Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Alureon, vundo, rootkits, fire, brimstone


  • Please log in to reply

#1
lolhalp

lolhalp

    New Member

  • Member
  • Pip
  • 1 posts
Hello and thanks in advance for helping.
I scanned an .exe file and it came up clean, so I held my breath and clicked on it. Then all [bleep] broke loose.
Various alarms sounded, things started blinking and blooping and it did the 30-sec auto-shutdown routine and rebooted.
I came here and started the pre-op treatments. Downloaded from my backup pc (this one) and saved to USB. Transferred to other pc and ran the following:

TFC - no prob
system restore- no prob
Erunt - Did its thing
Mbam - Quickscan... found about 25 items, including Alureon, Vundo and some rootkits. Removed selected.
Then did a full scan and found 1 rootkit in the system restore folder which i prompted the AV to delete.

At this point I thought I was in the clear, until I rebooted.
Default xp wallpaper comes up and desktop icons are gone. I didn't get as far as the OTlist program so I've got no log to show ya because I can't get to anything. Everything pretty much freezes once things start to load.

Once again, thanks for any assistance.

EDIT********************************************************

I was able to boot into safemode and run OTlist, here's the log-


OTListIt logfile created on: 5/28/2009 9:59:39 PM - Run 1
OTListIt2 by OldTimer - Version 2.0.15.8 Folder = C:\Documents and Settings\Dan\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 100.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 100.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 127.99 Gb Total Space | 12.16 Gb Free Space | 9.50% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
Drive E: | 104.89 Gb Total Space | 56.55 Gb Free Space | 53.91% Space Free | Partition Type: NTFS
Drive F: | 232.88 Gb Total Space | 46.63 Gb Free Space | 20.02% Space Free | Partition Type: NTFS
Drive G: | 977.47 Mb Total Space | 661.44 Mb Free Space | 67.67% Space Free | Partition Type: FAT
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive Z: | 465.76 Gb Total Space | 167.88 Gb Free Space | 36.04% Space Free | Partition Type: NTFS

Computer Name: DAN-TOPGAD2SSAV
Current User Name: Dan
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On

========== Processes (SafeList) ==========

PRC - [2009/02/05 17:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/02/05 17:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/02/05 17:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/02/05 17:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Explorer.EXE
PRC - [2009/02/05 17:08:45 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/05/28 19:26:38 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dan\Desktop\OTListIt2.exe

========== Win32 Services (SafeList) ==========

SRV - [2009/02/04 10:40:17 | 00,072,704 | ---- | M] (Adobe Systems) -- C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe -- (Adobe LM Service [Disabled | Stopped])
SRV - [2008/11/07 15:28:16 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (Apple Mobile Device [Disabled | Stopped])
SRV - [2008/07/25 12:16:40 | 00,034,312 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [Disabled | Stopped])
SRV - [2009/02/05 17:01:25 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2008/08/01 00:21:05 | 00,573,440 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\Ati2evxx.exe -- (Ati HotKey Poller [Disabled | Stopped])
SRV - [2009/02/05 17:08:40 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/02/05 17:08:26 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/02/05 17:06:04 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2008/08/29 11:18:44 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Disabled | Stopped])
SRV - [2008/07/25 12:17:02 | 00,069,632 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [Disabled | Stopped])
SRV - [2008/07/29 22:10:04 | 00,046,104 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [Disabled | Stopped])
SRV - [2009/02/28 16:50:44 | 00,133,104 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\GoogleUpdate.exe -- (gupdate1c999e63b2631c7 [Disabled | Stopped])
SRV - [2009/03/24 17:14:18 | 00,183,280 | ---- | M] (Google) -- C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe -- (gusvc [Disabled | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Disabled | Stopped])
SRV - File not found -- C:\WINDOWS\system32\Iasv32.dll -- (ias [Disabled | Stopped])
SRV - [2008/07/29 20:24:50 | 00,881,664 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2009/01/06 14:06:24 | 00,536,872 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPod Service [Disabled | Stopped])
SRV - [2009/03/09 05:19:15 | 00,152,984 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Java\jre6\bin\jqs.exe -- (JavaQuickStarterService [Disabled | Stopped])
SRV - [2008/12/16 21:59:50 | 00,150,040 | ---- | M] (Logitech Inc.) -- C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe -- (LVPrcSrv [Disabled | Stopped])
SRV - [2008/07/29 20:16:38 | 00,132,096 | ---- | M] (Microsoft Corporation) -- c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2002/11/27 07:30:30 | 00,065,536 | R--- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Disabled | Stopped])
SRV - [2009/02/13 22:27:17 | 00,066,872 | ---- | M] () -- C:\WINDOWS\system32\PnkBstrA.exe -- (PnkBstrA [Disabled | Stopped])
SRV - [2007/02/07 17:29:50 | 00,173,616 | ---- | M] () -- C:\Program Files\CyberLink\Shared files\RichVideo.exe -- (RichVideo [Disabled | Stopped])
SRV - [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Disabled | Stopped])

========== Driver Services (SafeList) ==========

DRV - [2009/05/28 18:56:44 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\5587881a.sys -- (5587881a [System | Stopped])
DRV - [2009/02/05 17:05:11 | 00,026,944 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4 [System | Running])
DRV - [2009/05/26 22:26:46 | 00,082,380 | ---- | M] (Oak Technology Inc.) -- C:\WINDOWS\System32\drivers\AFS2K.SYS -- (AFS2K [System | Running])
DRV - [2009/02/05 17:07:12 | 00,020,560 | ---- | M] (ALWIL Software) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys -- (aswFsBlk [Auto | Running])
DRV - [2009/02/05 17:08:10 | 00,094,032 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2 [Auto | Running])
DRV - [2009/02/05 17:06:10 | 00,023,152 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr [On_Demand | Running])
DRV - [2009/02/05 17:07:23 | 00,114,768 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP [System | Running])
DRV - [2009/02/05 17:06:20 | 00,051,376 | ---- | M] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi [System | Running])
DRV - [2008/08/01 02:38:20 | 03,266,560 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2008/12/17 02:02:06 | 00,023,832 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lvuvcflt.sys -- (FilterService [On_Demand | Stopped])
DRV - [2009/01/31 19:50:08 | 00,016,608 | ---- | M] (Windows ® 2000 DDK provider) -- C:\WINDOWS\gdrv.sys -- (gdrv [On_Demand | Stopped])
DRV - [2008/04/17 14:12:54 | 00,015,464 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [1996/04/03 15:33:26 | 00,005,248 | ---- | M] () -- C:\WINDOWS\system32\giveio.sys -- (giveio [Boot | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2002/11/27 07:30:30 | 00,050,960 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZid412.sys -- (HPZid412 [On_Demand | Stopped])
DRV - [2002/11/27 07:30:30 | 00,016,080 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped])
DRV - [2002/11/27 07:30:30 | 00,022,384 | R--- | M] (HP) -- C:\WINDOWS\system32\DRIVERS\HPZius12.sys -- (HPZius12 [On_Demand | Stopped])
DRV - [2001/08/17 14:06:02 | 00,154,496 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\Drivers\Icam4USB.sys -- (Icam4USB [On_Demand | Stopped])
DRV - [2008/08/27 05:22:24 | 04,754,432 | ---- | M] (Realtek Semiconductor Corp.) -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService [On_Demand | Running])
DRV - [2008/12/16 21:58:54 | 00,025,624 | ---- | M] () -- C:\WINDOWS\system32\Drivers\LVPr2Mon.sys -- (LVPr2Mon [On_Demand | Stopped])
DRV - [2008/12/17 02:00:12 | 00,768,024 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lvrs.sys -- (LVRS [On_Demand | Running])
DRV - [2008/12/17 02:01:20 | 00,041,752 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta [On_Demand | Running])
DRV - [2008/12/17 02:01:42 | 06,364,440 | ---- | M] (Logitech Inc.) -- C:\WINDOWS\system32\DRIVERS\lvuvc.sys -- (LVUVC [On_Demand | Running])
DRV - [2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy [On_Demand | Stopped])
DRV - [2007/02/27 15:31:28 | 00,021,504 | ---- | M] (Motorola) -- C:\WINDOWS\system32\DRIVERS\motmodem.sys -- (motmodem [On_Demand | Stopped])
DRV - [2009/03/16 20:20:09 | 00,047,360 | ---- | M] (VSO Software) -- C:\WINDOWS\System32\Drivers\pcouffin.sys -- (pcouffin [On_Demand | Running])
DRV - [2001/08/23 08:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2008/08/07 07:14:56 | 00,111,360 | R--- | M] (Realtek Semiconductor Corporation ) -- C:\WINDOWS\System32\DRIVERS\Rtenicxp.sys -- (RTLE8023xp [On_Demand | Running])
DRV - [2008/04/13 12:39:15 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2006/09/24 09:28:46 | 00,005,248 | ---- | M] (Windows ® 2000 DDK provider) -- C:\WINDOWS\system32\speedfan.sys -- (speedfan [Boot | Running])
DRV - [2008/11/07 15:23:30 | 00,032,000 | ---- | M] (Apple, Inc.) -- C:\WINDOWS\System32\Drivers\usbaapl.sys -- (USBAAPL [On_Demand | Stopped])
DRV - [2008/04/13 13:45:12 | 00,060,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\usbaudio.sys -- (usbaudio [On_Demand | Running])
DRV - [2006/11/02 17:51:58 | 00,013,560 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink\PowerDVD\000.fcl -- ({95808DC4-FA4A-4c74-92FE-5B863F82066B} [Auto | Running])

========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com"
FF - prefs.js..extensions.enabledItems: {9AA46F4F-4DC7-4c06-97AF-5035170633FE}:0.4.5.12
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.0.2
FF - prefs.js..extensions.enabledItems: {DDC359D1-844A-42a7-9AA1-88A850A938A8}:1.1.3
FF - prefs.js..extensions.enabledItems: [email protected]:1.1.6.2
FF - prefs.js..extensions.enabledItems: {3d7eb24f-2740-49df-8937-200b1cc08f8a}:1.5.10
FF - prefs.js..extensions.enabledItems: {0538E3E3-7E9B-4d49-8831-A227C80A7AD3}:0.9.9
FF - prefs.js..extensions.enabledItems: {44d0a1b4-9c90-4f86-ac92-8680b5d6549e}:0.6.3.11
FF - prefs.js..extensions.enabledItems: {77b819fa-95ad-4f2c-ac7c-486b356188a9}:1.5.20090207
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}:6.0.12
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}:6.0.13
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:0.9.5
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10


FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION\ [2009/01/31 11:38:57 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/01 19:01:15 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/04/28 19:41:55 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/04/28 19:41:55 | 00,000,000 | ---D | M]

[2009/01/31 13:35:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Extensions
[2009/01/31 13:35:42 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/28 17:22:27 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions
[2009/04/18 11:52:30 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{0538E3E3-7E9B-4d49-8831-A227C80A7AD3}
[2009/04/14 16:43:46 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{3d7eb24f-2740-49df-8937-200b1cc08f8a}
[2009/02/08 15:27:41 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{44d0a1b4-9c90-4f86-ac92-8680b5d6549e}
[2009/03/01 14:33:21 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/03/15 20:45:12 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{9AA46F4F-4DC7-4c06-97AF-5035170633FE}
[2009/04/15 20:14:53 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/05/08 19:25:13 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\{DDC359D1-844A-42a7-9AA1-88A850A938A8}
[2009/03/28 06:49:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\[email protected]
[2009/03/08 01:41:11 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Dan\Application Data\mozilla\Firefox\Profiles\1j7vuwni.default\extensions\[email protected]
[2009/05/28 17:22:27 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/04/28 19:41:55 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/01 19:01:21 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}
[2009/03/31 16:39:43 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
[2009/04/28 19:41:51 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/28 19:41:51 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/12/02 04:04:40 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/12/02 04:04:40 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/12/02 04:04:40 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/12/02 04:04:40 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/12/02 04:04:40 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/12/02 04:04:40 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/12/02 04:04:40 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml

O1 HOSTS File: (0 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Windows Live Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll (Google Inc.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra Button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {5C051655-FCD5-4969-9182-770EA5AA5565} http://messenger.zon...wn.cab56986.cab (Solitaire Showdown Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1233412949749 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zon...nt.cab56907.cab (MessengerStatsClient Class)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/31 10:22:00 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - * [2009/05/28 20:37:40 | 00,000,000 | ---D | M]

========== Files/Folders - Created Within 30 Days ==========

[2009/05/28 20:37:40 | 00,563,000 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Dan\Desktop\WindowsXP-KB922582-x86-ENU.exe
[2009/05/28 20:16:37 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/05/28 19:38:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dan\Application Data\Malwarebytes
[2009/05/28 19:38:56 | 00,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/28 19:38:54 | 00,040,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/28 19:38:53 | 00,019,096 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/28 19:38:53 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/05/28 19:38:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/05/28 19:36:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/05/28 19:35:53 | 00,000,611 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\NTREGOPT.lnk
[2009/05/28 19:35:53 | 00,000,592 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\ERUNT.lnk
[2009/05/28 19:35:53 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/05/28 19:30:40 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\Dan\Desktop\erunt_setup.exe
[2009/05/28 19:30:40 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dan\Desktop\OTListIt2.exe
[2009/05/28 19:30:40 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\Rooter.exe
[2009/05/28 19:30:40 | 00,264,704 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Dan\Desktop\TFC.exe
[2009/05/28 19:30:40 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\Dan\Desktop\SysRestorePoint.exe
[2009/05/28 18:49:35 | 00,000,000 | ---D | C] -- C:\Program Files\HijackThis
[2009/05/28 18:49:05 | 00,251,392 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\hijackthis_sfx.exe
[2009/05/28 17:57:00 | 00,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/28 17:51:34 | 00,000,000 | ---D | C] -- C:\WINDOWS\dhcp
[2009/05/28 17:51:30 | 00,040,448 | ---- | C] () -- C:\WINDOWS\System32\bekbn.dll
[2009/05/28 17:51:30 | 00,036,090 | ---- | C] () -- C:\WINDOWS\System32\fkas
[2009/05/28 17:51:21 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\drivers\5587881a.sys
[2009/05/28 17:51:20 | 00,000,000 | ---D | C] -- C:\Program Files\%windir%
[2009/05/28 17:51:08 | 00,000,224 | ---- | C] () -- C:\WINDOWS\System32\UACunyvsppqhkarprj.dat
[2009/05/26 22:27:18 | 00,000,386 | ---- | C] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1243391217.job
[2009/05/26 22:26:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dan\Application Data\Hewlett-Packard
[2009/05/26 22:26:49 | 00,000,669 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Memories Disc.lnk
[2009/05/26 22:24:29 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbprint.sys
[2009/05/26 22:24:29 | 00,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys
[2009/05/26 22:24:23 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\usbscan.sys
[2009/05/26 22:24:23 | 00,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys
[2009/05/26 22:18:08 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard
[2009/05/26 22:17:47 | 00,000,851 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/05/26 22:17:47 | 00,000,851 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/05/26 22:17:10 | 00,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard
[2009/05/26 22:15:36 | 00,020,724 | ---- | C] () -- C:\WINDOWS\hpoins01.dat
[2009/05/26 22:15:36 | 00,016,618 | ---- | C] () -- C:\WINDOWS\hpomdl01.dat
[2009/05/26 03:29:23 | 00,650,396 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\16596-67d.png
[2009/05/25 20:32:08 | 00,149,664 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\3150994743_ff05988f77.jpg
[2009/05/24 22:22:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Dan\Desktop\New Folder (2)
[2009/05/23 16:05:06 | 00,313,344 | ---- | C] () -- C:\Documents and Settings\Dan\My Documents\hjsplit.exe
[2009/05/17 22:46:57 | 18,356,0192 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\family.guy.716.pdtv-lol.avi
[2009/05/17 21:17:38 | 00,001,776 | ---- | C] () -- C:\Documents and Settings\Dan\Desktop\Adobe Photoshop CS2.lnk
[2009/05/16 18:27:41 | 00,001,836 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/05/15 22:19:10 | 02,567,693 | ---- | C] () -- C:\Documents and Settings\Dan\My Documents\How_to.pdf
[2009/04/04 20:54:14 | 00,081,110 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/03/03 23:17:29 | 00,000,040 | ---- | C] () -- C:\WINDOWS\nero.INI
[2009/02/13 22:27:29 | 00,139,152 | ---- | C] () -- C:\WINDOWS\System32\drivers\PnkBstrK.sys
[2009/02/01 02:15:31 | 00,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008/12/16 21:58:54 | 00,025,624 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/12/16 21:50:56 | 00,013,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\iKeyLgFT.dll
[2002/11/27 07:30:32 | 00,561,152 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2001/08/23 08:00:00 | 00,000,995 | ---- | C] () -- C:\WINDOWS\win.ini
[2001/08/23 08:00:00 | 00,000,327 | ---- | C] () -- C:\WINDOWS\system.ini
[1996/04/03 15:33:26 | 00,005,248 | ---- | C] () -- C:\WINDOWS\System32\giveio.sys

========== Files - Modified Within 30 Days ==========

[2009/05/28 21:59:09 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/28 21:59:08 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\Dan\Local Settings\desktop.ini
[2009/05/28 21:58:27 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/28 21:58:22 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\lvuvc.hs
[2009/05/28 21:58:19 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\logiflt.iad
[2009/05/28 21:54:02 | 00,000,995 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/28 21:54:02 | 00,000,327 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/28 21:54:02 | 00,000,211 | -HS- | M] () -- C:\boot.ini
[2009/05/28 21:46:49 | 00,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2009/05/28 21:46:38 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/28 20:54:36 | 00,000,882 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachine.job
[2009/05/28 20:37:40 | 00,563,000 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Dan\Desktop\WindowsXP-KB922582-x86-ENU.exe
[2009/05/28 19:49:06 | 00,508,956 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/05/28 19:49:06 | 00,432,356 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/05/28 19:49:06 | 00,067,312 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/05/28 19:38:56 | 00,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/05/28 19:35:53 | 00,000,611 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\NTREGOPT.lnk
[2009/05/28 19:35:53 | 00,000,592 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\ERUNT.lnk
[2009/05/28 19:26:38 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dan\Desktop\OTListIt2.exe
[2009/05/28 19:26:18 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\Rooter.exe
[2009/05/28 19:25:08 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\Dan\Desktop\erunt_setup.exe
[2009/05/28 19:24:18 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\Dan\Desktop\SysRestorePoint.exe
[2009/05/28 19:22:50 | 00,264,704 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dan\Desktop\TFC.exe
[2009/05/28 18:56:44 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\drivers\5587881a.sys
[2009/05/28 18:49:06 | 00,251,392 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\hijackthis_sfx.exe
[2009/05/28 18:09:52 | 00,000,224 | ---- | M] () -- C:\WINDOWS\System32\UACunyvsppqhkarprj.dat
[2009/05/28 17:57:00 | 00,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2009/05/28 17:51:30 | 00,036,090 | ---- | M] () -- C:\WINDOWS\System32\fkas
[2009/05/27 23:26:12 | 00,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2009/05/26 22:27:19 | 00,000,386 | ---- | M] () -- C:\WINDOWS\tasks\FRU Task #Hewlett-Packard#hp psc 1200 series#1243391217.job
[2009/05/26 22:26:57 | 00,020,724 | ---- | M] () -- C:\WINDOWS\hpoins01.dat
[2009/05/26 22:26:50 | 00,000,669 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Memories Disc.lnk
[2009/05/26 22:17:47 | 00,000,851 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Photo & Imaging.lnk
[2009/05/26 22:17:47 | 00,000,851 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\HP Director.lnk
[2009/05/26 13:20:08 | 00,040,160 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/05/26 13:19:56 | 00,019,096 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/05/26 03:29:24 | 00,650,396 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\16596-67d.png
[2009/05/25 20:32:08 | 00,149,664 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\3150994743_ff05988f77.jpg
[2009/05/24 22:31:37 | 00,000,040 | ---- | M] () -- C:\WINDOWS\nero.INI
[2009/05/17 21:30:00 | 18,356,0192 | ---- | M] () -- C:\Documents and Settings\Dan\Desktop\family.guy.716.pdtv-lol.avi
[2009/05/17 19:22:40 | 00,000,671 | ---- | M] () -- C:\Documents and Settings\Dan\Application Data\vso_ts_preview.xml
[2009/05/16 18:27:41 | 00,001,836 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Google Earth.lnk
[2009/05/16 14:10:19 | 00,171,008 | -HS- | M] () -- C:\Documents and Settings\Dan\My Documents\Thumbs.db
[2009/05/10 06:57:07 | 02,567,693 | ---- | M] () -- C:\Documents and Settings\Dan\My Documents\How_to.pdf

========== Alternate Data Streams ==========

@Alternate Data Stream - 141 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:05EE1EEF
< End of report >

Edited by lolhalp, 28 May 2009 - 08:18 PM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP