Hi sempei and thanks for the assistance!
Quote
The computer is still infected. Can you please tell me the things that you did or tools that you have run, if any.
I do not remember everything I did as much of it seemed to be troubleshooting. I do know that TDSKiller was ran after troubleshooting and Malwarebytes was ran twice after that, once in safe mode and once in normal mode.
Also, because I have no connection on the infected computer, I've been using a laptop and jumpdrive to move tools back and forth to run. As per your instructions, I am now running TDSKiller and OTL after re-downloading and moving to the desktop. I don't know if it's possible for me to infect my laptop via the jumpdrive, so any insight you have on that would be much appreciated.
The newest TDSKiller log is below. OTL caused a Windows prompt titled "Windows - No Disk" with the message "Exception Processing Message c0000013 Parameters 75b6bf9c 4 75b6bf9c 75b6bf9c" with the option to Cancel, Try Again, or Continue. At first, all three buttons simply caused the prompt to reappear, but after about 2 minutes I hit Continue and it worked.
If I'm typing too much, forgive me, this is my first time doing this sort of thing on a forum and I don't want to frustrate you with too much or too little information!
10:57:16.0093 1436 TDSS rootkit removing tool 2.6.9.0 Oct 14 2011 11:33:24
10:57:16.0109 1436 ============================================================
10:57:16.0109 1436 Current date / time: 2011/10/15 10:57:16.0109
10:57:16.0109 1436 SystemInfo:
10:57:16.0109 1436
10:57:16.0109 1436 OS Version: 5.1.2600 ServicePack: 2.0
10:57:16.0109 1436 Product type: Workstation
10:57:16.0109 1436 ComputerName: PICKLE
10:57:16.0109 1436 UserName: Owner
10:57:16.0109 1436 Windows directory: C:\WINDOWS
10:57:16.0109 1436 System windows directory: C:\WINDOWS
10:57:16.0109 1436 Processor architecture: Intel x86
10:57:16.0109 1436 Number of processors: 2
10:57:16.0109 1436 Page size: 0x1000
10:57:16.0109 1436 Boot type: Normal boot
10:57:16.0109 1436 ============================================================
10:57:17.0671 1436 Initialize success
10:57:51.0500 0776 ============================================================
10:57:51.0500 0776 Scan started
10:57:51.0500 0776 Mode: Manual;
10:57:51.0500 0776 ============================================================
10:57:51.0859 0776 Abiosdsk - ok
10:57:51.0953 0776 abp480n5 - ok
10:57:52.0046 0776 ACPI (a10c7534f7223f4a73a948967d00e69b) C:\WINDOWS\system32\DRIVERS\ACPI.sys
10:57:52.0062 0776 ACPI - ok
10:57:52.0171 0776 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
10:57:52.0171 0776 ACPIEC - ok
10:57:52.0265 0776 adpu160m - ok
10:57:52.0390 0776 aec (1ee7b434ba961ef845de136224c30fec) C:\WINDOWS\system32\drivers\aec.sys
10:57:52.0406 0776 aec - ok
10:57:52.0515 0776 AegisP (023867b6606fbabcdd52e089c4a507da) C:\WINDOWS\system32\DRIVERS\AegisP.sys
10:57:52.0515 0776 AegisP - ok
10:57:52.0625 0776 Afc (a7b8a3a79d35215d798a300df49ed23f) C:\WINDOWS\system32\drivers\Afc.sys
10:57:52.0640 0776 Afc - ok
10:57:52.0750 0776 agp440 (2c428fa0c3e3a01ed93c9b2a27d8d4bb) C:\WINDOWS\system32\DRIVERS\agp440.sys
10:57:52.0750 0776 agp440 - ok
10:57:52.0828 0776 Aha154x - ok
10:57:52.0906 0776 aic78u2 - ok
10:57:52.0984 0776 aic78xx - ok
10:57:53.0125 0776 ALCXSENS (fbbcb95f677cbaa924140b6ea2d9a97b) C:\WINDOWS\system32\drivers\ALCXSENS.SYS
10:57:53.0187 0776 ALCXSENS - ok
10:57:53.0390 0776 ALCXWDM (8d6c30e515717248e0e52b85fd7ac466) C:\WINDOWS\system32\drivers\ALCXWDM.SYS
10:57:53.0453 0776 ALCXWDM - ok
10:57:53.0546 0776 AliIde - ok
10:57:53.0656 0776 AmdK7 (680ad1c1bb16239e28d8f33a54a7a3c7) C:\WINDOWS\system32\DRIVERS\amdk7.sys
10:57:53.0671 0776 AmdK7 - ok
10:57:53.0750 0776 amsint - ok
10:57:53.0843 0776 Arp1394 (f0d692b0bffb46e30eb3cea168bbc49f) C:\WINDOWS\system32\DRIVERS\arp1394.sys
10:57:53.0859 0776 Arp1394 - ok
10:57:53.0937 0776 asc - ok
10:57:54.0015 0776 asc3350p - ok
10:57:54.0093 0776 asc3550 - ok
10:57:54.0218 0776 AsyncMac (02000abf34af4c218c35d257024807d6) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
10:57:54.0234 0776 AsyncMac - ok
10:57:54.0343 0776 atapi (cdfe4411a69c224bd1d11b2da92dac51) C:\WINDOWS\system32\DRIVERS\atapi.sys
10:57:54.0343 0776 atapi - ok
10:57:54.0421 0776 Atdisk - ok
10:57:54.0546 0776 Atmarpc (ec88da854ab7d7752ec8be11a741bb7f) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
10:57:54.0546 0776 Atmarpc - ok
10:57:54.0656 0776 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
10:57:54.0671 0776 audstub - ok
10:57:54.0781 0776 AVGIDSDriver (0c61f066f4d94bd67063dc6691935143) C:\WINDOWS\system32\DRIVERS\AVGIDSDriver.Sys
10:57:54.0796 0776 AVGIDSDriver - ok
10:57:54.0890 0776 AVGIDSEH (84853f800cd69252c3c764fe50d0346f) C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys
10:57:54.0906 0776 AVGIDSEH - ok
10:57:55.0000 0776 AVGIDSFilter (28d6adcd03e10f3838488b9b5d407dd4) C:\WINDOWS\system32\DRIVERS\AVGIDSFilter.Sys
10:57:55.0000 0776 AVGIDSFilter - ok
10:57:55.0109 0776 AVGIDSShim (0eb16f4dbbb946360af30d2b13a52d1d) C:\WINDOWS\system32\DRIVERS\AVGIDSShim.Sys
10:57:55.0125 0776 AVGIDSShim - ok
10:57:55.0218 0776 Avgldx86 (5fe5a2c2330c376a1d8dcff8d2680a2d) C:\WINDOWS\system32\DRIVERS\avgldx86.sys
10:57:55.0234 0776 Avgldx86 - ok
10:57:55.0453 0776 Avgmfx86 (54f1a9b4c9b540c2d8ac4baa171696b1) C:\WINDOWS\system32\DRIVERS\avgmfx86.sys
10:57:55.0468 0776 Avgmfx86 - ok
10:57:55.0562 0776 Avgrkx86 (8da3b77993c5f354cc2977b7ea06d03a) C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
10:57:55.0578 0776 Avgrkx86 - ok
10:57:55.0687 0776 Avgtdix (660788ec46f10ece80274d564fa8b4aa) C:\WINDOWS\system32\DRIVERS\avgtdix.sys
10:57:55.0703 0776 Avgtdix - ok
10:57:55.0796 0776 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
10:57:55.0812 0776 Beep - ok
10:57:55.0921 0776 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
10:57:55.0921 0776 cbidf2k - ok
10:57:56.0015 0776 cd20xrnt - ok
10:57:56.0109 0776 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
10:57:56.0125 0776 Cdaudio - ok
10:57:56.0250 0776 Cdfs (cd7d5152df32b47f4e36f710b35aae02) C:\WINDOWS\system32\drivers\Cdfs.sys
10:57:56.0265 0776 Cdfs - ok
10:57:56.0375 0776 Cdrom (af9c19b3100fe010496b1a27181fbf72) C:\WINDOWS\system32\DRIVERS\cdrom.sys
10:57:56.0390 0776 Cdrom - ok
10:57:56.0453 0776 Changer - ok
10:57:56.0546 0776 CmdIde - ok
10:57:56.0640 0776 Cpqarray - ok
10:57:56.0718 0776 dac2w2k - ok
10:57:56.0796 0776 dac960nt - ok
10:57:56.0906 0776 Disk (00ca44e4534865f8a3b64f7c0984bff0) C:\WINDOWS\system32\DRIVERS\disk.sys
10:57:56.0921 0776 Disk - ok
10:57:57.0062 0776 dmboot (c0fbb516e06e243f0cf31f597e7ebf7d) C:\WINDOWS\system32\drivers\dmboot.sys
10:57:57.0171 0776 dmboot - ok
10:57:57.0265 0776 dmio (f5e7b358a732d09f4bcf2824b88b9e28) C:\WINDOWS\system32\drivers\dmio.sys
10:57:57.0281 0776 dmio - ok
10:57:57.0375 0776 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
10:57:57.0390 0776 dmload - ok
10:57:57.0500 0776 DMusic (a6f881284ac1150e37d9ae47ff601267) C:\WINDOWS\system32\drivers\DMusic.sys
10:57:57.0515 0776 DMusic - ok
10:57:57.0578 0776 dpti2o - ok
10:57:57.0671 0776 drmkaud (1ed4dbbae9f5d558dbba4cc450e3eb2e) C:\WINDOWS\system32\drivers\drmkaud.sys
10:57:57.0687 0776 drmkaud - ok
10:57:57.0796 0776 EAPPkt (efacd8d57a42a93e244a0dbd357e8cb8) C:\WINDOWS\system32\DRIVERS\EAPPkt.sys
10:57:57.0812 0776 EAPPkt - ok
10:57:57.0937 0776 Fastfat (3117f595e9615e04f05a54fc15a03b20) C:\WINDOWS\system32\drivers\Fastfat.sys
10:57:57.0953 0776 Fastfat - ok
10:57:58.0031 0776 fasttx2k (c3901c5b9e491daa8c96d4219f691ef5) C:\WINDOWS\system32\DRIVERS\fasttx2k.sys
10:57:58.0046 0776 fasttx2k - ok
10:57:58.0156 0776 Fdc (ced2e8396a8838e59d8fd529c680e02c) C:\WINDOWS\system32\DRIVERS\fdc.sys
10:57:58.0156 0776 Fdc - ok
10:57:58.0234 0776 Fips (e153ab8a11de5452bcf5ac7652dbf3ed) C:\WINDOWS\system32\drivers\Fips.sys
10:57:58.0250 0776 Fips - ok
10:57:58.0343 0776 Flpydisk (0dd1de43115b93f4d85e889d7a86f548) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
10:57:58.0343 0776 Flpydisk - ok
10:57:58.0453 0776 FltMgr (3d234fb6d6ee875eb009864a299bea29) C:\WINDOWS\system32\drivers\fltmgr.sys
10:57:58.0500 0776 FltMgr - ok
10:57:58.0578 0776 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
10:57:58.0593 0776 Fs_Rec - ok
10:57:58.0671 0776 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
10:57:58.0687 0776 Ftdisk - ok
10:57:58.0812 0776 GearAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\drivers\gearaspiwdm.sys
10:57:58.0828 0776 GearAspiWDM - ok
10:57:58.0921 0776 Gpc (c0f1d4a21de5a415df8170616703debf) C:\WINDOWS\system32\DRIVERS\msgpc.sys
10:57:58.0921 0776 Gpc - ok
10:57:59.0062 0776 HidUsb (1de6783b918f540149aa69943bdfeba8) C:\WINDOWS\system32\DRIVERS\hidusb.sys
10:57:59.0078 0776 HidUsb - ok
10:57:59.0156 0776 hpn - ok
10:57:59.0281 0776 HPZid412 (287a63bd8509bd78e7978823b38afa81) C:\WINDOWS\system32\DRIVERS\HPZid412.sys
10:57:59.0296 0776 HPZid412 - ok
10:57:59.0421 0776 HPZipr12 (0b4fda2657c3e0315eaa57f9c6d4fd1f) C:\WINDOWS\system32\DRIVERS\HPZipr12.sys
10:57:59.0421 0776 HPZipr12 - ok
10:57:59.0562 0776 HPZius12 (29559db25258b60510a60c4e470fce32) C:\WINDOWS\system32\DRIVERS\HPZius12.sys
10:57:59.0578 0776 HPZius12 - ok
10:57:59.0718 0776 HTCAND32 (cbd09ed9cf6822177ee85aea4d8816a2) C:\WINDOWS\system32\Drivers\ANDROIDUSB.sys
10:57:59.0718 0776 HTCAND32 - ok
10:57:59.0859 0776 HTTP (9f8b0f4276f618964fd118be4289b7cd) C:\WINDOWS\system32\Drivers\HTTP.sys
10:57:59.0890 0776 HTTP - ok
10:57:59.0984 0776 i2omgmt - ok
10:58:00.0078 0776 i2omp - ok
10:58:00.0171 0776 i8042prt (5502b58eef7486ee6f93f3f164dcb808) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
10:58:00.0187 0776 i8042prt - ok
10:58:00.0312 0776 ialm (0acebb31989cbf9a5663fe4a33d28d21) C:\WINDOWS\system32\DRIVERS\ialmnt5.sys
10:58:00.0375 0776 ialm - ok
10:58:00.0468 0776 Imapi (f8aa320c6a0409c0380e5d8a99d76ec6) C:\WINDOWS\system32\DRIVERS\imapi.sys
10:58:00.0484 0776 Imapi - ok
10:58:00.0578 0776 ini910u - ok
10:58:00.0671 0776 IntelIde (2d722b2b54ab55b2fa475eb58d7b2aad) C:\WINDOWS\System32\DRIVERS\intelide.sys
10:58:00.0687 0776 IntelIde - ok
10:58:00.0921 0776 intelppm (279fb78702454dff2bb445f238c048d2) C:\WINDOWS\system32\DRIVERS\intelppm.sys
10:58:00.0937 0776 intelppm - ok
10:58:01.0046 0776 ip6fw (4448006b6bc60e6c027932cfc38d6855) C:\WINDOWS\system32\drivers\ip6fw.sys
10:58:01.0062 0776 ip6fw - ok
10:58:01.0156 0776 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
10:58:01.0171 0776 IpFilterDriver - ok
10:58:01.0265 0776 IpInIp (e1ec7f5da720b640cd8fb8424f1b14bb) C:\WINDOWS\system32\DRIVERS\ipinip.sys
10:58:01.0265 0776 IpInIp - ok
10:58:01.0375 0776 IpNat (e2168cbc7098ffe963c6f23f472a3593) C:\WINDOWS\system32\DRIVERS\ipnat.sys
10:58:01.0390 0776 IpNat - ok
10:58:01.0468 0776 IPSec (64537aa5c003a6afeee1df819062d0d1) C:\WINDOWS\system32\DRIVERS\ipsec.sys
10:58:01.0484 0776 IPSec - ok
10:58:01.0578 0776 IRENUM (50708daa1b1cbb7d6ac1cf8f56a24410) C:\WINDOWS\system32\DRIVERS\irenum.sys
10:58:01.0578 0776 IRENUM - ok
10:58:01.0671 0776 isapnp (e504f706ccb699c2596e9a3da1596e87) C:\WINDOWS\system32\DRIVERS\isapnp.sys
10:58:01.0687 0776 isapnp - ok
10:58:01.0781 0776 Kbdclass (ebdee8a2ee5393890a1acee971c4c246) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
10:58:01.0796 0776 Kbdclass - ok
10:58:01.0890 0776 kmixer (ba5deda4d934e6288c2f66caf58d2562) C:\WINDOWS\system32\drivers\kmixer.sys
10:58:01.0906 0776 kmixer - ok
10:58:02.0015 0776 KSecDD (674d3e5a593475915dc6643317192403) C:\WINDOWS\system32\drivers\KSecDD.sys
10:58:02.0046 0776 KSecDD - ok
10:58:02.0125 0776 lbrtfdc - ok
10:58:02.0281 0776 ltmodem5 (fa2ed4a054360f3f873c15420f1f19cc) C:\WINDOWS\system32\DRIVERS\ltmdmnt.sys
10:58:02.0296 0776 ltmodem5 - ok
10:58:02.0359 0776 MBAMSwissArmy - ok
10:58:02.0484 0776 MDC8021X (d7010580bf4e45d5e793a1fe75758c69) C:\WINDOWS\system32\DRIVERS\mdc8021x.sys
10:58:02.0500 0776 MDC8021X - ok
10:58:02.0578 0776 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
10:58:02.0593 0776 mnmdd - ok
10:58:02.0687 0776 Modem (6fc6f9d7acc36dca9b914565a3aeda05) C:\WINDOWS\system32\drivers\Modem.sys
10:58:02.0703 0776 Modem - ok
10:58:02.0781 0776 Mouclass (34e1f0031153e491910e12551400192c) C:\WINDOWS\system32\DRIVERS\mouclass.sys
10:58:02.0796 0776 Mouclass - ok
10:58:02.0921 0776 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
10:58:02.0921 0776 mouhid - ok
10:58:03.0015 0776 MountMgr (65653f3b4477f3c63e68a9659f85ee2e) C:\WINDOWS\system32\drivers\MountMgr.sys
10:58:03.0031 0776 MountMgr - ok
10:58:03.0109 0776 mraid35x - ok
10:58:03.0234 0776 MRxDAV (29414447eb5bde2f8397dc965dbb3156) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
10:58:03.0265 0776 MRxDAV - ok
10:58:03.0375 0776 Msfs (561b3a4333ca2dbdba28b5b956822519) C:\WINDOWS\system32\drivers\Msfs.sys
10:58:03.0390 0776 Msfs - ok
10:58:03.0468 0776 MSKSSRV (ae431a8dd3c1d0d0610cdbac16057ad0) C:\WINDOWS\system32\drivers\MSKSSRV.sys
10:58:03.0484 0776 MSKSSRV - ok
10:58:03.0578 0776 MSPCLOCK (13e75fef9dfeb08eeded9d0246e1f448) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
10:58:03.0578 0776 MSPCLOCK - ok
10:58:03.0687 0776 MSPQM (1988a33ff19242576c3d0ef9ce785da7) C:\WINDOWS\system32\drivers\MSPQM.sys
10:58:03.0687 0776 MSPQM - ok
10:58:03.0812 0776 mssmbios (469541f8bfd2b32659d5d463a6714bce) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
10:58:03.0812 0776 mssmbios - ok
10:58:03.0906 0776 Mup (82035e0f41c2dd05ae41d27fe6cf7de1) C:\WINDOWS\system32\drivers\Mup.sys
10:58:03.0921 0776 Mup - ok
10:58:04.0015 0776 NDIS (558635d3af1c7546d26067d5d9b6959e) C:\WINDOWS\system32\drivers\NDIS.sys
10:58:04.0031 0776 NDIS - ok
10:58:04.0109 0776 NdisTapi (08d43bbdacdf23f34d79e44ed35c1b4c) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
10:58:04.0125 0776 NdisTapi - ok
10:58:04.0218 0776 Ndisuio (34d6cd56409da9a7ed573e1c90a308bf) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
10:58:04.0218 0776 Ndisuio - ok
10:58:04.0312 0776 NdisWan (0b90e255a9490166ab368cd55a529893) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
10:58:04.0328 0776 NdisWan - ok
10:58:04.0421 0776 NDProxy (59fc3fb44d2669bc144fd87826bb571f) C:\WINDOWS\system32\drivers\NDProxy.sys
10:58:04.0421 0776 NDProxy - ok
10:58:04.0531 0776 NetBT (0c80e410cd2f47134407ee7dd19cc86b) C:\WINDOWS\system32\DRIVERS\netbt.sys
10:58:04.0546 0776 NetBT - ok
10:58:04.0656 0776 NIC1394 (5c5c53db4fef16cf87b9911c7e8c6fbc) C:\WINDOWS\system32\DRIVERS\nic1394.sys
10:58:04.0671 0776 NIC1394 - ok
10:58:04.0796 0776 nm (60cf8c7192b3614f240838ddbaa4a245) C:\WINDOWS\system32\DRIVERS\NMnt.sys
10:58:04.0812 0776 nm - ok
10:58:04.0890 0776 Npfs (4f601bcb8f64ea3ac0994f98fed03f8e) C:\WINDOWS\system32\drivers\Npfs.sys
10:58:04.0906 0776 Npfs - ok
10:58:05.0015 0776 Ntfs (19a811ef5f1ed5c926a028ce107ff1af) C:\WINDOWS\system32\drivers\Ntfs.sys
10:58:05.0062 0776 Ntfs - ok
10:58:05.0140 0776 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
10:58:05.0156 0776 Null - ok
10:58:05.0328 0776 nv (2b298519edbfcf451d43e0f1e8f1006d) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
10:58:05.0453 0776 nv - ok
10:58:05.0546 0776 nv_agp (db36442c20793c53b4128eb85f9a3d32) C:\WINDOWS\system32\DRIVERS\nv_agp.sys
10:58:05.0562 0776 nv_agp - ok
10:58:05.0656 0776 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
10:58:05.0656 0776 NwlnkFlt - ok
10:58:05.0765 0776 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
10:58:05.0781 0776 NwlnkFwd - ok
10:58:05.0859 0776 ohci1394 (0951db8e5823ea366b0e408d71e1ba2a) C:\WINDOWS\system32\DRIVERS\ohci1394.sys
10:58:05.0875 0776 ohci1394 - ok
10:58:05.0968 0776 Parport (29744eb4ce659dfe3b4122deb45bc478) C:\WINDOWS\system32\DRIVERS\parport.sys
10:58:05.0984 0776 Parport - ok
10:58:06.0062 0776 PartMgr (3334430c29dc338092f79c38ef7b4cd0) C:\WINDOWS\system32\drivers\PartMgr.sys
10:58:06.0062 0776 PartMgr - ok
10:58:06.0156 0776 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
10:58:06.0156 0776 ParVdm - ok
10:58:06.0250 0776 PCI (8086d9979234b603ad5bc2f5d890b234) C:\WINDOWS\system32\DRIVERS\pci.sys
10:58:06.0265 0776 PCI - ok
10:58:06.0343 0776 PCIDump - ok
10:58:06.0421 0776 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
10:58:06.0437 0776 PCIIde - ok
10:58:06.0531 0776 Pcmcia (82a087207decec8456fbe8537947d579) C:\WINDOWS\system32\drivers\Pcmcia.sys
10:58:06.0546 0776 Pcmcia - ok
10:58:06.0609 0776 PDCOMP - ok
10:58:06.0687 0776 PDFRAME - ok
10:58:06.0765 0776 PDRELI - ok
10:58:06.0843 0776 PDRFRAME - ok
10:58:06.0921 0776 perc2 - ok
10:58:07.0000 0776 perc2hib - ok
10:58:07.0109 0776 pfc (ed2e7f396b4098608c95bc3806bdf6fc) C:\WINDOWS\system32\drivers\pfc.sys
10:58:07.0125 0776 pfc - ok
10:58:07.0218 0776 PptpMiniport (1c5cc65aac0783c344f16353e60b72ac) C:\WINDOWS\system32\DRIVERS\raspptp.sys
10:58:07.0234 0776 PptpMiniport - ok
10:58:07.0328 0776 Processor (0d97d88720a4087ec93af7dbb303b30a) C:\WINDOWS\system32\DRIVERS\processr.sys
10:58:07.0343 0776 Processor - ok
10:58:07.0437 0776 Ps2 (9b793a1ffd480155fe9ee5261153f21b) C:\WINDOWS\system32\DRIVERS\PS2.sys
10:58:07.0453 0776 Ps2 - ok
10:58:07.0531 0776 PSched (48671f327553dcf1d27f6197f622a668) C:\WINDOWS\system32\DRIVERS\psched.sys
10:58:07.0546 0776 PSched - ok
10:58:07.0640 0776 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
10:58:07.0656 0776 Ptilink - ok
10:58:07.0718 0776 ql1080 - ok
10:58:07.0796 0776 Ql10wnt - ok
10:58:07.0875 0776 ql12160 - ok
10:58:07.0953 0776 ql1240 - ok
10:58:08.0031 0776 ql1280 - ok
10:58:08.0125 0776 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
10:58:08.0140 0776 RasAcd - ok
10:58:08.0218 0776 Rasl2tp (98faeb4a4dcf812ba1c6fca4aa3e115c) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
10:58:08.0234 0776 Rasl2tp - ok
10:58:08.0343 0776 RasPppoe (7306eeed8895454cbed4669be9f79faa) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
10:58:08.0343 0776 RasPppoe - ok
10:58:08.0437 0776 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
10:58:08.0453 0776 Raspti - ok
10:58:08.0546 0776 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
10:58:08.0546 0776 RDPCDD - ok
10:58:08.0671 0776 RDPWD (b54cd38a9ebfbf2b3561426e3fe26f62) C:\WINDOWS\system32\drivers\RDPWD.sys
10:58:08.0687 0776 RDPWD - ok
10:58:08.0812 0776 redbook (b31b4588e4086d8d84adbf9845c2402b) C:\WINDOWS\system32\DRIVERS\redbook.sys
10:58:08.0828 0776 redbook - ok
10:58:08.0921 0776 rtl8139 (d507c1400284176573224903819ffda3) C:\WINDOWS\system32\DRIVERS\RTL8139.SYS
10:58:08.0937 0776 rtl8139 - ok
10:58:09.0062 0776 RTL8187B (de4635e8b7975d2b5d961299469a7462) C:\WINDOWS\system32\DRIVERS\wg111v3.sys
10:58:09.0093 0776 RTL8187B - ok
10:58:09.0218 0776 RTLWUSB (691db86b09e13ca5d3e8881141738cc5) C:\WINDOWS\system32\DRIVERS\wg111v2.sys
10:58:09.0234 0776 RTLWUSB - ok
10:58:09.0375 0776 S3Psddr (0dbcc071a268e0340a2ba6bdd98bace4) C:\WINDOWS\system32\DRIVERS\s3gnbm.sys
10:58:09.0390 0776 S3Psddr - ok
10:58:09.0531 0776 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
10:58:09.0546 0776 Secdrv - ok
10:58:09.0640 0776 Serenum (a2d868aeeff612e70e213c451a70cafb) C:\WINDOWS\system32\DRIVERS\serenum.sys
10:58:09.0656 0776 Serenum - ok
10:58:09.0750 0776 Serial (cd9404d115a00d249f70a371b46d5a26) C:\WINDOWS\system32\DRIVERS\serial.sys
10:58:09.0765 0776 Serial - ok
10:58:09.0875 0776 Sfloppy (0d13b6df6e9e101013a7afb0ce629fe0) C:\WINDOWS\system32\drivers\Sfloppy.sys
10:58:09.0890 0776 Sfloppy - ok
10:58:09.0968 0776 Simbad - ok
10:58:10.0078 0776 SiS315 (3b37b6cdd8ccc24f294b9914cc54dba0) C:\WINDOWS\system32\DRIVERS\sisgrp.sys
10:58:10.0093 0776 SiS315 - ok
10:58:10.0187 0776 SISAGP (8dfbc5aa688caa1b7eebc704250fc06e) C:\WINDOWS\system32\DRIVERS\SISAGPX.sys
10:58:10.0187 0776 SISAGP - ok
10:58:10.0312 0776 SjyPkt (3d7ef286e806f9bd9339aa52e28dcd67) C:\WINDOWS\System32\Drivers\SjyPkt.sys
10:58:10.0328 0776 SjyPkt - ok
10:58:10.0515 0776 Sparrow - ok
10:58:10.0609 0776 splitter (0ce218578fff5f4f7e4201539c45c78f) C:\WINDOWS\system32\drivers\splitter.sys
10:58:10.0625 0776 splitter - ok
10:58:10.0718 0776 sr (e41b6d037d6cd08461470af04500dc24) C:\WINDOWS\System32\DRIVERS\sr.sys
10:58:10.0734 0776 sr - ok
10:58:10.0875 0776 Srv (ab9c79ed12d65e800aaad3d72a04792f) C:\WINDOWS\system32\DRIVERS\srv.sys
10:58:10.0906 0776 Srv - ok
10:58:11.0015 0776 swenum (03c1bae4766e2450219d20b993d6e046) C:\WINDOWS\system32\DRIVERS\swenum.sys
10:58:11.0015 0776 swenum - ok
10:58:11.0109 0776 swmidi (94abc808fc4b6d7d2bbf42b85e25bb4d) C:\WINDOWS\system32\drivers\swmidi.sys
10:58:11.0125 0776 swmidi - ok
10:58:11.0218 0776 symc810 - ok
10:58:11.0296 0776 symc8xx - ok
10:58:11.0375 0776 sym_hi - ok
10:58:11.0453 0776 sym_u3 - ok
10:58:11.0531 0776 sysaudio (650ad082d46bac0e64c9c0e0928492fd) C:\WINDOWS\system32\drivers\sysaudio.sys
10:58:11.0546 0776 sysaudio - ok
10:58:11.0687 0776 Tcpip (2a5554fc5b1e04e131230e3ce035c3f9) C:\WINDOWS\system32\DRIVERS\tcpip.sys
10:58:11.0718 0776 Tcpip - ok
10:58:11.0828 0776 TDPIPE (38d437cf2d98965f239b0abcd66dcb0f) C:\WINDOWS\system32\drivers\TDPIPE.sys
10:58:11.0843 0776 TDPIPE - ok
10:58:11.0953 0776 TDTCP (ed0580af02502d00ad8c4c066b156be9) C:\WINDOWS\system32\drivers\TDTCP.sys
10:58:11.0968 0776 TDTCP - ok
10:58:12.0062 0776 TermDD (a540a99c281d933f3d69d55e48727f47) C:\WINDOWS\system32\DRIVERS\termdd.sys
10:58:12.0093 0776 TermDD - ok
10:58:12.0171 0776 TosIde - ok
10:58:12.0296 0776 Udfs (12f70256f140cd7d52c58c7048fde657) C:\WINDOWS\system32\drivers\Udfs.sys
10:58:12.0312 0776 Udfs - ok
10:58:12.0406 0776 ultra - ok
10:58:12.0500 0776 Update (ced744117e91bdc0beb810f7d8608183) C:\WINDOWS\system32\DRIVERS\update.sys
10:58:12.0531 0776 Update - ok
10:58:12.0656 0776 USBAAPL (d4fb6ecc60a428564ba8768b0e23c0fc) C:\WINDOWS\system32\Drivers\usbaapl.sys
10:58:12.0656 0776 USBAAPL - ok
10:58:12.0781 0776 usbccgp (bffd9f120cc63bcbaa3d840f3eef9f79) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
10:58:12.0796 0776 usbccgp - ok
10:58:12.0906 0776 usbehci (15e993ba2f6946b2bfbbfcd30398621e) C:\WINDOWS\system32\DRIVERS\usbehci.sys
10:58:12.0921 0776 usbehci - ok
10:58:13.0015 0776 usbhub (c72f40947f92cea56a8fb532edf025f1) C:\WINDOWS\system32\DRIVERS\usbhub.sys
10:58:13.0015 0776 usbhub - ok
10:58:13.0109 0776 usbohci (bdfe799a8531bad8a5a985821fe78760) C:\WINDOWS\system32\DRIVERS\usbohci.sys
10:58:13.0125 0776 usbohci - ok
10:58:13.0265 0776 usbprint (a42369b7cd8886cd7c70f33da6fcbcf5) C:\WINDOWS\system32\DRIVERS\usbprint.sys
10:58:13.0281 0776 usbprint - ok
10:58:13.0390 0776 usbscan (a6bc71402f4f7dd5b77fd7f4a8ddba85) C:\WINDOWS\system32\DRIVERS\usbscan.sys
10:58:13.0406 0776 usbscan - ok
10:58:13.0859 0776 USBSTOR (6cd7b22193718f1d17a47a1cd6d37e75) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
10:58:13.0859 0776 USBSTOR - ok
10:58:13.0937 0776 usbuhci (f8fd1400092e23c8f2f31406ef06167b) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
10:58:13.0953 0776 usbuhci - ok
10:58:14.0046 0776 VgaSave (8a60edd72b4ea5aea8202daf0e427925) C:\WINDOWS\System32\drivers\vga.sys
10:58:14.0062 0776 VgaSave - ok
10:58:14.0156 0776 viaagp1 (0e3e3fae3a0a58b8d936a8e841a17d16) C:\WINDOWS\system32\DRIVERS\viaagp1.sys
10:58:14.0171 0776 viaagp1 - ok
10:58:14.0281 0776 ViaIde (59cb1338ad3654417bea49636457f65d) C:\WINDOWS\System32\DRIVERS\viaide.sys
10:58:14.0296 0776 ViaIde - ok
10:58:14.0406 0776 VolSnap (ee4660083deba849ff6c485d944b379b) C:\WINDOWS\system32\drivers\VolSnap.sys
10:58:14.0406 0776 VolSnap - ok
10:58:14.0546 0776 Wanarp (984ef0b9788abf89974cfed4bfbaacbc) C:\WINDOWS\system32\DRIVERS\wanarp.sys
10:58:14.0562 0776 Wanarp - ok
10:58:14.0703 0776 Wdf01000 (4769596d7cc0f5fa447d2babc239672a) C:\WINDOWS\system32\Drivers\wdf01000.sys
10:58:14.0750 0776 Wdf01000 - ok
10:58:14.0828 0776 WDICA - ok
10:58:14.0953 0776 wdmaud (efd235ca22b57c81118c1aeb4798f1c1) C:\WINDOWS\system32\drivers\wdmaud.sys
10:58:14.0968 0776 wdmaud - ok
10:58:15.0140 0776 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
10:58:15.0156 0776 WpdUsb - ok
10:58:15.0281 0776 WS2IFSL (6abe6e225adb5a751622a9cc3bc19ce8) C:\WINDOWS\System32\drivers\ws2ifsl.sys
10:58:15.0281 0776 WS2IFSL - ok
10:58:15.0406 0776 WudfPf (f15feafffbb3644ccc80c5da584e6311) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
10:58:15.0421 0776 WudfPf - ok
10:58:15.0531 0776 WudfRd (28b524262bce6de1f7ef9f510ba3985b) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
10:58:15.0546 0776 WudfRd - ok
10:58:15.0781 0776 {6080A529-897E-4629-A488-ABA0C29B635E} (3ee36328e860fbf102b54608a055c6be) C:\WINDOWS\system32\drivers\ialmsbw.sys
10:58:15.0796 0776 {6080A529-897E-4629-A488-ABA0C29B635E} - ok
10:58:15.0984 0776 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} (17f39a1916733ed228eb46ad67c35426) C:\WINDOWS\system32\drivers\ialmkchw.sys
10:58:16.0000 0776 {D31A0762-0CEB-444e-ACFF-B049A1F6FE91} - ok
10:58:16.0046 0776 MBR (0x1B8) (b716b775fcbdabf0e2ddff76f15c6790) \Device\Harddisk0\DR0
10:58:16.0046 0776 \Device\Harddisk0\DR0 - ok
10:58:16.0062 0776 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk1\DR3
10:58:16.0078 0776 \Device\Harddisk1\DR3 - ok
10:58:16.0093 0776 MBR (0x1B8) (5fb38429d5d77768867c76dcbdb35194) \Device\Harddisk2\DR9
10:58:16.0093 0776 \Device\Harddisk2\DR9 - ok
10:58:16.0109 0776 Boot (0x1200) (a439fa729399519be4362b8e8c6fa3fe) \Device\Harddisk0\DR0\Partition0
10:58:16.0109 0776 \Device\Harddisk0\DR0\Partition0 - ok
10:58:16.0125 0776 Boot (0x1200) (bdcce21e7707a859a030cfba1bb4b809) \Device\Harddisk0\DR0\Partition1
10:58:16.0140 0776 \Device\Harddisk0\DR0\Partition1 - ok
10:58:16.0140 0776 Boot (0x1200) (b92d4b411708ff0f3397d98ed7e1c609) \Device\Harddisk1\DR3\Partition0
10:58:16.0140 0776 \Device\Harddisk1\DR3\Partition0 - ok
10:58:16.0156 0776 Boot (0x1200) (b43e494c5ee4da67d24b151685dacaa8) \Device\Harddisk2\DR9\Partition0
10:58:16.0156 0776 \Device\Harddisk2\DR9\Partition0 - ok
10:58:16.0156 0776 ============================================================
10:58:16.0156 0776 Scan finished
10:58:16.0156 0776 ============================================================
10:58:16.0171 0276 Detected object count: 0
10:58:16.0171 0276 Actual detected object count: 0
OTL logfile created on: 10/15/2011 11:00:17 AM - Run 1
OTL by OldTimer - Version 3.2.30.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.49 Gb Total Physical Memory | 2.03 Gb Available Physical Memory | 81.54% Memory free
3.08 Gb Paging File | 2.81 Gb Available in Paging File | 91.17% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 107.56 Gb Total Space | 35.47 Gb Free Space | 32.98% Space Free | Partition Type: NTFS
Drive D: | 4.24 Gb Total Space | 0.69 Gb Free Space | 16.33% Space Free | Partition Type: FAT32
Drive G: | 465.76 Gb Total Space | 465.10 Gb Free Space | 99.86% Space Free | Partition Type: NTFS
Drive H: | 7.47 Gb Total Space | 6.95 Gb Free Space | 93.03% Space Free | Partition Type: FAT32
Computer Name: PICKLE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/10/15 10:39:00 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
PRC - [2011/10/08 13:12:58 | 000,161,664 | ---- | M] (Oracle Corporation) -- C:\Program Files\Java\jre7\bin\jqs.exe
PRC - [2011/01/07 01:22:54 | 002,747,744 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2011/01/06 15:23:20 | 000,737,872 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\Identity
Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2009/12/23 11:45:16 | 002,330,624 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
PRC - [2007/10/09 16:21:02 | 000,124,280 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
PRC - [2007/06/13 05:23:07 | 001,033,216 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2006/04/06 20:19:28 | 000,745,472 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
PRC - [2005/08/07 01:23:04 | 000,856,064 | ---- | M] (Side Effects Software Inc.) -- C:\WINDOWS\system32\sesinetd.exe
PRC - [2005/08/07 01:21:10 | 000,892,928 | ---- | M] (Side Effects Software Inc.) -- C:\WINDOWS\system32\hserver.exe
PRC - [2004/10/04 17:05:04 | 001,044,577 | ---- | M] () -- C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
PRC - [2002/09/02 07:51:40 | 000,049,152 | ---- | M] (GEAR Software) -- C:\WINDOWS\system32\gearsec.exe
========== Modules (No Company Name) ==========
MOD - [2009/12/23 11:45:16 | 002,330,624 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
MOD - [2009/12/23 10:56:34 | 000,053,248 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WlanDll.dll
MOD - [2009/07/14 17:31:30 | 000,335,872 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\WG111v3.dll
MOD - [2007/12/15 01:30:54 | 001,167,360 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\acAuth.dll
MOD - [2007/09/14 10:27:14 | 000,024,576 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v3\CheckSessions.dll
MOD - [2007/05/11 00:50:00 | 000,017,024 | ---- | M] () -- C:\Program Files\Adobe\Reader 8.0\Reader\ViewerPS.dll
MOD - [2006/04/06 20:19:28 | 000,745,472 | ---- | M] () -- C:\Program Files\NETGEAR\WG111v2 Configuration Utility\RtlWake.exe
MOD - [2004/10/04 17:05:04 | 001,044,577 | ---- | M] () -- C:\Program Files\NETGEAR\WG111 Configuration Utility\WG111CFG.exe
MOD - [2004/07/23 18:52:16 | 000,224,768 | ---- | M] () -- C:\WINDOWS\system32\B4FM.dll
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- -- (HidServ)
SRV - File not found [On_Demand | Stopped] -- -- (AppMgmt)
SRV - [2011/10/08 13:12:58 | 000,161,664 | ---- | M] (Oracle Corporation) [Auto | Running] -- C:\Program Files\Java\jre7\bin\jqs.exe --
(JavaQuickStarterService)
SRV - [2011/01/06 15:23:18 | 006,128,720 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\Identity
Protection\Agent\Bin\AVGIDSAgent.exe -- (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | ---- | M] (AVG Technologies CZ, s.r.o.) [Disabled | Stopped] -- C:\Program Files\AVG\AVG10\avgwdsvc.exe -- (avgwd)
SRV - [2007/10/09 16:21:02 | 000,124,280 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program
Files\Seagate\Basics\Service\SyncServicesBasics.exe -- (Basics Service)
SRV - [2005/08/07 01:23:04 | 000,856,064 | ---- | M] (Side Effects Software Inc.) [Auto | Running] -- C:\WINDOWS\system32\sesinetd.exe --
(HoudiniLicenseServer)
SRV - [2005/08/07 01:21:10 | 000,892,928 | ---- | M] (Side Effects Software Inc.) [Auto | Running] -- C:\WINDOWS\system32\hserver.exe -- (HoudiniServer)
SRV - [2004/01/05 02:30:14 | 000,065,795 | ---- | M] (HP) [Disabled | Stopped] -- C:\WINDOWS\system32\hpzipm12.exe -- (Pml Driver HPZ12)
SRV - [2002/09/02 07:51:40 | 000,049,152 | ---- | M] (GEAR Software) [Auto | Running] -- C:\WINDOWS\system32\gearsec.exe -- (GEARSecurity)
========== Driver Services (SafeList) ==========
DRV - [2010/12/08 04:12:38 | 000,251,728 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgldx86.sys --
(Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avgtdix.sys --
(Avgtdix)
DRV - [2010/09/13 15:27:24 | 000,025,680 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys --
(AVGIDSEH)
DRV - [2010/09/07 03:48:56 | 000,034,384 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\system32
\drivers\avgmfx86.sys -- (Avgmfx86)
DRV - [2010/09/07 03:48:50 | 000,026,064 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\avgrkx86.sys
-- (Avgrkx86)
DRV - [2010/08/19 20:42:38 | 000,030,288 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32
\drivers\AVGIDSFilter.sys -- (AVGIDSFilter)
DRV - [2010/08/19 20:42:36 | 000,123,472 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32
\drivers\AVGIDSDriver.sys -- (AVGIDSDriver)
DRV - [2010/08/19 20:42:34 | 000,026,192 | ---- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32
\drivers\AVGIDSShim.sys -- (AVGIDSShim)
DRV - [2009/07/31 15:12:18 | 000,341,504 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] --
C:\WINDOWS\system32\drivers\wg111v3.sys -- (RTL8187B)
DRV - [2009/06/10 16:49:32 | 000,024,576 | ---- | M] (HTC, Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ANDROIDUSB.sys --
(HTCAND32)
DRV - [2006/03/27 17:53:28 | 000,167,808 | ---- | M] (NETGEAR Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wg111v2.sys -- (RTLWUSB)
DRV - [2005/02/23 14:58:56 | 000,011,776 | ---- | M] (Arcsoft, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\afc.sys -- (Afc)
DRV - [2004/10/04 16:57:12 | 000,015,781 | ---- | M] (Meetinghouse Data Communications) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\mdc8021x.sys
-- (MDC8021X) AEGIS Protocol (IEEE 802.1x)
DRV - [2004/10/01 09:24:02 | 002,279,424 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS
-- (ALCXWDM) Service for Realtek AC97 Audio (WDM)
DRV - [2004/08/04 00:59:50 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2004/08/04 00:31:32 | 000,020,992 | ---- | M] (Realtek Semiconductor Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32
\drivers\rtl8139.sys -- (rtl8139) Realtek RTL8139(A/B/C)
DRV - [2004/08/04 00:29:51 | 000,166,912 | ---- | M] (S3 Graphics, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\s3gnbm.sys --
(S3Psddr)
DRV - [2004/02/17 05:49:14 | 000,391,424 | ---- | M] (Sensaura Ltd) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ALCXSENS.SYS -- (ALCXSENS)
DRV - [2003/03/31 13:29:00 | 000,625,537 | ---- | M] (LT) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ltmdmnt.sys -- (ltmodem5)
DRV - [2003/02/26 21:19:50 | 000,260,736 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32
\drivers\sisgrp.sys -- (SiS315)
DRV - [2003/02/22 21:55:26 | 000,141,824 | ---- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\fasttx2k.sys --
(fasttx2k)
DRV - [2002/12/27 13:41:00 | 000,026,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\viaagp1.sys --
(viaagp1)
DRV - [2002/12/25 00:09:48 | 000,030,848 | ---- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32
\DRIVERS\SISAGPX.sys -- (SISAGP)
DRV - [2002/10/02 08:57:12 | 000,013,532 | ---- | M] (Windows ® 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\SjyPkt.sys
-- (SjyPkt)
DRV - [2002/10/01 08:22:32 | 000,009,856 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)
DRV - [2002/09/06 20:24:00 | 000,013,568 | ---- | M] (NVIDIA Corporation) [Kernel | Boot | Running] -- C:\WINDOWS\System32\DRIVERS\nv_agp.sys -- (nv_agp)
DRV - [2002/07/29 23:43:50 | 000,023,808 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PS2.sys -- (Ps2)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.webcrawler.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page =
http://www.webcrawler.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Search Assistant =
http://www.seekseek.com/quicksearch.asp?keyphrase=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank
IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.webcrawler.com/
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Config = [Binary data over 100 bytes]
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Search,Data = C3 17 11 E0 B2 A4 AC 29 3E F1 D7 B3 41 49 45 BA F9
FE DE 71 3C 18 BA 8A C6 15 C8 FE F2 6F 7E 50 2E 2B CF 12 01 9E 7D 91 E9 EE CA 67 BD FC 1B 56 45 [binary data]
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Search,GUID = 94 FD 1C 6D 6D 6A C4 01 30 C6 2C CD 73 94 C4 01 EC
81 2B 96 2A 94 C4 01 [binary data]
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.startup.homepage: "http://www.google.com"
FF - prefs.js..extensions.enabledItems: moveplayer@movenetworks.com:1.0.0.071101000055
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:10.0.0.1178
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre7\bin\new_plugin\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\npctrl.1.0.20926.0.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
(Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.12.69: C:\Program Files\Real Alternative\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.69: C:\Program Files\Real Alternative\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: File not found
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2011/01/14 02:28:45
| 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/10/04 14:15:08 |
000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 7.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/08/04 10:31:52 |
000,000,000 | ---D | M]
[2008/07/10 19:19:03 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/05/11 17:16:08 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\4xw0c9j5.default\extensions
[2010/06/27 19:27:36 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\4xw0c9j5.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/12/13 20:17:44 | 000,000,000 | ---D | M] (Move Media Player) -- C:\Documents and Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\4xw0c9j5.default\extensions\moveplayer@movenetworks.com
[2008/06/20 18:46:33 | 000,001,108 | ---- | M] () -- C:\Documents and Settings\Owner\Application
Data\Mozilla\Firefox\Profiles\4xw0c9j5.default\searchplugins\wikipedia.xml
[2011/10/08 13:13:20 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2011/10/08 13:13:20 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
[2011/10/04 14:15:07 | 000,134,104 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2011/10/08 13:12:58 | 000,611,224 | ---- | M] (Oracle Corporation) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2006/10/07 16:40:23 | 000,114,688 | ---- | M] () -- C:\Program Files\mozilla firefox\plugins\npmozax.dll
[2011/10/04 14:15:03 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
O1 HOSTS File: ([2009/03/23 10:39:34 | 000,000,242 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 91.212.65.122 browser-security.microsoft.com
O1 - Hosts: 91.212.65.122 spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 www.spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 secure.spyware-protector-2009.com
O1 - Hosts: 91.212.65.122 knocker
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
(Adobe Systems Incorporated)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Reg Error: Value error.) - {FB8FBFDE-8BAD-4170-ADA2-43D983A111F8} - C:\WINDOWS\system32\bfggc.dll File not found
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe File not found
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe (HP)
O4 - HKLM..\Run: [iTunesHelper] "C:\Video\Itunes\iTunesHelper.exe" File not found
O4 - HKLM..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE ()
O4 - HKU\.DEFAULT..\Run: [EPSON Stylus Photo RX680 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICJA.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-18..\Run: [EPSON Stylus Photo RX680 Series (Copy 1)] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICJA.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003..\Run: [TimeCalendar] "C:\Program Files\TimeCalendarLE\TCLE.exe" auto File not found
O4 - HKU\.DEFAULT..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - HKU\S-1-5-18..\RunOnce: [RunNarrator] C:\WINDOWS\System32\narrator.exe (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
(Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG111v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG111v3\WG111v3.exe
()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk = C:\Program Files\NETGEAR\WG111
Configuration Utility\WG111CFG.exe ()
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WG111v2 Smart Wizard Wireless Setting.lnk = C:\Program Files\NETGEAR\WG111v2
Configuration Utility\RtlWake.exe ()
O4 - Startup: C:\Documents and Settings\Guest\Start Menu\Programs\Startup\WG111v2 Smart Wizard Wireless Setting.lnk = C:\Program Files\NETGEAR\WG111v2
Configuration Utility\RtlWake.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 0
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSaveSettings = 0
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMHelp = 0
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: StartMenuLogOff = 0
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoUserNameInStartMenu = 1
O7 - HKU\S-1-5-21-3538741722-1687360974-3598075396-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoStartMenuPinnedList = 1
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE}
http://www.symantec.com/techsupp/asa/LSSupCtl.cab (LSSupCtl Class)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab (Symantec RuFSI Utility Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.7.0/jinstall-1_7_0-windows-i586.cab (Java Plug-in 1.7.0)
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078}
http://www.symantec.com/techsupp/asa/SymAData.cab (ActiveDataInfo Class)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D719897A-B07A-4C0C-AEA9-9B663A28DFCB}
http://ax.phobos.apple.com.edgesuite.net/detection/ITDetector.cab (iTunesDetector Class)
O16 - DPF: DirectAnimation Java Classes file://C:\WINDOWS\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\bt2 {1730B77B-F429-498f-9B15-4514D83C8294} - C:\Audio Tools\BT2Net\bt2plugin.dll File not found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Filter\application/x-bt2 {6E1DDCE8-76BC-4390-9488-806E8FB1AD77} - C:\Audio Tools\BT2Net\bt2plugin.dll File not found
O20 - AppInit_DLLs: (C:\WINDOWS\System32\sqlbbkk.dll) - File not found
O20 - AppInit_DLLs: (bijotozu.dll) - File not found
O20 - AppInit_DLLs: (c:\windows\system32\jefosodi.dll) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\System32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - (igfxsrvc.dll) - C:\WINDOWS\System32\igfxsrvc.dll (Intel Corporation)
O21 - SSODL: beropemub - {3ce8b097-ab61-4dc4-ad07-37552f4e4f83} - c:\windows\system32\jefosodi.dll File not found
O22 - SharedTaskScheduler: {3ce8b097-ab61-4dc4-ad07-37552f4e4f83} - mujuzedij - c:\windows\system32\jefosodi.dll File not found
O28 - HKLM ShellExecuteHooks: {EDB0E980-90BD-11D4-8599-0008C7D3B6F8} - C:\Internet\Email\Eudora Tir na nOg\EuShlExt.dll (Qualcomm Inc.)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/07/28 07:07:38 | 000,000,000 | -HS- | M] () - D:\AUTOEXEC.BAT -- [ FAT32 ]
O32 - AutoRun File - [2002/09/11 04:02:32 | 000,000,045 | -HS- | M] () - D:\Autorun.inf -- [ FAT32 ]
O32 - AutoRun File - [2007/08/17 13:48:16 | 000,000,040 | ---- | M] () - G:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{7dde260f-1725-11df-a36c-000ea60491ae}\Shell - "" = AutoRun
O33 - MountPoints2\{7dde260f-1725-11df-a36c-000ea60491ae}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7dde260f-1725-11df-a36c-000ea60491ae}\Shell\AutoRun\command - "" = I:\LaunchU3.exe -a
O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Info.exe -- [2002/09/10 22:54:58 | 000,040,960 | -HS- | M] (XSS)
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/10/15 10:57:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\tdsskiller
[2011/10/15 10:56:45 | 000,583,168 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/10/09 19:34:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Local Settings\Application Data\Sun
[2011/10/08 13:44:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2011/10/08 13:13:19 | 000,214,408 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2011/10/08 13:13:19 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2011/10/08 13:13:19 | 000,173,960 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2011/10/08 13:13:19 | 000,128,000 | ---- | C] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2011/10/08 12:49:48 | 000,000,000 | -HSD | C] -- C:\Config.Msi
[2011/10/04 22:51:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/10/04 22:51:05 | 000,022,216 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2011/10/04 22:51:05 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2011/10/04 14:17:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Tools
[2011/10/04 14:09:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\HhTXwjUCeItPyAi
[2011/10/04 14:09:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\z2ibD3pnGaHdKfL
[2011/10/04 13:33:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/10/04 12:20:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Start Menu\Programs\Security Guard 2012
[2011/10/04 12:20:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\PkkUUVrlOBtx0uS
[2011/10/04 12:20:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\tQJJ77dEK8gRqhX
[2011/10/04 12:19:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\F2oobFF4p
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\*.tmp files -> C:\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/10/15 10:49:21 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/10/15 10:39:00 | 000,583,168 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/10/15 10:37:54 | 001,541,014 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2011/10/08 14:58:06 | 000,000,000 | ---- | M] () -- C:\Documents and Settings\Owner\defogger_reenable
[2011/10/08 13:12:58 | 000,544,656 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\deployJava1.dll
[2011/10/08 13:12:58 | 000,214,408 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaws.exe
[2011/10/08 13:12:58 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javaw.exe
[2011/10/08 13:12:58 | 000,173,960 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\java.exe
[2011/10/08 13:12:58 | 000,128,000 | ---- | M] (Oracle Corporation) -- C:\WINDOWS\System32\javacpl.cpl
[2011/10/07 21:09:41 | 000,055,361 | ---- | M] () -- C:\WINDOWS\cdplayer.ini
[2011/10/06 00:48:50 | 000,000,281 | -HS- | M] () -- C:\boot.ini
[2011/10/04 23:34:15 | 000,000,810 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes'
Anti-Malware.lnk
[2011/10/04 23:10:52 | 000,000,000 | ---- | M] () -- C:\WINDOWS\1429414237
[2011/10/04 23:01:30 | 000,000,792 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/04 20:17:37 | 000,000,880 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011/10/04 14:17:46 | 000,000,478 | ---- | M] () -- C:\WINDOWS\ODBC.INI
[2011/10/04 14:17:33 | 000,001,733 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/10/04 13:39:00 | 000,000,884 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011/10/04 12:20:28 | 000,001,209 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\ldr.ini
[2011/10/03 08:51:42 | 000,000,120 | ---- | M] () -- C:\Documents and Settings\Owner\webct_upload_applet.properties
[2011/10/01 18:33:02 | 000,026,954 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\AZ-tickets.pdf
[2011/09/28 20:14:02 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/09/28 01:03:15 | 000,023,503 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\1860738519-51806832-tickets.pdf
[2011/09/24 19:06:24 | 000,002,167 | ---- | M] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\IDLE (Python
GUI).lnk
[2011/09/20 08:43:20 | 000,026,879 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Modern English tickets.pdf
[2011/09/15 13:18:25 | 000,001,492 | ---- | M] () -- C:\WINDOWS\goldwave.ini
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[46 C:\*.tmp files -> C:\*.tmp -> ]
[4 C:\Documents and Settings\Owner\My Documents\*.tmp files -> C:\Documents and Settings\Owner\My Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2099/01/01 12:00:00 | 000,006,456 | -H-- | C] () -- C:\WINDOWS\System32\gubememe
[2011/10/15 10:56:31 | 001,541,014 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\tdsskiller.zip
[2011/10/08 14:58:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\defogger_reenable
[2011/10/05 08:44:49 | 000,001,862 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\WG111v2 Smart Wizard Wireless
Setting.lnk
[2011/10/05 08:44:49 | 000,001,659 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Smart Wizard Wireless Settings.lnk
[2011/10/04 23:34:15 | 000,000,810 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes'
Anti-Malware.lnk
[2011/10/04 22:51:10 | 000,000,792 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/10/04 22:27:14 | 000,000,000 | ---- | C] () -- C:\WINDOWS\1429414237
[2011/10/04 12:20:07 | 000,001,209 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\ldr.ini
[2011/10/01 18:33:01 | 000,026,954 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\AZ-tickets.pdf
[2011/09/28 01:03:14 | 000,023,503 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\1860738519-51806832-tickets.pdf
[2011/09/20 08:43:18 | 000,026,879 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Modern English tickets.pdf
[2011/06/24 16:43:45 | 000,376,832 | ---- | C] () -- C:\WINDOWS\System32\AegisI5Installer.exe
[2010/09/12 18:15:21 | 000,055,136 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/03/21 23:02:44 | 000,011,518 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\VH56DJI7u87yo
[2009/08/31 08:04:30 | 001,103,360 | ---- | C] () -- C:\WINDOWS\System32\cidfont.dll
[2009/08/31 08:04:29 | 001,503,232 | ---- | C] () -- C:\WINDOWS\System32\ptj.exe
[2009/08/31 08:04:25 | 004,369,408 | ---- | C] () -- C:\WINDOWS\System32\pdftk.exe
[2009/08/31 08:04:24 | 000,235,008 | ---- | C] () -- C:\WINDOWS\System32\office.exe
[2009/04/21 03:06:04 | 000,000,118 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2009/04/02 10:52:16 | 000,814,104 | ---- | C] () -- C:\WINDOWS\System32\rtdsk50.exe
[2009/04/02 10:52:16 | 000,292,376 | ---- | C] () -- C:\WINDOWS\System32\wl50ent.dll
[2009/04/02 10:52:16 | 000,155,648 | ---- | C] () -- C:\WINDOWS\System32\PCGW32.DLL
[2009/04/02 10:52:15 | 000,462,848 | ---- | C] () -- C:\WINDOWS\System32\dbisql.exe
[2009/04/02 10:52:15 | 000,173,568 | ---- | C] () -- C:\WINDOWS\System32\dbcon6.dll
[2009/04/02 10:52:15 | 000,102,936 | ---- | C] () -- C:\WINDOWS\System32\dbl50t.dll
[2009/04/02 10:52:15 | 000,101,376 | ---- | C] () -- C:\WINDOWS\System32\dbl50to.dll
[2009/04/02 10:52:14 | 000,262,168 | ---- | C] () -- C:\WINDOWS\System32\dbclient.exe
[2009/04/02 10:18:20 | 000,000,035 | ---- | C] () -- C:\WINDOWS\A5W.INI
[2009/01/12 11:25:45 | 000,073,220 | ---- | C] () -- C:\WINDOWS\System32\EPPICPrinterDB.dat
[2009/01/12 11:25:45 | 000,031,053 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern131.dat
[2009/01/12 11:25:45 | 000,021,021 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern3.dat
[2009/01/12 11:25:45 | 000,015,670 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern5.dat
[2009/01/12 11:25:45 | 000,013,280 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern2.dat
[2009/01/12 11:25:45 | 000,010,673 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern4.dat
[2009/01/12 11:25:45 | 000,004,943 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern6.dat
[2009/01/12 11:25:45 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_PT.dat
[2009/01/12 11:25:45 | 000,001,140 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_BP.dat
[2009/01/12 11:25:45 | 000,001,137 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_ES.dat
[2009/01/12 11:25:45 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_FR.dat
[2009/01/12 11:25:45 | 000,001,130 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_CF.dat
[2009/01/12 11:25:45 | 000,001,104 | ---- | C] () -- C:\WINDOWS\System32\EPPICPresetData_EN.dat
[2009/01/12 11:25:45 | 000,000,097 | ---- | C] () -- C:\WINDOWS\System32\PICSDK.ini
[2009/01/12 11:25:44 | 000,029,114 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern1.dat
[2009/01/12 11:25:44 | 000,027,417 | ---- | C] () -- C:\WINDOWS\System32\EPPICPattern121.dat
[2009/01/12 11:22:40 | 000,000,084 | ---- | C] () -- C:\WINDOWS\EPSPRX680.ini
[2008/10/17 15:23:01 | 000,000,128 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/05/15 16:58:07 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll
[2008/05/15 16:58:06 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll
[2006/01/18 17:21:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mngui.INI
[2005/08/16 14:46:58 | 000,000,030 | ---- | C] () -- C:\WINDOWS\Win9990.dat
[2005/08/16 14:46:58 | 000,000,030 | ---- | C] () -- C:\WINDOWS\Win6661.dat
[2005/08/16 14:46:58 | 000,000,030 | ---- | C] () -- C:\WINDOWS\Win1118.dat
[2005/08/12 14:21:55 | 000,004,473 | ---- | C] () -- C:\WINDOWS\System32\hserver.ini
[2005/05/09 16:16:12 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2005/04/22 18:08:57 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2005/04/22 18:08:48 | 000,099,965 | ---- | C] () -- C:\WINDOWS\UninstallFirefox.exe
[2005/04/22 18:08:34 | 000,004,459 | ---- | C] () -- C:\WINDOWS\mozver.dat
[2005/03/28 18:30:43 | 000,000,457 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2005/03/05 04:57:11 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/03/04 03:06:57 | 000,145,738 | ---- | C] () -- C:\WINDOWS\dhdom1.bin
[2005/02/25 00:05:19 | 000,007,471 | ---- | C] () -- C:\WINDOWS\ljqqt.dat
[2005/02/24 07:00:45 | 000,006,592 | ---- | C] () -- C:\WINDOWS\gwpreset.ini
[2005/02/24 07:00:44 | 008,412,754 | ---- | C] () -- C:\WINDOWS\salm_kyf.dat
[2005/02/16 11:20:57 | 000,007,471 | ---- | C] () -- C:\WINDOWS\System32\whfwf.dat
[2005/02/16 11:20:54 | 000,000,052 | ---- | C] () -- C:\WINDOWS\intuprof.ini
[2005/02/15 07:56:55 | 000,007,471 | ---- | C] () -- C:\WINDOWS\System32\helgb.dat
[2005/02/11 02:03:41 | 000,007,471 | ---- | C] () -- C:\WINDOWS\System32\nhkvu.dat
[2005/01/25 11:54:15 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2005/01/18 14:13:18 | 000,021,312 | ---- | C] () -- C:\WINDOWS\choice.exe
[2005/01/05 13:44:50 | 000,000,055 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\Sskdmns.dll
[2004/12/31 15:58:49 | 001,847,104 | ---- | C] () -- C:\WINDOWS\FT1_02_0_402_GEPFAH.EXE
[2004/12/28 16:36:30 | 000,005,460 | ---- | C] () -- C:\WINDOWS\kwv2.dat
[2004/12/28 15:58:12 | 000,000,333 | ---- | C] () -- C:\WINDOWS\salm_gdf.dat
[2004/12/28 15:58:04 | 000,318,050 | ---- | C] () -- C:\WINDOWS\salmau.dat
[2004/11/09 19:19:51 | 000,000,037 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\tvmcwrd.dll
[2004/11/02 16:13:43 | 000,000,002 | ---- | C] () -- C:\WINDOWS\System32\wcpsvsu.exe
[2004/10/20 01:05:23 | 000,060,416 | ---- | C] () -- C:\WINDOWS\sxstall2.exe
[2004/10/17 18:54:40 | 000,106,528 | ---- | C] () -- C:\WINDOWS\u1230_32.dll
[2004/10/17 18:54:40 | 000,047,616 | ---- | C] () -- C:\WINDOWS\ucmsp_32.dll
[2004/10/16 07:08:36 | 001,865,736 | ---- | C] () -- C:\WINDOWS\System32\lmd.bin
[2004/10/12 06:37:49 | 000,000,113 | ---- | C] () -- C:\WINDOWS\jawa32vs.bin
[2004/08/22 14:49:23 | 000,081,972 | ---- | C] () -- C:\WINDOWS\System32\zlib.dll
[2004/08/09 21:07:00 | 000,001,067 | ---- | C] () -- C:\WINDOWS\dsearch1.bin
[2004/08/09 21:06:59 | 000,087,016 | ---- | C] () -- C:\WINDOWS\dhdomp1.bin
[2004/07/23 18:52:16 | 000,224,768 | ---- | C] () -- C:\WINDOWS\System32\B4FM.dll
[2004/07/22 21:48:26 | 000,000,045 | ---- | C] () -- C:\WINDOWS\BHJGJFJJ.ini
[2004/07/15 05:26:45 | 000,086,030 | ---- | C] () -- C:\WINDOWS\System32\msdjgk.dll
[2004/06/29 21:38:14 | 000,000,627 | ---- | C] () -- C:\WINDOWS\sepsd.bin
[2004/06/22 12:55:01 | 000,000,036 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2004/06/10 12:03:31 | 000,300,012 | ---- | C] () -- C:\WINDOWS\mxtarget.ini
[2004/05/27 00:19:49 | 000,000,145 | ---- | C] () -- C:\WINDOWS\System32\EBPPORT3.DAT
[2004/05/25 14:47:21 | 000,511,488 | ---- | C] () -- C:\WINDOWS\System32\cwmdtl50.dll
[2004/05/25 14:47:21 | 000,102,400 | ---- | C] () -- C:\WINDOWS\System32\cwsmaf40.dll
[2004/04/26 20:28:08 | 000,112,640 | ---- | C] () -- C:\WINDOWS\lsb_un20.exe
[2004/01/15 09:00:26 | 000,000,033 | ---- | C] () -- C:\WINDOWS\quark.ini
[2004/01/13 14:25:06 | 000,000,000 | ---- | C] () -- C:\Documents and Settings\Owner\Application Data\sversion.ini
[2004/01/13 13:41:55 | 000,077,824 | ---- | C] () -- C:\WINDOWS\uinst001.exe
[2003/11/05 12:55:11 | 000,000,128 | ---- | C] () -- C:\WINDOWS\System32\mm_dsmd.exe
[2003/11/05 12:46:48 | 000,000,708 | ---- | C] () -- C:\WINDOWS\System32\dxamph3.dll
[2003/11/02 17:53:53 | 000,001,492 | ---- | C] () -- C:\WINDOWS\goldwave.ini
[2003/11/02 17:47:59 | 000,022,016 | ---- | C] () -- C:\WINDOWS\exeshl.dll
[2003/11/02 17:47:59 | 000,000,049 | ---- | C] () -- C:\WINDOWS\netctrl.ini
[2003/11/02 17:43:47 | 000,532,480 | ---- | C] () -- C:\WINDOWS\System32\NCTAudioEditor2.dll
[2003/11/02 17:43:47 | 000,233,472 | ---- | C] () -- C:\WINDOWS\System32\lame_enc.dll
[2003/09/16 19:35:47 | 000,072,192 | ---- | C] () -- C:\WINDOWS\System32\anti_deb.dll
[2003/06/19 20:23:55 | 000,040,960 | ---- | C] () -- C:\WINDOWS\DelPiv.exe
[2003/06/07 23:44:19 | 000,000,478 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2003/06/07 16:11:40 | 000,000,024 | ---- | C] () -- C:\WINDOWS\MSCPX.ini
[2003/06/07 15:57:18 | 000,135,200 | ---- | C] () -- C:\WINDOWS\u1220_32.dll
[2003/06/07 15:57:18 | 000,068,608 | ---- | C] () -- C:\WINDOWS\vufile32.dll
[2003/06/07 15:57:18 | 000,065,536 | ---- | C] () -- C:\WINDOWS\u2200_32.dll
[2003/06/07 15:57:18 | 000,030,208 | ---- | C] () -- C:\WINDOWS\uxmail32.dll
[2003/06/07 15:57:11 | 000,164,864 | ---- | C] () -- C:\WINDOWS\patchw32.dll
[2003/06/07 15:57:11 | 000,027,584 | ---- | C] () -- C:\WINDOWS\PIDGEN.DLL
[2003/06/07 15:57:10 | 000,025,600 | ---- | C] () -- C:\WINDOWS\MEMBOOT.DLL
[2003/06/07 15:57:10 | 000,005,440 | R--- | C] () -- C:\WINDOWS\MMLIB.DLL
[2003/06/07 15:57:02 | 000,102,400 | ---- | C] () -- C:\WINDOWS\BurnQuickShx.dll
[2003/06/07 15:57:02 | 000,095,152 | R--- | C] () -- C:\WINDOWS\CARDLIB.DLL
[2003/05/31 22:11:00 | 000,000,516 | ---- | C] () -- C:\WINDOWS\EZPHOTO.INI
[2003/05/29 16:43:08 | 000,006,550 | ---- | C] () -- C:\WINDOWS\jautoexp.dat
[2003/05/26 14:46:59 | 000,055,361 | ---- | C] () -- C:\WINDOWS\cdplayer.ini
[2003/05/26 12:11:17 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\F29435.bin
[2003/05/26 12:11:02 | 000,000,008 | ---- | C] () -- C:\WINDOWS\System32\e7462k.bin
[2003/05/26 10:38:41 | 000,153,088 | ---- | C] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/05/26 09:12:18 | 000,000,690 | ---- | C] () -- C:\WINDOWS\VTruck1.ini
[2003/05/25 16:35:39 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\cpuinf32.dll
[2003/04/25 11:24:15 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2003/04/25 11:24:14 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2003/04/25 11:23:54 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2003/04/25 11:23:50 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2003/04/25 10:44:46 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2003/04/25 10:44:46 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2003/04/25 10:44:43 | 000,004,490 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2003/04/25 10:44:37 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2003/04/25 10:44:32 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2003/04/10 06:10:20 | 000,167,936 | ---- | C] () -- C:\WINDOWS\System32\PCDrJNI_1_1.dll
[2003/04/10 06:08:02 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\syscontr.dll
[2003/04/10 06:08:01 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\hpreg.dll
[2003/04/10 05:59:52 | 000,000,608 | ---- | C] () -- C:\WINDOWS\QUICKEN.INI
[2003/04/10 05:53:45 | 000,000,051 | ---- | C] () -- C:\WINDOWS\System32\mshrml.ini
[2003/04/10 05:36:30 | 000,001,793 | ---- | C] () -- C:\WINDOWS\System32\fxsperf.ini
[2003/04/10 05:26:58 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis740.bin
[2003/04/10 05:26:58 | 000,049,152 | ---- | C] () -- C:\WINDOWS\System32\sis650.bin
[2003/04/10 05:16:02 | 000,363,520 | ---- | C] () -- C:\WINDOWS\System32\psisdecd.dll
[2003/04/10 05:06:11 | 000,299,073 | ---- | C] () -- C:\WINDOWS\System32\PythonCOM22.dll
[2003/04/10 05:06:11 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\PyWinTypes22.dll
[2003/04/10 05:05:46 | 000,016,896 | ---- | C] () -- C:\WINDOWS\System32\bcbmm.dll
[2003/04/10 04:53:32 | 000,000,802 | ---- | C] () -- C:\WINDOWS\orun32.ini
[2003/04/10 04:51:51 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2003/04/10 04:46:57 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2003/04/10 04:37:43 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\oeminfo.ini
[2003/04/10 04:37:11 | 000,442,466 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2003/04/10 04:37:11 | 000,071,732 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2003/04/10 02:08:18 | 000,000,438 | ---- | C] () -- C:\WINDOWS\System32\1_ssetup.ini
[2003/04/10 02:08:18 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\sunistlog.ini
[2003/04/09 21:42:03 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2003/04/09 21:41:03 | 000,293,760 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2002/12/05 17:51:00 | 000,059,392 | R--- | C] () -- C:\WINDOWS\streamhlp.dll
[2002/06/06 01:01:58 | 000,029,696 | ---- | C] () -- C:\WINDOWS\System32\asutl8.dll
[2000/02/16 00:00:00 | 000,016,384 | ---- | C] () -- C:\WINDOWS\System32\UniClear.exe
[1999/01/22 12:46:58 | 000,065,536 | ---- | C] () -- C:\WINDOWS\System32\MSRTEDIT.DLL
========== Alternate Data Streams ==========
@Alternate Data Stream - 7471 bytes -> C:\WINDOWS\Q329048Uninst.log:pffbrk
@Alternate Data Stream - 7471 bytes -> C:\WINDOWS\IEPatchUninstall.log:mocdsl
@Alternate Data Stream - 124 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 11736 bytes -> C:\WINDOWS\gwpreset.ini:tojyya
@Alternate Data Stream - 11591 bytes -> C:\WINDOWS\ucmsp_32.dll:efxcn
@Alternate Data Stream - 11591 bytes -> C:\WINDOWS\u1230_32.dll:leeps
@Alternate Data Stream - 11591 bytes -> C:\WINDOWS\ST6UNST.EXE:irwkl
@Alternate Data Stream - 11591 bytes -> C:\WINDOWS\SNMPAPI.DLL:pqefr
@Alternate Data Stream - 11591 bytes -> C:\WINDOWS\jawa32vs.bin:wsoki
< End of report >