Logfile of random's system information tool 1.08 (written by random/random)
Run by Renegade at 2011-03-22 19:43:05
Microsoft Windows 7 Home Premium
System drive C: has 110 GB (49%) free of 225 GB
Total RAM: 2807 MB (66% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 19:43:14, on 22/03/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16722)
Boot mode: Normal
Running processes:
C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe
C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe
C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe
C:\Program Files (x86)\Launch Manager\LManager.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Launch Manager\LMworker.exe
C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe
C:\Program Files (x86)\Last.fm\LastFM.exe
C:\Users\Renegade\Desktop\RSIT.exe
C:\Program Files (x86)\trend micro\Renegade.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://home.mywebsearch.com/index.jhtml?n=77C09F4F&ptnrS=ZNxpt735YYGB&ptb=hAyASS5A19U4S.uJusP7sg
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://acer.msn.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\progra~1\mcafee\msk\mskapbho.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110319225853.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [SuiteTray] "C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe"
O4 - HKLM\..\Run: [EgisUpdate] "C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe" -d
O4 - HKLM\..\Run: [EgisTecPMMUpdate] "C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe" -h -k
O4 - HKLM\..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Google] C:\Users\Renegade\AppData\Roaming\GD.exe
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: Dritek WMI Service (DsiWMIService) - Dritek System Inc. - C:\Program Files (x86)\Launch Manager\dsiwmis.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: GREGService - Acer Incorporated - C:\Program Files (x86)\Acer\Registration\GREGsvc.exe
O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\mcafee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe
O23 - Service: McShield - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NTI IScheduleSvc - NewTech Infosystems, Inc. - C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management & Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: Updater Service - Acer Group - C:\Program Files\Acer\Acer Updater\UpdaterService.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
--
End of file - 10544 bytes
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}]
Adobe PDF Link Helper - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{27B4851A-3207-45A2-B947-BE8AFE6163AB}]
McAfee Phishing Filter - c:\progra~1\mcafee\msk\mskapbho.dll [2010-11-25 238056]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}]
scriptproxy - C:\Program Files (x86)\Common Files\McAfee\SystemCore\ScriptSn.20110319225853.dll [2010-10-13 73288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}]
Windows Live ID Sign-in Helper - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2010-09-21 439168]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}]
McAfee SiteAdvisor BHO - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2010-02-01 251416]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll [2010-02-01 251416]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"=C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [2010-04-13 284696]
"mcui_exe"=C:\Program Files\McAfee.com\Agent\mcagent.exe [2011-01-17 1484856]
"SuiteTray"=C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [2010-05-27 337264]
"EgisUpdate"=C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [2010-03-11 201584]
"EgisTecPMMUpdate"=C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [2010-03-11 407920]
"Adobe Reader Speed Launcher"=C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-28 35696]
"BackupManagerTray"=C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [2010-06-28 265984]
"LManager"=C:\Program Files (x86)\Launch Manager\LManager.exe [2010-08-10 975952]
"QuickTime Task"=C:\Program Files (x86)\QuickTime\QTTask.exe [2010-11-29 421888]
"iTunesHelper"=C:\Program Files (x86)\iTunes\iTunesHelper.exe [2011-03-07 421160]
"Google"=C:\Users\Renegade\AppData\Roaming\GD.exe [2011-03-04 28672]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad]
WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - C:\Windows\SysWow64\webcheck.dll [2009-07-14 229376]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"= []
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"=credssp.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\AFD]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\McMPFSvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefire]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfefirek.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfehidk.sys]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mfevtp]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"ConsentPromptBehaviorAdmin"=5
"ConsentPromptBehaviorUser"=3
"EnableUIADesktopToggle"=0
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDrives"=0
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
======File associations======
.js - edit - C:\Windows\System32\Notepad.exe %1
======List of files/folders created in the last 1 months======
2011-03-22 19:43:05 ----D---- C:\rsit
2011-03-22 17:59:49 ----A---- C:\ComboFix.txt
2011-03-22 17:56:01 ----SHD---- C:\$RECYCLE.BIN
2011-03-22 17:48:46 ----A---- C:\Windows\zip.exe
2011-03-22 17:48:46 ----A---- C:\Windows\SWSC.exe
2011-03-22 17:48:46 ----A---- C:\Windows\SWREG.exe
2011-03-22 17:48:46 ----A---- C:\Windows\sed.exe
2011-03-22 17:48:46 ----A---- C:\Windows\PEV.exe
2011-03-22 17:48:46 ----A---- C:\Windows\NIRCMD.exe
2011-03-22 17:48:46 ----A---- C:\Windows\MBR.exe
2011-03-22 17:48:46 ----A---- C:\Windows\grep.exe
2011-03-22 17:48:40 ----D---- C:\Windows\ERDNT
2011-03-22 17:48:29 ----D---- C:\Qoobox
2011-03-22 17:48:12 ----A---- C:\Windows\SWXCACLS.exe
2011-03-22 17:48:10 ----D---- C:\32788R22FWJFW
2011-03-21 20:13:46 ----D---- C:\Program Files (x86)\Trend Micro
2011-03-21 18:18:43 ----D---- C:\Windows\en
2011-03-21 18:16:13 ----A---- C:\Windows\SysWOW64\XAudio2_5.dll
2011-03-21 18:16:13 ----A---- C:\Windows\SysWOW64\XAPOFX1_3.dll
2011-03-21 18:16:13 ----A---- C:\Windows\SysWOW64\d3dx10_42.dll
2011-03-21 18:09:20 ----D---- C:\Windows\SysWOW64\Wat
2011-03-21 17:45:28 ----D---- C:\Program Files (x86)\Microsoft.NET
2011-03-21 00:59:15 ----A---- C:\Windows\SysWOW64\wcncsvc.dll
2011-03-21 00:54:55 ----A---- C:\Windows\SysWOW64\PresentationHostProxy.dll
2011-03-21 00:54:54 ----A---- C:\Windows\SysWOW64\PresentationHost.exe
2011-03-21 00:54:54 ----A---- C:\Windows\SysWOW64\netfxperf.dll
2011-03-21 00:54:54 ----A---- C:\Windows\SysWOW64\mscoree.dll
2011-03-21 00:54:54 ----A---- C:\Windows\SysWOW64\dfshim.dll
2011-03-20 11:18:28 ----D---- C:\Program Files (x86)\Free Window Registry Repair
2011-03-20 09:57:26 ----A---- C:\Windows\SysWOW64\mshtml.dll
2011-03-20 09:57:22 ----A---- C:\Windows\SysWOW64\iertutil.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\mstime.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\msfeedsbs.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\msfeeds.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\licmgr10.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\iepeers.dll
2011-03-20 09:57:21 ----A---- C:\Windows\SysWOW64\iedkcs32.dll
2011-03-20 09:57:20 ----A---- C:\Windows\SysWOW64\mshtmled.dll
2011-03-20 09:57:20 ----A---- C:\Windows\SysWOW64\msfeedssync.exe
2011-03-20 09:57:17 ----A---- C:\Windows\SysWOW64\kerberos.dll
2011-03-20 09:57:11 ----A---- C:\Windows\SysWOW64\tzres.dll
2011-03-20 09:56:58 ----A---- C:\Windows\SysWOW64\EncDec.dll
2011-03-20 09:56:58 ----A---- C:\Windows\SysWOW64\CPFilters.dll
2011-03-20 09:56:57 ----A---- C:\Windows\SysWOW64\sbe.dll
2011-03-20 09:56:56 ----A---- C:\Windows\SysWOW64\t2embed.dll
2011-03-20 09:56:53 ----A---- C:\Windows\SysWOW64\ole32.dll
2011-03-20 09:56:50 ----A---- C:\Windows\SysWOW64\taskschd.dll
2011-03-20 09:56:50 ----A---- C:\Windows\SysWOW64\taskeng.exe
2011-03-20 09:56:50 ----A---- C:\Windows\SysWOW64\taskcomp.dll
2011-03-20 09:56:50 ----A---- C:\Windows\SysWOW64\schtasks.exe
2011-03-20 09:56:48 ----A---- C:\Windows\SysWOW64\StructuredQuery.dll
2011-03-20 09:56:45 ----A---- C:\Windows\SysWOW64\inetcomm.dll
2011-03-20 09:56:35 ----A---- C:\Windows\SysWOW64\schannel.dll
2011-03-20 09:56:34 ----A---- C:\Windows\SysWOW64\comctl32.dll
2011-03-20 09:56:29 ----A---- C:\Windows\SysWOW64\ieframe.dll
2011-03-20 09:56:28 ----A---- C:\Windows\SysWOW64\wininet.dll
2011-03-20 09:56:28 ----A---- C:\Windows\SysWOW64\urlmon.dll
2011-03-20 09:56:28 ----A---- C:\Windows\SysWOW64\upnp.dll
2011-03-20 09:56:28 ----A---- C:\Windows\SysWOW64\msxml6.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\wscapi.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\winhttp.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\WebClnt.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\slwga.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\msxml3.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\jsproxy.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\ieui.dll
2011-03-20 09:56:27 ----A---- C:\Windows\SysWOW64\davclnt.dll
2011-03-20 09:56:25 ----A---- C:\Windows\SysWOW64\oleaut32.dll
2011-03-20 09:56:20 ----A---- C:\Windows\SysWOW64\XpsPrint.dll
2011-03-20 09:56:19 ----A---- C:\Windows\SysWOW64\XpsGdiConverter.dll
2011-03-20 09:56:14 ----A---- C:\Windows\SysWOW64\DWrite.dll
2011-03-20 09:56:14 ----A---- C:\Windows\SysWOW64\d3d10warp.dll
2011-03-20 09:56:14 ----A---- C:\Windows\SysWOW64\d2d1.dll
2011-03-20 09:56:13 ----A---- C:\Windows\SysWOW64\WMVDECOD.DLL
2011-03-20 09:56:13 ----A---- C:\Windows\SysWOW64\mfreadwrite.dll
2011-03-20 09:56:13 ----A---- C:\Windows\SysWOW64\mf.dll
2011-03-20 09:56:13 ----A---- C:\Windows\SysWOW64\ExplorerFrame.dll
2011-03-20 09:56:13 ----A---- C:\Windows\SysWOW64\d3d10_1core.dll
2011-03-20 09:56:12 ----A---- C:\Windows\SysWOW64\XpsRasterService.dll
2011-03-20 09:56:12 ----A---- C:\Windows\SysWOW64\d3d10_1.dll
2011-03-20 09:56:10 ----A---- C:\Windows\SysWOW64\webio.dll
2011-03-20 09:56:07 ----A---- C:\Windows\SysWOW64\vbscript.dll
2011-03-20 09:56:07 ----A---- C:\Windows\SysWOW64\jscript.dll
2011-03-20 09:55:59 ----A---- C:\Windows\SysWOW64\wmpmde.dll
2011-03-20 09:55:47 ----A---- C:\Windows\SysWOW64\ntoskrnl.exe
2011-03-20 09:55:47 ----A---- C:\Windows\SysWOW64\ntkrnlpa.exe
2011-03-20 09:55:47 ----A---- C:\Windows\SysWOW64\ntdll.dll
2011-03-20 09:55:43 ----A---- C:\Windows\SysWOW64\atmlib.dll
2011-03-20 09:55:43 ----A---- C:\Windows\SysWOW64\atmfd.dll
2011-03-20 09:55:41 ----A---- C:\Windows\SysWOW64\mfc40u.dll
2011-03-20 09:55:41 ----A---- C:\Windows\SysWOW64\mfc40.dll
2011-03-20 09:55:40 ----A---- C:\Windows\SysWOW64\mstscax.dll
2011-03-20 09:55:40 ----A---- C:\Windows\SysWOW64\mstsc.exe
2011-03-20 09:55:33 ----A---- C:\Windows\SysWOW64\wmp.dll
2011-03-20 09:55:32 ----A---- C:\Windows\SysWOW64\wmploc.DLL
2011-03-20 09:55:27 ----A---- C:\Windows\SysWOW64\odbc32.dll
2011-03-20 09:55:23 ----A---- C:\Windows\SysWOW64\sscore.dll
2011-03-20 00:05:14 ----D---- C:\ProgramData\Last.fm
2011-03-20 00:04:20 ----D---- C:\Program Files (x86)\Last.fm
2011-03-19 20:51:45 ----D---- C:\Users\Renegade\AppData\Roaming\DAEMON Tools Lite
2011-03-19 19:15:35 ----D---- C:\Program Files (x86)\uTorrent
2011-03-19 19:14:35 ----D---- C:\Users\Renegade\AppData\Roaming\uTorrent
2011-03-19 17:55:15 ----D---- C:\Users\Renegade\AppData\Roaming\Apple Computer
2011-03-19 17:55:06 ----A---- C:\Windows\SysWOW64\GEARAspi.dll
2011-03-19 17:54:43 ----D---- C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
2011-03-19 17:54:43 ----D---- C:\Program Files (x86)\iTunes
2011-03-19 17:53:57 ----D---- C:\Program Files (x86)\QuickTime
2011-03-19 17:53:56 ----D---- C:\ProgramData\Apple Computer
2011-03-19 17:53:39 ----D---- C:\Program Files (x86)\Apple Software Update
2011-03-19 17:53:12 ----D---- C:\Program Files (x86)\Bonjour
2011-03-19 17:53:05 ----D---- C:\ProgramData\Apple
2011-03-19 17:53:05 ----D---- C:\Program Files (x86)\Common Files\Apple
2011-03-19 17:11:25 ----D---- C:\Program Files (x86)\MSXML 4.0
2011-03-19 17:10:59 ----D---- C:\Program Files (x86)\Datel
2011-03-19 16:51:52 ----D---- C:\Users\Renegade\AppData\Roaming\Mozilla
2011-03-19 16:51:43 ----D---- C:\Program Files (x86)\Mozilla Firefox
2011-03-19 16:50:16 ----D---- C:\Users\Renegade\AppData\Roaming\Adobe
2011-03-19 16:34:40 ----D---- C:\Users\Renegade\AppData\Roaming\Intel Corporation
2011-03-19 16:34:26 ----D---- C:\Users\Renegade\AppData\Roaming\Macromedia
2011-03-19 16:33:59 ----D---- C:\Users\Renegade\AppData\Roaming\Identities
2011-03-19 16:32:07 ----SD---- C:\Users\Renegade\AppData\Roaming\Microsoft
2011-03-19 16:32:07 ----D---- C:\Users\Renegade\AppData\Roaming\Media Center Programs
2011-03-19 16:31:39 ----D---- C:\Recovery
2011-03-04 17:05:48 ----A---- C:\Users\Renegade\AppData\Roaming\GD.exe
======List of files/folders modified in the last 1 months======
2011-03-22 19:43:10 ----D---- C:\Windows\Temp
2011-03-22 18:52:58 ----A---- C:\Windows\SysWOW64\log.txt
2011-03-22 18:22:19 ----AD---- C:\ProgramData\Temp
2011-03-22 18:11:59 ----D---- C:\Program Files (x86)\Acer GameZone
2011-03-22 18:11:58 ----D---- C:\ProgramData
2011-03-22 18:07:10 ----RD---- C:\Program Files (x86)
2011-03-22 17:56:28 ----D---- C:\Windows\Prefetch
2011-03-22 17:55:47 ----D---- C:\Windows
2011-03-22 17:55:47 ----A---- C:\Windows\system.ini
2011-03-22 17:52:19 ----D---- C:\Windows\SysWOW64\drivers
2011-03-22 17:52:19 ----D---- C:\Windows\SysWOW64
2011-03-22 17:52:19 ----D---- C:\Windows\System32
2011-03-22 17:52:19 ----D---- C:\Windows\AppPatch
2011-03-22 17:52:16 ----D---- C:\Program Files (x86)\Common Files
2011-03-22 02:02:04 ----SHD---- C:\System Volume Information
2011-03-22 01:33:46 ----D---- C:\Windows\rescache
2011-03-22 01:32:40 ----D---- C:\Windows\Logs
2011-03-21 23:11:26 ----D---- C:\Program Files (x86)\Acer
2011-03-21 23:04:11 ----D---- C:\Windows\Microsoft.NET
2011-03-21 23:03:53 ----RSD---- C:\Windows\assembly
2011-03-21 21:45:08 ----D---- C:\Windows\inf
2011-03-21 18:27:44 ----D---- C:\Windows\winsxs
2011-03-21 18:25:48 ----D---- C:\Program Files (x86)\Internet Explorer
2011-03-21 18:25:46 ----D---- C:\Windows\SysWOW64\en-US
2011-03-21 18:25:44 ----D---- C:\Windows\ehome
2011-03-21 18:25:44 ----D---- C:\Program Files (x86)\Windows Mail
2011-03-21 18:25:42 ----D---- C:\Windows\SysWOW64\migration
2011-03-21 18:21:23 ----D---- C:\Windows\debug
2011-03-21 18:20:22 ----SHD---- C:\Windows\Installer
2011-03-21 18:18:02 ----D---- C:\Program Files (x86)\Windows Live
2011-03-21 18:17:06 ----SD---- C:\ProgramData\Microsoft
2011-03-21 18:16:42 ----RD---- C:\Program Files
2011-03-21 18:16:22 ----D---- C:\Program Files (x86)\Common Files\microsoft shared
2011-03-21 18:03:17 ----D---- C:\Program Files (x86)\Windows Media Player
2011-03-20 09:47:08 ----D---- C:\Program Files (x86)\Microsoft Silverlight
2011-03-19 17:00:08 ----D---- C:\Windows\Tasks
2011-03-19 16:45:40 ----HD---- C:\Program Files (x86)\InstallShield Installation Information
2011-03-19 16:44:56 ----D---- C:\ProgramData\McAfee
2011-03-19 16:34:25 ----D---- C:\ProgramData\oem
2011-03-19 16:33:49 ----D---- C:\OEM
2011-03-19 16:32:12 ----D---- C:\Program Files (x86)\McAfee
2011-03-19 16:31:46 ----RD---- C:\Users
2011-03-19 16:31:39 ----D---- C:\Windows\SoftwareDistribution
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R0 iaStor;Intel AHCI Controller; C:\Windows\system32\DRIVERS\iaStor.sys []
R0 mfehidk;McAfee Inc. mfehidk; C:\Windows\system32\drivers\mfehidk.sys []
R0 mfewfpk;McAfee Inc. mfewfpk; C:\Windows\system32\drivers\mfewfpk.sys []
R0 rdyboost;ReadyBoost; C:\Windows\System32\drivers\rdyboost.sys []
R1 mfenlfk;McAfee NDIS Light Filter; C:\Windows\system32\DRIVERS\mfenlfk.sys []
R1 mwlPSDFilter;mwlPSDFilter; C:\Windows\system32\DRIVERS\mwlPSDFilter.sys []
R1 mwlPSDNServ;mwlPSDNServ; C:\Windows\system32\DRIVERS\mwlPSDNServ.sys []
R1 mwlPSDVDisk;mwlPSDVDisk; C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys []
R1 vwififlt;Virtual WiFi Filter Driver; C:\Windows\system32\DRIVERS\vwififlt.sys []
R3 athr;Atheros Extensible Wireless LAN device driver; C:\Windows\system32\DRIVERS\athrx.sys []
R3 cfwids;McAfee Inc. cfwids; C:\Windows\system32\drivers\cfwids.sys []
R3 ETD;ELAN PS/2 Port Input Device; C:\Windows\system32\DRIVERS\ETD.sys []
R3 GEARAspiWDM;GEAR ASPI Filter Driver; C:\Windows\system32\DRIVERS\GEARAspiWDM.sys []
R3 HECIx64;Intel(R) Management Engine Interface; C:\Windows\system32\DRIVERS\HECIx64.sys []
R3 igfx;igfx; C:\Windows\system32\DRIVERS\igdkmd64.sys []
R3 Impcd;Impcd; C:\Windows\system32\DRIVERS\Impcd.sys []
R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\Windows\system32\drivers\RTKVHD64.sys []
R3 IntcDAud;Intel(R) Display Audio; C:\Windows\system32\DRIVERS\IntcDAud.sys []
R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0; C:\Windows\system32\DRIVERS\k57nd60a.sys []
R3 mfeapfk;McAfee Inc. mfeapfk; C:\Windows\system32\drivers\mfeapfk.sys []
R3 mfeavfk;McAfee Inc. mfeavfk; C:\Windows\system32\drivers\mfeavfk.sys []
R3 mfefirek;McAfee Inc. mfefirek; C:\Windows\system32\drivers\mfefirek.sys []
R3 NTIDrvr;NTIDrvr; \??\C:\Windows\system32\drivers\NTIDrvr.sys []
R3 UBHelper;UBHelper; \??\C:\Windows\system32\drivers\UBHelper.sys []
S3 catchme;catchme; \??\C:\Renegade123.exe\catchme.sys []
S3 mfeavfk01;McAfee Inc.; C:\Windows\SysWOW64\drivers\mfeavfk01.sys []
S3 mferkdet;McAfee Inc. mferkdet; C:\Windows\system32\drivers\mferkdet.sys []
S3 pciide;pciide; C:\Windows\system32\DRIVERS\pciide.sys []
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader; C:\Windows\System32\Drivers\RtsUStor.sys []
S3 usbio;usbio; C:\Windows\System32\Drivers\dsiarhwprog_x64.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 Apple Mobile Device;Apple Mobile Device; C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [2011-02-18 37664]
R2 Bonjour Service;Bonjour Service; C:\Program Files (x86)\Bonjour\mDNSResponder.exe [2010-10-07 345376]
R2 DsiWMIService;Dritek WMI Service; C:\Program Files (x86)\Launch Manager\dsiwmis.exe [2010-08-10 321104]
R2 ePowerSvc;Acer ePower Service; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [2010-06-11 868896]
R2 GREGService;GREGService; C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [2010-01-08 23584]
R2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology; C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [2010-04-13 13336]
R2 LMS;Intel(R) Management and Security Application Local Management Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe [2010-03-18 268824]
R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 McMPFSvc;McAfee Personal Firewall Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 mcmscsvc;McAfee Services; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 McNaiAnn;McAfee VirusScan Announcer; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 McNASvc;McAfee Network Agent; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 McProxy;McAfee Proxy Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 McShield;McShield; C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe [2010-10-13 200056]
R2 mfefire;McAfee Firewall Core Service; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [2010-10-13 245352]
R2 mfevtp;McAfee Validation Trust Protection Service; C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe [2010-10-13 149032]
R2 MSK80Service;McAfee Anti-Spam Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [2010-03-10 355440]
R2 NTI IScheduleSvc;NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [2010-06-28 255744]
R2 UNS;Intel(R) Management & Security Application User Notification Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [2010-03-18 2320920]
R2 Updater Service;Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [2010-01-28 243232]
R2 wlidsvc;Windows Live ID Sign-in Assistant; C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE [2010-09-21 2286976]
R3 iPod Service;iPod Service; C:\Program Files\iPod\bin\iPodService.exe [2011-03-07 934176]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86; C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64; C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2010-11-02 655624]
S3 McODS;McAfee Scanner; C:\Program Files\mcafee\VirusScan\mcods.exe [2010-10-07 509416]
S3 MWLService;MyWinLocker Service; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [2010-05-27 305520]
S3 WatAdminSvc;@%SystemRoot%\system32\Wat\WatUX.exe,-601; C:\Windows\system32\Wat\WatAdminSvc.exe []
S4 McOobeSv;McAfee OOBE Service; C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe [2010-03-10 355440]
-----------------EOF-----------------