Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Trojan Horse Hider.DLU


  • Please log in to reply

#1
darkdemonette

darkdemonette

    New Member

  • Member
  • Pip
  • 1 posts
EDIT: have now posted OTL scan report

Thanks for your help in advance. AVG has picked up Trojan Horse Hider.DLU on my system restore files, is there anyway you can help me get rid of this, driving me crazy.

OTL logfile created on: 08/11/2010 17:32:21 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\User\My Documents\Downloads
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 58.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 228.94 Gb Total Space | 201.85 Gb Free Space | 88.17% Space Free | Partition Type: NTFS

Computer Name: USER-36B845E86D | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2010/11/08 17:32:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\My Documents\Downloads\OTL.exe
PRC - [2010/10/27 11:09:27 | 002,806,000 | ---- | M] (Emsi Software GmbH) -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe
PRC - [2010/10/18 04:03:16 | 003,987,808 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgui.exe
PRC - [2010/10/17 11:45:35 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/10/11 11:58:12 | 006,104,656 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/10/11 11:58:12 | 000,725,072 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/10/06 16:24:38 | 000,652,640 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/10/06 16:24:36 | 001,065,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2010/10/06 16:24:08 | 000,845,664 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgcsrvx.exe
PRC - [2010/10/06 16:24:08 | 000,647,008 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/09/15 04:29:10 | 002,745,696 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2010/09/14 23:02:44 | 000,910,296 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/09/14 23:02:44 | 000,014,808 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
PRC - [2010/09/10 00:45:22 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/09/10 00:45:18 | 003,210,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgfws.exe
PRC - [2010/09/07 02:50:22 | 001,047,392 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgemcx.exe
PRC - [2010/09/07 02:50:08 | 000,745,824 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgam.exe
PRC - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2009/07/23 16:23:56 | 000,178,720 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
PRC - [2009/07/23 16:23:54 | 000,387,616 | ---- | M] () -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
PRC - [2008/04/14 04:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2008/03/03 16:06:00 | 001,848,648 | ---- | M] (CANON INC.) -- C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
PRC - [2008/01/22 08:35:52 | 000,103,808 | ---- | M] () -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe


========== Modules (SafeList) ==========

MOD - [2010/11/08 17:32:02 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\My Documents\Downloads\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll


========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand | Stopped] -- C:\WINDOWS\System32\appmgmts.dll -- (AppMgmt)
SRV - [2010/10/27 11:09:27 | 002,806,000 | ---- | M] (Emsi Software GmbH) [Auto | Running] -- C:\Program Files\Emsisoft Anti-Malware\a2service.exe -- (a2AntiMalware)
SRV - [2010/10/11 11:58:12 | 006,104,656 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/06 10:31:48 | 000,517,448 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe -- (AVG Security Toolbar Service)
SRV - [2010/09/10 00:45:22 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2010/09/10 00:45:18 | 003,210,176 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG10\avgfws.exe -- (avgfws)
SRV - [2010/08/13 11:58:56 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
SRV - [2010/03/18 15:47:22 | 000,035,160 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe -- (aspnet_state)
SRV - [2010/03/18 12:16:28 | 000,753,504 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe -- (WPFFontCache_v0400)
SRV - [2010/03/18 12:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2010/03/18 12:16:28 | 000,124,240 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe -- (NetTcpPortSharing)
SRV - [2009/07/23 16:23:56 | 000,178,720 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe -- (nSvcIp)
SRV - [2009/07/23 16:23:54 | 000,387,616 | ---- | M] () [Auto | Running] -- C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe -- (ForceWare Intelligent Application Manager (IAM)) ForceWare Intelligent Application Manager (IAM)
SRV - [2008/01/22 08:35:52 | 000,103,808 | ---- | M] () [Auto | Running] -- C:\Program Files\Canon\IJPLM\ijplmsvc.exe -- (IJPLMSVC)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | System | Stopped] -- C:\WINDOWS\System32\drivers\ymhhyobb.sys -- (ymhhyobb)
DRV - [2010/10/24 16:36:17 | 000,164,896 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\nvgts.sys -- (nvgts)
DRV - [2010/09/19 07:57:36 | 000,072,808 | ---- | M] (Emsi Software GmbH) [File_System | On_Demand | Stopped] -- C:\Program Files\Emsisoft Anti-Malware\a2accx86.sys -- (a2acc)
DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys -- (AVGIDSEH)
DRV - [2010/09/07 02:49:00 | 000,298,448 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys -- (Avgtdix)
DRV - [2010/09/07 02:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 02:48:54 | 000,249,424 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys -- (Avgldx86)
DRV - [2010/09/07 02:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys -- (Avgrkx86)
DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2010/07/12 03:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)
DRV - [2010/07/12 03:33:54 | 000,030,432 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)
DRV - [2010/04/03 21:55:32 | 010,232,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010/02/16 22:45:06 | 000,019,320 | ---- | M] (REALiX™) [Kernel | System | Running] -- C:\Program Files\HWiNFO32\HWiNFO32.SYS -- (HWiNFO32)
DRV - [2009/12/15 09:27:42 | 006,020,128 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/11/17 23:17:00 | 001,395,800 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2009/11/17 23:16:00 | 001,691,480 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2009/07/01 03:53:34 | 000,013,824 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2009/07/01 03:53:30 | 000,066,688 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2008/04/13 21:06:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/04/16 15:46:34 | 000,033,792 | ---- | M] (Advanced Micro Devices) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\AmdPPM.sys -- (AmdPPM)
DRV - [2004/08/13 02:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)
DRV - [2003/06/12 06:47:42 | 000,024,704 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\PhTVTune.sys -- (PhTVTune)
DRV - [2003/06/05 06:04:22 | 000,350,752 | ---- | M] (Philips Semiconductors) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Cap7134.sys -- (Cap7134) MEDION (7134)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.mytalktalk.co.uk
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.selectedEngine: "AVG Secure Search"
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1151
FF - prefs.js..extensions.enabledItems: avg@igeared:6.010.006.004
FF - prefs.js..keyword.URL: "http://search.avg.co...k&lng=en-GB&q="

FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/10/17 11:46:20 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/10/26 10:23:09 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/10/22 13:42:52 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/10/17 11:46:14 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.10\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/10/17 11:46:28 | 000,000,000 | ---D | M]

[2010/10/07 11:36:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2010/11/08 13:07:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xkx3m9sr.default\extensions
[2010/10/09 21:07:52 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xkx3m9sr.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/11/03 12:44:43 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\xkx3m9sr.default\extensions\[email protected]
[2010/10/07 11:34:37 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010/09/14 21:09:10 | 000,001,538 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/09/14 21:09:10 | 000,000,947 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/09/14 21:09:10 | 000,000,769 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/09/14 21:09:10 | 000,001,135 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml

O1 HOSTS File: ([2010/10/24 16:17:44 | 000,000,098 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] File not found
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - Startup: C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} http://support.asus....ek_sys_ctrl.cab (asusTek_sysctrl Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.micros...b?1285074508435 (WUWebControl Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {56F9679E-7826-4C84-81F3-532071A8BCC5} - C:\Program Files\Windows Desktop Search\MsnlNamespaceMgr.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/21 18:07:11 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{5ee6f647-de13-11df-9231-20cf300d90b3}\Shell - "" = AutoRun
O33 - MountPoints2\{5ee6f647-de13-11df-9231-20cf300d90b3}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{798f1668-d201-11df-9212-20cf300d90b3}\Shell - "" = AutoRun
O33 - MountPoints2\{798f1668-d201-11df-9212-20cf300d90b3}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{c1cf4906-d9d7-11df-9222-20cf300d90b3}\Shell - "" = AutoRun
O33 - MountPoints2\{c1cf4906-d9d7-11df-9222-20cf300d90b3}\Shell\AutoRun - "" = Auto&Play
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/10/29 10:53:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\TweetDeckFast.FFF259DC0CE2657847BBB4AFF0E62062EFC56543.1
[2010/10/29 10:53:10 | 000,000,000 | ---D | C] -- C:\Program Files\TweetDeck
[2010/10/29 10:07:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\My Documents\My Received Files
[2010/10/27 11:07:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\EurekaLog
[2010/10/27 11:06:41 | 000,000,000 | ---D | C] -- C:\Program Files\Emsisoft Anti-Malware
[2010/10/27 11:06:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\My Documents\Anti-Malware
[2010/10/24 21:03:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\MpEngineStore
[2010/10/24 20:48:23 | 000,974,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc42.dll
[2010/10/24 20:48:23 | 000,953,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mfc40u.dll
[2010/10/24 20:48:19 | 000,617,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\comctl32.dll
[2010/10/24 20:46:34 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll
[2010/10/24 17:57:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Canon Easy-PhotoPrint EX
[2010/10/24 17:56:15 | 000,223,744 | ---- | C] (CANON INC.) -- C:\WINDOWS\System32\CNMLM97.DLL
[2010/10/24 16:30:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\GooredFix Backups
[2010/10/24 16:28:29 | 000,071,398 | ---- | C] (jpshortstuff) -- C:\Documents and Settings\User\Desktop\GooredFix.exe
[2010/10/24 16:17:43 | 000,000,000 | ---D | C] -- C:\_OTM
[2010/10/24 16:16:24 | 000,519,168 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTM.exe
[2010/10/24 16:16:06 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/10/24 16:15:22 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2010/10/24 16:11:00 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\User\Recent
[2010/10/24 16:08:22 | 000,000,000 | ---D | C] -- C:\Program Files\CCleaner
[2010/10/24 15:51:44 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2010/10/24 15:13:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Malwarebytes
[2010/10/24 15:13:30 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/10/24 15:13:28 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/10/24 15:13:28 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/10/24 15:13:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/10/22 18:38:57 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss
[2010/10/22 15:42:03 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Software
[2010/10/22 15:37:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\NCH Swift Sound
[2010/10/22 15:37:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010/10/22 15:37:11 | 000,000,000 | ---D | C] -- C:\Program Files\NCH Swift Sound
[2010/10/22 15:24:31 | 000,000,000 | ---D | C] -- C:\WINDOWS\Downloaded Installations
[2010/10/22 14:15:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\AVG Security Toolbar
[2010/10/22 13:43:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\AVG10
[2010/10/22 13:43:01 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/10/22 13:42:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG Security Toolbar
[2010/10/22 13:41:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/10/22 13:41:38 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\AVG
[2010/10/22 13:30:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2010/10/22 13:29:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Unused Desktop Shortcuts
[2010/10/19 18:01:44 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonIJEPPEX
[2010/10/18 22:28:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\WMTools Downloaded Files
[2010/10/17 11:46:14 | 000,185,920 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/10/17 11:46:08 | 000,006,656 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/10/17 11:46:08 | 000,005,632 | ---- | C] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/10/17 11:46:00 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\xing shared
[2010/10/17 11:45:36 | 000,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010/10/17 11:45:36 | 000,000,000 | ---D | C] -- C:\Program Files\Real
[2010/10/17 11:45:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Real
[2010/10/17 11:45:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Real
[2010/10/17 11:45:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Real
[2010/10/15 17:13:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/10/15 15:23:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\CanonIJ
[2010/10/15 15:17:45 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/10/15 15:17:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Canon
[2010/10/10 14:04:59 | 000,000,000 | ---D | C] -- C:\Temp
[2010/10/10 14:04:22 | 000,000,000 | ---D | C] -- C:\Program Files\MP4Converter
[2010/10/10 11:06:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Research In Motion
[2010/10/10 11:06:26 | 000,000,000 | ---D | C] -- C:\Program Files\Research In Motion
[2010/10/10 10:59:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\Apple Computer
[2010/10/10 10:59:39 | 000,107,368 | ---- | C] (GEAR Software Inc.) -- C:\WINDOWS\System32\GEARAspi.dll
[2010/10/10 10:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2010/10/10 10:58:52 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2010/10/10 10:58:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/10/10 10:58:09 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2010/10/10 10:58:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/10/10 10:57:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Apple
[2010/10/10 10:57:58 | 000,000,000 | ---D | C] -- C:\Program Files\Apple Software Update
[2010/10/10 10:57:24 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2010/10/10 10:57:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Apple
[2010/10/10 10:57:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Local Settings\Application Data\Apple Computer
[2010/10/09 21:38:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Application Data\PhotoFiltre
[2010/10/09 21:19:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Identities

========== Files - Modified Within 30 Days ==========

[2010/11/08 17:28:48 | 000,000,420 | -H-- | M] () -- C:\WINDOWS\tasks\User_Feed_Synchronization-{B0CDA9C2-1CA2-4D40-A15B-0A58CC6D1B5A}.job
[2010/11/08 17:00:00 | 000,000,370 | ---- | M] () -- C:\WINDOWS\tasks\At3.job
[2010/11/08 17:00:00 | 000,000,370 | ---- | M] () -- C:\WINDOWS\tasks\At2.job
[2010/11/08 17:00:00 | 000,000,370 | ---- | M] () -- C:\WINDOWS\tasks\At1.job
[2010/11/08 13:00:38 | 098,723,087 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/11/08 12:55:51 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-854245398-630328440-725345543-1004.job
[2010/11/08 12:55:32 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-630328440-725345543-1004.job
[2010/11/08 12:55:27 | 000,000,104 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2010/11/08 12:55:25 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2010/11/08 12:55:24 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-854245398-630328440-725345543-1006.job
[2010/11/08 12:54:20 | 000,000,310 | -HS- | M] () -- C:\WINDOWS\tasks\XNDLLSALB.job
[2010/11/08 12:54:16 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/11/07 12:54:26 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/11/07 12:51:26 | 000,000,020 | ---- | M] () -- C:\WINDOWS\System32\GTHRCTR6.DLL
[2010/11/05 18:43:55 | 000,000,649 | ---- | M] () -- C:\Documents and Settings\User\Desktop\PhotoFiltre.lnk
[2010/11/05 18:42:44 | 000,627,856 | ---- | M] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2010/11/05 18:38:43 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/11/03 15:34:47 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2010/11/03 15:07:44 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/11/03 14:59:21 | 000,000,276 | ---- | M] () -- C:\WINDOWS\tasks\mixpadShakeIcon.job
[2010/11/03 14:26:34 | 000,000,802 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2010/11/02 17:39:27 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-630328440-725345543-1006.job
[2010/10/31 12:30:31 | 003,207,360 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 O Fortuna_Bat Out of [bleep] (Medley.mp3
[2010/10/31 09:31:44 | 000,557,916 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/10/31 09:31:44 | 000,108,370 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/10/30 23:37:00 | 000,002,137 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/29 15:37:09 | 000,000,296 | ---- | M] () -- C:\WINDOWS\tasks\expressburnShakeIcon.job
[2010/10/29 10:53:10 | 000,000,640 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2010/10/28 14:19:31 | 000,000,690 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2010/10/27 11:06:54 | 000,000,706 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Emsisoft Anti-Malware.lnk
[2010/10/27 11:06:54 | 000,000,688 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2010/10/26 19:18:50 | 002,489,410 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 The Rhythm of the Night (X Factor.mp3
[2010/10/26 19:18:49 | 000,258,816 | ---- | M] () -- C:\Documents and Settings\User\My Documents\02 Wagner - Audio Message.mp3
[2010/10/25 10:12:07 | 000,000,288 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2010/10/25 10:08:52 | 000,095,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/24 22:38:10 | 002,420,447 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 Spice Up Your Life_Livin_ La Vida.mp3
[2010/10/24 22:38:09 | 003,382,464 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 Help Yourself (X Factor Performan.mp3
[2010/10/24 22:38:09 | 002,576,345 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 Telephone (X Factor Finalist Perf.mp3
[2010/10/24 21:39:45 | 002,199,720 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 We Built This City (X Factor Perf.mp3
[2010/10/24 21:04:12 | 000,001,393 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/10/24 21:03:06 | 000,000,183 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2010/10/24 16:36:17 | 000,164,896 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\System32\drivers\nvgts.sys
[2010/10/24 16:31:34 | 001,325,656 | ---- | M] (Kaspersky Lab ZAO) -- C:\Documents and Settings\User\Desktop\TDSSKiller.exe
[2010/10/24 16:28:29 | 000,071,398 | ---- | M] (jpshortstuff) -- C:\Documents and Settings\User\Desktop\GooredFix.exe
[2010/10/24 16:17:44 | 000,000,098 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\Hosts
[2010/10/24 16:16:25 | 000,519,168 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTM.exe
[2010/10/24 16:15:26 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/10/24 16:15:23 | 000,000,611 | ---- | M] () -- C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2010/10/24 16:15:23 | 000,000,592 | ---- | M] () -- C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2010/10/24 16:12:28 | 000,057,430 | ---- | M] () -- C:\Documents and Settings\User\My Documents\cc_20101024_171218.reg
[2010/10/24 16:08:24 | 000,000,682 | ---- | M] () -- C:\Documents and Settings\User\Desktop\CCleaner.lnk
[2010/10/24 15:51:44 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\User\Desktop\HiJackThis.exe
[2010/10/24 15:28:11 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/24 15:13:32 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 19:15:13 | 000,000,223 | RHS- | M] () -- C:\boot.ini
[2010/10/22 15:37:49 | 000,000,870 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Express Burn Disc Burning Software.lnk
[2010/10/22 15:37:45 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\MixPad Audio Mixer.lnk
[2010/10/22 15:37:11 | 000,000,798 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WavePad Sound Editor.lnk
[2010/10/22 15:25:54 | 001,075,270 | ---- | M] () -- C:\00.bmp
[2010/10/18 23:18:01 | 003,184,576 | ---- | M] () -- C:\Documents and Settings\User\My Documents\01 She Bangs_Love Shack (Medley) [X.mp3
[2010/10/18 22:24:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/17 11:46:14 | 000,185,920 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\rmoc3260.dll
[2010/10/17 11:46:08 | 000,006,656 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5016.dll
[2010/10/17 11:46:08 | 000,005,632 | ---- | M] (RealNetworks, Inc.) -- C:\WINDOWS\System32\pndx5032.dll
[2010/10/17 11:45:36 | 000,278,528 | ---- | M] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2010/10/16 15:17:08 | 000,001,683 | ---- | M] () -- C:\Documents and Settings\User\Desktop\n-Track Studio.lnk
[2010/10/15 16:02:15 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Tvugiho.dat
[2010/10/15 16:02:14 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Etocukururuli.bin
[2010/10/10 14:04:25 | 000,000,917 | ---- | M] () -- C:\Documents and Settings\User\Desktop\MP4 to MP3 Converter 3.lnk
[2010/10/10 12:44:24 | 000,013,132 | -H-- | M] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/10/10 11:06:46 | 000,001,956 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/10 10:58:27 | 000,001,604 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk

========== Files Created - No Company Name ==========

[2010/11/08 13:00:38 | 098,723,087 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2010/11/07 12:51:26 | 000,000,020 | ---- | C] () -- C:\WINDOWS\System32\GTHRCTR6.DLL
[2010/11/05 18:43:55 | 000,000,649 | ---- | C] () -- C:\Documents and Settings\User\Desktop\PhotoFiltre.lnk
[2010/11/05 18:42:44 | 000,627,856 | ---- | C] () -- C:\WINDOWS\System32\drivers\AVG\iavifw.avm
[2010/11/03 15:34:46 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\switchShakeIcon.job
[2010/11/03 15:07:44 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\wavepadShakeIcon.job
[2010/11/03 14:59:21 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\mixpadShakeIcon.job
[2010/10/31 12:24:58 | 003,207,360 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 O Fortuna_Bat Out of [bleep] (Medley.mp3
[2010/10/29 10:53:10 | 000,000,640 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\TweetDeck.lnk
[2010/10/27 11:06:54 | 000,000,706 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Emsisoft Anti-Malware.lnk
[2010/10/27 11:06:54 | 000,000,688 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Emsisoft Anti-Malware.lnk
[2010/10/24 21:39:40 | 002,199,720 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 We Built This City (X Factor Perf.mp3
[2010/10/24 21:39:31 | 002,489,410 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 The Rhythm of the Night (X Factor.mp3
[2010/10/24 21:39:17 | 002,576,345 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 Telephone (X Factor Finalist Perf.mp3
[2010/10/24 21:38:59 | 002,420,447 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 Spice Up Your Life_Livin_ La Vida.mp3
[2010/10/24 21:03:06 | 000,000,183 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2010/10/24 16:46:48 | 000,001,393 | ---- | C] () -- C:\WINDOWS\imsins.BAK
[2010/10/24 16:15:26 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\User\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2010/10/24 16:15:23 | 000,000,611 | ---- | C] () -- C:\Documents and Settings\User\Desktop\NTREGOPT.lnk
[2010/10/24 16:15:23 | 000,000,592 | ---- | C] () -- C:\Documents and Settings\User\Desktop\ERUNT.lnk
[2010/10/24 16:12:20 | 000,057,430 | ---- | C] () -- C:\Documents and Settings\User\My Documents\cc_20101024_171218.reg
[2010/10/24 16:08:24 | 000,000,682 | ---- | C] () -- C:\Documents and Settings\User\Desktop\CCleaner.lnk
[2010/10/24 15:13:32 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/10/22 15:37:53 | 000,000,802 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Switch Sound File Converter.lnk
[2010/10/22 15:37:51 | 000,000,296 | ---- | C] () -- C:\WINDOWS\tasks\expressburnShakeIcon.job
[2010/10/22 15:37:49 | 000,000,870 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Express Burn Disc Burning Software.lnk
[2010/10/22 15:37:45 | 000,000,784 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\MixPad Audio Mixer.lnk
[2010/10/22 15:37:11 | 000,000,798 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WavePad Sound Editor.lnk
[2010/10/22 15:25:54 | 001,075,270 | ---- | C] () -- C:\00.bmp
[2010/10/22 13:42:41 | 000,000,690 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[2010/10/19 08:48:43 | 000,000,292 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-630328440-725345543-1006.job
[2010/10/19 08:48:43 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-854245398-630328440-725345543-1006.job
[2010/10/18 22:26:59 | 003,382,464 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 Help Yourself (X Factor Performan.mp3
[2010/10/18 22:26:54 | 000,258,816 | ---- | C] () -- C:\Documents and Settings\User\My Documents\02 Wagner - Audio Message.mp3
[2010/10/18 20:57:08 | 000,000,288 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-18.job
[2010/10/18 20:57:08 | 000,000,280 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-18.job
[2010/10/17 11:46:21 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-854245398-630328440-725345543-1004.job
[2010/10/17 11:46:21 | 000,000,276 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-854245398-630328440-725345543-1004.job
[2010/10/16 15:17:08 | 000,001,683 | ---- | C] () -- C:\Documents and Settings\User\Desktop\n-Track Studio.lnk
[2010/10/15 16:00:42 | 000,000,310 | -HS- | C] () -- C:\WINDOWS\tasks\XNDLLSALB.job
[2010/10/10 14:04:59 | 003,184,576 | ---- | C] () -- C:\Documents and Settings\User\My Documents\01 She Bangs_Love Shack (Medley) [X.mp3
[2010/10/10 14:04:25 | 000,000,917 | ---- | C] () -- C:\Documents and Settings\User\Desktop\MP4 to MP3 Converter 3.lnk
[2010/10/10 12:44:24 | 000,013,132 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/10/10 11:06:46 | 000,001,956 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\BlackBerry Desktop Software.lnk
[2010/10/10 10:59:43 | 000,002,137 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/10/10 10:58:27 | 000,001,604 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/10/10 10:58:00 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/10/08 13:07:26 | 000,000,558 | ---- | C] () -- C:\Documents and Settings\User\Application Data\Rim.Desktop.HttpServerSetup.log
[2010/10/04 17:35:23 | 000,106,594 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\FASTWiz.log
[2010/09/23 15:54:24 | 000,011,264 | ---- | C] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/21 18:45:53 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010/09/21 18:26:23 | 000,023,054 | ---- | C] () -- C:\WINDOWS\Ascd_log.ini
[2010/09/21 18:25:53 | 000,005,810 | R--- | C] () -- C:\WINDOWS\System32\drivers\ASACPI.sys
[2010/09/21 18:25:48 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2010/09/21 18:25:46 | 000,019,256 | ---- | C] () -- C:\WINDOWS\Ascd_tmp.ini
[2010/09/21 18:25:45 | 000,010,296 | ---- | C] () -- C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
[2008/10/07 08:13:30 | 000,197,912 | ---- | C] () -- C:\WINDOWS\System32\physxcudart_20.dll
[2008/10/07 08:13:22 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelTraditionalChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSwedish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSpanish.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelSimplifiedChinese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelPortugese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelKorean.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelJapanese.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelGerman.dll
[2008/10/07 08:13:20 | 000,058,648 | ---- | C] () -- C:\WINDOWS\System32\AgCPanelFrench.dll
[2007/09/27 09:51:02 | 000,020,698 | ---- | C] () -- C:\WINDOWS\System32\idxcntrs.ini
[2007/09/27 09:48:48 | 000,030,628 | ---- | C] () -- C:\WINDOWS\System32\gsrvctr.ini
[2007/09/27 09:48:28 | 000,031,698 | ---- | C] () -- C:\WINDOWS\System32\gthrctr.ini

< End of report >

Edited by darkdemonette, 08 November 2010 - 11:34 AM.

  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP