pravdepodobne rootkit v notebooku
Napsal: 02 zář 2010 23:28
Prosil bych zkontrolvat vypis z notasu kamosky. Blbne to - kdyz se pripojim na internet tak se spusti automaticke vypnuti pocitace do jedne minuty - nejde tomu predejit ani nastavenim automatickeho vypinani v setupu. Take po instalaci Avastu, nahrani updatu (vzhledem k nefunkcnosti internetu z jineho pocitace) a provedeni Full scanu a naslednem restartu pocitace se mi objevi BLue Screen a memory dump v uvitaci obrazovce kde vybiram uzivatele. To jsem odstranil naslednym odinstalovanim avastu v safe mode. Avast nasel virus v c:\windows\system32\drivers\igdkmd32.sys ale nebyl schopen odstranit ani presunout do truhly. Tady davam vypis logu RSIT. Predem diky za pomoc Martin (Chtel jsem prilozit i vypis ze souboru info.txt vyvorenym RSIT ale prispevek mel vic jak 60000 znaku tak to neslo - doufam ze tohle staci)
Logfile of random's system information tool 1.08 (written by random/random)
Run by Kerry Dunne at 2010-09-02 23:06:43
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 102 GB (72%) free of 142 GB
Total RAM: 3001 MB (66% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3768133199-3547387650-2985043688-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3768133199-3547387650-2985043688-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2009-08-26 378736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL [2009-08-26 107896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-28 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2010-01-29 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-12-28 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-20 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2009-08-26 378736]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-28 256112]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NPSStartup"= []
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"WarReg_PopUp"=C:\Program Files\eMachines\WR_PopUp\WarReg_PopUp.exe [2008-11-04 57344]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-02-11 6724128]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-11-05 154136]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2009-02-12 862728]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-11-05 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-11-05 178712]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-07-21 159744]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"Acer ePower Management"=C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe [2009-04-03 698912]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-02-11 1833504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-28 68856]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
"Google Update"=C:\Users\Kerry Dunne\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 135664]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12CFG214-K641-12SF-N85P]
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast5]
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtamon]
C:\Program Files\Dell V305\dldtamon.exe [2008-06-24 16624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtmon.exe]
C:\Program Files\Dell V305\dldtmon.exe [2008-06-24 668912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\txnnjgma]
C:\Users\Kerry Dunne\AppData\Local\lgppigpvg\bmkpcvhshdw.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-10-28 221184]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-09-02 23:06:43 ----D---- C:\rsit
2010-09-02 23:06:43 ----D---- C:\Program Files\trend micro
2010-09-02 23:06:24 ----D---- C:\Antivir
2010-09-02 21:41:53 ----D---- C:\Windows\system32\vi-VN
2010-09-02 21:41:53 ----D---- C:\Windows\system32\eu-ES
2010-09-02 21:41:53 ----D---- C:\Windows\system32\ca-ES
2010-09-02 17:40:31 ----ASH---- C:\hiberfil.sys
2010-09-02 07:15:36 ----D---- C:\ProgramData\Lavasoft
2010-09-02 07:15:36 ----D---- C:\Program Files\Lavasoft
2010-09-02 07:14:06 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-02 06:35:00 ----D---- C:\Windows\system32\EventProviders
2010-09-02 03:25:33 ----D---- C:\Windows\pss
2010-09-02 03:16:51 ----D---- C:\prac
2010-09-02 02:59:10 ----D---- C:\ProgramData\Alwil Software
2010-09-02 02:59:10 ----D---- C:\Program Files\Alwil Software
2010-08-30 14:26:10 ----A---- C:\Windows\system32\drivers\ltjgdmbd.sys
2010-08-30 14:23:41 ----D---- C:\RECYCLER
2010-08-30 14:22:27 ----RSH---- C:\Users\Kerry Dunne\AppData\Roaming\ohydy.exe
2010-08-30 14:22:08 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\5E170330394A038E71BCC34714A0F947
2010-08-28 01:01:13 ----A---- C:\Windows\ntbtlog.txt
2010-08-27 09:33:39 ----D---- C:\Program Files\Common Files\DESIGNER
2010-08-27 09:30:50 ----D---- C:\Program Files\Microsoft Analysis Services
2010-08-27 00:42:19 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Template
2010-08-17 02:05:37 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\PC Suite
2010-08-17 02:05:37 ----D---- C:\ProgramData\PC Suite
2010-08-16 23:05:30 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-08-16 23:05:25 ----D---- C:\Program Files\DIFX
2010-08-16 23:05:23 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-08-16 23:05:21 ----DC---- C:\Windows\system32\DRVSTORE
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bwhnt.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bwh.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bmdm.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bmdfl.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bcmnt.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bcm.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bbus.sys
2010-08-16 23:04:29 ----D---- C:\Windows\system32\Samsung_USB_Drivers
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExService.Exe
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExDisk.Sys
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExDevice.Dll
2010-08-16 22:53:31 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Samsung
2010-08-16 22:52:35 ----D---- C:\Program Files\MarkAny
2010-08-16 22:52:33 ----D---- C:\Program Files\PC Connectivity Solution
2010-08-16 22:51:52 ----D---- C:\Program Files\Samsung
2010-08-12 16:25:07 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-12 16:22:48 ----A---- C:\Windows\system32\iccvid.dll
2010-08-12 16:22:44 ----A---- C:\Windows\system32\ieapfltr.dll
2010-08-12 16:22:43 ----A---- C:\Windows\system32\mshtml.dll
2010-08-12 16:22:41 ----A---- C:\Windows\system32\urlmon.dll
2010-08-12 16:22:41 ----A---- C:\Windows\system32\ieframe.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\wininet.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\mshtmled.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\iepeers.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\ieencode.dll
2010-08-12 16:22:11 ----A---- C:\Windows\system32\schannel.dll
2010-08-12 16:20:21 ----A---- C:\Windows\system32\win32k.sys
2010-08-12 16:20:16 ----A---- C:\Windows\system32\rtutils.dll
2010-08-12 16:20:11 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-12 16:20:10 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-12 02:43:07 ----A---- C:\Windows\system32\msxml3.dll
2010-08-12 02:43:05 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-12 02:43:05 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-04 14:06:34 ----A---- C:\Windows\system32\shell32.dll
======List of files/folders modified in the last 1 months======
2010-09-02 23:06:43 ----RD---- C:\Program Files
2010-09-02 23:06:37 ----D---- C:\Windows\Temp
2010-09-02 23:06:35 ----D---- C:\Windows\Prefetch
2010-09-02 23:05:42 ----D---- C:\Windows\System32
2010-09-02 23:05:42 ----D---- C:\Windows\inf
2010-09-02 23:05:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-02 22:12:17 ----D---- C:\Windows\rescache
2010-09-02 22:06:58 ----D---- C:\Windows\Microsoft.NET
2010-09-02 22:06:31 ----RSD---- C:\Windows\assembly
2010-09-02 21:53:39 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Skype
2010-09-02 21:47:50 ----D---- C:\Windows
2010-09-02 21:47:34 ----SHD---- C:\Boot
2010-09-02 21:47:21 ----D---- C:\Windows\system32\catroot
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Sidebar
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Photo Gallery
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Media Player
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Mail
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Collaboration
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Calendar
2010-09-02 21:42:19 ----D---- C:\Program Files\Movie Maker
2010-09-02 21:42:19 ----D---- C:\Program Files\Internet Explorer
2010-09-02 21:42:19 ----D---- C:\Program Files\Common Files\System
2010-09-02 21:42:18 ----D---- C:\Windows\servicing
2010-09-02 21:42:18 ----D---- C:\Program Files\Windows Defender
2010-09-02 21:42:17 ----D---- C:\Windows\system32\XPSViewer
2010-09-02 21:42:17 ----D---- C:\Windows\system32\sk-SK
2010-09-02 21:42:17 ----D---- C:\Windows\system32\lv-LV
2010-09-02 21:42:17 ----D---- C:\Windows\system32\ko-KR
2010-09-02 21:42:17 ----D---- C:\Windows\system32\hr-HR
2010-09-02 21:42:17 ----D---- C:\Windows\system32\et-EE
2010-09-02 21:42:17 ----D---- C:\Windows\system32\da-DK
2010-09-02 21:42:17 ----D---- C:\Windows\IME
2010-09-02 21:42:16 ----D---- C:\Windows\system32\en-US
2010-09-02 21:42:11 ----D---- C:\Windows\system32\sv-SE
2010-09-02 21:42:11 ----D---- C:\Windows\system32\SLUI
2010-09-02 21:42:11 ----D---- C:\Windows\system32\setup
2010-09-02 21:42:11 ----D---- C:\Windows\system32\ru-RU
2010-09-02 21:42:11 ----D---- C:\Windows\system32\pt-PT
2010-09-02 21:42:11 ----D---- C:\Windows\system32\oobe
2010-09-02 21:42:11 ----D---- C:\Windows\system32\migration
2010-09-02 21:42:11 ----D---- C:\Windows\system32\it-IT
2010-09-02 21:42:11 ----D---- C:\Windows\system32\hu-HU
2010-09-02 21:42:11 ----D---- C:\Windows\system32\he-IL
2010-09-02 21:42:11 ----D---- C:\Windows\system32\fr-FR
2010-09-02 21:42:11 ----D---- C:\Windows\system32\fi-FI
2010-09-02 21:42:11 ----D---- C:\Windows\system32\el-GR
2010-09-02 21:42:11 ----D---- C:\Windows\system32\de-DE
2010-09-02 21:42:11 ----D---- C:\Windows\system32\cs-CZ
2010-09-02 21:42:11 ----D---- C:\Windows\system32\AdvancedInstallers
2010-09-02 21:42:10 ----D---- C:\Windows\system32\zh-TW
2010-09-02 21:42:10 ----D---- C:\Windows\system32\zh-CN
2010-09-02 21:42:10 ----D---- C:\Windows\system32\wbem
2010-09-02 21:42:10 ----D---- C:\Windows\system32\uk-UA
2010-09-02 21:42:10 ----D---- C:\Windows\system32\tr-TR
2010-09-02 21:42:10 ----D---- C:\Windows\system32\th-TH
2010-09-02 21:42:10 ----D---- C:\Windows\system32\sr-Latn-CS
2010-09-02 21:42:10 ----D---- C:\Windows\system32\sl-SI
2010-09-02 21:42:10 ----D---- C:\Windows\system32\ro-RO
2010-09-02 21:42:10 ----D---- C:\Windows\system32\pl-PL
2010-09-02 21:42:10 ----D---- C:\Windows\system32\manifeststore
2010-09-02 21:42:10 ----D---- C:\Windows\system32\ja-JP
2010-09-02 21:42:10 ----D---- C:\Windows\system32\es-ES
2010-09-02 21:42:10 ----D---- C:\Windows\system32\en
2010-09-02 21:42:10 ----D---- C:\Windows\system32\drivers\en-US
2010-09-02 21:42:10 ----D---- C:\Windows\system32\drivers
2010-09-02 21:42:10 ----D---- C:\Windows\system32\bg-BG
2010-09-02 21:42:09 ----D---- C:\Windows\system32\pt-BR
2010-09-02 21:42:09 ----D---- C:\Windows\system32\nl-NL
2010-09-02 21:42:09 ----D---- C:\Windows\system32\nb-NO
2010-09-02 21:42:09 ----D---- C:\Windows\system32\migwiz
2010-09-02 21:42:09 ----D---- C:\Windows\system32\lt-LT
2010-09-02 21:42:09 ----D---- C:\Windows\system32\ar-SA
2010-09-02 21:41:59 ----RSD---- C:\Windows\Fonts
2010-09-02 21:41:59 ----D---- C:\Windows\AppPatch
2010-09-02 21:41:53 ----D---- C:\Windows\system32\Boot
2010-09-02 21:40:52 ----D---- C:\Windows\system32\drivers\UMDF
2010-09-02 21:40:35 ----D---- C:\Windows\system32\RTCOM
2010-09-02 21:32:04 ----D---- C:\Windows\winsxs
2010-09-02 21:30:39 ----A---- C:\Windows\fonts\GlobalUserInterface.CompositeFont
2010-09-02 21:25:36 ----SHD---- C:\System Volume Information
2010-09-02 17:32:14 ----D---- C:\Windows\Minidump
2010-09-02 07:16:05 ----SHD---- C:\Windows\Installer
2010-09-02 07:15:36 ----HD---- C:\ProgramData
2010-09-02 07:14:06 ----D---- C:\Program Files\Common Files
2010-09-02 06:25:22 ----D---- C:\Windows\system32\LogFiles
2010-09-02 05:46:41 ----D---- C:\Windows\system32\catroot2
2010-09-02 02:37:16 ----SD---- C:\ProgramData\Microsoft
2010-08-30 14:56:31 ----D---- C:\Windows\Tasks
2010-08-30 14:56:31 ----D---- C:\Windows\system32\spool
2010-08-30 14:56:31 ----D---- C:\Windows\system32\Msdtc
2010-08-30 14:56:31 ----D---- C:\Windows\registration
2010-08-30 14:47:48 ----SD---- C:\Users\Kerry Dunne\AppData\Roaming\Microsoft
2010-08-28 12:19:48 ----D---- C:\ProgramData\Microsoft Help
2010-08-27 09:36:04 ----D---- C:\Windows\system32\Tasks
2010-08-27 09:34:23 ----D---- C:\Program Files\Common Files\microsoft shared
2010-08-27 09:33:30 ----D---- C:\Program Files\Microsoft Office
2010-08-27 09:30:51 ----D---- C:\Windows\SHELLNEW
2010-08-27 00:39:48 ----SD---- C:\Windows\Downloaded Program Files
2010-08-24 16:13:30 ----SHD---- C:\$Recycle.Bin
2010-08-16 22:53:13 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-16 22:48:27 ----D---- C:\Program Files\Common Files\Adobe
2010-08-16 22:38:33 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Azureus
2010-08-13 13:45:10 ----D---- C:\Program Files\Microsoft Works
2010-08-03 19:09:31 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS [2009-08-26 310320]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-30 13824]
R1 BHDrvx86;Symantec Heuristics Driver; C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys [2009-08-26 259632]
R1 ccHP;Symantec Hash Provider; C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys [2010-02-04 482432]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2010-01-12 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100224.002\IDSvix86.sys [2009-12-30 343088]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS [2009-08-26 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-08-26 25648]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS [2009-08-26 217136]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-17 11032]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-02-18 166960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-11-04 952320]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-01-12 102448]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-10-28 2476544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-02-11 2324512]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C60x86.sys [2009-01-15 49664]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2010-01-20 124976]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-26 1044984]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2008-12-13 102784]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2008-12-30 103040]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100225.048\NAVENG.SYS [2010-02-03 84912]
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100225.048\NAVEX15.SYS [2010-02-03 1324720]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-02-23 62976]
S3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS [2009-08-26 308272]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 SYMDNS;SYMDNS; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS []
S3 SYMFW;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMFW.SYS [2009-08-26 89904]
S3 SYMNDISV;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMNDISV.SYS [2009-08-26 48688]
S3 SYMREDRV;SYMREDRV; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-05-12 611664]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [2009-04-03 723488]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-30 135664]
S3 GameConsoleService;GameConsoleService; C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe [2008-05-05 165416]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-30 182768]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 ASKService;ASKService; C:\Program Files\AskBarDis\bar\bin\AskService.exe [2009-04-02 464264]
S4 ASKUpgrade;ASKUpgrade; C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
S4 dldt_device;dldt_device; C:\Windows\system32\dldtcoms.exe [2008-02-25 595184]
S4 dldtCATSCustConnectService;dldtCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\dldtserv.exe [2008-02-25 99568]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 Norton Internet Security;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2009-08-26 117640]
-----------------EOF-----------------
Logfile of random's system information tool 1.08 (written by random/random)
Run by Kerry Dunne at 2010-09-02 23:06:43
Microsoft® Windows Vista™ Home Basic Service Pack 2
System drive C: has 102 GB (72%) free of 142 GB
Total RAM: 3001 MB (66% free)
HijackThis download failed
======Scheduled tasks folder======
C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3768133199-3547387650-2985043688-1000Core.job
C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3768133199-3547387650-2985043688-1000UA.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2008-06-11 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{201f27d4-3704-41d6-89c1-aa35e39143ed}]
AskBar BHO - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}]
Symantec NCO BHO - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2009-08-26 378736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}]
Symantec Intrusion Prevention - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\IPSBHO.DLL [2009-08-26 107896]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live Sign-in Helper - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-02-17 408440]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-28 256112]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll [2010-01-29 764912]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B4F3A835-0E21-4959-BA22-42B3008E02FF}]
Office Document Cache Handler - C:\PROGRA~1\MICROS~2\Office14\URLREDIR.DLL [2010-02-28 561552]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_B7C5AC242193BB3E.dll [2009-12-28 458736]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2010-01-20 41760]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - Norton Toolbar - C:\Program Files\Norton Internet Security\Engine\16.8.0.41\coIEPlg.dll [2009-08-26 378736]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2009-12-28 256112]
{3041d03e-fd4b-44e0-b742-2d9b88305f98} - Ask Toolbar - C:\Program Files\AskBarDis\bar\bin\askBar.dll [2009-04-02 333192]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"NPSStartup"= []
"Windows Defender"=C:\Program Files\Windows Defender\MSASCui.exe [2008-01-21 1008184]
"WarReg_PopUp"=C:\Program Files\eMachines\WR_PopUp\WarReg_PopUp.exe [2008-11-04 57344]
"SunJavaUpdateSched"=C:\Program Files\Common Files\Java\Java Update\jusched.exe [2010-01-11 246504]
"RtHDVCpl"=C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [2009-02-11 6724128]
"Persistence"=C:\Windows\system32\igfxpers.exe [2008-11-05 154136]
"LManager"=C:\PROGRA~1\LAUNCH~1\LManager.exe [2009-02-12 862728]
"IgfxTray"=C:\Windows\system32\igfxtray.exe [2008-11-05 150040]
"HotKeysCmds"=C:\Windows\system32\hkcmd.exe [2008-11-05 178712]
"Google Desktop Search"=C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192]
"Apoint"=C:\Program Files\Apoint2K\Apoint.exe [2007-07-21 159744]
"Adobe Reader Speed Launcher"=C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [2008-06-12 34672]
"Acer ePower Management"=C:\Program Files\eMachines\eMachines Power Management\ePowerTray.exe [2009-04-03 698912]
"Skytel"=C:\Program Files\Realtek\Audio\HDA\Skytel.exe [2009-02-11 1833504]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"WMPNSCFG"=C:\Program Files\Windows Media Player\WMPNSCFG.exe [2008-01-21 202240]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2009-12-28 68856]
"Skype"=C:\Program Files\Skype\Phone\Skype.exe [2010-03-09 26100520]
"Google Update"=C:\Users\Kerry Dunne\AppData\Local\Google\Update\GoogleUpdate.exe [2009-12-30 135664]
"AutoStartNPSAgent"=C:\Program Files\Samsung\Samsung New PC Studio\NPSAgent.exe [2009-04-02 102400]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\12CFG214-K641-12SF-N85P]
C:\RECYCLER\S-1-5-21-0243936033-3052116371-381863308-1811\vsbntlo.exe []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\avast5]
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui []
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtamon]
C:\Program Files\Dell V305\dldtamon.exe [2008-06-24 16624]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\dldtmon.exe]
C:\Program Files\Dell V305\dldtmon.exe [2008-06-24 668912]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\txnnjgma]
C:\Users\Kerry Dunne\AppData\Local\lgppigpvg\bmkpcvhshdw.exe []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"="C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui]
C:\Windows\system32\igfxdev.dll [2008-10-28 221184]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\aawservice]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\SymEFA.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\Wdf01000.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfPf]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfRd]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\WudfUsbccidDriver]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
"EnableUIADesktopToggle"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"BindDirectlyToPropertySetStorage"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======List of files/folders created in the last 1 months======
2010-09-02 23:06:43 ----D---- C:\rsit
2010-09-02 23:06:43 ----D---- C:\Program Files\trend micro
2010-09-02 23:06:24 ----D---- C:\Antivir
2010-09-02 21:41:53 ----D---- C:\Windows\system32\vi-VN
2010-09-02 21:41:53 ----D---- C:\Windows\system32\eu-ES
2010-09-02 21:41:53 ----D---- C:\Windows\system32\ca-ES
2010-09-02 17:40:31 ----ASH---- C:\hiberfil.sys
2010-09-02 07:15:36 ----D---- C:\ProgramData\Lavasoft
2010-09-02 07:15:36 ----D---- C:\Program Files\Lavasoft
2010-09-02 07:14:06 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2010-09-02 06:35:00 ----D---- C:\Windows\system32\EventProviders
2010-09-02 03:25:33 ----D---- C:\Windows\pss
2010-09-02 03:16:51 ----D---- C:\prac
2010-09-02 02:59:10 ----D---- C:\ProgramData\Alwil Software
2010-09-02 02:59:10 ----D---- C:\Program Files\Alwil Software
2010-08-30 14:26:10 ----A---- C:\Windows\system32\drivers\ltjgdmbd.sys
2010-08-30 14:23:41 ----D---- C:\RECYCLER
2010-08-30 14:22:27 ----RSH---- C:\Users\Kerry Dunne\AppData\Roaming\ohydy.exe
2010-08-30 14:22:08 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\5E170330394A038E71BCC34714A0F947
2010-08-28 01:01:13 ----A---- C:\Windows\ntbtlog.txt
2010-08-27 09:33:39 ----D---- C:\Program Files\Common Files\DESIGNER
2010-08-27 09:30:50 ----D---- C:\Program Files\Microsoft Analysis Services
2010-08-27 00:42:19 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Template
2010-08-17 02:05:37 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\PC Suite
2010-08-17 02:05:37 ----D---- C:\ProgramData\PC Suite
2010-08-16 23:05:30 ----A---- C:\Windows\system32\nmwcdcls.dll
2010-08-16 23:05:25 ----D---- C:\Program Files\DIFX
2010-08-16 23:05:23 ----A---- C:\Windows\system32\drivers\pccsmcfd.sys
2010-08-16 23:05:21 ----DC---- C:\Windows\system32\DRVSTORE
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bwhnt.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bwh.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bmdm.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bmdfl.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bcmnt.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bcm.sys
2010-08-16 23:04:58 ----A---- C:\Windows\system32\drivers\ss_bbus.sys
2010-08-16 23:04:29 ----D---- C:\Windows\system32\Samsung_USB_Drivers
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExService.Exe
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExDisk.Sys
2010-08-16 22:54:04 ----A---- C:\Windows\system32\FsUsbExDevice.Dll
2010-08-16 22:53:31 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Samsung
2010-08-16 22:52:35 ----D---- C:\Program Files\MarkAny
2010-08-16 22:52:33 ----D---- C:\Program Files\PC Connectivity Solution
2010-08-16 22:51:52 ----D---- C:\Program Files\Samsung
2010-08-12 16:25:07 ----A---- C:\Windows\system32\drivers\tcpip.sys
2010-08-12 16:22:48 ----A---- C:\Windows\system32\iccvid.dll
2010-08-12 16:22:44 ----A---- C:\Windows\system32\ieapfltr.dll
2010-08-12 16:22:43 ----A---- C:\Windows\system32\mshtml.dll
2010-08-12 16:22:41 ----A---- C:\Windows\system32\urlmon.dll
2010-08-12 16:22:41 ----A---- C:\Windows\system32\ieframe.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\wininet.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\mshtmled.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\iepeers.dll
2010-08-12 16:22:40 ----A---- C:\Windows\system32\ieencode.dll
2010-08-12 16:22:11 ----A---- C:\Windows\system32\schannel.dll
2010-08-12 16:20:21 ----A---- C:\Windows\system32\win32k.sys
2010-08-12 16:20:16 ----A---- C:\Windows\system32\rtutils.dll
2010-08-12 16:20:11 ----A---- C:\Windows\system32\ntkrnlpa.exe
2010-08-12 16:20:10 ----A---- C:\Windows\system32\ntoskrnl.exe
2010-08-12 02:43:07 ----A---- C:\Windows\system32\msxml3.dll
2010-08-12 02:43:05 ----A---- C:\Windows\system32\drivers\srv2.sys
2010-08-12 02:43:05 ----A---- C:\Windows\system32\drivers\srv.sys
2010-08-04 14:06:34 ----A---- C:\Windows\system32\shell32.dll
======List of files/folders modified in the last 1 months======
2010-09-02 23:06:43 ----RD---- C:\Program Files
2010-09-02 23:06:37 ----D---- C:\Windows\Temp
2010-09-02 23:06:35 ----D---- C:\Windows\Prefetch
2010-09-02 23:05:42 ----D---- C:\Windows\System32
2010-09-02 23:05:42 ----D---- C:\Windows\inf
2010-09-02 23:05:42 ----A---- C:\Windows\system32\PerfStringBackup.INI
2010-09-02 22:12:17 ----D---- C:\Windows\rescache
2010-09-02 22:06:58 ----D---- C:\Windows\Microsoft.NET
2010-09-02 22:06:31 ----RSD---- C:\Windows\assembly
2010-09-02 21:53:39 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Skype
2010-09-02 21:47:50 ----D---- C:\Windows
2010-09-02 21:47:34 ----SHD---- C:\Boot
2010-09-02 21:47:21 ----D---- C:\Windows\system32\catroot
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Sidebar
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Photo Gallery
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Media Player
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Mail
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Collaboration
2010-09-02 21:42:19 ----D---- C:\Program Files\Windows Calendar
2010-09-02 21:42:19 ----D---- C:\Program Files\Movie Maker
2010-09-02 21:42:19 ----D---- C:\Program Files\Internet Explorer
2010-09-02 21:42:19 ----D---- C:\Program Files\Common Files\System
2010-09-02 21:42:18 ----D---- C:\Windows\servicing
2010-09-02 21:42:18 ----D---- C:\Program Files\Windows Defender
2010-09-02 21:42:17 ----D---- C:\Windows\system32\XPSViewer
2010-09-02 21:42:17 ----D---- C:\Windows\system32\sk-SK
2010-09-02 21:42:17 ----D---- C:\Windows\system32\lv-LV
2010-09-02 21:42:17 ----D---- C:\Windows\system32\ko-KR
2010-09-02 21:42:17 ----D---- C:\Windows\system32\hr-HR
2010-09-02 21:42:17 ----D---- C:\Windows\system32\et-EE
2010-09-02 21:42:17 ----D---- C:\Windows\system32\da-DK
2010-09-02 21:42:17 ----D---- C:\Windows\IME
2010-09-02 21:42:16 ----D---- C:\Windows\system32\en-US
2010-09-02 21:42:11 ----D---- C:\Windows\system32\sv-SE
2010-09-02 21:42:11 ----D---- C:\Windows\system32\SLUI
2010-09-02 21:42:11 ----D---- C:\Windows\system32\setup
2010-09-02 21:42:11 ----D---- C:\Windows\system32\ru-RU
2010-09-02 21:42:11 ----D---- C:\Windows\system32\pt-PT
2010-09-02 21:42:11 ----D---- C:\Windows\system32\oobe
2010-09-02 21:42:11 ----D---- C:\Windows\system32\migration
2010-09-02 21:42:11 ----D---- C:\Windows\system32\it-IT
2010-09-02 21:42:11 ----D---- C:\Windows\system32\hu-HU
2010-09-02 21:42:11 ----D---- C:\Windows\system32\he-IL
2010-09-02 21:42:11 ----D---- C:\Windows\system32\fr-FR
2010-09-02 21:42:11 ----D---- C:\Windows\system32\fi-FI
2010-09-02 21:42:11 ----D---- C:\Windows\system32\el-GR
2010-09-02 21:42:11 ----D---- C:\Windows\system32\de-DE
2010-09-02 21:42:11 ----D---- C:\Windows\system32\cs-CZ
2010-09-02 21:42:11 ----D---- C:\Windows\system32\AdvancedInstallers
2010-09-02 21:42:10 ----D---- C:\Windows\system32\zh-TW
2010-09-02 21:42:10 ----D---- C:\Windows\system32\zh-CN
2010-09-02 21:42:10 ----D---- C:\Windows\system32\wbem
2010-09-02 21:42:10 ----D---- C:\Windows\system32\uk-UA
2010-09-02 21:42:10 ----D---- C:\Windows\system32\tr-TR
2010-09-02 21:42:10 ----D---- C:\Windows\system32\th-TH
2010-09-02 21:42:10 ----D---- C:\Windows\system32\sr-Latn-CS
2010-09-02 21:42:10 ----D---- C:\Windows\system32\sl-SI
2010-09-02 21:42:10 ----D---- C:\Windows\system32\ro-RO
2010-09-02 21:42:10 ----D---- C:\Windows\system32\pl-PL
2010-09-02 21:42:10 ----D---- C:\Windows\system32\manifeststore
2010-09-02 21:42:10 ----D---- C:\Windows\system32\ja-JP
2010-09-02 21:42:10 ----D---- C:\Windows\system32\es-ES
2010-09-02 21:42:10 ----D---- C:\Windows\system32\en
2010-09-02 21:42:10 ----D---- C:\Windows\system32\drivers\en-US
2010-09-02 21:42:10 ----D---- C:\Windows\system32\drivers
2010-09-02 21:42:10 ----D---- C:\Windows\system32\bg-BG
2010-09-02 21:42:09 ----D---- C:\Windows\system32\pt-BR
2010-09-02 21:42:09 ----D---- C:\Windows\system32\nl-NL
2010-09-02 21:42:09 ----D---- C:\Windows\system32\nb-NO
2010-09-02 21:42:09 ----D---- C:\Windows\system32\migwiz
2010-09-02 21:42:09 ----D---- C:\Windows\system32\lt-LT
2010-09-02 21:42:09 ----D---- C:\Windows\system32\ar-SA
2010-09-02 21:41:59 ----RSD---- C:\Windows\Fonts
2010-09-02 21:41:59 ----D---- C:\Windows\AppPatch
2010-09-02 21:41:53 ----D---- C:\Windows\system32\Boot
2010-09-02 21:40:52 ----D---- C:\Windows\system32\drivers\UMDF
2010-09-02 21:40:35 ----D---- C:\Windows\system32\RTCOM
2010-09-02 21:32:04 ----D---- C:\Windows\winsxs
2010-09-02 21:30:39 ----A---- C:\Windows\fonts\GlobalUserInterface.CompositeFont
2010-09-02 21:25:36 ----SHD---- C:\System Volume Information
2010-09-02 17:32:14 ----D---- C:\Windows\Minidump
2010-09-02 07:16:05 ----SHD---- C:\Windows\Installer
2010-09-02 07:15:36 ----HD---- C:\ProgramData
2010-09-02 07:14:06 ----D---- C:\Program Files\Common Files
2010-09-02 06:25:22 ----D---- C:\Windows\system32\LogFiles
2010-09-02 05:46:41 ----D---- C:\Windows\system32\catroot2
2010-09-02 02:37:16 ----SD---- C:\ProgramData\Microsoft
2010-08-30 14:56:31 ----D---- C:\Windows\Tasks
2010-08-30 14:56:31 ----D---- C:\Windows\system32\spool
2010-08-30 14:56:31 ----D---- C:\Windows\system32\Msdtc
2010-08-30 14:56:31 ----D---- C:\Windows\registration
2010-08-30 14:47:48 ----SD---- C:\Users\Kerry Dunne\AppData\Roaming\Microsoft
2010-08-28 12:19:48 ----D---- C:\ProgramData\Microsoft Help
2010-08-27 09:36:04 ----D---- C:\Windows\system32\Tasks
2010-08-27 09:34:23 ----D---- C:\Program Files\Common Files\microsoft shared
2010-08-27 09:33:30 ----D---- C:\Program Files\Microsoft Office
2010-08-27 09:30:51 ----D---- C:\Windows\SHELLNEW
2010-08-27 00:39:48 ----SD---- C:\Windows\Downloaded Program Files
2010-08-24 16:13:30 ----SHD---- C:\$Recycle.Bin
2010-08-16 22:53:13 ----HD---- C:\Program Files\InstallShield Installation Information
2010-08-16 22:48:27 ----D---- C:\Program Files\Common Files\Adobe
2010-08-16 22:38:33 ----D---- C:\Users\Kerry Dunne\AppData\Roaming\Azureus
2010-08-13 13:45:10 ----D---- C:\Program Files\Microsoft Works
2010-08-03 19:09:31 ----A---- C:\Windows\system32\mrt.exe
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 SymEFA;Symantec Extended File Attributes; C:\Windows\system32\drivers\NIS\1008000.029\SYMEFA.SYS [2009-08-26 310320]
R0 UBHelper;UBHelper; C:\Windows\system32\drivers\UBHelper.sys [2008-01-30 13824]
R1 BHDrvx86;Symantec Heuristics Driver; C:\Windows\System32\Drivers\NIS\1008000.029\BHDrvx86.sys [2009-08-26 259632]
R1 ccHP;Symantec Hash Provider; C:\Windows\System32\Drivers\NIS\1008000.029\ccHPx86.sys [2010-02-04 482432]
R1 DritekPortIO;Dritek General Port I/O; \??\C:\PROGRA~1\LAUNCH~1\DPortIO.sys [2006-11-02 20112]
R1 eeCtrl;Symantec Eraser Control driver; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [2010-01-12 371248]
R1 IDSVix86;IDSVix86; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\ipsdefs\20100224.002\IDSvix86.sys [2009-12-30 343088]
R1 SRTSPX;Symantec Real Time Storage Protection (PEL); C:\Windows\system32\drivers\NIS\1008000.029\SRTSPX.SYS [2009-08-26 43696]
R1 SymIM;Symantec Network Security Intermediate Filter Driver; C:\Windows\system32\DRIVERS\SymIMv.sys [2009-08-26 25648]
R1 SYMTDI;Symantec Network Dispatch Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMTDI.SYS [2009-08-26 217136]
R2 regi;regi; C:\Windows\system32\drivers\regi.sys [2007-04-17 11032]
R3 ApfiltrService;Alps Pointing-device Filter Driver; C:\Windows\system32\DRIVERS\Apfiltr.sys [2008-02-18 166960]
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athr.sys [2008-11-04 952320]
R3 DKbFltr;Dritek Keyboard Filter Driver; C:\Windows\system32\DRIVERS\DKbFltr.sys [2006-11-02 21264]
R3 EraserUtilRebootDrv;EraserUtilRebootDrv; \??\C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-01-12 102448]
R3 FsUsbExDisk;FsUsbExDisk; \??\C:\Windows\system32\FsUsbExDisk.SYS [2009-03-31 36608]
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd32.sys [2008-10-28 2476544]
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHDA.sys [2009-02-11 2324512]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller; C:\Windows\system32\DRIVERS\L1C60x86.sys [2009-01-15 49664]
R3 NTIDrvr;Upper Class Filter Driver; C:\Windows\system32\DRIVERS\NTIDrvr.sys [2008-01-30 14848]
R3 SymEvent;SymEvent; \??\C:\Windows\system32\Drivers\SYMEVENT.SYS [2010-01-20 124976]
R3 WUDFRd;WUDFRd; C:\Windows\system32\DRIVERS\WUDFRd.sys [2008-01-21 83328]
S3 BCM43XX;Broadcom 802.11 Network Adapter Driver; C:\Windows\system32\DRIVERS\bcmwl6.sys [2007-10-26 1044984]
S3 drmkaud;Microsoft Kernel DRM Audio Descrambler; C:\Windows\system32\drivers\drmkaud.sys [2008-01-21 5632]
S3 HdAudAddService;Microsoft 1.1 UAA Function Driver for High Definition Audio Service; C:\Windows\system32\drivers\HdAudio.sys [2006-11-02 235520]
S3 hwdatacard;Huawei DataCard USB Modem and USB Serial; C:\Windows\system32\DRIVERS\ewusbmdm.sys [2008-12-13 102784]
S3 hwusbfake;Huawei DataCard USB Fake; C:\Windows\system32\DRIVERS\ewusbfake.sys [2008-12-30 103040]
S3 MSKSSRV;Microsoft Streaming Service Proxy; C:\Windows\system32\drivers\MSKSSRV.sys [2008-01-21 8192]
S3 MSPCLOCK;Microsoft Streaming Clock Proxy; C:\Windows\system32\drivers\MSPCLOCK.sys [2008-01-21 5888]
S3 MSPQM;Microsoft Streaming Quality Manager Proxy; C:\Windows\system32\drivers\MSPQM.sys [2008-01-21 5504]
S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\Windows\system32\drivers\MSTEE.sys [2008-01-21 6016]
S3 NAVENG;NAVENG; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100225.048\NAVENG.SYS [2010-02-03 84912]
S3 NAVEX15;NAVEX15; \??\C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\Norton\Definitions\VirusDefs\20100225.048\NAVEX15.SYS [2010-02-03 1324720]
S3 pccsmcfd;PCCS Mode Change Filter Driver; C:\Windows\system32\DRIVERS\pccsmcfd.sys [2007-09-17 21632]
S3 RTSTOR;Realtek USB 2.0 Card Reader; C:\Windows\system32\drivers\RTSTOR.SYS [2009-02-23 62976]
S3 SRTSP;Symantec Real Time Storage Protection; C:\Windows\System32\Drivers\NIS\1008000.029\SRTSP.SYS [2009-08-26 308272]
S3 ss_bbus;SAMSUNG USB Mobile Device (WDM); C:\Windows\system32\DRIVERS\ss_bbus.sys [2009-03-20 90112]
S3 ss_bmdfl;SAMSUNG USB Mobile Modem (Filter); C:\Windows\system32\DRIVERS\ss_bmdfl.sys [2009-03-20 14976]
S3 ss_bmdm;SAMSUNG USB Mobile Modem; C:\Windows\system32\DRIVERS\ss_bmdm.sys [2009-03-20 121856]
S3 SYMDNS;SYMDNS; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMDNS.SYS []
S3 SYMFW;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMFW.SYS [2009-08-26 89904]
S3 SYMNDISV;Symantec Network Filter Driver; C:\Windows\System32\Drivers\NIS\1008000.029\SYMNDISV.SYS [2009-08-26 48688]
S3 SYMREDRV;SYMREDRV; \??\C:\Windows\system32\drivers\NIS\1000000.07D\SYMREDRV.SYS []
S3 usbscan;USB Scanner Driver; C:\Windows\system32\DRIVERS\usbscan.sys [2008-01-21 35328]
S4 ErrDev;Microsoft Hardware Error Device Driver; C:\Windows\system32\drivers\errdev.sys [2008-01-21 6656]
S4 MegaSR;MegaSR; C:\Windows\system32\drivers\megasr.sys [2008-01-21 386616]
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 aawservice;Lavasoft Ad-Aware Service; C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe [2008-05-12 611664]
R2 BcmSqlStartupSvc;Business Contact Manager SQL Server Startup Service; C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe [2008-01-11 30312]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\eMachines\eMachines Power Management\ePowerSvc.exe [2009-04-03 723488]
R2 FsUsbExService;FsUsbExService; C:\Windows\system32\FsUsbExService.Exe [2009-03-31 233472]
R2 IviRegMgr;IviRegMgr; C:\Program Files\Common Files\InterVideo\RegMgr\iviRegMgr.exe [2007-01-04 112152]
R2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [2008-09-23 144632]
R2 SQLBrowser;SQL Server Browser; c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe [2008-11-24 239968]
R2 SQLWriter;SQL Server VSS Writer; c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe [2008-11-24 87904]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 gupdate;Google Update Service (gupdate); C:\Program Files\Google\Update\GoogleUpdate.exe [2009-12-30 135664]
S3 GameConsoleService;GameConsoleService; C:\Program Files\eMachines Games\eMachines Game Console\GameConsoleService.exe [2008-05-05 165416]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [2010-07-28 30192]
S3 gusvc;Google Software Updater; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-12-30 182768]
S3 MSSQL$MSSMLBIZ;SQL Server (MSSMLBIZ); c:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [2009-05-27 29262680]
S3 NTIBackupSvc;NTI Backup Now 5 Backup Service; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [2008-09-23 50424]
S3 odserv;Microsoft Office Diagnostics Service; C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE [2008-11-04 441712]
S3 ose;Office Source Engine; C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [2010-01-09 149352]
S3 osppsvc;Office Software Protection Platform; C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-09 4640000]
S3 ServiceLayer;ServiceLayer; C:\Program Files\PC Connectivity Solution\ServiceLayer.exe [2008-04-07 430592]
S3 WPFFontCache_v0400;@C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe,-100; C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S4 ASKService;ASKService; C:\Program Files\AskBarDis\bar\bin\AskService.exe [2009-04-02 464264]
S4 ASKUpgrade;ASKUpgrade; C:\Program Files\AskBarDis\bar\bin\ASKUpgrade.exe [2009-04-02 234888]
S4 dldt_device;dldt_device; C:\Windows\system32\dldtcoms.exe [2008-02-25 595184]
S4 dldtCATSCustConnectService;dldtCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\W32X86\3\\dldtserv.exe [2008-02-25 99568]
S4 MSSQLServerADHelper;SQL Server Active Directory Helper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [2008-11-24 45408]
S4 Norton Internet Security;Norton Internet Security; C:\Program Files\Norton Internet Security\Engine\16.8.0.41\ccSvcHst.exe [2009-08-26 117640]
-----------------EOF-----------------