http://www.geekstogo...ed-t234652.html
I have scanned my computer with avast,no treats,but it found files that could not be scanned but i could not copy those files,superantispyware didnt find anything,Malewarebytes antimalware did not find anything,i used ATF cleaner,i used CCcleaner it found bad regerstry and repared them,I used Advanced windows cleaner it found bad regerstry and repared them.Windows didnt find any updates and restoreing my computer to a earlier date didnt fix the problem.
OTListIT Log
OTListIt logfile created on: 4/8/2009 8:03:08 PM - Run 6
OTListIt2 by OldTimer - Version 2.0.12.2 Folder = C:\Documents and Settings\terry martinez\My Documents\My Received Files\New Folder
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.24 Gb Total Physical Memory | 0.76 Gb Available Physical Memory | 61.48% Memory free
1.46 Gb Paging File | 1.14 Gb Available in Paging File | 77.68% Paging File free
Paging file location(s): C:\pagefile.sys 372 744;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 72.56 Gb Total Space | 61.40 Gb Free Space | 84.62% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
Drive H: | 2.00 Gb Total Space | 1.98 Gb Free Space | 99.36% Space Free | Partition Type: NTFS
Drive I: | 662.75 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: HOME-2BC94BDAB5
Current User Name: terry martinez
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: All users
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2008/04/13 19:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/02/05 16:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/02/05 16:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/03/09 05:19:17 | 00,148,888 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jusched.exe
PRC - [2008/03/18 18:27:12 | 00,013,312 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe
PRC - [2008/10/01 14:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
PRC - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe
PRC - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe
PRC - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2006/02/20 15:23:08 | 00,495,616 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcrcoms.exe
PRC - [2006/01/02 16:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2006/01/02 16:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
PRC - [2009/04/08 19:58:23 | 00,500,736 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\terry martinez\My Documents\My Received Files\New Folder\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2008/03/18 18:27:12 | 00,013,312 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\agrsmsvc.exe -- (AgereModemAudio [Auto | Running])
SRV - [2008/10/01 14:06:14 | 00,116,040 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Auto | Running])
SRV - [2008/07/25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2009/02/05 16:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2006/05/03 11:43:46 | 00,413,696 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Stopped])
SRV - [2006/05/03 11:57:00 | 00,520,192 | ---- | M] () -- C:\WINDOWS\system32\ati2sgag.exe -- (ATI Smart [Auto | Stopped])
SRV - [2009/02/05 16:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 16:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 16:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/12/12 12:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Running])
SRV - [2008/07/25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2008/04/13 19:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2008/03/25 21:38:24 | 00,217,088 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqcxs08.dll -- (hpqcxs08 [On_Demand | Running])
SRV - [2008/03/25 22:27:36 | 00,135,168 | ---- | M] (Hewlett-Packard Co.) -- C:\Program Files\HP\Digital Imaging\bin\hpqddsvc.dll -- (hpqddsvc [Auto | Running])
SRV - [2008/07/29 20:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Auto | Running])
SRV - [2006/02/20 15:23:08 | 00,495,616 | ---- | M] ( ) -- C:\WINDOWS\system32\lxcrcoms.exe -- (lxcr_device [On_Demand | Running])
SRV - [2008/02/28 12:53:18 | 00,043,520 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZinw12.dll -- (Net Driver HPZ12 [Auto | Running])
SRV - [2008/07/29 20:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2008/02/28 12:53:18 | 00,053,248 | ---- | M] (Hewlett-Packard) -- C:\WINDOWS\system32\HPZipm12.dll -- (Pml Driver HPZ12 [Auto | Running])
SRV - [2007/01/19 12:54:14 | 00,097,136 | ---- | M] (Microsoft Corporation) -- C:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc [On_Demand | Stopped])
SRV - [2006/10/18 22:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2009/02/05 16:05:11 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2008/10/29 21:43:44 | 01,204,128 | ---- | M] (Agere Systems) -- C:\WINDOWS\system32\DRIVERS\AGRSM.sys -- (AgereSoftModem [On_Demand | Running])
DRV - [2004/10/01 12:24:02 | 02,279,424 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running])
DRV - [2009/02/05 16:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 16:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 16:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 16:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 16:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2006/05/03 11:50:42 | 01,540,608 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2002/10/01 14:43:32 | 00,119,798 | ---- | M] (SP) -- C:\WINDOWS\System32\Drivers\SPCA561.SYS -- (CA561 [On_Demand | Running])
DRV - [2008/01/24 16:22:06 | 00,049,920 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2008/01/24 16:22:07 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2008/01/24 16:22:08 | 00,021,568 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2004/08/20 16:26:00 | 00,737,874 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys -- (ialm [On_Demand | Stopped])
DRV - [2005/09/20 17:27:20 | 00,010,368 | ---- | M] (InterVideo, Inc.) -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi [On_Demand | Running])
DRV - [2007/11/17 15:46:38 | 00,068,954 | ---- | M] (Windows ® 2000 DDK provider) -- C:\WINDOWS\System32\Drivers\jl2005c.sys -- (JL2005C [On_Demand | Stopped])
DRV - [2006/02/28 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2007/03/29 04:00:00 | 00,043,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2009/03/09 05:03:24 | 00,121,984 | ---- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\system32\DRIVERS\Rtnicxp.sys -- (RTL8023xp [On_Demand | Running])
DRV - [2009/04/02 13:32:08 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (SASDIFSV [System | Running])
DRV - [2008/09/03 14:07:16 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM [On_Demand | Running])
DRV - [2008/09/03 14:07:12 | 00,055,024 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (SASKUTIL [System | Running])
DRV - [2008/04/13 11:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2002/03/07 18:21:28 | 00,095,528 | ---- | M] (Sunplus Technology Co. LTD.) -- C:\WINDOWS\System32\Drivers\SPIXNEW.SYS -- (SUNPLUS [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://news.yahoo.com/;
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.yahoo.com/
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\S-1-5-21-448539723-1604221776-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-448539723-1604221776-725345543-1004\S-1-5-21-448539723-1604221776-725345543-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "eBay"
FF - prefs.js..browser.startup.homepage: "http://my.yahoo.com/"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.1
FF - prefs.js..extensions.enabledItems: [email protected]:1.2.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}:6.0.07
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: {28FAD68E-4001-48d5-B994-68069F7CFB1D}:0.4.5
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.5.1116
FF - prefs.js..extensions.enabledItems: [email protected]:1.1
FF - prefs.js..extensions.enabledItems: {DAD0F81A-CF67-4eed-98D6-26F6E47274CA}:1.3
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.8
FF - prefs.js..extensions.enabledItems: {c1dffba0-628e-11d9-9669-0800200c9a66}:3.0.4
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\HP\DIGITAL IMAGING\SMART WEB PRINTING\MOZILLAADDON2 [2009/01/24 19:12:03 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/01/30 20:22:30 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/04 21:50:12 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/28 13:29:19 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.8\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/28 13:29:19 | 00,000,000 | ---D | M]
[2008/08/15 23:43:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Extensions
[2008/08/15 23:43:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/07 21:28:06 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions
[2009/02/18 14:35:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2009/02/14 22:39:29 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2009/01/10 22:03:57 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2008/11/22 22:56:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\{DAD0F81A-CF67-4eed-98D6-26F6E47274CA}
[2008/11/22 22:56:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\[email protected]
[2009/02/14 20:42:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\[email protected]
[2009/02/10 20:29:54 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\[email protected]
[2008/11/23 22:55:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\terry martinez\Application Data\mozilla\Firefox\Profiles\tkve29t6.default\extensions\[email protected]
[2009/04/07 21:28:06 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/28 13:29:19 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2008/08/20 09:10:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
[2009/03/04 21:51:01 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/04/01 13:29:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/03/28 13:29:09 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/28 13:29:09 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/09/28 13:36:37 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/28 13:36:37 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/28 13:36:37 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/13 10:32:24 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/28 13:36:37 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/28 13:36:37 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/28 13:36:37 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Yahoo! IE Services Button) - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay (ATI Technologies Inc.)
O4 - HKLM..\Run: [ATIModeChange] Ati2mdxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [LXCRCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-448539723-1604221776-725345543-1004..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKU\S-1-5-21-448539723-1604221776-725345543-1004..\Run: [LXCRCATS] rundll32 C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\LXCRtime.dll,_RunDLLEntry@16 ()
O4 - HKU\S-1-5-21-448539723-1604221776-725345543-1004..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background (Microsoft Corporation)
O4 - HKU\S-1-5-21-448539723-1604221776-725345543-1004..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKU\S-1-5-21-448539723-1604221776-725345543-1004..\RunOnce: [Shockwave Updater] C:\WINDOWS\system32\Adobe\SHOCKW~1\SwHelper_1100470.exe -Update -1103470 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; IEMB3; .NET CLR 1.1.4322; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; IEMB3)" -"http://www.andkon.co...g/superbikegp/" (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\terry martinez\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O7 - HKU\S-1-5-21-448539723-1604221776-725345543-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = [binary data]
O9 - Extra Button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll (Yahoo! Inc.)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra Button: @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Messenger\Msgslang.dll,-61144 - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKU\S-1-5-21-448539723-1604221776-725345543-1004\..Trusted Domains: 8 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace....ploader1006.cab (MySpace Uploader Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.mi...b?1218858467390 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...t/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/08/15 21:49:21 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005/04/28 19:13:00 | 00,000,045 | R--- | M] () - I:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{8e470a4b-078b-11de-a7b6-0011090fc313}\Shell\AutoRun\command - "" = J:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8e470a4b-078b-11de-a7b6-0011090fc313}\Shell\install\command - "" = J:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8e470a4b-078b-11de-a7b6-0011090fc313}\Shell\usermanualEnglish\command - "" = J:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8e470a4b-078b-11de-a7b6-0011090fc313}\Shell\usermanualFrench\command - "" = J:\rcaeasyrip_setup.exe -- File not found
O33 - MountPoints2\{8e470a4b-078b-11de-a7b6-0011090fc313}\Shell\usermanualSpanish\command - "" = J:\rcaeasyrip_setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[7 C:\WINDOWS\*.tmp files]
[2009/04/08 20:02:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/04/08 20:01:58 | 00,000,767 | ---- | C] () -- C:\Documents and Settings\terry martinez\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/08 20:01:39 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\NTREGOPT.lnk
[2009/04/08 20:01:39 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\ERUNT.lnk
[2009/04/08 20:01:38 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/04/08 20:00:26 | 00,000,854 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to Rooter.exe.lnk
[2009/04/08 20:00:19 | 00,000,871 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to OTListIt2.exe.lnk
[2009/04/06 21:52:57 | 00,001,883 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Catalyst Control Center.lnk
[2009/04/06 21:43:22 | 00,001,034 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to 6-11-pre-r300_xp-2k_dd_ccc_wdm_38185.exe.lnk
[2009/04/06 20:53:02 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/06 20:07:52 | 00,520,192 | ---- | C] () -- C:\WINDOWS\System32\ati2sgag.exe
[2009/04/06 20:07:35 | 00,000,000 | ---D | C] -- C:\Program Files\ATI Technologies
[2009/04/06 19:59:02 | 00,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/04/06 18:08:51 | 00,000,000 | ---D | C] -- C:\ATI
[2009/04/06 17:28:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\terry martinez\Local Settings\Application Data\ATI
[2009/04/06 17:28:48 | 00,000,000 | ---D | C] -- C:\Documents and Settings\terry martinez\Application Data\ATI
[2009/04/06 17:28:46 | 00,000,137 | ---- | C] () -- C:\Documents and Settings\terry martinez\Local Settings\Application Data\fusioncache.dat
[2009/04/06 17:22:43 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009/04/06 17:22:43 | 00,354,816 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisdecd.dll
[2009/04/06 17:22:43 | 00,052,224 | ---- | C] () -- C:\WINDOWS\System32\msdvbnp.ax
[2009/04/06 17:22:43 | 00,052,224 | ---- | C] () -- C:\WINDOWS\System32\dllcache\msdvbnp.ax
[2009/04/06 17:22:43 | 00,052,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\msdv.sys
[2009/04/06 17:22:43 | 00,052,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\msdv.sys
[2009/04/06 17:22:43 | 00,030,208 | ---- | C] () -- C:\WINDOWS\System32\psisrndr.ax
[2009/04/06 17:22:43 | 00,030,208 | ---- | C] () -- C:\WINDOWS\System32\dllcache\psisrndr.ax
[2009/04/06 17:22:43 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdaplgin.ax
[2009/04/06 17:22:43 | 00,016,896 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bdaplgin.ax
[2009/04/06 17:22:43 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mpe.sys
[2009/04/06 17:22:43 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mpe.sys
[2009/04/06 17:22:43 | 00,011,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\bdasup.sys
[2009/04/06 17:22:43 | 00,011,392 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bdasup.sys
[2009/04/06 17:22:41 | 00,012,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksolay.ax
[2009/04/06 17:22:37 | 00,046,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dxdllreg.exe
[2009/04/06 17:22:34 | 00,797,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\d3dim700.dll
[2009/04/06 17:22:34 | 00,797,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dim700.dll
[2009/04/06 17:22:34 | 00,381,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dsound.dll
[2009/04/06 17:21:04 | 00,058,560 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativckxx.vp
[2009/04/06 17:21:04 | 00,028,080 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativvpxx.vp
[2009/04/06 17:21:04 | 00,006,005 | ---- | C] () -- C:\WINDOWS\System32\atifglpf.xml
[2009/04/06 17:21:04 | 00,000,929 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.vp
[2009/04/06 17:20:59 | 00,114,688 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\atipdlxx.dll
[2009/04/06 17:20:59 | 00,077,824 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Oemdspif.dll
[2009/04/06 17:20:59 | 00,026,112 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\Ati2mdxx.exe
[2009/04/06 17:20:59 | 00,024,064 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ativcoxx.dll
[2009/04/06 17:20:56 | 00,041,984 | ---- | C] (ATI Technologies, Inc.) -- C:\WINDOWS\System32\ati2edxx.dll
[2009/04/06 17:20:55 | 01,114,674 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativcaxx.cpa
[2009/04/06 17:20:55 | 00,127,614 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2009/04/06 17:20:02 | 00,000,000 | ---D | C] -- C:\Diamond
[2009/04/06 16:17:40 | 00,000,695 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Driver Sweeper.lnk
[2009/04/06 16:17:39 | 00,000,000 | ---D | C] -- C:\Program Files\Driver Sweeper
[2009/04/05 20:32:00 | 00,000,000 | ---D | C] -- C:\WINDOWS\Prefetch
[2009/04/05 18:56:01 | 00,000,000 | ---D | C] -- C:\hp
[2009/04/05 17:57:12 | 00,046,877 | ---- | C] () -- C:\WINDOWS\setupapi.old
[2009/04/05 15:30:14 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\$$TEMP$$.~~~
[2009/04/05 15:07:36 | 00,000,000 | ---D | C] -- C:\WINDOWS\NV388320.TMP
[2009/04/05 14:09:51 | 00,001,739 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\DMZ North Korea.lnk
[2009/04/05 14:07:17 | 00,000,000 | ---D | C] -- C:\Program Files\DMZ North Korea
[2009/04/05 13:57:50 | 00,000,000 | ---D | C] -- C:\Program Files\NetDevil
[2009/04/05 12:28:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\nview
[2009/04/02 12:44:09 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/04/01 14:27:36 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/03/31 20:40:59 | 00,245,760 | ---- | C] (LansSoft Studio) -- C:\WINDOWS\System32\aUpdateNow.ocx
[2009/03/31 20:40:58 | 00,101,888 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\VB6STKIT.DLL
[2009/03/31 20:40:56 | 00,000,000 | ---D | C] -- C:\Program Files\FriendBlasterPro
[2009/03/26 16:43:37 | 00,274,432 | ---- | C] (Riverdeep Interactive Learning Limited) -- C:\WINDOWS\TLCUninstall.exe
[2009/03/26 16:43:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\The Learning Company
[2009/03/23 03:59:52 | 00,000,000 | ---D | C] -- C:\Documents and Settings\terry martinez\Application Data\Malwarebytes
[2009/03/23 03:59:43 | 00,000,714 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/23 03:59:42 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/23 03:59:39 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/23 03:59:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/23 03:59:36 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/22 20:10:07 | 00,000,000 | ---D | C] -- C:\_OTListIt
[2009/03/20 00:56:30 | 00,001,224 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to LOLToasts_Raid_Tool_v7.lnk
[2009/03/18 04:37:00 | 00,024,827 | ---- | C] () -- C:\Documents and Settings\terry martinez\Desktop\Config.bin
[2009/03/14 19:13:59 | 00,000,000 | ---D | C] -- C:\Program Files\MSN Messenger
[2009/03/06 20:23:24 | 00,000,049 | ---- | C] () -- C:\WINDOWS\EasyRip.ini
[2008/12/14 21:26:59 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PTWebCam.INI
[2008/10/30 20:36:06 | 00,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2008/09/22 17:38:17 | 00,000,120 | ---- | C] () -- C:\WINDOWS\Sansa Media Converter.INI
[2008/09/19 19:44:52 | 00,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2008/09/19 19:41:22 | 00,000,028 | ---- | C] () -- C:\WINDOWS\D&D.ini
[2008/09/19 19:34:40 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcrvs.dll
[2008/09/19 19:34:37 | 00,409,600 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrinpa.dll
[2008/09/19 19:34:36 | 00,393,216 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcriesc.dll
[2008/09/19 19:34:34 | 00,303,104 | ---- | C] () -- C:\WINDOWS\System32\lxcrcoin.dll
[2008/09/19 19:33:53 | 00,692,224 | ---- | C] () -- C:\WINDOWS\System32\lxcrdrs.dll
[2008/09/19 19:33:53 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\lxcrcaps.dll
[2008/09/19 19:33:52 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\lxcrcnv4.dll
[2008/09/19 19:33:23 | 00,995,328 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrusb1.dll
[2008/09/19 19:33:23 | 00,233,472 | ---- | C] () -- C:\WINDOWS\System32\LXCRinst.dll
[2008/09/19 19:33:22 | 01,183,744 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrserv.dll
[2008/09/19 19:33:22 | 00,163,840 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrprox.dll
[2008/09/19 19:33:22 | 00,114,688 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrpplc.dll
[2008/09/19 19:33:21 | 00,536,576 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrlmpm.dll
[2008/09/19 19:33:19 | 00,421,888 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrcomm.dll
[2008/09/19 19:33:18 | 00,610,304 | ---- | C] ( ) -- C:\WINDOWS\System32\lxcrcomc.dll
[2008/09/19 19:17:07 | 00,014,385 | ---- | C] () -- C:\WINDOWS\Tw561a.ini
[2008/09/19 19:17:06 | 00,000,081 | ---- | C] () -- C:\WINDOWS\Setup8a.ini
[2008/07/21 18:14:10 | 00,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2006/02/28 07:00:00 | 00,000,745 | ---- | C] () -- C:\WINDOWS\win.ini
[2006/02/28 07:00:00 | 00,000,227 | ---- | C] () -- C:\WINDOWS\system.ini
[2002/03/11 11:33:28 | 00,002,470 | ---- | C] () -- C:\WINDOWS\SPIXNEW.INI
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/04/08 20:01:58 | 00,000,767 | ---- | M] () -- C:\Documents and Settings\terry martinez\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/04/08 20:01:39 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\NTREGOPT.lnk
[2009/04/08 20:01:39 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\ERUNT.lnk
[2009/04/08 20:00:26 | 00,000,854 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to Rooter.exe.lnk
[2009/04/08 20:00:19 | 00,000,871 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to OTListIt2.exe.lnk
[2009/04/07 14:50:27 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/07 14:50:22 | 00,013,742 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/07 14:50:19 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/07 14:49:19 | 03,776,894 | -H-- | M] () -- C:\Documents and Settings\terry martinez\Local Settings\Application Data\IconCache.db
[2009/04/06 21:52:57 | 00,001,883 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Catalyst Control Center.lnk
[2009/04/06 21:43:22 | 00,001,034 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to 6-11-pre-r300_xp-2k_dd_ccc_wdm_38185.exe.lnk
[2009/04/06 20:53:02 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/04/06 19:59:04 | 00,000,010 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2009/04/06 17:28:46 | 00,000,137 | ---- | M] () -- C:\Documents and Settings\terry martinez\Local Settings\Application Data\fusioncache.dat
[2009/04/06 16:23:07 | 01,393,216 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/06 16:17:40 | 00,000,695 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Driver Sweeper.lnk
[2009/04/05 20:55:48 | 00,012,712 | ---- | M] () -- C:\Documents and Settings\terry martinez\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/04/05 19:37:10 | 00,046,877 | ---- | M] () -- C:\WINDOWS\setupapi.old
[2009/04/05 15:30:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\$$TEMP$$.~~~
[2009/04/05 14:09:51 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\DMZ North Korea.lnk
[2009/04/04 17:41:55 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/02 21:42:06 | 00,000,580 | ---- | M] () -- C:\Documents and Settings\terry martinez\My Documents\My Sharing Folders.lnk
[2009/04/01 14:32:52 | 00,000,085 | -HS- | M] () -- C:\Documents and Settings\terry martinez\My Documents\desktop.ini
[2009/03/31 21:21:34 | 00,002,357 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Mspc2.lnk
[2009/03/28 02:17:15 | 00,024,827 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\Config.bin
[2009/03/23 03:59:43 | 00,000,714 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/21 23:51:42 | 02,615,296 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mbb
[2009/03/21 23:51:42 | 01,337,344 | R--- | M] () -- C:\Documents and Settings\All Users\Documents\ESBK.mb
[2009/03/20 00:56:31 | 00,001,224 | ---- | M] () -- C:\Documents and Settings\terry martinez\Desktop\Shortcut to LOLToasts_Raid_Tool_v7.lnk
[2009/03/10 16:29:20 | 00,521,942 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/10 16:29:20 | 00,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/10 16:29:20 | 00,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
< End of report >
Rooter Log
Microsoft Windows XP Home Edition (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:74300 Mo/Free:1429 Mo)
D:\ [Removable] (Total:0 Mo/Free:0 Mo)
E:\ [Removable] (Total:0 Mo/Free:0 Mo)
F:\ [Removable] (Total:0 Mo/Free:0 Mo)
G:\ [Removable] (Total:0 Mo/Free:0 Mo)
H:\ [Fixed] - NTFS - (Total:2045 Mo/Free:2031 Mo)
I:\ [CD-Rom] (Total:662 Mo/Free:0 Mo)
Wed 04/08/2009|20:07
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashServ.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\WINDOWS\system32\agrsmsvc.exe
---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
---------- C:\Program Files\Bonjour\mDNSResponder.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
---------- C:\WINDOWS\system32\lxcrcoms.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
---------- C:\WINDOWS\notepad.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Wed 04/08/2009|20:08
----------------------\\ Scan completed at 20:08