NOTE: I have been running scans on my computer (Symantec Antivirus, Ad-ware, Spybot, Malwarebytes, Kaspersky) and Malwarebytes and Kaspersky in particular has caught several infections - relsolving these infections did not stop my problem. (In fact, my Trojan.KillAV infection was after I detected a whole slew of infections with Malwarebytes). I do have the logs of all the scans I have done between March 30th to April 17th just in case anyone wants them.
OTListIt Log - <I've did it for 60 days - Sorry!>
OTListIt logfile created on: 17/04/2009 10:59:13 AM - Run 5
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = L:\
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
511.48 Mb Total Physical Memory | 122.22 Mb Available Physical Memory | 23.89% Memory free
1.22 Gb Paging File | 0.89 Gb Available in Paging File | 73.05% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 19.53 Gb Total Space | 4.31 Gb Free Space | 22.05% Space Free | Partition Type: NTFS
Drive D: | 17.73 Gb Total Space | 12.14 Gb Free Space | 68.44% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 233.76 Gb Total Space | 25.41 Gb Free Space | 10.87% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive L: | 3.80 Gb Total Space | 1.46 Gb Free Space | 38.57% Space Free | Partition Type: FAT32
Computer Name: PENGUIN
Current User Name: Candy
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 60 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\System32\Ati2evxx.exe ()
PRC - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
PRC - C:\Program Files\Norton AntiVirus\DefWatch.exe (Symantec Corporation)
PRC - C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Norton AntiVirus\Rtvscan.exe (Symantec Corporation)
PRC - C:\WINDOWS\system32\UAService7.exe ()
PRC - C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
PRC - C:\WINDOWS\System32\wbem\unsecapp.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\Ati2evxx.exe ()
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft)
PRC - C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
PRC - L:\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (Apple Mobile Device [Auto | Running]) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe (Apple, Inc.)
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) -- C:\WINDOWS\System32\Ati2evxx.exe ()
SRV - (ATI Smart [Auto | Stopped]) -- C:\WINDOWS\system32\ati2sgag.exe ()
SRV - (ccEvtMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DefWatch [Auto | Running]) -- C:\Program Files\Norton AntiVirus\DefWatch.exe (Symantec Corporation)
SRV - (EPSONStatusAgent2 [Auto | Running]) -- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe (SEIKO EPSON CORPORATION)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (IDriverT [On_Demand | Stopped]) -- C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (iPod Service [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Inc.)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Auto | Running]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (LiveUpdate [On_Demand | Stopped]) -- C:\Program Files\Symantec\LiveUpdate\LuComServer_3_1.EXE (Symantec Corporation)
SRV - (lxby_device [On_Demand | Stopped]) -- C:\WINDOWS\system32\lxbycoms.exe (Lexmark International, Inc.)
SRV - (SavRoam [On_Demand | Stopped]) -- C:\Program Files\Norton AntiVirus\SavRoam.exe (symantec)
SRV - (SPBBCSvc [Auto | Running]) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (Symantec AntiVirus [Auto | Running]) -- C:\Program Files\Norton AntiVirus\Rtvscan.exe (Symantec Corporation)
SRV - (UserAccess7 [Auto | Running]) -- C:\WINDOWS\system32\UAService7.exe ()
SRV - (usnjsvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\Messenger\usnsvc.exe (Microsoft Corporation)
SRV - (winvnc [Auto | Running]) -- C:\Program Files\UltraVNC\WinVNC.exe (UltraVNC)
SRV - (WLSetupSvc [On_Demand | Stopped]) -- C:\Program Files\Windows Live\installer\WLSetupSvc.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (ctac32k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctac32k.sys (Creative Technology Ltd)
DRV - (ctaud2k [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV - (ctljystk [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\ctljystk.sys (Creative Technology Ltd.)
DRV - (ctprxy2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV - (ctsfm2k [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV - (DLH5X [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\DLH5XND5.sys (D-Link Corporation)
DRV - (eeCtrl [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (emu10k [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\emu10k1m.sys (Creative Technology Ltd.)
DRV - (emu10k1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\ctlfacem.sys (Creative Technology Ltd.)
DRV - (emupia [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\emupia2k.sys (Creative Technology Ltd)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (FsVga [System | Running]) -- C:\WINDOWS\system32\DRIVERS\fsvga.sys (Microsoft Corporation)
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (ha10kx2k [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ha10kx2k.sys (Creative Technology Ltd)
DRV - (HCF_MSFT [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HCF_MSFT.sys (Conexant)
DRV - (hidgame [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\hidgame.sys (Microsoft Corporation)
DRV - (imagedrv [Boot | Running]) -- C:\WINDOWS\System32\Drivers\imagedrv.sys (Ahead Software AG)
DRV - (imagesrv [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\imagesrv.sys (Ahead Software AG)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (NAVENG [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090407.003\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090407.003\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (ossrv [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV - (PfModNT [Auto | Running]) -- C:\WINDOWS\System32\PfModNT.sys (Creative Technology Ltd.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (QCDonner [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\LVCD.sys (Logitech Inc.)
DRV - (RT25USBAP [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\rt25usbap.sys (Ralink Technology Inc.)
DRV - (SAVRT [System | Running]) -- C:\Program Files\Norton AntiVirus\savrt.sys (Symantec Corporation)
DRV - (SAVRTPEL [System | Running]) -- C:\Program Files\Norton AntiVirus\Savrtpel.sys (Symantec Corporation)
DRV - (Secdrv [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (sfdrv01 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfdrv01.sys (Protection Technology)
DRV - (sfhlp02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfhlp02.sys (Protection Technology)
DRV - (sfman [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\sfmanm.sys (Creative Technology Ltd.)
DRV - (sfsync02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfsync02.sys (Protection Technology)
DRV - (sfvfs02 [Boot | Running]) -- C:\WINDOWS\System32\drivers\sfvfs02.sys (Protection Technology)
DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (SPBBCDrv [System | Running]) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (SymEvent [On_Demand | Running]) -- C:\Program Files\Symantec\SYMEVENT.SYS (Symantec Corporation)
DRV - (viaagp1 [Boot | Running]) -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (vnccom [Auto | Running]) -- C:\WINDOWS\System32\Drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\vncdrv.sys (RDV Soft)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://sympatico.msn.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = localhost
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/04/02 20:22:11 | 00,000,000 | ---D | M]
O1 HOSTS File: (62929 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.altnetp2p.com
O1 - Hosts: 127.0.0.1 www.bonzi.com
O1 - Hosts: 127.0.0.1 www.brilliantdigital.com
O1 - Hosts: 127.0.0.1 www.b3d.com
O1 - Hosts: 127.0.0.1 ad.dk.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.es.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.fr.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.it.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.jp.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.kr.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.linkexchange.com
O1 - Hosts: 127.0.0.1 ad.linksynergy.com
O1 - Hosts: 127.0.0.1 ad.nl.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.no.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.preferences.com
O1 - Hosts: 127.0.0.1 ad.se.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.sma.punto.net
O1 - Hosts: 127.0.0.1 ad.uk.doubleclick.net
O1 - Hosts: 127.0.0.1 ad.webprovider.com
O1 - Hosts: 127.0.0.1 ad08.focalink.com
O1 - Hosts: 127.0.0.1 ad1.adcept.net
O1 - Hosts: 127.0.0.1 ad2.adcept.net
O1 - Hosts: 127.0.0.1 ad3.adcept.net
O1 - Hosts: 1817 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {491AF6C5-21F2-46E1-C653-3DF529127D7B} - C:\WINDOWS\wcidBHO.dll (Symantec Corporation)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {85CF4327-68DE-1974-B32E-766E84A9706C} - C:\WINDOWS\wcidBHO.dll (Symantec Corporation)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe" (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Norton Confidence Online - {144FDEB7-A23D-4D39-A00E-AA44195535B6} - C:\WINDOWS\wcidButton.exe (Symantec Corporation)
O9 - Extra Button: PalTalk - {4EAFEF58-EEFA-4116-983D-03B49BCBFFFE} - F:\Paltalk\Paltalk.exe (AVM Software Inc.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 49 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Sites: ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: 50 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://fpdownload.ma...director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://zone.msn.com/...nx.1.0.0.67.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} http://by108fd.bay10...es/MsnPUpld.cab (MSN Photo Upload Tool)
O16 - DPF: {62D21B0B-D96F-45F7-968E-7DC16E31FE57} http://tcrew.gamenga...oinActiveXE.cab (DazoinControl Class)
O16 - DPF: {639658F3-B141-4D6B-B936-226F75A5EAC3} http://zone.msn.com/...h2.1.0.0.55.cab (CPlayFirstDinerDash2Control Object)
O16 - DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://zone.msn.com/...mjolauncher.cab (MJLauncherCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-09.su...ows-i586-jc.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {AA07EBD2-EBDD-4BD6-9F8F-114BD513492C} http://dist.globalga...ffyLauncher.cab (NeffyLauncherCtl Class)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {C86FF4B0-AA1D-46D4-8612-025FB86583C7} http://sympatico.zon...ersion=1,0,0,10 (AstoundLauncher Control)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.m...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: ActiveGS.cab http://www.virtualap...rg/activegs.cab (Reg Error: Key error.)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O16 - DPF: RaptisoftGameLoader http://www.miniclip....tgameloader.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Cribbage http://download.game...nts/y/it1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Euchre http://download.game...nts/y/et1_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Go http://download.game...nts/y/gt2_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Go Fish http://download.game...nts/y/zt3_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Graffiti http://download.game...ts/y/grt5_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong http://download.game...nts/y/ot0_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! MahJong Solitaire http://download.game...s/y/mjst3_x.cab (Reg Error: Key error.)
O16 - DPF: Yahoo! Word Racer http://download.game...nts/y/wt0_x.cab (Reg Error: Key error.)
O18 - Protocol\Handler\cdo {CD00020A-8B95-11D1-82DB-00C04FB1625D} - C:\Program Files\Common Files\Microsoft Shared\Web Folders\PKMCDO.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O20 - AppInit_DLLs: (C:\WINDOWS\system32\wesiluya.dll) - C:\WINDOWS\system32\wesiluya.dll File not found
O20 - AppInit_DLLs: (zufizc.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\yanasiba.dll) - c:\windows\system32\yanasiba.dll File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll ()
O20 - Winlogon\Notify\iassdo32: DllName - iassdo32.dll - File not found
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll (Symantec Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O33 - MountPoints2\{66bd2a05-9a3f-11dc-bfc1-00055dff0a13}\Shell - "" = AutoRun
O33 - MountPoints2\{66bd2a05-9a3f-11dc-bfc1-00055dff0a13}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{66bd2a05-9a3f-11dc-bfc1-00055dff0a13}\Shell\AutoRun\command - "" = I:\TTconfig.exe -- File not found
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 60 Days ==========
[2009/04/04 00:03:47 | 00,015,234 | ---- | C] () -- C:\Documents and Settings\All Users\Documents\Curly Brace.bmp
[2009/04/03 16:43:06 | 00,005,893 | ---- | C] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 16-43.html
[2009/04/03 13:58:18 | 00,005,354 | ---- | C] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 13-58.html
[2009/04/03 10:44:29 | 00,003,880 | ---- | C] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 10-44.html
[2009/03/31 17:35:36 | 53,639,9872 | -HS- | C] () -- C:\hiberfil.sys
[2009/03/31 13:59:25 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/03/30 19:25:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Candy\Application Data\Malwarebytes
[2009/03/30 19:25:26 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/30 19:25:23 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/30 19:25:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/29 18:58:06 | 24,768,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/03/25 00:37:35 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Windows Live
[2009/03/04 17:34:35 | 00,002,713 | -HS- | C] () -- C:\WINDOWS\System32\nupotuku.exe
[2009/02/23 11:19:02 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/02/22 19:07:32 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft CAPICOM 2.1.0.2
[2009/02/21 21:39:48 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/02/21 21:39:37 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/02/21 21:38:23 | 00,000,867 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/21 21:38:11 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009/02/21 21:38:11 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft
[2009/02/21 21:36:29 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{83C91755-2546-441D-AC40-9A6B4B860800}
[2009/02/21 21:33:05 | 00,000,000 | ---- | C] () -- C:\WINDOWS\vpc32.INI
[2009/02/21 21:26:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Candy\Local Settings\Application Data\Symantec
[2009/02/21 21:25:48 | 00,109,744 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS
[2009/02/21 21:25:48 | 00,048,816 | ---- | C] (Symantec Corporation) -- C:\WINDOWS\System32\S32EVNT1.DLL
[2009/02/21 21:25:35 | 00,466,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\capicom.dll
[2008/08/29 23:05:06 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2008/08/29 23:05:06 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2007/11/01 23:46:23 | 00,000,203 | ---- | C] () -- C:\WINDOWS\GSdx9.INI
[2007/09/26 22:33:38 | 00,002,528 | ---- | C] () -- C:\WINDOWS\FCIC.INI
[2007/09/07 19:41:01 | 00,000,263 | ---- | C] () -- C:\WINDOWS\YODESK.INI
[2007/08/28 19:06:58 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2007/08/03 23:22:52 | 00,037,376 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/01/08 02:15:25 | 00,077,824 | ---- | C] () -- C:\WINDOWS\System32\nod.dll
[2007/01/08 02:14:56 | 00,005,244 | ---- | C] () -- C:\WINDOWS\System32\fscflist.ini
[2007/01/08 02:14:53 | 00,000,073 | ---- | C] () -- C:\WINDOWS\System32\fscagent.ini
[2006/05/03 15:23:13 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2005/12/04 21:04:54 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\LXPRMON.DLL
[2005/12/04 21:04:54 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\LXPMONUI.DLL
[2005/12/04 21:01:46 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbyvs.dll
[2005/11/13 19:02:59 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2005/10/06 22:36:47 | 00,044,544 | ---- | C] () -- C:\WINDOWS\System32\GIF89.DLL
[2005/10/06 22:36:02 | 00,000,467 | ---- | C] () -- C:\WINDOWS\SIERRA.INI
[2005/08/26 15:04:50 | 00,000,120 | ---- | C] () -- C:\WINDOWS\B&ARROW.INI
[2005/04/20 14:43:46 | 00,192,577 | ---- | C] () -- C:\WINDOWS\System32\libcurl.dll
[2004/09/19 09:47:33 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2004/07/11 19:01:39 | 00,000,386 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2004/06/11 01:27:12 | 00,131,072 | ---- | C] ( ) -- C:\WINDOWS\System32\ATIDEMGR.dll
[2004/06/10 22:46:34 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\ati2evxx.dll
[2004/06/06 12:53:42 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2004/06/05 12:56:16 | 00,679,936 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2004/04/05 22:14:31 | 00,007,168 | ---- | C] () -- C:\WINDOWS\System32\e0893c13.dll
[2004/01/16 03:21:36 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\031d2b86.dll
[2003/12/24 02:18:40 | 00,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2003/12/24 02:18:40 | 00,000,180 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2003/12/13 18:46:58 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/10/19 13:04:48 | 00,000,545 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2003/09/22 00:39:55 | 00,003,715 | ---- | C] () -- C:\WINDOWS\MTB12ST.INI
[2003/09/16 11:52:28 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\vorbis.dll
[2003/09/16 11:43:31 | 00,884,736 | ---- | C] () -- C:\WINDOWS\System32\vorbisenc.dll
[2003/09/16 11:41:43 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\ogg.dll
[2003/07/04 23:29:49 | 00,000,192 | ---- | C] () -- C:\WINDOWS\Winamp.ini
[2003/07/04 23:29:14 | 00,000,041 | ---- | C] () -- C:\WINDOWS\winampa.ini
[2003/07/04 23:13:57 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/07/04 19:15:02 | 00,000,241 | ---- | C] () -- C:\WINDOWS\QSync.INI
[2003/07/04 19:14:00 | 00,005,187 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2003/07/04 11:52:19 | 00,000,033 | ---- | C] () -- C:\WINDOWS\wwwbatch.ini
[2003/07/04 03:25:39 | 00,000,128 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2003/07/04 03:25:38 | 00,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2003/07/04 03:25:19 | 00,037,727 | ---- | C] () -- C:\WINDOWS\System32\Emu10kx.ini
[2003/07/04 03:25:19 | 00,000,029 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2002/10/06 14:42:57 | 00,237,568 | ---- | C] () -- C:\WINDOWS\System32\OggDS.dll
[2002/08/29 04:40:50 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\dbmsadsn.dll
[2002/03/22 12:40:00 | 00,126,976 | ---- | C] ( ) -- C:\WINDOWS\System32\Interop.VSFlex7L.dll
[2001/08/23 12:00:00 | 00,000,723 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 12:00:00 | 00,000,435 | ---- | C] () -- C:\WINDOWS\system.ini
[1999/01/27 13:39:06 | 00,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 00,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== Files - Modified Within 60 Days ==========
[8 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
[2009/04/17 10:54:46 | 00,002,262 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/17 10:53:32 | 00,000,431 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.ics
[2009/04/17 10:53:19 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/17 10:53:11 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/17 10:53:05 | 53,639,9872 | -HS- | M] () -- C:\hiberfil.sys
[2009/04/10 15:22:08 | 00,024,888 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000000-00000000-0000000A-00001102-00000002-80641102}.rfx
[2009/04/10 15:22:08 | 00,024,888 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000000-00000000-0000000A-00001102-00000002-80641102}.rfx
[2009/04/10 15:22:08 | 00,016,420 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000000-00000000-0000000A-00001102-00000002-80641102}.rfx
[2009/04/10 15:22:08 | 00,016,420 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000000-00000000-0000000A-00001102-00000002-80641102}.rfx
[2009/04/10 15:22:08 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2009/04/10 15:22:08 | 00,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2009/04/10 15:22:08 | 00,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000000-00000000-0000000A-00001102-00000002-80641102}.dat
[2009/04/10 15:22:08 | 00,000,024 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000000-00000000-0000000A-00001102-00000002-80641102}.dat
[2009/04/08 22:46:39 | 00,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2009/04/08 22:46:35 | 00,227,840 | ---- | M] () -- C:\Documents and Settings\Candy\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/04/07 07:31:06 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/06 23:08:42 | 00,000,568 | ---- | M] () -- C:\Documents and Settings\Candy\My Documents\My Sharing Folders.lnk
[2009/04/06 20:39:23 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/04/05 13:35:07 | 00,000,288 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2009/04/05 08:00:37 | 00,000,314 | ---- | M] () -- C:\WINDOWS\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2009/04/04 00:03:47 | 00,015,234 | ---- | M] () -- C:\Documents and Settings\All Users\Documents\Curly Brace.bmp
[2009/04/03 16:43:06 | 00,005,893 | ---- | M] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 16-43.html
[2009/04/03 13:58:18 | 00,005,354 | ---- | M] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 13-58.html
[2009/04/03 10:44:29 | 00,003,880 | ---- | M] () -- C:\Documents and Settings\Candy\My Documents\Apr 3 2009 10-44.html
[2009/03/31 14:20:26 | 00,000,435 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/03/29 20:17:10 | 00,062,929 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/03/29 19:03:59 | 00,365,704 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.bak
[2009/03/29 12:41:49 | 00,365,704 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090329-201710.backup
[2009/03/28 23:52:16 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
[2009/03/27 23:58:05 | 00,000,600 | ---- | M] () -- C:\Documents and Settings\Candy\Local Settings\Application Data\PUTTY.RND
[2009/03/27 01:36:25 | 00,000,263 | ---- | M] () -- C:\WINDOWS\YODESK.INI
[2009/03/26 16:49:56 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/26 16:49:50 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/26 01:51:16 | 00,000,192 | ---- | M] () -- C:\WINDOWS\Winamp.ini
[2009/03/08 22:14:11 | 00,480,096 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/08 22:14:11 | 00,408,000 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/08 22:14:11 | 00,064,404 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/05 02:03:58 | 00,364,422 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090329-124149.backup
[2009/03/05 01:50:10 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/03/05 01:40:50 | 00,000,723 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/03/05 01:40:50 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/03/04 22:15:16 | 00,006,456 | -H-- | M] () -- C:\WINDOWS\System32\ruwikeyo
[2009/03/04 17:34:35 | 00,002,713 | -HS- | M] () -- C:\WINDOWS\System32\nupotuku.exe
[2009/03/04 09:20:02 | 00,364,328 | R--- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts.20090305-010358.backup
[2009/03/04 01:17:42 | 00,000,386 | ---- | M] () -- C:\WINDOWS\WININIT.INI
[2009/02/25 12:55:00 | 24,768,960 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/02/22 00:15:37 | 03,717,944 | -H-- | M] () -- C:\Documents and Settings\Candy\Local Settings\Application Data\IconCache.db
[2009/02/21 21:39:24 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/02/21 21:38:23 | 00,000,867 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2009/02/21 21:33:05 | 00,000,000 | ---- | M] () -- C:\WINDOWS\vpc32.INI
[2009/02/21 18:59:30 | 03,374,937 | ---- | M] () -- C:\WINDOWS\{00000000-00000000-0000000A-00001102-00000002-80641102}.CDF
[2009/02/21 18:59:30 | 03,374,937 | ---- | M] () -- C:\WINDOWS\{00000000-00000000-0000000A-00001102-00000002-80641102}.BAK
< End of report >
Rooter Rookit Log
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:20002 Mo/Free:279 Mo)
D:\ [Fixed] - NTFS - (Total:18159 Mo/Free:139 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Fixed] - NTFS - (Total:239366 Mo/Free:1443 Mo)
G:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
H:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
J:\ [Removable] (Total:0 Mo/Free:0 Mo)
L:\ [Removable] (Total:3886 Mo/Free:1498 Mo)
17/04/2009|11:19
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\System32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
---------- C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
---------- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
---------- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
---------- C:\Program Files\Norton AntiVirus\DefWatch.exe
---------- C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Norton AntiVirus\Rtvscan.exe
---------- C:\WINDOWS\system32\UAService7.exe
---------- C:\Program Files\UltraVNC\WinVNC.exe
---------- C:\WINDOWS\System32\wbem\unsecapp.exe
---------- C:\WINDOWS\System32\wbem\wmiprvse.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe
---------- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
---------- C:\Program Files\QuickTime\qttask.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- L:\OTListIt2.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - 31/03/2009|14:00
2 - "C:\Rooter$\Rooter_2.txt" - 31/03/2009|14:02
3 - "C:\Rooter$\Rooter_3.txt" - 31/03/2009|14:32
4 - "C:\Rooter$\Rooter_4.txt" - 02/04/2009|19:58
5 - "C:\Rooter$\Rooter_5.txt" - 03/04/2009|21:12
6 - "C:\Rooter$\Rooter_6.txt" - 05/04/2009| 0:37
7 - "C:\Rooter$\Rooter_7.txt" - 08/04/2009|22:41
8 - "C:\Rooter$\Rooter_8.txt" - 17/04/2009|11:20
----------------------\\ Scan completed at 11:20
Thanks! (And sorry if I take a day to reply - very busy life!)