Avast antivirus has detected a "Rootkit: hidden boot sector" on my computer which I believe have been removed after a boot up scan.
Upon discovery of the rootkit, I ran Trend Micro RootkitBuster which detected many entries with "Zw" filenames.
Unfortunately, RootkitBuster can't fix any of the problems it listed.
No unusual behavior has been observed on the computer.
Could someone have a look at my OTL log please. Thanks very much.
---------------------------
OTL logfile created on: 3/20/2012 5:43:51 AM - Run 1
OTL by OldTimer - Version 3.2.39.1 Folder = C:\Documents and Settings\User\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.22 Gb Total Physical Memory | 2.64 Gb Available Physical Memory | 82.00% Memory free
3.78 Gb Paging File | 3.35 Gb Available in Paging File | 88.70% Paging File free
Paging file location(s): C:\pagefile.sys 742 742 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 39.06 Gb Total Space | 23.18 Gb Free Space | 59.34% Space Free | Partition Type: NTFS
Drive D: | 35.46 Gb Total Space | 35.38 Gb Free Space | 99.77% Space Free | Partition Type: NTFS
Computer Name: COMPUTER | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2012/03/20 05:43:22 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
PRC - [2012/03/14 11:14:20 | 000,180,912 | ---- | M] (PortableApps.com) -- C:\Documents and Settings\User\Desktop\FirefoxPortable\FirefoxPortable.exe
PRC - [2012/03/13 12:39:08 | 000,016,824 | ---- | M] (Mozilla Corporation) -- C:\Documents and Settings\User\Desktop\FirefoxPortable\App\Firefox\plugin-container.exe
PRC - [2012/03/13 12:39:04 | 000,924,600 | ---- | M] (Mozilla Corporation) -- C:\Documents and Settings\User\Desktop\FirefoxPortable\App\Firefox\firefox.exe
PRC - [2011/11/29 02:01:24 | 003,744,552 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2011/11/29 02:01:23 | 000,044,768 | ---- | M] (AVAST Software) -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe
PRC - [2010/12/22 21:21:38 | 000,088,688 | R--- | M] (VIA Technologies, Inc.) -- C:\WINDOWS\system32\KaraokeSer.exe
PRC - [2008/01/16 06:55:46 | 001,327,616 | ---- | M] (Nullsoft) -- C:\Program Files\Winamp\winamp.exe
PRC - [2006/09/21 16:36:18 | 000,053,248 | ---- | M] (S3 Graphics, Inc.) -- C:\WINDOWS\system32\VTTimer.exe
PRC - [2004/08/03 22:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2012/03/20 05:40:10 | 000,029,696 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Temp\nsj5.tmp\registry.dll
MOD - [2012/03/20 05:40:10 | 000,011,264 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Temp\nsj5.tmp\System.dll
MOD - [2012/03/20 05:40:10 | 000,008,704 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Temp\nsj5.tmp\newadvsplash.dll
MOD - [2012/03/20 04:44:08 | 001,744,896 | ---- | M] () -- C:\Program Files\AVAST Software\Avast\defs\12031901\algo.dll
MOD - [2012/03/13 12:39:06 | 001,969,080 | ---- | M] () -- C:\Documents and Settings\User\Desktop\FirefoxPortable\App\Firefox\mozjs.dll
MOD - [2012/03/06 00:03:22 | 008,527,008 | ---- | M] () -- C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll
MOD - [2009/11/05 08:39:40 | 000,087,552 | ---- | M] () -- C:\WINDOWS\system32\cpwmon2k.dll
MOD - [2008/01/16 06:54:32 | 001,506,816 | ---- | M] () -- C:\Program Files\Winamp\Plugins\gen_ff.dll
MOD - [2008/01/16 06:52:58 | 000,025,088 | ---- | M] () -- C:\Program Files\Winamp\Plugins\gen_hotkeys.dll
MOD - [2008/01/16 06:52:54 | 000,165,376 | ---- | M] () -- C:\Program Files\Winamp\Plugins\gen_ml.dll
MOD - [2008/01/16 06:52:42 | 000,025,088 | ---- | M] () -- C:\Program Files\Winamp\Plugins\gen_tray.dll
MOD - [2008/01/16 06:52:40 | 000,107,008 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_cdda.dll
MOD - [2008/01/16 06:52:22 | 000,007,168 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_linein.dll
MOD - [2008/01/16 06:52:18 | 000,098,816 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_midi.dll
MOD - [2008/01/16 06:52:10 | 000,160,768 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_mod.dll
MOD - [2008/01/16 06:52:06 | 000,019,456 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_nowplaying.dll
MOD - [2008/01/16 06:51:58 | 000,019,968 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_flv.dll
MOD - [2008/01/16 06:51:52 | 000,406,528 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_mp3.dll
MOD - [2008/01/16 06:51:16 | 000,039,936 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_mp4.dll
MOD - [2008/01/16 06:51:04 | 000,171,520 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_nsv.dll
MOD - [2008/01/16 06:50:58 | 000,222,208 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_vorbis.dll
MOD - [2008/01/16 06:50:46 | 000,024,576 | ---- | M] () -- C:\Program Files\Winamp\System\dlmgr.w5s
MOD - [2008/01/16 06:50:42 | 000,026,112 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_autotag.dll
MOD - [2008/01/16 06:50:38 | 000,057,856 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_plg.dll
MOD - [2008/01/16 06:50:26 | 000,184,832 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_wire.dll
MOD - [2008/01/16 06:50:06 | 000,047,104 | ---- | M] () -- C:\Program Files\Winamp\Plugins\out_ds.dll
MOD - [2008/01/16 06:50:04 | 000,018,432 | ---- | M] () -- C:\Program Files\Winamp\Plugins\out_wave.dll
MOD - [2008/01/16 06:49:52 | 000,073,728 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_dshow.dll
MOD - [2008/01/16 06:49:44 | 000,026,624 | ---- | M] () -- C:\Program Files\Winamp\System\jnetlib.w5s
MOD - [2008/01/16 06:49:32 | 000,365,056 | ---- | M] () -- C:\Program Files\Winamp\System\aacPlusDecoder.w5s
MOD - [2008/01/16 06:49:24 | 000,297,472 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_wm.dll
MOD - [2008/01/16 06:48:52 | 000,019,456 | ---- | M] () -- C:\Program Files\Winamp\Plugins\out_disk.dll
MOD - [2008/01/16 06:48:50 | 000,012,288 | ---- | M] () -- C:\Program Files\Winamp\System\gracenote.w5s
MOD - [2008/01/16 06:48:46 | 000,013,824 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_wave.dll
MOD - [2008/01/16 06:48:42 | 000,018,944 | ---- | M] () -- C:\Program Files\Winamp\System\tagz.w5s
MOD - [2008/01/16 06:48:36 | 000,199,168 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_pmp.dll
MOD - [2008/01/16 06:48:14 | 000,212,480 | ---- | M] () -- C:\Program Files\Winamp\Plugins\pmp_ipod.dll
MOD - [2008/01/16 06:48:00 | 000,017,920 | ---- | M] () -- C:\Program Files\Winamp\Plugins\pmp_njb.dll
MOD - [2008/01/16 06:47:56 | 000,114,176 | ---- | M] () -- C:\Program Files\Winamp\Plugins\pmp_p4s.dll
MOD - [2008/01/16 06:47:50 | 000,098,304 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_online.dll
MOD - [2008/01/16 06:47:34 | 000,087,040 | ---- | M] () -- C:\Program Files\Winamp\System\xml.w5s
MOD - [2008/01/16 06:47:28 | 000,094,208 | ---- | M] () -- C:\Program Files\Winamp\System\png.w5s
MOD - [2008/01/16 06:47:20 | 000,019,968 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_bookmarks.dll
MOD - [2008/01/16 06:47:16 | 000,141,824 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_disc.dll
MOD - [2008/01/16 06:47:02 | 000,037,376 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_history.dll
MOD - [2008/01/16 06:46:54 | 000,270,336 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_local.dll
MOD - [2008/01/16 06:46:44 | 000,368,640 | ---- | M] () -- C:\Program Files\Winamp\Plugins\freeform\wacs\freetype\freetype.wac
MOD - [2008/01/16 06:46:40 | 000,070,144 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_playlists.dll
MOD - [2008/01/16 06:46:34 | 000,035,840 | ---- | M] () -- C:\Program Files\Winamp\System\playlist.w5s
MOD - [2008/01/16 06:46:20 | 000,072,704 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_orb.dll
MOD - [2008/01/16 06:46:10 | 000,017,408 | ---- | M] () -- C:\Program Files\Winamp\System\gif.w5s
MOD - [2008/01/16 06:46:08 | 000,011,776 | ---- | M] () -- C:\Program Files\Winamp\System\filereader.w5s
MOD - [2008/01/16 06:46:04 | 000,040,448 | ---- | M] () -- C:\Program Files\Winamp\Plugins\pmp_usb.dll
MOD - [2008/01/16 06:45:54 | 000,025,600 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_rg.dll
MOD - [2008/01/16 06:45:50 | 000,040,960 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_dash.dll
MOD - [2008/01/16 06:45:38 | 000,100,864 | ---- | M] () -- C:\Program Files\Winamp\System\jpeg.w5s
MOD - [2008/01/16 06:45:30 | 000,007,168 | ---- | M] () -- C:\Program Files\Winamp\System\bmp.w5s
MOD - [2008/01/16 06:45:12 | 000,037,376 | ---- | M] () -- C:\Program Files\Winamp\Plugins\in_flac.dll
MOD - [2008/01/16 06:44:52 | 000,027,136 | ---- | M] () -- C:\Program Files\Winamp\Plugins\ml_transcode.dll
MOD - [2008/01/16 06:44:48 | 000,064,000 | ---- | M] () -- C:\Program Files\Winamp\tataki.dll
MOD - [2008/01/16 06:44:40 | 000,201,728 | ---- | M] () -- C:\Program Files\Winamp\libsndfile.dll
MOD - [2008/01/16 06:44:24 | 000,088,576 | ---- | M] () -- C:\Program Files\Winamp\nde.dll
MOD - [2007/10/10 06:50:22 | 000,189,440 | ---- | M] () -- C:\Program Files\Winamp\Plugins\gen_jumpex.dll
MOD - [2004/08/03 22:56:44 | 000,014,336 | ---- | M] () -- C:\WINDOWS\system32\msdmo.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/11/29 02:01:23 | 000,044,768 | ---- | M] (AVAST Software) [Auto | Running] -- C:\Program Files\AVAST Software\Avast\AvastSvc.exe -- (avast! Antivirus)
SRV - [2010/12/22 21:21:38 | 000,088,688 | R--- | M] (VIA Technologies, Inc.) [Auto | Running] -- C:\WINDOWS\system32\KaraokeSer.exe -- (KaraokeService)
SRV - [2009/03/27 22:10:56 | 000,014,336 | ---- | M] (LSI Corporation) [Disabled | Stopped] -- C:\Program Files\LSI SoftModem\agrsmsvc.exe -- (AgereModemAudio)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xpsec.sys -- (xpsec)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\xcpip.sys -- (xcpip)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\DOCUME~1\User\LOCALS~1\Temp\mfe_rr.sys -- (MFE_RR)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\B.tmp -- (MEMSWEEP2)
DRV - [2012/02/18 16:06:23 | 000,017,488 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2011/11/29 01:53:53 | 000,435,032 | ---- | M] (AVAST Software) [File_System | System | Running] -- C:\WINDOWS\System32\drivers\aswSnx.sys -- (aswSnx)
DRV - [2011/11/29 01:53:35 | 000,314,456 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2011/11/29 01:52:19 | 000,034,392 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2011/11/29 01:52:16 | 000,052,952 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2011/11/29 01:52:02 | 000,111,320 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswmon2.sys -- (aswMon2)
DRV - [2011/11/29 01:51:50 | 000,020,568 | ---- | M] (AVAST Software) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\aswFsBlk.sys -- (aswFsBlk)
DRV - [2011/11/29 01:48:49 | 000,030,808 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2011/03/22 15:58:42 | 000,065,136 | R--- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\l1c51x86.sys -- (L1c)
DRV - [2011/02/12 14:29:45 | 000,123,952 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SYMEVENT.SYS -- (SymEvent)
DRV - [2010/12/22 21:21:40 | 002,804,720 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009/08/13 15:07:12 | 001,163,328 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AGRSM.sys -- (AgereSoftModem)
DRV - [2009/08/05 22:48:42 | 000,054,752 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys -- (fssfltr)
DRV - [2007/06/27 14:42:00 | 000,207,488 | R--- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\vinyl97.sys -- (VIAudio) Vinyl AC'97 Audio Controller (WDM)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://search.live.com/sphome.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://search.live.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,start page = http://google.com/
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {CCC7A320-B3CA-4199-B1A6-9F516DD69829}
IE - HKCU\..\SearchScopes\{18EAB056-9057-F224-FD4C-1F6569C4D8D2}: "URL" = http://www.plusnetwo...ferrer:source?}
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://search.avg.co...{language}&nt=1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/...?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
FF - prefs.js..extensions.enabledItems: {d9284e50-81fc-11da-a72b-0800200c9a66}:7.5.0
FF - prefs.js..keyword.URL: "http://search.avg.co...&tp=ab&nt=1&q="
FF - prefs.js..network.proxy.type: 0
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeLive,version=1.3: C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{27182e60-b5f3-411c-b545-b44205977502}: C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\firefoxextension\SearchHelperExtension\ [2011/05/29 17:25:50 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files\AVAST Software\Avast\WebRep\FF
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/06/01 17:38:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/06/01 17:38:07 | 000,000,000 | ---D | M]
[2012/03/20 05:40:15 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions
[2011/05/06 13:11:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions-BackupByFirefoxPortable
[2011/05/06 13:11:30 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Extensions-BackupByFirefoxPortable\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2012/02/01 11:10:13 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\8gdradj4.default\extensions
[2010/01/28 17:05:04 | 000,001,681 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\8gdradj4.default\searchplugins\ask.uk.xml
[2009/12/07 08:13:15 | 000,002,171 | ---- | M] () -- C:\Documents and Settings\User\Application Data\Mozilla\Firefox\Profiles\8gdradj4.default\searchplugins\bing.xml
[2011/05/03 20:35:32 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/04/21 07:07:17 | 000,001,538 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-en-GB.xml
[2011/04/21 07:07:17 | 000,000,947 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\chambers-en-GB.xml
[2011/04/21 07:07:17 | 000,000,769 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-en-GB.xml
[2011/04/21 07:07:17 | 000,001,135 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2010/07/03 16:13:20 | 000,000,736 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {3AF255C7-8742-4B96-8971-1268EEE04974} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3F954663-A500-42AE-B82D-045EF17D587D}: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B79022B6-AD74-4054-ABBF-681C349B3375}: DhcpNameServer = 192.168.0.1
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp
O32 - HKLM CDRom: AutoRun - 0
O32 - AutoRun File - [2009/05/30 11:07:12 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{3e2252da-5006-11de-97fa-0019219d0393}\Shell\AutoRun\command - "" = eman' s picture.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2012/03/20 05:43:12 | 000,594,432 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012/03/17 18:49:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Sophos
[2012/03/17 18:49:14 | 000,000,000 | ---D | C] -- C:\Program Files\Sophos
[2012/03/15 21:31:41 | 000,014,664 | ---- | C] (McAfee, Inc.) -- C:\WINDOWS\stinger.sys
[2012/03/15 21:31:13 | 000,000,000 | ---D | C] -- C:\Program Files\stinger
[2012/03/15 21:27:06 | 000,205,072 | ---- | C] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2012/03/15 20:54:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\Rootkit
[2012/03/15 20:53:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\FirefoxPortable
[2012/03/15 19:43:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\New Folder
[2012/02/23 15:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\User\Desktop\perpermohonanpembiayaanptptn
[2012/02/21 21:23:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\avast! Free Antivirus
[2012/02/21 21:23:44 | 000,314,456 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2012/02/21 21:23:44 | 000,020,568 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2012/02/21 21:23:43 | 000,052,952 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2012/02/21 21:23:43 | 000,034,392 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2012/02/21 21:23:42 | 000,435,032 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswSnx.sys
[2012/02/21 21:23:42 | 000,111,320 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2012/02/21 21:23:41 | 000,105,176 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2012/02/21 21:23:41 | 000,030,808 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2012/02/21 21:22:34 | 000,199,816 | ---- | C] (AVAST Software) -- C:\WINDOWS\System32\aswBoot.exe
[2012/02/21 21:22:34 | 000,041,184 | ---- | C] (AVAST Software) -- C:\WINDOWS\avastSS.scr
[2012/02/21 21:22:22 | 000,000,000 | ---D | C] -- C:\Program Files\AVAST Software
[2012/02/21 21:22:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/03/20 05:43:22 | 000,594,432 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\User\Desktop\OTL.exe
[2012/03/20 05:29:04 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2012/03/17 18:00:00 | 000,014,664 | ---- | M] (McAfee, Inc.) -- C:\WINDOWS\stinger.sys
[2012/03/15 21:27:03 | 000,205,072 | ---- | M] (Trend Micro Inc.) -- C:\WINDOWS\System32\drivers\tmcomm.sys
[2012/03/15 20:55:06 | 000,000,623 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Shortcut to FirefoxPortable.lnk
[2012/03/15 19:41:00 | 003,983,743 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Bondan Prakoso & Fade 2 Black - Ya Sudahlah.mp3
[2012/03/07 18:12:06 | 000,168,195 | ---- | M] () -- C:\Documents and Settings\User\Desktop\preliminary analysis.jpg
[2012/03/06 18:51:15 | 000,850,002 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Tute 3 p1.JPG
[2012/03/02 15:51:07 | 000,779,290 | ---- | M] () -- C:\Documents and Settings\User\Desktop\1.jpg
[2012/02/27 18:18:31 | 004,162,499 | ---- | M] () -- C:\Documents and Settings\User\Desktop\Coldplay - Paradise.mp3
[2012/02/25 20:12:58 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2012/02/21 21:23:42 | 000,002,625 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2012/02/20 19:09:56 | 000,070,656 | ---- | M] () -- C:\Documents and Settings\User\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/03/15 20:55:06 | 000,000,623 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Shortcut to FirefoxPortable.lnk
[2012/03/07 18:11:35 | 000,168,195 | ---- | C] () -- C:\Documents and Settings\User\Desktop\preliminary analysis.jpg
[2012/03/06 18:51:15 | 000,850,002 | ---- | C] () -- C:\Documents and Settings\User\Desktop\Tute 3 p1.JPG
[2012/03/02 15:50:36 | 000,779,290 | ---- | C] () -- C:\Documents and Settings\User\Desktop\1.jpg
[2012/02/25 10:07:07 | 000,038,470 | ---- | C] () -- C:\WINDOWS\System32\hidserv.afm
[2012/02/18 15:19:03 | 000,004,096 | R--- | C] ( ) -- C:\WINDOWS\System32\IGFXDEVLib.dll
[2012/02/18 15:19:03 | 000,000,151 | R--- | C] () -- C:\WINDOWS\System32\GfxUI.exe.config
[2012/02/18 15:19:02 | 000,982,224 | R--- | C] () -- C:\WINDOWS\System32\igkrng500.bin
[2012/02/18 15:19:02 | 000,439,336 | R--- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin
[2012/02/18 15:17:28 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
[2012/02/18 15:17:28 | 000,254,000 | R--- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
[2012/02/18 15:06:16 | 000,207,400 | R--- | C] () -- C:\WINDOWS\GSetup.exe
[2012/02/18 15:06:16 | 000,000,010 | ---- | C] () -- C:\WINDOWS\GSetup.ini
[2012/01/19 00:50:03 | 000,087,552 | ---- | C] () -- C:\WINDOWS\System32\cpwmon2k.dll
[2010/12/08 17:28:45 | 000,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2010/08/15 20:31:34 | 000,000,130 | ---- | C] () -- C:\WINDOWS\cfplogvw.INI
[2010/07/18 16:19:52 | 000,192,512 | ---- | C] () -- C:\WINDOWS\off-road-uninst.exe
========== LOP Check ==========
[2010/10/05 21:17:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\A-PDF
[2012/02/21 21:22:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2012/02/21 21:19:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2009/05/30 12:17:24 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\CanonBJ
[2011/02/03 10:10:35 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2011/01/12 20:09:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET
[2012/02/21 21:17:31 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2009/12/26 13:23:35 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PopCap Games
[2010/12/17 09:56:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\RegistryCleanerFlash
[2011/06/01 05:56:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ScanSoft
[2011/02/03 16:01:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2011/05/29 16:02:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Canon
[2010/11/14 11:42:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\GetRightToGo
[2011/11/25 06:47:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\IsolatedStorage
[2011/03/01 10:37:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Online Games Downloader
[2011/08/01 13:41:40 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Opera
[2010/12/13 14:45:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Pointstone
[2010/12/17 09:56:02 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\RegistryCleanerFlash
[2011/04/09 07:48:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\ScanSoft
[2009/07/20 18:08:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Skinux
[2012/02/20 18:55:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Splashtop
[2010/12/17 09:27:23 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Uniblue
[2010/12/13 08:30:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\User\Application Data\Wildfire
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
< End of report >
Edited by AliceK, 19 March 2012 - 04:06 PM.