In accord with instructions Malware and Spyware Cleaning Guide here is gmer log:
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-03-07 03:26:43
Windows 5.1.2600 Service Pack 1
Running: gmer.exe; Driver: C:\DOCUME~1\User\LOCALS~1\Temp\pgporfow.sys
---- System - GMER 1.0.15 ----
SSDT \??\C:\WINDOWS\System32\Drivers\DP.sys ZwCreateFile [0xF98AE370]
SSDT \??\C:\WINDOWS\System32\Drivers\DP.sys ZwOpenFile [0xF98AE2B0]
---- Devices - GMER 1.0.15 ----
AttachedDevice \FileSystem\Ntfs \Ntfs srntflt.sys (Xpoint UPTIME! Filter Driver/Xpoint Technologies, Inc.)
AttachedDevice \Driver\Tcpip \Device\Ip SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \Driver\Tcpip \Device\RawIp SYMTDI.SYS (Network Dispatch Driver/Symantec Corporation)
AttachedDevice \FileSystem\Fastfat \Fat srntflt.sys (Xpoint UPTIME! Filter Driver/Xpoint Technologies, Inc.)
---- Processes - GMER 1.0.15 ----
Process C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe (*** hidden *** ) 532
Library C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe (*** hidden *** ) @ C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe [532] 0x00400000
---- Services - GMER 1.0.15 ----
Service C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe (*** hidden *** ) [AUTO] Time <-- ROOTKIT !!!
Service C:\WINDOWS\System32\timedrv26.sys (*** hidden *** ) [MANUAL] WTime <-- ROOTKIT !!!
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\Time (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Minimal\Time@ Service
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Time (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Control\SafeBoot\Network\Time@ Service
Reg HKLM\SYSTEM\ControlSet002\Services\Time (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Time@Type 272
Reg HKLM\SYSTEM\ControlSet002\Services\Time@Start 2
Reg HKLM\SYSTEM\ControlSet002\Services\Time@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\Time@ImagePath C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe
Reg HKLM\SYSTEM\ControlSet002\Services\Time@DisplayName Time Service
Reg HKLM\SYSTEM\ControlSet002\Services\Time@ObjectName LocalSystem
Reg HKLM\SYSTEM\ControlSet002\Services\Time@Description Maintains date and time synchronization on all clients and servers in the network.
Reg HKLM\SYSTEM\ControlSet002\Services\Time\Security (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\Time\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\ControlSet002\Services\WTime (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\Services\WTime@ErrorControl 0
Reg HKLM\SYSTEM\ControlSet002\Services\WTime@ImagePath \??\C:\WINDOWS\System32\timedrv26.sys
Reg HKLM\SYSTEM\ControlSet002\Services\WTime@Start 3
Reg HKLM\SYSTEM\ControlSet002\Services\WTime@Type 1
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Time
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Time@ Service
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Time
Reg HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Time@ Service
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@Type 272
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@Start 2
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@ImagePath C:\WINDOWS\System32\nlkfev7pzcfjnsxch.exe
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@DisplayName Time Service
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@ObjectName LocalSystem
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time@Description Maintains date and time synchronization on all clients and servers in the network.
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time\Security
Reg HKLM\SYSTEM\CurrentControlSet\Services\Time\Security@Security 0x01 0x00 0x14 0x80 ...
Reg HKLM\SYSTEM\CurrentControlSet\Services\WTime
Reg HKLM\SYSTEM\CurrentControlSet\Services\WTime@ErrorControl 0
Reg HKLM\SYSTEM\CurrentControlSet\Services\WTime@ImagePath \??\C:\WINDOWS\System32\timedrv26.sys
Reg HKLM\SYSTEM\CurrentControlSet\Services\WTime@Start 3
Reg HKLM\SYSTEM\CurrentControlSet\Services\WTime@Type 1
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\mlsdf8haknquydin.exe 96800 bytes
File C:\WINDOWS\system32\mlsdf8hbeil.exe 87040 bytes executable
File C:\WINDOWS\system32\mlsdf8hdowaeimrwc.exe 96800 bytes
File C:\WINDOWS\system32\mlsdf8hrceimq.exe 96800 bytes
File C:\WINDOWS\system32\mlsdf8hxbgikmo.exe 96800 bytes
File C:\WINDOWS\system32\mlsdf8hxflps.exe 87040 bytes executable
File C:\WINDOWS\system32\mlsdf8hyhkoswafkq.exe 96800 bytes
File C:\WINDOWS\system32\nlkfev7dmqtxbg.exe 96800 bytes
File C:\WINDOWS\system32\nlkfev7lvzcgkpt.exe 96800 bytes
File C:\WINDOWS\system32\nlkfev7otzcgkpuze.exe 87040 bytes executable
File C:\WINDOWS\system32\nlkfev7pwzdhl.exe 87040 bytes executable
File C:\WINDOWS\system32\nlkfev7pzcfjnsxch.exe 96800 bytes <-- ROOTKIT !!!
File C:\WINDOWS\system32\nlkfev7pzcgkosxci.exe 96800 bytes
File C:\WINDOWS\system32\nlkfev7uxaeimqva.exe 87040 bytes executable
File C:\WINDOWS\system32\nlkfev7weil.exe 96800 bytes
File C:\WINDOWS\system32\sklrr7ygqtx.exe 96800 bytes
File C:\WINDOWS\system32\sklrr7yilor.exe 87040 bytes executable
File C:\WINDOWS\system32\sklrr7yilos.exe 87040 bytes executable
File C:\WINDOWS\system32\sklrr7yiosvzdim.exe 87040 bytes executable
File C:\WINDOWS\system32\sklrr7yknqtx.exe 87040 bytes executable
File C:\WINDOWS\system32\sklrr7yluxbfjnsxd.exe 96800 bytes
File C:\WINDOWS\system32\sklrr7yzcfjnrvaf.exe 87040 bytes executable
File C:\WINDOWS\system32\timedrv26.sys 4352 bytes executable <-- ROOTKIT !!!
File C:\WINDOWS\system32\dior4f4dmptxbfkp.exe 96800 bytes
File C:\WINDOWS\system32\dior4f4filpsxbg.exe 87040 bytes executable
File C:\WINDOWS\system32\dior4f4gknqu.exe 87040 bytes executable
File C:\WINDOWS\system32\dior4f4gqtxafjo.exe 96800 bytes
File C:\WINDOWS\system32\dior4f4szgjn.exe 96800 bytes
File C:\WINDOWS\system32\cjnr4r4gnqu.exe 87040 bytes executable
File C:\WINDOWS\system32\cjnr4r4isae.exe 96800 bytes
File C:\WINDOWS\system32\cjnr4r4nrsuwyad.exe 87040 bytes executable
File C:\WINDOWS\system32\cjnr4r4qtwaeimrwb.exe 87040 bytes executable
File C:\WINDOWS\system32\cjnr4r4twzd.exe 87040 bytes executable
File C:\WINDOWS\system32\cjnr4r4vfnruzd.exe 96800 bytes
File C:\WINDOWS\system32\cjnr4r4wdhkosx.exe 87040 bytes executable
File C:\WINDOWS\Temp\sklrr7y253238.exe 87552 bytes executable
File C:\WINDOWS\Temp\cjnr4r43728920.exe 87552 bytes executable
File C:\WINDOWS\Temp\dior4f4172096.exe 87552 bytes executable
File C:\Documents and Settings\michelle\Local Settings\Temp\nlkfev78105707.exe 87552 bytes executable
---- EOF - GMER 1.0.15 ----
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Malwarebytes log:
Malwarebytes' Anti-Malware 1.44
Database version: 3830
Windows 5.1.2600 Service Pack 1
Internet Explorer 6.0.2800.1106
3/7/2010 3:33:54 AM
mbam-log-2010-03-07 (03-33-54).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 143170
Time elapsed: 26 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\timedrv26.sys (Backdoor.HacDef) -> Quarantined and deleted successfully.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
OTL custom scan log:
OTL logfile created on: 3/7/2010 3:33:43 AM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = F:\virus tools
Windows XP Professional Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2800.1106)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
247.00 Mb Total Physical Memory | 70.00 Mb Available Physical Memory | 28.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 28.42 Gb Total Space | 23.14 Gb Free Space | 81.43% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 963.73 Mb Total Space | 540.28 Mb Free Space | 56.06% Space Free | Partition Type: FAT
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: IBM-D0360C6B369
Current User Name: User
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/03/07 01:55:26 | 000,553,984 | ---- | M] (OldTimer Tools) -- F:\virus tools\OTL.exe
PRC - [2010/01/07 16:07:10 | 001,394,000 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2006/08/21 17:20:55 | 000,015,360 | ---- | M] () -- C:\WINDOWS\system32\win32bootcfg.exe
PRC - [2006/08/21 14:41:04 | 000,032,768 | ---- | M] (04399289e8uwhru243y5r78f73yh3t7y3) -- C:\nwnmff_12.exe
PRC - [2006/08/21 14:41:01 | 000,098,304 | ---- | M] (*&&*#&$*#RU*#Y&*#YR&Y#&RY#R) -- C:\kybrdff_12.exe
PRC - [2006/08/19 11:28:36 | 000,159,744 | ---- | M] () -- C:\WINDOWS\system32\SIX.exe
PRC - [2006/03/16 21:04:15 | 000,075,264 | -H-- | M] () -- C:\WINDOWS\system32\zgtfxcob.exe
PRC - [2006/03/11 10:59:07 | 000,159,744 | ---- | M] () -- C:\WINDOWS\system32\MDN.exe
PRC - [2006/02/24 06:44:28 | 000,189,952 | RHS- | M] () -- C:\WINDOWS\sqlmanagement.exe
PRC - [2006/02/18 03:46:46 | 000,039,936 | ---- | M] () -- C:\WINDOWS\win32host.exe
PRC - [2006/02/07 08:11:34 | 000,023,040 | ---- | M] () -- C:\WINDOWS\update\updmgr.exe
PRC - [2006/02/07 03:48:19 | 000,091,484 | RHS- | M] () -- C:\WINDOWS\system32\vcshost.exe
PRC - [2003/04/25 16:59:00 | 000,098,304 | ---- | M] () -- C:\Program Files\Xpoint\agent\Xpagent.exe
PRC - [2003/04/25 16:58:06 | 000,831,551 | ---- | M] (Xpoint Technologies) -- C:\Program Files\Xpoint\EEClient\Xpclient.exe
PRC - [2003/04/25 16:56:48 | 000,028,672 | ---- | M] () -- C:\Program Files\Xpoint\xpadmin\xpadmin.exe
PRC - [2003/04/16 00:17:16 | 000,167,936 | ---- | M] () -- C:\Program Files\Xpoint\PE\Skin\RRPCSB.EXE
PRC - [2003/04/15 17:52:46 | 002,702,336 | ---- | M] () -- C:\Program Files\Xpoint\PE\PCRecSA.exe
PRC - [2003/04/11 16:43:00 | 000,020,549 | ---- | M] () -- C:\Program Files\Xpoint\SAS\JRE\bin\javaw.exe
PRC - [2003/04/10 03:03:10 | 000,532,480 | ---- | M] (IBM) -- C:\Program Files\IBM\Messages By IBM\ibmmessages.exe
PRC - [2002/09/21 00:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
PRC - [2002/08/29 11:41:24 | 001,004,032 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2002/08/29 11:41:24 | 000,196,096 | RHS- | M] () -- C:\WINDOWS\system32\msnmsgsm.exe
PRC - [2002/08/29 11:41:24 | 000,144,896 | RHS- | M] () -- C:\WINDOWS\system32\ddoSygate.exe
PRC - [2001/08/18 10:00:00 | 000,375,808 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cmd.exe
========== Modules (SafeList) ==========
MOD - [2010/03/07 01:55:26 | 000,553,984 | ---- | M] (OldTimer Tools) -- F:\virus tools\OTL.exe
MOD - [2002/08/29 11:41:32 | 000,921,600 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (sdktemp)
SRV - [2006/08/19 11:28:36 | 000,159,744 | ---- | M] () [Disabled | Running] -- C:\WINDOWS\System32\SIX.exe -- (Six.update.net)
SRV - [2006/03/12 18:44:54 | 000,009,609 | ---- | M] () [Auto | Running] -- C:\WINDOWS\system32\wgareg.exe -- (wgareg)
SRV - [2006/03/11 10:59:07 | 000,159,744 | ---- | M] () [Disabled | Running] -- C:\WINDOWS\System32\MDN.exe -- (MDM.update.net)
SRV - [2006/03/05 23:09:40 | 000,053,760 | RHS- | M] () [Disabled | Stopped] -- C:\WINDOWS\mnsmsgr.exe -- (€?
)
SRV - [2006/02/24 06:44:28 | 000,189,952 | RHS- | M] () [Auto | Running] -- C:\WINDOWS\sqlmanagement.exe -- (sqlmanagement)
SRV - [2006/02/18 03:46:46 | 000,039,936 | ---- | M] () [Auto | Running] -- C:\WINDOWS\win32host.exe -- (Win32Kernel)
SRV - [2006/02/07 08:11:34 | 000,023,040 | ---- | M] () [Auto | Running] -- C:\WINDOWS\update\updmgr.exe -- (UpdateManager)
SRV - [2005/07/06 10:14:12 | 000,471,040 | ---- | M] (Lexmark International, Inc.) [On_Demand | Stopped] -- C:\WINDOWS\System32\lxcecoms.exe -- (lxce_device)
SRV - [2005/04/05 19:17:22 | 000,206,552 | ---- | M] (Symantec Corporation) [On_Demand | Stopped] -- C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe -- (SNDSrvc)
SRV - [2003/04/25 17:01:34 | 000,040,960 | ---- | M] () [Auto | Stopped] -- C:\Program Files\Xpoint\PE\pcradmin.exe -- (PCRadminServer)
SRV - [2003/04/25 16:59:00 | 000,098,304 | ---- | M] () [Auto | Running] -- C:\Program Files\Xpoint\agent\Xpagent.exe -- (xpAgentServer)
SRV - [2003/04/25 16:56:48 | 000,028,672 | ---- | M] () [Auto | Running] -- C:\Program Files\Xpoint\xpadmin\xpadmin.exe -- (XPadminServer)
SRV - [2003/03/03 21:33:40 | 000,143,360 | ---- | M] (Intel® Corporation) [On_Demand | Stopped] -- C:\Program Files\Intel\NCS\Sync\NetSvc.exe -- (NetSvc)
SRV - [2002/09/21 00:50:10 | 000,045,056 | ---- | M] (Analog Devices, Inc.) [Auto | Running] -- C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe -- (SoundMAX Agent Service (default))
SRV - [2002/08/12 02:17:04 | 000,026,624 | R--- | M] () [On_Demand | Stopped] -- C:\WINDOWS\system32\Psasrv.exe -- (PsaSrv)
SRV - [2001/08/18 10:00:00 | 000,019,456 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\system32\tcpsvcs.exe -- (LPDSVC)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (WTime)
DRV - [2010/01/07 16:07:14 | 000,038,224 | ---- | M] (Malwarebytes Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys -- (MBAMSwissArmy)
DRV - [2006/03/05 01:12:09 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\rdriv.sys -- (rdriv)
DRV - [2006/02/18 08:55:45 | 000,012,288 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\DP.sys -- (DP1112)
DRV - [2005/05/14 08:37:42 | 000,260,608 | R--- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\WlanUZXP.sys -- (SG760_XP)
DRV - [2005/04/05 19:17:02 | 000,267,192 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\SYMTDI.SYS -- (SYMTDI)
DRV - [2005/04/05 19:17:00 | 000,017,976 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\SYMREDRV.SYS -- (SYMREDRV)
DRV - [2003/04/14 22:31:34 | 000,006,272 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\psadd.sys -- (psadd)
DRV - [2003/04/11 16:43:18 | 000,084,224 | ---- | M] (Xpoint Technologies, Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\srntflt.sys -- (SRFilter)
DRV - [2002/08/29 07:16:30 | 000,891,711 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2002/06/29 02:21:40 | 000,017,251 | ---- | M] (Primax Electronics Ltd.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\PELMOUSE.SYS -- (pelmouse)
DRV - [2002/04/12 21:49:40 | 000,029,329 | ---- | M] (Primax Electronics Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PELPS2M.SYS -- (pelps2m)
DRV - [2001/09/13 15:58:02 | 000,007,012 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\PMEMNT.SYS -- (PMEM)
DRV - [2001/08/17 22:07:44 | 000,019,072 | ---- | M] (Adaptec, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sparrow.sys -- (Sparrow)
DRV - [2001/08/17 22:07:42 | 000,030,688 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sym_u3.sys -- (sym_u3)
DRV - [2001/08/17 22:07:40 | 000,028,384 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sym_hi.sys -- (sym_hi)
DRV - [2001/08/17 22:07:36 | 000,032,640 | ---- | M] (LSI Logic) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\symc8xx.sys -- (symc8xx)
DRV - [2001/08/17 22:07:34 | 000,016,256 | ---- | M] (Symbios Logic Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\symc810.sys -- (symc810)
DRV - [2001/08/17 21:58:02 | 000,027,648 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\amdagp.sys -- (amdagp)
DRV - [2001/08/17 21:58:02 | 000,026,112 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\sisagp.sys -- (sisagp)
DRV - [2001/08/17 21:52:22 | 000,036,736 | ---- | M] (Promise Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ultra.sys -- (ultra)
DRV - [2001/08/17 21:52:20 | 000,045,312 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql12160.sys -- (ql12160)
DRV - [2001/08/17 21:52:20 | 000,040,320 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql1080.sys -- (ql1080)
DRV - [2001/08/17 21:52:18 | 000,049,024 | ---- | M] (QLogic Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\ql1280.sys -- (ql1280)
DRV - [2001/08/17 21:52:16 | 000,179,584 | ---- | M] (Mylex Corporation) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\dac2w2k.sys -- (dac2w2k)
DRV - [2001/08/17 21:52:12 | 000,017,280 | ---- | M] (American Megatrends Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\mraid35x.sys -- (mraid35x)
DRV - [2001/08/17 21:52:00 | 000,026,496 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\asc.sys -- (asc)
DRV - [2001/08/17 21:51:58 | 000,014,848 | ---- | M] (Advanced System Products, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\asc3550.sys -- (asc3550)
DRV - [2001/08/17 21:51:56 | 000,005,248 | ---- | M] (Acer Laboratories Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\aliide.sys -- (AliIde)
DRV - [2001/08/17 21:51:54 | 000,006,656 | ---- | M] (CMD Technology, Inc.) [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\cmdide.sys -- (CmdIde)
DRV - [2001/08/17 20:20:04 | 000,096,256 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ac97intc.sys -- (ac97intc) Intel® 82801 Audio Driver Install Service (WDM)
DRV - [1999/09/10 11:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\aspi32.sys -- (Aspi32)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = c:\secure32.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://searchbar.fin...siteyouneed.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = c:\secure32.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://searchbar.fin...siteyouneed.com
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
[2010/01/23 15:30:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2006/02/16 00:30:10 | 000,000,000 | ---D | M] (Google Toolbar for Firefox) -- C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2006/06/20 00:09:18 | 000,039,424 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\npclntax.dll
[2006/02/16 00:47:45 | 002,078,344 | ---- | M] () -- C:\Program Files\Mozilla Firefox\plugins\NPSWF32.dll
O1 HOSTS File: ([2010/01/23 15:22:08 | 000,000,000 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx ()
O3 - HKLM\..\Toolbar: (ToolBar888) - {CBCC61FA-0221-4ccc-B409-CEE865CACA3A} - C:\Program Files\ToolBar888\MyToolBar.dll File not found
O3 - HKLM\..\Toolbar: (Zango Toolbar) - {EA0D26BD-9029-431A-86E0-83152D67828A} - C:\Program Files\Zango Programs\Zango Toolbar\ZangoTB.dll File not found
O4 - HKLM..\Run: [defender] C:\dfndrff_12.exe File not found
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [keyboard] C:\\kybrdff_12.exe ()
O4 - HKLM..\Run: [LXCECATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCEtime.DLL ()
O4 - HKLM..\Run: [MDM] C:\WINDOWS\System32\MDN.exe ()
O4 - HKLM..\Run: [Microsoft ® Windows Update Manager] C:\WINDOWS\update\updmgr.exe ()
O4 - HKLM..\Run: [Microsoft Windows Update 32] File not found
O4 - HKLM..\Run: [MSN messanger] C:\WINDOWS\System32\msnmsgsm.exe ()
O4 - HKLM..\Run: [newname] C:\\nwnmff_12.exe ()
O4 - HKLM..\Run: [Rapid Restore] C:\Program Files\Xpoint\PE\Skin\RRPCSB.EXE ()
O4 - HKLM..\Run: [Real0ne] C:\WINDOWS\system32\boys.exe ()
O4 - HKLM..\Run: [REGEDIT] C:\Program Files\My App\zlip.exe File not found
O4 - HKLM..\Run: [SIX] C:\WINDOWS\System32\SIX.exe ()
O4 - HKLM..\Run: [Sygatedsa Personal Firewall] C:\WINDOWS\System32\ddoSygate.exe ()
O4 - HKLM..\Run: [VCS Host] C:\WINDOWS\System32\vcshost.exe ()
O4 - HKLM..\Run: [Windows Core Kernel Update] C:\WINDOWS\system32\win32bootcfg.exe ()
O4 - HKLM..\Run: [Winsock2 wqr1s] C:\WINDOWS\System32\zgtfxcob.exe ()
O4 - HKCU..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe (IBM)
O4 - HKCU..\Run: [MDM] C:\WINDOWS\System32\MDN.exe ()
O4 - HKCU..\Run: [Microsoft Windows Update 32] File not found
O4 - HKCU..\Run: [SIX] C:\WINDOWS\System32\SIX.exe ()
O4 - HKCU..\Run: [Sygatedsa Personal Firewall] C:\WINDOWS\System32\ddoSygate.exe ()
O4 - HKCU..\Run: [VCS Host] C:\WINDOWS\System32\vcshost.exe ()
O4 - HKLM..\RunOnce: [MDM] C:\WINDOWS\System32\MDN.exe ()
O4 - HKLM..\RunOnce: [SIX] C:\WINDOWS\System32\SIX.exe ()
O4 - HKCU..\RunOnce: [MDM] C:\WINDOWS\System32\MDN.exe ()
O4 - HKCU..\RunOnce: [SIX] C:\WINDOWS\System32\SIX.exe ()
O4 - HKCU..\RunOnce: [Winsock2 wqr1s] C:\WINDOWS\System32\zgtfxcob.exe ()
O4 - HKLM..\RunOnceEx: [RRPC-nls] File not found
O4 - HKLM..\RunServices: [MDM] C:\WINDOWS\System32\MDN.exe ()
O4 - HKLM..\RunServices: [MSN messanger] C:\WINDOWS\System32\msnmsgsm.exe ()
O4 - HKLM..\RunServices: [SIX] C:\WINDOWS\System32\SIX.exe ()
O4 - HKLM..\RunServices: [Sygatedsa Personal Firewall] C:\WINDOWS\System32\ddoSygate.exe ()
O4 - HKLM..\RunServices: [System Update] File not found
O4 - HKLM..\RunServices: [tutcdchk2] C:\WINDOWS\System32\tutcdchk2.exe File not found
O4 - HKLM..\RunServices: [updwebmin] C:\WINDOWS\System32\updwebmin.exe File not found
O4 - HKLM..\RunServices: [VCS Host] C:\WINDOWS\System32\vcshost.exe ()
O4 - HKCU..\RunServices: [System Update] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 8
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\NPJPI150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\Web\related.htm ()
O12 - Plugin for: .spop - C:\Program Files\Internet Explorer\PLUGINS\NPDocBox.dll (InterTrust Technologies Corporation, Inc.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1139340454234 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.micros...b?1156174650718 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macr...ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.137.1
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINDOWS\system32\msdxm.ocx ()
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\Control Panel: DllName - C:\WINDOWS\system32\guard.tmp - C:\WINDOWS\System32\guard.tmp File not found
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/01/07 02:07:08 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2009/07/30 19:01:18 | 000,001,723 | ---- | M] () - F:\autocadaddremovefix.zip -- [ FAT ]
O32 - AutoRun File - [2008/04/01 20:55:24 | 000,000,000 | ---D | M] - F:\autocadaddremovefix -- [ FAT ]
O32 - AutoRun File - [2010/03/06 00:22:14 | 000,000,209 | ---- | M] () - F:\Autorun.ini -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O35 - comfile [open] -- "%1" %*
O35 - exefile [open] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2003/02/19 21:16:04 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16891891626803200)
========== Files/Folders - Created Within 30 Days ==========
[2010/03/07 02:56:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/03/07 02:55:34 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/03/07 02:10:48 | 000,057,344 | ---- | C] (Registry Fix) -- C:\Documents and Settings\User\Desktop\RegistryFix.exe
[2010/03/07 02:08:51 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/03/06 23:21:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2010/03/06 23:21:39 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/06 23:21:37 | 000,018,520 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/06 23:21:37 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/06 23:21:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/03/06 23:17:35 | 000,260,608 | R--- | C] (ZyDAS Technology Corporation) -- C:\WINDOWS\System32\drivers\WlanUZXP.sys
[2006/03/10 02:51:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2006/03/10 02:51:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2006/03/05 23:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Help
[2006/03/05 23:16:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\Help
[2003/02/19 21:34:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2003/02/19 21:34:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2003/02/19 21:19:10 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2003/02/19 21:19:10 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
========== Files - Modified Within 30 Days ==========
[2010/03/07 03:34:23 | 000,054,016 | ---- | M] () -- C:\WINDOWS\System32\drivers\oaaudlhk.sys
[2010/03/07 02:55:34 | 000,000,622 | ---- | M] () -- C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2010/03/07 02:55:34 | 000,000,603 | ---- | M] () -- C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2010/03/07 02:54:47 | 000,002,730 | ---- | M] () -- C:\WINDOWS\System32\xt34mxxx
[2010/03/07 02:54:47 | 000,000,104 | ---- | M] () -- C:\WINDOWS\IBMVPD.INI
[2010/03/07 02:54:23 | 000,000,000 | ---- | M] () -- C:\WINDOWS\keyboard1.dat
[2010/03/07 02:53:30 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/07 02:53:24 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/03/07 02:53:20 | 259,051,520 | -HS- | M] () -- C:\hiberfil.sys
[2010/03/07 02:52:53 | 000,786,432 | -H-- | M] () -- C:\Documents and Settings\User\NTUSER.DAT
[2010/03/07 02:52:53 | 000,000,180 | -HS- | M] () -- C:\Documents and Settings\User\ntuser.ini
[2010/03/07 02:11:17 | 004,298,590 | -H-- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\IconCache.db
[2010/03/07 02:10:50 | 000,057,344 | ---- | M] (Registry Fix) -- C:\Documents and Settings\User\Desktop\RegistryFix.exe
[2010/03/07 02:09:44 | 000,000,396 | RHS- | M] () -- C:\Documents and Settings\User\ntuser.pol
[2010/03/07 02:07:19 | 000,001,341 | ---- | M] () -- C:\Documents and Settings\User\Desktop\regtools.vbs
[2010/03/07 01:42:15 | 000,000,123 | ---- | M] () -- C:\WINDOWS\System32\987.reg
[2010/03/07 01:42:12 | 000,000,123 | ---- | M] () -- C:\WINDOWS\System32\376.reg
[2010/03/06 23:36:57 | 000,000,123 | ---- | M] () -- C:\WINDOWS\System32\535.reg
[2010/03/06 23:21:42 | 000,000,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/06 23:13:33 | 000,002,278 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
========== Files Created - No Company Name ==========
[2010/03/07 03:34:22 | 000,054,016 | ---- | C] () -- C:\WINDOWS\System32\drivers\oaaudlhk.sys
[2010/03/07 02:55:34 | 000,000,622 | ---- | C] () -- C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2010/03/07 02:55:34 | 000,000,603 | ---- | C] () -- C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2010/03/07 02:09:44 | 000,000,396 | RHS- | C] () -- C:\Documents and Settings\User\ntuser.pol
[2010/03/07 02:07:33 | 000,001,341 | ---- | C] () -- C:\Documents and Settings\User\Desktop\regtools.vbs
[2010/03/07 02:03:35 | 259,051,520 | -HS- | C] () -- C:\hiberfil.sys
[2010/03/07 01:42:15 | 000,000,123 | ---- | C] () -- C:\WINDOWS\System32\987.reg
[2010/03/07 01:42:12 | 000,000,123 | ---- | C] () -- C:\WINDOWS\System32\376.reg
[2010/03/06 23:36:57 | 000,000,123 | ---- | C] () -- C:\WINDOWS\System32\535.reg
[2010/03/06 23:21:42 | 000,000,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/01/23 15:30:55 | 000,000,164 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/01/23 15:27:13 | 000,235,721 | R-S- | C] () -- C:\WINDOWS\System32\fpr8039ue.dll
[2010/01/23 15:22:03 | 000,235,721 | R-S- | C] () -- C:\WINDOWS\System32\sye.dll
[2006/08/21 15:24:27 | 000,240,640 | ---- | C] () -- C:\WINDOWS\System32\nmocod.dll
[2006/08/21 15:22:26 | 000,000,104 | ---- | C] () -- C:\WINDOWS\IBMVPD.INI
[2006/08/21 15:22:25 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\pmemw.dll
[2006/08/21 15:21:07 | 000,236,830 | R-S- | C] () -- C:\WINDOWS\System32\mv0ml9d11.dll
[2006/08/21 15:15:04 | 000,234,903 | R-S- | C] () -- C:\WINDOWS\System32\hI0q0cd5ef0.dll
[2006/08/21 15:11:30 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\sfi.dll
[2006/08/21 14:48:47 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\eV02ledo1h0c.dll
[2006/08/21 14:48:45 | 000,233,593 | R-S- | C] () -- C:\WINDOWS\System32\jt6007jme.dll
[2006/08/21 14:45:54 | 000,235,154 | R-S- | C] () -- C:\WINDOWS\System32\azaolc131f.dll
[2006/08/21 14:40:08 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\eucbbbc.dll
[2006/08/21 14:40:07 | 000,234,730 | R-S- | C] () -- C:\WINDOWS\System32\e402ledo1h0c.dll
[2006/08/20 11:42:34 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\l44qleh51h4.dll
[2006/08/19 00:06:57 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\azam0cf1ef2.dll
[2006/08/18 20:32:17 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\s2rslc971f.dll
[2006/08/18 14:12:40 | 000,233,539 | R-S- | C] () -- C:\WINDOWS\System32\lv4o09h3e.dll
[2006/08/18 12:47:50 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\azam09d1e.dll
[2006/08/18 12:44:42 | 000,234,428 | R-S- | C] () -- C:\WINDOWS\System32\l20u0cd9ef0.dll
[2006/08/18 12:44:38 | 000,235,118 | R-S- | C] () -- C:\WINDOWS\System32\irnml5511.dll
[2006/08/18 12:37:48 | 000,234,320 | R-S- | C] () -- C:\WINDOWS\System32\s4rs0e97eh.dll
[2006/08/18 12:37:43 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\n6r20g9oe6.dll
[2006/08/18 12:25:18 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\kbfcaww.dll
[2006/08/18 12:25:17 | 000,234,100 | R-S- | C] () -- C:\WINDOWS\System32\o4pq0e75eh.dll
[2006/08/18 12:25:12 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\ktl4l73q1.dll
[2006/08/18 12:20:15 | 000,234,663 | R-S- | C] () -- C:\WINDOWS\System32\ktlml7311.dll
[2006/08/18 12:20:12 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\fpnm0351e.dll
[2006/08/18 05:19:41 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\f22m0cf1ef2.dll
[2006/08/17 23:47:32 | 000,235,477 | R-S- | C] () -- C:\WINDOWS\System32\ennul1591.dll
[2006/08/17 23:47:32 | 000,233,526 | ---- | C] () -- C:\WINDOWS\System32\ukildll.dll
[2006/08/17 23:47:29 | 000,233,526 | ---- | C] () -- C:\WINDOWS\System32\unrsdpia.dll
[2006/08/17 23:47:28 | 000,233,635 | R-S- | C] () -- C:\WINDOWS\System32\lv0m09d1e.dll
[2006/08/17 23:44:37 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\mvi.dll
[2006/08/17 23:44:32 | 000,234,271 | R-S- | C] () -- C:\WINDOWS\System32\hr4s05h7e.dll
[2006/08/17 23:39:47 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\wbecedit.dll
[2006/08/17 23:31:13 | 000,234,464 | R-S- | C] () -- C:\WINDOWS\System32\o8lu0i39e8.dll
[2006/08/17 23:28:00 | 000,235,152 | R-S- | C] () -- C:\WINDOWS\System32\k626lgfs1626.dll
[2006/03/17 05:36:53 | 000,233,526 | R-S- | C] () -- C:\WINDOWS\System32\nL6qlgj516o.dll
[2006/03/17 05:22:47 | 000,234,074 | R-S- | C] () -- C:\WINDOWS\System32\l84q0ih5e84.dll
[2006/03/17 04:52:45 | 000,237,158 | R-S- | C] () -- C:\WINDOWS\System32\lzasrv.dll
[2006/03/17 04:52:44 | 000,233,877 | R-S- | C] () -- C:\WINDOWS\System32\mvn2l95o1.dll
[2006/03/17 00:05:42 | 000,235,739 | R-S- | C] () -- C:\WINDOWS\System32\g2220cfoef2c0.dll
[2006/03/16 20:06:32 | 000,235,446 | R-S- | C] () -- C:\WINDOWS\System32\aza2le5o1h.dll
[2006/03/16 09:53:10 | 000,234,888 | R-S- | C] () -- C:\WINDOWS\System32\m4nq0e55eh.dll
[2006/03/16 08:07:18 | 000,235,211 | R-S- | C] () -- C:\WINDOWS\System32\azaq01j5e.dll
[2006/03/16 05:15:55 | 000,234,334 | R-S- | C] () -- C:\WINDOWS\System32\cubcatq.dll
[2006/03/15 06:36:32 | 000,234,334 | R-S- | C] () -- C:\WINDOWS\System32\enj6l11s1.dll
[2006/03/15 04:49:39 | 000,234,334 | R-S- | C] () -- C:\WINDOWS\System32\aza2059oe.dll
[2006/03/15 02:08:12 | 000,235,899 | R-S- | C] () -- C:\WINDOWS\System32\ir6ql5j51.dll
[2006/03/15 01:58:04 | 000,234,880 | R-S- | C] () -- C:\WINDOWS\System32\l64q0gh5e64.dll
[2006/03/14 07:20:32 | 000,234,021 | R-S- | C] () -- C:\WINDOWS\System32\yVyyxwt.dll
[2006/03/11 09:23:57 | 000,036,527 | ---- | C] () -- C:\WINDOWS\System32\lovely.sys
[2006/03/11 09:23:57 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\msn.dll
[2006/03/11 09:23:57 | 000,003,072 | ---- | C] () -- C:\WINDOWS\System32\knlps.sys
[2006/03/11 09:23:56 | 000,006,192 | ---- | C] () -- C:\WINDOWS\System32\aliases.ini
[2006/03/10 02:42:49 | 000,234,241 | R-S- | C] () -- C:\WINDOWS\System32\ktn0l75m1.dll
[2006/03/09 07:05:05 | 000,234,241 | R-S- | C] () -- C:\WINDOWS\System32\kvdindev.dll
[2006/03/09 02:57:11 | 000,235,533 | R-S- | C] () -- C:\WINDOWS\System32\mvnol9531.dll
[2006/03/09 00:17:08 | 000,235,533 | R-S- | C] () -- C:\WINDOWS\System32\p04ulah91d4.dll
[2006/03/09 00:07:27 | 000,235,469 | R-S- | C] () -- C:\WINDOWS\System32\hrrq0595e.dll
[2006/03/08 21:24:16 | 000,235,469 | R-S- | C] () -- C:\WINDOWS\System32\kxdycl.dll
[2006/03/08 06:00:46 | 000,235,469 | R-S- | C] () -- C:\WINDOWS\System32\c200lcdm1f0a.dll
[2006/03/08 00:51:49 | 000,234,249 | R-S- | C] () -- C:\WINDOWS\System32\jtjq0715e.dll
[2006/03/07 21:24:07 | 000,234,299 | R-S- | C] () -- C:\WINDOWS\System32\h0n00a5med.dll
[2006/03/07 06:17:08 | 000,237,054 | R-S- | C] () -- C:\WINDOWS\System32\dn8q01l5e.dll
[2006/03/07 05:49:47 | 000,234,124 | R-S- | C] () -- C:\WINDOWS\System32\o2nslc571f.dll
[2006/03/07 05:43:01 | 000,237,054 | R-S- | C] () -- C:\WINDOWS\System32\jcmd400.dll
[2006/03/07 05:43:01 | 000,237,054 | R-S- | C] () -- C:\WINDOWS\System32\hrn4055qe.dll
[2006/03/07 01:17:50 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\lvp0097me.dll
[2006/03/06 23:13:35 | 000,237,145 | R-S- | C] () -- C:\WINDOWS\System32\gp04l3dq1.dll
[2006/03/06 23:10:45 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\mh43dmod.dll
[2006/03/06 21:41:50 | 000,236,745 | R-S- | C] () -- C:\WINDOWS\System32\kt8ol7l31.dll
[2006/03/06 21:26:02 | 000,234,193 | R-S- | C] () -- C:\WINDOWS\System32\enr8l19u1.dll
[2006/03/06 19:43:41 | 000,236,745 | R-S- | C] () -- C:\WINDOWS\System32\kmdhu1.dll
[2006/03/06 19:02:18 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\q6860glse6q60.dll
[2006/03/06 03:44:30 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxcevs.dll
[2006/03/06 03:38:19 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\r48slel71hq.dll
[2006/03/05 23:03:44 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\g4jole131h.dll
[2006/03/05 22:47:35 | 000,235,087 | R-S- | C] () -- C:\WINDOWS\System32\hrls0537e.dll
[2006/03/05 22:39:28 | 000,234,027 | R-S- | C] () -- C:\WINDOWS\System32\mvlol9331.dll
[2006/03/05 13:03:11 | 000,234,027 | R-S- | C] () -- C:\WINDOWS\System32\lxvely.dll
[2006/03/05 12:50:42 | 000,235,466 | R-S- | C] () -- C:\WINDOWS\System32\mvl4l93q1.dll
[2006/03/05 09:18:18 | 000,234,991 | R-S- | C] () -- C:\WINDOWS\System32\r46u0ej9eho.dll
[2006/03/05 09:02:14 | 000,234,584 | R-S- | C] () -- C:\WINDOWS\System32\lvlo0933e.dll
[2006/03/05 00:09:12 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\frdrclnr.dll
[2006/03/05 00:09:12 | 000,233,898 | R-S- | C] () -- C:\WINDOWS\System32\f00olad31d0.dll
[2006/03/04 23:56:05 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\lz8609lse.dll
[2006/03/04 23:41:28 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\mologmgr.dll
[2006/03/04 22:05:44 | 000,234,207 | R-S- | C] () -- C:\WINDOWS\System32\m8juli1918.dll
[2006/03/04 21:51:55 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\mfsip32.dll
[2006/03/04 21:27:28 | 000,234,022 | R-S- | C] () -- C:\WINDOWS\System32\dzcpmon.dll
[2006/03/04 20:13:37 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\bZtt.dll
[2006/03/04 19:28:43 | 000,236,324 | R-S- | C] () -- C:\WINDOWS\System32\lv0209doe.dll
[2006/03/04 19:25:19 | 000,233,913 | R-S- | C] () -- C:\WINDOWS\System32\i0lola331d.dll
[2006/03/04 19:23:40 | 000,234,108 | R-S- | C] () -- C:\WINDOWS\System32\l02slaf71d2.dll
[2006/03/04 19:20:38 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\snarddlg.dll
[2006/03/04 18:17:21 | 000,237,097 | R-S- | C] () -- C:\WINDOWS\System32\fpju0319e.dll
[2006/03/04 18:17:21 | 000,236,184 | ---- | C] () -- C:\WINDOWS\System32\dwdmo.dll
[2006/03/04 18:09:11 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\cgbcatex.dll
[2006/03/04 17:55:35 | 000,236,184 | ---- | C] () -- C:\WINDOWS\System32\esp0l17m1.dll
[2006/03/04 17:55:33 | 000,236,587 | R-S- | C] () -- C:\WINDOWS\System32\fp0403dqe.dll
[2006/03/04 17:44:04 | 000,234,264 | R-S- | C] () -- C:\WINDOWS\System32\f2l02c3mgf.dll
[2006/03/04 06:16:09 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\akctres.dll
[2006/03/04 04:02:14 | 000,233,912 | R-S- | C] () -- C:\WINDOWS\System32\mv2ol9f31.dll
[2006/03/04 04:00:20 | 000,233,904 | R-S- | C] () -- C:\WINDOWS\System32\g2jolc131f.dll
[2006/03/04 03:57:31 | 000,237,263 | R-S- | C] () -- C:\WINDOWS\System32\mvp0l97m1.dll
[2006/03/04 03:22:48 | 000,001,763 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\QTSBandwidthCache
[2006/03/04 01:08:33 | 000,234,197 | R-S- | C] () -- C:\WINDOWS\System32\k0lqla351d.dll
[2006/03/03 23:06:04 | 000,236,184 | R-S- | C] () -- C:\WINDOWS\System32\hrr2059oe.dll
[2006/03/03 20:08:54 | 000,540,672 | -HS- | C] () -- C:\WINDOWS\System32\libprm.dll
[2006/03/02 22:44:59 | 000,233,521 | R-S- | C] () -- C:\WINDOWS\System32\mvl2l93o1.dll
[2006/03/02 22:30:06 | 000,233,497 | R-S- | C] () -- C:\WINDOWS\System32\rzfsaps.dll
[2006/03/02 22:30:06 | 000,233,497 | R-S- | C] () -- C:\WINDOWS\System32\j0n20a5oed.dll
[2006/03/02 21:40:32 | 000,233,497 | R-S- | C] () -- C:\WINDOWS\System32\kqdsl1.dll
[2006/03/02 21:40:31 | 000,237,291 | R-S- | C] () -- C:\WINDOWS\System32\p46slej71ho.dll
[2006/03/02 09:00:57 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\rdriv.sys
[2006/03/02 08:36:26 | 000,237,291 | R-S- | C] () -- C:\WINDOWS\System32\o866lijs18o6.dll
[2006/03/02 06:50:30 | 000,237,291 | R-S- | C] () -- C:\WINDOWS\System32\k0pm0a71ed.dll
[2006/03/01 07:07:54 | 000,237,291 | R-S- | C] () -- C:\WINDOWS\System32\pzflbmsg.dll
[2006/03/01 07:03:48 | 000,237,291 | R-S- | C] () -- C:\WINDOWS\System32\dlcpmon.dll
[2006/02/28 21:03:24 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\ir06l5ds1.dll
[2006/02/27 22:05:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\OpPrintServer.INI
[2006/02/27 21:33:40 | 000,233,872 | R-S- | C] () -- C:\WINDOWS\System32\i842liho184c.dll
[2006/02/26 06:01:00 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\ggjql3151.dll
[2006/02/26 06:00:44 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\fR2mlef11h2.dll
[2006/02/26 05:24:16 | 000,237,043 | R-S- | C] () -- C:\WINDOWS\System32\n82u0if9e82.dll
[2006/02/25 22:11:25 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\uxrfaxa.dll
[2006/02/25 22:11:23 | 000,236,753 | R-S- | C] () -- C:\WINDOWS\System32\l8l60i3se8.dll
[2006/02/25 18:50:41 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\hr2q05f5e.dll
[2006/02/25 18:45:42 | 000,234,094 | R-S- | C] () -- C:\WINDOWS\System32\r2r6lc9s1f.dll
[2006/02/24 06:42:19 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\veoy.dll
[2006/02/24 05:40:04 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\wbpcore.dll
[2006/02/24 05:40:03 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\o0ro0a93ed.dll
[2006/02/23 22:37:14 | 000,064,512 | ---- | C] () -- C:\WINDOWS\System32\lovely.dll
[2006/02/23 22:37:14 | 000,003,162 | ---- | C] () -- C:\WINDOWS\System32\mirc.ini
[2006/02/23 22:37:14 | 000,000,127 | ---- | C] () -- C:\WINDOWS\System32\remote.ini
[2006/02/23 22:08:23 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\emcdec.dll
[2006/02/23 20:29:41 | 000,236,115 | R-S- | C] () -- C:\WINDOWS\System32\wussvc.dll
[2006/02/23 19:29:59 | 000,001,167 | ---- | C] () -- C:\WINDOWS\System32\tvm1eb79.sys
[2006/02/23 19:29:56 | 000,061,952 | ---- | C] () -- C:\WINDOWS\System32\tvm1eb79.dll
[2006/02/23 19:29:35 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\w001c02e.dll
[2006/02/22 02:05:57 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\lv2809fue.dll
[2006/02/22 00:52:13 | 000,236,709 | R-S- | C] () -- C:\WINDOWS\System32\lv8609lse.dll
[2006/02/22 00:48:27 | 000,236,898 | R-S- | C] () -- C:\WINDOWS\System32\r8p80i7ue8.dll
[2006/02/22 00:30:28 | 000,237,227 | R-S- | C] () -- C:\WINDOWS\System32\kt02l7do1.dll
[2006/02/22 00:24:23 | 000,233,932 | R-S- | C] () -- C:\WINDOWS\System32\mv6ol9j31.dll
[2006/02/22 00:19:18 | 000,236,053 | R-S- | C] () -- C:\WINDOWS\System32\fpl0033me.dll
[2006/02/22 00:13:59 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\uzerenv.dll
[2006/02/22 00:11:00 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\mCg_hook.dll
[2006/02/21 21:04:55 | 000,064,472 | ---- | C] () -- C:\WINDOWS\System32\lzx32.sys
[2006/02/21 20:50:28 | 000,019,840 | ---- | C] () -- C:\WINDOWS\System32\ntio256.sys
[2006/02/21 20:47:55 | 000,003,066 | ---- | C] () -- C:\Program Files\secure32.html
[2006/02/21 20:47:53 | 001,426,193 | ---- | C] () -- C:\Documents and Settings\LocalService\Application Data\Install.dat
[2006/02/21 20:21:24 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\f42mlef11h2.dll
[2006/02/21 20:09:49 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\dDdrm.dll
[2006/02/21 19:55:29 | 000,236,020 | ---- | C] () -- C:\WINDOWS\System32\asmfd.dll
[2006/02/21 19:55:25 | 000,236,581 | R-S- | C] () -- C:\WINDOWS\System32\dn6q01j5e.dll
[2006/02/21 19:45:19 | 000,236,522 | R-S- | C] () -- C:\WINDOWS\System32\h20q0cd5ef0.dll
[2006/02/21 19:37:53 | 000,234,004 | R-S- | C] () -- C:\WINDOWS\System32\gpjql3151.dll
[2006/02/21 19:23:30 | 000,236,131 | R-S- | C] () -- C:\WINDOWS\System32\dnjm0111e.dll
[2006/02/21 19:19:20 | 000,234,202 | R-S- | C] () -- C:\WINDOWS\System32\l80ulid9180.dll
[2006/02/21 05:53:28 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\hqghumea.dll
[2006/02/21 05:48:21 | 000,236,468 | R-S- | C] () -- C:\WINDOWS\System32\k8440ihqe84e0.dll
[2006/02/21 05:44:12 | 000,236,622 | R-S- | C] () -- C:\WINDOWS\System32\i2060cdsef060.dll
[2006/02/21 05:22:32 | 000,540,672 | ---- | C] () -- C:\WINDOWS\System32\qghumeay.dll
[2006/02/21 05:21:27 | 000,236,974 | R-S- | C] () -- C:\WINDOWS\System32\q4nu0e59eh.dll
[2006/02/21 05:03:56 | 000,236,992 | R-S- | C] () -- C:\WINDOWS\System32\s2pu0c79ef.dll
[2006/02/21 05:00:22 | 000,236,069 | R-S- | C] () -- C:\WINDOWS\System32\lv4009hme.dll
[2006/02/21 04:29:19 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\fp6203joe.dll
[2006/02/21 00:09:07 | 000,234,178 | R-S- | C] () -- C:\WINDOWS\System32\dn0q01d5e.dll
[2006/02/20 19:43:52 | 000,236,020 | R-S- | C] () -- C:\WINDOWS\System32\o248lchu1f48.dll
[2006/02/20 04:01:13 | 000,234,614 | R-S- | C] () -- C:\WINDOWS\System32\k026lafs1d26.dll
[2006/02/19 09:09:08 | 000,236,991 | R-S- | C] () -- C:\WINDOWS\System32\gp2ol3f31.dll
[2006/02/19 09:01:10 | 000,233,473 | R-S- | C] () -- C:\WINDOWS\System32\h60q0gd5e60.dll
[2006/02/19 07:26:56 | 000,233,473 | R-S- | C] () -- C:\WINDOWS\System32\tgpmon.dll
[2006/02/18 08:54:27 | 000,235,085 | R-S- | C] () -- C:\WINDOWS\System32\pwh.dll
[2006/02/18 06:26:01 | 000,237,011 | R-S- | C] () -- C:\WINDOWS\System32\hrn6055se.dll
[2006/02/17 05:53:38 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\DP.sys
[2006/02/17 05:51:30 | 000,234,272 | ---- | C] () -- C:\WINDOWS\System32\ddband.dll
[2006/02/17 05:50:39 | 000,235,085 | R-S- | C] () -- C:\WINDOWS\System32\azpmgr.dll
[2006/02/15 05:09:57 | 000,235,259 | R-S- | C] () -- C:\WINDOWS\System32\ktl2l73o1.dll
[2006/02/15 05:08:01 | 000,235,925 | R-S- | C] () -- C:\WINDOWS\System32\gp0ul3d91.dll
[2006/02/14 23:36:20 | 000,235,257 | R-S- | C] () -- C:\WINDOWS\System32\irl2l53o1.dll
[2006/02/13 08:57:07 | 000,237,071 | R-S- | C] () -- C:\WINDOWS\System32\fpn6035se.dll
[2006/02/13 03:29:55 | 000,237,071 | R-S- | C] () -- C:\WINDOWS\System32\dimrtp.dll
[2006/02/13 00:46:41 | 000,233,699 | R-S- | C] () -- C:\WINDOWS\System32\fp0u03d9e.dll
[2006/02/13 00:30:46 | 000,233,733 | R-S- | C] () -- C:\WINDOWS\System32\s0pu0a79ed.dll
[2006/02/12 20:30:58 | 000,237,071 | R-S- | C] () -- C:\WINDOWS\System32\h2j4lc1q1f.dll
[2006/02/12 06:15:10 | 000,234,272 | ---- | C] () -- C:\WINDOWS\System32\mxc42u.dll
[2006/02/12 06:14:12 | 000,237,071 | R-S- | C] () -- C:\WINDOWS\System32\ior8l59u1.dll
[2006/02/12 06:14:11 | 000,235,895 | R-S- | C] () -- C:\WINDOWS\System32\k6js0g17e6.dll
[2006/02/12 01:47:20 | 000,234,272 | ---- | C] () -- C:\WINDOWS\System32\nutevent.dll
[2006/02/12 00:34:12 | 000,235,895 | R-S- | C] () -- C:\WINDOWS\System32\mhlogmgr.dll
[2006/02/12 00:21:56 | 000,235,895 | R-S- | C] () -- C:\WINDOWS\System32\nelanman.dll
[2006/02/11 19:17:15 | 000,235,895 | R-S- | C] () -- C:\WINDOWS\System32\j4n2le5o1h.dll
[2006/02/11 08:25:58 | 000,234,072 | R-S- | C] () -- C:\WINDOWS\System32\mv46l9hs1.dll
[2006/02/11 08:19:17 | 000,235,895 | R-S- | C] () -- C:\WINDOWS\System32\uyat.dll
[2006/02/11 07:53:40 | 000,095,744 | -HS- | C] () -- C:\WINDOWS\System32\wsync32.dll
[2006/02/11 07:52:37 | 000,236,558 | R-S- | C] () -- C:\WINDOWS\System32\fp6603jse.dll
[2006/02/11 06:04:51 | 000,233,712 | R-S- | C] () -- C:\WINDOWS\System32\enp0l17m1.dll
[2006/02/10 09:26:33 | 000,236,648 | R-S- | C] () -- C:\WINDOWS\System32\hrp6057se.dll
[2006/02/10 08:04:59 | 000,234,198 | R-S- | C] () -- C:\WINDOWS\System32\l00ulad91d0.dll
[2006/02/10 08:03:05 | 000,235,068 | R-S- | C] () -- C:\WINDOWS\System32\fplo0333e.dll
[2006/02/09 07:45:06 | 000,098,324 | ---- | C] () -- C:\WINDOWS\System32\mpefjgcn.dll
[2006/02/09 04:52:14 | 000,235,102 | R-S- | C] () -- C:\WINDOWS\System32\hr2u05f9e.dll
[2006/02/09 03:08:42 | 000,235,102 | R-S- | C] () -- C:\WINDOWS\System32\csmctl32.dll
[2006/02/09 02:05:25 | 000,236,872 | R-S- | C] () -- C:\WINDOWS\System32\q0psla771d.dll
[2006/02/08 23:34:53 | 000,236,668 | R-S- | C] () -- C:\WINDOWS\System32\n66qlgj516o.dll
[2006/02/08 21:45:11 | 000,236,188 | ---- | C] () -- C:\WINDOWS\System32\f02mlaf11d2.dll
[2006/02/08 21:38:31 | 000,237,009 | R-S- | C] () -- C:\WINDOWS\System32\en4ul1h91.dll
[2006/02/08 21:36:05 | 000,235,123 | R-S- | C] () -- C:\WINDOWS\System32\irr8l59u1.dll
[2006/02/08 21:36:05 | 000,235,068 | R-S- | C] () -- C:\WINDOWS\System32\kpdth3.dll
[2006/02/08 07:45:24 | 000,235,068 | R-S- | C] () -- C:\WINDOWS\System32\ic41_qcx.dll
[2006/02/08 06:39:48 | 000,235,123 | R-S- | C] () -- C:\WINDOWS\System32\mypmsp.dll
[2006/02/07 19:48:27 | 000,235,123 | R-S- | C] () -- C:\WINDOWS\System32\p04u0ah9ed4.dll
[2006/02/07 06:10:36 | 000,235,068 | R-S- | C] () -- C:\WINDOWS\System32\okedlg.dll
[2006/02/07 06:07:18 | 000,235,068 | R-S- | C] () -- C:\WINDOWS\System32\d8j00i1me8.dll
[2006/02/07 05:35:42 | 000,235,600 | R-S- | C] () -- C:\WINDOWS\System32\k2lq0c35ef.dll
[2006/02/07 04:26:37 | 000,234,272 | R-S- | C] () -- C:\WINDOWS\System32\mvpql9751.dll
[2006/02/07 03:58:32 | 000,235,413 | R-S- | C] () -- C:\WINDOWS\System32\en4ml1h11.dll
[2006/02/07 03:53:59 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\utalaek.dll
[2006/01/08 21:30:06 | 000,000,044 | ---- | C] () -- C:\WINDOWS\SMWizard.INI
[2006/01/08 21:11:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\iPlayer.INI
[2006/01/07 01:51:29 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2006/01/07 01:50:20 | 000,282,624 | ---- | C] () -- C:\WINDOWS\System32\PCDrSystemInformation.dll
[2006/01/07 01:50:16 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\PcdrKernelModeServices.dll
[2006/01/07 01:50:16 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\ProgressTrace.dll
[2006/01/07 01:44:36 | 000,000,023 | ---- | C] () -- C:\WINDOWS\Welcome.ini
[2006/01/07 01:38:37 | 000,000,044 | ---- | C] () -- C:\WINDOWS\System32\msssc.dll
[2006/01/07 01:35:10 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2006/01/07 01:31:12 | 000,002,481 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2003/02/19 21:39:14 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2002/11/15 10:14:26 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\AIBMRUNL.dll
[1980/01/01 08:00:00 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[1980/01/01 08:00:00 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\e100bmsg.dll
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2006/03/05 23:34:01 | 000,028,160 | ---- | M] () -- C:\1x.exe
[2006/02/23 19:29:30 | 000,002,560 | ---- | M] () -- C:\ac3_0010.exe
[2006/02/15 01:36:38 | 001,175,664 | ---- | M] (instyler installation software) -- C:\beti.exe
[2006/02/21 21:04:55 | 000,070,144 | ---- | M] () -- C:\bhowvt.exe
[2006/03/09 00:30:14 | 000,956,300 | ---- | M] () -- C:\c0p.exe
[2006/03/10 22:09:14 | 000,146,944 | ---- | M] () -- C:\cf.exe
[2006/03/08 00:34:33 | 000,020,062 | ---- | M] () -- C:\cold.exe
[2006/03/10 06:49:42 | 000,004,948 | ---- | M] (.) -- C:\ddi.exe
[2006/03/14 20:18:03 | 000,251,262 | ---- | M] () -- C:\deskbar.exe
[2006/02/13 23:39:23 | 000,081,920 | ---- | M] (DJWK JWBND HWBDH BWHDB HWHD H) -- C:\dfndrac_6.exe
[2006/02/10 04:10:30 | 000,081,920 | ---- | M] (DJWK JWBND HWBDH BWHDB HWHD H) -- C:\dfndrad_5.exe
[2006/02/15 19:42:17 | 000,081,920 | ---- | M] (DJWK JWBND HWBDH BWHDB HWHD H) -- C:\dfndrdd_6.exe
[2006/02/18 03:30:49 | 000,073,728 | ---- | M] (::::::::::::::::::::::::::::::::::::::::::: -- C:\dfndred_7.exe
[2006/02/20 20:04:17 | 000,077,824 | ---- | M] (/|/\?\?\/|?\?) -- C:\dfndref_7.exe
[2006/02/07 03:48:58 | 000,081,920 | ---- | M] (DJWK JWBND HWBDH BWHDB HWHD H) -- C:\dfndre_5.exe
[2006/03/16 19:56:21 | 000,073,728 | ---- | M] (3u38742897r8yuruy4u3yru743433r) -- C:\dfndrff_11.exe
[2006/08/18 16:05:46 | 000,073,728 | ---- | M] (3u38742897r8yuruy4u3yru743433r) -- C:\dfndrff_11a.exe
[2006/02/28 21:04:12 | 000,077,824 | ---- | M] ((*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)) -- C:\dfndrff_7.exe
[2006/03/06 19:03:12 | 000,077,824 | ---- | M] (&@#*&#*#&@#*&@#*@&#*@&#*) -- C:\dfndrff_8.exe
[2006/03/10 20:53:48 | 000,073,728 | ---- | M] (..../...../..../..../..../..//......./////....) -- C:\dfndrff_9.exe
[2006/02/25 08:44:50 | 000,077,824 | ---- | M] (&%&%&%&%%&%&%%&%) -- C:\dfndrfg_7.exe
[2006/03/05 21:57:40 | 000,077,824 | ---- | M] (#^&$#^&$^&$^783647364763647367) -- C:\dfndrfg_8.exe
[2006/03/13 21:11:53 | 000,073,728 | ---- | M] ((%)(%)(%)(%)(%)(%)(%)(%)(%)(%)) -- C:\dfndrfh_10.exe
[2006/02/16 00:46:54 | 000,004,948 | ---- | M] (.) -- C:\do.exe
[2006/02/26 06:00:38 | 000,004,948 | ---- | M] (.) -- C:\dodi.exe
[2006/06/22 08:25:34 | 000,016,384 | ---- | M] (.) -- C:\dotdr.exe
[2006/02/09 07:35:40 | 000,006,144 | ---- | M] () -- C:\dr.exe
[2006/02/20 04:01:21 | 000,016,157 | ---- | M] () -- C:\drmy.exe
[2006/08/21 17:21:00 | 000,069,632 | ---- | M] (32489238eue7r734yr7634yr763t65535) -- C:\drsmartload.exe
[2006/08/21 14:59:23 | 000,069,632 | ---- | M] (32489238eue7r734yr7634yr763t65535) -- C:\drsmartload1.exe
[2006/02/11 06:07:10 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload45a1.exe
[2006/03/14 20:32:54 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a100.exe
[2006/03/15 05:23:24 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a1001.exe
[2006/02/12 01:47:30 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload45a2.exe
[2006/03/16 19:56:38 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a2002.exe
[2006/08/18 16:10:13 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a2002a.exe
[2006/02/13 00:31:39 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload45a3.exe
[2006/08/21 14:41:10 | 000,020,480 | ---- | M] (ewq48u328u747823yu) -- C:\drsmartload45a3333a.exe
[2006/02/13 23:39:40 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a4.exe
[2006/02/14 23:45:30 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a5.exe
[2006/02/15 00:31:50 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a6.exe
[2006/02/17 01:06:55 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7.exe
[2006/02/17 05:51:33 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7a.exe
[2006/02/18 03:30:53 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7c.exe
[2006/02/19 02:38:34 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7d.exe
[2006/02/20 04:01:44 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7e.exe
[2006/02/20 19:44:44 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7f.exe
[2006/02/21 19:20:48 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7g.exe
[2006/02/22 03:14:49 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7h.exe
[2006/02/23 19:28:25 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a7i.exe
[2006/03/03 20:08:34 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a8a.exe
[2006/03/05 21:57:43 | 000,020,480 | ---- | M] (.) -- C:\drsmartload45a8b.exe
[2006/03/07 21:24:31 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a8b5.exe
[2006/03/10 02:44:07 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a8b9.exe
[2006/03/10 20:53:58 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a8b9abc.exe
[2006/03/14 01:14:47 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a99.exe
[2006/08/19 11:21:43 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a999.exe
[2006/08/20 11:44:04 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload45a9999.exe
[2006/02/07 03:51:07 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload45y.exe
[2006/02/08 00:12:18 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload45z.exe
[2006/02/11 06:07:13 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload46a1.exe
[2006/03/14 20:32:57 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a100.exe
[2006/03/15 05:23:30 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a1001.exe
[2006/02/12 01:47:32 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload46a2.exe
[2006/03/16 19:56:44 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a2002.exe
[2006/08/18 16:10:27 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a2002a.exe
[2006/02/13 00:31:41 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload46a3.exe
[2006/08/21 14:41:11 | 000,020,480 | ---- | M] (ewq48u328u747823yu) -- C:\drsmartload46a3333a.exe
[2006/02/13 23:39:43 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a4.exe
[2006/02/14 23:45:32 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a5.exe
[2006/02/15 00:31:51 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a6.exe
[2006/02/17 01:07:00 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7.exe
[2006/02/17 05:51:39 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7a.exe
[2006/02/18 03:30:54 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7c.exe
[2006/02/19 02:38:37 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7d.exe
[2006/02/20 04:01:59 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7e.exe
[2006/02/20 19:44:46 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7f.exe
[2006/02/21 19:20:58 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7g.exe
[2006/02/22 03:14:52 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7h.exe
[2006/02/23 19:28:26 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a7i.exe
[2006/03/03 20:08:39 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a8a.exe
[2006/03/05 21:57:45 | 000,020,480 | ---- | M] (.) -- C:\drsmartload46a8b.exe
[2006/03/07 21:24:34 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a8b5.exe
[2006/03/10 02:44:13 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a8b9.exe
[2006/03/10 20:53:59 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a8b9abc.exe
[2006/03/14 01:14:49 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a99.exe
[2006/08/19 11:21:44 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a999.exe
[2006/08/20 11:44:02 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload46a9999.exe
[2006/02/07 03:51:17 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload46y.exe
[2006/02/08 00:12:21 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload46z.exe
[2006/02/07 03:49:20 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849a.exe
[2006/02/11 06:07:14 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849a1.exe
[2006/03/14 20:33:01 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a100.exe
[2006/03/15 05:23:35 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a1001.exe
[2006/02/12 01:47:34 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849a2.exe
[2006/03/16 19:57:18 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a2002.exe
[2006/08/18 16:12:02 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a2002a.exe
[2006/02/13 00:31:46 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849a3.exe
[2006/08/21 14:43:30 | 000,020,480 | ---- | M] (ewq48u328u747823yu) -- C:\drsmartload849a3333a.exe
[2006/02/13 23:39:45 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849a4.exe
[2006/02/14 23:45:34 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a5.exe
[2006/02/15 00:31:52 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a6.exe
[2006/02/17 01:06:59 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7.exe
[2006/02/17 05:51:42 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7a.exe
[2006/02/18 03:30:56 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7c.exe
[2006/02/19 02:38:39 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7d.exe
[2006/02/20 04:02:01 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7e.exe
[2006/02/20 19:44:47 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7f.exe
[2006/02/21 19:21:40 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7g.exe
[2006/02/22 03:15:31 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7h.exe
[2006/02/23 19:28:32 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a7i.exe
[2006/03/03 20:08:46 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a8a.exe
[2006/03/05 21:57:46 | 000,020,480 | ---- | M] (.) -- C:\drsmartload849a8b.exe
[2006/03/07 21:24:48 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a8b5.exe
[2006/03/10 02:44:14 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a8b9.exe
[2006/03/10 20:54:02 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a8b9abc.exe
[2006/03/14 01:14:50 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a99.exe
[2006/08/19 11:21:46 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a999.exe
[2006/08/20 11:44:29 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\drsmartload849a9999.exe
[2006/02/07 03:51:15 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849y.exe
[2006/02/08 00:12:29 | 000,020,480 | ---- | M] (eww hduew yr78 y784) -- C:\drsmartload849z.exe
[2006/08/21 15:28:54 | 000,004,940 | ---- | M] (.) -- C:\dwin.exe
[2006/02/21 21:05:32 | 000,001,024 | ---- | M] () -- C:\gqyqhf.exe
[2006/02/15 05:27:28 | 000,827,613 | ---- | M] (instyler installation software) -- C:\gt.exe
[2006/08/18 15:30:25 | 000,000,338 | ---- | M] () -- C:\hehe.exe
[2006/02/21 21:04:51 | 000,001,024 | ---- | M] () -- C:\humxsgbm.exe
[2006/08/21 17:20:55 | 000,015,360 | ---- | M] () -- C:\iexplorer.exe
[2006/02/07 03:50:49 | 000,578,560 | ---- | M] () -- C:\Installer.exe
[2006/02/12 01:47:19 | 000,578,560 | ---- | M] () -- C:\Installer2.exe
[2006/02/17 05:51:30 | 000,578,560 | ---- | M] () -- C:\Installer3.exe
[2006/02/14 23:45:18 | 000,040,960 | ---- | M] (re8wru ehu hrweurhuweur 37wr3) -- C:\kybrdaca_6.exe
[2006/02/13 23:39:32 | 000,028,672 | ---- | M] (erijdf cisjtfgurhbyethb784yue7) -- C:\kybrdac_6.exe
[2006/02/10 04:10:35 | 000,040,960 | ---- | M] (re8wru ehu hrweurhuweur 37wr3) -- C:\kybrdad_5.exe
[2006/02/15 19:42:22 | 000,040,960 | ---- | M] (re8wru ehu hrweurhuweur 37wr3) -- C:\kybrddd_6.exe
[2006/02/18 03:30:47 | 000,028,672 | ---- | M] (re8wru ehu hrweurhuweur 37wr3) -- C:\kybrded_7.exe
[2006/02/20 20:04:20 | 000,032,768 | ---- | M] (|||?|||||||???||||) -- C:\kybrdef_7.exe
[2006/02/07 03:49:03 | 000,040,960 | ---- | M] (re8wru ehu hrweurhuweur 37wr3) -- C:\kybrde_5.exe
[2006/03/16 19:58:12 | 000,098,304 | ---- | M] (*&&*#&$*#RU*#Y&*#YR&Y#&RY#R) -- C:\kybrdff_11.exe
[2006/08/18 16:06:26 | 000,094,208 | ---- | M] (*&&*#&$*#RU*#Y&*#YR&Y#&RY#R) -- C:\kybrdff_11a.exe
[2006/08/21 14:41:01 | 000,098,304 | ---- | M] (*&&*#&$*#RU*#Y&*#YR&Y#&RY#R) -- C:\kybrdff_12.exe
[2006/02/28 05:35:28 | 000,086,016 | ---- | M] ((*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)) -- C:\kybrdff_7.exe
[2006/03/06 19:03:10 | 000,094,208 | ---- | M] (......) -- C:\kybrdff_8.exe
[2006/03/10 20:53:52 | 000,094,208 | ---- | M] (89482382884288442884382382488832) -- C:\kybrdff_9.exe
[2006/02/25 08:44:32 | 000,032,768 | ---- | M] (#$*&$*&#&$&*$&#&*$&*#$&*) -- C:\kybrdfg_7.exe
[2006/03/05 21:57:44 | 000,061,440 | ---- | M] ((*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)(*)) -- C:\kybrdfg_8.exe
[2006/03/13 21:11:56 | 000,094,208 | ---- | M] ((%)(%)(%)(%)(%)(%)(%)(%)(%)(%)) -- C:\kybrdfh_10.exe
[2006/02/21 21:05:31 | 000,001,024 | ---- | M] () -- C:\lemj.exe
[2006/03/12 07:56:01 | 001,014,304 | ---- | M] () -- C:\lips.exe
[2006/02/07 20:11:48 | 000,151,112 | ---- | M] () -- C:\mc-110-12-0000144.exe
[2006/02/08 06:38:04 | 000,131,137 | ---- | M] () -- C:\Mendoza1.exe
[2006/03/02 23:54:48 | 000,151,112 | ---- | M] () -- C:\mok32.exe
[2006/02/22 00:31:50 | 000,151,112 | ---- | M] () -- C:\moot32.exe
[2006/02/07 03:49:33 | 000,025,105 | ---- | M] () -- C:\MTE3NDI6ODoxNg.exe
[2006/03/10 21:57:19 | 000,678,344 | ---- | M] (Administrator) -- C:\musique.exe
[2006/03/11 22:32:10 | 000,678,344 | ---- | M] (Administrator) -- C:\musiqueti.exe
[2006/02/23 22:09:36 | 000,151,112 | ---- | M] () -- C:\mzt32.exe
[2006/08/21 14:57:45 | 000,016,384 | ---- | M] (.) -- C:\navy.exe
[2006/02/13 23:39:41 | 000,028,672 | ---- | M] (erijdf cisjtfgurhbyethb784yue7) -- C:\nwnmac_6.exe
[2006/02/10 04:10:36 | 000,028,672 | ---- | M] (ewe wr 2344 45 454545) -- C:\nwnmad_5.exe
[2006/02/16 06:43:28 | 000,032,768 | ---- | M] (erijdf cisjtfgurhbyethb784yue7) -- C:\nwnmdd_6.exe
[2006/02/18 03:30:49 | 000,032,768 | ---- | M] (erijdf cisjtfgurhbyethb784yue7) -- C:\nwnmed_7.exe
[2006/02/20 20:04:15 | 000,032,768 | ---- | M] (erijdf cisjtfgurhbyethb784yue7) -- C:\nwnmef_7.exe
[2006/02/07 03:49:15 | 000,028,672 | ---- | M] (ewe wr 2344 45 454545) -- C:\nwnme_5.exe
[2006/03/16 19:56:04 | 000,032,768 | ---- | M] ((%)(%)(%)(%)(%)(%)(%)(%)(%)(%)) -- C:\nwnmff_11.exe
[2006/08/21 14:41:04 | 000,032,768 | ---- | M] (04399289e8uwhru243y5r78f73yh3t7y3) -- C:\nwnmff_12.exe
[2006/02/28 21:03:59 | 000,032,768 | ---- | M] (&#&*&$*#&*$&*#&$*&*&$*&#*&#*) -- C:\nwnmff_7.exe
[2006/03/06 19:03:07 | 000,032,768 | ---- | M] (rew9q8er3289374823748782474723842) -- C:\nwnmff_8.exe
[2006/03/10 20:53:42 | 000,032,768 | ---- | M] (...............................................) -- C:\nwnmff_9.exe
[2006/02/25 08:44:53 | 000,032,768 | ---- | M] (&#&*&$*#&*$&*#&$*&*&$*&#*&#*) -- C:\nwnmfg_7.exe
[2006/03/05 21:57:31 | 000,032,768 | ---- | M] (rew9q8er3289374823748782474723842) -- C:\nwnmfg_8.exe
[2006/03/13 21:11:42 | 000,032,768 | ---- | M] ((%)(%)(%)(%)(%)(%)(%)(%)(%)(%)) -- C:\nwnmfh_10.exe
[2006/03/03 23:10:22 | 000,000,371 | ---- | M] () -- C:\outwin1.exe
[2006/02/21 21:04:49 | 000,072,704 | ---- | M] () -- C:\qjmm.exe
[2006/03/11 22:31:01 | 000,678,344 | ---- | M] (Administrator) -- C:\qmekimic.exe
[2006/03/16 23:10:49 | 000,692,606 | ---- | M] () -- C:\qo.exe
[2006/03/03 23:35:08 | 000,869,995 | ---- | M] (smart) -- C:\ret.exe
[2006/02/21 21:04:50 | 000,032,768 | ---- | M] () -- C:\rftojhv.exe
[2006/03/12 06:03:50 | 000,159,744 | ---- | M] () -- C:\scan.exe
[2006/03/12 22:13:00 | 000,678,344 | ---- | M] (Administrator) -- C:\schmblack.exe
[2006/03/08 21:42:09 | 000,148,992 | ---- | M] () -- C:\spam.exe
[2006/03/12 22:19:14 | 000,678,344 | ---- | M] (Administrator) -- C:\ssssdefr.exe
[2006/03/05 23:34:55 | 000,151,112 | ---- | M] () -- C:\tam32.exe
[2006/02/10 09:35:16 | 000,004,956 | ---- | M] (..) -- C:\toislf.exe
[2006/03/12 06:03:59 | 000,000,236 | ---- | M] () -- C:\tu.exe
[2006/02/21 19:20:33 | 000,517,168 | ---- | M] () -- C:\ucmoreiex.exe
[2006/03/10 22:07:05 | 000,678,344 | ---- | M] (Administrator) -- C:\uhytr.exe
[2006/03/09 00:24:52 | 000,858,144 | ---- | M] () -- C:\ux.exe
[2006/02/21 21:05:31 | 000,005,632 | ---- | M] () -- C:\viobqsd.exe
[2006/03/10 02:50:42 | 000,858,144 | ---- | M] () -- C:\w33d.exe
[2006/02/07 03:51:17 | 000,578,560 | ---- | M] () -- C:\warebundle2.exe
[2006/02/17 05:51:40 | 000,578,560 | ---- | M] () -- C:\warebundle3.exe
[2006/02/07 03:50:40 | 000,578,560 | ---- | M] () -- C:\warebundlenew.exe
[2006/02/12 06:15:07 | 000,578,560 | ---- | M] () -- C:\warebundlenewer.exe
[2006/02/22 02:06:45 | 000,016,157 | ---- | M] () -- C:\wdb.exe
[2006/02/21 05:51:18 | 000,016,157 | ---- | M] () -- C:\wdl.exe
[2006/03/09 07:33:01 | 000,161,740 | ---- | M] () -- C:\wew.exe
[2006/03/07 01:34:30 | 000,135,460 | ---- | M] () -- C:\wgfhfg.exe
[2006/02/22 00:24:39 | 000,020,480 | ---- | M] (.) -- C:\windiwl.exe
[2006/02/19 09:17:30 | 000,020,480 | ---- | M] (.) -- C:\windowl.exe
[2006/02/23 22:08:41 | 000,020,480 | ---- | M] (.) -- C:\windui.exe
[2006/02/22 04:30:41 | 000,020,480 | ---- | M] (.) -- C:\windwl.exe
[2006/02/26 05:25:21 | 000,006,131 | ---- | M] () -- C:\winpatch.exe
[2006/03/17 04:55:45 | 000,066,745 | ---- | M] () -- C:\winquidsaan.exe
[2006/02/17 06:39:09 | 000,020,480 | ---- | M] (.) -- C:\winsdl.exe
[2006/03/15 02:49:18 | 000,135,680 | ---- | M] () -- C:\winsystesm.exe
[2006/02/18 06:26:32 | 000,020,480 | ---- | M] (.) -- C:\winzdl.exe
[2006/03/07 02:14:32 | 000,020,480 | ---- | M] (*$(*$#*$#&$&*$&*#&&$##&&$*#) -- C:\wksv.exe
[2006/03/05 23:34:52 | 000,130,558 | ---- | M] () -- C:\woa32.exe
[2006/03/02 23:55:41 | 000,130,558 | ---- | M] () -- C:\ww32.exe
[2006/03/10 21:50:19 | 000,682,150 | ---- | M] (Instyler® Software) -- C:\yhaaa.exe
< MD5 for: AGP440.SYS >
[2001/08/17 21:58:00 | 000,025,472 | ---- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF -- C:\WINDOWS\system32\drivers\AGP440.SYS
< MD5 for: ATAPI.SYS >
[2002/08/29 11:50:10 | 010,158,890 | ---- | M] () .cab file -- C:\I386\sp1.cab:atapi.sys
[2002/08/29 11:50:10 | 010,158,890 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp1.cab:atapi.sys
[2002/10/17 01:31:10 | 000,087,040 | ---- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 -- C:\I386\ATAPI.SYS
[2002/10/17 01:31:10 | 000,087,040 | ---- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2002/10/17 01:31:10 | 000,087,040 | ---- | M] (Microsoft Corporation) MD5=3DF589B9A15FF9EF4AA499F98C1C16D5 -- C:\WINDOWS\system32\drivers\ATAPI.SYS
[2002/08/29 09:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\$NtUninstallQ331060$\ATAPI.SYS
[2002/08/29 09:27:50 | 000,086,912 | ---- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA -- C:\WINDOWS\system32\ReinstallBackups\0005\DriverFiles\i386\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2002/08/29 11:40:52 | 000,049,152 | ---- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2002/08/29 11:41:08 | 000,399,360 | ---- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2002/08/29 11:41:12 | 000,174,592 | ---- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 -- C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2003/02/19 21:18:16 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2003/02/19 21:18:16 | 000,626,688 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2003/02/19 21:18:16 | 000,405,504 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< >
========== Files - Unicode (All) ==========
[2006/02/07 03:54:00 | 000,000,000 | ---D | M](C:\WINDOWS\?icrosoft) -- C:\WINDOWS\Μicrosoft
[2006/02/07 03:54:00 | 000,000,000 | ---D | C](C:\WINDOWS\?icrosoft) -- C:\WINDOWS\Μicrosoft
[2006/02/07 03:53:00 | 000,000,000 | ---D | M](C:\WINDOWS\System32\?ymantec) -- C:\WINDOWS\System32\Ѕymantec
[2006/02/07 03:52:39 | 000,000,000 | ---D | C](C:\WINDOWS\System32\?ymantec) -- C:\WINDOWS\System32\Ѕymantec
< End of report >
Malwarebytes' Anti-Malware 1.44
Database version: 3830
Windows 5.1.2600 Service Pack 1
Internet Explorer 6.0.2800.1106
3/7/2010 3:33:54 AM
mbam-log-2010-03-07 (03-33-54).txt
Scan type: Full Scan (C:\|D:\|)
Objects scanned: 143170
Time elapsed: 26 minute(s), 13 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\system32\timedrv26.sys (Backdoor.HacDef) -> Quarantined and deleted successfully.
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
Any ideas?
Thanks in advance.
Edited by mechanima, 06 March 2010 - 10:17 PM.