Okay, ran all the steps,and still my IE homepage was changed to the same site, as well as my host fils being funky and trying to overwrite itself when something tries to acess it.
OTL logfile created on: 5/13/2010 7:54:08 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = E:\Documents and Settings\Administrator.MEMO.000\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 539.00 Mb Available Physical Memory | 53.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072G:\pagefile.sys 0 0 [binary data]
%SystemDrive% = E: | %SystemRoot% = E:\WINDOWS | %ProgramFiles% = E:\Program Files
Drive C: | 53.77 Gb Total Space | 4.70 Gb Free Space | 8.74% Space Free | Partition Type: FAT32
Drive D: | 15.63 Gb Total Space | 4.32 Gb Free Space | 27.66% Space Free | Partition Type: NTFS
Drive E: | 20.70 Gb Total Space | 1.38 Gb Free Space | 6.68% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
Drive G: | 133.42 Gb Total Space | 8.75 Gb Free Space | 6.56% Space Free | Partition Type: NTFS
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: MEMO3
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/05/13 19:23:50 | 000,570,880 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\OTL.exe
PRC - [2010/04/05 08:37:12 | 000,307,672 | ---- | M] (Mozilla Corporation) -- E:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/05/22 18:34:34 | 000,851,968 | ---- | M] () -- E:\Program Files\TVersity\Media Server\MediaServer.exe
PRC - [2009/03/23 23:31:30 | 000,917,504 | ---- | M] (Eset ) -- E:\Program Files\ESET\nod32kui.exe
PRC - [2009/03/23 23:31:30 | 000,507,904 | ---- | M] (Eset ) -- E:\Program Files\ESET\nod32krn.exe
PRC - [2009/03/05 16:28:08 | 000,585,728 | ---- | M] (TightVNC Group) -- E:\Program Files\TightVNC\WinVNC.exe
PRC - [2004/08/04 12:00:00 | 001,032,192 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2010/05/13 19:23:50 | 000,570,880 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\OTL.exe
MOD - [2004/08/04 12:00:00 | 001,050,624 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll
MOD - [2004/08/04 12:00:00 | 000,102,400 | ---- | M] (Microsoft Corporation) -- E:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (xzzoip)
SRV - File not found [Disabled | Stopped] -- -- (Wiyselp32)
SRV - File not found [Disabled | Stopped] -- -- (Wihkep32)
SRV - File not found [Disabled | Stopped] -- -- (Wibettin32)
SRV - [2009/12/07 00:19:00 | 001,590,216 | ---- | M] (UltraVNC) [On_Demand | Stopped] -- E:\Program Files\UltraVNC\WinVNC.exe -- (uvnc_service)
SRV - [2009/09/05 11:07:58 | 000,768,512 | ---- | M] () [Disabled | Stopped] -- E:\WINDOWS\system32\UsbService.exe -- (UsbService)
SRV - [2009/05/22 18:34:34 | 000,851,968 | ---- | M] () [Auto | Running] -- E:\Program Files\TVersity\Media Server\MediaServer.exe -- (TVersityMediaServer)
SRV - [2009/03/23 23:31:30 | 000,507,904 | ---- | M] (Eset ) [Auto | Running] -- E:\Program Files\Eset\nod32krn.exe -- (NOD32krn)
SRV - [2009/03/05 16:28:08 | 000,585,728 | ---- | M] (TightVNC Group) [Auto | Running] -- E:\Program Files\TightVNC\WinVNC.exe -- (winvnc)
SRV - [2007/11/06 15:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [Disabled | Stopped] -- E:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/03/14 20:19:10 | 000,779,824 | ---- | M] (Nero AG) [Disabled | Stopped] -- G:\Archivos de programa\Nero 7\Nero BackItUp\NBService.exe -- (NBService)
SRV - [2007/01/19 12:54:14 | 000,097,136 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- E:\Program Files\MSN Messenger\usnsvc.exe -- (usnjsvc)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)
DRV - [2009/09/09 13:59:32 | 000,082,380 | ---- | M] (Oak Technology Inc.) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\AFS2K.SYS -- (AFS2K)
DRV - [2009/03/29 20:24:20 | 000,717,296 | ---- | M] (Duplex Secure Ltd.) [Kernel | Disabled | Stopped] -- E:\WINDOWS\system32\drivers\sptd.sys -- (sptd)
DRV - [2009/03/23 23:31:30 | 000,502,368 | ---- | M] (Eset ) [Kernel | Auto | Running] -- E:\WINDOWS\system32\drivers\amon.sys -- (AMON)
DRV - [2009/02/18 14:44:00 | 006,308,224 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2009/01/20 18:53:06 | 005,027,840 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/12/24 05:40:12 | 000,080,256 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\NmPar.sys -- (NmPar)
DRV - [2008/12/16 06:10:34 | 000,070,016 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\NmSerial.sys -- (nmserial)
DRV - [2008/10/30 21:14:20 | 000,117,888 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2008/05/16 12:33:14 | 000,115,752 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016unic.sys -- (s0016unic) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM)
DRV - [2008/05/16 12:33:14 | 000,025,512 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016nd5.sys -- (s0016nd5) Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS)
DRV - [2008/05/16 12:33:14 | 000,015,016 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016mdfl.sys -- (s0016mdfl)
DRV - [2008/05/16 12:33:12 | 000,120,744 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016mdm.sys -- (s0016mdm)
DRV - [2008/05/16 12:33:12 | 000,114,216 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016mgmt.sys -- (s0016mgmt) Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM)
DRV - [2008/05/16 12:33:12 | 000,110,632 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016obex.sys -- (s0016obex)
DRV - [2008/05/16 12:33:12 | 000,089,256 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s0016bus.sys -- (s0016bus) Sony Ericsson Device 0016 driver (WDM)
DRV - [2008/05/14 11:27:44 | 000,066,432 | ---- | M] () [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\vuhub.sys -- (vuhub)
DRV - [2007/11/06 15:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/04/24 09:33:46 | 000,100,488 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s125mgmt.sys -- (s125mgmt) Sony Ericsson Device 125 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/24 09:33:46 | 000,098,696 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s125obex.sys -- (s125obex)
DRV - [2007/04/24 09:33:44 | 000,108,680 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s125mdm.sys -- (s125mdm)
DRV - [2007/04/24 09:33:42 | 000,015,112 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s125mdfl.sys -- (s125mdfl)
DRV - [2007/04/24 09:33:34 | 000,083,336 | ---- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\s125bus.sys -- (s125bus) Sony Ericsson Device 125 driver (WDM)
DRV - [2006/11/30 22:21:00 | 000,013,824 | ---- | M] (FSPro Labs) [Kernel | Boot | Running] -- E:\WINDOWS\SYSTEM32\DRIVERS\HFXP2.SYS -- (HFXP2)
DRV - [2006/09/24 08:28:46 | 000,005,248 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | Boot | Running] -- E:\WINDOWS\system32\speedfan.sys -- (speedfan)
DRV - [2006/09/05 12:58:26 | 000,061,536 | R--- | M] (MCCI) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\se58bus.sys -- (se58bus) Sony Ericsson Device 088 driver (WDM)
DRV - [2005/01/07 17:07:18 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\Hdaudbus.sys -- (HDAudBus)
DRV - [2004/11/22 06:03:56 | 000,061,440 | ---- | M] (Microchip Technology, Inc.) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\mchpusb.sys -- (PicUSB)
DRV - [2004/08/04 12:00:00 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2004/08/04 12:00:00 | 000,029,696 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- E:\WINDOWS\system32\drivers\ikajl.sys -- (cwwhwh)
DRV - [2004/08/03 23:07:56 | 000,059,264 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- E:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2004/08/03 23:07:46 | 000,063,744 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- E:\WINDOWS\system32\drivers\mf.sys -- (mf)
DRV - [2002/09/16 17:14:32 | 000,004,228 | ---- | M] (PowerQuest Corporation) [Kernel | System | Running] -- E:\WINDOWS\system32\drivers\PQNTDRV.sys -- (PQNTDrv)
DRV - [1996/04/03 14:33:26 | 000,005,248 | ---- | M] () [Kernel | Boot | Running] -- E:\WINDOWS\system32\giveio.sys -- (giveio)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.9348.cn/?205486
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = www.9348.cn/?205486
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [email protected]:4.0.21.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:2.2.280608
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: E:\Program Files\Mozilla Firefox\components [2009/03/24 09:54:46 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: E:\Program Files\Mozilla Firefox\plugins [2009/03/24 09:54:46 | 000,000,000 | ---D | M]
[2009/03/25 21:34:18 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Mozilla\Extensions
[2009/03/25 21:34:18 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Mozilla\Firefox\Profiles\6uvh8cew.default\extensions
[2009/05/30 11:18:16 | 000,000,000 | ---D | M] (IE Tab) -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Mozilla\Firefox\Profiles\6uvh8cew.default\extensions\{77b819fa-95ad-4f2c-ac7c-486b356188a9}
[2009/07/14 16:29:24 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Mozilla\Firefox\Profiles\6uvh8cew.default\extensions\[email protected]
[2010/04/18 02:06:46 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Mozilla\Firefox\Profiles\6uvh8cew.default\extensions\[email protected]
[2009/03/24 09:54:46 | 000,000,000 | ---D | M] -- E:\Program Files\Mozilla Firefox\extensions
O1 - HOSTS file present but inaccessible!
O4 - HKLM..\Run: [nod32kui] E:\Program Files\Eset\nod32kui.exe (Eset )
O4 - HKLM..\Run: [NvCplDaemon] E:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] E:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [WinVNC] E:\Program Files\TightVNC\WinVNC.exe (TightVNC Group)
O4 - HKCU..\Run: [DAEMON Tools Lite] E:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - G:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - G:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - E:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} http://www.systemreq...sreqlab_srl.cab (System Requirements Lab Class)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71} http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - E:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - E:\WINDOWS\explorer.exe (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/10/24 15:00:56 | 000,000,358 | -HS- | M] () - C:\AUTOEXEC.BAK -- [ FAT32 ]
O32 - AutoRun File - [2007/10/24 15:00:56 | 000,000,358 | -H-- | M] () - C:\AutoExec.bat -- [ FAT32 ]
O32 - AutoRun File - [2005/08/05 10:06:50 | 000,000,194 | ---- | M] () - C:\AUTOEXEC.NS0 -- [ FAT32 ]
O32 - AutoRun File - [2006/08/17 13:48:56 | 000,000,289 | ---- | M] () - C:\autoexec.nav -- [ FAT32 ]
O32 - AutoRun File - [2007/10/23 22:11:30 | 000,000,378 | -HS- | M] () - C:\AUTOEXEC.WIN -- [ FAT32 ]
O32 - AutoRun File - [2004/08/12 23:39:06 | 000,000,000 | -H-- | M] () - G:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2010/05/03 20:55:06 | 000,232,448 | ---- | M] () - G:\AutoSHSH-3.1.3+3.2--RC2.exe -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - \6to4.dll ()
NetSvcs: AppMgmt - E:\WINDOWS\system32\appmgmts.dll (Shenzhen QVOD Technology Co.,Ltd)
NetSvcs: Ias - E:\WINDOWS\system32\ias [2009/03/22 22:07:44 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: WmdmPmSN - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16620634377289728)
========== Files/Folders - Created Within 90 Days ==========
[2010/05/13 19:51:36 | 000,000,000 | ---D | C] -- E:\WINDOWS\temp
[2010/05/13 19:30:58 | 000,212,480 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWXCACLS.exe
[2010/05/13 19:30:58 | 000,161,792 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWREG.exe
[2010/05/13 19:30:58 | 000,136,704 | ---- | C] (SteelWerX) -- E:\WINDOWS\SWSC.exe
[2010/05/13 19:30:58 | 000,031,232 | ---- | C] (NirSoft) -- E:\WINDOWS\NIRCMD.exe
[2010/05/13 19:29:47 | 000,000,000 | ---D | C] -- E:\Qoobox
[2010/05/13 19:27:56 | 006,153,376 | ---- | C] (Malwarebytes Corporation ) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\mbam-setup-1.46.exe
[2010/05/13 19:23:58 | 000,570,880 | ---- | C] (OldTimer Tools) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\OTL.exe
[2010/05/12 18:58:12 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\fixing
[2010/05/12 18:38:37 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\LolClient
[2010/05/12 00:58:02 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Local Settings\Application Data\PMB Files
[2010/05/12 00:57:57 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\PMB Files
[2010/05/12 00:57:10 | 000,000,000 | ---D | C] -- E:\Program Files\Pando Networks
[2010/05/11 21:17:45 | 000,049,152 | ---- | C] (Tencent) -- E:\WINDOWS\System32\woaizuguo.ime
[2010/05/11 14:31:02 | 000,000,000 | RH-D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Recent
[2010/05/06 22:07:26 | 000,000,000 | ---D | C] -- E:\FOUND.000
[2010/05/04 21:52:37 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Local Settings\Application Data\Cranium_Consulting_and_Cu
[2010/04/19 20:06:25 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\LoLBaseUploader.1.2.0
[2010/03/12 14:37:33 | 000,000,000 | ---D | C] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\Real
[2010/03/03 20:20:29 | 000,000,000 | ---D | C] -- E:\MSNCleaner
[2010/03/03 20:05:12 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\backups
[2010/03/03 19:43:50 | 000,000,000 | ---D | C] -- E:\WINDOWS\ERDNT
[2010/03/02 21:38:25 | 000,000,000 | ---D | C] -- E:\Program Files\Sophos
[2010/03/02 19:54:50 | 000,401,720 | ---- | C] (Trend Micro Inc.) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\HijackThis.exe
[2010/02/17 15:20:47 | 000,000,000 | ---D | C] -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\Boardingpass.aspx_files
[9 C:\Mis documentos\*.tmp files -> C:\Mis documentos\*.tmp -> ]
[3 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/05/13 19:45:44 | 000,000,227 | ---- | M] () -- E:\WINDOWS\system.ini
[2010/05/13 19:45:18 | 000,213,319 | ---- | M] () -- E:\WINDOWS\System32\nvapps.xml
[2010/05/13 19:44:22 | 000,000,006 | -H-- | M] () -- E:\WINDOWS\tasks\SA.DAT
[2010/05/13 19:44:20 | 000,002,048 | --S- | M] () -- E:\WINDOWS\bootstat.dat
[2010/05/13 19:41:50 | 009,961,472 | -H-- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\NTUSER.DAT
[2010/05/13 19:30:20 | 003,688,866 | R--- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\George.exe
[2010/05/13 19:28:26 | 006,153,376 | ---- | M] (Malwarebytes Corporation ) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\mbam-setup-1.46.exe
[2010/05/13 19:23:50 | 000,570,880 | ---- | M] (OldTimer Tools) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\OTL.exe
[2010/05/13 18:51:50 | 000,002,184 | ---- | M] () -- E:\WINDOWS\System32\wpa.dbl
[2010/05/12 08:03:40 | 000,000,543 | ---- | M] () -- E:\Documents and Settings\All Users.WINDOWS\Desktop\Play League of Legends.lnk
[2010/05/12 01:06:24 | 000,070,016 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/05/12 00:54:06 | 000,002,560 | ---- | M] () -- E:\WINDOWS\System32\InetDummy.dll
[2010/05/12 00:48:16 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\msimg32.dll
[2010/05/12 00:48:12 | 000,049,152 | ---- | M] (Tencent) -- E:\WINDOWS\System32\woaizuguo.ime
[2010/05/12 00:40:40 | 000,000,000 | ---- | M] () -- E:\WINDOWS\System32\fvhm.dll
[2010/05/12 00:12:28 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\0004C1D5.new
[2010/05/12 00:03:20 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\0018A081.new
[2010/05/11 23:23:26 | 000,269,392 | ---- | M] () -- E:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/11 23:20:42 | 000,000,178 | -HS- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\ntuser.ini
[2010/05/11 22:58:40 | 000,000,012 | ---- | M] () -- E:\WINDOWS\System32\DELETEIT.bat
[2010/05/11 22:55:56 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\00103D1A.new
[2010/05/11 22:43:08 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\00100159.new
[2010/05/11 22:26:02 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\00046C91.new
[2010/05/11 21:48:40 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\00074880.new
[2010/05/11 21:36:14 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\0003FB2A.new
[2010/05/11 21:34:00 | 000,000,069 | ---- | M] () -- E:\WINDOWS\NeroDigital.ini
[2010/05/11 21:31:04 | 000,001,072 | RHS- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\ntuser.pol
[2010/05/11 21:17:48 | 000,003,584 | ---- | M] () -- E:\WINDOWS\System32\00097757.new
[2010/05/11 14:12:46 | 000,000,086 | ---- | M] () -- E:\WINDOWS\System32\tempc.bat
[2010/05/11 14:12:46 | 000,000,056 | ---- | M] () -- E:\WINDOWS\System32\temp2.bat
[2010/05/11 14:12:46 | 000,000,000 | ---- | M] () -- E:\WINDOWS\System32\xzzoip_svr.dat
[2010/05/11 14:11:32 | 000,003,262 | ---- | M] () -- E:\WINDOWS\̀Ô±¦Íø.ico
[2010/05/10 23:28:28 | 003,888,054 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\pjhreak.bmp
[2010/05/09 19:49:54 | 000,000,183 | ---- | M] () -- E:\WINDOWS\hpbafd.ini
[2010/05/05 22:18:54 | 003,888,054 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\untitled.bmp
[2010/05/04 21:54:08 | 000,564,211 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\SetupiPhoneBrowser.1.93.exe
[2010/05/01 11:57:12 | 000,007,454 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\processCreditCardPayment.do.htm
[2010/04/30 14:06:14 | 000,005,101 | ---- | M] () -- E:\WINDOWS\xnview.ini
[2010/04/30 11:54:18 | 000,022,016 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\PENDIENTES. MEMO AGUILAR.xls
[2010/04/30 08:46:54 | 000,015,872 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\PENDIENTES MEMO AGUILAR.xls
[2010/04/26 15:58:14 | 000,256,512 | ---- | M] () -- E:\WINDOWS\PEV.exe
[2010/04/24 16:20:38 | 000,008,558 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\logo.gif
[2010/04/18 21:38:44 | 006,961,328 | -H-- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Local Settings\Application Data\IconCache.db
[2010/04/08 21:00:32 | 000,184,319 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\powerlevel.JPG
[2010/03/15 21:41:54 | 000,678,535 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\4429654194_567ae6e920_o.jpg
[2010/03/07 23:38:26 | 001,207,677 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\batmanrobw1-6cvr.jpg
[2010/03/06 17:36:00 | 000,019,229 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\templateguy2.jpg
[2010/03/06 17:35:26 | 000,013,592 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\templateguy.jpg
[2010/03/04 16:09:28 | 008,238,193 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\gua.png
[2010/03/04 16:07:36 | 000,000,680 | ---- | M] () -- E:\WINDOWS\AUTOLNCH.REG
[2010/03/02 21:32:24 | 000,000,000 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\settings.dat
[2010/03/02 19:54:50 | 000,401,720 | ---- | M] (Trend Micro Inc.) -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\HijackThis.exe
[2010/03/01 10:02:28 | 000,053,850 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\ubicacion antena.JPG
[2010/03/01 10:02:06 | 001,106,262 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\ubiccacion antena.bmp
[2010/02/28 21:01:04 | 000,050,868 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\sandra estefania.jpg
[2010/02/28 20:58:24 | 000,030,622 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\margarita zacarias.jpg
[2010/02/28 20:57:40 | 000,023,326 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\andres freyria.jpg
[2010/02/28 20:57:14 | 000,013,815 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\guillermo aguilar.jpg
[2010/02/28 03:30:54 | 003,888,054 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\winscreen2.bmp
[2010/02/26 00:28:08 | 000,181,864 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\winscreen.JPG
[2010/02/25 20:42:32 | 000,002,137 | ---- | M] () -- E:\Documents and Settings\All Users.WINDOWS\Desktop\iTunes.lnk
[2010/02/17 15:22:52 | 000,003,395 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\Boardingpass2.aspx.htm
[2010/02/17 15:20:50 | 000,019,388 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\Boardingpass.aspx.htm
[2010/02/17 14:22:24 | 000,029,184 | ---- | M] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\FormuladeExcel.xls
[9 C:\Mis documentos\*.tmp files -> C:\Mis documentos\*.tmp -> ]
[3 E:\WINDOWS\*.tmp files -> E:\WINDOWS\*.tmp -> ]
[1 E:\WINDOWS\System32\*.tmp files -> E:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/05/13 19:30:58 | 000,256,512 | ---- | C] () -- E:\WINDOWS\PEV.exe
[2010/05/13 19:30:58 | 000,098,816 | ---- | C] () -- E:\WINDOWS\sed.exe
[2010/05/13 19:30:58 | 000,080,412 | ---- | C] () -- E:\WINDOWS\grep.exe
[2010/05/13 19:30:58 | 000,077,312 | ---- | C] () -- E:\WINDOWS\MBR.exe
[2010/05/13 19:30:58 | 000,068,096 | ---- | C] () -- E:\WINDOWS\zip.exe
[2010/05/13 19:22:14 | 003,688,866 | R--- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\George.exe
[2010/05/12 08:03:39 | 000,000,543 | ---- | C] () -- E:\Documents and Settings\All Users.WINDOWS\Desktop\Play League of Legends.lnk
[2010/05/12 00:54:22 | 000,002,560 | ---- | C] () -- E:\WINDOWS\System32\InetDummy.dll
[2010/05/11 22:58:15 | 000,000,012 | ---- | C] () -- E:\WINDOWS\System32\DELETEIT.bat
[2010/05/11 22:12:08 | 000,002,184 | ---- | C] () -- E:\WINDOWS\System32\wpa.dbl
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\msimg32.dll
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\0018A081.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\00103D1A.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\00100159.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\00074880.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\0004C1D5.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\00046C91.new
[2010/05/11 21:36:12 | 000,003,584 | ---- | C] () -- E:\WINDOWS\System32\0003FB2A.new
[2010/05/11 21:30:30 | 000,001,072 | RHS- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\ntuser.pol
[2010/05/11 14:12:45 | 000,000,086 | ---- | C] () -- E:\WINDOWS\System32\tempc.bat
[2010/05/11 14:12:45 | 000,000,056 | ---- | C] () -- E:\WINDOWS\System32\temp2.bat
[2010/05/11 14:12:45 | 000,000,000 | ---- | C] () -- E:\WINDOWS\System32\xzzoip_svr.dat
[2010/05/11 14:11:30 | 000,003,262 | ---- | C] () -- E:\WINDOWS\̀Ô±¦Íø.ico
[2010/05/10 23:28:23 | 003,888,054 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\pjhreak.bmp
[2010/05/05 22:18:49 | 003,888,054 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\untitled.bmp
[2010/05/04 21:54:07 | 000,564,211 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\SetupiPhoneBrowser.1.93.exe
[2010/05/01 11:57:09 | 000,007,454 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\processCreditCardPayment.do.htm
[2010/04/30 11:54:17 | 000,022,016 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\PENDIENTES. MEMO AGUILAR.xls
[2010/04/30 08:47:01 | 000,015,872 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\PENDIENTES MEMO AGUILAR.xls
[2010/04/08 21:00:30 | 000,184,319 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\powerlevel.JPG
[2010/03/15 21:41:52 | 000,678,535 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\4429654194_567ae6e920_o.jpg
[2010/03/07 23:38:24 | 001,207,677 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\batmanrobw1-6cvr.jpg
[2010/03/06 17:35:57 | 000,019,229 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\templateguy2.jpg
[2010/03/06 17:35:23 | 000,013,592 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\templateguy.jpg
[2010/03/04 16:08:51 | 008,238,193 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\gua.png
[2010/03/04 15:49:58 | 000,000,680 | ---- | C] () -- E:\WINDOWS\AUTOLNCH.REG
[2010/03/02 21:32:23 | 000,000,000 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\settings.dat
[2010/03/01 10:02:27 | 000,053,850 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\ubicacion antena.JPG
[2010/03/01 10:02:03 | 001,106,262 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\ubiccacion antena.bmp
[2010/02/28 21:00:38 | 000,050,868 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\sandra estefania.jpg
[2010/02/28 20:58:21 | 000,030,622 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\margarita zacarias.jpg
[2010/02/28 20:57:37 | 000,023,326 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\andres freyria.jpg
[2010/02/28 20:57:11 | 000,013,815 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\guillermo aguilar.jpg
[2010/02/28 03:30:49 | 003,888,054 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\winscreen2.bmp
[2010/02/26 00:28:06 | 000,181,864 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\winscreen.JPG
[2010/02/17 15:22:50 | 000,003,395 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\Boardingpass2.aspx.htm
[2010/02/17 15:20:47 | 000,019,388 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\Boardingpass.aspx.htm
[2010/02/17 14:22:34 | 000,029,184 | ---- | C] () -- E:\Documents and Settings\Administrator.MEMO.000\Desktop\FormuladeExcel.xls
[2009/12/28 22:44:16 | 000,000,262 | ---- | C] () -- E:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/09/09 20:34:33 | 000,000,183 | ---- | C] () -- E:\WINDOWS\hpbafd.ini
[2009/09/05 10:39:14 | 000,066,432 | ---- | C] () -- E:\WINDOWS\System32\drivers\vuhub.sys
[2009/08/05 21:15:07 | 000,000,151 | ---- | C] () -- E:\WINDOWS\PhotoSnapViewer.INI
[2009/06/28 14:22:44 | 000,007,680 | ---- | C] () -- E:\WINDOWS\System32\ff_vfw.dll
[2009/06/28 14:22:44 | 000,000,547 | ---- | C] () -- E:\WINDOWS\System32\ff_vfw.dll.manifest
[2009/05/25 17:43:11 | 000,005,101 | ---- | C] () -- E:\WINDOWS\xnview.ini
[2009/05/05 12:59:02 | 000,000,023 | ---- | C] () -- E:\WINDOWS\BlendSettings.ini
[2009/04/20 19:45:30 | 000,000,020 | ---- | C] () -- E:\WINDOWS\hppsapp.INI
[2009/04/20 19:15:41 | 000,101,376 | ---- | C] () -- E:\WINDOWS\System32\hpgt34.dll
[2009/04/20 19:15:09 | 000,306,688 | ---- | C] () -- E:\WINDOWS\System32\Lffpx7.dll
[2009/04/20 19:15:09 | 000,095,232 | ---- | C] () -- E:\WINDOWS\System32\Lfkodak.dll
[2009/03/29 11:50:44 | 000,000,069 | ---- | C] () -- E:\WINDOWS\NeroDigital.ini
[2009/03/24 00:18:44 | 000,168,448 | ---- | C] () -- E:\WINDOWS\System32\unrar.dll
[2009/02/18 14:44:00 | 001,724,416 | ---- | C] () -- E:\WINDOWS\System32\nvwdmcpl.dll
[2009/02/18 14:44:00 | 001,507,328 | ---- | C] () -- E:\WINDOWS\System32\nview.dll
[2009/02/18 14:44:00 | 001,101,824 | ---- | C] () -- E:\WINDOWS\System32\nvwimg.dll
[2009/02/18 14:44:00 | 000,466,944 | ---- | C] () -- E:\WINDOWS\System32\nvshell.dll
[2008/10/07 09:13:30 | 000,197,912 | ---- | C] () -- E:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | ---- | C] () -- E:\WINDOWS\System32\AgCPanelFrench.dll
[2008/08/01 16:13:40 | 000,303,104 | ---- | C] () -- E:\WINDOWS\System32\ShowHCRemCfgWnd.dll
[2008/08/01 14:24:58 | 000,032,768 | ---- | C] () -- E:\WINDOWS\System32\RemoteCfgRes_CHI.dll
[2008/08/01 14:24:08 | 000,032,768 | ---- | C] () -- E:\WINDOWS\System32\RemoteCfgRes_TRAD.dll
[2008/08/01 14:23:32 | 000,045,056 | ---- | C] () -- E:\WINDOWS\System32\RemoteCfgRes_ENG.dll
[2008/08/01 10:32:10 | 000,040,960 | ---- | C] () -- E:\WINDOWS\System32\Language.dll
[2008/07/30 14:36:00 | 000,356,352 | ---- | C] () -- E:\WINDOWS\System32\HCNetSDK.dll
[2008/07/30 11:17:34 | 000,417,792 | ---- | C] () -- E:\WINDOWS\System32\playm4.dll
[2007/11/06 15:19:28 | 000,053,299 | ---- | C] () -- E:\WINDOWS\System32\pthreadVC.dll
[2004/08/04 12:00:00 | 000,027,440 | ---- | C] () -- E:\WINDOWS\System32\drivers\secdrv.sys
[2004/08/04 12:00:00 | 000,000,000 | ---- | C] () -- E:\WINDOWS\System32\fvhm.dll
[2004/08/03 20:55:30 | 000,006,432 | ---- | C] () -- E:\WINDOWS\System32\drivers\26E62FDE.sys
[2001/11/17 13:25:08 | 000,094,274 | ---- | C] () -- E:\WINDOWS\System32\HPBHEALR.DLL
[1996/04/03 14:33:26 | 000,005,248 | ---- | C] () -- E:\WINDOWS\System32\giveio.sys
========== LOP Check ==========
[2009/03/25 08:34:02 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\Messenger Plus!
[2009/03/25 12:34:54 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\1.0.0.0
[2009/03/25 22:09:00 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\Azureus
[2009/03/29 20:26:50 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\DAEMON Tools Lite
[2009/05/05 09:04:18 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\KSP
[2009/05/12 23:26:40 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\Soulseek
[2009/07/29 21:00:36 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906}
[2009/09/05 11:07:34 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP
[2010/01/13 16:01:22 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/05/12 00:57:58 | 000,000,000 | ---D | M] -- E:\Documents and Settings\All Users.WINDOWS\Application Data\PMB Files
[2009/03/25 22:08:56 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Azureus
[2009/03/25 22:21:38 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\LimeWire
[2009/03/29 20:24:10 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\DAEMON Tools Lite
[2009/03/29 20:27:44 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\DAEMON Tools Pro
[2009/03/29 20:27:44 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\DAEMON Tools
[2009/03/29 21:17:26 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Bioshock
[2009/04/24 15:32:50 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\DMCache
[2009/05/20 21:31:58 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\BSplayer
[2009/05/20 21:31:58 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\BSplayer Pro
[2009/05/21 20:42:20 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Orbit
[2009/11/01 23:31:52 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\LolClient.F24C99354F615F3BAB18AE7B93E3F9B9E8784FA6.1
[2009/12/29 15:36:06 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\Softland
[2010/05/12 18:38:38 | 000,000,000 | ---D | M] -- E:\Documents and Settings\Administrator.MEMO.000\Application Data\LolClient
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2007/09/27 12:13:22 | 000,005,596 | ---- | M] () -- E:\_OOKIE~1.MOZ
[2007/09/27 12:13:22 | 000,001,253 | ---- | M] () -- E:\sessionstore.js.moztmp
[2007/12/18 22:57:38 | 000,003,734 | ---- | M] () -- E:\Bin 1.plb
[2009/03/23 23:24:38 | 000,000,010 | ---- | M] () -- E:\csb.log
[2009/08/26 00:40:32 | 1608,126,464 | -HS- | M] () -- E:\pagefile.sys
[2010/05/13 19:51:36 | 000,015,308 | ---- | M] () -- E:\ComboFix.txt
[2007/12/22 21:30:34 | 000,000,218 | -HS- | M] () -- E:\boot.inibkp
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\appmgmts.dll
[2009/03/24 21:14:42 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt00.sqm
[2008/11/29 11:15:06 | 000,002,575 | ---- | M] () -- E:\odbcconf.log
[2009/03/24 21:14:42 | 000,000,268 | -H-- | M] () -- E:\sqmdata00.sqm
[2009/03/25 10:28:34 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt01.sqm
[2009/03/25 10:28:34 | 000,000,268 | -H-- | M] () -- E:\sqmdata01.sqm
[2009/03/25 21:24:46 | 000,000,268 | -H-- | M] () -- E:\sqmdata06.sqm
[2009/03/25 12:45:40 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt02.sqm
[2009/03/25 12:45:40 | 000,000,268 | -H-- | M] () -- E:\sqmdata02.sqm
[2009/03/25 13:18:50 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt03.sqm
[2009/03/25 13:18:50 | 000,000,268 | -H-- | M] () -- E:\sqmdata03.sqm
[2009/03/25 16:00:48 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt04.sqm
[2009/03/25 16:00:48 | 000,000,268 | -H-- | M] () -- E:\sqmdata04.sqm
[2009/03/25 19:18:56 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt05.sqm
[2009/03/25 19:18:56 | 000,000,268 | -H-- | M] () -- E:\sqmdata05.sqm
[2009/03/25 21:24:46 | 000,000,244 | -H-- | M] () -- E:\sqmnoopt06.sqm
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\shsvcs.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\mspmsnsv.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\xmlprov.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\ntmssvc.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\upnphost.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\qmgr.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\mswsock.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\browser.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\cryptsvc.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\pchsvc.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\schedsvc.dll
[2004/08/03 20:55:30 | 000,050,289 | ---- | M] (Shenzhen QVOD Technology Co.,Ltd) -- E:\6to4.dll
[2010/05/11 22:38:48 | 000,000,886 | ---- | M] () -- E:\avenger.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2010/05/12 00:40:40 | 000,000,000 | ---- | M] () Unable to obtain MD5 -- E:\WINDOWS\system32\fvhm.dll
[1 E:\WINDOWS\system32\*.tmp files -> E:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/03/23 20:23:20 | 000,905,216 | ---- | M] () -- E:\WINDOWS\system32\config\system.sav
[2009/03/23 20:23:20 | 000,659,456 | ---- | M] () -- E:\WINDOWS\system32\config\software.sav
[2009/03/23 20:23:20 | 000,094,208 | ---- | M] () -- E:\WINDOWS\system32\config\default.sav
< %systemroot%\system32\drivers\*.sys /90 >
< End of report >
And lastly the MWB log.