What started the problem is described in this topic.
I went through the Malware Removal Guide topic, but it didn't solve the problem.
MalwareBytes Log:
Malwarebytes' Anti-Malware 1.42
Database version: 3414
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180
12/23/2009 12:16:27 AM
mbam-log-2009-12-23 (00-16-27).txt
Scan type: Quick Scan
Objects scanned: 162499
Time elapsed: 5 minute(s), 4 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
OTL Log:
OTL logfile created on: 12/23/2009 11:47:10 AM - Run 1
OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Axel\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 290.00 Mb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS2 | %ProgramFiles% = C:\Program Files
Drive C: | 69.50 Gb Total Space | 0.31 Gb Free Space | 0.45% Space Free | Partition Type: NTFS
Drive D: | 5.02 Gb Total Space | 1.18 Gb Free Space | 23.47% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 467.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AXEL2
Current User Name: Axel
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/12/23 11:44:31 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Axel\My Documents\Downloads\OTL.exe
PRC - [2009/12/02 09:17:44 | 00,908,248 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/11/24 18:51:40 | 00,081,000 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 18:51:35 | 00,138,680 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 18:51:21 | 00,254,040 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 18:48:48 | 00,352,920 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 18:43:56 | 00,018,752 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2004/08/04 07:00:00 | 01,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS2\explorer.exe
========== Modules (SafeList) ==========
MOD - [2009/12/23 11:44:31 | 00,513,536 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Axel\My Documents\Downloads\OTL.exe
MOD - [2004/08/04 07:00:00 | 01,050,624 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS2\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2009/11/24 18:51:35 | 00,138,680 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2009/11/24 18:51:21 | 00,254,040 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2009/11/24 18:48:48 | 00,352,920 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2009/11/24 18:43:56 | 00,018,752 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS2\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/12/17 23:43:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/12/17 23:43:46 | 00,000,000 | ---D | M]
[2009/12/17 23:44:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Axel\Application Data\Mozilla\Extensions
[2009/12/17 23:44:03 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Axel\Application Data\Mozilla\Firefox\Profiles\jq7b4q6u.default\extensions
[2009/12/23 08:38:02 | 00,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/08/07 18:18:03 | 00,114,688 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npmozax.dll
[2005/04/27 15:10:49 | 00,102,400 | ---- | M] (RealNetworks) -- C:\Program Files\Mozilla Firefox\plugins\npracplug.dll
O1 HOSTS File: (734 bytes) - C:\WINDOWS2\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [IMEKRMIG6.1] C:\WINDOWS2\ime\IMKR6_1\imekrmig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS2\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS2\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS2\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS2\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Axel\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 167.206.245.130 167.206.245.129
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS2\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/12/17 23:27:28 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2001/07/28 06:07:38 | 00,000,000 | ---- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2004/08/04 07:00:00 | 00,000,110 | R--- | M] () - F:\AUTORUN.INF -- [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS2\system32\ias [2009/12/18 18:41:46 | 00,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS2\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16892003295952896)
========== Files/Folders - Created Within 14 Days ==========
[2009/12/23 11:28:58 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Minidump
[2009/12/23 02:21:12 | 00,000,000 | ---D | C] -- C:\WINDOWS2\ERDNT
[2009/12/23 00:26:53 | 00,023,120 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswRdr.sys
[2009/12/23 00:26:52 | 00,048,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswTdi.sys
[2009/12/23 00:26:51 | 00,027,408 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aavmker4.sys
[2009/12/23 00:26:49 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\AvastSS.scr
[2009/12/23 00:26:49 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswFsBlk.sys
[2009/12/23 00:26:48 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswSP.sys
[2009/12/23 00:26:48 | 00,094,160 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswmon2.sys
[2009/12/23 00:26:48 | 00,093,424 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\drivers\aswmon.sys
[2009/12/23 00:26:25 | 01,280,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS2\System32\aswBoot.exe
[2009/12/23 00:03:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Malwarebytes
[2009/12/23 00:03:23 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS2\System32\drivers\mbamswissarmy.sys
[2009/12/23 00:02:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Application Data\Malwarebytes
[2009/12/23 00:02:34 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS2\System32\drivers\mbam.sys
[2009/12/22 23:45:03 | 00,000,000 | ---D | C] -- C:\WINDOWS2\ERUNTSTUFF
[2009/12/21 01:32:40 | 00,000,000 | ---D | C] -- C:\WINDOWS2\ServicePackFiles
[2009/12/18 19:10:31 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\WinRAR
[2009/12/18 18:46:05 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Prefetch
[2009/12/18 18:29:57 | 00,020,992 | ---- | C] (Realtek Semiconductor Corporation) -- C:\WINDOWS2\System32\drivers\RTL8139.sys
[2009/12/18 15:17:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Lavasoft
[2009/12/18 14:59:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\My Documents\EA Games
[2009/12/18 14:57:18 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Desktop\Mijana
[2009/12/18 03:43:54 | 00,000,000 | ---D | C] -- C:\Program Files\EA GAMES
[2009/12/18 03:27:51 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\CatRoot_bak
[2009/12/18 03:00:40 | 00,000,000 | -H-D | C] -- C:\WINDOWS2\$MSI31Uninstall_KB893803v2$
[2009/12/18 03:00:20 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\PreInstall
[2009/12/18 03:00:17 | 00,000,000 | -H-D | C] -- C:\WINDOWS2\$hf_mig$
[2009/12/18 00:51:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Macromedia
[2009/12/18 00:51:50 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Adobe
[2009/12/17 23:48:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\My Documents\Downloads
[2009/12/17 23:43:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Local Settings\Application Data\Mozilla
[2009/12/17 23:43:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Mozilla
[2009/12/17 23:42:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\My Documents\Set-up Files
[2009/12/17 23:41:11 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\SoftwareDistribution
[2009/12/17 23:38:05 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Application Data\Identities
[2009/12/17 23:38:01 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Axel\My Documents\My Pictures
[2009/12/17 23:38:01 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Axel\My Documents\My Music
[2009/12/17 23:37:55 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Axel\Application Data\Microsoft
[2009/12/17 23:37:55 | 00,000,000 | --SD | C] -- C:\Documents and Settings\Axel\Cookies
[2009/12/17 23:37:55 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Axel\SendTo
[2009/12/17 23:37:55 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Axel\Recent
[2009/12/17 23:37:55 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\Axel\Application Data
[2009/12/17 23:37:55 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Axel\Start Menu
[2009/12/17 23:37:55 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Axel\My Documents
[2009/12/17 23:37:55 | 00,000,000 | R--D | C] -- C:\Documents and Settings\Axel\Favorites
[2009/12/17 23:37:55 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Axel\Templates
[2009/12/17 23:37:55 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Axel\PrintHood
[2009/12/17 23:37:55 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Axel\NetHood
[2009/12/17 23:37:55 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Axel\Local Settings
[2009/12/17 23:37:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Local Settings\Application Data\Microsoft
[2009/12/17 23:37:55 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Axel\Desktop
[2009/12/17 23:33:07 | 00,000,000 | ---D | C] -- C:\WINDOWS2\SoftwareDistribution
[2009/12/17 23:33:05 | 00,000,000 | --SD | C] -- C:\WINDOWS2\System32\Microsoft
[2009/12/17 23:27:44 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\xircom
[2009/12/17 23:25:51 | 00,000,000 | -HSD | C] -- C:\Documents and Settings\All Users.WINDOWS2\DRM
[2009/12/17 23:25:34 | 00,000,000 | --SD | C] -- C:\WINDOWS2\Downloaded Program Files
[2009/12/17 23:25:34 | 00,000,000 | R--D | C] -- C:\WINDOWS2\Offline Web Pages
[2009/12/17 23:25:14 | 00,000,000 | -H-D | C] -- C:\Program Files\WindowsUpdate
[2009/12/17 23:24:46 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\DirectX
[2009/12/17 23:24:13 | 00,000,000 | --SD | C] -- C:\WINDOWS2\Tasks
[2009/12/17 23:24:09 | 00,000,000 | ---D | C] -- C:\WINDOWS2\srchasst
[2009/12/17 23:24:07 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\Macromed
[2009/12/17 23:23:50 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\Restore
[2009/12/17 23:23:17 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Documents\My Pictures
[2009/12/17 23:23:00 | 00,000,000 | ---D | C] -- C:\Program Files\ComPlus Applications
[2009/12/17 23:22:50 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Registration
[2009/12/17 23:22:01 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Documents\My Music
[2009/12/17 23:21:25 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\MsDtc
[2009/12/17 23:21:23 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\Com
[2009/12/17 17:51:52 | 00,606,684 | ---- | C] (LT) -- C:\WINDOWS2\System32\drivers\ltmdmnt.sys
[2009/12/17 17:44:39 | 00,000,000 | -HSD | C] -- C:\WINDOWS2\Installer
[2009/12/17 17:42:47 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Start Menu
[2009/12/17 17:42:47 | 00,000,000 | R--D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Documents
[2009/12/17 17:42:47 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Templates
[2009/12/17 17:42:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Favorites
[2009/12/17 17:42:47 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Desktop
[2009/12/17 17:42:33 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\CatRoot2
[2009/12/17 17:42:33 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\CatRoot
[2009/12/17 17:42:26 | 00,000,000 | --SD | C] -- C:\Documents and Settings\All Users.WINDOWS2\Application Data\Microsoft
[2009/12/17 17:42:26 | 00,000,000 | RH-D | C] -- C:\Documents and Settings\All Users.WINDOWS2\Application Data
[2009/12/17 17:34:19 | 00,000,000 | R-SD | C] -- C:\WINDOWS2\Fonts
[2009/12/17 17:34:19 | 00,000,000 | RHSD | C] -- C:\WINDOWS2\System32\dllcache
[2009/12/17 17:34:19 | 00,000,000 | R--D | C] -- C:\WINDOWS2\Web
[2009/12/17 17:34:19 | 00,000,000 | -H-D | C] -- C:\WINDOWS2\inf
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\WinSxS
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\wins
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\wbem
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\usmt
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\twain_32
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Temp
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\system32
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\system
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\spool
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\ShellExt
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\Setup
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\security
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Resources
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\repair
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\ras
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Provisioning
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\PeerNet
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\pchealth
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\oobe
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\npp
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\mui
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\mui
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\msapps
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\msagent
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Media
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\java
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\inetsrv
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\IME
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\ime
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\icsxml
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\ias
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Help
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\export
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\drivers\etc
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\drivers
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Driver Cache
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\drivers\disdn
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\dhcp
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Debug
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Cursors
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Connection Wizard
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\config
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\Config
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\AppPatch
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\addins
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\3com_dmi
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\3076
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\2052
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1054
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1042
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1041
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1037
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1033
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1031
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1028
[2009/12/17 17:34:19 | 00,000,000 | ---D | C] -- C:\WINDOWS2\System32\1025
[2009/12/13 11:38:06 | 00,000,000 | ---D | C] -- C:\2fdba7db7da457586f2871dafb6db562
[2009/04/10 13:11:37 | 00,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/04/10 13:11:37 | 00,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/04/10 13:11:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/04/10 13:11:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2006/01/27 18:38:41 | 00,774,144 | ---- | C] (RealNetworks, Inc.) -- C:\Program Files\RngInterstitial.dll
========== Files - Modified Within 14 Days ==========
[2009/12/23 11:43:18 | 00,000,006 | -H-- | M] () -- C:\WINDOWS2\tasks\SA.DAT
[2009/12/23 11:43:06 | 00,002,048 | --S- | M] () -- C:\WINDOWS2\bootstat.dat
[2009/12/23 11:36:15 | 01,048,576 | -H-- | M] () -- C:\Documents and Settings\Axel\NTUSER.DAT
[2009/12/23 11:36:15 | 00,000,178 | -HS- | M] () -- C:\Documents and Settings\Axel\ntuser.ini
[2009/12/23 11:28:47 | 53,642,8544 | ---- | M] () -- C:\WINDOWS2\MEMORY.DMP
[2009/12/23 00:26:53 | 00,001,720 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\avast! Antivirus.lnk
[2009/12/23 00:26:48 | 00,002,626 | ---- | M] () -- C:\WINDOWS2\System32\CONFIG.NT
[2009/12/23 00:03:25 | 00,000,707 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/22 23:44:44 | 00,000,778 | ---- | M] () -- C:\Documents and Settings\Axel\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/12/22 21:24:49 | 00,356,120 | ---- | M] () -- C:\WINDOWS2\System32\PerfStringBackup.INI
[2009/12/22 21:24:49 | 00,311,604 | ---- | M] () -- C:\WINDOWS2\System32\perfh009.dat
[2009/12/22 21:24:49 | 00,039,992 | ---- | M] () -- C:\WINDOWS2\System32\perfc009.dat
[2009/12/22 19:43:47 | 00,001,393 | ---- | M] () -- C:\WINDOWS2\imsins.BAK
[2009/12/21 10:08:43 | 00,157,160 | ---- | M] () -- C:\WINDOWS2\System32\FNTCACHE.DAT
[2009/12/21 01:29:18 | 00,002,206 | ---- | M] () -- C:\WINDOWS2\System32\wpa.dbl
[2009/12/18 18:44:39 | 00,000,314 | ---- | M] () -- C:\WINDOWS2\System32\$winnt$.inf
[2009/12/18 18:42:31 | 00,316,640 | ---- | M] () -- C:\WINDOWS2\WMSysPr9.prx
[2009/12/18 18:42:29 | 00,023,392 | ---- | M] () -- C:\WINDOWS2\System32\nscompat.tlb
[2009/12/18 18:42:29 | 00,016,832 | ---- | M] () -- C:\WINDOWS2\System32\amcompat.tlb
[2009/12/18 18:42:15 | 00,004,205 | ---- | M] () -- C:\WINDOWS2\ODBCINST.INI
[2009/12/18 18:41:06 | 00,000,488 | RH-- | M] () -- C:\WINDOWS2\System32\WindowsLogon.manifest
[2009/12/18 18:41:06 | 00,000,488 | RH-- | M] () -- C:\WINDOWS2\System32\logonui.exe.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\System32\wuaucpl.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\WindowsShell.Manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\System32\sapi.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\System32\nwc.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\System32\ncpa.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | M] () -- C:\WINDOWS2\System32\cdplayer.exe.manifest
[2009/12/18 18:40:42 | 00,000,477 | ---- | M] () -- C:\WINDOWS2\win.ini
[2009/12/18 18:40:01 | 00,022,720 | ---- | M] () -- C:\WINDOWS2\System32\emptyregdb.dat
[2009/12/18 18:37:43 | 00,000,323 | -HS- | M] () -- C:\boot.ini
[2009/12/18 18:20:57 | 00,000,231 | ---- | M] () -- C:\WINDOWS2\system.ini
[2009/12/18 16:13:26 | 06,409,336 | -H-- | M] () -- C:\Documents and Settings\Axel\Local Settings\Application Data\IconCache.db
[2009/12/18 14:42:55 | 00,237,680 | ---- | M] () -- C:\WINDOWS2\setupapi.old
[2009/12/17 23:43:59 | 00,000,000 | ---- | M] () -- C:\WINDOWS2\nsreg.dat
[2009/12/17 23:43:49 | 00,001,613 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\Mozilla Firefox.lnk
[2009/12/17 23:39:25 | 00,034,552 | ---- | M] () -- C:\Documents and Settings\Axel\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2009/12/17 23:32:43 | 00,008,192 | ---- | M] () -- C:\WINDOWS2\REGLOCS.OLD
[2009/12/17 23:27:28 | 00,000,000 | ---- | M] () -- C:\WINDOWS2\control.ini
[2009/12/17 23:27:28 | 00,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/12/17 23:22:57 | 00,000,037 | ---- | M] () -- C:\WINDOWS2\vbaddin.ini
[2009/12/17 23:22:57 | 00,000,036 | ---- | M] () -- C:\WINDOWS2\vb.ini
[2009/12/15 11:24:48 | 00,293,376 | ---- | M] () -- C:\Documents and Settings\Axel\Desktop\gmer.exe
========== Files Created - No Company Name ==========
[2009/12/23 10:45:39 | 00,293,376 | ---- | C] () -- C:\Documents and Settings\Axel\Desktop\gmer.exe
[2009/12/23 00:26:53 | 00,001,720 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\avast! Antivirus.lnk
[2009/12/23 00:26:25 | 00,380,928 | ---- | C] () -- C:\WINDOWS2\System32\actskin4.ocx
[2009/12/23 00:03:25 | 00,000,707 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/12/22 23:44:44 | 00,000,778 | ---- | C] () -- C:\Documents and Settings\Axel\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/12/22 19:41:29 | 53,642,8544 | ---- | C] () -- C:\WINDOWS2\MEMORY.DMP
[2009/12/19 20:50:02 | 01,290,752 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\quartz.dll
[2009/12/18 18:41:06 | 00,000,488 | RH-- | C] () -- C:\WINDOWS2\System32\logonui.exe.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\System32\wuaucpl.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\WindowsShell.Manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\System32\sapi.cpl.manifest
[2009/12/18 18:40:58 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\System32\ncpa.cpl.manifest
[2009/12/18 18:21:22 | 00,016,254 | ---- | C] () -- C:\WINDOWS2\System32\PINTLPAE.HLP
[2009/12/18 18:21:22 | 00,014,821 | ---- | C] () -- C:\WINDOWS2\System32\PINTLPAD.HLP
[2009/12/18 18:20:41 | 00,797,189 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\NT5IIS.CAT
[2009/12/18 18:20:41 | 00,399,645 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\MAPIMIG.CAT
[2009/12/18 18:20:41 | 00,168,806 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\startoc.cat
[2009/12/18 18:20:41 | 00,037,484 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\MW770.CAT
[2009/12/18 18:20:41 | 00,031,281 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\FP4.CAT
[2009/12/18 18:20:41 | 00,024,209 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\msn7.cat
[2009/12/18 18:20:41 | 00,013,753 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\IMS.CAT
[2009/12/18 18:20:41 | 00,013,472 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\HPCRDP.CAT
[2009/12/18 18:20:41 | 00,011,651 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\msn9.cat
[2009/12/18 18:20:41 | 00,009,581 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\MSMSGS.CAT
[2009/12/18 18:20:41 | 00,008,574 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\IASNT4.CAT
[2009/12/18 18:20:41 | 00,007,245 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\MSTSWEB.CAT
[2009/12/18 18:20:41 | 00,007,029 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\OEMBIOS.CAT
[2009/12/18 18:20:40 | 02,012,670 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\NT5.CAT
[2009/12/18 18:20:40 | 01,042,903 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\SP2.CAT
[2009/12/18 18:20:40 | 00,382,952 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\NT5INF.CAT
[2009/12/17 23:43:59 | 00,000,000 | ---- | C] () -- C:\WINDOWS2\nsreg.dat
[2009/12/17 23:43:49 | 00,001,613 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS2\Desktop\Mozilla Firefox.lnk
[2009/12/17 23:37:57 | 00,000,178 | -HS- | C] () -- C:\Documents and Settings\Axel\ntuser.ini
[2009/12/17 23:37:55 | 01,048,576 | -H-- | C] () -- C:\Documents and Settings\Axel\NTUSER.DAT
[2009/12/17 23:32:43 | 00,008,192 | ---- | C] () -- C:\WINDOWS2\REGLOCS.OLD
[2009/12/17 23:31:17 | 00,002,048 | --S- | C] () -- C:\WINDOWS2\bootstat.dat
[2009/12/17 23:27:28 | 00,002,626 | ---- | C] () -- C:\WINDOWS2\System32\CONFIG.NT
[2009/12/17 23:27:28 | 00,000,000 | ---- | C] () -- C:\AUTOEXEC.BAT
[2009/12/17 23:27:16 | 00,023,392 | ---- | C] () -- C:\WINDOWS2\System32\nscompat.tlb
[2009/12/17 23:27:16 | 00,016,832 | ---- | C] () -- C:\WINDOWS2\System32\amcompat.tlb
[2009/12/17 23:27:14 | 00,316,640 | ---- | C] () -- C:\WINDOWS2\WMSysPr9.prx
[2009/12/17 23:25:34 | 00,000,488 | RH-- | C] () -- C:\WINDOWS2\System32\WindowsLogon.manifest
[2009/12/17 23:25:23 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\System32\nwc.cpl.manifest
[2009/12/17 23:25:23 | 00,000,749 | RH-- | C] () -- C:\WINDOWS2\System32\cdplayer.exe.manifest
[2009/12/17 23:24:22 | 00,048,680 | -HS- | C] () -- C:\WINDOWS2\winnt256.bmp
[2009/12/17 23:24:22 | 00,048,680 | -HS- | C] () -- C:\WINDOWS2\winnt.bmp
[2009/12/17 23:23:15 | 00,022,720 | ---- | C] () -- C:\WINDOWS2\System32\emptyregdb.dat
[2009/12/17 23:21:42 | 00,065,954 | ---- | C] () -- C:\WINDOWS2\Prairie Wind.bmp
[2009/12/17 23:21:42 | 00,065,832 | ---- | C] () -- C:\WINDOWS2\Santa Fe Stucco.bmp
[2009/12/17 23:21:42 | 00,026,680 | ---- | C] () -- C:\WINDOWS2\River Sumida.bmp
[2009/12/17 23:21:42 | 00,017,362 | ---- | C] () -- C:\WINDOWS2\Rhododendron.bmp
[2009/12/17 23:21:42 | 00,009,522 | ---- | C] () -- C:\WINDOWS2\Zapotec.bmp
[2009/12/17 23:21:41 | 00,093,702 | ---- | C] () -- C:\WINDOWS2\System32\subrange.uce
[2009/12/17 23:21:41 | 00,065,978 | ---- | C] () -- C:\WINDOWS2\Soap Bubbles.bmp
[2009/12/17 23:21:41 | 00,026,582 | ---- | C] () -- C:\WINDOWS2\Greenstone.bmp
[2009/12/17 23:21:41 | 00,017,336 | ---- | C] () -- C:\WINDOWS2\Gone Fishing.bmp
[2009/12/17 23:21:41 | 00,017,062 | ---- | C] () -- C:\WINDOWS2\Coffee Bean.bmp
[2009/12/17 23:21:41 | 00,016,730 | ---- | C] () -- C:\WINDOWS2\FeatherTexture.bmp
[2009/12/17 23:21:41 | 00,001,272 | ---- | C] () -- C:\WINDOWS2\Blue Lace 16.bmp
[2009/12/17 23:21:40 | 00,060,458 | ---- | C] () -- C:\WINDOWS2\System32\ideograf.uce
[2009/12/17 23:21:40 | 00,024,006 | ---- | C] () -- C:\WINDOWS2\System32\gb2312.uce
[2009/12/17 23:21:40 | 00,022,984 | ---- | C] () -- C:\WINDOWS2\System32\bopomofo.uce
[2009/12/17 23:21:40 | 00,016,740 | ---- | C] () -- C:\WINDOWS2\System32\shiftjis.uce
[2009/12/17 23:21:40 | 00,012,876 | ---- | C] () -- C:\WINDOWS2\System32\korean.uce
[2009/12/17 23:21:40 | 00,008,484 | ---- | C] () -- C:\WINDOWS2\System32\kanji_2.uce
[2009/12/17 23:21:40 | 00,006,948 | ---- | C] () -- C:\WINDOWS2\System32\kanji_1.uce
[2009/12/17 23:21:38 | 00,003,286 | ---- | C] () -- C:\WINDOWS2\System32\tslabels.h
[2009/12/17 23:21:38 | 00,001,161 | ---- | C] () -- C:\WINDOWS2\System32\usrlogon.cmd
[2009/12/17 23:21:37 | 00,000,768 | ---- | C] () -- C:\WINDOWS2\System32\msdtcprf.h
[2009/12/17 23:21:32 | 00,063,488 | ---- | C] () -- C:\WINDOWS2\System32\wmimgmt.msc
[2009/12/17 17:44:44 | 00,001,393 | ---- | C] () -- C:\WINDOWS2\imsins.BAK
[2009/12/17 17:44:18 | 00,066,594 | ---- | C] () -- C:\WINDOWS2\System32\c_864.nls
[2009/12/17 17:44:18 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_708.nls
[2009/12/17 17:44:18 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\C_28596.NLS
[2009/12/17 17:44:18 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_10004.nls
[2009/12/17 17:44:16 | 00,066,594 | ---- | C] () -- C:\WINDOWS2\System32\c_862.nls
[2009/12/17 17:44:16 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_10005.nls
[2009/12/17 17:44:12 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_10021.nls
[2009/12/17 17:44:11 | 01,158,818 | ---- | C] () -- C:\WINDOWS2\System32\korwbrkr.lex
[2009/12/17 17:44:11 | 00,002,060 | ---- | C] () -- C:\WINDOWS2\System32\noise.jpn
[2009/12/17 17:44:11 | 00,001,486 | ---- | C] () -- C:\WINDOWS2\System32\noise.kor
[2009/12/17 17:44:02 | 00,211,938 | ---- | C] () -- C:\WINDOWS2\System32\lcphrase.tbl
[2009/12/17 17:44:02 | 00,146,126 | ---- | C] () -- C:\WINDOWS2\System32\array30.tab
[2009/12/17 17:44:02 | 00,110,566 | ---- | C] () -- C:\WINDOWS2\System32\arphr.tbl
[2009/12/17 17:44:02 | 00,018,600 | ---- | C] () -- C:\WINDOWS2\System32\arrayhw.tab
[2009/12/17 17:44:02 | 00,016,312 | ---- | C] () -- C:\WINDOWS2\System32\arptr.tbl
[2009/12/17 17:44:01 | 00,043,242 | ---- | C] () -- C:\WINDOWS2\System32\phoncode.tbl
[2009/12/17 17:44:01 | 00,024,114 | ---- | C] () -- C:\WINDOWS2\System32\lcptr.tbl
[2009/12/17 17:44:01 | 00,004,071 | ---- | C] () -- C:\WINDOWS2\System32\phon.tbl
[2009/12/17 17:44:01 | 00,002,714 | ---- | C] () -- C:\WINDOWS2\System32\phonptr.tbl
[2009/12/17 17:43:59 | 00,195,618 | ---- | C] () -- C:\WINDOWS2\System32\c_10002.nls
[2009/12/17 17:43:59 | 00,116,285 | ---- | C] () -- C:\WINDOWS2\System32\msdayi.tbl
[2009/12/17 17:43:59 | 00,082,172 | ---- | C] () -- C:\WINDOWS2\System32\bopomofo.nls
[2009/12/17 17:43:59 | 00,066,728 | ---- | C] () -- C:\WINDOWS2\System32\big5.nls
[2009/12/17 17:43:59 | 00,044,370 | ---- | C] () -- C:\WINDOWS2\System32\acode.tbl
[2009/12/17 17:43:59 | 00,044,370 | ---- | C] () -- C:\WINDOWS2\System32\a234.tbl
[2009/12/17 17:43:59 | 00,001,460 | ---- | C] () -- C:\WINDOWS2\System32\a15.tbl
[2009/12/17 17:43:59 | 00,000,700 | ---- | C] () -- C:\WINDOWS2\System32\dayiptr.tbl
[2009/12/17 17:43:59 | 00,000,520 | ---- | C] () -- C:\WINDOWS2\System32\dayiphr.tbl
[2009/12/17 17:43:53 | 01,223,500 | ---- | C] () -- C:\WINDOWS2\System32\WINZM.MB
[2009/12/17 17:43:52 | 01,783,864 | ---- | C] () -- C:\WINDOWS2\System32\WINPY.MB
[2009/12/17 17:43:52 | 01,564,868 | ---- | C] () -- C:\WINDOWS2\System32\WINSP.MB
[2009/12/17 17:43:52 | 00,173,602 | ---- | C] () -- C:\WINDOWS2\System32\c_10008.nls
[2009/12/17 17:43:52 | 00,083,748 | ---- | C] () -- C:\WINDOWS2\System32\prcp.nls
[2009/12/17 17:43:52 | 00,083,748 | ---- | C] () -- C:\WINDOWS2\System32\prc.nls
[2009/12/17 17:43:42 | 00,189,986 | ---- | C] () -- C:\WINDOWS2\System32\c_1361.nls
[2009/12/17 17:43:42 | 00,177,698 | ---- | C] () -- C:\WINDOWS2\System32\c_10003.nls
[2009/12/17 17:43:20 | 00,180,770 | ---- | C] () -- C:\WINDOWS2\System32\c_20932.nls
[2009/12/17 17:43:20 | 00,180,258 | ---- | C] () -- C:\WINDOWS2\System32\c_20000.nls
[2009/12/17 17:43:20 | 00,177,698 | ---- | C] () -- C:\WINDOWS2\System32\c_20949.nls
[2009/12/17 17:43:20 | 00,173,602 | ---- | C] () -- C:\WINDOWS2\System32\c_20936.nls
[2009/12/17 17:43:20 | 00,162,850 | ---- | C] () -- C:\WINDOWS2\System32\c_10001.nls
[2009/12/17 17:43:20 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_21027.nls
[2009/12/17 17:43:20 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_20290.nls
[2009/12/17 17:43:19 | 00,028,288 | ---- | C] () -- C:\WINDOWS2\System32\xjis.nls
[2009/12/17 17:43:14 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_28603.nls
[2009/12/17 17:43:13 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_28599.nls
[2009/12/17 17:43:11 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\C_28595.NLS
[2009/12/17 17:43:10 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\C_28597.NLS
[2009/12/17 17:43:08 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\C_28594.NLS
[2009/12/17 17:43:05 | 00,066,082 | ---- | C] () -- C:\WINDOWS2\System32\c_20127.nls
[2009/12/17 17:43:01 | 00,001,688 | ---- | C] () -- C:\WINDOWS2\System32\AUTOEXEC.NT
[2009/12/17 17:42:46 | 00,007,334 | ---- | C] () -- C:\WINDOWS2\System32\dllcache\wmerrenu.cat
[2009/12/17 17:42:26 | 00,237,680 | ---- | C] () -- C:\WINDOWS2\setupapi.old
[2009/12/17 17:41:53 | 00,157,160 | ---- | C] () -- C:\WINDOWS2\System32\FNTCACHE.DAT
[2009/12/17 17:40:55 | 00,000,314 | ---- | C] () -- C:\WINDOWS2\System32\$winnt$.inf
[2008/11/06 02:12:28 | 00,018,199 | ---- | C] () -- C:\Program Files\Common Files\nupunaga.bat
[2008/11/06 02:12:28 | 00,018,130 | ---- | C] () -- C:\Program Files\Common Files\jyxep.exe
[2008/11/06 02:12:28 | 00,014,676 | ---- | C] () -- C:\Program Files\Common Files\fywu._sy
[2008/11/06 02:12:28 | 00,012,197 | ---- | C] () -- C:\Program Files\Common Files\ifica.ban
[2008/11/06 02:12:27 | 00,018,506 | ---- | C] () -- C:\Program Files\Common Files\paguhyva.scr
[2008/11/06 02:12:27 | 00,010,051 | ---- | C] () -- C:\Program Files\Common Files\rukufysyg.db
[2004/08/04 07:00:00 | 00,027,440 | ---- | C] () -- C:\WINDOWS2\System32\drivers\secdrv.sys
========== LOP Check ==========
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2002/07/15 20:20:56 | 03,534,931 | ---- | M] () -- C:\0712i32.exe
[2002/07/15 20:53:56 | 03,537,441 | ---- | M] () -- C:\0715i32.exe
[2005/10/31 10:56:00 | 00,700,416 | ---- | M] (LimeWire) -- C:\StubInstaller.exe
< MD5 for: AGP440.SYS >
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\system32\drivers\agp440.sys
[2008/04/13 13:36:38 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
[2004/08/04 07:00:00 | 00,042,368 | ---- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB -- C:\WINDOWS2\system32\drivers\agp440.sys
< MD5 for: ATAPI.SYS >
[2008/04/13 13:40:30 | 00,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004/08/04 07:00:00 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
[2004/08/04 07:00:00 | 00,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS2\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 19:11:53 | 00,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
[2004/08/04 07:00:00 | 00,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS2\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/13 19:12:01 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS2\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS2\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS2\SoftwareDistribution\Download\78cf8552430e25a8f24bc1e4dfb1970e\sp2qfe\netlogon.dll
[2009/02/06 13:46:09 | 00,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS2\SoftwareDistribution\Download\de81b460c3abcfc5b8494c785a5f3944\sp2qfe\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
[2004/08/04 07:00:00 | 00,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS2\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 07:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
[2004/08/04 07:00:00 | 00,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS2\system32\scecli.dll
[2008/04/13 19:12:05 | 00,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS2\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\scecli.dll
< %systemroot%\*. /mp /s >
< End of report >
Extras Log:
OTL Extras logfile created on: 12/23/2009 11:47:10 AM - Run 1
OTL by OldTimer - Version 3.1.19.0 Folder = C:\Documents and Settings\Axel\My Documents\Downloads
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
511.00 Mb Total Physical Memory | 290.00 Mb Available Physical Memory | 57.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 79.00% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS2 | %ProgramFiles% = C:\Program Files
Drive C: | 69.50 Gb Total Space | 0.31 Gb Free Space | 0.45% Space Free | Partition Type: NTFS
Drive D: | 5.02 Gb Total Space | 1.18 Gb Free Space | 23.47% Space Free | Partition Type: FAT32
E: Drive not present or media not loaded
Drive F: | 467.06 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: AXEL2
Current User Name: Axel
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
htmlfile [edit] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" -nohome (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
========== Security Center Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS2\system32\usmt\migwiz.exe" = C:\WINDOWS2\system32\usmt\migwiz.exe:*:Enabled:Files and Settings Transfer Wizard -- (Microsoft Corporation)
========== HKEY_LOCAL_MACHINE Uninstall List ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast!" = avast! Antivirus
"ERUNT_is1" = ERUNT 1.1j
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mozilla Firefox (3.5.6)" = Mozilla Firefox (3.5.6)
"WinRAR archiver" = WinRAR archiver
========== Last 10 Event Log Errors ==========
[ System Events ]
Error - 12/18/2009 5:32:24 AM | Computer Name = AXEL2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service netman with
arguments "" in order to run the server: {BA126AE5-2166-11D1-B1D0-00805FC1270E}
Error - 12/18/2009 5:32:34 AM | Computer Name = AXEL2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
Error - 12/18/2009 5:32:58 AM | Computer Name = AXEL2 | Source = Service Control Manager | ID = 7001
Description = The DHCP Client service depends on the NetBios over Tcpip service
which failed to start because of the following error: %%31
Error - 12/18/2009 5:32:58 AM | Computer Name = AXEL2 | Source = Service Control Manager | ID = 7001
Description = The DNS Client service depends on the TCP/IP Protocol Driver service
which failed to start because of the following error: %%31
Error - 12/18/2009 5:32:58 AM | Computer Name = AXEL2 | Source = Service Control Manager | ID = 7001
Description = The TCP/IP NetBIOS Helper service depends on the AFD service which
failed to start because of the following error: %%31
Error - 12/18/2009 5:32:58 AM | Computer Name = AXEL2 | Source = Service Control Manager | ID = 7001
Description = The IPSEC Services service depends on the IPSEC driver service which
failed to start because of the following error: %%31
Error - 12/18/2009 5:32:58 AM | Computer Name = AXEL2 | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
AFD AmdK7 Fips IPSec MRxSmb NetBIOS NetBT RasAcd Rdbss Tcpip
Error - 12/18/2009 5:42:24 AM | Computer Name = AXEL2 | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}
< End of report >
I couldn't get a GMER log because when I tried running it my computer crashed (as described in the other topic).
Thanks to anyone who helps !
Edited by SardonicWhisper, 23 December 2009 - 06:13 PM.