OTListIT.txtOTListIt logfile created on: 4/28/2009 8:26:25 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.14.0 Folder = C:\Documents and Settings\user\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.77 Gb Total Space | 112.70 Gb Free Space | 78.39% Space Free | Partition Type: NTFS
Drive D: | 5.26 Gb Total Space | 0.68 Gb Free Space | 12.97% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HACKS
Current User Name: user
Logged in as Administrator.
Current Boot Mode: SafeMode with Networking
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ========== PRC - c:\program Files\ThunMail\testabd.exe File not found
PRC - C:\WINDOWS\system32\tpsaxyd.exe (65.38.43.234)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.)
PRC - C:\WINDOWS\system32\3361\SVCHOST.exe (All)
PRC - C:\Documents and Settings\user\Local Settings\Temp\732249922.exe ()
PRC - C:\WINDOWS\System32\reader_s.exe (Microsoft Corporation)
PRC - C:\WINDOWS\sysguard.exe (?????????? ??????????)
PRC - C:\WINDOWS\system32\dncyool64.sys (sdmggt)
PRC - C:\Documents and Settings\user\Desktop\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ========== SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ccEvtMgr [Auto | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe (Symantec Corporation)
SRV - (ccProxy [Auto | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\ccProxy.exe (Symantec Corporation)
SRV - (ccPwdSvc [On_Demand | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe (Symantec Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (iPodService [On_Demand | Stopped]) -- C:\Program Files\iPod\bin\iPodService.exe (Apple Computer, Inc.)
SRV - (MDM [Auto | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE (Microsoft Corporation)
SRV - (navapsvc [Auto | Stopped]) -- c:\Program Files\Norton AntiVirus\navapsvc.exe (Symantec Corporation)
SRV - (NPFMntor [Auto | Stopped]) -- c:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe (Symantec Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (SAVScan [Disabled | Stopped]) -- c:\Program Files\Norton AntiVirus\SAVScan.exe (Symantec Corporation)
SRV - (SNDSrvc [On_Demand | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (Symantec Corporation)
SRV - (SPBBCSvc [On_Demand | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe (Symantec Corporation)
SRV - (SymWSC [Auto | Stopped]) -- c:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe (Symantec Corporation)
SRV - (UMWdf [Auto | Stopped]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (msncache [Auto | Stopped]) -- C:\WINDOWS\system32\msncache.dll (2.6.0.5)
SRV - (sopidkc [Auto | Stopped]) -- C:\WINDOWS\system32\sopidkc.exe (65.543.235.12)
SRV - (6to4 [Auto | Stopped]) -- C:\WINDOWS\system32\6to4v32.dll ()
SRV - (DhcpSrv [Auto | Stopped]) -- C:\WINDOWS\dhcp\svchost.exe ()
========== Driver Services (SafeList) ========== DRV - (AgereSoftModem [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\AGRSM.sys (Agere Systems)
DRV - (GEARAspiWDM [On_Demand | Running]) -- C:\WINDOWS\SYSTEM32\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (HDAudBus [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys (Windows ® Server 2003 DDK provider)
DRV - (ialm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ialmnt5.sys (Intel Corporation)
DRV - (IntcAzAudAddService [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (Iviaspi [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\iviaspi.sys (InterVideo, Inc.)
DRV - (NAVENG [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\VirusDefs\20041006.020\NAVEX15.SYS (Symantec Corporation)
DRV - (nv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (Pfc [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pfc.sys (Padus, Inc.)
DRV - (protect [Boot | Stopped]) -- C:\WINDOWS\System32\drivers\protect.sys ()
DRV - (Ps2 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\PS2.sys (Hewlett-Packard Company)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (restore [On_Demand | Stopped]) -- C:\WINDOWS\System32\Restore [2009/04/25 17:44:00 | 00,000,000 | ---D | M]
DRV - (rtl8139 [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\R8139n51.SYS (Realtek Semiconductor Corporation )
DRV - (SAVRT [On_Demand | Stopped]) -- c:\Program Files\Norton AntiVirus\SAVRT.SYS (Symantec Corporation)
DRV - (SAVRTPEL [Auto | Stopped]) -- c:\Program Files\Norton AntiVirus\SAVRTPEL.SYS (Symantec Corporation)
DRV - (SiS315 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\sisgrp.sys (Silicon Integrated Systems Corporation)
DRV - (SISAGP [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\SISAGPX.sys (Silicon Integrated Systems Corporation)
DRV - (SiSkp [System | Stopped]) -- C:\WINDOWS\system32\DRIVERS\srvkp.sys (Silicon Integrated Systems Corporation)
DRV - (SPBBCDrv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SymEvent [On_Demand | Stopped]) -- C:\WINDOWS\System32\drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMIDSCO [On_Demand | Stopped]) -- C:\Program Files\Common Files\Symantec Shared\SymcData\idsdefs\20040813.178\SymIDSCo.sys (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Stopped]) -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (viaagp1 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viagfx [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\vtmini.sys (Copyright © VIA/S3 Graphics Co, Ltd.)
DRV - (qtkab87 [System | Stopped]) -- C:\WINDOWS\System32\drivers\qtkab87.sys ()
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch =
http://ie.search.msn...st/srchcust.htmIE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://ie.search.msn...st/srchasst.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft...amp;ar=iesearchIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft...p...&ar=msnhomeIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..extensions.enabledItems: {1B04D445-8137-4F0A-AC44-8B6D466C435C}:1.0
FF - prefs.js..extensions.enabledItems: {8396A770-0CE6-4596-8D07-F89D64B526BB}:1.0
FF - prefs.js..extensions.enabledItems: {B13721C7-F507-4982-B2E5-502A71474FED}:2.2.0.102
FF - prefs.js..extensions.enabledItems: {DB4D516B-67C5-48EE-90A2-EF6E43183423}:1.0
FF - prefs.js..extensions.enabledItems: {E33DE41D-572C-4388-BABF-8550E62D3F96}:1.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 15:31:10 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 15:31:10 | 00,000,000 | ---D | M]
[2009/04/26 21:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Extensions
[2009/04/26 21:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/04/26 21:00:56 | 00,000,000 | ---D | M] -- C:\Documents and Settings\user\Application Data\mozilla\Firefox\Profiles\wpggbgvk.default\extensions
[2009/04/28 20:12:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/25 10:43:09 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{1B04D445-8137-4F0A-AC44-8B6D466C435C}
[2009/04/25 12:51:07 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{8396A770-0CE6-4596-8D07-F89D64B526BB}
[2009/04/28 15:31:10 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/01/19 23:30:47 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}
[2009/04/25 11:26:51 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{DB4D516B-67C5-48EE-90A2-EF6E43183423}
[2009/04/25 11:53:28 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{E33DE41D-572C-4388-BABF-8550E62D3F96}
[2009/04/28 15:31:07 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 15:31:07 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/10/29 23:00:50 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/10/29 23:00:50 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/10/29 23:00:50 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/10/29 23:00:50 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/10/29 23:00:50 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/10/29 23:00:50 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/10/29 23:00:50 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (181 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.65.122 browser-security.microsoft.com
O1 - Hosts: 91.212.65.122 antiwareprotect.com
O1 - Hosts: 91.212.65.122 www.antiwareprotect.com
O1 - Hosts: 127.0.0.1 microsoft.com
O2 - BHO: (C:\WINDOWS\system32\kjsdiowq8oikf.dll) - {B2BA40A2-74F0-42BD-F434-12345A2C8953} - C:\WINDOWS\system32\kjsdiowq8oikf.dll ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.)
O4 - HKLM..\Run: [reader_s] C:\WINDOWS\System32\reader_s.exe (Microsoft Corporation)
O4 - HKLM..\Run: [RRT-Auto] C:\Documents and Settings\user\Desktop\RRT\RRT.exe auto File not found
O4 - HKLM..\Run: [svchost.exe] "C:\WINDOWS\system32\3361\SVCHOST.exe" (All)
O4 - HKCU..\Run: [Diagnostic Manager] C:\DOCUME~1\user\LOCALS~1\Temp\732249922.exe ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKLM..\RunOnce: [svchost.exe] "C:\WINDOWS\system32\3361\SVCHOST.exe" (All)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoFolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000 (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\ntos.exe) - C:\WINDOWS\system32\ntos.exe [FILE handle not seen by OS]
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINDOWS\system32\igfxsrvc.dll (Intel Corporation)
O22 - SharedTaskScheduler: {B2BA40A2-74F0-42BD-F434-12345A2C8953} - jso8joigm409gopgmrlgd - C:\WINDOWS\system32\kjsdiowq8oikf.dll ()
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - Autorun File - C:\AUTOEXEC.BAT () - [ NTFS ]
O32 - Autorun File - D:\AUTOEXEC.BAT () - [ FAT32 ]
O32 - Autorun File - D:\AUTORUN.FCB () - [ FAT32 ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ========== [181 C:\*.tmp files]
[27 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/04/28 20:13:41 | 00,523,264 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/04/28 20:12:12 | 00,114,419 | ---- | C] () -- C:\Documents and Settings\user\Desktop\error1.JPG
[2009/04/28 20:11:37 | 00,113,724 | ---- | C] () -- C:\Documents and Settings\user\Desktop\error2.JPG
[2009/04/28 20:11:06 | 01,440,054 | ---- | C] () -- C:\Documents and Settings\user\Desktop\error1.bmp
[2009/04/28 19:56:59 | 00,010,752 | ---- | C] () -- C:\WINDOWS\System32\iehelper.dll
[2009/04/28 19:56:41 | 00,314,384 | ---- | C] (?????????? ??????????) -- C:\WINDOWS\sysguard.exe
[2009/04/28 19:56:23 | 00,032,768 | ---- | C] () -- C:\svn.exe
[2009/04/28 19:56:22 | 00,382,976 | ---- | C] () -- C:\FWSb.exe
[2009/04/28 19:49:58 | 00,018,944 | -H-- | C] () -- C:\WINDOWS\System32\drivers\protect.sys
[2009/04/28 19:49:50 | 00,017,376 | ---- | C] () -- C:\WINDOWS\System32\drivers\qtkab87.sys
[2009/04/28 15:33:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\gmer
[2009/04/28 15:28:45 | 00,246,272 | ---- | C] (65.38.43.234) -- C:\WINDOWS\System32\tpsaxyd.exe
[2009/04/28 15:28:45 | 00,036,864 | ---- | C] (wixdjmajfojh) -- C:\WINDOWS\System32\dpcxool64.sys
[2009/04/28 15:28:45 | 00,000,008 | ---- | C] () -- C:\WINDOWS\System32\comsa32.sys
[2009/04/28 07:29:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Desktop\S
[2009/04/28 07:28:45 | 00,041,984 | ---- | C] (Doug Knox) -- C:\Documents and Settings\user\Desktop\SysRestorePoint.exe
[2009/04/27 17:38:52 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/04/27 17:38:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Malwarebytes
[2009/04/27 16:34:15 | 00,000,000 | ---D | C] -- C:\!KillBox
[2009/04/27 16:24:49 | 00,000,000 | ---D | C] -- C:\Program Files\Hijackthis!
[2009/04/27 15:54:27 | 00,000,000 | ---D | C] -- C:\Program Files\internet explorer
[2009/04/27 15:48:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Adobe
[2009/04/27 15:48:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\My Documents\My eBooks
[2009/04/27 15:45:06 | 00,016,244 | ---- | C] () -- C:\WINDOWS\System32\rrt_is.wav
[2009/04/27 15:45:06 | 00,007,302 | ---- | C] () -- C:\WINDOWS\System32\rrt_vf.wav
[2009/04/27 15:45:06 | 00,007,148 | ---- | C] () -- C:\WINDOWS\System32\rrt_tv.wav
[2009/04/27 15:45:06 | 00,006,282 | ---- | C] () -- C:\WINDOWS\System32\rrt_tn.wav
[2009/04/27 15:35:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage
[2009/04/26 21:10:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Macromedia
[2009/04/26 21:10:03 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Adobe
[2009/04/26 21:00:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Mozilla
[2009/04/26 21:00:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Mozilla
[2009/04/26 21:00:28 | 00,000,658 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Shortcut to firefox.lnk
[2009/04/26 20:57:52 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\kjsdiowq8oikf.dll
[2009/04/26 20:57:34 | 00,036,352 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
[2009/04/26 20:57:17 | 00,822,152 | -H-- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\IconCache.db
[2009/04/26 20:57:17 | 00,002,235 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Help and Support.lnk
[2009/04/26 20:57:17 | 00,001,527 | ---- | C] () -- C:\Documents and Settings\user\Desktop\Notepad.lnk
[2009/04/26 20:57:17 | 00,000,128 | ---- | C] () -- C:\Documents and Settings\user\Local Settings\Application Data\fusioncache.dat
[2009/04/26 20:57:17 | 00,000,084 | -HS- | C] () -- C:\Documents and Settings\user\Start Menu\Programs\Startup\desktop.ini
[2009/04/26 20:57:17 | 00,000,076 | -HS- | C] () -- C:\Documents and Settings\user\My Documents\desktop.ini
[2009/04/26 20:57:17 | 00,000,062 | -HS- | C] () -- C:\Documents and Settings\user\Application Data\desktop.ini
[2009/04/26 20:57:16 | 00,000,000 | --SD | C] -- C:\Documents and Settings\user\Application Data\Microsoft
[2009/04/26 20:57:16 | 00,000,000 | R--D | C] -- C:\Documents and Settings\user\My Documents\My Videos
[2009/04/26 20:57:16 | 00,000,000 | R--D | C] -- C:\Documents and Settings\user\My Documents\My Pictures
[2009/04/26 20:57:16 | 00,000,000 | R--D | C] -- C:\Documents and Settings\user\My Documents\My Music
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Microsoft
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\ApplicationHistory
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\Apple Computer
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142030}
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Symantec
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Sun
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Sonic
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\SampleView
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Real
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Intervideo
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Identities
[2009/04/26 20:57:16 | 00,000,000 | ---D | C] -- C:\Documents and Settings\user\Application Data\Apple Computer
[2009/04/26 20:31:44 | 00,000,000 | ---D | C] -- C:\Program Files\Free RAR Extract Frog
[2009/04/26 20:16:12 | 00,000,000 | ---D | C] -- C:\Program Files\Exterminate It!
[2009/04/26 19:59:11 | 00,108,336 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MSWINSCK.OCX
[2009/04/26 19:59:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\3361
[2009/04/26 19:59:08 | 00,000,000 | ---D | C] -- C:\WINDOWS\dhcp
[2009/04/26 11:55:47 | 02,180,480 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe
[2009/04/26 11:55:47 | 02,015,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe
[2009/04/26 11:55:46 | 02,136,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe
[2009/04/26 11:55:46 | 02,057,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe
[2009/04/26 11:55:15 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood.Tmp
[2009/04/26 11:54:18 | 00,351,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpsp3res.dll
[2009/04/26 09:10:37 | 00,015,000 | ---- | C] () -- C:\WINDOWS\System32\jksahfo93wjfkd.dll
[2009/04/26 08:26:51 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall
[2009/04/26 08:26:50 | 00,026,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe
[2009/04/26 08:19:48 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution
[2009/04/25 23:09:23 | 24,921,544 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/04/25 18:51:47 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/25 18:51:47 | 00,000,704 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/25 18:51:43 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/25 18:35:40 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/04/25 18:16:54 | 00,000,286 | ---- | C] () -- C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/25 18:10:14 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/04/25 18:09:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang
[2009/04/25 18:06:46 | 00,001,697 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Install Quicken New User Edition.lnk
[2009/04/25 18:06:46 | 00,001,641 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Install Game Channel.lnk
[2009/04/25 18:06:06 | 00,021,060 | ---- | C] (InterVideo, Inc.) -- C:\WINDOWS\System32\drivers\iviaspi.sys
[2009/04/25 18:00:33 | 00,221,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wmpns.dll
[2009/04/25 17:55:31 | 00,059,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2009/04/25 17:55:24 | 00,012,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\mouhid.sys
[2009/04/25 17:55:23 | 00,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\splitter.sys
[2009/04/25 17:55:22 | 00,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wdmaud.sys
[2009/04/25 17:55:21 | 00,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\DMusic.sys
[2009/04/25 17:55:18 | 00,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\swmidi.sys
[2009/04/25 17:55:17 | 00,142,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\aec.sys
[2009/04/25 17:55:16 | 00,171,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\kmixer.sys
[2009/04/25 17:55:16 | 00,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmkaud.sys
[2009/04/25 17:55:15 | 00,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\sysaudio.sys
[2009/04/25 17:55:14 | 00,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSKSSRV.sys
[2009/04/25 17:55:13 | 00,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSPQM.sys
[2009/04/25 17:55:12 | 00,031,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbccgp.sys
[2009/04/25 17:55:12 | 00,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\MSPCLOCK.sys
[2009/04/25 17:55:10 | 00,026,496 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\USBSTOR.SYS
[2009/04/25 17:55:07 | 00,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\hidusb.sys
[2009/04/25 17:55:03 | 00,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax
[2009/04/25 17:55:03 | 00,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys
[2009/04/25 17:55:03 | 00,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll
[2009/04/25 17:54:34 | 00,061,056 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ohci1394.sys
[2009/04/25 17:54:34 | 00,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\enum1394.sys
[2009/04/25 17:54:33 | 00,053,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\1394bus.sys
[2009/04/25 17:37:18 | 00,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache
[2009/04/25 13:59:05 | 00,007,168 | -HS- | C] () -- C:\WINDOWS\Thumbs.db
[2009/04/25 13:31:24 | 00,000,000 | -HSD | C] -- C:\Config.Msi
[2009/04/25 10:45:30 | 00,000,000 | ---- | C] () -- C:\WINDOWS\mqcd.dbt
[2009/04/25 10:44:56 | 00,000,000 | RHSD | C] -- C:\Program Files\ThunMail
[2009/04/25 10:44:51 | 00,000,434 | ---- | C] () -- C:\WINDOWS\tasks\At1.job
[2009/04/25 10:44:50 | 00,000,001 | ---- | C] () -- C:\WINDOWS\9g2234wesdf3dfgjf23
[2009/04/25 10:44:36 | 00,175,104 | ---- | C] (kgqlcwbpci Corporation) -- C:\xptfh.exe
[2009/04/25 10:44:32 | 00,043,520 | ---- | C] () -- C:\pdtivk.exe
[2009/04/25 10:44:27 | 00,000,002 | ---- | C] () -- C:\-1935368898
[2009/04/25 10:44:26 | 00,031,232 | ---- | C] () -- C:\celkadaa.exe
[2009/04/25 10:44:22 | 00,290,304 | ---- | C] () -- C:\kggi.exe
[2009/04/24 18:59:31 | 00,000,000 | ---D | C] -- C:\Program Files\nygreen.net
[2009/04/24 18:58:23 | 00,000,000 | ---D | C] -- C:\Program Files\Mind Compression
[2009/04/20 19:34:51 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Synchronization Services
[2009/04/20 19:29:03 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft Visual Studio 9.0
[2009/04/20 19:28:04 | 00,000,000 | ---D | C] -- C:\Program Files\Microsoft SDKs
[2009/04/20 19:23:41 | 00,000,000 | ---D | C] -- C:\2fdb6db04d66e1b892e5351b2597b275
[2009/04/10 12:10:55 | 00,000,000 | ---D | C] -- C:\Program Files\MagicDVDRipper
[2009/04/10 11:49:08 | 00,000,000 | ---D | C] -- C:\Program Files\uTorrent
[2009/04/10 11:35:10 | 00,000,000 | ---D | C] -- C:\Program Files\ImgBurn
[2009/04/10 11:34:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2009/04/10 11:34:54 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
[2009/04/09 20:02:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Software
[2009/04/09 20:02:43 | 00,000,000 | ---D | C] -- C:\Program Files\NCH Software
[2009/04/09 20:01:57 | 00,000,000 | ---D | C] -- C:\Program Files\DVD Decrypter
[2008/11/12 23:19:46 | 00,000,056 | ---- | C] () -- C:\WINDOWS\wb.ini
[2004/10/28 19:21:46 | 00,019,968 | ---- | C] () -- C:\WINDOWS\System32\6to4v32.dll
[2004/10/28 19:21:38 | 00,081,920 | ---- | C] () -- C:\WINDOWS\System32\ieencode.dll
[2004/10/22 03:16:20 | 00,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2004/10/21 23:09:10 | 00,013,948 | ---- | C] () -- C:\WINDOWS\System32\CHODDI.SYS
[2004/10/21 23:08:58 | 00,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2004/10/21 22:57:10 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2004/10/21 22:38:10 | 00,204,800 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeW7.dll
[2004/10/21 22:38:10 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeA6.dll
[2004/10/21 22:38:10 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeP6.dll
[2004/10/21 22:38:10 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\IVIresizeM6.dll
[2004/10/21 22:38:10 | 00,188,416 | ---- | C] () -- C:\WINDOWS\System32\IVIresizePX.dll
[2004/10/21 22:38:10 | 00,020,480 | ---- | C] () -- C:\WINDOWS\System32\IVIresize.dll
[2004/10/21 22:18:25 | 00,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2004/10/21 22:05:35 | 00,192,512 | ---- | C] () -- C:\WINDOWS\System32\RTCOMDLL.dll
[2004/10/21 22:05:35 | 00,156,160 | ---- | C] () -- C:\WINDOWS\System32\RTLCPAPI.dll
[2004/10/21 21:28:28 | 00,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2004/10/21 21:28:28 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2004/10/21 21:27:01 | 00,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2004/10/21 21:13:11 | 00,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/10/21 20:48:55 | 00,000,572 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2004/10/21 20:48:09 | 00,000,573 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/10/21 20:47:59 | 00,000,231 | ---- | C] () -- C:\WINDOWS\system.ini
[2004/09/13 23:35:56 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/08/20 03:14:46 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2004/08/20 03:14:46 | 00,065,536 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2004/08/13 19:00:18 | 00,182,912 | ---- | C] () -- C:\WINDOWS\System32\drivers\symndis.sys
[2004/08/03 14:00:00 | 00,000,006 | ---- | C] () -- C:\WINDOWS\System32\FInstall.sys
[2003/04/10 23:04:00 | 00,028,672 | ---- | C] () -- C:\WINDOWS\System32\JAWTAccessBridge.dll
[2003/01/07 22:05:08 | 00,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2002/03/16 17:00:00 | 00,007,420 | ---- | C] () -- C:\WINDOWS\UA000106.DLL
========== Files - Modified Within 30 Days ========== [181 C:\*.tmp files]
[27 C:\WINDOWS\System32\*.tmp files]
[2 C:\WINDOWS\*.tmp files]
[2009/04/29 01:34:39 | 00,246,272 | ---- | M] (65.38.43.234) -- C:\WINDOWS\System32\tpsaxyd.exe
[2009/04/29 01:30:43 | 00,036,864 | ---- | M] (wixdjmajfojh) -- C:\WINDOWS\System32\dpcxool64.sys
[2009/04/28 20:13:42 | 00,523,264 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\user\Desktop\OTListIt2.exe
[2009/04/28 20:12:12 | 00,114,419 | ---- | M] () -- C:\Documents and Settings\user\Desktop\error1.JPG
[2009/04/28 20:11:37 | 00,113,724 | ---- | M] () -- C:\Documents and Settings\user\Desktop\error2.JPG
[2009/04/28 20:11:06 | 01,440,054 | ---- | M] () -- C:\Documents and Settings\user\Desktop\error1.bmp
[2009/04/28 19:59:37 | 00,000,181 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/04/28 19:56:59 | 00,010,752 | ---- | M] () -- C:\WINDOWS\System32\iehelper.dll
[2009/04/28 19:56:23 | 00,314,384 | ---- | M] (?????????? ??????????) -- C:\WINDOWS\sysguard.exe
[2009/04/28 19:56:23 | 00,032,768 | ---- | M] () -- C:\svn.exe
[2009/04/28 19:56:22 | 00,382,976 | ---- | M] () -- C:\FWSb.exe
[2009/04/28 19:49:58 | 00,036,352 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\reader_s.exe
[2009/04/28 19:49:58 | 00,018,944 | -H-- | M] () -- C:\WINDOWS\System32\drivers\protect.sys
[2009/04/28 19:49:50 | 00,017,376 | ---- | M] () -- C:\WINDOWS\System32\drivers\qtkab87.sys
[2009/04/28 15:27:50 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/04/28 07:28:46 | 00,041,984 | ---- | M] (Doug Knox) -- C:\Documents and Settings\user\Desktop\SysRestorePoint.exe
[2009/04/27 15:52:48 | 00,001,527 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Notepad.lnk
[2009/04/27 15:45:06 | 00,016,244 | ---- | M] () -- C:\WINDOWS\System32\rrt_is.wav
[2009/04/27 15:45:06 | 00,007,302 | ---- | M] () -- C:\WINDOWS\System32\rrt_vf.wav
[2009/04/27 15:45:06 | 00,007,148 | ---- | M] () -- C:\WINDOWS\System32\rrt_tv.wav
[2009/04/27 15:45:06 | 00,006,282 | ---- | M] () -- C:\WINDOWS\System32\rrt_tn.wav
[2009/04/27 15:35:48 | 00,001,158 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/04/26 21:01:40 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/04/26 21:00:28 | 00,000,658 | ---- | M] () -- C:\Documents and Settings\user\Desktop\Shortcut to firefox.lnk
[2009/04/26 20:57:52 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\kjsdiowq8oikf.dll
[2009/04/26 20:57:37 | 00,182,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\ndis.sys
[2009/04/26 20:57:37 | 00,182,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndis.sys
[2009/04/26 20:52:21 | 00,441,626 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/04/26 20:52:21 | 00,382,022 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/04/26 20:52:21 | 00,053,640 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/04/26 20:51:39 | 00,000,894 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/04/26 19:59:11 | 00,108,336 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MSWINSCK.OCX
[2009/04/26 09:10:37 | 00,015,000 | ---- | M] () -- C:\WINDOWS\System32\jksahfo93wjfkd.dll
[2009/04/25 18:51:47 | 00,000,704 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/04/25 18:41:45 | 00,154,768 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/04/25 18:17:14 | 00,003,649 | ---- | M] () -- C:\WINDOWS\viassary-hp.reg
[2009/04/25 18:17:03 | 00,000,286 | ---- | M] () -- C:\WINDOWS\tasks\Easy Internet Sign-up.job
[2009/04/25 18:10:52 | 00,000,283 | RHS- | M] () -- C:\boot.ini
[2009/04/25 18:10:02 | 00,000,244 | ---- | M] () -- C:\WINDOWS\System\hpsysdrv.dat
[2009/04/25 18:07:09 | 00,000,993 | ---- | M] () -- C:\WINDOWS\System32\$winnt$.inf
[2009/04/25 17:58:49 | 00,000,213 | RHS- | M] () -- C:\BOOT.BAK
[2009/04/25 17:55:51 | 00,000,231 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/04/25 14:06:32 | 00,000,434 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2009/04/25 13:59:05 | 00,007,168 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
[2009/04/25 10:45:30 | 00,000,000 | ---- | M] () -- C:\WINDOWS\mqcd.dbt
[2009/04/25 10:44:50 | 00,000,001 | ---- | M] () -- C:\WINDOWS\9g2234wesdf3dfgjf23
[2009/04/25 10:44:43 | 00,175,104 | ---- | M] (kgqlcwbpci Corporation) -- C:\xptfh.exe
[2009/04/25 10:44:34 | 00,043,520 | ---- | M] () -- C:\pdtivk.exe
[2009/04/25 10:44:28 | 00,000,002 | ---- | M] () -- C:\-1935368898
[2009/04/25 10:44:26 | 00,031,232 | ---- | M] () -- C:\celkadaa.exe
[2009/04/25 10:44:24 | 00,290,304 | ---- | M] () -- C:\kggi.exe
[2009/04/24 18:00:00 | 00,000,422 | ---- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for Compaq_Owner.job
[2009/04/23 08:03:01 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/04/15 18:57:55 | 00,000,008 | ---- | M] () -- C:\WINDOWS\System32\comsa32.sys
[2009/04/06 15:32:54 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/04/06 15:32:46 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/04/06 07:57:26 | 24,921,544 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/04/05 12:55:05 | 00,054,156 | -H-- | M] () -- C:\WINDOWS\QTFont.qfn
========== Alternate Data Streams ========== @Alternate Data Stream - 110 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:888AFB86
< End of report >