Recently I was infected with a bunch of malware but with the help of my friends, SuperAntiSpyware, and MalWareBytes I think I was able to get rid of most of it. However, my automatic updates will not turn on as well as my firewall. Also, my background is a pure gray screen and not my usual background. Below are my rooter and OldTimer logs. Could someone please point me in the right direction. Thanks!!!!!
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
C:\ [Fixed] - NTFS - (Total:109638 Mo/Free:3909 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Sun 03/29/2009|13:54
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\Ati2evxx.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\eHome\ehRecvr.exe
---------- C:\WINDOWS\eHome\ehSched.exe
---------- C:\WINDOWS\system32\LxrSII1s.exe
---------- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
---------- C:\WINDOWS\eHome\ehRec.exe
---------- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
---------- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\ehome\mcrdsvc.exe
---------- C:\WINDOWS\system32\wbem\wmiprvse.exe
---------- C:\WINDOWS\system32\wscntfy.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
---------- C:\WINDOWS\stsystra.exe
---------- C:\Program Files\iTunes\iTunesHelper.exe
---------- C:\WINDOWS\ehome\ehtray.exe
---------- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
---------- C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
---------- C:\WINDOWS\eHome\ehmsas.exe
---------- C:\Documents and Settings\Blake\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
---------- C:\Program Files\Dell Support\DSAgnt.exe
---------- C:\Program Files\iPod\bin\iPodService.exe
---------- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\explorer.exe
---------- C:\Program Files\Mozilla Firefox\firefox.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Sat 03/28/2009|22:42
2 - "C:\Rooter$\Rooter_2.txt" - Sat 03/28/2009|22:44
3 - "C:\Rooter$\Rooter_3.txt" - Sun 03/29/2009| 1:09
4 - "C:\Rooter$\Rooter_4.txt" - Sun 03/29/2009|12:19
5 - "C:\Rooter$\Rooter_5.txt" - Sun 03/29/2009|13:54
----------------------\\ Scan completed at 13:54
Old Timer Log..
OTListIt logfile created on: 3/29/2009 1:54:47 PM - Run 4
OTListIt2 by OldTimer - Version 2.0.7.2 Folder = C:\Documents and Settings\Blake\Desktop
Windows XP Media Center Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
893.98 Mb Total Physical Memory | 407.78 Mb Available Physical Memory | 45.61% Memory free
2.12 Gb Paging File | 1.75 Gb Available in Paging File | 82.80% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688;
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.07 Gb Total Space | 87.82 Gb Free Space | 82.02% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: DCY278C1
Current User Name: Blake
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Standard
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - [2006/10/11 21:37:24 | 00,430,080 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2006/10/11 21:37:24 | 00,430,080 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe
PRC - [2009/02/12 06:12:12 | 00,390,536 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe
PRC - [2006/10/09 18:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe
PRC - [2005/08/05 15:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe
PRC - [2007/03/07 10:51:52 | 00,049,152 | ---- | M] () -- C:\WINDOWS\system32\LxrSII1s.exe
PRC - [2003/06/20 01:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
PRC - [2008/04/13 20:12:18 | 00,136,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRec.exe
PRC - [2008/12/18 11:47:08 | 09,158,656 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe
PRC - [2006/08/23 18:13:28 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe
PRC - [2005/08/05 15:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe
PRC - [2008/04/13 20:12:40 | 00,218,112 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wbem\wmiprvse.exe
PRC - [2008/04/13 20:12:41 | 00,013,824 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wscntfy.exe
PRC - [2006/09/22 13:47:54 | 00,761,947 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2006/09/22 13:06:26 | 00,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2009/03/12 20:56:58 | 00,342,312 | ---- | M] (Apple Inc.) -- C:\Program Files\iTunes\iTunesHelper.exe
PRC - [2005/09/29 16:01:14 | 00,067,584 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\ehtray.exe
PRC - [2005/12/09 22:29:52 | 00,049,152 | ---- | M] (CyberLink Corp.) -- C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
PRC - [2006/01/02 17:41:22 | 00,045,056 | ---- | M] (ATI Technologies Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
PRC - [2005/08/05 15:56:28 | 00,046,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehmsas.exe
PRC - [2007/03/07 10:51:52 | 00,024,576 | ---- | M] () -- C:\Documents and Settings\Blake\Local Settings\Application Data\Lexar Media\LxrAutorun.exe
PRC - [2006/08/28 23:57:12 | 00,395,776 | ---- | M] (Gteko Ltd.) -- C:\Program Files\Dell Support\DSAgnt.exe
PRC - [2009/03/12 20:56:52 | 00,656,168 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe
PRC - [2005/05/04 00:07:32 | 00,081,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
PRC - [2008/04/13 20:12:19 | 01,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2009/03/09 16:08:55 | 00,307,704 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/03/29 13:54:41 | 00,498,688 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Blake\Desktop\OTListIt2.exe
========== Win32 Services (SafeList) ==========
SRV - [2009/03/06 00:04:30 | 00,132,424 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe -- (apple mobile device [Auto | Stopped])
SRV - [2007/10/24 01:47:22 | 00,033,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped])
SRV - [2006/10/11 21:37:24 | 00,430,080 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\Ati2evxx.exe -- (Ati HotKey Poller [Auto | Running])
SRV - [2008/12/12 11:17:38 | 00,238,888 | ---- | M] (Apple Inc.) -- C:\Program Files\Bonjour\mDNSResponder.exe -- (Bonjour Service [Auto | Stopped])
SRV - [2007/10/24 01:47:40 | 00,070,144 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2006/10/09 18:16:56 | 00,237,568 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehRecvr.exe -- (ehRecvr [Auto | Running])
SRV - [2005/08/05 15:56:32 | 00,102,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\eHome\ehSched.exe -- (ehSched [Auto | Running])
SRV - [2006/12/14 00:41:11 | 00,086,528 | ---- | M] (Google) -- C:\Program Files\Google\Google Desktop Search\GoogleDesktopManager.exe -- (GoogleDesktopManager [On_Demand | Stopped])
SRV - [2008/04/13 20:12:02 | 00,038,400 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll -- (helpsvc [Auto | Running])
SRV - [2009/03/12 20:56:52 | 00,656,168 | ---- | M] (Apple Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (ipod service [On_Demand | Running])
SRV - [2009/02/12 06:12:12 | 00,390,536 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\IswSvc.exe -- (iswsvc [Auto | Running])
SRV - File not found -- -- (IYXRDSOSDMQW [Disabled | Stopped])
SRV - [2007/03/07 10:51:52 | 00,049,152 | ---- | M] () -- C:\WINDOWS\system32\LxrSII1s.exe -- (LxrSII1s [Auto | Running])
SRV - [2005/08/05 15:27:08 | 00,099,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\ehome\mcrdsvc.exe -- (McrdSvc [Auto | Running])
SRV - [2003/06/20 01:25:00 | 00,322,120 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE -- (MDM [Auto | Running])
SRV - [2004/08/10 06:11:50 | 00,085,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\mhn.dll -- (MHN [On_Demand | Stopped])
SRV - [2008/12/18 11:47:08 | 09,158,656 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlservr.exe -- (MSSQL$MICROSOFTSMLBIZ [Auto | Running])
SRV - [2005/05/04 00:50:28 | 00,073,728 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqladhlp.exe -- (MSSQLServerADHelper [On_Demand | Stopped])
SRV - [2006/08/23 18:13:28 | 00,380,928 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NICCONFIGSVC.exe -- (NICCONFIGSVC [Auto | Running])
SRV - [2007/08/24 03:19:12 | 00,443,776 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE -- (odserv [On_Demand | Stopped])
SRV - [2006/10/26 14:03:08 | 00,145,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE -- (ose [On_Demand | Stopped])
SRV - [2005/05/03 23:42:56 | 00,323,584 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft SQL Server\MSSQL$MICROSOFTSMLBIZ\Binn\sqlagent.EXE -- (SQLAgent$MICROSOFTSMLBIZ [On_Demand | Stopped])
SRV - [2009/02/15 23:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Stopped])
SRV - [2006/10/18 22:05:24 | 00,913,408 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\WMPNetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Driver Services (SafeList) ==========
DRV - [2001/08/17 15:51:56 | 00,005,248 | ---- | M] (Acer Laboratories Inc.) -- C:\WINDOWS\system32\DRIVERS\aliide.sys -- (AliIde [Disabled | Stopped])
DRV - [2008/04/13 14:36:39 | 00,043,008 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\WINDOWS\system32\DRIVERS\amdagp.sys -- (amdagp [Disabled | Stopped])
DRV - [2005/08/12 19:50:46 | 00,016,128 | ---- | M] (Dell Inc) -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV [System | Running])
DRV - [2001/08/17 15:52:00 | 00,026,496 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc.sys -- (asc [Disabled | Stopped])
DRV - [2001/08/17 15:51:58 | 00,014,848 | ---- | M] (Advanced System Products, Inc.) -- C:\WINDOWS\system32\DRIVERS\asc3550.sys -- (asc3550 [Disabled | Stopped])
DRV - [2006/10/11 21:43:56 | 01,777,152 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\ati2mtag.sys -- (ati2mtag [On_Demand | Running])
DRV - [2006/09/13 18:41:46 | 00,003,456 | ---- | M] (ATI Technologies Inc.) -- C:\WINDOWS\system32\DRIVERS\atiide.sys -- (atiide [Boot | Running])
DRV - [2005/11/02 21:24:34 | 00,424,320 | ---- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcmwl5.sys -- (BCM43XX [On_Demand | Running])
DRV - [2006/11/21 04:25:44 | 00,045,568 | R--- | M] (Broadcom Corporation) -- C:\WINDOWS\system32\DRIVERS\bcm4sbxp.sys -- (bcm4sbxp [On_Demand | Running])
DRV - [2001/08/17 15:51:54 | 00,006,656 | ---- | M] (CMD Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\cmdide.sys -- (CmdIde [Disabled | Stopped])
DRV - [2001/08/17 15:52:16 | 00,179,584 | ---- | M] (Mylex Corporation) -- C:\WINDOWS\system32\DRIVERS\dac2w2k.sys -- (dac2w2k [Disabled | Stopped])
DRV - [2006/01/10 13:07:58 | 00,004,864 | ---- | M] (GTek Technologies Ltd.) -- C:\Program Files\Dell Support\GTAction\triggers\DSproct.sys -- (DSproct [On_Demand | Running])
DRV - [2001/08/17 14:12:10 | 00,117,760 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\DRIVERS\e100b325.sys -- (E100B [On_Demand | Stopped])
DRV - [2009/01/15 12:19:36 | 00,023,848 | ---- | M] (GEAR Software Inc.) -- C:\WINDOWS\System32\Drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running])
DRV - [2008/04/13 12:36:05 | 00,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) -- C:\WINDOWS\system32\DRIVERS\HDAudBus.sys -- (HDAudBus [On_Demand | Running])
DRV - [2005/12/01 09:40:56 | 00,936,960 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\DRIVERS\HSX_DPV.sys -- (HSF_DPV [On_Demand | Running])
DRV - [2005/12/01 09:40:12 | 00,192,512 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\DRIVERS\HSXHWAZL.sys -- (HSXHWAZL [On_Demand | Running])
DRV - [2009/02/12 06:11:48 | 00,054,928 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\AK\icsak.sys -- (icsak [On_Demand | Running])
DRV - [2009/02/12 06:12:18 | 00,021,136 | ---- | M] (Check Point Software Technologies) -- C:\Program Files\CheckPoint\ZAForceField\ISWKL.sys -- (iswkl [Auto | Running])
DRV - [2008/12/11 22:32:42 | 00,148,496 | ---- | M] (Kaspersky Lab) -- C:\WINDOWS\System32\DRIVERS\klif.sys -- (klif [System | Running])
DRV - [2007/03/07 10:51:52 | 00,072,672 | ---- | M] () -- C:\WINDOWS\system32\Drivers\LxrSII1d.sys -- (LxrSII1d [Auto | Running])
DRV - [2005/10/05 06:57:08 | 00,012,544 | ---- | M] (Conexant) -- C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys -- (mdmxsdk [Auto | Running])
DRV - [2001/08/17 15:52:12 | 00,017,280 | ---- | M] (American Megatrends Inc.) -- C:\WINDOWS\system32\DRIVERS\mraid35x.sys -- (mraid35x [Disabled | Stopped])
DRV - [2004/08/04 00:29:56 | 01,897,408 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\DRIVERS\nv4_mini.sys -- (nv [On_Demand | Stopped])
DRV - [2004/08/10 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\DRIVERS\ptilink.sys -- (Ptilink [On_Demand | Running])
DRV - [2006/08/24 14:33:36 | 00,036,528 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys -- (PxHelp20 [Boot | Running])
DRV - [2001/08/17 15:52:20 | 00,040,320 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1080.sys -- (ql1080 [Disabled | Stopped])
DRV - [2001/08/17 15:52:20 | 00,045,312 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql12160.sys -- (ql12160 [Disabled | Stopped])
DRV - [2001/08/17 15:52:18 | 00,049,024 | ---- | M] (QLogic Corporation) -- C:\WINDOWS\system32\DRIVERS\ql1280.sys -- (ql1280 [Disabled | Stopped])
DRV - [2006/11/15 00:16:24 | 00,032,256 | ---- | M] (REDC) -- C:\WINDOWS\system32\DRIVERS\rimmptsk.sys -- (rimmptsk [Auto | Running])
DRV - [2009/03/23 14:07:26 | 00,009,968 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS -- (sasdifsv [System | Running])
DRV - [2009/03/23 14:07:28 | 00,007,408 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (sasenum [On_Demand | Running])
DRV - [2009/03/23 14:07:26 | 00,072,944 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys -- (saskutil [System | Running])
DRV - [2007/11/13 06:25:53 | 00,020,480 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\DRIVERS\secdrv.sys -- (Secdrv [On_Demand | Stopped])
DRV - [2008/04/13 14:36:39 | 00,040,960 | ---- | M] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\system32\DRIVERS\sisagp.sys -- (sisagp [Disabled | Stopped])
DRV - [2001/08/17 16:07:44 | 00,019,072 | ---- | M] (Adaptec, Inc.) -- C:\WINDOWS\system32\DRIVERS\sparrow.sys -- (Sparrow [Disabled | Stopped])
DRV - [2008/11/17 02:24:00 | 00,051,688 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\system32\ZoneLabs\srescan.sys -- (srescan [Boot | Running])
DRV - [2006/09/22 13:06:26 | 01,171,464 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA [On_Demand | Running])
DRV - [2001/08/17 16:07:34 | 00,016,256 | ---- | M] (Symbios Logic Inc.) -- C:\WINDOWS\system32\DRIVERS\symc810.sys -- (symc810 [Disabled | Stopped])
DRV - [2001/08/17 16:07:36 | 00,032,640 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\symc8xx.sys -- (symc8xx [Disabled | Stopped])
DRV - [2006/12/14 00:38:58 | 00,010,344 | ---- | M] (Symantec Corporation) -- C:\WINDOWS\system32\drivers\symlcbrd.sys -- (symlcbrd [Auto | Running])
DRV - [2001/08/17 16:07:40 | 00,028,384 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_hi.sys -- (sym_hi [Disabled | Stopped])
DRV - [2001/08/17 16:07:42 | 00,030,688 | ---- | M] (LSI Logic) -- C:\WINDOWS\system32\DRIVERS\sym_u3.sys -- (sym_u3 [Disabled | Stopped])
DRV - [2006/03/08 12:35:10 | 00,191,872 | ---- | M] (Synaptics, Inc.) -- C:\WINDOWS\system32\DRIVERS\SynTP.sys -- (SynTP [On_Demand | Running])
DRV - [2001/08/17 15:52:22 | 00,036,736 | ---- | M] (Promise Technology, Inc.) -- C:\WINDOWS\system32\DRIVERS\ultra.sys -- (ultra [Disabled | Stopped])
DRV - [2009/02/15 23:10:26 | 00,353,672 | ---- | M] (Check Point Software Technologies LTD) -- C:\WINDOWS\System32\vsdatant.sys -- (vsdatant [System | Running])
DRV - [2005/12/01 09:40:08 | 00,669,696 | ---- | M] (Conexant Systems, Inc.) -- C:\WINDOWS\system32\DRIVERS\HSX_CNXT.sys -- (winachsf [On_Demand | Running])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn...st/srchasst.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Page_Transitions = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft...amp;ar=iesearch
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft...p...&ar=msnhome
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: {FFB96CC1-7EB3-449D-B827-DB661701C6BB}:1.3.130.0
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.7
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/03/27 13:44:16 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.7\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/03/28 15:03:51 | 00,000,000 | ---D | M]
[2008/08/30 09:14:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Blake\Application Data\mozilla\Extensions
[2008/08/30 09:14:28 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Blake\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/03/28 19:48:02 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Blake\Application Data\mozilla\Firefox\Profiles\wpuafikj.default\extensions
[2008/07/18 19:25:38 | 00,000,000 | ---D | M] -- C:\Documents and Settings\Blake\Application Data\mozilla\Firefox\Profiles\wpuafikj.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2008/07/17 21:51:17 | 00,001,769 | ---- | M] () -- C:\Documents and Settings\Blake\Application Data\Mozilla\FireFox\Profiles\wpuafikj.default\searchplugins\aim-search.xml
[2008/05/03 10:30:40 | 00,000,998 | ---- | M] () -- C:\Documents and Settings\Blake\Application Data\Mozilla\FireFox\Profiles\wpuafikj.default\searchplugins\aolsearch.gif
[2008/05/03 10:30:40 | 00,000,293 | ---- | M] () -- C:\Documents and Settings\Blake\Application Data\Mozilla\FireFox\Profiles\wpuafikj.default\searchplugins\aolsearch.src
[2008/03/05 19:52:45 | 00,001,877 | ---- | M] () -- C:\Documents and Settings\Blake\Application Data\Mozilla\FireFox\Profiles\wpuafikj.default\searchplugins\aolsearch.xml
[2008/08/30 09:14:32 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2009/03/09 16:09:03 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2009/03/09 16:08:54 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/03/09 16:08:54 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2008/09/29 18:50:57 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2008/09/29 18:50:57 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2008/09/29 18:50:57 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2008/11/15 19:24:29 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2008/09/29 18:50:57 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2008/09/29 18:50:57 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2008/09/29 18:50:57 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
O1 HOSTS File: (736 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (ForceField Toolbar Registrar) - {8a4a36c2-0535-4d2c-bd3d-496cb7eed6e3} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKLM\..\Toolbar: (ForceField Toolbar) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {0B53EAC3-8D69-4B9E-9B19-A37C9A5676A7} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - C:\Program Files\CheckPoint\ZAForceField\TrustChecker\bin\TrustCheckerIEPlugin.dll (Check Point Software Technologies)
O4 - HKLM..\Run: [aticcc] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe" ()
O4 - HKLM..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe" (CyberLink Corp.)
O4 - HKLM..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup (Google)
O4 - HKLM..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" (Apple Inc.)
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SigmatelSysTrayApp] stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [syntpenh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [syntplpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [DellSupport] "C:\Program Files\Dell Support\DSAgnt.exe" /startup (Gteko Ltd.)
O4 - HKCU..\Run: [LxrAutorun] C:\Documents and Settings\Blake\Local Settings\Application Data\Lexar Media\LxrAutorun.exe ()
O4 - HKCU..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background (Microsoft Corporation)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk = C:\Program Files\Digital Line Detect\DLG.exe File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\npjpi150_06.dll (Sun Microsystems, Inc.)
O9 - Extra Button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exe (PokerStars)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [NWLink IPX/SPX/NetBIOS Compatible Transport Protocol] - C:\WINDOWS\System32\nwprovau.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [mdnsNSP] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macr...director/sw.cab (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.m...ash/swflash.cab (Reg Error: Key error.)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\Program Files\Common Files\Microsoft Shared\Web Components\11\OWC11.DLL (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!saswinlogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/08/16 06:43:04 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}\Shell\AutoRun\command - "" = E:\setup.exe -- File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
========== Files/Folders - Created Within 30 Days ==========
[2 C:\WINDOWS\*.tmp files]
[2009/03/29 13:54:40 | 00,498,688 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Blake\Desktop\OTListIt2.exe
[2009/03/29 13:43:45 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2009/03/29 13:43:45 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2009/03/29 13:43:45 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2009/03/29 13:43:45 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2009/03/29 13:43:45 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe
[2009/03/29 13:43:45 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2009/03/29 13:43:45 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2009/03/29 13:43:45 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe
[2009/03/29 13:43:45 | 00,029,696 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2009/03/29 13:43:23 | 00,000,000 | ---D | C] -- C:\Qoobox
[2009/03/29 13:42:55 | 02,936,847 | R--- | C] () -- C:\Documents and Settings\Blake\Desktop\ComboFix.exe
[2009/03/29 03:55:21 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\Blake\Application Data\GTek
[2009/03/29 03:30:39 | 00,001,908 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Service Manager.lnk
[2009/03/29 03:30:39 | 00,001,757 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
[2009/03/29 03:30:39 | 00,000,493 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Digital Line Detect.lnk
[2009/03/29 03:27:14 | 00,000,000 | ---D | C] -- C:\Program Files\backups
[2009/03/29 02:39:35 | 00,000,209 | ---- | C] () -- C:\Boot.bak
[2009/03/29 02:39:26 | 00,260,272 | ---- | C] () -- C:\cmldr
[2009/03/29 02:39:16 | 00,000,000 | RHSD | C] -- C:\cmdcons
[2009/03/29 02:37:29 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2009/03/29 02:21:41 | 93,747,2000 | -HS- | C] () -- C:\hiberfil.sys
[2009/03/29 01:58:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
[2009/03/29 01:58:22 | 00,000,780 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/29 01:58:21 | 00,000,000 | ---D | C] -- C:\Program Files\SUPERAntiSpyware
[2009/03/29 01:58:21 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Application Data\SUPERAntiSpyware.com
[2009/03/29 01:57:51 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Wise Installation Wizard
[2009/03/29 01:56:42 | 06,237,728 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\SUPERAntiSpyware.exe
[2009/03/29 01:54:46 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/03/29 01:54:40 | 00,175,504 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\activescan2_en.exe
[2009/03/29 01:50:07 | 00,396,288 | ---- | C] (Trend Micro Inc.) -- C:\Program Files\HijackThis.exe
[2009/03/29 01:50:07 | 00,001,435 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\HijackThis.lnk
[2009/03/29 01:41:10 | 00,812,344 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Blake\Desktop\HJTInstall.exe
[2009/03/29 01:00:28 | 00,009,584 | ---- | C] () -- C:\Documents and Settings\Blake\My Documents\cc_20090329_010026.reg
[2009/03/29 00:59:00 | 01,114,392 | ---- | C] () -- C:\Documents and Settings\Blake\My Documents\cc_20090329_005857.reg
[2009/03/29 00:54:47 | 00,001,486 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\CCleaner.lnk
[2009/03/29 00:54:46 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Desktop\CCleaner
[2009/03/29 00:52:14 | 03,190,688 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Blake\Desktop\ccsetup218.exe
[2009/03/28 22:41:07 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/03/28 22:27:57 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Rooter.exe
[2009/03/28 19:32:34 | 00,003,157 | ---- | C] () -- C:\rollback.ini
[2009/03/28 19:16:37 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Application Data\#ISW.FS#
[2009/03/28 19:16:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\My Documents\ForceField Shared Files
[2009/03/28 19:16:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Application Data\CheckPoint
[2009/03/28 19:16:02 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Application Data\MailFrontier
[2009/03/28 19:14:20 | 83,878,176 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/03/28 19:14:20 | 01,097,732 | -HS- | C] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/03/28 19:09:24 | 00,000,144 | ---- | C] () -- C:\WINDOWS\System32\pdfl.dat
[2009/03/28 19:09:24 | 00,000,144 | ---- | C] () -- C:\WINDOWS\System32\lkfl.dat
[2009/03/28 19:09:24 | 00,000,080 | ---- | C] () -- C:\WINDOWS\System32\ibfl.dat
[2009/03/28 19:09:15 | 00,000,000 | ---D | C] -- C:\Program Files\CheckPoint
[2009/03/28 19:08:53 | 00,148,496 | ---- | C] (Kaspersky Lab) -- C:\WINDOWS\System32\drivers\klif.sys
[2009/03/28 19:08:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\System32\ZoneLabs
[2009/03/28 19:08:11 | 00,000,000 | ---D | C] -- C:\Program Files\Zone Labs
[2009/03/28 19:08:08 | 00,351,219 | ---- | C] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/03/28 19:02:30 | 00,267,656 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\ZASPSetup_en.exe
[2009/03/28 17:03:53 | 24,768,960 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\MRT.exe
[2009/03/28 17:03:05 | 10,246,088 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\Blake\Desktop\windows-kb890830-v2.8.exe
[2009/03/27 13:46:57 | 00,000,000 | ---D | C] -- C:\Program Files\iPod
[2009/03/27 13:46:54 | 00,000,000 | ---D | C] -- C:\Program Files\iTunes
[2009/03/27 13:46:54 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\{00D89592-F643-4D8D-8F0F-AFAE0F14D4C3}
[2009/03/27 13:44:51 | 00,000,000 | ---D | C] -- C:\Program Files\QuickTime
[2009/03/27 13:42:59 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\Apple
[2009/03/27 13:32:29 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller
[2009/03/27 13:31:34 | 03,063,218 | ---- | C] (Symantec Corporation) -- C:\Documents and Settings\Blake\Desktop\Norton_Removal_Tool.exe
[2009/03/19 17:55:40 | 00,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\wmiacpi.sys
[2009/03/19 17:55:40 | 00,008,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wmiacpi.sys
[2009/03/19 17:35:14 | 03,107,788 | ---- | C] () -- C:\WINDOWS\System32\ativvaxx.dat
[2009/03/19 17:35:14 | 00,002,096 | ---- | C] () -- C:\WINDOWS\System32\drivers\ativdkxx.vp
[2009/03/19 17:33:20 | 00,000,000 | ---D | C] -- C:\Program Files\Broadcom
[2009/03/19 17:32:32 | 00,000,000 | ---D | C] -- C:\Program Files\DIFX
[2009/03/19 17:26:17 | 00,000,000 | -H-D | C] -- C:\$AVG8.VAULT$
[2009/03/19 17:21:00 | 00,000,000 | ---D | C] -- C:\Program Files\AVG
[2009/03/19 17:20:58 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8
[2009/03/19 16:09:36 | 00,026,112 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\userinit.exe
[2009/03/19 16:06:48 | 00,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2009/03/18 20:58:22 | 00,000,000 | ---D | C] -- C:\WINDOWS\pss
[2009/03/18 20:50:43 | 00,061,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\yxjr.sys
[2009/03/18 20:07:30 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Application Data\Malwarebytes
[2009/03/18 20:07:27 | 00,000,696 | ---- | C] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/18 20:07:26 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2009/03/18 20:07:24 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/03/18 20:07:23 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2009/03/18 20:07:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2009/03/18 20:04:24 | 00,004,128 | ---- | C] () -- C:\INFCACHE.1
[2009/03/18 20:01:42 | 00,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2009/03/14 20:35:25 | 00,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2009/03/14 16:46:55 | 04,790,272 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Grad wall athletes prior to 1990 highlighted by Sarah FINAL VERSION.xls
[2009/03/13 14:53:33 | 01,769,472 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Original Grad wall athletes prior to 1990 highlighted by Sarah.xls
[2009/03/11 01:09:52 | 00,011,163 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Fall Term 2009.docx
[2009/03/11 01:01:15 | 00,029,184 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Language Content.doc
[2009/03/06 16:42:03 | 04,758,528 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\stuhandbook.doc
[2009/03/06 14:13:30 | 00,014,427 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\NCAA REGULATIONS.docx
[2009/03/04 14:21:42 | 00,587,776 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Progress_Report_Coaches_Mar3.xls
[2009/03/02 11:14:19 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Blake\Desktop\Assignment 2
[2009/03/02 11:05:45 | 00,897,161 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\Assignment 2.zip
[2009/02/27 16:47:52 | 00,031,232 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\WSU Outside Competition Approval Form1.doc
[2009/02/27 16:46:53 | 00,039,936 | ---- | C] () -- C:\Documents and Settings\Blake\Desktop\WSU Donation Request Form1.doc
========== Files - Modified Within 30 Days ==========
[2 C:\WINDOWS\*.tmp files]
[2009/03/29 13:54:47 | 83,878,176 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2009/03/29 13:54:41 | 00,498,688 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Blake\Desktop\OTListIt2.exe
[2009/03/29 13:50:37 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/03/29 13:48:07 | 00,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/03/29 13:43:08 | 02,936,847 | R--- | M] () -- C:\Documents and Settings\Blake\Desktop\ComboFix.exe
[2009/03/29 13:36:02 | 00,000,144 | ---- | M] () -- C:\WINDOWS\System32\pdfl.dat
[2009/03/29 13:34:58 | 00,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/03/29 13:34:32 | 00,351,219 | ---- | M] () -- C:\WINDOWS\System32\vsconfig.xml
[2009/03/29 13:34:08 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/03/29 13:34:04 | 93,747,2000 | -HS- | M] () -- C:\hiberfil.sys
[2009/03/29 13:32:53 | 01,097,732 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2009/03/29 13:32:24 | 05,895,250 | -H-- | M] () -- C:\Documents and Settings\Blake\Local Settings\Application Data\IconCache.db
[2009/03/29 03:30:41 | 00,000,738 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/03/29 03:30:41 | 00,000,279 | RHS- | M] () -- C:\boot.ini
[2009/03/29 01:58:22 | 00,000,780 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\SUPERAntiSpyware Free Edition.lnk
[2009/03/29 01:57:03 | 06,237,728 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\SUPERAntiSpyware.exe
[2009/03/29 01:54:40 | 00,175,504 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\activescan2_en.exe
[2009/03/29 01:50:07 | 00,001,435 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\HijackThis.lnk
[2009/03/29 01:44:55 | 00,003,157 | ---- | M] () -- C:\rollback.ini
[2009/03/29 01:41:14 | 00,812,344 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Blake\Desktop\HJTInstall.exe
[2009/03/29 01:01:24 | 00,009,584 | ---- | M] () -- C:\Documents and Settings\Blake\My Documents\cc_20090329_010026.reg
[2009/03/29 01:00:08 | 01,114,392 | ---- | M] () -- C:\Documents and Settings\Blake\My Documents\cc_20090329_005857.reg
[2009/03/29 00:54:47 | 00,001,486 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\CCleaner.lnk
[2009/03/29 00:52:20 | 03,190,688 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Blake\Desktop\ccsetup218.exe
[2009/03/28 22:28:08 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Rooter.exe
[2009/03/28 21:59:46 | 00,000,209 | ---- | M] () -- C:\Boot.bak
[2009/03/28 19:11:17 | 00,004,212 | -H-- | M] () -- C:\WINDOWS\System32\zllictbl.dat
[2009/03/28 19:09:24 | 00,000,144 | ---- | M] () -- C:\WINDOWS\System32\lkfl.dat
[2009/03/28 19:09:24 | 00,000,080 | ---- | M] () -- C:\WINDOWS\System32\ibfl.dat
[2009/03/28 19:02:30 | 00,267,656 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\ZASPSetup_en.exe
[2009/03/28 17:03:39 | 10,246,088 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\Blake\Desktop\windows-kb890830-v2.8.exe
[2009/03/27 13:48:21 | 00,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/03/27 13:31:54 | 03,063,218 | ---- | M] (Symantec Corporation) -- C:\Documents and Settings\Blake\Desktop\Norton_Removal_Tool.exe
[2009/03/24 18:42:17 | 00,444,908 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2009/03/24 18:42:17 | 00,081,712 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2009/03/24 18:42:17 | 00,003,842 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2009/03/18 20:50:43 | 00,061,440 | ---- | M] () -- C:\WINDOWS\System32\drivers\yxjr.sys
[2009/03/18 20:09:51 | 00,000,736 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2009/03/18 20:07:27 | 00,000,696 | ---- | M] () -- C:\DOCUME~1\ALLUSE~1\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/03/18 20:04:24 | 00,004,128 | ---- | M] () -- C:\INFCACHE.1
[2009/03/14 20:52:07 | 00,011,168 | -H-- | M] () -- C:\WINDOWS\System32\buzifupa
[2009/03/14 16:46:57 | 04,790,272 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Grad wall athletes prior to 1990 highlighted by Sarah FINAL VERSION.xls
[2009/03/13 14:53:38 | 01,769,472 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Original Grad wall athletes prior to 1990 highlighted by Sarah.xls
[2009/03/11 19:16:24 | 00,029,184 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Language Content.doc
[2009/03/11 06:58:35 | 00,275,760 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2009/03/11 01:09:52 | 00,011,163 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Fall Term 2009.docx
[2009/03/10 23:37:34 | 00,002,672 | -HS- | M] () -- C:\WINDOWS\System32\KGyGaAvL.sys
[2009/03/10 23:37:25 | 00,000,088 | RHS- | M] () -- C:\WINDOWS\System32\8509F7DFD7.sys
[2009/03/06 16:42:09 | 04,758,528 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\stuhandbook.doc
[2009/03/06 15:47:04 | 00,014,427 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\NCAA REGULATIONS.docx
[2009/03/04 16:10:12 | 00,587,776 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Progress_Report_Coaches_Mar3.xls
[2009/03/02 11:05:46 | 00,897,161 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\Assignment 2.zip
[2009/02/27 16:47:52 | 00,031,232 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\WSU Outside Competition Approval Form1.doc
[2009/02/27 16:47:14 | 00,039,936 | ---- | M] () -- C:\Documents and Settings\Blake\Desktop\WSU Donation Request Form1.doc
< End of report >