Sorry for the late reply and posting... due to a busy week
Anyway as result to the two computer scan the result is as follow:
SuperAntiSpyware --> no malware was found and no report generated
and for the Deckard's System Scanner here is the report...
Deckard's System Scanner v20071014.68
Run by jerion on 2008-04-16 00:48:36
Computer is in Normal Mode.
--------------------------------------------------------------------------------
-- System Restore --------------------------------------------------------------
Successfully created a Deckard's System Scanner Restore Point.
-- Last 5 Restore Point(s) --
37: 2008-04-16 07:48:41 UTC - RP37 - Deckard's System Scanner Restore Point
36: 2008-04-15 03:05:58 UTC - RP36 - System Checkpoint
35: 2008-04-12 19:36:39 UTC - RP35 - Installed Garena
34: 2008-04-11 07:44:20 UTC - RP34 - Software Distribution Service 3.0
33: 2008-04-10 03:03:05 UTC - RP33 - System Checkpoint
-- First Restore Point --
1: 2008-03-30 21:46:03 UTC - RP1 - System Checkpoint
Backed up registry hives.
Performed disk cleanup.
-- HijackThis (run as jerion.exe) ----------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 12:49:19 AM, on 4/16/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\Autorun Eater\oldmcdonald.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Autorun Eater\billy.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\jerion\Desktop\dss.exe
C:\PROGRA~1\TRENDM~1\HIJACK~1\jerion.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://us.rd.yahoo.c...//www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://us.rd.yahoo.c...rch/search.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.c...//www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.yahoo.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) =
http://us.rd.yahoo.c...//www.yahoo.comR3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Autorun Eater] C:\Program Files\Autorun Eater\oldmcdonald.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: Microtek Scanner Finder.lnk = C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) -
http://www.kaspersky...can_unicode.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
--
End of file - 5522 bytes
-- File Associations -----------------------------------------------------------
All associations okay.
-- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ---------------------
R0 ivicd (Ivi CDVD Filter Driver) - c:\windows\system32\drivers\ivicd.sys <Not Verified; InterVideo; InterVideo C/DVD Filter Driver>
R0 RITFSD - c:\windows\system32\drivers\ritfsd.sys
R0 VVBackd5 - c:\windows\system32\drivers\vvbackd5.sys
R2 Rcfilter - c:\windows\system32\drivers\rcfilter.sys <Not Verified; FarStone Technology Inc.,; Restore IT!>
R3 exdisk (Express Disk Service) - c:\windows\system32\drivers\exdisk.sys
R3 Iviaspi (IVI ASPI Shell) - c:\windows\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
R3 Pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
R3 SASENUM - c:\program files\superantispyware\sasenum.sys <Not Verified; SuperAdBlocker, Inc.; SuperAntiSpyware>
S3 EagleNT - c:\windows\system32\drivers\eaglent.sys (file missing)
S3 iviudf - c:\windows\system32\drivers\iviudf.sys <Not Verified; InterVideo; UDF File System Driver>
S3 npkcrypt - c:\program files\gravity\ragnarokonline\npkcrypt.sys <Not Verified; INCA Internet Co., Ltd.; nProtect KeyCrypt Driver>
-- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------
All services whitelisted.
-- Device Manager: Disabled ----------------------------------------------------
No disabled devices found.
-- Files created between 2008-03-16 and 2008-04-16 -----------------------------
2008-04-14 19:43:00 0 d-------- C:\Documents and Settings\jerion\Application Data\Malwarebytes
2008-04-14 19:42:54 0 d-------- C:\Program Files\Malwarebytes' Anti-Malware
2008-04-14 19:42:54 0 d-------- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2008-04-12 12:36:40 53248 --a------ C:\WINDOWS\system32\ImageOle.dll <Not Verified; TODO: <Company name>; TODO: <Product name>>
2008-04-12 12:36:39 0 d-------- C:\Program Files\Garena
2008-04-12 12:36:29 0 d-------- C:\Documents and Settings\jerion\Application Data\InstallShield
2008-04-11 21:03:21 0 d-------- C:\Documents and Settings\jerion\Application Data\Yahoo!
2008-04-11 21:03:21 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo! Companion
2008-04-11 20:59:39 0 d-------- C:\Documents and Settings\jerion\Application Data\Macromedia
2008-04-11 20:58:14 0 d-------- C:\Documents and Settings\All Users\Application Data\Yahoo!
2008-04-11 20:57:13 0 d-------- C:\Program Files\Yahoo!
2008-04-10 15:19:05 0 d-------- C:\Program Files\uTorrent
2008-04-10 15:19:01 0 d-------- C:\Documents and Settings\jerion\Application Data\uTorrent
2008-04-07 13:59:25 0 d-------- C:\WINDOWS\ShellNew
2008-04-07 13:58:38 0 d-------- C:\Documents and Settings\jerion\Application Data\Microsoft Web Folders
2008-04-07 13:41:42 60928 --a------ C:\WINDOWS\system32\drivers\Smplscsi.sys <Not Verified; OnSpec Electronic, Inc.; Microsoft® Windows Operating System>
2008-04-07 13:41:42 7680 --a------ C:\WINDOWS\system32\drivers\Onsreged.sys
2008-04-07 13:41:41 285216 --a------ C:\WINDOWS\system32\drivers\Onsio.sys
2008-04-07 13:41:39 0 d-------- C:\Kpcms
2008-04-07 13:41:36 13962 --a------ C:\WINDOWS\system32\Msmusd6.dll <Not Verified; Microtek International Inc.; ScanMaker 4600>
2008-04-07 13:41:36 0 d-------- C:\Program Files\Microtek
2008-04-06 17:08:46 0 d-------- C:\WINDOWS\system32\ctfmon.exe
2008-04-06 16:57:02 0 d-------- C:\New Folder
2008-04-05 14:00:00 0 d-------- C:\AUTORUN.INF
2008-04-05 03:10:11 0 d-------- C:\Documents and Settings\Administrator\Application Data\AVG7
2008-04-05 03:05:04 0 d-------- C:\Documents and Settings\Administrator\Favorites
2008-04-05 03:05:04 0 d-------- C:\Documents and Settings\Administrator\Desktop
2008-04-05 03:05:04 0 d--hs---- C:\Documents and Settings\Administrator\Cookies
2008-04-05 03:05:04 0 dr-h----- C:\Documents and Settings\Administrator\Application Data
2008-04-05 03:05:04 0 d---s---- C:\Documents and Settings\Administrator\Application Data\Microsoft
2008-04-05 03:05:03 0 d--h----- C:\Documents and Settings\Administrator\Templates
2008-04-05 03:05:03 0 dr------- C:\Documents and Settings\Administrator\Start Menu
2008-04-05 03:05:03 0 dr-h----- C:\Documents and Settings\Administrator\SendTo
2008-04-05 03:05:03 0 d--h----- C:\Documents and Settings\Administrator\Recent
2008-04-05 03:05:03 0 d--h----- C:\Documents and Settings\Administrator\PrintHood
2008-04-05 03:05:03 524288 --ah----- C:\Documents and Settings\Administrator\NTUSER.DAT
2008-04-05 03:05:03 0 d--h----- C:\Documents and Settings\Administrator\NetHood
2008-04-05 03:05:03 0 d-------- C:\Documents and Settings\Administrator\My Documents
2008-04-05 03:05:03 0 d--h----- C:\Documents and Settings\Administrator\Local Settings
2008-04-04 23:48:59 0 d-------- C:\Documents and Settings\All Users\Application Data\Kaspersky Lab
2008-04-04 23:48:58 0 d-------- C:\WINDOWS\system32\Kaspersky Lab
2008-04-04 23:20:56 0 d-------- C:\Program Files\Trend Micro
2008-04-04 23:16:41 0 d-------- C:\WINDOWS\network diagnostic
2008-04-04 22:30:57 0 d-------- C:\Documents and Settings\jerion\Application Data\Talkback
2008-04-04 22:30:50 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-04 22:30:40 0 d-------- C:\Documents and Settings\jerion\Application Data\Mozilla
2008-04-04 17:43:25 0 d-------- C:\WINDOWS\system32\PreInstall
2008-04-04 17:43:23 0 d--h----- C:\WINDOWS\$hf_mig$
2008-04-04 16:10:52 4682 --a------ C:\WINDOWS\system32\npptNT2.sys <Not Verified; INCA Internet Co., Ltd.; nProtect NPSC Kernel Mode Driver for NT>
2008-04-04 16:10:34 0 d-------- C:\Program Files\Common Files\INCA Shared
2008-03-31 23:10:43 0 d-------- C:\WINDOWS\system32\SoftwareDistribution
2008-03-31 17:48:40 0 d-------- C:\Documents and Settings\jerion\Application Data\Ahead
2008-03-31 17:45:14 0 dr-h----- C:\$VAULT$.AVG
2008-03-30 18:45:19 2829 --a------ C:\WINDOWS\War3Unin.pif
2008-03-30 18:45:19 139264 --a------ C:\WINDOWS\War3Unin.exe <Not Verified; Blizzard Entertainment; Warcraft III Uninstaller>
2008-03-30 18:45:19 66005 --a------ C:\WINDOWS\War3Unin.dat
2008-03-30 18:38:57 0 d-------- C:\Program Files\Warcraft III
2008-03-30 18:28:59 394240 --a------ C:\WINDOWS\system32\Smab.dll
2008-03-30 18:28:59 719872 --a------ C:\WINDOWS\system32\devil.dll <Not Verified; Abysmal Software; Developer's Image Library (DevIL)>
2008-03-30 18:28:59 318976 --a------ C:\WINDOWS\system32\avisynth.dll <Not Verified; The Public; Avisynth 2.5>
2008-03-30 18:28:58 70656 --a------ C:\WINDOWS\system32\yv12vfw.dll <Not Verified; www.helixcommunity.org; Helix YV12 YUV Codec>
2008-03-30 18:28:58 70656 --a------ C:\WINDOWS\system32\i420vfw.dll <Not Verified; www.helixcommunity.org; Helix I420 YUV Codec>
2008-03-30 18:28:58 27648 --a------ C:\WINDOWS\system32\AVSredirect.dll
2008-03-30 18:28:58 66560 --a------ C:\WINDOWS\MOTA113.exe
2008-03-30 18:28:58 217073 --a------ C:\WINDOWS\meta4.exe
2008-03-30 18:28:57 0 d-------- C:\Program Files\AviSynth 2.5
2008-03-30 18:28:47 31232 -r-hs---- C:\WINDOWS\system32\msfDX.dll <Not Verified; Hans Mayerl; msfDX.dll>
2008-03-30 18:28:47 163328 -r-hs---- C:\WINDOWS\system32\flvDX.dll <Not Verified; Gabest; FLV Splitter>
2008-03-30 18:28:43 0 d-------- C:\Program Files\eRightSoft
2008-03-30 18:26:40 0 d-------- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2008-03-30 18:26:32 0 d-------- C:\Program Files\SUPERAntiSpyware
2008-03-30 18:26:32 0 d-------- C:\Documents and Settings\jerion\Application Data\SUPERAntiSpyware.com
2008-03-30 18:26:18 0 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-03-30 18:25:47 0 d-------- C:\Documents and Settings\jerion\Application Data\AVG7
2008-03-30 18:25:37 0 d-------- C:\Documents and Settings\LocalService\Application Data\AVG7
2008-03-30 18:25:22 0 d-------- C:\Documents and Settings\All Users\Application Data\Grisoft
2008-03-30 18:25:22 0 d-------- C:\Documents and Settings\All Users\Application Data\avg7
2008-03-30 18:09:34 0 d-------- C:\Program Files\AC3Filter
2008-03-30 18:09:14 0 d-------- C:\Program Files\DivX
2008-03-30 18:05:41 0 d-------- C:\Program Files\NetGames
2008-03-30 18:05:00 0 d-------- C:\Program Files\Autorun Eater
2008-03-30 17:55:51 0 d-------- C:\Program Files\Tales of Pirates Online
2008-03-30 17:53:54 0 d-------- C:\Program Files\Softnyx
2008-03-30 17:45:39 0 d-------- C:\WINDOWS\pss
2008-03-30 16:51:33 0 d-------- C:\Program Files\RF Online Crimson Dawn
2008-03-30 16:24:22 0 d-------- C:\WINDOWS\Perfect World
2008-03-30 16:24:22 0 d-------- C:\Program Files\Perfect World
2008-03-30 16:20:25 155648 --a------ C:\WINDOWS\system32\NeroCheck.exe <Not Verified; Ahead Software Gmbh; Ahead Software Gmbh NeroCheck>
2008-03-30 16:20:03 0 d-------- C:\Program Files\Common Files\Nero
2008-03-30 16:18:35 2932736 -----n--- C:\WINDOWS\UNNeroVision.exe <Not Verified; Nero AG; Nero Web Engine>
2008-03-30 16:17:55 364544 -----n--- C:\WINDOWS\system32\TwnLib4.dll <Not Verified; Pegasus Imaging Corp.; TwnLib4>
2008-03-30 16:17:55 0 d-------- C:\Documents and Settings\All Users\Application Data\Ahead
2008-03-30 16:17:54 106496 --a------ C:\WINDOWS\system32\TwnLib20.dll <Not Verified; Pegasus Software; TWNLIB20>
2008-03-30 16:17:54 38912 -----n--- C:\WINDOWS\system32\picn20.dll <Not Verified; Pegasus Imaging Corp.; PEGASUS>
2008-03-30 16:17:54 471040 -----n--- C:\WINDOWS\system32\ImagXRA7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-03-30 16:17:54 262144 -----n--- C:\WINDOWS\system32\ImagXR7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-03-30 16:17:54 1568768 -----n--- C:\WINDOWS\system32\ImagX7.dll <Not Verified; Pegasus Imaging Corp.; ImagXpress7>
2008-03-30 16:17:46 0 d-------- C:\Program Files\Common Files\Ahead
2008-03-30 16:17:45 0 d-------- C:\Program Files\Ahead
2008-03-30 16:05:05 0 d-------- C:\Program Files\e-Games
2008-03-30 15:58:58 0 d-------- C:\Program Files\FreeStyle Philippines
2008-03-30 15:44:28 0 d-------- C:\Program Files\Gravity
2008-03-30 15:39:00 0 d-------- C:\Documents and Settings\All Users\Application Data\UDL
2008-03-30 15:36:16 495616 --a------ C:\WINDOWS\system32\PICSDK2.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON PIC SDK>
2008-03-30 15:36:16 73728 --a------ C:\WINDOWS\system32\PICSDK.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON PIC SDK>
2008-03-30 15:36:16 77824 --a------ C:\WINDOWS\system32\PICEntry.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON PIC SDK>
2008-03-30 15:36:16 114688 --a------ C:\WINDOWS\system32\EpPicPrt.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON PIC SDK>
2008-03-30 15:36:16 111932 --a------ C:\WINDOWS\system32\EPPICPrinterDB.dat
2008-03-30 15:36:16 1139 --a------ C:\WINDOWS\system32\EPPICPresetData_PT.dat
2008-03-30 15:36:16 1120 --a------ C:\WINDOWS\system32\EPPICPresetData_IT.dat
2008-03-30 15:36:16 1107 --a------ C:\WINDOWS\system32\EPPICPresetData_GE.dat
2008-03-30 15:36:16 1129 --a------ C:\WINDOWS\system32\EPPICPresetData_FR.dat
2008-03-30 15:36:16 1136 --a------ C:\WINDOWS\system32\EPPICPresetData_ES.dat
2008-03-30 15:36:16 1104 --a------ C:\WINDOWS\system32\EPPICPresetData_EN.dat
2008-03-30 15:36:16 1146 --a------ C:\WINDOWS\system32\EPPICPresetData_DU.dat
2008-03-30 15:36:16 1129 --a------ C:\WINDOWS\system32\EPPICPresetData_CF.dat
2008-03-30 15:36:16 1139 --a------ C:\WINDOWS\system32\EPPICPresetData_BP.dat
2008-03-30 15:36:16 4943 --a------ C:\WINDOWS\system32\EPPICPattern6.dat
2008-03-30 15:36:16 21390 --a------ C:\WINDOWS\system32\EPPICPattern5.dat
2008-03-30 15:36:16 11811 --a------ C:\WINDOWS\system32\EPPICPattern4.dat
2008-03-30 15:36:16 24903 --a------ C:\WINDOWS\system32\EPPICPattern3.dat
2008-03-30 15:36:16 20148 --a------ C:\WINDOWS\system32\EPPICPattern2.dat
2008-03-30 15:36:16 31053 --a------ C:\WINDOWS\system32\EPPICPattern131.dat
2008-03-30 15:36:16 27417 --a------ C:\WINDOWS\system32\EPPICPattern121.dat
2008-03-30 15:36:16 26154 --a------ C:\WINDOWS\system32\EPPICPattern1.dat
2008-03-30 15:36:16 65536 --a------ C:\WINDOWS\system32\EPPicMgr.dll <Not Verified; SEIKO EPSON CORPORATION; EPSON PIC SDK>
2008-03-30 15:34:51 0 d-------- C:\Program Files\EPSON
2008-03-30 15:06:26 0 d-------- C:\Documents and Settings\jerion\Application Data\Symantec
2008-03-30 15:05:51 0 d-------- C:\Documents and Settings\All Users\Application Data\Symantec
2008-03-30 15:04:49 183987 --a------ C:\WINDOWS\system32\drivers\VVBackd5.sys
2008-03-30 15:04:46 33249 -ra------ C:\WINDOWS\system32\drivers\RITFSD.sys
2008-03-30 15:04:46 31872 -ra------ C:\WINDOWS\system32\drivers\Rcfilter.sys <Not Verified; FarStone Technology Inc.,; Restore IT!>
2008-03-30 15:04:46 14074 -ra------ C:\WINDOWS\system32\drivers\exdisk.sys
2008-03-30 15:04:46 45056 -ra------ C:\WINDOWS\DxpAppEx.exe
2008-03-30 15:04:44 49152 -ra------ C:\WINDOWS\system32\HookAPI.dll
2008-03-30 15:04:40 32768 -ra------ C:\WINDOWS\system32\RitShell.dll <Not Verified; ; RitShell Module>
2008-03-30 15:04:31 0 d-------- C:\Program Files\FarStone
2008-03-30 15:02:43 10368 -----n--- C:\WINDOWS\system32\drivers\pfc.sys <Not Verified; Padus, Inc.; Padus® ASPI Shell>
2008-03-30 15:02:36 204800 --a------ C:\WINDOWS\system32\IVIresizeW7.dll
2008-03-30 15:02:36 188416 --a------ C:\WINDOWS\system32\IVIresizePX.dll
2008-03-30 15:02:36 192512 --a------ C:\WINDOWS\system32\IVIresizeP6.dll
2008-03-30 15:02:36 192512 --a------ C:\WINDOWS\system32\IVIresizeM6.dll
2008-03-30 15:02:36 200704 --a------ C:\WINDOWS\system32\IVIresizeA6.dll
2008-03-30 15:02:36 20480 --a------ C:\WINDOWS\system32\IVIresize.dll
2008-03-30 15:01:56 5248 -----n--- C:\WINDOWS\system32\drivers\udffsrec.sys
2008-03-30 15:01:56 116224 -----n--- C:\WINDOWS\system32\drivers\IviUdf.sys <Not Verified; InterVideo; UDF File System Driver>
2008-03-30 15:01:56 38784 -----n--- C:\WINDOWS\system32\drivers\ivicd.sys <Not Verified; InterVideo; InterVideo C/DVD Filter Driver>
2008-03-30 15:01:55 59392 --a------ C:\WINDOWS\system32\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
2008-03-30 15:01:47 10752 -----n--- C:\WINDOWS\system32\drivers\iviaspi.sys <Not Verified; InterVideo, Inc.; InterVideo ASPI Shell>
2008-03-30 15:01:39 26694 --a------ C:\WINDOWS\HWS.exe
2008-03-30 15:01:39 26694 --a------ C:\WINDOWS\HMD.exe
2008-03-30 15:01:39 0 d-------- C:\Program Files\InterVideo
2008-03-30 15:01:38 0 d-------- C:\Documents and Settings\jerion\Application Data\InterVideo
2008-03-30 15:01:16 0 d-------- C:\WINDOWS\Profiles
2008-03-30 15:01:00 0 d-------- C:\WINDOWS\system32\Adobe
2008-03-30 15:01:00 0 d-------- C:\Program Files\Common Files\Adobe
2008-03-30 15:01:00 0 d-------- C:\Documents and Settings\jerion\Application Data\InterTrust
2008-03-30 15:01:00 0 d-------- C:\Documents and Settings\jerion\Application Data\Adobe
2008-03-30 15:00:58 306688 --a------ C:\WINDOWS\IsUninst.exe <Not Verified; InstallShield Software Corporation; InstallShield® unInstaller>
2008-03-30 14:59:05 74752 --a------ C:\WINDOWS\system32\drivers\Rtnicxp.sys <Not Verified; Realtek Semiconductor Corporation; Realtek 10/100/1000 NIC Family all in one NDIS Driver>
2008-03-30 14:59:04 0 d-------- C:\WINDOWS\OPTIONS
2008-03-30 14:58:38 0 d-------- C:\WINDOWS\system32\Lang
2008-03-30 14:55:48 40960 -r------- C:\WINDOWS\system32\ChCfg.exe
2008-03-30 14:55:26 0 d-------- C:\WINDOWS\system32\RTCOM
2008-03-30 14:54:36 0 d-------- C:\Program Files\Realtek
2008-03-30 14:54:33 487424 -r------- C:\WINDOWS\RtlExUpd.dll <Not Verified; Realtek Semiconductor Corp.; RtlExUpd Dynamic Link Library>
2008-03-30 14:52:48 516096 -----n--- C:\WINDOWS\system32\ati2sgag.exe <Not Verified; ; ATI Smart>
2008-03-30 14:49:22 0 d-------- C:\WINDOWS\system32\ReinstallBackups
2008-03-30 14:49:03 0 d--h----- C:\Program Files\InstallShield Installation Information
2008-03-30 14:49:00 0 d-------- C:\Program Files\Common Files\InstallShield
2008-03-30 14:48:10 0 d-------- C:\Program Files\MSXML 4.0
2008-03-30 14:47:42 0 d-------- C:\TempEI4
2008-03-30 14:45:51 0 d-------- C:\Documents and Settings\jerion\Application Data\Identities
2008-03-30 14:45:43 0 d--h----- C:\Documents and Settings\jerion\Templates
2008-03-30 14:45:43 0 dr------- C:\Documents and Settings\jerion\Start Menu
2008-03-30 14:45:43 0 dr-h----- C:\Documents and Settings\jerion\SendTo
2008-03-30 14:45:43 0 dr-h----- C:\Documents and Settings\jerion\Recent
2008-03-30 14:45:43 0 d--h----- C:\Documents and Settings\jerion\PrintHood
2008-03-30 14:45:43 3670016 --ah----- C:\Documents and Settings\jerion\NTUSER.DAT
2008-03-30 14:45:43 0 d--h----- C:\Documents and Settings\jerion\NetHood
2008-03-30 14:45:43 0 dr------- C:\Documents and Settings\jerion\My Documents
2008-03-30 14:45:43 0 d--h----- C:\Documents and Settings\jerion\Local Settings
2008-03-30 14:45:43 0 dr------- C:\Documents and Settings\jerion\Favorites
2008-03-30 14:45:43 0 d-------- C:\Documents and Settings\jerion\Desktop
2008-03-30 14:45:43 0 d--hs---- C:\Documents and Settings\jerion\Cookies
2008-03-30 14:45:43 0 dr-h----- C:\Documents and Settings\jerion\Application Data
2008-03-30 14:44:39 0 d-------- C:\WINDOWS\SoftwareDistribution
2008-03-30 14:44:27 0 d-------- C:\WINDOWS\Prefetch
2008-03-30 14:44:26 0 d---s---- C:\WINDOWS\system32\Microsoft
2008-03-30 14:44:25 262144 --ah----- C:\Documents and Settings\LocalService\NTUSER.DAT
2008-03-30 14:44:25 0 d--h----- C:\Documents and Settings\LocalService\Local Settings
2008-03-30 14:44:25 0 d--hs---- C:\Documents and Settings\LocalService\Cookies
2008-03-30 14:44:25 0 d-------- C:\Documents and Settings\LocalService\Application Data
2008-03-30 14:44:25 0 d---s---- C:\Documents and Settings\LocalService\Application Data\Microsoft
2008-03-30 14:44:11 0 d--h----- C:\Documents and Settings\NetworkService\Local Settings
2008-03-30 14:44:11 0 d--hs---- C:\Documents and Settings\NetworkService\Cookies
2008-03-30 14:44:11 0 d-------- C:\Documents and Settings\NetworkService\Application Data
2008-03-30 14:44:11 0 d---s---- C:\Documents and Settings\NetworkService\Application Data\Microsoft
2008-03-30 14:44:10 225280 --ah----- C:\Documents and Settings\NetworkService\NTUSER.DAT
2008-03-30 14:41:22 0 d-------- C:\WINDOWS\system32\xircom
2008-03-30 14:41:22 0 d-------- C:\Program Files\microsoft frontpage
2008-03-30 14:41:20 225280 ---h----- C:\Documents and Settings\Default User\NTUSER.DAT
2008-03-30 14:41:14 0 -rahs---- C:\MSDOS.SYS
2008-03-30 14:41:14 0 -rahs---- C:\IO.SYS
2008-03-30 14:41:14 0 --a------ C:\CONFIG.SYS
2008-03-30 14:41:14 0 --a------ C:\AUTOEXEC.BAT
2008-03-30 14:40:09 0 d--hs---- C:\Documents and Settings\All Users\DRM
2008-03-30 14:40:00 0 dr------- C:\WINDOWS\Offline Web Pages
2008-03-30 14:40:00 0 d---s---- C:\WINDOWS\Downloaded Program Files
2008-03-30 14:39:50 0 d--h----- C:\Program Files\WindowsUpdate
2008-03-30 14:39:29 0 d-------- C:\WINDOWS\system32\DirectX
2008-03-30 14:38:54 0 d---s---- C:\WINDOWS\Tasks
2008-03-30 14:38:53 0 d-------- C:\Program Files\Common Files\MSSoap
2008-03-30 14:38:49 0 d-------- C:\WINDOWS\srchasst
2008-03-30 14:38:48 0 d-------- C:\WINDOWS\system32\Macromed
2008-03-30 14:38:38 0 d-------- C:\Program Files\Movie Maker
2008-03-30 14:38:30 0 d-------- C:\WINDOWS\system32\Restore
2008-03-30 14:38:11 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat
2008-03-30 14:37:57 0 d-------- C:\WINDOWS\Registration
2008-03-30 14:37:29 0 d-------- C:\Program Files\Online Services
2008-03-30 14:37:23 0 d-------- C:\Program Files\Messenger
2008-03-30 14:37:19 0 d-------- C:\Program Files\MSN Gaming Zone
2008-03-30 14:36:35 0 d-------- C:\Program Files\Windows NT
2008-03-30 14:36:32 0 d-------- C:\WINDOWS\system32\MsDtc
2008-03-30 14:36:30 0 d-------- C:\WINDOWS\system32\Com
2008-03-30 06:29:41 0 d--hs---- C:\WINDOWS\Installer
2008-03-30 06:29:40 0 d-------- C:\Program Files\Common Files\ODBC
2008-03-30 06:29:36 0 dr------- C:\Program Files
2008-03-30 06:29:36 0 d-------- C:\Program Files\Common Files
2008-03-30 06:29:36 0 d-------- C:\Program Files\Common Files\SpeechEngines
2008-03-30 06:29:12 0 d--h----- C:\Documents and Settings\Default User\Templates
2008-03-30 06:29:12 0 dr------- C:\Documents and Settings\Default User\Start Menu
2008-03-30 06:29:12 0 dr-h----- C:\Documents and Settings\Default User\SendTo
2008-03-30 06:29:12 0 d--h----- C:\Documents and Settings\Default User\Recent
2008-03-30 06:29:12 0 d--h----- C:\Documents and Settings\Default User\PrintHood
2008-03-30 06:29:12 0 d--h----- C:\Documents and Settings\Default User\NetHood
2008-03-30 06:29:12 0 d-------- C:\Documents and Settings\Default User\My Documents
2008-03-30 06:29:12 0 dr-h----- C:\Documents and Settings\Default User\Local Settings
2008-03-30 06:29:12 0 d-------- C:\Documents and Settings\Default User\Favorites
2008-03-30 06:29:12 0 d-------- C:\Documents and Settings\Default User\Desktop
2008-03-30 06:29:12 0 d---s---- C:\Documents and Settings\Default User\Cookies
2008-03-30 06:29:12 0 d--h----- C:\Documents and Settings\All Users\Templates
2008-03-30 06:29:12 0 dr------- C:\Documents and Settings\All Users\Start Menu
2008-03-30 06:29:12 0 d-------- C:\Documents and Settings\All Users\Favorites
2008-03-30 06:29:12 0 dr------- C:\Documents and Settings\All Users\Documents
2008-03-30 06:29:12 0 d-------- C:\Documents and Settings\All Users\Desktop
2008-03-30 06:28:59 0 d-------- C:\WINDOWS\system32\CatRoot2
2008-03-30 06:28:59 0 d-------- C:\WINDOWS\system32\CatRoot
2008-03-30 06:28:54 0 dr-h----- C:\Documents and Settings\Default User\Application Data
2008-03-30 06:28:54 0 d---s---- C:\Documents and Settings\Default User\Application Data\Microsoft
2008-03-30 06:28:54 0 dr-h----- C:\Documents and Settings\All Users\Application Data
2008-03-30 06:28:54 0 d---s---- C:\Documents and Settings\All Users\Application Data\Microsoft
2008-03-30 06:28:30 0 d--hs---- C:\System Volume Information
2008-03-30 06:28:30 0 d-------- C:\Documents and Settings
2008-03-30 06:20:10 0 d-------- C:\WINDOWS
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\WinSxS
2008-03-30 06:20:10 0 dr------- C:\WINDOWS\Web
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\twain_32
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\wins
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\wbem
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\usmt
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\spool
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\ShellExt
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\Setup
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\ras
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\oobe
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\npp
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\mui
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\inetsrv
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\IME
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\icsxml
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\ias
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\export
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\drivers
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\drivers\etc
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\drivers\disdn
2008-03-30 06:20:10 0 dr-hs--c- C:\WINDOWS\system32\dllcache
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\dhcp
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\config
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\3com_dmi
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\3076
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\2052
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1054
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1042
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1041
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1037
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1033
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1031
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1028
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system32\1025
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\system
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\security
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Resources
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\repair
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Provisioning
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\PeerNet
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\pchealth
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\mui
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\msapps
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\msagent
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Media
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\java
2008-03-30 06:20:10 0 d--h----- C:\WINDOWS\inf
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\ime
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Help
2008-03-30 06:20:10 0 dr--s---- C:\WINDOWS\Fonts
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Driver Cache
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Debug
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Cursors
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Connection Wizard
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\Config
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\AppPatch
2008-03-30 06:20:10 0 d-------- C:\WINDOWS\addins
-- Find3M Report ---------------------------------------------------------------
2008-03-30 15:03:01 56 --a------ C:\Program Files\Common Files\appop.log
2008-03-30 06:29:12 62 --ahs---- C:\Documents and Settings\jerion\Application Data\desktop.ini
-- Registry Dump ---------------------------------------------------------------
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"RTHDCPL"="RTHDCPL.EXE" [10/14/2005 06:51 PM C:\WINDOWS\RTHDCPL.exe]
"Autorun Eater"="C:\Program Files\Autorun Eater\oldmcdonald.exe" [01/31/2008 03:48 AM]
"AVG7_CC"="C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" [03/30/2008 06:25 PM]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SUPERAntiSpyware"="C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [02/29/2008 05:03 PM]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [08/30/2007 05:43 PM]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [2/17/1999 1:05:56 PM]
Microtek Scanner Finder.lnk - C:\Program Files\Microtek\ScanWizard 5\ScannerFinder.exe [4/7/2008 1:41:36 PM]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [12/20/2006 01:55 PM 77824]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll 04/19/2007 01:41 PM 294912 C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^InterVideo WinCinema Manager.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk
backup=C:\WINDOWS\pss\InterVideo WinCinema Manager.lnkCommon Startup
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Alcmtr]
ALCMTR.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ccApp]
"C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
C:\WINDOWS\system32\ctfmon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EPSON Stylus C59 Series]
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATIBHP.EXE /FU "C:\WINDOWS\TEMP\E_S162.tmp" /EF "HKLM"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\farstone]
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS]
"C:\Program Files\Messenger\msmsgs.exe" /background
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
C:\WINDOWS\system32\NeroCheck.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RestoreIT!]
"C:\Program Files\FarStone\RestoreIT\RestoreIT_XP\VBPTASK.EXE" VBStart
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WINCINEMAMGR]
"C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe"
-- End of Deckard's System Scanner: finished at 2008-04-16 00:50:28 ------------
and may I also include the online scan I made last Apr. 5, 2008 with Kaspersky Online Scan
-------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER REPORT
Saturday, April 05, 2008 2:58:35 AM
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky Online Scanner version: 5.0.98.0
Kaspersky Anti-Virus database last update: 4/04/2008
Kaspersky Anti-Virus database records: 681538
-------------------------------------------------------------------------------
Scan Settings:
Scan using the following antivirus database: extended
Scan Archives: true
Scan Mail Bases: true
Scan Target - My Computer:
A:\
B:\
C:\
D:\
E:\
Scan Statistics:
Total number of scanned objects: 81668
Number of viruses found: 6
Number of infected objects: 43
Number of suspicious objects: 0
Duration of the scan process: 01:29:54
Infected Object Name / Virus Name / Last Action
C:\Documents and Settings\All Users\Application Data\avg7\Log\emc.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log Object is locked skipped
C:\Documents and Settings\All Users\Application Data\Grisoft\Avg7Data\avg7log.log.lck Object is locked skipped
C:\Documents and Settings\jerion\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware\AppLogs\SUPERANTISPYWARE-4-4-2008( 23-34-18 ).LOG Object is locked skipped
C:\Documents and Settings\jerion\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\Temp\~DF4F08.tmp Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped
C:\Documents and Settings\jerion\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\jerion\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\jerion\NTUSER.DAT.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Cookies\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\History\History.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped
C:\Documents and Settings\LocalService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\LocalService\ntuser.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat Object is locked skipped
C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped
C:\Documents and Settings\NetworkService\NTUSER.DAT Object is locked skipped
C:\Documents and Settings\NetworkService\ntuser.dat.LOG Object is locked skipped
C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
C:\System Volume Information\_restore{012C3B24-DC0E-4065-99A8-BEDFC24A123F}\RP30\change.log Object is locked skipped
C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped
C:\WINDOWS\SchedLgU.Txt Object is locked skipped
C:\WINDOWS\SoftwareDistribution\EventCache\{560E43A8-0E4B-412A-B0D3-68905CE1D020}.bin Object is locked skipped
C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped
C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped
C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\default Object is locked skipped
C:\WINDOWS\system32\config\default.LOG Object is locked skipped
C:\WINDOWS\system32\config\Internet.evt Object is locked skipped
C:\WINDOWS\system32\config\SAM Object is locked skipped
C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped
C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\SECURITY Object is locked skipped
C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped
C:\WINDOWS\system32\config\software Object is locked skipped
C:\WINDOWS\system32\config\software.LOG Object is locked skipped
C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped
C:\WINDOWS\system32\config\system Object is locked skipped
C:\WINDOWS\system32\config\system.LOG Object is locked skipped
C:\WINDOWS\system32\h323log.txt Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped
C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped
C:\WINDOWS\WindowsUpdate.log Object is locked skipped
D:\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe/data0017 Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
D:\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Nero PhotoShow Express/nero_photoshow_express_5_setup.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
D:\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso/Toolbar.exe Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm skipped
D:\Nero 8 Ultra Edition 8.3.0 Multilanguage FULL Retail\Nero 8.3.0.iso ISOimage: infected - 3 skipped
D:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP18\A0001801.cmd Object is locked skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP18\A0001802.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP18\A0001938.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP18\A0001948.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP19\A0001952.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP22\A0002420.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP34\A0003561.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP35\A0003567.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP36\A0003571.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP36\A0003700.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP36\A0003718.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP36\A0003740.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP36\A0003753.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0003791.inf Infected: Trojan-PSW.Win32.OnLineGames.uhv skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004804.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004827.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004847.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004862.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004884.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004901.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004914.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004925.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004938.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004949.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004964.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0004982.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0005982.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0005994.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0006994.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0007021.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0007032.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0007048.inf Infected: Trojan-PSW.Win32.OnLineGames.upg skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP37\A0007070.inf Infected: Trojan-PSW.Win32.OnLineGames.uyx skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP38\A0007094.inf Infected: Trojan-PSW.Win32.OnLineGames.uyx skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP38\A0007167.inf Infected: Trojan-PSW.Win32.OnLineGames.uyx skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP38\A0007190.inf Infected: Worm.Win32.AutoRun.dao skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP39\A0007196.inf Infected: Worm.Win32.AutoRun.dao skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP40\A0007200.inf Infected: Worm.Win32.AutoRun.dao skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP40\A0007214.inf Infected: Worm.Win32.AutoRun.dao skipped
D:\System Volume Information\_restore{37860509-6D4B-4D19-8A18-1CEA5A76E211}\RP40\A0008214.inf Infected: Trojan-PSW.Win32.OnLineGames.vum skipped
Scan process completed.
--------------------------------------------------------------------------------------
As report show viruses resides on my partition D: of the hard drive... when I use the system restore using RestoreIt application my system will go fast like before but when I start using or open my files at the D: partition my system will become slow again and a ctfmon.exe runs on my system and an Autorun.inf infected my C: drive also...
However last April 8.. using safemode with command prompt..and manually deleted the ctfmon.exe and autorun.inf and created a folder named ctfmon.exe to my system32 and a folder autorun.inf on my root directories C:& D:... now the ctfmon.exe is not running but still my system turns slow when I use my D: partition...
I hope this my help to solve my problem and did not bring you to confusion... thank you very much