Wife's netbook, Dell Mini 9, SS drive 16GB, XP Home has serious virus infections. AVG scan finds 24 instances, mostly "Trojan horse Generic13.ATPH" with a few "Win32/Cryptor". AVG says it moves 15 to vault, leaving 9 still infecting. Rescanning after reboot again finds 24 viruses. Initial symptoms were windowsclick redirects. Later, things seemed to get worse, and the fake Spyware Protect screens started popping up. Also was getting unsolicited bluetooth radio/commercial streams.
Preperation Steps:
1) TFC goes to blue screen every time I try to run it.
2) SystemRestorePoint.exe shows error saying "Restore Point Creation Failed!"
3) ERUNT seems to work. Registry backup created.
4) MalwareBytes' Anti-Malware won't run.
5) Windows update worked, after finally getting to the MS site. Installed one patch for MS Office.
6 & 7) Rooter.ext and OTListIt logs follow below.
Thanks in advance for any helpful tips!
Rooter_1.txt:
Rooter.exe (v1.0) by Eric_71
¨
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
32_bits - x86 Family 6 Model 28 Stepping 2, GenuineIntel
¨
C:\ [Fixed-NTFS] .. ( Total:14 Go - Free:5 Go )
¨
Scan : 14:53.07
Path : C:\Documents and Settings\MrX3\Desktop\MALWARE_TOOLS\Rooter.exe
User : MrX3 ( Administrator -> YES )
¨
----------------------\\ Processes
¨
Locked [System Process] (0)
______ System (4)
______ \??\C:\WINDOWS\system32\csrss.exe (652)
______ \??\C:\WINDOWS\system32\winlogon.exe (676)
______ C:\WINDOWS\system32\services.exe (724)
______ C:\WINDOWS\system32\lsass.exe (736)
______ C:\WINDOWS\system32\svchost.exe (904)
______ C:\WINDOWS\system32\svchost.exe (1008)
______ C:\WINDOWS\System32\svchost.exe (1076)
______ C:\WINDOWS\system32\svchost.exe (1176)
______ C:\WINDOWS\system32\svchost.exe (1252)
______ C:\WINDOWS\system32\spoolsv.exe (1320)
______ C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe (1428)
______ C:\Program Files\Java\jre6\bin\jqs.exe (1464)
______ C:\Program Files\Dell Support Center\bin\sprtsvc.exe (1528)
______ C:\PROGRA~1\AVG\AVG8\avgrsx.exe (1628)
______ C:\PROGRA~1\AVG\AVG8\avgnsx.exe (1636)
______ C:\WINDOWS\system32\svchost.exe (1680)
______ C:\PROGRA~1\AVG\AVG8\avgemc.exe (1772)
______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (1860)
______ C:\Program Files\AVG\AVG8\avgcsrvx.exe (364)
______ C:\WINDOWS\Explorer.EXE (1508)
______ C:\WINDOWS\System32\alg.exe (2068)
______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2504)
______ C:\WINDOWS\RTHDCPL.EXE (2596)
______ C:\WINDOWS\system32\igfxpers.exe (2612)
______ C:\Program Files\Battery Meter\BTMeter.exe (2620)
______ C:\Program Files\Wireless Select Switch\WLSS.exe (2644)
______ C:\Program Files\Dell Support Center\bin\sprtcmd.exe (2688)
______ C:\WINDOWS\system32\igfxsrvc.exe (2704)
______ C:\PROGRA~1\AVG\AVG8\avgtray.exe (2764)
______ C:\Program Files\Java\jre6\bin\jusched.exe (2776)
______ C:\WINDOWS\system32\ctfmon.exe (2808)
______ C:\WINDOWS\System32\svchost.exe (3964)
______ C:\Program Files\Mozilla Firefox\firefox.exe (2104)
______ C:\WINDOWS\system32\NOTEPAD.EXE (3892)
______ C:\Program Files\Internet Explorer\Iexplore.exe (3448)
______ C:\Program Files\Internet Explorer\Iexplore.exe (3208)
______ C:\Documents and Settings\MrX3\Desktop\MALWARE_TOOLS\Rooter.exe (252)
¨
----------------------\\ Device\Harddisk0\
¨
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
¨
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:41094144)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:41126400 | Length:15365871104)
¨
----------------------\\ Scheduled Tasks
¨
C:\WINDOWS\Tasks\desktop.ini
C:\WINDOWS\Tasks\SA.DAT
C:\WINDOWS\Tasks\User_Feed_Synchronization-{A8D7AE51-7F82-4FCF-856D-6031391897B2}.job
C:\WINDOWS\Tasks\WECPUpdate.job
¨
----------------------\\ Registry
¨
¨
----------------------\\ Files & Folders
¨
----------------------\\ Scan completed at 14:53.09
¨
C:\Rooter$\Rooter_1.txt - (15/06/2009 | 14:53.09)
OTL
OTL logfile created on: 6/15/2009 2:56:53 PM - Run 3
OTL by OldTimer - Version 2.1.1.0 Folder = C:\Documents and Settings\MrX3\Desktop\MALWARE_TOOLS
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.39 Gb Available Physical Memory | 69.76% Memory free
2.04 Gb Paging File | 1.52 Gb Available in Paging File | 74.43% Paging File free
Paging file location(s): C:\pagefile.sys 200 200 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 14.31 Gb Total Space | 5.65 Gb Free Space | 39.46% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: INTLLIFE-MINI9
Current User Name: MrX3
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\AVG\AVG8\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG8\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
PRC - C:\WINDOWS\RTHDCPL.EXE (Realtek Semiconductor Corp.)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\Program Files\Battery Meter\BTMeter.exe (Dell)
PRC - C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\Iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\MrX3\Desktop\MALWARE_TOOLS\OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (avg8emc [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg8wd [Auto | Running]) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (GoToAssist [On_Demand | Stopped]) -- C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (sprtsvc_dellsupportcenter [Auto | Running]) -- C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WMPNetworkSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Media Player\WMPNetwk.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (AliIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (amdagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (asc [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AvgLdx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86 [System | Running]) -- C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgTdiX [System | Running]) -- C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (BCM43XX [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys (Broadcom Corporation)
DRV - (BTWUSB [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\btwusb.sys (Broadcom Corporation.)
DRV - (CmdIde [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (dac2w2k [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (EMSC [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\EMSC.SYS ()
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\igxpmp32.sys (Intel Corporation)
DRV - (IntcAzAudAddService [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (JMCR [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\jmcr.sys (JMicron Technology Corp.)
DRV - (mraid35x [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (OA004Afx [On_Demand | Running]) -- C:\WINDOWS\system32\Drivers\OA004Afx.sys (Creative Technology Ltd.)
DRV - (OA004Ufd [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\OA004Ufd.sys (Creative Technology Ltd.)
DRV - (OA004Vid [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\OA004Vid.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (ql1080 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql12160 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1280 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (RTLE8023xp [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sisagp [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (Sparrow [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (symc810 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (symc8xx [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_hi [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (sym_u3 [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (SynTP [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV - (ultra [Disabled | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.co...html?channel=us
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=3081203
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\S-1-5-21-3436034942-565223664-3386438656-1006\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://nyt.com/"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}:6.0.11
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.11
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\PROGRAM FILES\AVG\AVG8\FIREFOX [2009/05/01 18:48:39 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/03/31 22:19:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/12/27 17:07:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/06/14 10:58:55 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.11\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/06/14 10:58:55 | 00,000,000 | ---D | M]
[2009/05/23 12:27:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MrX3\Application Data\mozilla\Extensions
[2009/05/23 12:27:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MrX3\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/23 12:27:39 | 00,000,000 | ---D | M] -- C:\Documents and Settings\MrX3\Application Data\mozilla\Firefox\Profiles\pmenvbl5.default\extensions
[2009/06/13 19:01:52 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/06/14 10:58:55 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/12/27 17:08:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}
[2009/05/22 22:18:46 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/06/14 10:58:36 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/06/14 10:58:37 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/02/19 12:33:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/02/19 12:33:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/02/19 12:33:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/02/19 12:33:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/02/19 12:33:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/02/19 12:33:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/02/19 12:33:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (149 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 209.44.111.57 antispyware.microsoft.com
O1 - Hosts: 209.44.111.57 2009antivirpro.com
O1 - Hosts: 209.44.111.57 www.2009antivirpro.com
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (BHO) - {26070AD0-CF3E-49be-8C83-85A63BFD36D5} - C:\WINDOWS\system32\iehelper.dll File not found
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (796525 Class) - {E7F15AC4-E0A9-43F0-921B-70DFEA621220} - C:\WINDOWS\system32\796525\796525.dll File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Alcmtr] ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BTMeter] C:\Program Files\Battery Meter\BTMeter.exe (Dell)
O4 - HKLM..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe" ( )
O4 - HKLM..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k File not found
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [RTHDCPL] RTHDCPL.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [WLSS] C:\Program Files\Wireless Select Switch\WLSS.exe (Dell)
O4 - HKU\S-1-5-21-3436034942-565223664-3386438656-1006..\Run: [MalwareRemovalBot] C:\Program Files\MalwareRemovalBot\MalwareRemovalBot.exe -boot File not found
O4 - HKU\S-1-5-21-3436034942-565223664-3386438656-1006..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3436034942-565223664-3386438656-1006\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200 (Google Inc.)
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm File not found
O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm File not found
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINDOWS\system32\lsp.dll ()
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINDOWS\system32\lsp.dll ()
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\sdra64.exe) - C:\WINDOWS\system32\sdra64.exe [FILE handle not seen by OS]
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\system32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\system32\igfxdev.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/04/25 18:45:49 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/06/15 14:52:01 | 00,000,000 | ---D | M]
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[2009/06/15 14:53:09 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/06/15 14:51:52 | 00,170,029 | ---- | C] (Eric_71) -- C:\Documents and Settings\MrX3\Desktop\Rooter.exe
[2009/06/15 13:16:07 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/06/15 13:15:47 | 00,000,613 | ---- | C] () -- C:\Documents and Settings\MrX3\Desktop\NTREGOPT.lnk
[2009/06/15 13:15:47 | 00,000,594 | ---- | C] () -- C:\Documents and Settings\MrX3\Desktop\ERUNT.lnk
[2009/06/15 13:15:46 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/06/15 13:11:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Desktop\MALWARE_TOOLS
[2009/06/15 12:38:26 | 00,005,574 | ---- | C] () -- C:\Documents and Settings\MrX3\Desktop\AVG_Scan_20090615.csv
[2009/06/15 10:55:46 | 00,000,698 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/15 10:55:42 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/06/15 10:55:40 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/06/15 10:55:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/06/15 09:54:13 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/06/15 01:54:51 | 03,371,376 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\MrX3\Desktop\getup.exe
[2009/06/15 01:50:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\MalwareRemovalBot
[2009/06/14 22:40:51 | 00,183,296 | ---- | C] () -- C:\WINDOWS\System32\lsp.dll
[2009/06/14 22:40:48 | 00,096,768 | ---- | C] () -- C:\WINDOWS\syssvc.exe
[2009/06/14 22:05:04 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\796525
[2009/06/14 16:25:13 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/06/14 16:23:54 | 03,371,384 | ---- | C] (Malwarebytes Corporation ) -- C:\zzz-setup.exe
[2009/06/10 12:11:40 | 00,246,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ieproxy.dll
[2009/06/10 12:11:40 | 00,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpshims.dll
[2009/06/08 00:11:59 | 00,000,000 | R--D | C] -- C:\Documents and Settings\MrX3\My Documents\My Videos
[2009/06/08 00:09:21 | 00,000,471 | ---- | C] () -- C:\Documents and Settings\MrX3\Desktop\Shortcut to BELEZA on I-life-25-11-06.lnk
[2009/06/08 00:08:32 | 00,000,281 | ---- | C] () -- C:\Shortcut to OS ©.lnk
[2009/05/29 22:30:32 | 00,000,000 | ---D | C] -- C:\$WIN_NT$.~BT
[2009/05/29 22:18:17 | 00,000,254 | RHS- | C] () -- C:\BOOT.BAK
[2009/05/29 22:18:12 | 00,458,092 | R--- | C] () -- C:\txtsetup.sif
[2009/05/29 22:18:12 | 00,260,288 | R--- | C] () -- C:\$LDR$
[2009/05/29 22:17:49 | 00,000,000 | ---D | C] -- C:\WINDOWS\setup.pss
[2009/05/27 20:07:54 | 21,374,44352 | -HS- | C] () -- C:\hiberfil.sys
[2009/05/23 12:27:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\Mozilla
[2009/05/23 12:26:12 | 00,001,616 | ---- | C] () -- C:\Documents and Settings\MrX3\Desktop\Mozilla Firefox.lnk
[2009/05/23 01:37:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\Macromedia
[2009/05/23 01:37:24 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\Adobe
[2009/05/23 01:34:43 | 00,000,000 | -H-D | C] -- C:\Program Files\Uninstall Information
[2009/05/23 01:34:08 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\MrX3\Application Data\desktop.ini
[2009/05/23 01:34:06 | 00,000,089 | -HS- | C] () -- C:\Documents and Settings\MrX3\My Documents\desktop.ini
[2009/05/23 01:34:06 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\MrX3\Local Settings\desktop.ini
[2009/05/23 01:34:04 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\MrX3\Start Menu\Programs\Startup\desktop.ini
[2009/05/23 01:34:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\InstallShield
[2009/05/23 01:34:04 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\Identities
[2009/05/23 01:34:03 | 00,000,000 | --SD | C] -- C:\Documents and Settings\MrX3\Application Data\Microsoft
[2009/05/23 01:34:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Application Data\Sun
[2009/05/23 01:34:02 | 00,000,000 | R--D | C] -- C:\Documents and Settings\MrX3\My Documents\My Pictures
[2009/05/23 01:34:02 | 00,000,000 | R--D | C] -- C:\Documents and Settings\MrX3\My Documents\My Music
[2009/05/23 01:34:02 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\MrX3\Local Settings\Temporary Internet Files
[2009/05/23 01:34:02 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\MrX3\Local Settings\History
[2009/05/23 01:34:02 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\MrX3\Local Settings\Application Data
[2009/05/23 01:34:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\My Documents\My Google Gadgets
[2009/05/23 01:34:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\My Documents\Dell WebCam Central
[2009/05/23 01:34:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\My Documents\Bluetooth Exchange Folder
[2009/05/23 01:34:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\MrX3\Local Settings\Temp
[2009/01/09 12:00:47 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/12/03 10:05:36 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2008/12/03 10:03:09 | 00,001,154 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2008/12/03 09:34:00 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2008/12/03 08:58:42 | 00,266,240 | ---- | C] () -- C:\WINDOWS\System32\EMSC.DLL
[2008/12/03 08:58:42 | 00,009,856 | ---- | C] () -- C:\WINDOWS\System32\drivers\EMSC.sys
[2008/04/25 18:42:57 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2008/04/25 13:33:23 | 00,000,507 | ---- | C] () -- C:\WINDOWS\win.ini
[2008/04/25 13:33:22 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[2009/06/15 13:54:15 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\MrX3\Local Settings\desktop.ini
[2009/06/15 13:53:55 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/06/15 13:53:52 | 21,374,44352 | -HS- | M] () -- C:\hiberfil.sys
[2009/06/15 13:53:52 | 00,224,816 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/06/15 13:15:47 | 00,000,613 | ---- | M] () -- C:\Documents and Settings\MrX3\Desktop\NTREGOPT.lnk
[2009/06/15 13:15:47 | 00,000,594 | ---- | M] () -- C:\Documents and Settings\MrX3\Desktop\ERUNT.lnk
[2009/06/15 12:38:26 | 00,005,574 | ---- | M] () -- C:\Documents and Settings\MrX3\Desktop\AVG_Scan_20090615.csv
[2009/06/15 12:37:32 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/06/15 12:24:38 | 00,170,029 | ---- | M] (Eric_71) -- C:\Documents and Settings\MrX3\Desktop\Rooter.exe
[2009/06/15 10:55:46 | 00,000,698 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/06/15 09:43:32 | 37,123,328 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2009/06/15 09:43:32 | 00,077,480 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2009/06/15 01:55:04 | 03,371,376 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\MrX3\Desktop\getup.exe
[2009/06/14 22:40:51 | 00,183,296 | ---- | M] () -- C:\WINDOWS\System32\lsp.dll
[2009/06/14 22:40:49 | 00,096,768 | ---- | M] () -- C:\WINDOWS\syssvc.exe
[2009/06/14 16:15:31 | 03,371,384 | ---- | M] (Malwarebytes Corporation ) -- C:\zzz-setup.exe
[2009/06/12 08:07:44 | 00,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2009/06/08 00:09:21 | 00,000,471 | ---- | M] () -- C:\Documents and Settings\MrX3\Desktop\Shortcut to BELEZA on I-life-25-11-06.lnk
[2009/06/08 00:08:32 | 00,000,281 | ---- | M] () -- C:\Shortcut to OS ©.lnk
[2009/06/07 18:02:35 | 00,000,269 | RHS- | M] () -- C:\boot.ini
[2009/06/01 09:51:12 | 23,635,392 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/05/29 22:18:17 | 00,000,254 | RHS- | M] () -- C:\BOOT.BAK
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/23 01:35:21 | 00,000,089 | -HS- | M] () -- C:\Documents and Settings\MrX3\My Documents\desktop.ini
< End of report >