I had some problems getting GMER to run. It would freeze up, or when it did run all the way through, there was no log created. It was weird.
Also, Norton has popped up a couple times saying it found a virus named Backdoor.Tidserv!inf
Here's the ComboFix Log:
ComboFix 10-08-21.06 - Pozydaev 08/25/2010 17:18:00.3.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.1022.342 [GMT -4:00]
Running from: c:\documents and settings\Pozydaev\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Pozydaev\Desktop\CFScript.txt
FILE ::
"c:\windows\system32\drivers\zwfuhslde3.sys"
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_ZWFUHSLDE3
-------\Service_zwfuhslde3
((((((((((((((((((((((((( Files Created from 2010-07-25 to 2010-08-25 )))))))))))))))))))))))))))))))
.
2010-08-25 21:16 . 2010-08-25 21:17 -------- d-----w- C:\8be4beba3156b27715f28b0d
2010-08-23 21:41 . 2010-08-25 21:18 -------- d-----w- c:\windows\LastGood.Tmp
2010-08-22 20:44 . 2008-04-14 00:12 50176 -c--a-w- c:\windows\system32\dllcache\proquota.exe
2010-08-22 20:44 . 2008-04-14 00:12 50176 ----a-w- c:\windows\system32\proquota.exe
2010-08-22 19:52 . 2010-08-22 19:52 -------- d-----w- C:\_OTL
2010-08-17 01:57 . 2010-08-17 01:57 -------- d-----w- c:\documents and settings\Administrator\Local Settings\Application Data\Mozilla
2010-08-17 01:52 . 2010-08-17 01:52 -------- d-----w- c:\documents and settings\Administrator\Application Data\Lavasoft
2010-08-11 23:06 . 2010-08-11 23:06 -------- d-----w- c:\documents and settings\LocalService\Local Settings\Application Data\Mozilla
2010-08-10 21:23 . 2010-08-10 21:23 -------- d-s---w- c:\documents and settings\NetworkService\UserData
2010-08-09 13:34 . 2010-08-17 02:56 -------- d-----w- c:\documents and settings\All Users\Application Data\Update
2010-07-30 17:17 . 2010-07-30 17:18 -------- d-----w- c:\documents and settings\NetworkService\Local Settings\Application Data\Adobe
2010-07-28 17:04 . 2010-08-08 04:23 664 ----a-w- c:\windows\system32\d3d9caps.dat
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-08-09 21:30 . 2009-06-23 02:00 -------- d-----w- c:\documents and settings\Pozydaev\Application Data\HPAppData
2010-07-31 02:30 . 2009-05-02 13:40 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-17 14:03 . 2004-08-04 12:00 80384 ----a-w- c:\windows\system32\iccvid.dll
2010-06-14 14:31 . 2007-03-15 23:58 744448 ----a-w- c:\windows\pchealth\helpctr\binaries\helpsvc.exe
2010-06-11 20:51 . 2010-06-11 20:51 3055600 ----a-w- c:\documents and settings\Pozydaev\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
2010-06-11 20:36 . 2010-06-11 20:36 275952 ----a-w- c:\documents and settings\Pozydaev\Application Data\Mozilla\plugins\npgoogletalk.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Google Update"="c:\documents and settings\Pozydaev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2010-03-12 135664]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2006-03-08 761947]
"ATICCC"="c:\program files\ATI Technologies\ATI.ACE\cli.exe" [2006-01-02 45056]
"Broadcom Wireless Manager UI"="c:\windows\system32\WLTRAY.exe" [2006-11-01 1392640]
"SigmatelSysTrayApp"="stsystra.exe" [2006-03-24 282624]
"vptray"="c:\program files\NavNT\vptray.exe" [2001-12-05 73728]
"NeroFilterCheck"="c:\windows\system32\NeroCheck.exe" [2001-07-09 155648]
"DVDLauncher"="c:\program files\CyberLink\PowerDVD\DVDLauncher.exe" [2004-10-12 57344]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-12 39792]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-03-09 148888]
"AtiPTA"="atiptaxx.exe" [2006-02-22 344064]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Picasa Media Detector"="c:\program files\Picasa2\PicasaMediaDetector.exe" [2008-02-26 443968]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-10-14 214360]
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Schwab\\Velocity Velocity\\lib\\jre\\bin\\java.exe"=
"c:\\Program Files\\ExamSoft\\SofTest\\SoftLnch.exe"= c:\\Program Files\\ExamSoft\\SoftLnch.exe
"c:\\Program Files\\ExamSoft\\SofTest\\softest.exe"= c:\\Program Files\\ExamSoft\\SofTest.exe
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqtra08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqste08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpofxm08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposfx08.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hposid01.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpqkygrp.exe"=
"c:\\Program Files\\HP\\Digital Imaging\\bin\\hpzwiz01.exe"=
"c:\\WINDOWS\\system32\\dpvsetup.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
"c:\\Documents and Settings\\Pozydaev\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.dll"=
"c:\\Documents and Settings\\Pozydaev\\Local Settings\\Application Data\\Google\\Google Talk Plugin\\googletalkplugin.exe"=
"c:\\Program Files\\Malwarebytes' Anti-Malware\\mbam.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3389:TCP"= 3389:TCP:@xpsp2res.dll,-22009
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
HPService REG_MULTI_SZ HPSLPSVC
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
.
Contents of the 'Scheduled Tasks' folder
2010-08-21 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003Core.job
- c:\documents and settings\Pozydaev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-12 18:35]
2010-08-23 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003UA.job
- c:\documents and settings\Pozydaev\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2010-03-12 18:35]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.netscape.com/
uDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: keyword.URL - hxxp://search.search-go.net/?sid=10101052100&s=
FF - plugin: c:\documents and settings\Pozydaev\Application Data\Mozilla\plugins\npgoogletalk.dll
FF - plugin: c:\documents and settings\Pozydaev\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll
FF - plugin: c:\documents and settings\Pozydaev\Local Settings\Application Data\Google\Update\1.2.183.29\npGoogleOneClick8.dll
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2010-08-25 17:25
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(880)
c:\windows\system32\Ati2evxx.dll
c:\windows\System32\BCMLogon.dll
c:\windows\system32\NavLogon.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\system32\Ati2evxx.exe
c:\windows\System32\WLTRYSVC.EXE
c:\windows\System32\bcmwltry.exe
c:\program files\NavNT\defwatch.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\NavNT\rtvscan.exe
c:\windows\system32\wdfmgr.exe
c:\windows\system32\Ati2evxx.exe
c:\program files\Canon\CAL\CALMAIN.exe
c:\windows\system32\MsgSys.EXE
c:\windows\stsystra.exe
c:\windows\system32\wbem\wmiapsrv.exe
c:\program files\HP\Digital Imaging\bin\hpqSTE08.exe
c:\program files\HP\Digital Imaging\bin\hpqbam08.exe
.
**************************************************************************
.
Completion time: 2010-08-25 17:29:07 - machine was rebooted
ComboFix-quarantined-files.txt 2010-08-25 21:29
ComboFix2.txt 2010-08-23 21:42
ComboFix3.txt 2010-08-22 20:51
Pre-Run: 131,548,758,016 bytes free
Post-Run: 131,557,990,400 bytes free
- - End Of File - - 4B1A6717C432933CF2D39D174209A985
And the OTL:
OTL logfile created on: 8/26/2010 3:19:42 PM - Run 4
OTL by OldTimer - Version 3.2.10.0 Folder = C:\Documents and Settings\Pozydaev\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,022.00 Mb Total Physical Memory | 473.00 Mb Available Physical Memory | 46.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 86.00% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 137.00 Gb Total Space | 122.43 Gb Free Space | 89.36% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 6.22 Gb Free Space | 62.18% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: P-LAPTOP
Current User Name: Pozydaev
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ========== PRC - [2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
PRC - [2010/07/20 16:30:10 | 011,660,648 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\SoftwareDistribution\Download\Install\NDP20SP2-KB983583-x86.exe
PRC - [2010/05/19 13:08:56 | 000,321,888 | ---- | M] (Microsoft Corporation) -- c:\3f07fb866953a584dae17b3f60a7ee07\HotFixInstaller.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2006/03/24 18:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2001/12/05 11:53:54 | 000,073,728 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\vptray.exe
PRC - [2001/12/05 11:45:38 | 000,471,040 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\rtvscan.exe
PRC - [2001/12/05 11:37:36 | 000,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\defwatch.exe
PRC - [2000/09/18 17:12:40 | 000,014,336 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\MSGSYS.EXE
========== Modules (SafeList) ========== MOD - [2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2001/12/05 11:45:38 | 000,471,040 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\NavNT\rtvscan.exe -- (Norton AntiVirus Server)
SRV - [2001/12/05 11:37:36 | 000,032,768 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\NavNT\defwatch.exe -- (DefWatch)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\s24trans.sys -- (s24trans)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/06 16:37:26 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2006/11/15 01:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/14 20:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/14 18:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/01 13:48:10 | 000,033,664 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\BCMWLNPF.SYS -- (BCMWLNPF)
DRV - [2006/10/12 16:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/05/03 12:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/03/24 18:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 13:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/12/01 02:40:56 | 000,936,960 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSX_DPV.sys -- (HSF_DPV)
DRV - [2005/12/01 02:40:12 | 000,192,512 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSXHWAZL.sys -- (HSXHWAZL)
DRV - [2005/12/01 02:40:08 | 000,669,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2005/08/05 12:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/07/14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2001/12/04 20:30:46 | 000,008,464 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\NavNT\Navapel.sys -- (NAVAPEL)
DRV - [2001/10/16 14:19:00 | 000,058,032 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.netscape.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0.6
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..keyword.URL: "
http://search.search...10101052100&s=" FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/11 19:06:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 21:11:24 | 000,000,000 | ---D | M]
[2008/09/03 08:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Extensions
[2010/08/13 12:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions
[2010/08/02 07:41:19 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/02 07:41:23 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/07/18 06:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\
[email protected][2008/06/20 07:49:56 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\searchplugins\wikipedia-en.xml
[2010/08/16 21:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/08/25 17:23:47 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1174008100046 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
http://acs.pandasoft...free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://activex.micro...jects/ocget.dll (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Pozydaev\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pozydaev\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/15 20:01:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.yv12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 90 Days ========== [2010/08/26 15:18:32 | 000,000,000 | ---D | C] -- C:\3f07fb866953a584dae17b3f60a7ee07
[2010/08/26 15:15:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/08/25 17:38:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/08/25 17:16:14 | 000,000,000 | ---D | C] -- C:\8be4beba3156b27715f28b0d
[2010/08/25 17:16:12 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/08/25 17:15:18 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2010/08/22 16:08:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/08/22 16:05:15 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/22 16:05:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/22 16:05:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/22 16:05:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/22 16:02:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/08/22 16:02:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/08/22 15:52:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/08/16 21:43:08 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2010/08/12 19:01:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/11 19:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/08/11 19:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/08/09 09:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Update
[2010/08/02 21:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/30 22:22:00 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2010/07/30 13:17:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/30 13:17:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/28 13:04:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/28 11:30:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[1996/11/18 01:00:00 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\Implode.dll
[16 C:\Documents and Settings\Pozydaev\My Documents\*.tmp files -> C:\Documents and Settings\Pozydaev\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/08/26 15:23:21 | 001,050,134 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/08/26 15:23:21 | 000,417,256 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/08/26 15:23:21 | 000,004,832 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/26 15:18:21 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/08/26 15:14:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/26 15:14:07 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/26 15:14:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/26 15:14:01 | 1072,103,424 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/25 21:13:26 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003UA.job
[2010/08/25 19:13:01 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003Core.job
[2010/08/25 17:23:58 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/25 17:23:47 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/25 17:22:33 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Pozydaev\ntuser.ini
[2010/08/25 17:22:32 | 004,194,304 | -H-- | M] () -- C:\Documents and Settings\Pozydaev\NTUSER.DAT
[2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2010/08/25 16:37:46 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.zip
[2010/08/22 16:08:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/08/22 16:04:04 | 003,820,698 | R--- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2010/08/12 13:47:53 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\The Art of Thank You Note Writing.doc
[2010/08/12 13:40:27 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\Microsoft Word.lnk
[2010/08/08 00:23:17 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/08/04 14:18:00 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2010/08/04 12:15:08 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\dds.scr
[2010/07/30 22:29:33 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2010/07/28 17:22:27 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/27 22:23:53 | 000,242,176 | ---- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\digi - carrollers.doc
[2010/07/27 22:23:53 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\~$gi - carrollers.doc
[2010/07/26 16:29:36 | 002,531,687 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\awhiholger.zip
[2010/07/20 21:26:41 | 000,025,088 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\Mary Jane Pozydaev Resume.doc
[2010/06/30 12:25:39 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\brunch invitation 2010.doc
[2010/06/16 16:20:56 | 000,013,824 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\budget.xls
[2010/06/15 11:02:45 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\AmericorpsStatement.doc
[2010/06/11 10:08:08 | 000,196,160 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[16 C:\Documents and Settings\Pozydaev\My Documents\*.tmp files -> C:\Documents and Settings\Pozydaev\My Documents\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/25 17:33:51 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.exe
[2010/08/25 17:15:20 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.zip
[2010/08/22 16:08:39 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/08/22 16:08:36 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/08/22 16:05:15 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/22 16:05:15 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/22 16:05:15 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/22 16:05:15 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/22 16:05:15 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/22 16:04:19 | 003,820,698 | R--- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2010/08/19 15:35:25 | 1072,103,424 | -HS- | C] () -- C:\hiberfil.sys
[2010/08/16 21:43:15 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\dds.scr
[2010/08/12 13:47:53 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\The Art of Thank You Note Writing.doc
[2010/07/28 13:04:50 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/27 22:23:53 | 000,242,176 | ---- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\digi - carrollers.doc
[2010/07/27 22:23:53 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\~$gi - carrollers.doc
[2010/07/26 16:29:14 | 002,531,687 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\awhiholger.zip
[2010/07/20 21:26:41 | 000,025,088 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\Mary Jane Pozydaev Resume.doc
[2010/06/30 08:23:42 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\brunch invitation 2010.doc
[2010/06/16 16:20:56 | 000,013,824 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\budget.xls
[2010/06/09 16:03:32 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\AmericorpsStatement.doc
[2010/02/24 21:14:36 | 000,000,176 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/06/20 12:07:19 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/04/06 16:37:27 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2008/01/20 19:12:53 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/07/29 05:02:01 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2007/03/16 22:33:04 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/16 18:04:57 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/03/15 23:09:49 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/03/15 21:53:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/03/15 21:47:09 | 000,000,592 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/03/15 21:43:35 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2007/03/15 21:43:34 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2007/03/15 21:28:30 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Local Settings\Application Data\fusioncache.dat
[2007/03/15 21:06:19 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007/02/23 00:29:56 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2006/12/12 12:24:42 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/31 16:00:35 | 000,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2005/08/10 11:56:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ESxUtil.dll
[2004/06/24 02:20:02 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\EAL32.INI
[2001/12/05 11:52:38 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2000/09/18 17:12:40 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\CSSMS_IN.DLL
[1996/11/18 01:00:00 | 000,748,160 | ---- | C] () -- C:\WINDOWS\System32\Co2c40en.dll
[1996/11/18 01:00:00 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\P2sodbc.dll
[1996/11/18 01:00:00 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\P2irdao.dll
[1996/11/18 01:00:00 | 000,050,176 | ---- | C] () -- C:\WINDOWS\System32\P2ctdao.dll
[1996/11/18 01:00:00 | 000,036,352 | ---- | C] () -- C:\WINDOWS\System32\P2bbnd.dll
[1996/05/25 17:00:00 | 000,107,008 | ---- | C] () -- C:\WINDOWS\System32\fxtls432.dll
========== LOP Check ========== [2008/07/31 14:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Examsoft
[2010/08/16 22:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Update
[2008/02/23 14:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Opera
[2007/03/20 13:02:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Thunderbird
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2007/03/15 20:01:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/03/15 21:17:46 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/08/22 16:08:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/08/25 17:29:07 | 000,009,416 | ---- | M] () -- C:\ComboFix.txt
[2007/03/15 20:01:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/08/26 15:14:01 | 1072,103,424 | -HS- | M] () -- C:\hiberfil.sys
[2007/03/15 20:01:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/03/15 20:01:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/10/10 21:55:08 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/26 15:14:00 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2007/03/15 21:48:10 | 000,003,395 | -H-- | M] () -- C:\_NavCClt.Log
< %systemroot%\Fonts\*.com >[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini >[2007/03/15 20:01:06 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* >[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/12/03 18:55:24 | 000,278,016 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav >[2007/03/15 14:20:05 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/03/15 14:20:05 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/03/15 14:20:05 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >[2008/07/31 12:17:11 | 000,000,000 | ---D | M] -- C:\Program Files\ExamSoft\SofTest\bak
< %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[2009/10/10 22:13:42 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x > < %systemroot%\*.config > < %systemroot%\system32\*.db > < %PROGRAMFILES%\Internet Explorer\*.dat > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[2009/10/11 09:59:18 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/03/15 21:01:31 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >[2010/08/22 16:04:04 | 003,820,698 | R--- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2009/12/15 11:24:48 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.exe
[2010/03/12 14:34:49 | 000,569,520 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\GoogleVoiceAndVideoSetup.exe
[2010/08/04 14:18:00 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2008/09/22 15:44:06 | 001,495,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Pozydaev\Desktop\install_flash_player(2).exe
[2008/09/22 15:38:30 | 001,495,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Pozydaev\Desktop\install_flash_player.exe
[2010/07/30 22:29:33 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2009/05/02 09:38:10 | 002,967,816 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup.exe
[2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2009/09/15 18:13:30 | 009,775,465 | ---- | M] (Digital Smoke ) -- C:\Documents and Settings\Pozydaev\Desktop\SolCity.exe
< %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src > < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 19:26:41
< End of report >
PRC - [2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
PRC - [2008/04/13 20:12:19 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) -- C:\Program Files\Canon\CAL\CALMAIN.exe
PRC - [2006/03/24 18:30:44 | 000,282,624 | ---- | M] (SigmaTel, Inc.) -- C:\WINDOWS\stsystra.exe
PRC - [2001/12/05 11:53:54 | 000,073,728 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\vptray.exe
PRC - [2001/12/05 11:45:38 | 000,471,040 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\rtvscan.exe
PRC - [2001/12/05 11:37:36 | 000,032,768 | ---- | M] (Symantec Corporation) -- C:\Program Files\NavNT\defwatch.exe
PRC - [2000/09/18 17:12:40 | 000,014,336 | ---- | M] (Intel Corporation) -- C:\WINDOWS\system32\MSGSYS.EXE
========== Modules (SafeList) ========== MOD - [2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
MOD - [2008/04/13 20:10:20 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ========== SRV - File not found [Disabled | Stopped] -- C:\WINDOWS\System32\hidserv.dll -- (HidServ)
SRV - [2007/01/31 15:55:42 | 000,096,370 | ---- | M] (Canon Inc.) [Auto | Running] -- C:\Program Files\Canon\CAL\CALMAIN.exe -- (CCALib8)
SRV - [2001/12/05 11:45:38 | 000,471,040 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\NavNT\rtvscan.exe -- (Norton AntiVirus Server)
SRV - [2001/12/05 11:37:36 | 000,032,768 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files\NavNT\defwatch.exe -- (DefWatch)
========== Driver Services (SafeList) ========== DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\DRIVERS\UIUSYS.SYS -- (UIUSys)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\WINDOWS\System32\DRIVERS\s24trans.sys -- (s24trans)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2008/04/13 12:36:05 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/04/06 16:37:26 | 000,047,616 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\Haspnt.sys -- (Haspnt)
DRV - [2006/11/15 01:16:24 | 000,032,256 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimmptsk.sys -- (rimmptsk)
DRV - [2006/11/14 20:42:46 | 000,043,520 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rimsptsk.sys -- (rimsptsk)
DRV - [2006/11/14 18:35:20 | 000,037,376 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rixdptsk.sys -- (rismxdp)
DRV - [2006/11/01 13:48:10 | 000,033,664 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\BCMWLNPF.SYS -- (BCMWLNPF)
DRV - [2006/10/12 16:28:42 | 000,604,928 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\BCMWL5.SYS -- (BCM43XX)
DRV - [2006/05/03 12:50:42 | 001,540,608 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2006/03/24 18:34:30 | 001,156,648 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2006/03/08 13:35:10 | 000,191,872 | ---- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SynTP.sys -- (SynTP)
DRV - [2005/12/01 02:40:56 | 000,936,960 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSX_DPV.sys -- (HSF_DPV)
DRV - [2005/12/01 02:40:12 | 000,192,512 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSXHWAZL.sys -- (HSXHWAZL)
DRV - [2005/12/01 02:40:08 | 000,669,696 | ---- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\HSX_CNXT.sys -- (winachsf)
DRV - [2005/08/05 12:32:16 | 000,045,312 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\bcm4sbxp.sys -- (bcm4sbxp)
DRV - [2004/07/14 12:54:42 | 000,676,864 | ---- | M] (Aladdin Knowledge Systems) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\hardlock.sys -- (Hardlock)
DRV - [2001/12/04 20:30:46 | 000,008,464 | ---- | M] () [Kernel | Auto | Running] -- C:\Program Files\NavNT\Navapel.sys -- (NAVAPEL)
DRV - [2001/10/16 14:19:00 | 000,058,032 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Stopped] -- C:\Program Files\Symantec\SYMEVENT.SYS -- (SymEvent)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.netscape.com/IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF - prefs.js..browser.search.order.1: "Google"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2.1
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0.6
FF - prefs.js..extensions.enabledItems:
[email protected]:1.0
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:2.1.3.20100310105313
FF - prefs.js..keyword.URL: "
http://search.search...10101052100&s=" FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/08/11 19:06:54 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.0.19\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 21:11:24 | 000,000,000 | ---D | M]
[2008/09/03 08:12:05 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Extensions
[2010/08/13 12:44:57 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions
[2010/08/02 07:41:19 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/08/02 07:41:23 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2009/07/18 06:52:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\extensions\
[email protected][2008/06/20 07:49:56 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Mozilla\Firefox\Profiles\6qizzd76.default\searchplugins\wikipedia-en.xml
[2010/08/16 21:57:15 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/08/25 17:23:47 | 000,000,027 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: () - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [ATICCC] C:\Program Files\ATI Technologies\ATI.ACE\cli.exe (ATI Technologies Inc.)
O4 - HKLM..\Run: [AtiPTA] C:\WINDOWS\System32\atiptaxx.exe (ATI Technologies, Inc.)
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\WINDOWS\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\Run: [vptray] C:\Program Files\NavNT\vptray.exe (Symantec Corporation)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
http://update.micros...b?1174008100046 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1}
http://acs.pandasoft...free/asinst.cab (ActiveScan Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://activex.micro...jects/ocget.dll (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.11.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\NavLogon: DllName - C:\WINDOWS\system32\NavLogon.dll - C:\WINDOWS\system32\NavLogon.dll ()
O24 - Desktop WallPaper: C:\Documents and Settings\Pozydaev\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Pozydaev\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/03/15 20:01:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 90 Days ========== [2010/08/26 15:15:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\LastGood
[2010/08/25 17:38:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2010/08/25 17:16:14 | 000,000,000 | ---D | C] -- C:\8be4beba3156b27715f28b0d
[2010/08/25 17:16:12 | 000,000,000 | ---D | C] -- C:\ComboFix
[2010/08/25 17:15:18 | 000,575,488 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2010/08/22 16:44:07 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\proquota.exe
[2010/08/22 16:44:07 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\proquota.exe
[2010/08/22 16:08:33 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2010/08/22 16:05:15 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2010/08/22 16:05:15 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2010/08/22 16:05:15 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2010/08/22 16:05:15 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2010/08/22 16:02:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2010/08/22 16:02:05 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/08/22 15:52:50 | 000,000,000 | ---D | C] -- C:\_OTL
[2010/08/16 21:43:08 | 000,388,608 | ---- | C] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2010/08/12 19:01:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/08/11 19:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla
[2010/08/11 19:06:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Mozilla
[2010/08/09 09:34:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Update
[2010/08/02 21:15:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/07/30 22:22:00 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2010/07/30 13:17:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/07/30 13:17:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010/07/28 13:04:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/07/28 11:30:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[1996/11/18 01:00:00 | 000,018,944 | ---- | C] ( ) -- C:\WINDOWS\System32\Implode.dll
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[16 C:\Documents and Settings\Pozydaev\My Documents\*.tmp files -> C:\Documents and Settings\Pozydaev\My Documents\*.tmp -> ]
========== Files - Modified Within 90 Days ========== [2010/08/26 15:25:52 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/08/26 15:23:21 | 001,050,134 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/08/26 15:23:21 | 000,417,256 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/08/26 15:23:21 | 000,004,832 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/08/26 15:14:09 | 000,013,646 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/08/26 15:14:07 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/08/26 15:14:05 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/08/26 15:14:01 | 1072,103,424 | -HS- | M] () -- C:\hiberfil.sys
[2010/08/25 21:13:26 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003UA.job
[2010/08/25 19:13:01 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-790525478-1220945662-725345543-1003Core.job
[2010/08/25 17:23:58 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/08/25 17:23:47 | 000,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts
[2010/08/25 17:22:33 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Pozydaev\ntuser.ini
[2010/08/25 17:22:32 | 004,194,304 | -H-- | M] () -- C:\Documents and Settings\Pozydaev\NTUSER.DAT
[2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2010/08/25 16:37:46 | 000,284,915 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.zip
[2010/08/22 16:08:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/08/22 16:04:04 | 003,820,698 | R--- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2010/08/12 13:47:53 | 000,027,136 | ---- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\The Art of Thank You Note Writing.doc
[2010/08/12 13:40:27 | 000,002,483 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\Microsoft Word.lnk
[2010/08/08 00:23:17 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/08/04 14:18:00 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2010/08/04 12:15:08 | 000,525,824 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\dds.scr
[2010/07/30 22:29:33 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2010/07/28 17:22:27 | 000,000,116 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/07/27 22:23:53 | 000,242,176 | ---- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\digi - carrollers.doc
[2010/07/27 22:23:53 | 000,000,162 | -H-- | M] () -- C:\Documents and Settings\Pozydaev\My Documents\~$gi - carrollers.doc
[6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[16 C:\Documents and Settings\Pozydaev\My Documents\*.tmp files -> C:\Documents and Settings\Pozydaev\My Documents\*.tmp -> ]
========== Files Created - No Company Name ========== [2010/08/25 17:33:51 | 000,293,376 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.exe
[2010/08/25 17:15:20 | 000,284,915 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.zip
[2010/08/22 16:08:39 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2010/08/22 16:08:36 | 000,260,272 | ---- | C] () -- C:\cmldr
[2010/08/22 16:05:15 | 000,256,512 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2010/08/22 16:05:15 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2010/08/22 16:05:15 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2010/08/22 16:05:15 | 000,077,312 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2010/08/22 16:05:15 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2010/08/22 16:04:19 | 003,820,698 | R--- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2010/08/19 15:35:25 | 1072,103,424 | -HS- | C] () -- C:\hiberfil.sys
[2010/08/16 21:43:15 | 000,525,824 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Desktop\dds.scr
[2010/08/12 13:47:53 | 000,027,136 | ---- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\The Art of Thank You Note Writing.doc
[2010/07/28 13:04:50 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/07/27 22:23:53 | 000,242,176 | ---- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\digi - carrollers.doc
[2010/07/27 22:23:53 | 000,000,162 | -H-- | C] () -- C:\Documents and Settings\Pozydaev\My Documents\~$gi - carrollers.doc
[2010/02/24 21:14:36 | 000,000,176 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2009/06/20 12:07:19 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2008/04/06 16:37:27 | 000,000,383 | ---- | C] () -- C:\WINDOWS\System32\haspdos.sys
[2008/01/20 19:12:53 | 000,000,032 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/07/29 05:02:01 | 000,011,776 | ---- | C] () -- C:\WINDOWS\System32\ZPORT4AS.dll
[2007/03/16 22:33:04 | 000,013,312 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/03/16 18:04:57 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2007/03/15 23:09:49 | 000,014,848 | ---- | C] () -- C:\WINDOWS\System32\BASSMOD.dll
[2007/03/15 21:53:03 | 000,000,000 | ---- | C] () -- C:\WINDOWS\VPC32.INI
[2007/03/15 21:47:09 | 000,000,592 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/03/15 21:43:35 | 000,086,016 | ---- | C] () -- C:\WINDOWS\System32\preflib.dll
[2007/03/15 21:43:34 | 000,757,760 | ---- | C] () -- C:\WINDOWS\System32\bcm1xsup.dll
[2007/03/15 21:28:30 | 000,000,131 | ---- | C] () -- C:\Documents and Settings\Pozydaev\Local Settings\Application Data\fusioncache.dat
[2007/03/15 21:06:19 | 000,016,480 | ---- | C] () -- C:\WINDOWS\System32\rixdicon.dll
[2007/02/23 00:29:56 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2006/12/12 12:24:42 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/31 16:00:35 | 000,000,011 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.ini
[2005/08/10 11:56:00 | 000,028,672 | ---- | C] () -- C:\WINDOWS\System32\ESxUtil.dll
[2004/06/24 02:20:02 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\EAL32.INI
[2001/12/05 11:52:38 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\NavLogon.dll
[2000/09/18 17:12:40 | 000,023,040 | ---- | C] () -- C:\WINDOWS\System32\CSSMS_IN.DLL
[1996/11/18 01:00:00 | 000,748,160 | ---- | C] () -- C:\WINDOWS\System32\Co2c40en.dll
[1996/11/18 01:00:00 | 000,131,072 | ---- | C] () -- C:\WINDOWS\System32\P2sodbc.dll
[1996/11/18 01:00:00 | 000,054,272 | ---- | C] () -- C:\WINDOWS\System32\P2irdao.dll
[1996/11/18 01:00:00 | 000,050,176 | ---- | C] () -- C:\WINDOWS\System32\P2ctdao.dll
[1996/11/18 01:00:00 | 000,036,352 | ---- | C] () -- C:\WINDOWS\System32\P2bbnd.dll
[1996/05/25 17:00:00 | 000,107,008 | ---- | C] () -- C:\WINDOWS\System32\fxtls432.dll
========== LOP Check ========== [2008/07/31 14:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Examsoft
[2010/08/16 22:56:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Update
[2008/02/23 14:43:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Opera
[2007/03/20 13:02:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Pozydaev\Application Data\Thunderbird
========== Purity Check ========== ========== Custom Scans ========== < %SYSTEMDRIVE%\*.* >[2007/03/15 20:01:33 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2007/03/15 21:17:46 | 000,000,211 | ---- | M] () -- C:\Boot.bak
[2010/08/22 16:08:40 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | ---- | M] () -- C:\cmldr
[2010/08/25 17:29:07 | 000,009,416 | ---- | M] () -- C:\ComboFix.txt
[2007/03/15 20:01:33 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2010/08/26 15:14:01 | 1072,103,424 | -HS- | M] () -- C:\hiberfil.sys
[2007/03/15 20:01:33 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2007/03/15 20:01:33 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2004/08/04 08:00:00 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2009/10/10 21:55:08 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/08/26 15:14:00 | 1610,612,736 | -HS- | M] () -- C:\pagefile.sys
[2007/03/15 21:48:10 | 000,003,395 | -H-- | M] () -- C:\_NavCClt.Log
< %systemroot%\Fonts\*.com >[2006/04/18 16:39:28 | 000,026,040 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 15:53:56 | 000,026,489 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 16:39:28 | 000,029,779 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006/06/29 15:58:52 | 000,030,808 | ---- | M] () -- C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll > < %systemroot%\Fonts\*.ini >[2007/03/15 20:01:06 | 000,000,067 | -HS- | M] () -- C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 > < %systemroot%\Fonts\*.exe > < %systemroot%\system32\spool\prtprocs\w32x86\*.* >[2008/07/06 08:06:10 | 000,089,088 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007/12/03 18:55:24 | 000,278,016 | ---- | M] (Hewlett-Packard Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\hpzpp5mu.dll
[2008/07/06 06:50:03 | 000,597,504 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 > < %systemroot%\REPAIR\*.ini > < %systemroot%\system32\*.jpg > < %systemroot%\*.jpg > < %systemroot%\*.png > < %systemroot%\*.scr > < %systemroot%\*._sy > < %APPDATA%\Adobe\Update\*.* > < %ALLUSERSPROFILE%\Favorites\*.* > < %APPDATA%\Microsoft\*.* > < %PROGRAMFILES%\*.* > < %APPDATA%\Update\*.* > < %systemroot%\*. /mp /s > < %systemroot%\System32\config\*.sav >[2007/03/15 14:20:05 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/03/15 14:20:05 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/03/15 14:20:05 | 000,897,024 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >[2008/07/31 12:17:11 | 000,000,000 | ---D | M] -- C:\Program Files\ExamSoft\SofTest\bak
< %systemroot%\system32\bak. /s > < %ALLUSERSPROFILE%\Start Menu\*.lnk /x >[2009/10/10 22:13:42 | 000,000,272 | -HS- | M] () -- C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x > < %systemroot%\*.config > < %systemroot%\system32\*.db > < %PROGRAMFILES%\Internet Explorer\*.dat > < %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >[2009/10/11 09:59:18 | 000,000,119 | -HS- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/03/15 21:01:31 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >[2010/08/22 16:04:04 | 003,820,698 | R--- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\ComboFix.exe
[2009/12/15 11:24:48 | 000,293,376 | ---- | M] () -- C:\Documents and Settings\Pozydaev\Desktop\gmer.exe
[2010/03/12 14:34:49 | 000,569,520 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\GoogleVoiceAndVideoSetup.exe
[2010/08/04 14:18:00 | 000,388,608 | ---- | M] (Trend Micro Inc.) -- C:\Documents and Settings\Pozydaev\Desktop\HijackThis.exe
[2008/09/22 15:44:06 | 001,495,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Pozydaev\Desktop\install_flash_player(2).exe
[2008/09/22 15:38:30 | 001,495,112 | ---- | M] (Adobe Systems Incorporated) -- C:\Documents and Settings\Pozydaev\Desktop\install_flash_player.exe
[2010/07/30 22:29:33 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup-1.46.exe
[2009/05/02 09:38:10 | 002,967,816 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\Pozydaev\Desktop\mbam-setup.exe
[2010/08/25 16:37:56 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Pozydaev\Desktop\OTL.exe
[2009/09/15 18:13:30 | 009,775,465 | ---- | M] (Digital Smoke ) -- C:\Documents and Settings\Pozydaev\Desktop\SolCity.exe
< %PROGRAMFILES%\Common Files\*.* > < %systemroot%\*.src > < %systemroot%\install\*.* > < %systemroot%\system32\DLL\*.* > < %systemroot%\system32\HelpFiles\*.* > < %systemroot%\system32\rundll\*.* > < %systemroot%\winn32\*.* > < %systemroot%\Java\*.* > < %systemroot%\system32\test\*.* > < %systemroot%\system32\Rundll32\*.* > < %systemroot%\AppPatch\Custom\*.* > < HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU > < HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-08-26 19:26:41
< End of report >