Hello oldman960,
Thank goodness there are alternative programs!
I successfully ran the MBR and OTL programs.
Here are the MBR and the OTL Logfile (1 of 2 files).
Due to its length and to make it easier for reading, the
OTL Extras Logfile is posted in the next reply following this one.
MBR Log:
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer,
http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
kernel: MBR read successfully
user & kernel MBR OK
********************************************************************************
************************************************
OTL Logfile
OTL logfile created on: 2/17/2010 5:40:10 AM - Run 1
OTL by OldTimer - Version 3.1.28.0 Folder = C:\Documents and Settings\Cookie\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,013.00 Mb Total Physical Memory | 629.00 Mb Available Physical Memory | 62.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 294.73 Gb Total Space | 273.72 Gb Free Space | 92.87% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
Drive I: | 3.72 Gb Total Space | 1.38 Gb Free Space | 36.98% Space Free | Partition Type: FAT32
Computer Name: MAMASPC
Current User Name: Cookie
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe (OldTimer Tools)
PRC - C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
PRC - C:\WINDOWS\system32\igfxsrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
PRC - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
PRC - C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
PRC - C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
PRC - C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe (OldTimer Tools)
========== Win32 Services (SafeList) ==========
SRV - (gupdate) Google Update Service (gupdate) – C:\Program Files\Google\Update\GoogleUpdate.exe (Google Inc.)
SRV - (iWinTrusted) – C:\Program Files\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (JavaQuickStarterService) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (SeaPort) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (gusvc) – C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe (Google)
SRV - (PcCtlCom) – C:\Program Files\Trend Micro\Internet Security 14\PcCtlCom.exe (Trend Micro Inc.)
SRV - (GoogleDesktopManager) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (Tmntsrv) – C:\Program Files\Trend Micro\Internet Security 14\Tmntsrv.exe (Trend Micro Inc.)
SRV - (DellAMBrokerService) – C:\Program Files\DellAutomatedPCTuneUp\brkrsvc.exe ()
SRV - (tmproxy) – C:\Program Files\Trend Micro\Internet Security 14\tmproxy.exe (Trend Micro Inc.)
SRV - (TmPfw) – C:\Program Files\Trend Micro\Internet Security 14\TmPfw.exe (Trend Micro Inc.)
SRV - (RoxMediaDB9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe (Sonic Solutions)
SRV - (RoxWatch9) – C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe (Sonic Solutions)
SRV - (stllssvr) – C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (MicroVision Development, Inc.)
SRV - (IDriverT) – C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe (Macrovision Corporation)
SRV - (aspnet_state) – C:\WINDOWS\Microsoft.NET\Framework\v1.1.4322\aspnet_state.exe (Microsoft Corporation)
SRV - (ose) – C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE (Microsoft Corporation)
SRV - (Bjmcmng) – C:\Program Files\Canon\BJCard\Bjmcmng.exe (CANON INC.)
========== Driver Services (SafeList) ==========
DRV - (tmxpflt) – C:\WINDOWS\system32\drivers\tmxpflt.sys (Trend Micro Inc.)
DRV - (tmpreflt) – C:\WINDOWS\system32\drivers\tmpreflt.sys (Trend Micro Inc.)
DRV - (vsapint) – C:\WINDOWS\system32\drivers\vsapint.sys (Trend Micro Inc.)
DRV - (amdagp) – C:\WINDOWS\system32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\system32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (HDAudBus) – C:\WINDOWS\system32\drivers\hdaudbus.sys (Windows ® Server 2003 DDK provider)
DRV - (Secdrv) – C:\WINDOWS\system32\drivers\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (datunidr) – C:\WINDOWS\system32\drivers\datunidr.sys (Gteko Ltd.)
DRV - (e1express) Intel® – C:\WINDOWS\system32\drivers\e1e5132.sys (Intel Corporation)
DRV - (iaStor) – C:\WINDOWS\system32\drivers\iaStor.sys (Intel Corporation)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (ialm) – C:\WINDOWS\system32\drivers\igxpmp32.sys (Intel Corporation)
DRV - (tmcfw) – C:\WINDOWS\system32\drivers\TM_CFW.sys (Trend Micro Inc.)
DRV - (tmtdi) – C:\WINDOWS\system32\drivers\tmtdi.sys (Trend Micro Inc.)
DRV - (PTproct) – C:\Program Files\DellAutomatedPCTuneUp\GTAction\triggers\PTproct.sys (Gteko Ltd.)
DRV - (DLADResM) – C:\WINDOWS\system32\DLA\DLADResM.SYS (Roxio)
DRV - (DLABMFSM) – C:\WINDOWS\system32\DLA\DLABMFSM.SYS (Roxio)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\DLA\DLAUDF_M.SYS (Roxio)
DRV - (DLAUDFAM) – C:\WINDOWS\system32\DLA\DLAUDFAM.SYS (Roxio)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\DLA\DLAOPIOM.SYS (Roxio)
DRV - (DLABOIOM) – C:\WINDOWS\system32\DLA\DLABOIOM.SYS (Roxio)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\DLA\DLAIFS_M.SYS (Roxio)
DRV - (DLAPoolM) – C:\WINDOWS\system32\DLA\DLAPoolM.SYS (Roxio)
DRV - (DRVNDDM) – C:\WINDOWS\system32\drivers\DRVNDDM.SYS (Roxio)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Roxio)
DRV - (DLARTL_M) – C:\WINDOWS\system32\drivers\DLARTL_M.SYS (Roxio)
DRV - (PxHelp20) – C:\WINDOWS\System32\Drivers\PxHelp20.sys (Sonic Solutions)
DRV - (DRVMCDB) – C:\WINDOWS\System32\Drivers\DRVMCDB.SYS (Sonic Solutions)
DRV - (Ptilink) – C:\WINDOWS\system32\drivers\ptilink.sys (Parallel Technologies, Inc.)
DRV - (nv) – C:\WINDOWS\system32\drivers\nv4_mini.sys (NVIDIA Corporation)
DRV - (HSFHWBS2) – C:\WINDOWS\system32\drivers\HSFHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (mdmxsdk) – C:\WINDOWS\system32\drivers\mdmxsdk.sys (Conexant)
DRV - (FilterService) – C:\WINDOWS\system32\drivers\bjhid.sys (Canon.inc)
DRV - (Sparrow) – C:\WINDOWS\system32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (sym_u3) – C:\WINDOWS\system32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\system32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (symc8xx) – C:\WINDOWS\system32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (symc810) – C:\WINDOWS\system32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\system32\drivers\MODEMCSA.sys (Microsoft Corporation)
DRV - (ultra) – C:\WINDOWS\system32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (ql12160) – C:\WINDOWS\system32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\system32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (ql1280) – C:\WINDOWS\system32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (dac2w2k) – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (mraid35x) – C:\WINDOWS\system32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (asc) – C:\WINDOWS\system32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (asc3550) – C:\WINDOWS\system32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (AliIde) – C:\WINDOWS\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (CmdIde) – C:\WINDOWS\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (E100B) Intel® – C:\WINDOWS\system32\drivers\e100b325.sys (Intel Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client;=dell-usuk&channel;=us&ibd;=0080318
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com/hws/sb/dell-usuk/en/…html?channel=us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://home.alot.com/?client_id=3B798D1001…rsion=2.4.2.399
IE - HKCU\..\URLSearchHook: {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Google"
FF - prefs.js..browser.search.defaulturl: "
http://search.live.com/results.aspx?FORM=SOLTDF&q;="
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..keyword.URL: "
http://search.live.com/results.aspx?FORM=SOLTDF&q;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0847}: C:\Program Files\iWin Games\firefox\ [2009/06/18 17:30:08 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/09 17:54:57 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.7\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/01/14 16:45:06 | 000,000,000 | —D | M]
[2009/05/09 07:56:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Mozilla\Extensions
[2010/01/08 16:34:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Mozilla\Firefox\Profiles\l6l76x0t.default\extensions
[2009/12/05 14:12:56 | 000,001,633 | —- | M] () – C:\Documents and Settings\Cookie\Application Data\Mozilla\Firefox\Profiles\l6l76x0t.default\searchplugins\live-search.xml
[2010/02/16 18:06:52 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2004/08/04 03:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (IEHlprObj Class) - {8CA5ED52-F3FB-4414-A105-2E3491156990} - C:\Program Files\iWin Games\iWinGamesHookIE.dll (iWin Inc.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (iWin Toolbar) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O2 - BHO: (MSN Toolbar Helper) - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (MSN Toolbar) - {1E61ED7C-7CB8-49d6-B9E9-AB4C880C8414} - C:\Program Files\MSN\Toolbar\3.0.1125.0\msneshellx.dll (Microsoft Corp.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Miva)
O3 - HKLM\..\Toolbar: (iWin Toolbar) - {ce0c2586-da36-452b-acdb-320d9bcb19bf} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (iWin Toolbar) - {CE0C2586-DA36-452B-ACDB-320D9BCB19BF} - C:\Program Files\iWin\tbiWi1.dll (Conduit Ltd.)
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [DellAutomatedPCTuneUp] C:\Program Files\DellAutomatedPCTuneUp\PTAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [OE_OEM] C:\Program Files\Trend Micro\Internet Security 14\TMAS_OE\TMAS_OEMon.exe (Trend Micro Inc.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\WINDOWS\System32\Adobe\Shockwave 11\SwHelper_1150596.exe -Update -1150596 -Mozilla\4.0 ( File not found
O4 - Startup: C:\Documents and Settings\Cookie\Start Menu\Programs\Startup\DING!.lnk = C:\Program Files\Southwest Airlines\Ding\Ding.exe (Southwest Airlines)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Google Sidewiki… - C:\Program Files\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll (Google Inc.)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)
O15 - HKCU\..Trusted Domains: //@mail.mar@/ ([]msn in Local intranet)
O15 - HKCU\..Trusted Domains: //@signup.mar@ ([]msn in My Computer)
O15 - HKCU\..Trusted Domains: //@signup.mar@/ ([]msn in My Computer)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1210395665609 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn.com/binFramework/v10/…ro.cab56649.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab (PopCapLoader Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Cookie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Cookie\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2004/08/11 15:15:00 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2004/08/11 15:02:12 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/02/17 05:38:02 | 000,549,376 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe
[2010/02/16 05:24:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Cookie\Application Data\Malwarebytes
[2010/02/16 05:19:23 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/02/15 14:00:11 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/02/14 10:42:19 | 000,000,000 | -H-D | C] – C:\WINDOWS\PIF
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-TW
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\zh-HK
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\tr-TR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\sv-SE
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\pt-BR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nl-NL
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\nb-NO
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ko-KR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\it-IT
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\he-IL
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fr-FR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\fi-FI
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\es-ES
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\el-GR
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\de-DE
[2010/02/11 17:38:14 | 000,000,000 | —D | C] – C:\WINDOWS\System32\da-DK
[2010/02/11 17:38:13 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ar-SA
[2010/02/11 17:14:41 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/02/09 17:54:31 | 000,000,000 | -HSD | C] – C:\WINDOWS\CSC
[2010/02/09 16:27:44 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/02/09 16:27:43 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/02/09 16:27:42 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/02/09 16:27:42 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/09 16:19:10 | 005,061,512 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Cookie\Desktop\fluffy.exe
[2010/02/06 08:38:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MSNDynFiles
[2008/08/18 19:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2008/04/02 19:13:06 | 000,000,000 | –SD | M] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2008/03/17 19:24:35 | 000,000,000 | —D | M] – C:\Documents and Settings\LocalService\Application Data\Roxio
[2004/08/11 15:20:16 | 000,000,000 | —D | M] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2004/08/11 15:06:56 | 000,000,000 | –SD | M] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/02/17 05:31:02 | 000,549,376 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Cookie\Desktop\erunt_setup DLd as OTL.exe
[2010/02/17 05:27:56 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/02/17 05:27:40 | 000,000,236 | —- | M] () – C:\WINDOWS\tasks\OGALogon.job
[2010/02/17 05:27:39 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/17 05:27:36 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/02/17 05:27:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/02/17 05:27:33 | 1062,387,712 | -HS- | M] () – C:\hiberfil.sys
[2010/02/17 05:05:05 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/16 18:15:56 | 004,194,304 | -H– | M] () – C:\Documents and Settings\Cookie\NTUSER.DAT
[2010/02/16 18:15:56 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cookie\ntuser.ini
[2010/02/16 18:13:35 | 000,293,376 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\rue0v3z3.exe
[2010/02/15 17:49:03 | 000,000,560 | —- | M] () – C:\WINDOWS\tasks\Norton Security Scan for Cookie.job
[2010/02/15 15:12:18 | 000,000,089 | —- | M] () – C:\WINDOWS\popcinfot.dat
[2010/02/15 14:32:09 | 000,000,027 | —- | M] () – C:\WINDOWS\popcinfo.dat
[2010/02/15 13:59:51 | 000,359,929 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\dds.scr
[2010/02/15 12:53:20 | 000,000,009 | —- | M] () – C:\WINDOWS\System32\Class14
[2010/02/15 12:53:20 | 000,000,005 | —- | M] () – C:\WINDOWS\System32\Band4
[2010/02/10 21:22:33 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/02/10 06:49:28 | 000,015,004 | -HS- | M] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\g52C
[2010/02/09 18:14:35 | 000,000,901 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\Shortcut (2) to HijackThis Log 02-09-10.lnk
[2010/02/09 18:13:37 | 000,000,901 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\Shortcut to HijackThis Log 02-09-10.lnk
[2010/02/09 18:04:07 | 000,001,734 | —- | M] () – C:\Documents and Settings\Cookie\Desktop\HiJackThis.lnk
[2010/02/09 17:52:52 | 000,000,477 | —- | M] () – C:\WINDOWS\win.ini
[2010/02/09 17:52:52 | 000,000,227 | —- | M] () – C:\WINDOWS\system.ini
[2010/02/09 17:52:52 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/02/09 16:27:47 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 16:21:49 | 004,770,096 | -H– | M] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\IconCache.db
[2010/02/09 16:19:19 | 005,061,512 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Cookie\Desktop\fluffy.exe
[2010/02/09 11:46:02 | 000,005,970 | —- | M] () – C:\Documents and Settings\Cookie\Application Data\wklnhst.dat
[2010/01/24 05:53:00 | 003,456,282 | —- | M] () – C:\Documents and Settings\Cookie\My Documents\ELVIS_seatplan.pdf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/02/16 18:13:35 | 000,293,376 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\rue0v3z3.exe
[2010/02/16 05:19:16 | 1062,387,712 | -HS- | C] () – C:\hiberfil.sys
[2010/02/15 14:01:54 | 000,359,929 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\dds.scr
[2010/02/15 14:00:07 | 000,000,886 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/02/15 14:00:07 | 000,000,882 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/02/11 17:38:15 | 000,000,236 | —- | C] () – C:\WINDOWS\tasks\OGALogon.job
[2010/02/09 18:14:35 | 000,000,901 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\Shortcut (2) to HijackThis Log 02-09-10.lnk
[2010/02/09 18:13:37 | 000,000,901 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\Shortcut to HijackThis Log 02-09-10.lnk
[2010/02/09 18:04:07 | 000,001,734 | —- | C] () – C:\Documents and Settings\Cookie\Desktop\HiJackThis.lnk
[2010/02/09 16:27:47 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/09 15:09:50 | 000,015,004 | -HS- | C] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\g52C
[2010/01/24 05:52:59 | 003,456,282 | —- | C] () – C:\Documents and Settings\Cookie\My Documents\ELVIS_seatplan.pdf
[2009/08/03 15:07:42 | 000,403,816 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.dll
[2008/08/24 15:06:56 | 000,005,632 | —- | C] () – C:\Documents and Settings\Cookie\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/08/17 06:29:56 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2008/07/03 13:35:25 | 000,005,970 | —- | C] () – C:\Documents and Settings\Cookie\Application Data\wklnhst.dat
[2008/06/15 12:19:48 | 000,011,776 | —- | C] () – C:\WINDOWS\System32\pmsbfn32.dll
[2008/06/15 12:16:12 | 000,000,412 | —- | C] () – C:\WINDOWS\MAXLINK.INI
[2008/04/04 05:31:18 | 000,005,632 | —- | C] () – C:\WINDOWS\System32\CNMVS4y.DLL
[2008/03/22 08:28:41 | 000,101,376 | —- | C] () – C:\WINDOWS\System32\hpgt34.dll
[2008/03/17 19:24:50 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2008/03/17 19:15:39 | 000,056,056 | —- | C] () – C:\WINDOWS\System32\DLAAPI_W.DLL
[2008/03/17 19:15:39 | 000,000,120 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/03/17 18:48:46 | 000,876,544 | —- | C] () – C:\WINDOWS\System32\TEACico2.dll
[2008/03/17 18:48:37 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4820.dll
[2008/03/17 18:47:06 | 000,001,119 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2006/11/07 02:25:58 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2006/09/16 20:36:50 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Roxio.dll
[2006/09/16 20:36:50 | 000,204,800 | —- | C] () – C:\WINDOWS\System32\CddbFileTaggerRoxio.dll
[2004/08/11 15:24:19 | 000,000,791 | —- | C] () – C:\WINDOWS\orun32.ini
[2004/08/11 15:11:31 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
========== LOP Check ==========
[2008/06/15 12:11:44 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2008/08/16 19:52:27 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IM
[2008/08/16 19:51:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\IncrediMail
[2009/04/08 06:41:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\iWin Games
[2008/05/24 14:03:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Masque
[2008/03/22 10:46:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSN Messenger 6.1.0207
[2010/02/16 05:54:37 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MSNDynFiles
[2009/06/21 18:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PlayFirst
[2008/04/01 05:43:38 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap
[2008/11/16 13:17:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PopCap Games
[2008/06/15 12:16:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ScanSoft
[2009/07/31 15:25:47 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SpinTop Games
[2008/03/17 19:19:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2010/02/15 17:48:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009/12/15 16:28:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\alot
[2009/06/19 05:53:15 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Aveyond 3
[2008/06/16 09:37:16 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Canon
[2009/03/27 08:14:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Fabulous Finds
[2009/06/18 18:03:48 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Faerie Solitaire
[2008/05/24 14:13:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Masque
[2008/07/09 18:30:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\MSNInstaller
[2009/06/21 18:18:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PlayFirst
[2009/07/30 17:50:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PopCapv1001
[2009/03/24 06:20:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\PopCapv1002
[2008/06/15 12:16:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\ScanSoft
[2008/08/28 09:14:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Southwest Airlines
[2009/02/05 18:33:26 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Stellarium
[2008/07/03 13:35:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Cookie\Application Data\Template
[2010/02/17 05:27:40 | 000,000,236 | —- | M] () – C:\WINDOWS\Tasks\OGALogon.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:AGP440.sys
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 10:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\agp440.sys
[2004/08/03 21:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\i386\AGP440.SYS
[2004/08/03 21:07:42 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\i386\sp2.cab:atapi.sys
[2004/08/04 03:00:00 | 018,738,937 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/08/18 18:55:44 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2006/08/28 00:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\i386\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\system32\ReinstallBackups\0002\DriverFiles\i386\atapi.sys
[2006/08/27 19:02:10 | 000,095,872 | —- | M] (Microsoft Corporation) MD5=40CAACE7F2E7668148A1D45CF91E1131 – C:\WINDOWS\system32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 10:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 16:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\i386\eventlog.dll
[2004/08/04 03:00:00 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
< MD5 for: IASTOR.SYS >
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\drivers\storage\R158515\iastor.sys
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\i386\iastor.sys
[2007/07/19 16:26:24 | 000,304,920 | —- | M] (Intel Corporation) MD5=997E8F5939F2D12CD9F2E6B395724C16 – C:\WINDOWS\system32\drivers\iastor.sys
< MD5 for: NETLOGON.DLL >
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 16:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\i386\netlogon.dll
[2004/08/04 03:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll
< MD5 for: SCECLI.DLL >
[2004/08/04 03:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\i386\scecli.dll
[2004/08/04 03:00:00 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 16:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2004/08/11 15:06:14 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2004/08/11 15:06:14 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2004/08/11 15:06:14 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 143 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:37C5B4CA
@Alternate Data Stream - 140 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:7198E1D2
@Alternate Data Stream - 130 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:C9D9AD33
@Alternate Data Stream - 116 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3932BB3
@Alternate Data Stream - 115 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:E39052E1
< End of report >