Logfile of random's system information tool 1.05 (written by random/random)
Run by Administrator at 2009-03-16 00:03:09
Microsoft Windows 2000 Professional Service Pack 4
System drive C: has 4 GB (10%) free of 38 GB
Total RAM: 503 MB (59% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:03:28 AM, on 3/16/2009
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal
Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\netdde.exe
C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
C:\WINNT\system32\basfipm.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\WINNT\system32\cisvc.exe
C:\WINNT\system32\clipsrv.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\locator.exe
C:\WINNT\System32\SCardSvr.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\tcpsvcs.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\dmadmin.exe
C:\WINNT\system32\msdtc.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\cidaemon.exe
C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\internet explorer\iexplore.exe
C:\WINNT\system32\DllHost.exe
C:\Documents and Settings\Administrator\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackCheck\Administrator.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://live.xbox.com/en-US/profile/Friends.aspxR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKUS\S-1-5-21-577020384-2308808795-1272252130-1009\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'ASPNET')
O4 - HKUS\.DEFAULT\..\Run: [internat.exe] internat.exe (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: BitComet Search - {461CC20B-FB6E-4f16-8FE8-C29359DB100E} - C:\WINNT\system32\shdocvw.dll
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O10 - Unknown file in Winsock LSP: c:\winnt\system32\nwprovau.dll
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) -
http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cabO16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) -
http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cabO16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) -
http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/...b?1134589117044O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdat...b?1143753340215O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) -
http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) -
http://cdn2.zone.msn.com/binFramework/v10/...ro.cab56649.cabO16 - DPF: {BFF1950D-B1B4-4AE8-B842-B2CCF06D9A1B} (Zylom Games Player) -
http://aolsvc.aol.com/onlinegames/free-tri...zylomplayer.cabO16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) -
http://zone.msn.com/binframework/v10/StProxy.cab55579.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{9758C124-7DE9-4E40-8FA8-9A680ACA1457}: NameServer = 167.206.254.1,167.206.254.2
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
O23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
O23 - Service: Broadcom ASF IP monitoring service v6.0.3 (BAsfIpM) - Broadcom Corp. - C:\WINNT\system32\basfipm.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: McAfee Real-time Scanner (McShield) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe (file missing)
O23 - Service: McAfee SystemGuards (McSysmon) - Unknown owner - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe (file missing)
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: NFServer - Unknown owner - C:\Program Files\Fortress\AirFortress® Client\NFServer.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: WLANKEEPER - Intel® Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
--
End of file - 9800 bytes
======Scheduled tasks folder======
C:\WINNT\tasks\Symantec NetDetect.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}]
SSVHelper Class - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll [2008-06-10 509328]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - c:\program files\google\googletoolbar1.dll [2008-05-13 2403392]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\3.1.807.1746\swg.dll [2008-09-07 737776]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{8E718888-423F-11D2-876E-00A0C9082467} - @msdxmLC.dll,-1@1033,&Radio - C:\WINNT\s [2007-08-25 40]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google - c:\program files\google\googletoolbar1.dll [2008-05-13 2403392]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"ccApp"=C:\Program Files\Common Files\Symantec Shared\ccApp.exe [2004-02-29 66680]
"GhostStartTrayApp"=C:\Program Files\Symantec\Norton Ghost 2003\GhostStartTrayApp.exe [2002-08-14 94208]
"IntelWireless"=C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe [2004-10-30 385024]
"ISUSPM Startup"=C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe [2004-06-16 221184]
"ISUSScheduler"=C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [2004-06-16 81920]
"Synchronization Manager"=mobsync.exe /logon []
"vptray"=C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe [2004-05-06 124112]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINNT\system32\ctfmon.exe [2001-02-20 8192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\WINNT\system32\igfxdev.dll [2005-10-14 135168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\IntelWireless]
C:\Program Files\Intel\Wireless\Bin\LgNotify.dll [2004-09-07 110592]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\NavLogon]
C:\WINNT\s [2007-08-25 40]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\nwprovau]
C:\WINNT\system32\nwprovau.dll [2006-09-01 140048]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ScCertProp]
C:\WINNT\system32\wlnotify.dll [2005-04-08 57104]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa]
"authentication packages"=msv1_0
nwprovau
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"disablecad"=0
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=323
"NoDriveAutoRun"=67108863
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveAutoRun"=
"NoDriveTypeAutoRun"=
"NoDrives"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"C:\Program Files\BitTorrent\bittorrent.exe"="C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2009-03-15 23:26:12 ----D---- C:\WINNT\ERUNT
2009-03-15 23:12:12 ----D---- C:\SDFix
2009-03-15 21:58:36 ----A---- C:\WINNT\system32\wuauclt.exe
2009-03-15 21:44:43 ----D---- C:\Program Files\Adaptec
2009-03-15 16:24:55 ----D---- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
2009-03-15 15:47:26 ----SHD---- C:\RECYCLER
2009-03-15 12:48:16 ----A---- C:\WINNT\SchedLgU.Txt
2009-03-15 12:17:07 ----D---- C:\WINNT\temp
2009-03-15 12:17:04 ----A---- C:\ComboFix.txt
2009-03-15 11:54:54 ----A---- C:\WINNT\zip.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\VFIND.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\SWXCACLS.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\SWSC.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\SWREG.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\sed.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\NIRCMD.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\grep.exe
2009-03-15 11:54:54 ----A---- C:\WINNT\fdsv.exe
2009-03-15 11:54:31 ----D---- C:\WINNT\ERDNT
2009-03-15 11:54:29 ----D---- C:\Qoobox
2009-03-14 23:52:31 ----D---- C:\rsit
2009-03-14 13:05:17 ----D---- C:\Program Files\MBAM
2009-03-14 13:05:17 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-14 12:59:52 ----A---- C:\WINNT\ntbtlog.txt
2009-03-14 12:37:31 ----D---- C:\Program Files\CCleaner
2009-03-13 20:19:31 ----D---- C:\fixwareout
2009-03-13 14:16:25 ----D---- C:\Program Files\Trend Micro
2009-03-12 21:30:43 ----D---- C:\Program Files\F-Group
2009-03-12 21:00:13 ----ASH---- C:\BOOT.BAK
2009-03-12 20:55:54 ----D---- C:\$WIN_NT$.~LS
2009-03-12 20:55:54 ----D---- C:\$WIN_NT$.~BT
2009-03-12 17:40:12 ----A---- C:\WINNT\UPGRADE.TXT
2009-03-12 17:40:10 ----D---- C:\WINNT\setup.pss
2009-03-12 14:02:45 ----A---- C:\WINNT\system32\sqlite3.dll
2009-03-12 14:02:45 ----A---- C:\WINNT\system32\ascbalon.dll
2009-03-12 14:02:44 ----A---- C:\WINNT\system32\SysRestore.dll
2009-03-12 14:02:44 ----A---- C:\WINNT\system32\SQLiteWrapper.dll
2009-03-12 14:02:44 ----A---- C:\WINNT\system32\ConTest.dll
2009-03-12 14:02:43 ----D---- C:\Program Files\Ascentive
2009-03-12 00:33:29 ----D---- C:\Program Files\Anti Trojan Elite
2009-03-12 00:20:44 ----A---- C:\WINNT\system32\XceedCry.dll
2009-03-12 00:20:44 ----A---- C:\WINNT\system32\XceedBkp.dll
2009-03-11 21:31:54 ----D---- C:\Program Files\Panda Security
2009-03-11 20:16:26 ----D---- C:\WINNT\SoftwareDistribution
2009-03-10 15:13:08 ----D---- C:\Documents and Settings\Administrator\Application Data\Thinstall
======List of files/folders modified in the last 1 months======
2009-03-16 00:03:10 ----AD---- C:\WINNT\SYSTEM32
2009-03-16 00:00:47 ----D---- C:\Program Files\Mozilla Firefox
2009-03-15 23:42:00 ----D---- C:\WINNT\system32\NtmsData
2009-03-15 23:41:57 ----AD---- C:\WINNT\system32\IAS
2009-03-15 23:41:36 ----A---- C:\WINNT\ModemLog_Conexant D110 MDC V.92 Modem.txt
2009-03-15 23:41:33 ----AD---- C:\WINNT\Debug
2009-03-15 23:26:12 ----AD---- C:\WINNT
2009-03-15 21:58:41 ----RASHD---- C:\WINNT\system32\DLLCACHE
2009-03-15 21:58:27 ----AHD---- C:\WINNT\INF
2009-03-15 21:44:43 ----AD---- C:\Program Files\Windows Media Player
2009-03-15 21:44:43 ----AD---- C:\Program Files\Common Files
2009-03-15 21:44:43 ----AD---- C:\Program Files
2009-03-15 21:41:07 ----AD---- C:\WINNT\Help
2009-03-15 21:38:44 ----RASH---- C:\BOOT.INI
2009-03-15 18:58:35 ----AD---- C:\WINNT\system32\DRIVERS
2009-03-15 15:05:28 ----D---- C:\Program Files\yRead2
2009-03-15 12:13:34 ----A---- C:\WINNT\system.ini
2009-03-15 12:07:39 ----AD---- C:\WINNT\AppPatch
2009-03-15 12:05:43 ----SD---- C:\WINNT\Web
2009-03-14 12:51:26 ----D---- C:\WINNT\Minidump
2009-03-14 01:13:38 ----SHD---- C:\WINNT\CSC
2009-03-13 22:26:23 ----SD---- C:\WINNT\Downloaded Program Files
2009-03-13 20:12:14 ----D---- C:\Documents and Settings\All Users\Application Data\Viewpoint
2009-03-13 12:44:18 ----D---- C:\WINNT\system32\Macromed
2009-03-13 00:00:08 ----D---- C:\Program Files\Advanced Uninstaller PRO - Version 9
2009-03-12 21:30:20 ----D---- C:\Downloads
2009-03-12 16:38:33 ----D---- C:\Rome
2009-03-12 15:44:08 ----HD---- C:\Program Files\InstallShield Installation Information
2009-03-12 15:38:00 ----SD---- C:\WINNT\Tasks
2009-03-12 14:05:10 ----D---- C:\Program Files\Common Files\Symantec Shared
2009-03-12 14:02:54 ----SHD---- C:\WINNT\Installer
2009-03-12 14:02:54 ----AHD---- C:\Config.Msi
2009-03-12 14:02:47 ----D---- C:\WINNT\Support_Files
2009-03-11 16:04:55 ----A---- C:\WINNT\WIN.INI
2009-03-11 16:04:51 ----RASD---- C:\WINNT\Fonts
2009-03-11 15:52:16 ----ASD---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2009-03-11 14:37:38 ----AD---- C:\Documents and Settings
2009-03-11 14:19:40 ----AD---- C:\WINNT\system32\CONFIG
2009-03-11 12:32:11 ----D---- C:\Program Files\DivX
2009-02-27 17:03:48 ----D---- C:\Documents and Settings\Administrator\Application Data\LimeWire
2009-02-25 12:55:00 ----A---- C:\WINNT\system32\MRT.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 Cdr4_2K;Cdr4_2K; C:\WINNT\s [2007-08-25 40]
R1 Cdralw2k;Cdralw2k; C:\WINNT\s [2007-08-25 40]
R1 Dlc;DLC Protocol; C:\WINNT\s [2007-08-25 40]
R1 GhPciScan;GhostPciScanner; \??\C:\Program Files\Symantec\Norton Ghost 2003\ghpciscan.sys []
R1 MPFP;MPFP; C:\WINNT\S [2007-08-25 40]
R1 omci;OMCI WDM Device Driver; C:\WINNT\s [2007-08-25 40]
R1 SAVRT;SAVRT; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\savrt.sys []
R1 SbcpHid;SbcpHid; \??\C:\WINNT\system32\Drivers\SbcpHid.sys []
R1 SYMTDI;SYMTDI; C:\WINNT\S [2007-08-25 40]
R2 AegisP;AEGIS Protocol (IEEE 802.1x) v3.2.0.3; C:\WINNT\s [2007-08-25 40]
R2 AppleTalk;AppleTalk Protocol; C:\WINNT\s [2007-08-25 40]
R2 Aspi32;Aspi32; C:\WINNT\s [2007-08-25 40]
R2 BASFND;BASFND; \??\C:\WINNT\system32\Drivers\BASFND.sys []
R2 mdmxsdk;mdmxsdk; C:\WINNT\s [2007-08-25 40]
R2 NwlnkIpx;NWLink IPX/SPX/NetBIOS Compatible Transport Protocol; C:\WINNT\s [2007-08-25 40]
R2 NwlnkNb;NWLink NetBIOS; C:\WINNT\s [2007-08-25 40]
R2 NwlnkSpx;NWLink SPX/SPXII Protocol; C:\WINNT\s [2007-08-25 40]
R2 PRPC;PRPC; C:\WINNT\s [2007-08-25 40]
R2 s24trans;WLAN Transport; C:\WINNT\s [2007-08-25 40]
R2 SAVRTPEL;SAVRTPEL; \??\C:\Program Files\Symantec Client Security\Symantec AntiVirus\Savrtpel.sys []
R3 ApfiltrService;Alps Touch Pad Filter Driver for Windows 2000/XP; C:\WINNT\s [2007-08-25 40]
R3 b57w2k;Broadcom NetXtreme 57xx Gigabit Controller; C:\WINNT\s [2007-08-25 40]
R3 catchme;catchme; \??\C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\catchme.sys []
R3 CmBatt;Microsoft ACPI Control Method Battery Driver; C:\WINNT\s [2007-08-25 40]
R3 GTIPCI21;GTIPCI21; C:\WINNT\s [2007-08-25 40]
R3 HSF_DPV;HSF_DPV; C:\WINNT\s [2007-08-25 40]
R3 HSFHWICH;HSFHWICH; C:\WINNT\s [2007-08-25 40]
R3 ialm;ialm; C:\WINNT\s [2007-08-25 40]
R3 IWCA2K;Intel Wireless Connection Agent Miniport for Win 2K; C:\WINNT\s [2007-08-25 40]
R3 NAVENG;NAVENG; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090311.003\naveng.sys []
R3 NAVEX15;NAVEX15; \??\C:\PROGRA~1\COMMON~1\SYMANT~1\VIRUSD~1\20090311.003\navex15.sys []
R3 NWRDR;NetWare Rdr; C:\WINNT\s [2007-08-25 40]
R3 ROOTMODEM;Microsoft Legacy Modem Driver; C:\WINNT\S [2007-08-25 40]
R3 STAC97;SigmaTel C-Major Audio; C:\WINNT\s [2007-08-25 40]
R3 SYMDNS;SYMDNS; C:\WINNT\S [2007-08-25 40]
R3 SymEvent;SymEvent; \??\C:\Program Files\Symantec\SYMEVENT.SYS []
R3 SYMFW;SYMFW; C:\WINNT\S [2007-08-25 40]
R3 SYMIDS;SYMIDS; C:\WINNT\S [2007-08-25 40]
R3 SYMIDSCO;SYMIDSCO; C:\WINNT\S [2007-08-25 40]
R3 SYMNDIS;SYMNDIS; C:\WINNT\S [2007-08-25 40]
R3 SYMREDRV;SYMREDRV; C:\WINNT\S [2007-08-25 40]
R3 uhcd;Microsoft USB Universal Host Controller Driver; C:\WINNT\s [2007-08-25 40]
R3 usbehci;Microsoft USB 2.0 Enhanced Host Controller Miniport Driver; C:\WINNT\s [2007-08-25 40]
R3 usbhub;Microsoft USB Standard Hub Driver; C:\WINNT\s [2007-08-25 40]
R3 usbhub20;USB 2.0 Root Hub Support; C:\WINNT\s [2007-08-25 40]
R3 wanatw;WAN Miniport (ATW); C:\WINNT\s [2007-08-25 40]
R3 winachsf;winachsf; C:\WINNT\s [2007-08-25 40]
S2 HidUsb;Microsoft HID Class Driver; C:\WINNT\s [2007-08-25 40]
S3 ATE_PROCMON;ATE_PROCMON; C:\WINNT\s [2007-08-25 40]
S3 ATWPKT2;ATWPKT2; \??\C:\Program Files\Common Files\AOL\ACS\ATWPKT2.SYS []
S3 BCM43XX;Dell Wireless WLAN Card Driver; C:\WINNT\s [2007-08-25 40]
S3 bvrp_pci;bvrp_pci; C:\WINNT\s [2007-08-25 40]
S3 ccdecode;Closed Caption Decoder; C:\WINNT\s [2007-08-25 40]
S3 EL90BC;3Com EtherLink XL B/C Adapter Driver; C:\WINNT\s [2007-08-25 40]
S3 HSF_DP;HSF_DP; C:\WINNT\s [2007-08-25 40]
S3 mouhid;Mouse HID Driver; C:\WINNT\s [2007-08-25 40]
S3 MPE;BDA MPE Filter; C:\WINNT\s [2007-08-25 40]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINNT\s [2007-08-25 40]
S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINNT\s [2007-08-25 40]
S3 ndiscm;Motorola SURFboard USB Cable Modem Windows Driver; C:\WINNT\s [2007-08-25 40]
S3 nm;Network Monitor Driver; C:\WINNT\s [2007-08-25 40]
S3 nv4;nv4; C:\WINNT\s [2007-08-25 40]
S3 O2SCBUS;O2Micro SmartCardBus Reader; C:\WINNT\s [2007-08-25 40]
S3 Scr110;SCR110 Serial Smart Card Reader; C:\WINNT\s [2007-08-25 40]
S3 SCRx31 USB Reader;SCRx31 USB Reader; C:\WINNT\s [2007-08-25 40]
S3 SLIP;BDA Slip De-Framer; C:\WINNT\s [2007-08-25 40]
S3 streamip;BDA IPSink; C:\WINNT\s [2007-08-25 40]
S3 tapvpn;TAP VPN Adapter; C:\WINNT\s [2007-08-25 40]
S3 UIUSys;Conexant Setup API; C:\WINNT\s [2007-08-25 40]
S3 USBSTOR;USB Mass Storage Driver; C:\WINNT\s [2007-08-25 40]
S3 w70n5;Intel® PRO/Wireless 7100 Adapter Driver; C:\WINNT\s [2007-08-25 40]
S3 WSTCODEC;World Standard Teletext Codec; C:\WINNT\s [2007-08-25 40]
S4 WS2IFSL;Windows Socket 2.0 Non-IFS Service Provider Support Environment; C:\WINNT\S [2007-08-25 40]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AOL ACS;AOL Connectivity Service; C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe [2004-10-20 10328]
R2 AOL TopSpeedMonitor;AOL TopSpeed Monitor; C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe [2004-10-15 100016]
R2 aspnet_state;ASP.NET State Service; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800]
R2 BAsfIpM;Broadcom ASF IP monitoring service v6.0.3; C:\WINNT\s [2007-08-25 40]
R2 ccEvtMgr;Symantec Event Manager; C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe [2004-02-29 255096]
R2 ccProxy;Symantec Network Proxy; C:\Program Files\Common Files\Symantec Shared\ccProxy.exe [2004-02-29 291960]
R2 ccSetMgr;Symantec Settings Manager; C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe [2004-02-29 242808]
R2 DefWatch;Symantec AntiVirus Definition Watcher; C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe [2004-05-06 29912]
R2 EvtEng;EvtEng; C:\Program Files\Intel\Wireless\Bin\EvtEng.exe [2004-09-07 86016]
R2 GhostStartService;GhostStartService; C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE [2002-08-14 200704]
R2 MDM;Machine Debug Manager; C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe [2003-06-20 322120]
R2 MpfService;McAfee Personal Firewall Service; C:\Program Files\McAfee\MPF\MPFSrv.exe [2008-07-09 884360]
R2 NWCWorkstation;Client Service for NetWare; C:\WINNT\s [2007-08-25 40]
R2 RegSrvc;RegSrvc; C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe [2004-09-07 139264]
R2 S24EventMonitor;Spectrum24 Event Monitor; C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe [2004-09-07 360521]
R2 SimpTcp;Simple TCP/IP Services; C:\WINNT\s [2007-08-25 40]
R2 SNDSrvc;Symantec Network Drivers Service; C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe [2004-03-11 193760]
R2 Symantec AntiVirus;Symantec AntiVirus; C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe [2004-03-12 1221864]
R2 SymSecurePort;Symantec SecurePort; C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe [2004-05-05 222352]
R2 WLANKEEPER;WLANKEEPER; C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe [2004-09-07 225353]
S2 ccPwdSvc;Symantec Password Validation; C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe [2004-02-29 87160]
S2 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2008-05-13 138168]
S2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe []
S2 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe []
S2 NFServer;NFServer; C:\Program Files\Fortress\AirFortress® Client\NFServer.exe [2002-06-21 110592]
S2 WmdmPmSN;Portable Media Serial Number Service; C:\WINNT\S [2007-08-25 40]
S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINNT\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144]
S3 SavRoam;SAVRoam; C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe [2004-03-12 169192]
-----------------EOF-----------------