there are tons of IE browser popping up. i cant see them on my monitor, but i see lots of them at the task manager.
even if im not surfing the web/ using any browser. i see a lot of iexplorer on the taskbar menu. i have to close them all one by one for my pc to go fast again.
i downloaded spysweeper yesterday, and it keeps blocking internet access from hundreds of websites. i was able to list a few..
AD.MOKEAD.COM
ADSEXTEND.NET
ALLMEGABUCKS.COM
AMAENA.COM
ANALCORD.COM
ANIMEPORNMAG.COM
ANTISPYLAB.COM
ANTIVIRUSGOLDEN.COM
APROTECTEDPAGE.COM
ASDBIZ.NET
ASECURITISSUE.COM
ASTA-KILLER.COM
ATTREZZI.BIZ
AWMDABEST.COM
BABESPORNMAGS.COM
BARDOWNLOAD.COM
those are few of the sites that my pv keep logging on to.
another irritating problem is the sysfader error. i have my windows system at "for best performance" state already. no animation or fading whatsoever. yet it still pops up a lot of sysfader error.
i know theres a virus somewhere. i tried everything (ad-aware, search destroy, spysweeper etc) i also tried a bunch of antivirus and online scans (avira, avast, avg, trendmicro, bitdefender) yet non of them seem to detect them.
i followed the instructions above and here're my logs
Microsoft Windows XP Professional (5.1.2600) Service Pack 2
C:\ [Fixed] - NTFS - (Total:38154 Mo/Free:712 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Mon 05/04/2009|14:27
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\Program Files\Windows Defender\MsMpEng.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\S24EvMon.exe
---------- C:\WINDOWS\system32\ZCfgSvc.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\wltrysvc.exe
---------- C:\WINDOWS\System32\bcmwltry.exe
---------- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashServ.exe
---------- C:\WINDOWS\system32\1XConfig.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\WINDOWS\System32\SCardSvr.exe
---------- C:\WINDOWS\system32\wltray.exe
---------- C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
---------- C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\system32\RegSrvc.exe
---------- C:\Program Files\Spyware Terminator\sp_rsser.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe
---------- C:\WINDOWS\system32\rundll71.exe
---------- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
---------- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\WINDOWS\system32\wuauclt.exe
---------- C:\Program Files\Webroot\WebrootSecurity\SSU.EXE
---------- C:\WINDOWS\system32\msiexec.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Program Files\Internet Explorer\iexplore.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{4C9B3070-CF49-4D16-ADC0-927871099B13}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\..\{7B009066-5D21-445C-A2F2-E3B7BA29EB31}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{4C9B3070-CF49-4D16-ADC0-927871099B13}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\..\{7B009066-5D21-445C-A2F2-E3B7BA29EB31}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{4C9B3070-CF49-4D16-ADC0-927871099B13}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\..\{7B009066-5D21-445C-A2F2-E3B7BA29EB31}]
NameServer REG_SZ 85.255.112.195,85.255.112.14
==> WAREOUT <==
----------------------\\ ROOTKIT !!
----------------------\\ Cracks & Keygens..
C:\DOCUME~1\XCAPE~1.LAF\My Documents\Downloads\xxx games. pc games HentaII 3D\HentaII 3D\Crack.exe
C:\DOCUME~1\XCAPE~1.LAF\My Documents\Downloads\XXX games. pc games VirtuallyJenny\3DVirtuallyJenny\Crack\VirtuallyJenna-025.002.exe
1 - "C:\Rooter$\Rooter_1.txt" - Mon 05/04/2009|13:25
2 - "C:\Rooter$\Rooter_2.txt" - Mon 05/04/2009|14:28
----------------------\\ Scan completed at 14:28
------------------------------------------------------------------------------------
OTListIt logfile created on: 5/4/2009 2:29:15 PM - Run 2
OTListIt2 by OldTimer - Version 2.0.15.3 Folder = C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
767.23 Mb Total Physical Memory | 304.85 Mb Available Physical Memory | 39.73% Memory free
1.83 Gb Paging File | 1.30 Gb Available in Paging File | 70.91% Paging File free
Paging file location(s): C:\pagefile.sys 1152 2304 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.26 Gb Total Space | 4.69 Gb Free Space | 12.59% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: LAFFITHU-7FBCJV
Current User Name: xcape
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Output = Minimal
File Age = 30 Days
Company Name Whitelist: On
========== Processes (SafeList) ==========
PRC - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
PRC - C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
PRC - C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
PRC - C:\WINDOWS\system32\ZCfgSvc.exe (Intel Corporation)
PRC - C:\WINDOWS\System32\wltrysvc.exe ()
PRC - C:\WINDOWS\System32\bcmwltry.exe (Broadcom Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
PRC - C:\WINDOWS\system32\1XConfig.exe (Intel Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\WINDOWS\system32\wltray.exe (Broadcom Corporation)
PRC - C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe (Webroot Software, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
PRC - C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
PRC - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
PRC - C:\WINDOWS\system32\rundll71.exe ()
PRC - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
PRC - C:\Program Files\Webroot\WebrootSecurity\SSU.EXE (Webroot Software, Inc. (www.webroot.com))
PRC - C:\WINDOWS\system32\cmd.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\OTListIt2.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (aswUpdSv [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe (ALWIL Software)
SRV - (Ati HotKey Poller [Disabled | Stopped]) -- C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (avast! Antivirus [Auto | Running]) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe (ALWIL Software)
SRV - (avast! Mail Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe (ALWIL Software)
SRV - (avast! Web Scanner [On_Demand | Running]) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe (ALWIL Software)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (helpsvc [Auto | Running]) -- C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) -- C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (Lavasoft Ad-Aware Service [Disabled | Stopped]) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (Microsoft Office Groove Audit Service [Disabled | Stopped]) -- C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe (Microsoft Corporation)
SRV - (odserv [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE (Microsoft Corporation)
SRV - (ose [On_Demand | Stopped]) -- C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Pml Driver HPZ12 [Disabled | Stopped]) -- C:\WINDOWS\System32\HPZipm12.exe (HP)
SRV - (RegSrvc [Auto | Running]) -- C:\WINDOWS\system32\RegSrvc.exe (Intel Corporation)
SRV - (S24EventMonitor [Auto | Running]) -- C:\WINDOWS\system32\S24EvMon.exe (Intel Corporation )
SRV - (sp_rssrv [Auto | Running]) -- C:\Program Files\Spyware Terminator\sp_rsser.exe (Crawler.com)
SRV - (WebrootSpySweeperService [Auto | Running]) -- C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe (Webroot Software, Inc. (www.webroot.com))
SRV - (WinDefend [Auto | Running]) -- C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (wltrysvc [Auto | Running]) -- C:\WINDOWS\System32\wltrysvc.exe ()
SRV - (WRConsumerService [Auto | Running]) -- C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe (Webroot Software, Inc. )
========== Driver Services (SafeList) ==========
DRV - (a016bus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016bus.sys (MCCI Corporation)
DRV - (a016mdfl [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mdfl.sys (MCCI Corporation)
DRV - (a016mdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mdm.sys (MCCI Corporation)
DRV - (a016mgmt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016mgmt.sys (MCCI Corporation)
DRV - (a016obex [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\a016obex.sys (MCCI Corporation)
DRV - (Aavmker4 [System | Running]) -- C:\WINDOWS\System32\drivers\aavmker4.sys (ALWIL Software)
DRV - (AegisP [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\AegisP.sys (Meetinghouse Data Communications)
DRV - (AnyDVD [On_Demand | Running]) -- C:\WINDOWS\System32\Drivers\AnyDVD.sys (SlySoft, Inc.)
DRV - (ApfiltrService [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\Apfiltr.sys (Alps Electric Co., Ltd.)
DRV - (aswFsBlk [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\aswFsBlk.sys (ALWIL Software)
DRV - (aswMon2 [Auto | Running]) -- C:\WINDOWS\System32\drivers\aswmon2.sys (ALWIL Software)
DRV - (aswRdr [On_Demand | Running]) -- C:\WINDOWS\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswSP [System | Running]) -- C:\WINDOWS\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswTdi [System | Running]) -- C:\WINDOWS\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (ati2mtag [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (b57w2k [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\b57xp32.sys (Broadcom Corporation)
DRV - (BCMWLNPF [Auto | Running]) -- C:\WINDOWS\system32\drivers\bcmwlnpf.sys (CACE Technologies)
DRV - (DNINDIS5 [On_Demand | Stopped]) -- C:\WINDOWS\system32\DNINDIS5.SYS (Printing Communications Assoc., Inc. (PCAUSA))
DRV - (ElbyCDIO [Auto | Running]) -- C:\WINDOWS\System32\Drivers\ElbyCDIO.sys (Elaborate Bytes AG)
DRV - (gv3 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\gv3.sys (Microsoft Corporation)
DRV - (HPZid412 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZid412.sys (HP)
DRV - (HPZipr12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZipr12.sys (HP)
DRV - (HPZius12 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\HPZius12.sys (HP)
DRV - (HSFHWICH [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (HSF_DPV [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_DPV.SYS (Conexant Systems, Inc.)
DRV - (k750bus [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\k750bus.sys (MCCI)
DRV - (k750mdfl [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\k750mdfl.sys (MCCI)
DRV - (k750mdm [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\k750mdm.sys (MCCI)
DRV - (k750mgmt [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\k750mgmt.sys (MCCI)
DRV - (k750obex [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\k750obex.sys (MCCI)
DRV - (Lbd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (mdmxsdk [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\mdmxsdk.sys (Conexant)
DRV - (NAL [On_Demand | Stopped]) -- C:\WINDOWS\System32\Drivers\iqvw32.sys (Intel Corporation )
DRV - (NdisWDM [On_Demand | Stopped]) -- C:\WINDOWS\system32\DRIVERS\ndiswdm.sys (Broadcom Corporation)
DRV - (omci [System | Running]) -- C:\WINDOWS\System32\DRIVERS\omci.sys (Dell Computer Corporation)
DRV - (oreans32 [System | Running]) -- C:\WINDOWS\system32\drivers\oreans32.sys ()
DRV - (OZSCR [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ozscr.sys (O2Micro)
DRV - (Ptilink [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (PxHelp20 [Boot | Running]) -- C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (s24trans [Auto | Running]) -- C:\WINDOWS\System32\DRIVERS\s24trans.sys (Intel Corporation)
DRV - (SCDEmu [System | Running]) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (SONYPVU1 [On_Demand | Stopped]) -- C:\WINDOWS\System32\DRIVERS\SONYPVU1.SYS (Sony Corporation)
DRV - (sptd [Boot | Running]) -- C:\WINDOWS\System32\Drivers\sptd.sys ()
DRV - (sp_rsdrv2 [System | Running]) -- C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ()
DRV - (ssfs0bbc [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ssfs0bbc.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (sshrmd [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\sshrmd.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (ssidrv [Boot | Running]) -- C:\WINDOWS\system32\DRIVERS\ssidrv.sys (Webroot Software, Inc. (www.webroot.com))
DRV - (STAC97 [On_Demand | Running]) -- C:\WINDOWS\system32\drivers\stac97.sys (SigmaTel, Inc.)
DRV - (usbaudio [On_Demand | Stopped]) -- C:\WINDOWS\system32\drivers\usbaudio.sys (Microsoft Corporation)
DRV - (w70n51 [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\w70n51.sys (Intel® Corporation)
DRV - (winachsf [On_Demand | Running]) -- C:\WINDOWS\System32\DRIVERS\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (zumbus [Auto | Running]) -- C:\WINDOWS\system32\DRIVERS\zumbus.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://www.google.co...m...tf8&oe=utf8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/?fr=fp-yie8
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,AutoSearch = http://ie.search.msn...autosearch.aspx
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn...st/srchcust.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo....r=ytff-msgr&p="
FF - prefs.js..browser.search.param.yahoo-fr: "moz2-ytff-msgr"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "moz2-ytff-msgr"
FF - prefs.js..browser.search.selectedEngine: "Yahoo"
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: [email protected]:1.0.0.07074039
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.0.10
FF - prefs.js..keyword.URL: "http://search.yahoo....r=ytff-msgr&p="
FF - HKLM\software\mozilla\Firefox\Extensions\\[email protected]: C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2009/03/10 19:58:29 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Components: C:\PROGRAM FILES\MOZILLA FIREFOX\COMPONENTS [2009/05/04 05:24:01 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.10\extensions\\Plugins: C:\PROGRAM FILES\MOZILLA FIREFOX\PLUGINS [2009/05/04 05:24:00 | 00,000,000 | ---D | M]
[2009/05/04 05:24:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\mozilla\Extensions
[2009/05/04 05:24:23 | 00,000,000 | ---D | M] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/05/04 07:03:37 | 00,000,000 | ---D | M] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\mozilla\Firefox\Profiles\szbofuzl.default\extensions
[2007/10/01 17:18:01 | 00,000,000 | ---D | M] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\mozilla\Firefox\Profiles\szbofuzl.default\extensions\[email protected]
[2009/05/04 05:24:24 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions
[2007/10/06 19:33:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2009/05/04 05:24:00 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
[2006/09/26 21:44:35 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions(2)
[2006/09/26 20:53:22 | 00,000,000 | ---D | M] -- C:\Program Files\mozilla firefox\extensions(2)\{972ce4c6-7e08-4474-a285-3208198ce6fd}(2)
[2009/04/23 21:38:30 | 00,023,032 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browserdirprovider.dll
[2009/04/23 21:38:32 | 00,134,648 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\brwsrcmp.dll
[2009/04/23 17:39:08 | 00,001,394 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom.xml
[2009/04/23 17:39:08 | 00,002,193 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\answers.xml
[2009/04/23 17:39:08 | 00,001,534 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\creativecommons.xml
[2009/04/23 17:39:08 | 00,002,343 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay.xml
[2009/04/23 17:39:08 | 00,001,706 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\google.xml
[2009/04/23 17:39:08 | 00,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia.xml
[2009/04/23 17:39:08 | 00,000,792 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo.xml
Hosts file not found
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - Reg Error: Key error. File not found
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (D) - {3D3F79EC-2889-3C5A-BFC7-A32C5229FB98} - C:\WINDOWS\system32\xwr32678.dll (Microsoft Corporation)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (Groove GFS Browser Helper) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - Reg Error: Key error. File not found
O2 - BHO: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - Reg Error: Key error. File not found
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (no name) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {6134CEA9-DD6E-495C-A0D1-4F232027D7D7} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {84798B8E-69F8-4846-9516-373C2996E2F7} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - Reg Error: Key error. File not found
O3 - HKLM\..\Toolbar: (no name) - {FBA44040-BD27-4A09-ACC8-C08B7C723DCD} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key error. File not found
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [Broadcom Wireless Manager] "C:\WINDOWS\system32\wltray.exe" (Broadcom Corporation)
O4 - HKLM..\Run: [Hotfix-KB5504305] "C:\WINDOWS\system32\rundll71.exe" ()
O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Inc.)
O4 - HKLM..\Run: [SpySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray (Webroot Software, Inc.)
O4 - HKCU..\Run: [DiskChk help] rundll32.exe "C:\Documents and Settings\All Users.WINDOWS\proto.dll" run File not found
O4 - HKCU..\Run: [Hotfix-KB5504305] "C:\WINDOWS\system32\rundll71.exe" ()
O4 - HKCU..\Run: [nvd32_r] rundll32.exe "C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\unobi.dll" s File not found
O4 - HKLM..\RunServices: [Hotfix-KB5504305] "C:\WINDOWS\system32\rundll71.exe" ()
O4 - HKCU..\RunServices: [Hotfix-KB5504305] "C:\WINDOWS\system32\rundll71.exe" ()
O4 - Startup: C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 1 [binary data]
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe ()
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe File not found
O15 - HKLM\..Trusted Domains: 34 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: 33 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} http://housecall65.t...ivex/hcImpl.cab (Trend Micro ActiveX Scan Agent 6.6)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/b...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} http://download.bitd...can8/oscan8.cab (BDSCANONLINE Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onec...lscbase5483.cab (Windows Live Safety Center Base Module)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://dl8-cdn-01.su...ows-i586-jc.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.ma...r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_12)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{4C9B3070-CF49-4D16-ADC0-927871099B13}\\NameServer = 85.255.112.195,85.255.112.14
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Interfaces\{7B009066-5D21-445C-A2F2-E3B7BA29EB31}\\NameServer = 85.255.112.195,85.255.112.14
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - Reg Error: Key error. File not found
O18 - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Filter: - text/xml - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\system32\Ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\Sebring: DllName - C:\WINDOWS\System32\LgNotify.dll - C:\WINDOWS\System32\LgNotify.dll (Intel Corporation)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O27 - HKLM IFEO\ctfmon.exe: Debugger - C:\WINDOWS\system32\ctfmon_lh.exe File not found
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O28 - HKLM ShellExecuteHooks: {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/06/08 02:11:03 | 00,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
========== Files/Folders - Created Within 30 Days ==========
[5 C:\WINDOWS\*.tmp files]
[2009/05/04 14:12:50 | 00,001,674 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Spy Sweeper.lnk
[2009/05/04 14:10:45 | 01,553,272 | ---- | C] (Webroot Software, Inc.) -- C:\WINDOWS\WRSetup.dll
[2009/05/04 14:10:44 | 00,000,000 | ---D | C] -- C:\Program Files\Webroot
[2009/05/04 14:10:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\Webroot
[2009/05/04 14:10:44 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Webroot
[2009/05/04 13:35:15 | 00,000,000 | ---D | C] -- C:\Binaries
[2009/05/04 13:26:04 | 00,501,248 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\OTListIt2.exe
[2009/05/04 13:24:50 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/05/04 13:24:44 | 00,267,612 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\Rooter.exe
[2009/05/04 12:55:53 | 02,967,800 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\tup.exe
[2009/05/04 12:51:40 | 00,000,772 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/05/04 12:51:38 | 00,000,616 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\NTREGOPT.lnk
[2009/05/04 12:51:38 | 00,000,597 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\ERUNT.lnk
[2009/05/04 12:51:37 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/05/04 12:50:21 | 00,791,393 | ---- | C] (Lars Hederer ) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\erunt_setup.exe
[2009/05/04 12:48:13 | 00,021,504 | ---- | C] (Doug Knox) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\SysRestorePoint.exe
[2009/05/04 05:30:50 | 00,000,000 | -H-D | C] -- C:\WINDOWS\ie8
[2009/05/04 05:27:08 | 20,098,288 | ---- | C] (Microsoft Corporation) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\ie8-setup-full.exe
[2009/05/04 05:24:41 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Google
[2009/05/04 05:24:04 | 00,001,607 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2009/05/04 05:23:53 | 11,179,045 | ---- | C] () -- C:\WINDOWS\393830.gt
[2009/05/04 05:07:17 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswRdr.sys
[2009/05/04 05:07:17 | 00,001,714 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\avast! Antivirus.lnk
[2009/05/04 05:07:15 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswTdi.sys
[2009/05/04 05:07:12 | 00,026,944 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aavmker4.sys
[2009/05/04 05:07:10 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\AvastSS.scr
[2009/05/04 05:07:09 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswSP.sys
[2009/05/04 05:07:09 | 00,094,032 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon2.sys
[2009/05/04 05:07:09 | 00,093,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswmon.sys
[2009/05/04 05:07:09 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2009/05/04 05:06:49 | 01,256,296 | ---- | C] (ALWIL Software) -- C:\WINDOWS\System32\aswBoot.exe
[2009/05/04 05:06:49 | 00,380,928 | ---- | C] () -- C:\WINDOWS\System32\actskin4.ocx
[2009/05/04 05:06:46 | 00,000,000 | ---D | C] -- C:\Program Files\Alwil Software
[2009/05/04 04:36:52 | 00,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2009/05/04 02:35:40 | 00,027,649 | ---- | C] () -- C:\WINDOWS\System32\gxvxcoeiuyqbtstvdosnylwairpmuweaeeybd.dll
[2009/05/04 02:35:40 | 00,000,004 | ---- | C] () -- C:\WINDOWS\System32\gxvxccounter
[2009/05/04 02:35:34 | 00,065,536 | RHS- | C] () -- C:\WINDOWS\System32\rundll71.exe
[2009/05/04 02:35:29 | 00,036,864 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\unobi.dll
[2009/05/04 02:20:32 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Avira
[2009/05/03 18:45:27 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2296592.exe
[2009/05/03 18:45:26 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2296392.exe
[2009/05/03 18:44:46 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2256354.exe
[2009/05/03 18:44:46 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2256154.exe
[2009/05/03 18:44:37 | 01,355,776 | ---- | C] (Python Software Foundation) -- C:\WINDOWS\System32\python25.dll
[2009/05/03 18:43:42 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2191701.exe
[2009/05/03 18:43:41 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2191511.exe
[2009/05/03 18:43:27 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr32678.dll
[2009/05/03 18:43:27 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr32678.dll
[2009/05/03 18:43:26 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2176289.exe
[2009/05/03 18:43:26 | 00,033,280 | ---- | C] () -- C:\WINDOWS\System32\xa2176008.exe
[2009/05/03 17:45:02 | 00,004,096 | ---- | C] () -- C:\WINDOWS\d3dx.dat
[2009/05/03 17:37:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\Fishing Craze
[2009/05/03 17:37:54 | 00,000,000 | ---D | C] -- C:\Program Files\Fishing Craze
[2009/05/03 17:29:03 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\d3dx9_24.dll
[2009/05/03 17:28:20 | 02,222,800 | ---- | C] (Microsoft Corporation) -- C:\d3dx9_24.dll
[2009/05/03 16:05:30 | 00,000,000 | ---D | C] -- C:\Program Files\Illusion
[2009/05/03 15:42:32 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr96890.dll
[2009/05/03 15:42:32 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr96890.dll
[2009/05/03 15:42:30 | 09,653,423 | ---- | C] () -- C:\WINDOWS\System32\xa1938978.exe
[2009/05/03 15:42:28 | 09,653,423 | ---- | C] () -- C:\WINDOWS\System32\xa1937265.exe
[2009/05/03 15:36:04 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr13723.dll
[2009/05/03 15:36:04 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr13723.dll
[2009/05/03 15:36:03 | 00,409,600 | ---- | C] () -- C:\WINDOWS\System32\xa1551911.exe
[2009/05/03 15:36:01 | 00,409,600 | ---- | C] () -- C:\WINDOWS\System32\xa1550309.exe
[2009/05/03 10:38:35 | 00,000,938 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Spybot - Search & Destroy.lnk
[2009/05/03 10:38:25 | 00,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2009/05/03 10:38:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Spybot - Search & Destroy
[2009/05/03 10:36:23 | 00,001,739 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\HijackThis.lnk
[2009/05/03 10:36:23 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2009/05/03 02:40:31 | 00,015,688 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/05/03 01:57:43 | 00,000,472 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/05/03 01:57:27 | 00,064,160 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/05/03 01:55:50 | 00,000,000 | -H-D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\{7972B2E5-3E09-4E5E-81B7-FE5819D6772F}
[2009/05/03 01:55:48 | 00,000,872 | ---- | C] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Ad-Aware.lnk
[2009/05/03 01:55:36 | 00,000,000 | ---D | C] -- C:\Program Files\Lavasoft
[2009/05/03 01:55:36 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Lavasoft
[2009/05/02 13:07:11 | 00,000,000 | ---D | C] -- C:\Program Files\Panda Security
[2009/05/02 11:48:35 | 00,000,000 | ---D | C] -- C:\WINDOWS\BDOSCAN8
[2009/05/02 09:13:17 | 00,001,747 | ---- | C] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\My Exotic Farm.lnk
[2009/05/02 09:12:44 | 00,000,000 | ---D | C] -- C:\Program Files\Games
[2009/05/02 09:10:44 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr61915.dll
[2009/05/02 09:10:43 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr61915.dll
[2009/05/02 09:10:39 | 86,296,198 | ---- | C] (Games ) -- C:\WINDOWS\System32\xa14182513.exe
[2009/05/02 09:10:10 | 86,296,198 | ---- | C] (Games ) -- C:\WINDOWS\System32\xa14153471.exe
[2009/05/02 09:09:24 | 86,296,198 | ---- | C] (Games ) -- C:\WINDOWS\System32\xa14107515.exe
[2009/05/02 09:08:09 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr70064.dll
[2009/05/02 09:08:09 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr70064.dll
[2009/05/02 09:08:08 | 00,915,968 | ---- | C] () -- C:\WINDOWS\System32\xa14030845.exe
[2009/05/02 09:08:07 | 00,915,968 | ---- | C] () -- C:\WINDOWS\System32\xa14030264.exe
[2009/05/02 08:03:19 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr19877.dll
[2009/05/02 08:03:16 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr19877.dll
[2009/05/02 08:02:59 | 06,352,680 | ---- | C] () -- C:\WINDOWS\System32\xa10122164.exe
[2009/05/02 08:02:20 | 06,352,680 | ---- | C] () -- C:\WINDOWS\System32\xa10082958.exe
[2009/05/02 07:59:39 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa9921947.exe
[2009/05/02 07:59:35 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa9917971.exe
[2009/05/02 06:46:24 | 00,000,000 | ---D | C] -- C:\Program Files\thriXXX
[2009/05/02 06:45:00 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr76379.dll
[2009/05/02 06:44:59 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr76379.dll
[2009/05/02 06:43:34 | 28,962,712 | ---- | C] () -- C:\WINDOWS\System32\xa5357273.exe
[2009/05/02 06:41:47 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5249959.exe
[2009/05/02 06:41:37 | 28,962,712 | ---- | C] () -- C:\WINDOWS\System32\xa5239574.exe
[2009/05/02 06:41:18 | 28,962,712 | ---- | C] () -- C:\WINDOWS\System32\xa5220727.exe
[2009/05/02 06:40:32 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5175041.exe
[2009/05/02 06:39:56 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr43707.dll
[2009/05/02 06:39:55 | 00,204,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wr43707.dll
[2009/05/02 06:39:53 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5135764.exe
[2009/05/02 06:39:46 | 22,502,160 | ---- | C] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5128834.exe
[2009/04/29 17:20:27 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Unused Desktop Shortcuts
[2009/04/25 19:38:36 | 00,278,528 | ---- | C] (Real Networks, Inc) -- C:\WINDOWS\System32\pncrt.dll
[2009/04/25 19:38:34 | 00,000,000 | ---D | C] -- C:\Program Files\Real Alternative
[2009/04/25 19:38:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\Real
[2009/04/25 19:38:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\Real
[2009/04/21 19:58:34 | 00,000,531 | ---- | C] () -- C:\WINDOWS\eReg.dat
[2009/04/21 19:58:27 | 00,000,000 | ---D | C] -- C:\Program Files\Maxis
[2009/04/18 23:38:35 | 00,283,648 | ---- | C] (Stirling Technologies, Inc.) -- C:\WINDOWS\uninst.exe
[2009/04/18 20:29:00 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\TVU Networks
[2009/04/18 03:45:18 | 00,000,000 | ---D | C] -- C:\Program Files\Apprentice
[2009/04/18 03:42:21 | 00,000,000 | ---D | C] -- C:\Program Files\Magic Workstation
[2009/04/16 21:53:00 | 00,007,680 | -HS- | C] () -- C:\WINDOWS\Thumbs.db
[2009/04/12 18:27:25 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\My Games
[2009/04/12 17:36:07 | 00,000,000 | ---D | C] -- C:\Program Files\Firaxis Games
[2009/04/12 17:35:27 | 02,297,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_26.dll
[2009/04/12 02:04:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Application Data\AVS4YOU
[2009/04/12 02:04:14 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users.WINDOWS\Application Data\AVS4YOU
[2009/04/12 02:02:06 | 00,000,000 | ---D | C] -- C:\Program Files\Common Files\AVSMedia
[2009/04/12 02:01:36 | 00,024,576 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\msxml3a.dll
[2009/04/12 02:01:35 | 00,000,000 | ---D | C] -- C:\Program Files\AVS4YOU
[2009/04/11 14:14:23 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Pictures
[2009/04/11 14:05:12 | 00,000,000 | ---D | C] -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Music
[2009/03/12 19:23:07 | 00,685,816 | ---- | C] () -- C:\WINDOWS\System32\drivers\sptd.sys
[2009/03/04 19:22:33 | 00,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2009/03/04 19:22:32 | 00,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2009/02/27 08:17:45 | 00,142,592 | ---- | C] () -- C:\WINDOWS\System32\drivers\sp_rsdrv2.sys
[2008/11/12 16:02:20 | 00,031,088 | ---- | C] () -- C:\WINDOWS\System32\wrLZMA.dll
[2008/06/22 15:18:43 | 00,033,952 | ---- | C] () -- C:\WINDOWS\System32\drivers\oreans32.sys
[2008/05/05 15:12:19 | 00,000,412 | ---- | C] () -- C:\WINDOWS\MAXLINK.INI
[2008/03/13 01:13:06 | 00,000,031 | ---- | C] () -- C:\WINDOWS\GunzLauncher.INI
[2008/01/23 00:13:00 | 00,000,754 | ---- | C] () -- C:\WINDOWS\WORDPAD.INI
[2008/01/09 15:01:48 | 00,000,453 | ---- | C] () -- C:\WINDOWS\bdoscandellang.ini
[2007/11/12 18:13:20 | 00,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll
[2007/10/04 09:04:46 | 00,000,000 | ---- | C] () -- C:\WINDOWS\PROTOCOL.INI
[2007/09/24 13:18:02 | 03,196,928 | ---- | C] () -- C:\WINDOWS\System32\libavcodec.dll
[2007/09/24 13:18:02 | 00,662,016 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2007/09/24 13:18:02 | 00,533,504 | ---- | C] () -- C:\WINDOWS\System32\ff_x264.dll
[2007/09/24 13:18:02 | 00,405,504 | ---- | C] () -- C:\WINDOWS\System32\libmplayer.dll
[2007/09/24 13:18:02 | 00,245,760 | ---- | C] () -- C:\WINDOWS\System32\ff_libfaad2.dll
[2007/09/24 13:18:02 | 00,155,648 | ---- | C] () -- C:\WINDOWS\System32\ff_libdts.dll
[2007/09/24 13:18:02 | 00,143,360 | ---- | C] () -- C:\WINDOWS\System32\ff_theora.dll
[2007/09/24 13:18:02 | 00,122,880 | ---- | C] () -- C:\WINDOWS\System32\ff_samplerate.dll
[2007/09/24 13:18:02 | 00,118,784 | ---- | C] () -- C:\WINDOWS\System32\ff_libmad.dll
[2007/09/24 13:18:02 | 00,114,688 | ---- | C] () -- C:\WINDOWS\System32\libmpeg2_ff.dll
[2007/09/24 13:18:02 | 00,097,280 | ---- | C] () -- C:\WINDOWS\System32\ff_realaac.dll
[2007/09/24 13:18:02 | 00,079,872 | ---- | C] () -- C:\WINDOWS\System32\ff_tremor.dll
[2007/09/24 13:18:02 | 00,040,960 | ---- | C] () -- C:\WINDOWS\System32\ff_liba52.dll
[2007/09/24 13:18:02 | 00,038,400 | ---- | C] () -- C:\WINDOWS\System32\ff_unrar.dll
[2007/09/24 13:18:02 | 00,026,624 | ---- | C] () -- C:\WINDOWS\System32\ff_wmv9.dll
[2007/09/24 13:18:02 | 00,008,192 | ---- | C] () -- C:\WINDOWS\System32\FLT_ffdshow.dll
[2007/09/24 13:06:38 | 00,007,680 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2007/08/21 23:53:32 | 00,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2007/08/20 17:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dtu100.dll.manifest
[2007/08/20 17:26:52 | 00,000,416 | ---- | C] () -- C:\WINDOWS\System32\dpl100.dll.manifest
[2007/08/15 15:33:14 | 03,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2007/06/03 00:06:14 | 00,151,040 | ---- | C] () -- C:\WINDOWS\System32\mkx.dll
[2007/06/03 00:06:08 | 00,110,592 | ---- | C] () -- C:\WINDOWS\System32\avi.dll
[2007/06/03 00:05:44 | 00,142,848 | ---- | C] () -- C:\WINDOWS\System32\mp4.dll
[2007/06/03 00:05:38 | 00,106,496 | ---- | C] () -- C:\WINDOWS\System32\avss.dll
[2007/06/03 00:05:34 | 00,123,392 | ---- | C] () -- C:\WINDOWS\System32\ogm.dll
[2007/06/03 00:05:20 | 00,159,744 | ---- | C] () -- C:\WINDOWS\System32\mmfinfo.dll
[2007/06/03 00:05:04 | 00,167,936 | ---- | C] () -- C:\WINDOWS\System32\ts.dll
[2007/06/03 00:04:54 | 00,233,984 | ---- | C] () -- C:\WINDOWS\System32\dxr.dll
[2007/06/03 00:04:32 | 00,100,352 | ---- | C] () -- C:\WINDOWS\System32\avs.dll
[2007/06/03 00:04:16 | 00,079,360 | ---- | C] () -- C:\WINDOWS\System32\mkzlib.dll
[2007/06/03 00:04:14 | 00,023,552 | ---- | C] () -- C:\WINDOWS\System32\mkunicode.dll
[2007/04/30 21:49:36 | 00,565,248 | ---- | C] () -- C:\WINDOWS\System32\hpotscl.dll
[2006/12/31 16:00:00 | 00,741,376 | ---- | C] () -- C:\WINDOWS\System32\audxlib.dll
[2006/12/31 16:00:00 | 00,221,184 | ---- | C] () -- C:\WINDOWS\System32\ff_kernelDeint.dll
[2006/12/31 16:00:00 | 00,200,704 | ---- | C] () -- C:\WINDOWS\System32\TomsMoComp_ff.dll
[2006/12/31 16:00:00 | 00,000,547 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll.manifest
[2006/11/01 07:54:30 | 00,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2005/07/05 02:37:14 | 00,045,124 | ---- | C] () -- C:\WINDOWS\System32\LsaWrApi.dll
[2005/07/05 02:29:16 | 00,139,264 | ---- | C] () -- C:\WINDOWS\System32\ShellNav.dll
[2005/07/05 02:27:42 | 00,532,549 | ---- | C] () -- C:\WINDOWS\System32\C1XStngs.dll
[2005/07/05 02:26:40 | 00,069,632 | ---- | C] () -- C:\WINDOWS\System32\D8021Xps.dll
[2005/01/13 04:00:14 | 00,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2003/09/04 09:49:16 | 00,000,000 | ---- | C] () -- C:\WINDOWS\System32\HPODStormEncoder(2).dll
[2002/08/29 05:00:00 | 00,000,617 | ---- | C] () -- C:\WINDOWS\win.ini
[2002/08/29 05:00:00 | 00,000,348 | ---- | C] () -- C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[5 C:\WINDOWS\*.tmp files]
File not found -- C:\WINDOWS\System32\drivers\etc\HOSTS.bak
[2049/12/31 17:00:00 | 00,045,195 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Xmas FLC 2008 19.JPG
[2009/05/04 14:17:54 | 00,000,330 | -H-- | M] () -- C:\WINDOWS\tasks\MP Scheduled Scan.job
[2009/05/04 14:17:34 | 00,002,422 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2009/05/04 14:14:53 | 00,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2009/05/04 14:14:41 | 00,000,062 | -HS- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Local Settings\desktop.ini
[2009/05/04 14:14:38 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2009/05/04 14:14:35 | 80,456,4992 | -HS- | M] () -- C:\hiberfil.sys
[2009/05/04 14:12:50 | 00,001,674 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Spy Sweeper.lnk
[2009/05/04 13:26:05 | 00,501,248 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\OTListIt2.exe
[2009/05/04 13:24:45 | 00,267,612 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\Rooter.exe
[2009/05/04 12:55:58 | 02,967,800 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\tup.exe
[2009/05/04 12:51:40 | 00,000,772 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2009/05/04 12:51:38 | 00,000,616 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\NTREGOPT.lnk
[2009/05/04 12:51:38 | 00,000,597 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\ERUNT.lnk
[2009/05/04 12:50:23 | 00,791,393 | ---- | M] (Lars Hederer ) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\erunt_setup.exe
[2009/05/04 12:48:14 | 00,021,504 | ---- | M] (Doug Knox) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\SysRestorePoint.exe
[2009/05/04 05:42:57 | 00,000,617 | ---- | M] () -- C:\WINDOWS\win.ini
[2009/05/04 05:42:57 | 00,000,348 | ---- | M] () -- C:\WINDOWS\system.ini
[2009/05/04 05:42:57 | 00,000,211 | RHS- | M] () -- C:\boot.ini
[2009/05/04 05:39:10 | 00,000,076 | -HS- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\desktop.ini
[2009/05/04 05:36:58 | 11,179,045 | ---- | M] () -- C:\WINDOWS\393830.gt
[2009/05/04 05:27:09 | 20,098,288 | ---- | M] (Microsoft Corporation) -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\ie8-setup-full.exe
[2009/05/04 05:24:04 | 00,001,607 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Mozilla Firefox.lnk
[2009/05/04 05:08:33 | 00,000,004 | ---- | M] () -- C:\WINDOWS\System32\gxvxccounter
[2009/05/04 05:07:17 | 00,001,714 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\avast! Antivirus.lnk
[2009/05/04 05:07:09 | 00,002,626 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2009/05/04 04:22:05 | 00,007,680 | -HS- | M] () -- C:\WINDOWS\Thumbs.db
[2009/05/04 02:35:40 | 00,027,649 | ---- | M] () -- C:\WINDOWS\System32\gxvxcoeiuyqbtstvdosnylwairpmuweaeeybd.dll
[2009/05/04 02:35:22 | 00,065,536 | RHS- | M] () -- C:\WINDOWS\System32\rundll71.exe
[2009/05/04 01:57:06 | 00,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2009/05/03 22:00:00 | 00,000,384 | ---- | M] () -- C:\WINDOWS\tasks\SmartDefrag.job
[2009/05/03 18:45:26 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2296592.exe
[2009/05/03 18:45:26 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2296392.exe
[2009/05/03 18:44:46 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2256354.exe
[2009/05/03 18:44:46 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2256154.exe
[2009/05/03 18:43:41 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2191701.exe
[2009/05/03 18:43:41 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2191511.exe
[2009/05/03 18:43:27 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr32678.dll
[2009/05/03 18:43:27 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr32678.dll
[2009/05/03 18:43:26 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2176289.exe
[2009/05/03 18:43:26 | 00,033,280 | ---- | M] () -- C:\WINDOWS\System32\xa2176008.exe
[2009/05/03 17:45:02 | 00,004,096 | ---- | M] () -- C:\WINDOWS\d3dx.dat
[2009/05/03 15:42:32 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr96890.dll
[2009/05/03 15:42:32 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr96890.dll
[2009/05/03 15:42:30 | 09,653,423 | ---- | M] () -- C:\WINDOWS\System32\xa1938978.exe
[2009/05/03 15:42:30 | 09,653,423 | ---- | M] () -- C:\WINDOWS\System32\xa1937265.exe
[2009/05/03 15:36:04 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr13723.dll
[2009/05/03 15:36:04 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr13723.dll
[2009/05/03 15:36:03 | 00,409,600 | ---- | M] () -- C:\WINDOWS\System32\xa1551911.exe
[2009/05/03 15:36:03 | 00,409,600 | ---- | M] () -- C:\WINDOWS\System32\xa1550309.exe
[2009/05/03 12:00:03 | 00,000,394 | ---- | M] () -- C:\WINDOWS\tasks\Schedule Task Weekly.job
[2009/05/03 10:38:35 | 00,000,938 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\Spybot - Search & Destroy.lnk
[2009/05/03 10:36:23 | 00,001,739 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\HijackThis.lnk
[2009/05/03 01:57:19 | 00,015,688 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe
[2009/05/03 01:57:06 | 00,064,160 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys
[2009/05/03 01:55:48 | 00,000,872 | ---- | M] () -- C:\Documents and Settings\All Users.WINDOWS\Desktop\Ad-Aware.lnk
[2009/05/02 09:13:17 | 00,001,747 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\My Exotic Farm.lnk
[2009/05/02 09:10:44 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr61915.dll
[2009/05/02 09:10:44 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr61915.dll
[2009/05/02 09:10:39 | 86,296,198 | ---- | M] (Games ) -- C:\WINDOWS\System32\xa14182513.exe
[2009/05/02 09:10:39 | 86,296,198 | ---- | M] (Games ) -- C:\WINDOWS\System32\xa14153471.exe
[2009/05/02 09:10:39 | 86,296,198 | ---- | M] (Games ) -- C:\WINDOWS\System32\xa14107515.exe
[2009/05/02 09:08:09 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr70064.dll
[2009/05/02 09:08:09 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr70064.dll
[2009/05/02 09:08:07 | 00,915,968 | ---- | M] () -- C:\WINDOWS\System32\xa14030845.exe
[2009/05/02 09:08:07 | 00,915,968 | ---- | M] () -- C:\WINDOWS\System32\xa14030264.exe
[2009/05/02 08:03:17 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr19877.dll
[2009/05/02 08:03:17 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr19877.dll
[2009/05/02 08:02:46 | 06,352,680 | ---- | M] () -- C:\WINDOWS\System32\xa10122164.exe
[2009/05/02 08:02:46 | 06,352,680 | ---- | M] () -- C:\WINDOWS\System32\xa10082958.exe
[2009/05/02 07:59:38 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa9921947.exe
[2009/05/02 07:59:38 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa9917971.exe
[2009/05/02 06:44:59 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr76379.dll
[2009/05/02 06:44:59 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr76379.dll
[2009/05/02 06:43:09 | 28,962,712 | ---- | M] () -- C:\WINDOWS\System32\xa5357273.exe
[2009/05/02 06:43:09 | 28,962,712 | ---- | M] () -- C:\WINDOWS\System32\xa5239574.exe
[2009/05/02 06:43:09 | 28,962,712 | ---- | M] () -- C:\WINDOWS\System32\xa5220727.exe
[2009/05/02 06:41:22 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5249959.exe
[2009/05/02 06:41:22 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5175041.exe
[2009/05/02 06:39:55 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\xwr43707.dll
[2009/05/02 06:39:55 | 00,204,800 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\System32\wr43707.dll
[2009/05/02 06:39:52 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5135764.exe
[2009/05/02 06:39:52 | 22,502,160 | ---- | M] (NET-DIMENSION CORPORATION) -- C:\WINDOWS\System32\xa5128834.exe
[2009/04/21 19:58:34 | 00,000,531 | ---- | M] () -- C:\WINDOWS\eReg.dat
[2009/04/17 06:00:10 | 00,117,248 | -HS- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\Thumbs.db
[2009/04/10 09:56:19 | 00,001,553 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\Desktop\CCleaner.lnk
[2009/04/07 02:04:03 | 00,035,345 | ---- | M] () -- C:\Documents and Settings\xcape.LAFFITHU-7FBCJV\My Documents\resume.rtf
========== Alternate Data Streams ==========
@Alternate Data Stream - 118 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:0A6D6CB4
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:D1B5B4F1
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:DFC5A2B2
@Alternate Data Stream - 106 bytes -> C:\Documents and Settings\All Users.WINDOWS\Application Data\TEMP:1CA73D29
< End of report >
please help me my laptop is really really slow now