Sorry for the failure of the basic rules of the forum.
Just help me draw up a script!
In report I can not see the infected files or dispute (unwanted) process.
OTL.txt
OTL logfile created on: 26.11.2010 12:26:50 - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = G:\My documents\Prenosi
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000424 | Country: Slovenia | Language: SLV | Date Format: d.M.yyyy
1.023,00 Mb Total Physical Memory | 464,00 Mb Available Physical Memory | 45,00% Memory free
3,00 Gb Paging File | 2,00 Gb Available in Paging File | 83,00% Paging File free
Paging file location(s): c:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 29,29 Gb Total Space | 4,42 Gb Free Space | 15,08% Space Free | Partition Type: NTFS
Drive D: | 47,03 Gb Total Space | 4,08 Gb Free Space | 8,68% Space Free | Partition Type: NTFS
Drive G: | 189,92 Gb Total Space | 38,05 Gb Free Space | 20,03% Space Free | Partition Type: NTFS
Computer Name: REZERVA | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - G:\My documents\Prenosi\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe (Adobe Systems Inc.)
PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
PRC - C:\Program Files\DynDNS Updater\DynUpSvc.exe (Dynamic Network Services, Inc.)
PRC - C:\Program Files\DynDNS Updater\DynTray.exe (Dynamic Network Services, Inc.)
PRC - C:\Program Files\eMule\emule.exe (
http://www.emule-project.net)
PRC - C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
PRC - C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
PRC - C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
PRC - C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
PRC - C:\Program Files\Hmonitor\hmonitor.exe (AB Software)
PRC - C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe (CANON INC.)
PRC - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Modules (SafeList) ========== MOD - G:\My documents\Prenosi\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ========== SRV - (HidServ) -- C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (DynDNS Updater) -- C:\Program Files\DynDNS Updater\DynUpSvc.exe (Dynamic Network Services, Inc.)
SRV - (ACDaemon) -- C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (NMSAccessU) -- C:\Program Files\CDBurnerXP\NMSAccessU.exe ()
SRV - (CCALib8) -- C:\Program Files\Canon\CAL\CALMAIN.exe (Canon Inc.)
SRV - (Autodesk Licensing Service) -- C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.)
SRV - (W3SVC) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (SMTPSVC) Simple Mail Transfer Protocol (SMTP) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (MSFtpsvc) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) -- C:\WINDOWS\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (FolderSize) -- C:\Program Files\FolderSize\FolderSizeSvc.exe (Brio)
SRV - (B&W License Server) -- C:\Program Files\BuW LicenseServer\i486_nt\obj\lmgrd.exe (Macrovision Corporation)
SRV - (UleadBurningHelper) -- C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe (Ulead Systems, Inc.)
========== Driver Services (SafeList) ========== DRV - (Trufos) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\trufos.sys File not found
DRV - (Profos) -- C:\Program Files\Common Files\BitDefender\BitDefender Threat Scanner\profos.sys File not found
DRV - (catchme) -- C:\ComboFix\catchme.sys File not found
DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH)
DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH)
DRV - (EverestDriver) -- C:\Program Files\Lavalys\EVEREST Ultimate Edition\kerneld.wnt ()
DRV - (StarOpen) -- C:\WINDOWS\System32\drivers\StarOpen.sys ()
DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH)
DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (cpuz132) -- C:\WINDOWS\system32\drivers\cpuz132_x32.sys (Windows ® Codename Longhorn DDK provider)
DRV - (cpuidlep) -- C:\WINDOWS\System32\drivers\cpuidlep.sys ()
DRV - (WFLR6654) WinFast TV2000 XP Global/Global TV (XC2028) -- C:\WINDOWS\system32\drivers\wfeaglxt.sys (Leadtek Research Inc.)
DRV - (nv) -- C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (MPE) -- C:\WINDOWS\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (gameenum) -- C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (LUMDriver) -- C:\WINDOWS\system32\drivers\LUMDriver.sys (IBM)
DRV - (CDRPDACC) Quinnware CDDA Driver (by InfinaDyne) -- C:\Program Files\Quintessential Media Player\cdrpdacc.sys (Arrowkey)
DRV - (hmonitor) -- C:\WINDOWS\system32\drivers\Hmonitor.sys ()
DRV - (pmem) -- C:\WINDOWS\system32\drivers\pmemnt.sys (Microsoft Corporation)
DRV - (nvnforce) Service for NVIDIA® nForce -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA® nForce -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (mbmiodrvr) -- C:\WINDOWS\system32\mbmiodrvr.sys (
[email protected])
DRV - (Sentinel) -- C:\WINDOWS\System32\Drivers\SENTINEL.SYS (Rainbow Technologies, Inc.)
DRV - (NVENET) -- C:\WINDOWS\system32\drivers\NVENET.sys (NVIDIA Corporation)
DRV - (nv_agp) -- C:\WINDOWS\system32\DRIVERS\nv_agp.sys (NVIDIA Corporation)
DRV - (sptd) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (ms_mpu401) -- C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems:
[email protected]:0.6.8
FF - prefs.js..network.proxy.socks: "24.80.170.231"
FF - prefs.js..network.proxy.socks_port: 26516
FF - prefs.js..network.proxy.socks_version: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\
[email protected]: C:\Program Files\MyWebSearch\bar\1.bin File not found
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010.10.29 11:23:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.15\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010.11.25 14:38:35 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\
[email protected]: C:\Program Files\BitDefender\BitDefender 2008\tbextension
[2001.12.31 23:53:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Mozilla\Extensions
[2010.11.26 12:20:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Mozilla\Firefox\Profiles\jxonht7i.default\extensions
[2010.08.18 23:20:06 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Mozilla\Firefox\Profiles\jxonht7i.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010.08.25 22:13:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Mozilla\Firefox\Profiles\jxonht7i.default\extensions\
[email protected][2010.11.26 12:20:08 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2010.08.06 13:19:22 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010.08.07 00:16:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2010.08.07 00:16:38 | 000,423,656 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010.09.20 03:49:50 | 000,001,503 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\iskalnik-gov-si.xml
[2010.09.20 03:49:50 | 000,001,420 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\najdi-si.xml
[2010.09.20 03:49:50 | 000,001,328 | ---- | M] () -- C:\Program Files\Mozilla Firefox\searchplugins\wikipedia-sl.xml
O1 HOSTS File: ([2002.01.03 08:18:06 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (Gretech Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Gretech Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Gretech Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [CnwiDeviceAgent] C:\Program Files\Canon\GAROStatusMonitor\cnwida.exe (CANON INC.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [hmonitor] C:\Program Files\Hmonitor\hmonitor.exe (AB Software)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O4 - HKCU..\Run: [eMuleAutoStart] C:\Program Files\eMule\emule.exe (
http://www.emule-project.net)
O4 - Startup: C:\Documents and Settings\Administrator.REZERVA\Start Menu\Programs\Startup\Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\DynDNS Updater Tray Icon.lnk = C:\Program Files\DynDNS Updater\DynTray.exe (Dynamic Network Services, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\GARO Status Monitor.lnk = C:\Program Files\Canon\GAROStatusMonitor\cnwism.exe (CANON INC.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Low Rights present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700}
http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {31435657-9980-0010-8000-00AA00389B71}
http://download.micr...78f/wvc1dmo.cab (Reg Error: Key error.)
O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967}
http://dlcdnet.asus....vex-2.2.5.0.cab (DLM Control)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499}
http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1276184575171 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_21)
O20 - AppInit_DLLs: (acaptuser32.dll) - C:\WINDOWS\System32\acaptuser32.dll (Adobe Systems Incorporated)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Reg Error: Value error. - Reg Error: Value error. File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008.11.21 14:43:07 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002.01.01 00:55:19 | 000,000,000 | ---D | M] - D:\AutoCAD_Inventor_2010_SC_X86 -- [ NTFS ]
O32 - AutoRun File - [2009.05.28 18:36:57 | 2203,549,694 | -H-- | M] () - D:\Autodesk.AutoCAD.Inventor.Professional.v2010.EN.SC.Win32.DVDISO.iso -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2010.11.25 14:38:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010.11.25 14:35:10 | 000,000,000 | ---D | C] -- C:\_AcroTemp
[2010.11.18 16:44:22 | 000,519,680 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Administrator.REZERVA\Desktop\OTM.exe
[2010.11.18 16:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Malwarebytes
[2010.11.17 13:16:29 | 000,000,000 | ---D | C] -- G:\My documents\Updater
[2010.11.13 03:04:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\PCHealth
[2010.11.12 15:34:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.REZERVA\Local Settings\Application Data\PCHealth
[2010.11.12 14:31:03 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Works
[2010.11.12 14:29:17 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW
[2010.11.12 14:29:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.REZERVA\Local Settings\Application Data\Microsoft Help
[2010.11.12 14:28:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft Help
[2010.11.12 14:28:21 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2010.11.09 12:17:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\vlc
[2010.11.05 01:09:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Opera
[2010.11.05 00:58:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Adobe Systems
[2010.11.05 00:54:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\Adobe PDF
[2010.11.05 00:54:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe Systems Shared
[2010.10.28 00:01:56 | 000,000,000 | ---D | C] -- C:\!KillBox
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ========== [2010.11.26 12:01:00 | 000,000,232 | ---- | M] () -- C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010.11.25 14:50:52 | 126,697,286 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\031.jpg
[2010.11.25 13:41:06 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010.11.25 13:41:05 | 1073,270,784 | -HS- | M] () -- C:\hiberfil.sys
[2010.11.24 17:30:57 | 000,038,912 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010.11.24 13:23:42 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010.11.24 13:23:38 | 000,240,736 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010.11.23 00:45:40 | 000,061,960 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2010.11.19 00:35:41 | 000,288,107 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\gmer.zip
[2010.11.18 16:44:12 | 000,519,680 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator.REZERVA\Desktop\OTM.exe
[2010.11.18 16:43:11 | 003,911,345 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\ComboFix.exe
[2010.11.18 16:28:48 | 000,115,048 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\Clipboard01.jpg
[2010.11.08 10:32:38 | 000,296,448 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\gmer.exe
[2010.11.05 01:18:28 | 000,540,844 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010.11.05 01:18:28 | 000,107,046 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010.11.05 00:54:44 | 000,000,988 | ---- | M] () -- C:\Documents and Settings\Administrator.REZERVA\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2010.11.04 11:22:48 | 000,001,742 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Adobe Acrobat 9 Pro Extended.lnk
[2010.11.03 10:43:03 | 000,126,856 | ---- | M] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[12 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ========== [2010.11.25 14:38:54 | 126,697,286 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\031.jpg
[2010.11.19 00:42:07 | 000,296,448 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\gmer.exe
[2010.11.19 00:42:02 | 000,288,107 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\gmer.zip
[2010.11.18 16:42:42 | 003,911,345 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\ComboFix.exe
[2010.11.18 16:28:48 | 000,115,048 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Desktop\Clipboard01.jpg
[2010.11.05 00:54:44 | 000,000,988 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Start Menu\Programs\Startup\Adobe Gamma.lnk
[2010.10.04 17:26:28 | 000,000,144 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Local Settings\Application Data\fusioncache.dat
[2010.09.22 21:55:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\tmpPrst.dll
[2010.09.22 21:55:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\ssprs.dll
[2010.09.22 21:55:51 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\lsprst7.dll
[2010.05.25 00:20:36 | 000,108,032 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2010.04.14 23:04:39 | 000,007,909 | ---- | C] () -- C:\WINDOWS\System32\ftpctrs.ini
[2010.04.14 22:49:34 | 000,021,791 | ---- | C] () -- C:\WINDOWS\System32\smtpctrs.ini
[2010.04.14 22:49:34 | 000,001,037 | ---- | C] () -- C:\WINDOWS\System32\ntfsdrct.ini
[2010.04.14 22:48:56 | 000,038,576 | ---- | C] () -- C:\WINDOWS\System32\w3ctrs.ini
[2010.04.14 22:48:56 | 000,010,225 | ---- | C] () -- C:\WINDOWS\System32\axperf.ini
[2010.04.14 22:48:55 | 000,011,435 | ---- | C] () -- C:\WINDOWS\System32\infoctrs.ini
[2010.02.04 21:14:10 | 000,000,107 | ---- | C] () -- C:\WINDOWS\VobEdit.INI
[2010.02.04 20:07:35 | 000,482,816 | ---- | C] () -- C:\WINDOWS\System32\VFCodec.dll
[2009.11.19 02:38:45 | 000,038,912 | ---- | C] () -- C:\Documents and Settings\Administrator.REZERVA\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009.03.06 10:09:31 | 000,043,520 | ---- | C] () -- C:\WINDOWS\System32\CmdLineExt03.dll
[2009.02.17 17:14:10 | 000,000,436 | ---- | C] () -- C:\WINDOWS\SAP2000v9.ini
[2009.02.17 17:13:51 | 000,002,048 | ---- | C] () -- C:\WINDOWS\System32\sysprs7.dll
[2009.02.17 17:13:51 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth2.dll
[2009.02.17 17:13:51 | 000,001,025 | ---- | C] () -- C:\WINDOWS\System32\clauth1.dll
[2009.01.12 11:52:50 | 000,000,161 | ---- | C] () -- C:\WINDOWS\System32\AddPort.ini
[2009.01.12 11:51:44 | 000,000,672 | ---- | C] () -- C:\WINDOWS\hpntwksetup.ini
[2009.01.12 11:45:18 | 000,000,658 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2009.01.06 16:31:23 | 000,004,484 | ---- | C] () -- C:\WINDOWS\System32\drivers\cpuidlep.sys
[2008.12.04 17:58:20 | 000,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008.12.04 16:55:36 | 000,026,491 | ---- | C] () -- C:\WINDOWS\CSTBox.INI
[2008.12.02 18:55:34 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\bassmod.dll
[2008.12.02 15:39:49 | 000,691,696 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2008.12.01 23:21:32 | 000,434,176 | ---- | C] () -- C:\WINDOWS\System32\CNQL3203.DLL
[2008.11.28 11:59:13 | 000,164,352 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2008.11.28 11:59:13 | 000,000,038 | ---- | C] () -- C:\WINDOWS\avisplitter.ini
[2008.11.21 15:34:28 | 000,000,121 | ---- | C] () -- C:\WINDOWS\bdagent.INI
[2008.11.21 15:19:19 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2008.01.09 15:01:48 | 000,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007.03.19 07:15:00 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2007.03.19 07:15:00 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2007.03.19 07:15:00 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2007.03.19 07:15:00 | 000,581,632 | ---- | C] () -- C:\WINDOWS\System32\nvhwvid.dll
[2007.03.19 07:15:00 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2007.03.19 07:15:00 | 000,286,720 | ---- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2006.10.05 14:31:22 | 000,007,188 | ---- | C] () -- C:\WINDOWS\System32\drivers\Hmonitor.sys
[2005.12.01 11:33:56 | 000,237,568 | ---- | C] () -- C:\WINDOWS\System32\hppapr02.DLL
[2004.08.04 01:56:46 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2004.08.02 19:03:00 | 000,102,441 | ---- | C] () -- C:\WINDOWS\System32\getvpd.dll
[2004.08.02 19:03:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\pmemw.dll
[2002.01.20 22:37:46 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\Dvbpws.dll
[2002.01.14 19:19:36 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2002.01.05 03:50:50 | 000,118,384 | ---- | C] () -- C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2002.01.02 01:42:51 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2001.07.06 16:30:00 | 000,003,399 | ---- | C] () -- C:\WINDOWS\System32\hptcpmon.ini
========== LOP Check ========== [2010.10.04 11:27:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Autodesk
[2010.11.17 12:20:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\BitTorrent
[2002.01.04 23:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\DAEMON Tools Lite
[2010.11.05 01:09:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\Opera
[2010.09.15 20:48:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator.REZERVA\Application Data\PTC
[2009.07.18 13:34:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ACD Systems
[2002.01.02 01:43:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canneverbe Limited
[2009.01.12 13:07:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Canon
[2002.01.02 01:21:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009.06.24 16:18:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DassaultSystemes
[2010.04.11 20:54:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DynDNS
[2008.12.16 17:40:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010.11.26 12:01:00 | 000,000,232 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job
========== Purity Check ========== ========== Alternate Data Streams ========== @Alternate Data Stream - 216 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A4E79860
< End of report >