So I came across this web site, and after caching it on google I was able to view the content of the web site.
I've learned a few things already, I just don't know what to do about the information I've recieved, for example I've run the GMER rootkit program, and here is the log that I received from that:
Rootkit scan 2011-01-18 19:15:41
Windows 5.1.2600 Service Pack 3 Harddisk0\DR0 -> \Device\Ide\IdePort3 WDC_WD800AAJS-00PSA0 rev.05.06H05
Running: r7qy192j.exe; Driver: C:\DOCUME~1\Computer\LOCALS~1\Temp\pxtdqpow.sys
---- Kernel code sections - GMER 1.0.15 ----
.text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB74A7360, 0x3CDCE5, 0xE8000020]
.rsrc C:\WINDOWS\system32\DRIVERS\termdd.sys entry point in ".rsrc" section [0xB81A1214]
---- Devices - GMER 1.0.15 ----
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort0 8AC46AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort1 8AC46AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T0L0-4 8AC46AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort2 8AC46AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdePort3 8AC46AEA
Device \Driver\atapi -> DriverStartIo \Device\Ide\IdeDeviceP0T1L0-c 8AC46AEA
Device \Device\Ide\IdeDeviceP3T1L0-19 -> \??\IDE#DiskWDC_WD800AAJS-00PSA0____________________05.06H05#5&fc9f62&0&0.1.0#{53f56307-b6bf-11d0-94f2-00a0c91efb8b} device not found
---- Disk sectors - GMER 1.0.15 ----
Disk \Device\Harddisk0\DR0 sectors 156301232 (+254): rootkit-like behavior;
---- Files - GMER 1.0.15 ----
File C:\WINDOWS\system32\DRIVERS\termdd.sys suspicious modification; TDL3 <-- ROOTKIT !!!
---- EOF - GMER 1.0.15 ----
And it's nothing like the Logs I've seen on this web site so far.
Then I ran OTL, and got this log file:
OTL logfile created on: 1/18/2011 7:45:51 PM - Run 1
OTL by OldTimer - Version Folder = C:\Documents and Settings\Computer\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 84.00% Memory free
4.00 Gb Paging File | 4.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 1344 2688 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 1.79 Gb Free Space | 2.41% Space Free | Partition Type: NTFS
Computer Name: B | User Name: Computer | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/01/18 19:45:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Computer\My Documents\Downloads\OTL.exe
PRC - [2010/12/20 16:10:44 | 000,912,344 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2010/04/19 15:35:21 | 000,202,256 | ---- | M] (RealNetworks, Inc.) -- C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PRC - [2010/04/12 17:46:36 | 001,135,912 | ---- | M] () -- C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/03/19 09:49:20 | 000,144,672 | ---- | M] (Apple Inc.) -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2008/04/14 05:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (SafeList) ==========
MOD - [2011/01/18 19:45:38 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Computer\My Documents\Downloads\OTL.exe
MOD - [2010/04/19 15:36:12 | 000,040,960 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Chrome\Hook\rpchromebrowserrecordhelper.dll
MOD - [2008/04/14 05:42:02 | 001,384,479 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msvbvm60.dll
MOD - [2008/04/14 05:41:56 | 000,094,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\iphlpapi.dll
MOD - [2008/04/14 05:41:54 | 000,158,720 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\dinput.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Auto | Stopped] -- -- (wuauserv)
SRV - [2010/03/19 09:49:20 | 000,144,672 | ---- | M] (Apple Inc.) [Auto | Running] -- C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe -- (Apple Mobile Device)
========== Driver Services (SafeList) ==========
DRV - [2010/05/10 13:41:30 | 000,067,656 | ---- | M] ( and [Kernel | System | Running] -- C:\Documents and Settings\Computer\Local Settings\Temp\SAS_SelfExtract\saskutil.sys -- (SASKUTIL)
DRV - [2010/02/17 13:25:48 | 000,012,872 | ---- | M] ( and [Kernel | System | Running] -- C:\Documents and Settings\Computer\Local Settings\Temp\SAS_SelfExtract\sasdifsv.sys -- (SASDIFSV)
DRV - [2009/07/08 09:07:00 | 007,967,712 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2008/09/11 10:52:58 | 000,088,064 | ---- | M] (Novation Digital Music Systems Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nvnnio.sys -- (nvnnio)
DRV - [2008/04/17 09:33:26 | 004,707,328 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/04/13 23:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 22:06:06 | 000,144,384 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2007/03/06 07:27:32 | 000,019,968 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nvnetbus.sys -- (nvnetbus)
DRV - [2007/03/06 07:27:28 | 000,058,752 | R--- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NVENETFD.sys -- (NVENETFD)
DRV - [2001/07/13 12:56:14 | 000,014,976 | ---- | M] () [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\SBKUPNT.SYS -- (SBKUPNT)
DRV - [2001/04/13 18:18:24 | 000,188,276 | ---- | M] (Roland) [Kernel | Auto | Running] -- C:\Program Files\Roland\Virtual Sound Canvas VST\RVIEg01VST.sys -- (RVIEGVST)
DRV - [2001/04/13 18:16:38 | 000,187,992 | ---- | M] (Roland) [Kernel | Auto | Running] -- C:\Program Files\Roland\Virtual Sound Canvas DXi\RVIEg01.sys -- (RVIEG01)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [email protected]:1.0
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.3
FF - prefs.js..extensions.enabledItems: {7E797E4F-1642-44D9-A1D0-698952FED61D}:1.9.1
FF - HKLM\software\mozilla\Firefox\extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/04/19 15:36:13 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Firefox\extensions\\{7E797E4F-1642-44D9-A1D0-698952FED61D}: C:\Documents and Settings\Computer\Local Settings\Application Data\{7E797E4F-1642-44D9-A1D0-698952FED61D} [2010/12/21 18:46:40 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/12/30 23:56:21 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/12/20 16:10:49 | 000,000,000 | ---D | M]
[2009/10/28 14:50:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Application Data\Mozilla\Extensions
[2011/01/18 15:53:00 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Computer\Application Data\Mozilla\Firefox\Profiles\ecxhcidf.default\extensions
[2010/04/29 22:08:47 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Computer\Application Data\Mozilla\Firefox\Profiles\ecxhcidf.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011/01/08 19:14:16 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/12/21 18:46:40 | 000,000,000 | ---D | M] (XULRunner) -- C:\DOCUMENTS AND SETTINGS\COMPUTER\LOCAL SETTINGS\APPLICATION DATA\{7E797E4F-1642-44D9-A1D0-698952FED61D}
[2009/10/28 14:12:20 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
O1 HOSTS File: ([2004/08/04 07:00:00 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: localhost
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Application Data\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [AppleSyncNotifier] C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe (Apple Inc.)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [*parsecertcsc.exe] C:\Documents and Settings\LocalService\Application Data\parsecertcsc.exe (It Systems)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.6.0_16)
O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} (Java Plug-in 1.6.0_16)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer =
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Computer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Computer\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/10/28 13:16:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{1caec205-edc4-11de-9ab2-001e90dff2cd}\Shell\AutoRun\command - "" = F:\rcaeasyrip_setup.exe
O33 - MountPoints2\{1caec205-edc4-11de-9ab2-001e90dff2cd}\Shell\install\command - "" = F:\rcaeasyrip_setup.exe
O33 - MountPoints2\{1caec205-edc4-11de-9ab2-001e90dff2cd}\Shell\usermanualEnglish\command - "" = F:\rcaeasyrip_setup.exe /pdf_English
O33 - MountPoints2\{1caec205-edc4-11de-9ab2-001e90dff2cd}\Shell\usermanualFrench\command - "" = F:\rcaeasyrip_setup.exe /pdf_French
O33 - MountPoints2\{1caec205-edc4-11de-9ab2-001e90dff2cd}\Shell\usermanualSpanish\command - "" = F:\rcaeasyrip_setup.exe /pdf_Spanish
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\ [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/18 18:44:21 | 000,148,480 | ---- | C] (It Systems) -- C:\Documents and Settings\LocalService\Application Data\parsecertcsc.exe
[2011/01/18 17:23:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Application Data\
[2011/01/18 17:23:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\
[2011/01/18 17:16:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\New Folder
[2011/01/18 16:39:03 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/01/18 16:39:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/01/18 16:39:00 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/01/18 16:39:00 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware2
[2011/01/18 16:27:40 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2
[2011/01/18 16:16:38 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2011/01/18 16:16:34 | 000,014,592 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2011/01/18 15:53:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Motive
[2011/01/18 15:50:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt
[2011/01/18 15:39:32 | 000,012,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mouhid.sys
[2011/01/18 15:10:46 | 000,000,000 | -HSD | C] -- C:\WINDOWS\CSC
[2010/12/21 20:05:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Start Menu\Programs\Disk Repair
[2010/12/21 18:49:29 | 000,000,000 | ---D | C] -- C:\Program Files\SweetIM
[2010/12/21 18:49:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SweetIM
[2010/12/21 18:46:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Start Menu\Programs\Antimalware Doctor
[2010/12/21 18:46:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Computer\Local Settings\Application Data\{7E797E4F-1642-44D9-A1D0-698952FED61D}
[2010/12/21 18:44:06 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Documents\Server
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/18 19:48:00 | 000,000,890 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/01/18 19:26:20 | 000,236,466 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml
[2011/01/18 19:26:13 | 000,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/01/18 19:26:06 | 000,000,886 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/01/18 19:26:06 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1960408961-725345543-1003.job
[2011/01/18 19:25:55 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/01/18 18:44:22 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2011/01/18 18:05:34 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011/01/18 18:02:51 | 000,000,791 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/01/18 17:00:31 | 000,000,292 | ---- | M] () -- C:\WINDOWS\tasks\RealUpgradeScheduledTaskS-1-5-21-527237240-1960408961-725345543-1003.job
[2011/01/08 19:38:48 | 000,000,255 | ---- | M] () -- C:\WINDOWS\lsrslt.ini
[2011/01/08 19:07:48 | 000,441,124 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/01/08 19:07:47 | 000,071,060 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/01/08 19:03:46 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Afiqubovis.bin
[2011/01/08 19:03:42 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Ohudahukur.dat
[2010/12/31 00:14:48 | 000,130,048 | ---- | M] () -- C:\Documents and Settings\Computer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/12/21 20:05:56 | 000,000,818 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\Disk Repair.lnk
[2010/12/21 20:05:48 | 000,000,336 | ---- | M] () -- C:\Documents and Settings\All Users\Application Data\NDTEIYvj8tQ
[2010/12/21 18:49:41 | 000,001,122 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\Press to smile.lnk
[2010/12/21 18:49:40 | 000,001,152 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\FREE MUSIC.lnk
[2010/12/21 18:46:51 | 000,001,174 | ---- | M] () -- C:\Documents and Settings\Computer\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk
[2010/12/21 18:46:49 | 000,001,196 | ---- | M] () -- C:\Documents and Settings\Computer\Desktop\Antimalware Doctor.lnk
[2010/12/20 18:09:00 | 000,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/12/20 18:08:40 | 000,020,952 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[5 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/18 16:39:46 | 000,000,284 | ---- | C] () -- C:\WINDOWS\tasks\RealUpgradeLogonTaskS-1-5-21-527237240-1960408961-725345543-1003.job
[2011/01/18 16:39:03 | 000,000,791 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/12/30 23:58:11 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/12/21 20:07:31 | 000,000,255 | ---- | C] () -- C:\WINDOWS\lsrslt.ini
[2010/12/21 20:05:56 | 000,000,818 | ---- | C] () -- C:\Documents and Settings\Computer\Desktop\Disk Repair.lnk
[2010/12/21 20:05:48 | 000,000,336 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\NDTEIYvj8tQ
[2010/12/21 18:48:04 | 000,001,122 | ---- | C] () -- C:\Documents and Settings\Computer\Desktop\Press to smile.lnk
[2010/12/21 18:48:03 | 000,001,152 | ---- | C] () -- C:\Documents and Settings\Computer\Desktop\FREE MUSIC.lnk
[2010/12/21 18:46:51 | 000,001,174 | ---- | C] () -- C:\Documents and Settings\Computer\Application Data\Microsoft\Internet Explorer\Quick Launch\Antimalware Doctor.lnk
[2010/12/21 18:46:46 | 000,001,196 | ---- | C] () -- C:\Documents and Settings\Computer\Desktop\Antimalware Doctor.lnk
[2010/12/21 18:46:43 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Afiqubovis.bin
[2010/12/21 18:46:42 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Ohudahukur.dat
[2010/09/03 11:22:54 | 000,025,600 | ---- | C] () -- C:\WINDOWS\System32\AVSredirect.dll
[2010/07/23 18:04:04 | 000,000,077 | ---- | C] () -- C:\WINDOWS\BBW_INFO.INI
[2010/05/25 22:50:23 | 000,014,976 | ---- | C] () -- C:\WINDOWS\System32\drivers\SBKUPNT.SYS
[2010/04/17 21:34:59 | 000,000,088 | RHS- | C] () -- C:\Documents and Settings\All Users\Application Data\7FA21157EA.sys
[2010/04/17 21:34:58 | 000,001,682 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\KGyGaAvL.sys
[2010/03/14 22:54:24 | 000,354,816 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2009/11/04 11:58:41 | 000,217,088 | ---- | C] () -- C:\WINDOWS\System32\avformat-50.dll
[2009/11/04 11:58:41 | 000,018,432 | ---- | C] () -- C:\WINDOWS\System32\avutil-49.dll
[2009/11/04 11:58:40 | 001,984,512 | ---- | C] () -- C:\WINDOWS\System32\avcodec-51.dll
[2009/10/28 19:45:44 | 000,130,048 | ---- | C] () -- C:\Documents and Settings\Computer\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/10/28 14:11:48 | 000,168,448 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2009/10/28 14:11:45 | 003,596,288 | ---- | C] () -- C:\WINDOWS\System32\qt-dx331.dll
[2009/10/28 14:11:45 | 000,795,648 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/10/28 14:11:45 | 000,130,048 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/10/28 14:11:43 | 000,057,344 | ---- | C] () -- C:\WINDOWS\System32\ff_vfw.dll
[2009/10/28 14:08:58 | 000,286,720 | R--- | C] () -- C:\WINDOWS\System32\nvnt4cpl.dll
[2009/10/28 08:05:20 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2009/07/08 10:58:18 | 001,724,416 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2009/07/08 10:58:18 | 001,507,328 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2009/07/08 10:58:18 | 001,101,824 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2009/07/08 10:58:18 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
========== Alternate Data Streams ==========
@Alternate Data Stream - 132 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:3AEA6AF9
< End of report >
Which a little bit looks off, but I'm not fully sure what I'm looking for in that log, and not sure exactly what my next steps would be, any help would be greatly appreciated