Malwarebytes' Anti-Malware 1.36
Database version: 2167
Windows 5.1.2600 Service Pack 3
5/22/2009 4:13:10 PM
mbam-log-2009-05-22 (16-13-10).txt
Scan type: Quick Scan
Objects scanned: 84923
Time elapsed: 11 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 4
Registry Values Infected: 3
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 9
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\sk9ou0s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sk9ou0s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sk9ou0s (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\srosa (Rootkit.Bagle) -> Delete on reboot.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\german.exe (Rootkit.Bagle) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\drvsyskit (Rootkit.Bagle) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\mule_st_key (Rootkit.Bagle) -> Delete on reboot.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Documents and Settings\Elvis\Application Data\m (Trojan.Agent) -> Delete on reboot.
Files Infected:
C:\Documents and Settings\Elvis\Application Data\m\data.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Elvis\Application Data\m\list.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Elvis\Application Data\m\srvlist.oct (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Elvis\Application Data\drivers\srosa2.sys (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Elvis\Application Data\drivers\winupgro.exe (Trojan.Agent) -> Delete on reboot.
C:\WINDOWS\system32\mdelk.exe (Trojan.Spammer) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\wintems.exe (Trojan.Spammer) -> Delete on reboot.
C:\Documents and Settings\Elvis\Application Data\m\flec006.exe (Trojan.Agent) -> Delete on reboot.
C:\Documents and Settings\Elvis\Application Data\drivers\wfsintwq.sys (Rootkit.Bagle) -> Quarantined and deleted successfully.
Rooter:
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:78520 Mo/Free:420 Mo)
D:\ [Fixed] - NTFS - (Total:78528 Mo/Free:472 Mo)
E:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
F:\ [Fixed] - NTFS - (Total:238472 Mo/Free:1017 Mo)
Fri 05/22/2009|16:16
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\LEXBCES.EXE
---------- C:\WINDOWS\system32\LEXPPS.EXE
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\wdfmgr.exe
---------- C:\WINDOWS\system32\wbem\wmiprvse.exe
---------- C:\Program Files\Google\Quick Search Box\qsb.exe
---------- C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
---------- C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
---------- C:\Advanced SystemCare 3\AWC.exe
---------- C:\ICQ\ICQ.exe
---------- C:\Program Files\Portrait Displays\Pivot Software\floater.exe
---------- C:\Documents and Settings\Elvis\Application Data\drivers\winupgro.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
C:\WINDOWS\System32\ban_list.txt
C:\DOCUME~1\Elvis\APPLIC~1\drivers\srosa2.sys
C:\DOCUME~1\Elvis\APPLIC~1\drivers\wfsintwq.sys
C:\DOCUME~1\Elvis\APPLIC~1\drivers\winupgro.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\101500.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\104203.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\104718.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\105062.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\105656.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\107437.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\107859.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\108015.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\108265.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\109406.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\115062.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\115078.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\118062.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\118937.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\119343.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\119859.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\120703.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\121500.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\125781.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\126718.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\127046.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\149765.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\150312.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\167406.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\169203.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\170515.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\185812.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\188937.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\189328.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\199562.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\212437.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\213734.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\214843.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\225359.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\226437.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\226609.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\235453.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\285906.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\287515.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\288359.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\313250.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\314078.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\314562.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\330812.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\331718.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\332578.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\336359.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\338609.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\338812.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\341437.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\342656.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\343828.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\344062.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\344750.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\345656.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\347343.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\348781.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\348906.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\350625.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\351234.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\351250.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\356812.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\359500.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\360609.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\361125.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\361437.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\361781.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\362062.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\362296.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\362765.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\380750.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\540078.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\540703.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\540765.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\671421.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\673203.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\673406.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\686109.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\686937.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\687187.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\692937.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\696953.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\698734.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\699781.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\701015.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\702046.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\702109.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\88468.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\95343.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld\95390.exe
C:\DOCUME~1\Elvis\APPLIC~1\drivers\downld
C:\DOCUME~1\Elvis\APPLIC~1\drivers
==> BAGLE <==
----------------------\\ ROOTKIT !!
HKLM\SYSTEM\ControlSet001\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\ControlSet003\Enum\Root\LEGACY_SROSA
HKLM\SYSTEM\ControlSet003\Services\srosa
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_SROSA
----------------------\\ Cracks & Keygens..
C:\DOCUME~1\Elvis\Desktop\Office Xp\2003_Windows_XP_Pro_or_Office-XP_keygen_computes_unique_cd-keys.zip
1 - "C:\Rooter$\Rooter_1.txt" - Thu 03/12/2009|12:12
2 - "C:\Rooter$\Rooter_2.txt" - Thu 03/12/2009|12:13
3 - "C:\Rooter$\Rooter_3.txt" - Thu 03/12/2009|16:36
4 - "C:\Rooter$\Rooter_4.txt" - Fri 05/22/2009|16:05
5 - "C:\Rooter$\Rooter_5.txt" - Fri 05/22/2009|16:19
----------------------\\ Scan completed at 16:19
OTListit:
ent and OTListIt logfile created on: 5/22/2009 4:20:01 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Elvis\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.97 Gb Total Physical Memory | 1.49 Gb Available Physical Memory | 75.65% Memory free
3.82 Gb Paging File | 3.51 Gb Available in Paging File | 91.86% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 76.68 Gb Total Space | 60.41 Gb Free Space | 78.78% Space Free | Partition Type: NTFS
Drive D: | 76.69 Gb Total Space | 68.46 Gb Free Space | 89.27% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
Drive F: | 232.88 Gb Total Space | 140.99 Gb Free Space | 60.54% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RONALD
Current User Name: Elvis
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\system32\LEXPPS.EXE (Lexmark International, Inc.)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
PRC - C:\Program Files\Google\Quick Search Box\qsb.exe (Google Inc.)
PRC - C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\ICQ\ICQ.exe (ICQ Inc.)
PRC - C:\Program Files\Portrait Displays\Pivot Software\floater.exe ()
PRC - C:\Documents and Settings\Elvis\Application Data\drivers\winupgro.exe ()
PRC - C:\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\WINDOWS\system32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\Elvis\Desktop\OTListIt2.exe (OldTimer Tools)
PRC - C:\WINDOWS\system32\wintems.exe ()
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Disabled | Stopped]) -- C:\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (avast! Antivirus [Disabled | Stopped]) -- C:\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [Disabled | Stopped]) -- C:\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [Disabled | Stopped]) -- C:\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (DTSRVC [Auto | Running]) -- C:\Program Files\Common Files\Portrait Displays\Shared\DTSRVC.exe ()
SRV - (FontCache3.0.0.0 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe (Microsoft Corporation)
SRV - (gusvc [On_Demand | Stopped]) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (idsvc [Unknown | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LexBceS [Auto | Running]) -- C:\WINDOWS\system32\LEXBCES.EXE (Lexmark International, Inc.)
SRV - (NetTcpPortSharing [Disabled | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe (Microsoft Corporation)
SRV - (UMWdf [Auto | Running]) -- C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation)
SRV - (WinDefend [Disabled | Stopped]) -- C:\Windows Defender\MsMpEng.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV - (aeaudio [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (aslm75 [Auto | Running]) -- C:\WINDOWS\system32\drivers\aslm75.sys ()
DRV - (DCamUSBCompany [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\p35u.sys (Tekom Technologies, Inc.)
DRV - (FET5X86V [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys (VIA Technologies, Inc. )
DRV - (FETND5BV [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys (VIA Technologies, Inc. )
DRV - (FETNDIS [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\fetnd5.sys (VIA Technologies, Inc. )
DRV - (gameenum [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\gameenum.sys (Microsoft Corporation)
DRV - (giveio [Boot | Running]) -- C:\WINDOWS\system32\giveio.sys ()
DRV - (ms_mpu401 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
DRV - (pdiddcci [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\pdiddcci.sys (Portrait Displays, Inc.)
DRV - (PdiPorts [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\PdiPorts.sys (Portrait Displays, Inc.)
DRV - (Pivot [System | Running]) -- C:\WINDOWS\System32\drivers\pivot.sys (Portrait Displays, Inc.)
DRV - (pivotmou [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\pivotmou.sys (Portrait Displays, Inc.)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\PxHelp20.sys (Sonic Solutions)
DRV - (SASDIFSV [System | Running]) -- C:\SUPERAntiSpyware\SASDIFSV.SYS (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (SASENUM [On_Demand | Stopped]) -- C:\SUPERAntiSpyware\SASENUM.SYS (SuperAdBlocker, Inc.)
DRV - (SASKUTIL [System | Running]) -- C:\SUPERAntiSpyware\SASKUTIL.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (smwdm [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (speedfan [Boot | Running]) -- C:\WINDOWS\system32\speedfan.sys (Windows Ū 2000 DDK provider)
DRV - (viaagp1 [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\viaagp1.sys (VIA Technologies, Inc.)
DRV - (viagfx [On_Demand | Running]) -- C:\WINDOWS\system32\DRIVERS\vtmini.sys (Copyright Đ VIA/S3 Graphics, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.tigerdirect.com/cgi-bin/Shoppin...p;q=2,%201,%201
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "Ask.com"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.selectedEngine: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.tigerdirect.com/cgi-bin/ShoppingCart.asp?prchbcart=y&msg=0&q=1,%201,%203,%202,%202,%201,%204"
FF - prefs.js..extensions.enabledItems: anycolor.pavlos256@gmail.com:0.2.6
FF - prefs.js..extensions.enabledItems: {872A1C39-DF0B-4c8b-AD84-12BA24A3B781}:3.10.0.0
FF - prefs.js..extensions.enabledItems: {3112ca9c-de6d-4884-a869-9855de68056c}:3.1.20081127W
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.0
FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.0
FF - prefs.js..extensions.enabledItems: {7E7165E2-0767-448c-852F-5FA8714F2C37}:1.0.1
FF - prefs.js..extensions.enabledItems: {03B08592-E5B4-45ff-A0BE-C1D975458688}:0.6.0.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - HKLM\software\mozilla\Firefox\extensions\\jqs@sun.com: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/03 04:30:01 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/04/11 20:29:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\siteranker@siteranker.com: C:\PROGRAM FILES\SITERANKER\FIREFOX\ [2009/05/02 09:11:24 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{872A1C39-DF0B-4c8b-AD84-12BA24A3B781}: C:\PROGRAM FILES\DOUBLED\DESKTOP SMILEY TOOLBAR\3.10.0.11120\FFTOOLBAR [2009/05/02 09:23:23 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\MOZILLA FIREFOX\COMPONENTS [2009/05/13 21:54:18 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\MOZILLA FIREFOX\PLUGINS [2009/05/13 21:54:18 | 00,000,000 | ---D | M]
[2009/03/03 00:25:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Extensions
[2009/03/03 00:25:50 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/21 22:27:31 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions
[2009/04/07 10:01:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2009/03/15 01:28:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/03/12 13:39:08 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2009/03/15 11:08:44 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\{7E7165E2-0767-448c-852F-5FA8714F2C37}
[2009/04/07 09:38:48 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\anycolor.pavlos256@gmail.com
[2009/05/09 22:38:07 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Elvis\Application Data\mozilla\Firefox\Profiles\0u9fdn78.default\extensions\personas@christopher.beard
O1 HOSTS File: (5397 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 65.75.216.6 www.winmx.com err.winmx.com
O1 - Hosts: 205.238.40.54 www.winmx.com err.winmx.com
O1 - Hosts: 65.75.216.6 cache0.winmx.com test3201.winmx.com test3206.winmx.com
O1 - Hosts: 65.75.216.7 cache1.winmx.com test3202.winmx.com test3207.winmx.com
O1 - Hosts: 82.43.229.238 cache2.winmx.com test3203.winmx.com test3208.winmx.com
O1 - Hosts: 205.238.40.1 cache3.winmx.com test3204.winmx.com
O1 - Hosts: 205.238.40.2 cache4.winmx.com test3205.winmx.com
O1 - Hosts: 65.75.216.6 c3310.z1301.winmx.com c3310.z1302.winmx.com c3310.z1303.winmx.com c3310.z1304.winmx.com c3310.z1305.winmx.com c3310.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3311.z1301.winmx.com c3311.z1302.winmx.com c3311.z1303.winmx.com c3311.z1304.winmx.com c3311.z1305.winmx.com c3311.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3312.z1301.winmx.com c3312.z1302.winmx.com c3312.z1303.winmx.com c3312.z1304.winmx.com c3312.z1305.winmx.com c3312.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3313.z1301.winmx.com c3313.z1302.winmx.com c3313.z1303.winmx.com c3313.z1304.winmx.com c3313.z1305.winmx.com c3313.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3314.z1301.winmx.com c3314.z1302.winmx.com c3314.z1303.winmx.com c3314.z1304.winmx.com c3314.z1305.winmx.com c3314.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3315.z1301.winmx.com c3315.z1302.winmx.com c3315.z1303.winmx.com c3315.z1304.winmx.com c3315.z1305.winmx.com c3315.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3316.z1301.winmx.com c3316.z1302.winmx.com c3316.z1303.winmx.com c3316.z1304.winmx.com c3316.z1305.winmx.com c3316.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3317.z1301.winmx.com c3317.z1302.winmx.com c3317.z1303.winmx.com c3317.z1304.winmx.com c3317.z1305.winmx.com c3317.z1306.winmx.com
O1 - Hosts: 205.238.40.1 c3318.z1301.winmx.com c3318.z1302.winmx.com c3318.z1303.winmx.com c3318.z1304.winmx.com c3318.z1305.winmx.com c3318.z1306.winmx.com
O1 - Hosts: 205.238.40.2 c3319.z1301.winmx.com c3319.z1302.winmx.com c3319.z1303.winmx.com c3319.z1304.winmx.com c3319.z1305.winmx.com c3319.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3520.z1301.winmx.com c3520.z1302.winmx.com c3520.z1303.winmx.com c3520.z1304.winmx.com c3520.z1305.winmx.com c3520.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3521.z1301.winmx.com c3521.z1302.winmx.com c3521.z1303.winmx.com c3521.z1304.winmx.com c3521.z1305.winmx.com c3521.z1306.winmx.com
O1 - Hosts: 65.75.216.6 c3522.z1301.winmx.com c3522.z1302.winmx.com c3522.z1303.winmx.com c3522.z1304.winmx.com c3522.z1305.winmx.com c3522.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3523.z1301.winmx.com c3523.z1302.winmx.com c3523.z1303.winmx.com c3523.z1304.winmx.com c3523.z1305.winmx.com c3523.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3524.z1301.winmx.com c3524.z1302.winmx.com c3524.z1303.winmx.com c3524.z1304.winmx.com c3524.z1305.winmx.com c3524.z1306.winmx.com
O1 - Hosts: 65.75.216.7 c3525.z1301.winmx.com c3525.z1302.winmx.com c3525.z1303.winmx.com c3525.z1304.winmx.com c3525.z1305.winmx.com c3525.z1306.winmx.com
O1 - Hosts: 82.43.229.238 c3526.z1301.winmx.com c3526.z1302.winmx.com c3526.z1303.winmx.com c3526.z1304.winmx.com c3526.z1305.winmx.com c3526.z1306.winmx.com
O1 - Hosts: 15 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {11BF46C6-B3DE-48BD-BF70-3AD85CAB80B5} - C:\Program Files\SiteRanker\SiteRank.dll (Crawler, LLC)
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Google Dictionary Compression sdch) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll (Google Inc.)
O2 - BHO: (System Search Dispatcher) - {CDBFB47B-58A8-4111-BF95-06178DCE326D} - C:\Program Files\System Search Dispatcher\1.2.0.750\ssd.dll ()
O2 - BHO: () - {DB35C569-5624-4CFC-8043-E5139F55A073} - C:\Program Files\Crawler\Shared\CShared.dll (Crawler.com)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (&Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKLM\..\Toolbar: (Desktop Smiley Toolbar) - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - C:\Program Files\DoubleD\Desktop Smiley Toolbar\3.10.0.11120\stb0.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {00000000-0000-0000-0000-000000000000} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {5617ECA9-488D-4BA2-8562-9710B9AB78D2} - C:\Program Files\DoubleD\Desktop Smiley Toolbar\3.10.0.11120\stb0.dll ()
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Google Quick Search Box] C:\Program Files\Google\Quick Search Box\qsb.exe /autorun (Google Inc.)
O4 - HKLM..\Run: [Mirabilis ICQ] C:\ICQ\ICQNet.exe ()
O4 - HKLM..\Run: [PivotSoftware] C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe ()
O4 - HKCU..\Run: [Advanced SystemCare 3] "C:\Advanced SystemCare 3\AWC.exe" /startup (IObit)
O4 - HKCU..\Run: [ALLUpdate] "C:\ALLPlayer\ALLUpdate.exe" "sleep" ()
O4 - HKCU..\Run: [drvsyskit] C:\Documents and Settings\Elvis\Application Data\drivers\winupgro.exe ()
O4 - HKCU..\Run: [german.exe] C:\WINDOWS\system32\wintems.exe ()
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Infodelivery present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoResolveSearch = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: LinkResolveIgnoreLinkInfo = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\MICROS~1\Office10\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Crawler Smileys - {16FE352D-F643-4A81-BC61-2C051F3A757D} - C:\Program Files\Crawler\Smileys\CSmileyAX.dll (Crawler.com)
O9 - Extra Button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\ICQ\ICQ.exe (ICQ Inc.)
O9 - Extra 'Tools' menuitem : ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\ICQ\ICQ.exe (ICQ Inc.)
O9 - Extra Button: Crawler eCards - {82E2B317-7C9C-4F12-B920-AC37D928CD43} - C:\Program Files\Crawler\Smileys\CSmileyAX.dll (Crawler.com)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft....k/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} http://dlm.tools.akamai.com/dlmanager/vers...vex-2.2.4.8.cab (DLM Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdat...b?1236058644531 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {BDBDE413-7B1C-4C68-A8FF-C5B2B4090876} http://support.f-sec...m/ols/fscax.cab (F-Secure Online Scanner 3.3)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc...ash/swflash.cab (Shockwave Flash Object)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\OLE DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\Program Files\Common Files\Microsoft Shared\Web Components\10\OWC10.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - x-sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_9993303B90FE6C1D.dll (Google Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\SUPERAntiSpyware\SASWINLO.DLL - C:\SUPERAntiSpyware\SASWINLO.DLL (SUPERAntiSpyware.com)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/03/03 00:06:27 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/03/14 07:55:12 | 00,000,000 | ---D | M] - C:\Autorun -- [ NTFS ]
O32 - AutoRun File - [2007/04/15 05:57:52 | 00,000,025 | -HS- | M] () - C:\autorun.inf -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/22 16:19:21 | 00,000,000 | ---D | M]
========== Files/Folders - Created Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[13 C:\DOCUME~1\Elvis\Desktop\*.tmp files]
[2009/05/22 16:19:51 | 00,067,667 | ---- | C] () -- C:\WINDOWS\System32\wintems.exe
[2009/05/22 16:19:49 | 01,084,416 | ---- | C] () -- C:\WINDOWS\System32\drivers\down\304343.exe
[2009/05/22 16:19:46 | 00,067,667 | ---- | C] () -- C:\WINDOWS\System32\mdelk.exe
[2009/05/22 16:19:41 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\down
[2009/05/22 16:18:26 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\DOCUME~1\Elvis\Desktop\OTListIt2.exe
[2009/05/22 16:02:26 | 00,267,612 | ---- | C] () -- C:\DOCUME~1\Elvis\Desktop\Rooter.exe
[2009/05/22 15:31:24 | 00,000,620 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/05/22 15:25:07 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Elvis\Application Data\drivers
[2009/05/22 15:08:47 | 00,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ribbons.scr
[2009/05/22 15:08:37 | 00,117,248 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\Mystify.scr
[2009/05/22 15:08:27 | 00,773,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\bubbles.scr
[2009/05/22 15:08:18 | 01,263,616 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\aurora.scr
[2009/05/22 15:03:41 | 00,000,000 | ---D | C] -- C:\Program Files\Ribbons
[2009/05/22 15:03:41 | 00,000,000 | ---D | C] -- C:\Program Files\Mystify
[2009/05/22 15:03:41 | 00,000,000 | ---D | C] -- C:\Program Files\Bubbles
[2009/05/22 15:03:41 | 00,000,000 | ---D | C] -- C:\Program Files\Aurora
[2009/05/22 15:01:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Ribbons
[2009/05/22 15:01:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Mystify
[2009/05/22 15:01:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Bubbles
[2009/05/22 15:01:09 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Aurora
[2009/05/16 19:49:38 | 00,000,162 | -H-- | C] () -- C:\DOCUME~1\Elvis\Desktop\~$ols And Canned Speeches Exercise.doc
[2009/05/14 17:53:05 | 25,309,75744 | ---- | C] () -- C:\DOCUME~1\Elvis\Desktop\7100.0.090421-1700_x86fre_client_en-us_retail_ultimate-grc1culfrer_en_dvd.iso
[2009/05/13 13:26:26 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe
[2009/05/13 09:15:47 | 00,000,000 | ---D | C] -- C:\WINDOWS\VistaMizer
[2009/05/11 18:45:09 | 00,176,640 | ---- | C] () -- C:\DOCUME~1\Elvis\Desktop\Tools And Canned Speeches Exercise.doc
[2009/05/10 12:35:01 | 00,000,000 | ---D | C] -- C:\Advanced SystemCare 3
[2009/05/09 19:32:53 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Elvis\Desktop\Office Xp
[2009/05/05 22:02:26 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Elvis\Application Data\Desktopicon
[2009/05/05 22:02:24 | 00,000,000 | ---D | C] -- C:\Unlocker
[2009/05/05 09:05:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Elvis\Application Data\Download Manager
[2009/05/02 09:27:28 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Elvis\Desktop\Picture Inserts
[2009/05/02 09:23:34 | 00,000,000 | ---D | C] -- C:\Program Files\System Search Dispatcher
[2009/05/02 09:23:19 | 00,000,000 | ---D | C] -- C:\Program Files\DoubleD
[2009/05/02 09:22:51 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\{1CFDD724-D742-4A0A-A374-89DBFF6ECA5F}
[2009/05/02 09:22:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Elvis\Application Data\SiteRanker
[2009/05/02 09:11:22 | 00,000,000 | ---D | C] -- C:\Program Files\SiteRanker
[2009/05/02 09:11:14 | 00,000,000 | ---D | C] -- C:\Program Files\Crawler
[2009/04/30 00:48:02 | 00,000,000 | ---D | C] -- C:\WhatsRunning
[2009/04/28 21:52:18 | 00,000,000 | ---D | C] -- C:\SpeedFan
[2009/04/28 21:52:16 | 00,000,045 | ---- | C] () -- C:\WINDOWS\System32\initdebug.nfo
[2009/04/27 09:51:38 | 00,000,000 | ---D | C] -- C:\DOCUME~1\Elvis\Desktop\GTG Files
[2009/04/24 21:12:11 | 00,000,000 | ---D | C] -- C:\EVEREST Home Edition
[2009/03/18 07:56:01 | 00,000,039 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2009/03/06 04:32:12 | 00,010,382 | -HS- | C] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/03/06 04:32:12 | 00,000,056 | RHS- | C] () -- C:\WINDOWS\System32\4F3DA9204E.sys
[2009/03/05 22:49:42 | 00,000,252 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2009/03/05 22:49:07 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxczvs.dll
[2009/03/05 22:48:39 | 00,000,270 | ---- | C] () -- C:\WINDOWS\System32\lxczcoin.ini
[2009/03/05 09:02:23 | 00,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/03/03 09:19:29 | 00,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2009/03/03 08:41:29 | 00,002,304 | ---- | C] () -- C:\WINDOWS\System32\Machnm32.sys
[2009/03/03 00:31:33 | 00,006,272 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASLM75.SYS
[2009/03/03 00:29:26 | 00,003,415 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2009/03/03 00:29:24 | 00,005,824 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/11/26 15:28:48 | 00,000,272 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2008/11/06 11:37:32 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2008/11/06 11:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2008/11/06 11:34:00 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2008/11/06 11:33:02 | 00,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2008/06/04 19:53:33 | 00,143,872 | ---- | C] () -- C:\WINDOWS\System32\swscale-0.dll
[2008/06/04 19:53:32 | 00,032,768 | ---- | C] () -- C:\WINDOWS\System32\postproc-51.dll
[2008/06/04 19:53:29 | 00,466,944 | ---- | C] () -- C:\WINDOWS\System32\JobS.dll
[2008/06/04 19:53:27 | 00,458,752 | ---- | C] () -- C:\WINDOWS\System32\avformat-51.dll
[2008/06/04 19:53:27 | 00,026,112 | ---- | C] () -- C:\WINDOWS\System32\avutil-49.dll
[2008/06/04 19:53:26 | 06,902,272 | ---- | C] () -- C:\WINDOWS\System32\avcodec-51.dll
[2004/10/26 17:39:05 | 03,375,104 | ---- | C] () -- C:\WINDOWS\System32\qt-mt331.dll
[2004/09/17 18:37:42 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\vuins32.dll
[2004/08/04 07:00:00 | 00,000,847 | ---- | C] () -- C:\WINDOWS\win.ini
[2004/08/04 07:00:00 | 00,000,256 | ---- | C] () -- C:\WINDOWS\system.ini
[2003/09/09 16:37:16 | 00,057,344 | ---- | C] () -- C:\WINDOWS\System32\avisynth_c.dll
[2002/10/15 17:54:04 | 00,153,088 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2002/05/10 20:14:33 | 00,091,136 | ---- | C] () -- C:\WINDOWS\System32\mp4fil32.dll
[1996/04/03 14:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys
========== Files - Modified Within 30 Days ==========
[4 C:\WINDOWS\System32\*.tmp files]
[4 C:\WINDOWS\*.tmp files]
[13 C:\DOCUME~1\Elvis\Desktop\*.tmp files]
[2009/05/22 16:19:51 | 01,084,416 | ---- | M] () -- C:\WINDOWS\System32\drivers\down\304343.exe
[2009/05/22 16:19:44 | 00,067,667 | ---- | M] () -- C:\WINDOWS\System32\wintems.exe
[2009/05/22 16:19:44 | 00,067,667 | ---- | M] () -- C:\WINDOWS\System32\mdelk.exe
[2009/05/22 16:19:27 | 00,508,956 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/22 16:19:27 | 00,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/22 16:19:27 | 00,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/22 16:18:37 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\DOCUME~1\Elvis\Desktop\OTListIt2.exe
[2009/05/22 16:15:27 | 00,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/22 16:15:13 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Elvis\Local Settings\desktop.ini
[2009/05/22 16:15:10 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/22 16:15:07 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/22 16:02:37 | 00,267,612 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Rooter.exe
[2009/05/22 15:31:24 | 00,000,620 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/05/22 02:14:10 | 00,000,302 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/21 15:29:57 | 00,176,640 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Tools And Canned Speeches Exercise.doc
[2009/05/16 22:29:35 | 00,019,936 | ---- | M] () -- C:\Documents and Settings\Elvis\Application Data\GDIPFONTCACHEV1.DAT
[2009/05/16 19:49:38 | 00,000,162 | -H-- | M] () -- C:\DOCUME~1\Elvis\Desktop\~$ols And Canned Speeches Exercise.doc
[2009/05/15 08:54:59 | 00,001,503 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Paint.lnk
[2009/05/15 08:54:59 | 00,000,365 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Download.lnk
[2009/05/14 22:02:37 | 00,000,252 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2009/05/14 20:57:20 | 25,309,75744 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\7100.0.090421-1700_x86fre_client_en-us_retail_ultimate-grc1culfrer_en_dvd.iso
[2009/05/14 17:44:14 | 00,001,509 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Windows Explorer.lnk
[2009/05/13 15:29:31 | 00,010,382 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/05/13 09:35:28 | 00,001,486 | ---- | M] () -- C:\DOCUME~1\Elvis\Desktop\Calculator.lnk
[2009/05/13 09:31:49 | 00,000,847 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/13 09:31:49 | 00,000,256 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/13 09:31:49 | 00,000,210 | -HS- | M] () -- C:\boot.ini
[2009/05/13 09:28:05 | 00,123,728 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/05/07 02:16:29 | 24,769,480 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mrt.exe
[2009/04/28 21:52:18 | 00,000,045 | ---- | M] () -- C:\WINDOWS\System32\initdebug.nfo
< End of report >

