A while back I had a problem with Virtumonde and you guys helped me out. Here's a link to that thread: http://www.geekstogo...ed-t273493.html
While I don't have any recurrence of that one, my PC started acting up again shortly after I cleaned it. I chaulked it up to Windows being Windows, but lots of crazy stuff happening recently (BSODs, foreign programs wanting Internet access) led me to think I was either still or re-infected. A Malwarebytes scan hit 3 files, all associated with Rootkit.Agent. AVG Antivirus's rootkit scanner found nothing, But GMER did report rootkit-like activity.
System specs:
Dell Dimension 9100
Windows XP Pro, SP3
I ran the prerequisite programs TFC, ERUNT, MBAM, GMER and OTL. All ran fine except: the first time I ran GMER, part way into the scan I got a BSOD; the file RNDISMP.SYS caused a STOP error. I have the entire error message written out, including memory addresses, if needed. I had to boot into safe mode for it to run to completion. Hope that didn't affect the scan. Also, when I ran OTL, I only got one log file. There is no extras.txt. I remember this happening last time so I'm wondering if it was done away with or if my malware is interfering with it.
Here are the logs:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4143
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
5/25/2010 7:42:06 PM
mbam-log-2010-05-25 (19-42-06).txt
Scan type: Quick scan
Objects scanned: 141282
Time elapsed: 17 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Documents and Settings\Eric\Local Settings\temp\70.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Local Settings\temp\qoox.dll (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Documents and Settings\Eric\Local Settings\Temporary Internet Files\Content.IE5\MSM92GYQ\yH321d989bV0100f080006R7b25c934102T669674f0201l0409317P000000070[1] (Rootkit.Agent) -> Quarantined and deleted successfully.
---------
GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-05-25 21:03:16
Windows 5.1.2600 Service Pack 3
Running: gmer.exe; Driver: C:\DOCUME~1\Eric\LOCALS~1\Temp\ffdoapob.sys
---- System - GMER 1.0.15 ----
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateKey [0xF745D514]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcess [0xF744C282]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwCreateProcessEx [0xF744C474]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteKey [0xF745DD00]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwDeleteValueKey [0xF745DFB8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwOpenKey [0xF745C3FA]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwRenameKey [0xF745E422]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwSetValueKey [0xF745D7D8]
SSDT PCTCore.sys (PC Tools KDS Core Driver/PC Tools) ZwTerminateProcess [0xF744BF32]
---- Devices - GMER 1.0.15 ----
AttachedDevice \Driver\Tcpip \Device\Ip avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\Tcp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
Device \Driver\atapi \Device\Ide\IdePort0 8AD6DEC0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T0L0-4 8AD6DEC0
Device \Driver\atapi \Device\Ide\IdePort1 8AD6DEC0
Device \Driver\atapi \Device\Ide\IdePort2 8AD6DEC0
Device \Driver\atapi \Device\Ide\IdeDeviceP0T1L0-c 8AD6DEC0
Device \Driver\atapi \Device\Ide\IdeDeviceP1T0L0-17 8AD6DEC0
Device \Driver\USB_RNDIS \Device\{62F78C4A-D970-4A38-B300-774A3180A88C} RNDISMP.SYS (Remote NDIS Miniport/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Udp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \Driver\Tcpip \Device\RawIp avgtdix.sys (AVG Network connection watcher/AVG Technologies CZ, s.r.o.)
AttachedDevice \FileSystem\Fastfat \Fat fltmgr.sys (Microsoft Filesystem Filter Manager/Microsoft Corporation)
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\ControlSet002\Services\AvgLdx86@RenameOnShutdown ?????p??avgrkx86.sys????????????????????Provides launch functionality for DCOM services.????%SystemRoot%\system32\svchost.exe -k netsvcs?c???????????:?????e?????:?=?=??0403?????????????p??????t???Manages the configuration and tracking of Component Object Model (COM)+-based components. If the service is stopped, most COM+-based components will not function properly. If this service is disabled, any services that explicitly depend on it will fail to start.????????,?????????????????????????????? ??????????????p???????????????????????????Brother RemovableDisk(U)????C:\WINDOWS\system32\dlbtcoms.exe -service???Filter????????????????????????????8???????????h??????7?7?7???????????????.???????????????????e???%?%0.??%SystemRoot%\system32\svchost.exe -k netsvcs?i???????????????????????????????e?????????????g????????????????ca???%?%0???????????????????????AVG WatchDog????SCSI miniport????????????????F??tM??COM+ System Application?????100??K??primary_ide_channel??????????????6???????e??? (???????????????????,??????S?????
Reg HKLM\SYSTEM\CurrentControlSet\Services\AvgLdx86@RenameOnShutdown ???;?-??LegacyDriver? ??? ???;?????????????????7???7???7???;????? ???????7???????????7?O?????????????????????????????n?????sr????????-??? ^??<???O??????sD???????????????????.??????????Lo??????0???0????<?<?<?<?;????N??;???0??d4??{7b47881d-4d79-4369-adf5-d1293852d36b}?????????<????? ???????<?????????????P???????? ??? ????????,??? ???????,?????,?,??? ??;???,?????,?,??ndis5,ndis5_ip6??,?????;?????????8???????T?????????????????s?>??? ?????????????????????P???????????????????sin??x86 Family 15 Model 4 Stepping 3, GenuineIntel????????N??>???d?????sLe??enum?????<???;?????????????g????scheduler?loadbalance?avgfilter?failover????2?3?4????Q???;??? ??????????????l??????<?????????;???????????????????????????????????????????????<??Network Adapters????1?2?3?????????h??v?????????eTO???;?;?;?;?;?;????? ???<???????????????????????l???????P??IPv6 Helper Service????????????????G?????????<???M??? ???1???9?????e?:??? ???????S??????????? (??@???P?????nsc??????????????2???????????????????? ???????????????????<?P???????????????????
Reg HKLM\SYSTEM\ControlSet005\Services\AvgLdx86@RenameOnShutdown ?????????????????????5?????e????AVG Firewall?<??? ???????.??????????LocalSystem?S\??????????????????????????????????????????????t??????????????????????????????????g??????T???????????h?????\SystemRoot\System32\Drivers\avgldx86.sys?????4????????????e????AVG AVI Loader Driver x86????????????3??ms??????????????p????????????a??????????????????????????????????????????????????t\??AVG??????????????t??????ET???????????\?g\W??PNP_TDI?\A????T??????e????hsht??\SystemRoot\System32\Drivers\avgmfx86.sys?????X??????S?????em3??AVG On-access Scanner Minifilter Driver x86?????????????????????????????????p???????????????????????????????t?????????????????????????????????????????????????????????<???????????h?????System32\Drivers\avgrkx86.sys??????????????????e????avgrkx86.sys????????????????????????????????t?????????????????????????R???????????h?????\SystemRoot\System32\Drivers\avgtdix.sys????Base??????????0????????????e????AVG8 Network Redirector??????????????o??pm??????????????????????V????e?g?r???????????????????????? ????????
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sector 00: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 10: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 11: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 12: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 57: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 62: rootkit-like behavior;
Disk \Device\Harddisk0\DR0 sector 63: rootkit-like behavior;
---- EOF - GMER 1.0.15 ----
OTL logfile created on: 5/26/2010 1:38:26 AM - Run 3
OTL by OldTimer - Version 3.2.1.0 Folder = C:\Documents and Settings\Eric\Desktop\HelpApps
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 81.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 461.55 Gb Total Space | 283.11 Gb Free Space | 61.34% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: D7C2Q581
Current User Name: Eric
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/04/20 02:25:06 | 000,620,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgnsx.exe
PRC - [2010/04/06 23:35:01 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eric\Desktop\HelpApps\OTL.exe
PRC - [2010/03/29 13:33:28 | 001,101,152 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgchsvx.exe
PRC - [2010/03/05 15:22:53 | 000,508,184 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgrsx.exe
PRC - [2010/03/05 15:22:48 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgwdsvc.exe
PRC - [2010/03/05 15:21:29 | 002,325,816 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgfws9.exe
PRC - [2010/03/05 15:21:23 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgemc.exe
PRC - [2010/03/05 15:21:23 | 000,710,424 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgcsrvx.exe
PRC - [2010/03/05 15:21:20 | 000,836,888 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG9\avgam.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2010/01/07 14:09:38 | 000,105,632 | ---- | M] (Corel) -- C:\Program Files\Common Files\Corel\Standby\Standby.exe
PRC - [2009/12/30 19:47:38 | 000,523,408 | ---- | M] (Corel, Inc.) -- C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe
PRC - [2009/10/04 00:39:11 | 000,160,592 | ---- | M] (Siber Systems) -- C:\Program Files\Siber Systems\AI RoboForm\robotaskbaricon.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/04/04 14:37:59 | 000,088,584 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\Gaming Software\LWEMon.exe
PRC - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
PRC - [2005/04/25 09:50:08 | 000,139,264 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2005/04/25 09:49:52 | 000,086,142 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
PRC - [2005/03/23 00:20:44 | 000,339,968 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2005/01/27 02:02:00 | 000,086,016 | ---- | M] () -- C:\Program Files\Dell\Media Experience\DMXLauncher.exe
PRC - [2004/08/14 02:11:16 | 001,533,952 | ---- | M] (Cisco Linksys Corporation) -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GS.exe
PRC - [2004/07/27 17:50:18 | 000,081,920 | ---- | M] (InstallShield Software Corporation) -- C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
PRC - [2004/03/10 21:57:06 | 000,045,056 | ---- | M] () -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InfoMyCa.exe
PRC - [2004/02/06 23:56:14 | 000,041,025 | ---- | M] (GEMTEKS) -- C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
PRC - [2003/10/29 03:06:00 | 000,024,576 | R--- | M] (BVRP Software) -- C:\Program Files\Digital Line Detect\DLG.exe
PRC - [2003/09/17 11:43:36 | 000,057,344 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe
PRC - [2003/06/18 02:00:00 | 000,045,056 | ---- | M] (Creative Technology Ltd) -- C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.exe
========== Modules (SafeList) ==========
MOD - [2010/04/06 23:35:01 | 000,561,664 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Eric\Desktop\HelpApps\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Running] -- -- (WUSB54GSSVC)
SRV - [2010/03/05 15:22:48 | 000,308,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgwdsvc.exe -- (avg9wd)
SRV - [2010/03/05 15:21:29 | 002,325,816 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgfws9.exe -- (avgfws9)
SRV - [2010/03/05 15:21:23 | 000,916,760 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG9\avgemc.exe -- (avg9emc)
SRV - [2010/02/19 20:30:16 | 000,067,360 | ---- | M] (NOS Microsystems Ltd.) [On_Demand | Stopped] -- C:\Program Files\NOS\bin\getPlus_Helper.dll -- (getPlusHelper) getPlus®
SRV - [2008/11/09 16:48:14 | 000,602,392 | ---- | M] (Yahoo! Inc.) [Disabled | Stopped] -- C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe -- (YahooAUService)
SRV - [2007/07/24 12:15:14 | 000,185,632 | ---- | M] (Protexis Inc.) [Auto | Running] -- c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe -- (PSI_SVC_2)
SRV - [2005/04/25 09:49:52 | 000,086,142 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe -- (IAANTMon) Intel®
SRV - [2004/10/25 22:01:52 | 000,421,888 | ---- | M] (Dell) [On_Demand | Stopped] -- C:\WINDOWS\System32\dlbtcoms.exe -- (dlbt_device)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1A 4A 9A DF 86 B5 CA 01 [binary data]
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = <local>
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "http://www.comcast.net"
FF - prefs.js..extensions.enabledItems: {22119944-ED35-4ab1-910B-E619EA06A115}:6.9.97
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.812
FF - prefs.js..extensions.enabledItems: avg@igeared:4.002.023.004
FF - prefs.js..extensions.enabledItems: [email protected]:1.2
FF - prefs.js..extensions.enabledItems: {0545b830-f0aa-4d7e-8820-50a4629a56fe}:4.6
FF - prefs.js..extensions.enabledItems: {1280606b-2510-4fe0-97ef-9b5a22eafe41}:1.0.9
FF - prefs.js..extensions.enabledItems: {1018e4d6-728f-4b20-ad56-37578a4de76b}:4.0.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: [email protected]:7
FF - prefs.js..extensions.enabledItems: [email protected]:2.0
FF - prefs.js..extensions.enabledItems: {02450954-cdd9-410f-b1da-db804e18c671}:0.96.3
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.2.20100119091315
FF - prefs.js..keyword.URL: "http://us.yhs.search...?...tb-web_us="
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010/04/22 21:36:30 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{22119944-ED35-4ab1-910B-E619EA06A115}: C:\Program Files\Siber Systems\AI RoboForm\Firefox [2009/08/18 15:01:44 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG9\Toolbar\Firefox\avg@igeared [2010/03/27 15:39:26 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/08 14:24:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/05/13 22:55:01 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Components: C:\Program Files\Mozilla Thunderbird\components [2010/02/17 18:29:06 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Thunderbird 3.0.1\extensions\\Plugins: C:\Program Files\Mozilla Thunderbird\plugins
[2010/02/09 05:08:44 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Mozilla\Extensions
[2010/02/09 05:08:44 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2010/05/25 18:30:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions
[2010/04/05 23:08:13 | 000,000,000 | ---D | M] (Screengrab) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{02450954-cdd9-410f-b1da-db804e18c671}
[2010/05/14 23:15:14 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{0545b830-f0aa-4d7e-8820-50a4629a56fe}
[2010/05/14 23:15:14 | 000,000,000 | ---D | M] (Flagfox) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{1018e4d6-728f-4b20-ad56-37578a4de76b}
[2010/01/09 02:26:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe41}
[2010/05/03 15:07:33 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/03/13 23:40:22 | 000,000,000 | ---D | M] (Linkification) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2010/03/13 23:40:24 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/09/23 12:45:20 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2009/10/02 15:44:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\[email protected]
[2009/09/30 01:20:10 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Mozilla\Firefox\Profiles\gqhqshtr.default\extensions\[email protected]
[2010/05/25 18:30:58 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/05/13 22:55:02 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/13 22:54:49 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2009/09/15 22:27:59 | 000,238,776 | ---- | M] (Pando Networks) -- C:\Program Files\Mozilla Firefox\plugins\npPandoWebInst.dll
[2009/08/17 16:39:27 | 000,693,048 | ---- | M] (Yahoo! Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npybrowserplus_2.4.17.dll
[2010/02/17 17:37:01 | 000,122,856 | ---- | M] (NOS Microsystems Ltd.) -- C:\Program Files\Mozilla Firefox\plugins\np_IEGetPlugin.dll
O1 HOSTS File: ([2010/04/08 16:10:15 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll (Sonic Solutions)
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.4.4525.1752\swg.dll (Google Inc.)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (&RoboForm) - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&RoboForm) - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files\Siber Systems\AI RoboForm\roboform.dll (Siber Systems Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG9\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [CTDVDDET] C:\Program Files\Creative\SBAudigy2ZS\DVDAudio\CTDVDDET.EXE (Creative Technology Ltd)
O4 - HKLM..\Run: [CTSysVol] C:\Program Files\Creative\SBAudigy2ZS\Surround Mixer\CTSysVol.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [DLBTCATS] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLBTtime.DLL ()
O4 - HKLM..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe ()
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [ISUSPM Startup] c:\Program Files\Common Files\InstallShield\UpdateService\ISUSPM.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [ISUSScheduler] C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe (InstallShield Software Corporation)
O4 - HKLM..\Run: [Lexmark X73 Button Manager] C:\Program Files\LexmarkX73\AcBtnMgr_X73.exe (Jetsoft Development Company)
O4 - HKLM..\Run: [Lexmark X73 Button Monitor] C:\Program Files\LexmarkX73\ACMonitor_X73.exe (Silitek Corp.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [Standby] c:\Program Files\Common Files\Corel\Standby\Standby.exe (Corel)
O4 - HKLM..\Run: [Start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe File not found
O4 - HKLM..\Run: [UpdReg] C:\WINDOWS\Updreg.EXE (Creative Technology Ltd.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKLM..\Run: [WUSB54GS] C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\InvokeSvc3.exe ()
O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKCU..\Run: [Corel Photo Downloader] C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe (Corel, Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\Dell Support\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [RoboForm] C:\Program Files\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe (Siber Systems)
O4 - HKCU..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe (BVRP Software)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Eric\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Customize Menu - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComCustomizeIEMenu.html ()
O8 - Extra context menu item: Fill Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O8 - Extra context menu item: Google Sidewiki... - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_60D6097707281E79.dll (Google Inc.)
O8 - Extra context menu item: RoboForm Toolbar - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O8 - Extra context menu item: Save Forms - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra 'Tools' menuitem : Fill Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F46} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComFillForms.html ()
O9 - Extra Button: Save - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra 'Tools' menuitem : Save Forms - {320AF880-6646-11D3-ABEE-C5DBF3571F49} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComSavePass.html ()
O9 - Extra Button: RoboForm - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O9 - Extra 'Tools' menuitem : RoboForm Toolbar - {724d43aa-0d85-11d4-9908-00400523e39a} - C:\Program Files\Siber Systems\AI RoboForm\RoboFormComShowToolbar.html ()
O16 - DPF: {40F576AD-8680-4F9E-9490-99D069CD665F} http://srtest-cdn.sy...eqlabdetect.cab (Reg Error: Key error.)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.4.2_03)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.ma...ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Eric\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Eric\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MSNLNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 18:15:00 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/11 18:02:12 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.dvacm - c:\Program Files\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.MPEGacm - c:\Program Files\Common Files\Ulead Systems\MPEG\MPEGACM.acm (Ulead Systems, Inc.)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.ulmp3acm - c:\Program Files\Common Files\Ulead Systems\MPEG\ulmp3acm.acm (Ulead systems)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: wave1 - C:\WINDOWS\System32\serwvdrv.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 14 Days ==========
[2100/02/08 16:03:54 | 000,053,248 | ---- | C] (Silitek Corp.) -- C:\Program Files\ACMonitor_X73.exe
[2010/05/25 17:40:29 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/05/25 17:26:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Eric\Application Data\Windows Desktop Search
[2010/05/25 17:26:17 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Desktop Search
[2010/05/25 17:26:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\GroupPolicy
[2010/05/22 13:09:24 | 016,555,584 | ---- | C] (Xceed Software Inc. 1-450-442-2626 [email protected] www.xceedsoft.com) -- C:\Documents and Settings\Eric\Desktop\R130119.EXE
[2009/11/22 05:47:33 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2009/11/22 05:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2009/11/22 05:47:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2009/08/18 14:23:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Application Data\McAfee.com Personal Firewall
[2005/08/16 23:10:20 | 000,065,536 | ---- | C] ( ) -- C:\WINDOWS\System32\a3d.dll
[2001/05/30 20:57:08 | 000,018,024 | ---- | C] ( ) -- C:\WINDOWS\System32\drivers\Lxarscan.sys
========== Files - Modified Within 14 Days ==========
[2010/05/26 01:30:36 | 000,000,047 | ---- | M] () -- C:\WINDOWS\ACMonitor_X73.ini
[2010/05/26 01:29:23 | 000,007,275 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2010/05/26 01:29:21 | 000,000,266 | ---- | M] () -- C:\WINDOWS\X73_DS.ini
[2010/05/26 01:29:13 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/05/26 01:28:59 | 000,000,236 | ---- | M] () -- C:\WINDOWS\tasks\OGALogon.job
[2010/05/26 01:28:50 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/05/26 01:28:45 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/05/26 01:28:43 | 3219,296,256 | -HS- | M] () -- C:\hiberfil.sys
[2010/05/26 01:27:30 | 008,912,896 | -H-- | M] () -- C:\Documents and Settings\Eric\NTUSER.DAT
[2010/05/26 01:27:29 | 000,031,056 | ---- | M] () -- C:\WINDOWS\System32\BMXStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2010/05/26 01:27:29 | 000,031,056 | ---- | M] () -- C:\WINDOWS\System32\BMXState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2010/05/26 01:27:29 | 000,030,528 | ---- | M] () -- C:\WINDOWS\System32\BMXCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2010/05/26 01:27:29 | 000,030,528 | ---- | M] () -- C:\WINDOWS\System32\BMXBkpCtrlState-{00000005-00000000-00000004-00001102-00000004-20061102}.rfx
[2010/05/26 01:27:29 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settingsbkup.sfm
[2010/05/26 01:27:29 | 000,001,080 | ---- | M] () -- C:\WINDOWS\System32\settings.sfm
[2010/05/26 01:27:29 | 000,000,384 | ---- | M] () -- C:\WINDOWS\System32\DVCStateBkp-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2010/05/26 01:27:29 | 000,000,384 | ---- | M] () -- C:\WINDOWS\System32\DVCState-{00000005-00000000-00000004-00001102-00000004-20061102}.dat
[2010/05/26 01:27:07 | 000,000,278 | -HS- | M] () -- C:\Documents and Settings\Eric\ntuser.ini
[2010/05/25 18:14:09 | 003,711,780 | -H-- | M] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\IconCache.db
[2010/05/25 17:34:54 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\prvlcl.dat
[2010/05/25 17:27:05 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/05/25 17:26:26 | 000,001,787 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/05/25 17:26:23 | 000,549,368 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/25 17:26:23 | 000,466,414 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/05/25 17:26:23 | 000,079,630 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/05/25 13:36:15 | 060,360,981 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2010/05/24 23:36:05 | 000,000,726 | ---- | M] () -- C:\WINDOWS\dellstat.ini
[2010/05/24 23:25:28 | 004,932,819 | ---- | M] () -- C:\WINDOWS\{00000005-00000000-00000004-00001102-00000004-20061102}.CDF
[2010/05/22 13:09:24 | 016,555,584 | ---- | M] (Xceed Software Inc. 1-450-442-2626 [email protected] www.xceedsoft.com) -- C:\Documents and Settings\Eric\Desktop\R130119.EXE
[2010/05/22 03:27:06 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/05/22 03:27:05 | 000,047,104 | ---- | M] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/21 22:44:47 | 000,590,284 | ---- | M] () -- C:\WINDOWS\System32\drivers\Avg\iavifw.avm
[2010/05/21 01:02:33 | 000,012,171 | ---- | M] () -- C:\Documents and Settings\Eric\My Documents\2010tips.ods
[2010/05/18 03:19:27 | 000,000,600 | ---- | M] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\PUTTY.RND
[2010/05/17 00:04:12 | 000,000,036 | -H-- | M] () -- C:\WINDOWS\System32\f9t.dat
========== Files Created - No Company Name ==========
[2100/02/08 15:53:34 | 000,001,437 | ---- | C] () -- C:\WINDOWS\GtX73.ini
[2100/02/08 15:53:34 | 000,001,437 | ---- | C] () -- C:\Program Files\gtx73.ini
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\WINDOWS\System32\yutimuwi
[2010/05/26 01:17:12 | 3219,296,256 | -HS- | C] () -- C:\hiberfil.sys
[2010/05/25 17:26:26 | 000,001,787 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Windows Search.lnk
[2010/04/06 14:45:06 | 000,002,692 | ---- | C] () -- C:\Documents and Settings\Eric\avgrep.txt
[2010/02/28 15:46:06 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2010/02/17 19:07:12 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\3DD9423E2F.sys
[2010/02/17 19:07:10 | 000,002,828 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/02/01 21:43:10 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\prvlcl.dat
[2010/01/13 19:50:42 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\PUTTY.RND
[2009/12/25 22:25:56 | 000,000,023 | ---- | C] () -- C:\WINDOWS\BlendSettings.ini
[2009/11/28 22:26:46 | 000,016,456 | ---- | C] () -- C:\WINDOWS\System32\pwdrvio.sys
[2009/11/28 22:26:46 | 000,011,088 | ---- | C] () -- C:\WINDOWS\System32\pwdspio.sys
[2009/11/28 21:04:52 | 000,014,976 | ---- | C] () -- C:\WINDOWS\System32\drivers\SBKUPNT.SYS
[2009/11/28 21:04:52 | 000,000,543 | ---- | C] () -- C:\WINDOWS\SWISV3.INI
[2009/11/28 21:04:51 | 000,000,287 | ---- | C] () -- C:\WINDOWS\SKNIFE.INI
[2009/11/28 21:04:19 | 000,002,799 | ---- | C] () -- C:\WINDOWS\SKLANG.INI
[2009/10/03 23:27:11 | 000,047,104 | ---- | C] () -- C:\Documents and Settings\Eric\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/15 23:09:41 | 000,000,045 | ---- | C] () -- C:\Documents and Settings\Eric\jagex_runescape_preferences2.dat
[2009/09/15 23:08:33 | 000,000,037 | ---- | C] () -- C:\Documents and Settings\Eric\jagex_runescape_preferences.dat
[2009/08/26 11:33:57 | 000,000,079 | ---- | C] () -- C:\Documents and Settings\Eric\default.pls
[2009/08/26 11:33:42 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/08/18 14:34:23 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2009/08/18 14:34:23 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2009/08/18 14:34:23 | 000,094,208 | ---- | C] () -- C:\WINDOWS\System32\GTW32N50.dll
[2009/08/18 14:34:04 | 000,001,733 | ---- | C] () -- C:\WINDOWS\System32\WLAN.INI
[2009/08/18 14:26:36 | 000,000,002 | ---- | C] () -- C:\WINDOWS\msoffice.ini
[2009/08/18 14:23:26 | 000,000,726 | ---- | C] () -- C:\WINDOWS\dellstat.ini
[2009/08/18 14:22:43 | 000,000,310 | ---- | C] () -- C:\Documents and Settings\Eric\convert.log
[2009/08/18 14:22:38 | 008,912,896 | -H-- | C] () -- C:\Documents and Settings\Eric\NTUSER.DAT
[2009/08/18 14:22:38 | 000,020,480 | -H-- | C] () -- C:\Documents and Settings\Eric\ntuser.dat.LOG
[2009/08/18 14:22:38 | 000,000,278 | -HS- | C] () -- C:\Documents and Settings\Eric\ntuser.ini
[2009/08/18 14:22:02 | 000,262,144 | ---- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT
[2009/08/18 14:22:02 | 000,001,024 | -H-- | C] () -- C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2009/08/03 16:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2007/09/27 10:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 10:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 10:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini
[2005/08/16 23:23:44 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/08/16 23:18:46 | 000,000,450 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2005/08/16 23:12:57 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2005/08/16 23:10:42 | 000,000,231 | ---- | C] () -- C:\WINDOWS\AC3API.INI
[2005/08/16 23:10:22 | 000,014,424 | ---- | C] () -- C:\WINDOWS\System32\Aud2_Del.ini
[2005/08/16 23:10:22 | 000,000,030 | ---- | C] () -- C:\WINDOWS\System32\ctzapxx.ini
[2005/08/16 23:10:20 | 000,000,194 | ---- | C] () -- C:\WINDOWS\System32\KILL.INI
[2005/08/16 23:10:00 | 000,000,136 | ---- | C] () -- C:\WINDOWS\SBWIN.INI
[2005/08/16 22:44:58 | 000,000,430 | ---- | C] () -- C:\WINDOWS\System32\dlbtplc.ini
[2005/08/16 22:44:12 | 000,000,375 | ---- | C] () -- C:\WINDOWS\System32\OEMINFO.INI
[2005/01/28 09:08:34 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2004/11/09 19:11:08 | 000,114,688 | ---- | C] () -- C:\WINDOWS\System32\dlbtcur.dll
[2004/11/09 19:10:28 | 000,573,440 | ---- | C] () -- C:\WINDOWS\System32\dlbtjswr.dll
[2004/11/09 19:05:58 | 000,069,632 | ---- | C] () -- C:\WINDOWS\System32\dlbtcu.dll
[2004/11/09 18:59:26 | 000,405,504 | ---- | C] () -- C:\WINDOWS\System32\dlbtutil.dll
[2004/08/23 15:42:30 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\dlbtsnls.dll
[2004/08/23 15:40:14 | 000,143,360 | ---- | C] () -- C:\WINDOWS\System32\dlbtcoin.dll
[2004/08/11 18:24:19 | 000,000,791 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2004/08/11 18:11:31 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/10/08 15:09:46 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\dlbtvs.dll
[2003/01/07 16:05:08 | 000,002,695 | ---- | C] () -- C:\WINDOWS\System32\OUTLPERF.INI
[2001/07/20 10:48:06 | 000,008,116 | ---- | C] () -- C:\Program Files\OSLO3071b2.USB
[2001/06/27 11:29:20 | 000,001,094 | ---- | C] () -- C:\WINDOWS\Lexmark_ICM.ini
[2000/12/05 15:56:34 | 000,114,688 | ---- | C] () -- C:\WINDOWS\lxarscan.dll
[2000/12/05 15:56:34 | 000,114,688 | ---- | C] () -- C:\Program Files\lxarscan.dll
[2000/10/24 09:08:36 | 000,118,784 | ---- | C] () -- C:\WINDOWS\System32\LFKODAK.DLL
[2000/10/24 09:08:33 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2000/01/11 12:50:48 | 000,000,047 | ---- | C] () -- C:\WINDOWS\ACMonitor_X73.ini
[2000/01/11 12:50:48 | 000,000,047 | ---- | C] () -- C:\Program Files\ACMonitor_X73.ini
[2000/01/11 12:42:22 | 000,000,266 | ---- | C] () -- C:\WINDOWS\X73_DS.ini
[1964/01/18 08:07:18 | 000,000,768 | ---- | C] () -- C:\Program Files\x73_lut.dat
========== LOP Check ==========
[2009/11/22 14:06:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2009/11/22 05:49:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\avg9
[2009/09/23 12:46:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Azureus
[2010/02/17 18:27:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo
[2009/09/17 03:29:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Last.fm
[2009/09/15 22:30:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PMB Files
[2009/08/18 15:01:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RoboForm
[2009/09/22 01:19:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Soulseek
[2010/02/13 19:35:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/02/17 18:27:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2009/08/22 14:25:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{92D9D9C1-B27F-45B5-BC1E-C7896D0B2FAA}
[2010/04/08 17:11:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\AVG9
[2010/01/13 21:31:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Azureus
[2010/02/14 01:59:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\CoffeeCup Software
[2009/08/25 04:56:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Leadertech
[2010/04/07 03:09:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\OpenOffice.org
[2009/08/27 23:18:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Opera
[2009/08/24 22:45:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Stamps.com Internet Postage
[2010/04/09 00:00:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\SystemRequirementsLab
[2010/02/09 05:08:36 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Thunderbird
[2010/02/17 18:30:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Ulead Systems
[2010/05/25 17:26:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Eric\Application Data\Windows Desktop Search
[2010/05/26 01:28:59 | 000,000,236 | ---- | M] () -- C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2004/08/11 18:15:00 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2009/09/20 14:34:58 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/04/08 15:59:05 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/04/10 13:27:21 | 000,865,784 | ---- | M] () -- C:\ComboFix.txt
[2004/08/11 18:15:00 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2005/08/16 22:56:06 | 000,006,569 | RH-- | M] () -- C:\dell.sdr
[2009/08/18 14:23:06 | 000,000,100 | ---- | M] () -- C:\dlbt.log
[2010/05/26 01:28:43 | 3219,296,256 | -HS- | M] () -- C:\hiberfil.sys
[2010/02/24 03:47:23 | 011,225,082 | ---- | M] () -- C:\immudebug.log
[2009/08/18 15:19:00 | 000,004,128 | ---- | M] () -- C:\INFCACHE.1
[2004/08/11 18:15:00 | 000,000,000 | -H-- | M] () -- C:\IO.SYS
[2005/08/16 23:17:32 | 000,000,838 | -H-- | M] () -- C:\IPH.PH
[2009/09/15 13:50:49 | 000,000,065 | ---- | M] () -- C:\jetscan.log
[2010/05/25 17:01:17 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2009/09/20 00:24:34 | 000,000,016 | --S- | M] () -- C:\mnt
[2004/08/11 18:15:00 | 000,000,000 | -H-- | M] () -- C:\MSDOS.SYS
[2004/08/04 06:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2010/01/18 17:06:17 | 000,250,048 | ---- | M] () -- C:\ntldr
[2010/05/26 01:28:42 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2005/08/16 23:17:38 | 000,000,087 | ---- | M] () -- C:\SystemInfo.ini
[2010/04/06 20:27:07 | 000,000,408 | ---- | M] () -- C:\VundoFix.txt
< %systemroot%*./mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
Invalid Environment Variable:
< %systemroot%\System32\config\*.sav >
[2004/08/11 18:06:14 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2004/08/11 18:06:14 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2004/08/11 18:06:14 | 000,876,544 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\drivers\*.sys /180 >
[2010/03/05 15:21:23 | 000,216,200 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgldx86.sys
[2010/03/05 15:22:53 | 000,029,512 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgmfx86.sys
[2010/03/05 15:21:20 | 000,052,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgrkx86.sys
[2010/04/20 02:25:06 | 000,242,896 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\WINDOWS\system32\drivers\avgtdix.sys
[2010/04/29 15:39:26 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/10 16:41:08 | 000,015,648 | ---- | M] (Meetinghouse Data Communications) -- C:\WINDOWS\system32\drivers\mdc8021x.sys
[2010/02/24 09:11:07 | 000,455,680 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\mrxsmb.sys
[2009/12/31 12:50:03 | 000,353,792 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\srv.sys
[2010/02/11 08:02:15 | 000,226,880 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\tcpip6.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 112 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2
< End of report >