files (x86)\HP\QuickPlay\000.fcl [2008-04-23 32240] R2 BVRPMPR5a64;BVRPMPR5a64 NDIS Protocol Driver; \??\C:\Windows\system32\drivers\BVRPMPR5a64.SYS [] R2 sxuptp;SXUPTP Driver; C:\Windows\system32\DRIVERS\sxuptp.sys [] R3 Accelerometer;HP Accelerometer; C:\Windows\system32\DRIVERS\Accelerometer.sys [] R3 Afc;PPdus ASPI Shell; C:\Windows\SysWOW64\drivers\Afc.sys [2006-09-18 22784] R3 AgereSoftModem;Agere Systems Soft Modem; C:\Windows\system32\DRIVERS\agrsm64.sys [] R3 AVerBDA6x_x64;AVerMedia SAA716x BDA Service; C:\Windows\system32\DRIVERS\AVerBDA716x_x64.sys [] R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\Windows\system32\DRIVERS\CmBatt.sys [] R3 enecir;ENE CIR Receiver; C:\Windows\system32\DRIVERS\enecir.sys [] R3 HpqKbFiltr;HpqKbFilter Driver; C:\Windows\system32\DRIVERS\HpqKbFiltr.sys [] R3 JMCR;JMCR; C:\Windows\system32\DRIVERS\jmcr.sys [] R3 ksthunk;Kernel Streaming Thunks; C:\Windows\system32\drivers\ksthunk.sys [] R3 NVHDA;Service for NVIDIA High Definition Audio Driver; C:\Windows\system32\drivers\nvhda64v.sys [] R3 nvlddmkm;nvlddmkm; C:\Windows\system32\DRIVERS\nvlddmkm.sys [] R3 NWADI;NWADI Bus Enumerator; C:\Windows\system32\DRIVERS\NWADIenum.sys [] R3 NWUSBModem;Novatel Wireless USB Modem Driver; C:\Windows\system32\DRIVERS\nwusbmdm.sys [] R3 NWUSBPort;Novatel Wireless USB Status Port Driver; C:\Windows\system32\DRIVERS\nwusbser.sys [] R3 NWUSBPort2;Novatel Wireless USB Status2 Port Driver; C:\Windows\system32\DRIVERS\nwusbser2.sys [] R3 RTL8169;Realtek 8169 NT Driver; C:\Windows\system32\DRIVERS\Rtlh64.sys [] R3 STHDA;IDT High Definition Audio CODEC; C:\Windows\system32\DRIVERS\stwrt64.sys [] R3 SynTP;Synaptics TouchPad Driver; C:\Windows\system32\DRIVERS\SynTP.sys [] R3 WmiAcpi;Microsoft Windows Management Interface for ACPI; C:\Windows\system32\DRIVERS\wmiacpi.sys [] R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [] S2 tmpreflt;tmpreflt; \??\C:\PROGRA~2\AVANQU~1\SYSTEM~1\tmpreflt.sys [2007-09-05 32528] S2 tmxpflt;tmxpflt; \??\C:\PROGRA~2\AVANQU~1\SYSTEM~1\tmxpflt.sys [2007-09-05 199440] S2 Vsapint;Vsapint; \??\C:\PROGRA~2\AVANQU~1\SYSTEM~1\Vsapint.sys [2007-09-05 1052472] S3 BCM43XV;Broadcom Extensible 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl664.sys [] S3 BthEnum;Bluetooth Request Block Driver; C:\Windows\system32\DRIVERS\BthEnum.sys [] S3 BthPan;Bluetooth Device (Personal Area Network); C:\Windows\system32\DRIVERS\bthpan.sys [] S3 BTHPORT;Bluetooth Port Driver; C:\Windows\System32\Drivers\BTHport.sys [] S3 BTHUSB;Bluetooth Radio USB Driver; C:\Windows\System32\Drivers\BTHUSB.sys [] S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [] S3 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [] S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [] S3 HpqRemHid;HP Remote Control HID Device; C:\Windows\system32\DRIVERS\HpqRemHid.sys [] S3 HSF_DPV;HSF_DPV; C:\Windows\system32\DRIVERS\VSTDPV6.SYS [] S3 HSFHWAZL;HSFHWAZL; C:\Windows\system32\DRIVERS\VSTAZL6.SYS [] S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [] S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [] S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [] S3 NETw5v64;Intel(R) Wireless WiFi Link Adapter Driver for Windows Vista 64 Bit ; C:\Windows\system32\DRIVERS\NETw5v64.sys [] S3 NVENETFD;NVIDIA nForce Networking Controller Driver; C:\Windows\system32\DRIVERS\nvm60x64.sys [] S3 RFCOMM;Bluetooth Device (RFCOMM Protocol TDI); C:\Windows\system32\DRIVERS\rfcomm.sys [] S3 sdbus;sdbus; C:\Windows\system32\DRIVERS\sdbus.sys [] S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [] S3 usbvideo;USB Video Device (WDM); C:\Windows\System32\Drivers\usbvideo.sys [] S3 winachsf;winachsf; C:\Windows\system32\DRIVERS\VSTCNXT6.SYS [] S3 x64kdss;x64kdss; syswow64\Drivers\x64kdss.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 ACDaemon;ArcSoft Connect Daemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [2007-11-14 104960] R2 AESTFilters;Andrea ST Filters Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\AESTSr64.exe [] R2 AgereModemAudio;Agere Modem Call Progress Audio; C:\Windows\system32\agr64svc.exe [] R2 HP Health Check Service;HP Health Check Service; c:\Program Files (x86)\Hewlett-Packard\HP Health Check\hphc_service.exe [2008-06-16 94208] R2 hpsrv;HP Service; C:\Windows\system32\Hpservice.exe [] R2 nvsvc;NVIDIA Display Driver Service; C:\Windows\system32\nvvsvc.exe [] R2 Pml Driver HPZ12;Pml Driver HPZ12; C:\Windows\System32\svchost.exe [2008-01-20 21504] R2 QPSched;QuickPlay Task Scheduler (QTS); C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPSched.exe [2008-04-23 112008] R2 Recovery Service for Windows;Recovery Service for Windows; C:\Windows\SMINST\BLService.exe [2008-03-26 341328] R2 RichVideo;Cyberlink RichVideo Service(CRVS); C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe [2007-01-09 272024] R2 SCAppMgr;Smart Client Manager; C:\Program Files (x86)\Ellie Mae\SCAppMgr\SCAppMgr.exe [2008-07-29 36864] R2 STacSV;Audio Service; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_48fbb870\STacSV64.exe [] R2 SystemSuite Task Manager;SystemSuite Task Manager; C:\PROGRA~2\AVANQU~1\SYSTEM~1\MXTask.exe [2008-08-26 152832] R2 Viewpoint Manager Service;Viewpoint Manager Service; C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652] R3 hpqwmiex;hpqwmiex; C:\Program Files (x86)\Hewlett-Packard\Shared\hpqwmiex.exe [2008-01-25 148832] S3 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64; C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2008-01-20 93696] S3 GameConsoleService;GameConsoleService; C:\Program Files (x86)\HP Games\My HP Game Console\GameConsoleService.exe [2007-12-04 181784] S3 GoToAssist;GoToAssist; C:\Program Files (x86)\Citrix\GoToAssist\480\g2aservice.exe [2008-09-26 16936] S3 IDriverT;InstallDriver Table Manager; C:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe [2004-10-22 73728] S3 ose;Office Source Engine; C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2006-10-26 145184] S3 PerfHost;@%systemroot%\sysWow64\perfhost.exe,-2; C:\Windows\SysWow64\perfhost.exe [2008-01-20 19968] S4 BthServ;Bluetooth Support Service; C:\Windows\system32\svchost.exe [2008-01-20 21504] S4 Com4QLBEx;Com4QLBEx; C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch Buttons\Com4QLBEx.exe [2008-04-03 193840] S4 gusvc;Google Updater Service; C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-09-25 138168] S4 Microsoft Office Groove Audit Service;Microsoft Office Groove Audit Service; C:\Program Files (x86)\Microsoft Office\Office12\GrooveAuditService.exe [2007-08-24 68464] S4 odserv;Microsoft Office Diagnostics Service; C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2007-08-24 443776] S4 QPCapSvc;QuickPlay Background Capture Service (QBCS); C:\Program Files (x86)\HP\QuickPlay\Kernel\TV\QPCapSvc.exe [2008-04-23 292232] -----------------EOF-----------------