This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] Need help with removing a trojan.dnschanger and more

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

Can you take a hold of all the computers at the same time even if only till after we're done with the steps below?

As this infection might be coming from the other pc's and infecting the other pc's on your network, we'll try to do some fixes on all of them at the same time.

_________________________________________


Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order in which they are mentioned below. If there's anything that you don't understand, please ask your question(s) before proceeding with the fixes.


1. Download, install, update and run MBAM on all the pc's.
Please download Malwarebytes' Anti-Malware to the pc's desktop.
  • Right-click mbam-setup.exe then choose "Run as Administrator" and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • NOTE: After updating, disconnect all of the pc's from the network and router before running a scan.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post back the log.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer, please do so immediately.

2. Flush the DNS on all the pc's. Be sure not to connect the pc's to the network or router.
Do the following:
  • Click the Start logo in the bottom left corner of the screen.
  • Click All Programs.
  • Click Accessories.
  • RIGHT-click on Command Prompt.
  • Select Run As Administrator.
  • In the command window type the following or copy/paste and then hit enter: ipconfig /flushdns
    NOTE:There is a space between the letter g in ipconfig and the slash(/) in /flushdns.
  • You will see the following confirmation:

Windows IP Configuration
Successfully flushed the DNS Resolver Cache.


3. Reset the router. Be sure not to connect the pc's to the network or router.
  • This can be done by inserting something tiny like a paper clip end or pencil tip into a small hole labeled "reset" located on the back of the router.
  • Press and hold down the small button inside until the lights on the front of the router blink off and then on again (usually about 10 seconds).
  • If you don’t know the router's default password, you can look it up. HERE
  • You also need to reconfigure any security settings you had in place prior to the reset.
  • You may also need to consult with your Internet service provider to find out which DNS servers your network should be using.
4. Reboot the pc's.

5. You may now connect the pc's to the network/router.

Run another OTL scan on the first pc we are working on.
  • Open OTL.exe.
  • Right click on the icon then choose "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • There will only be a single log produced. OTL.Txt.
    Note:This log can be located in the OTL. folder on your C:\ drive if it fails to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of this file and post it with your next reply.
To post in your next reply:
1. All the Malwarebytes' logs taken from all the pc's.
2. OTL log.
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3999 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/16/2010 9:50:08 PM mbam-log-2010-04-16 (21-50-08).txt Scan type: Quick scan Objects scanned: 104348 Time elapsed: 5 minute(s), 46 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{33efffa5-1f9c-4866-a2bf-47329d48e2d5}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
OTL logfile created on: 4/16/2010 10:00:09 PM - Run 4
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\ZSnake\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 494.00 Mb Available Physical Memory | 55.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 78.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.59 Gb Total Space | 25.72 Gb Free Space | 46.26% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZSNAKE-PC
Current User Name: ZSnake
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\ZSnake\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\ZSnake\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PStrip) – C:\Windows\System32\drivers\pstrip.sys (EnTech Taiwan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FB BC DC FF 84 CF CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:1.9.9.63
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q="

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/08 02:14:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/16 19:05:59 | 000,000,000 | —D | M]

[2010/03/29 14:44:05 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Extensions
[2010/04/16 20:44:56 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions
[2010/04/15 17:02:52 | 000,000,000 | —D | M] (NoScript) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/03/29 16:00:07 | 000,000,000 | —D | M] (WOT) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/03/29 14:43:47 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk = C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/07 22:54:57 | 000,458,752 | —- | C] (Apple Computer, Inc.) – C:\Windows\System32\CoreFoundation.dll
[2010/04/07 21:26:37 | 000,000,000 | —D | C] – C:\ProgramData\Last.fm
[2010/04/07 21:24:11 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Last.fm
[2010/04/07 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\Last.fm
[2010/04/07 19:52:35 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/07 19:52:34 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/07 19:52:34 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/07 19:49:46 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/07 19:47:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/03 13:52:03 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\ElevatedDiagnostics
[2010/04/02 14:03:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/04/02 14:03:01 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/04/02 14:02:44 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2010/04/02 14:01:59 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/04/02 14:01:38 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/04/02 14:01:28 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2010/04/02 14:00:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2010/04/02 13:54:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/04/02 13:27:53 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Avira
[2010/04/01 14:41:07 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2010/04/01 14:40:43 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Audacity
[2010/04/01 14:40:27 | 000,000,000 | —D | C] – C:\Program Files\Audacity 1.3 Beta (Unicode)
[2010/04/01 14:28:18 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/04/01 14:27:47 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/04/01 14:16:14 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/04/01 14:16:14 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/04/01 14:16:14 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/04/01 14:16:04 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/04/01 14:15:41 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/01 14:15:26 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/04/01 14:15:22 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/03/30 21:36:00 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/30 17:21:44 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Users\ZSnake\Desktop\OTL.exe
[2010/03/30 12:16:32 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Juce VST Host
[2010/03/30 12:16:02 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Hardcore
[2010/03/29 22:15:29 | 000,000,000 | —D | C] – C:\Program Files\BeatPack
[2010/03/29 21:16:57 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2010/03/29 21:16:45 | 000,225,280 | —- | C] (Propellerhead Software AB) – C:\Windows\System32\rewire.dll
[2010/03/29 21:16:21 | 001,554,944 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\Windows\System32\vorbis.acm
[2010/03/29 21:15:57 | 000,000,000 | —D | C] – C:\Program Files\VstPlugins
[2010/03/29 21:15:55 | 000,000,000 | —D | C] – C:\Program Files\Outsim
[2010/03/29 21:12:38 | 000,000,000 | —D | C] – C:\Program Files\Image-Line
[2010/03/29 20:39:41 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\DVDVideoSoft
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[2010/03/29 19:39:53 | 000,000,000 | —D | C] – C:\Program Files\PowerStrip
[2010/03/29 16:14:48 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Malwarebytes
[2010/03/29 16:14:40 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 16:14:37 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/29 16:14:36 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 16:14:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/29 16:14:06 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple Computer
[2010/03/29 16:14:05 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Apple Computer
[2010/03/29 16:13:34 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/03/29 16:13:34 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2010/03/29 16:12:27 | 000,000,000 | —D | C] – C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/29 16:10:11 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/29 16:09:56 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple
[2010/03/29 16:09:49 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/03/29 15:20:50 | 000,028,520 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\ssmdrv.sys
[2010/03/29 15:20:49 | 000,124,784 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avipbb.sys
[2010/03/29 15:20:49 | 000,060,936 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avgntflt.sys
[2010/03/29 15:20:49 | 000,051,992 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntdd.sys
[2010/03/29 15:20:49 | 000,017,016 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntmgr.sys
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/03/29 15:16:02 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Mozilla
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Mozilla
[2010/03/29 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/03/29 14:34:11 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\WinRAR
[2010/03/29 14:32:20 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/03/29 14:26:31 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Diagnostics
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Macromedia
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Adobe
[2010/03/29 14:19:07 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/03/29 01:43:29 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/03/29 01:19:54 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Searches
[2010/03/29 01:19:39 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Identities
[2010/03/29 01:19:34 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Contacts
[2010/03/29 01:19:17 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\VirtualStore
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Temporary Internet Files
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Templates
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Start Menu
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\SendTo
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Recent
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\PrintHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\NetHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Videos
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Pictures
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Music
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\My Documents
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Local Settings
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\History
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Cookies
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Application Data
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Application Data
[2010/03/29 01:19:01 | 000,000,000 | –SD | C] – C:\Users\ZSnake\AppData\Roaming\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Videos
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Saved Games
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Pictures
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Music
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Links
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Favorites
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Downloads
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Documents
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Desktop
[2010/03/29 01:19:01 | 000,000,000 | -H-D | C] – C:\Users\ZSnake\AppData
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Temp
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Media Center Programs
[2010/03/29 00:48:00 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/03/29 00:44:52 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/03/23 15:30:07 | 000,000,000 | —D | C] – C:\Users\ZSnake\Documents\Samples
[2010/03/23 14:48:06 | 000,000,000 | —D | C] – C:\Users\ZSnake\Desktop\Okage Shadow King - Soundtrack

========== Files - Modified Within 30 Days ==========

[2010/04/16 21:58:49 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/04/16 21:58:46 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/04/16 21:58:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/04/16 21:58:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/04/16 21:58:11 | 703,156,224 | -HS- | M] () – C:\hiberfil.sys
[2010/04/16 21:57:32 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/16 21:57:32 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/16 21:57:28 | 001,310,720 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT
[2010/04/16 21:57:25 | 000,008,486 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/04/16 21:55:43 | 000,713,888 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/04/16 21:55:43 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/04/16 21:55:43 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/04/16 21:51:48 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/04/15 16:16:28 | 002,036,274 | -H– | M] () – C:\Users\ZSnake\AppData\Local\IconCache.db
[2010/04/12 14:04:56 | 000,001,208 | —- | M] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/04/07 21:23:58 | 000,000,905 | —- | M] () – C:\Users\Public\Desktop\Last.fm.lnk
[2010/04/07 19:53:16 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/04/07 19:49:58 | 000,001,826 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/03 14:25:27 | 000,000,375 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2010/04/02 14:00:50 | 000,000,020 | —- | M] () – C:\Windows\Èøš
[2010/04/01 20:16:00 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 14:40:39 | 000,001,023 | —- | M] () – C:\Users\ZSnake\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010/04/01 14:25:37 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/04/01 14:07:08 | 003,906,159 | R— | M] () – C:\Users\ZSnake\Desktop\Subsfix.exe
[2010/03/30 23:09:57 | 000,100,908 | —- | M] () – C:\Users\ZSnake\Desktop\SystemLook.exe
[2010/03/30 22:23:30 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/30 17:22:27 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\ZSnake\Desktop\OTL.exe
[2010/03/29 22:15:32 | 000,000,994 | —- | M] () – C:\Users\ZSnake\Desktop\BeatPack.lnk
[2010/03/29 21:16:45 | 000,001,108 | —- | M] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | M] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 19:48:40 | 000,001,435 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/03/29 19:40:04 | 000,000,063 | —- | M] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 15:24:58 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 15:21:16 | 000,002,023 | —- | M] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:46:25 | 000,057,560 | —- | M] () – C:\Users\ZSnake\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/29 14:43:49 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | M] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | M] () – C:\GQILH
[2010/03/29 01:43:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/03/29 01:19:12 | 000,000,020 | -HS- | M] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 00:58:21 | 000,266,808 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/29 00:49:39 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2010/03/28 21:16:15 | 000,000,330 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:31 | 000,010,702 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg

========== Files Created - No Company Name ==========

[2010/04/07 21:23:58 | 000,000,905 | —- | C] () – C:\Users\Public\Desktop\Last.fm.lnk
[2010/04/07 19:53:16 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/04/07 19:49:58 | 000,001,826 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 14:00:49 | 000,000,020 | —- | C] () – C:\Windows\Èøš
[2010/04/01 20:16:00 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 14:40:39 | 000,001,023 | —- | C] () – C:\Users\ZSnake\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010/04/01 14:16:14 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/04/01 14:16:14 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/04/01 14:16:14 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/04/01 14:16:14 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/04/01 14:16:14 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/04/01 14:07:01 | 003,906,159 | R— | C] () – C:\Users\ZSnake\Desktop\Subsfix.exe
[2010/03/30 23:09:55 | 000,100,908 | —- | C] () – C:\Users\ZSnake\Desktop\SystemLook.exe
[2010/03/30 22:23:30 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/30 17:45:31 | 000,293,376 | —- | C] () – C:\Users\ZSnake\Desktop\gmer.exe
[2010/03/30 12:15:36 | 000,008,486 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/03/30 12:15:29 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/03/29 22:15:32 | 000,000,994 | —- | C] () – C:\Users\ZSnake\Desktop\BeatPack.lnk
[2010/03/29 21:16:45 | 000,001,108 | —- | C] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | C] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 20:23:57 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/03/29 20:11:13 | 000,001,208 | —- | C] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/03/29 19:48:38 | 000,001,435 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/03/29 19:48:36 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/03/29 19:40:04 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 15:21:16 | 000,002,023 | —- | C] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:43:49 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | C] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | C] () – C:\GQILH
[2010/03/29 01:19:12 | 000,000,020 | -HS- | C] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 01:19:01 | 001,310,720 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT
[2010/03/29 00:44:23 | 703,156,224 | -HS- | C] () – C:\hiberfil.sys
[2010/03/28 21:15:53 | 000,000,330 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:24 | 000,010,702 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
< End of report >
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 3999 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/16/2010 9:50:54 PM mbam-log-2010-04-16 (21-50-54).txt Scan type: Quick scan Objects scanned: 111788 Time elapsed: 6 minute(s), 25 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8424a5e7-4999-4479-92cd-82f31b3061ff}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Your log is looking good. How is your computer?

Do the following scans on the first pc we are working on, no need to run it on the second pc as we will be dealing with that after we're through with the first one.

Let's do another MBAM scan to be sure:
  • Please open your MalwareBytes AntiMalware Program
  • Click the Update Tab and search for updates
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected. <– very important
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.

Extra Note:If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.


–Next–

Run an on-line scan with Kaspersky

Right click Internet Explorer or Firefox then choose "Run as Administrator" to run the program.

NOTE: After scanning with Kaspersky, close your browser then run it without administrator privileges for your browsing.

Using Internet Explorer or Firefox, visit Kaspersky On-line Scanner

1. Click Accept, when prompted to download and install the program files and database of malware definitions.
2. To optimize scanning time and produce a more sensible report for review:
  • Close any open programs
  • Turn off the real time scanner of any existing antivirus program while performing the online scan
3. Click Run at the Security prompt.
The program will then begin downloading and installing and will also update the database.
Please be patient as this can take several minutes.
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Click View scan report at the bottom.

    [external image: Posted Image]
  • Click the Save as Text button to save the file to your desktop so that you may post it in your next reply
To post in your next reply:
1. Malwarebytes' scan.
2. Kaspersky scan.
3. How is your computer?
I'm sorry Inzanity i been away on vacation and couldn't get on to respond if anything i done what you asked me on the last page. I'll add my results now.
Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Database version: 4029 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 4/23/2010 11:37:37 PM mbam-log-2010-04-23 (23-37-37).txt Scan type: Quick scan Objects scanned: 105360 Time elapsed: 7 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 2 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{33efffa5-1f9c-4866-a2bf-47329d48e2d5}\DhcpNameServer (Trojan.DNSChanger) -> Data: [removed] [removed] [removed] -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
Hi,

Since it's been a while, let's hold off Kaspersky scan for now. It seems that your computer has been reinfected. We might be doing the steps over again.

Let's do another round of OTL.

If you no longer have OTL in your computer then do the following:
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on your C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
I still have OTL Here:

OTL logfile created on: 4/24/2010 6:21:39 PM - Run 5
OTL by OldTimer - Version 3.1.37.3 Folder = C:\Users\ZSnake\Desktop
Ultimate Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

894.00 Mb Total Physical Memory | 535.00 Mb Available Physical Memory | 60.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 71.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 55.59 Gb Total Space | 26.08 Gb Free Space | 46.91% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ZSNAKE-PC
Current User Name: ZSnake
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Users\ZSnake\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH)
PRC - C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\conhost.exe (Microsoft Corporation)


========== Modules (SafeList) ==========

MOD - C:\Users\ZSnake\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (AntiVirService) – C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (Apple Mobile Device) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PeerDistSvc) – C:\Windows\System32\PeerDistSvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (avipbb) – C:\Windows\System32\drivers\avipbb.sys (Avira GmbH)
DRV - (avgntflt) – C:\Windows\System32\drivers\avgntflt.sys (Avira GmbH)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nvstor) – C:\Windows\system32\DRIVERS\nvstor.sys (NVIDIA Corporation)
DRV - (nvraid) – C:\Windows\system32\DRIVERS\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vmbus) – C:\Windows\system32\DRIVERS\vmbus.sys (Microsoft Corporation)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (storflt) – C:\Windows\system32\DRIVERS\vmstorfl.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (storvsc) – C:\Windows\system32\DRIVERS\storvsc.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\System32\drivers\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwififlt) – C:\Windows\System32\drivers\vwififlt.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\System32\drivers\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (WinUsb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (s3cap) – C:\Windows\system32\DRIVERS\vms3cap.sys (Microsoft Corporation)
DRV - (VMBusHID) – C:\Windows\system32\DRIVERS\VMBusHID.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (RTL8023xp) – C:\Windows\System32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (ssmdrv) – C:\Windows\System32\drivers\ssmdrv.sys (Avira GmbH)
DRV - (PStrip) – C:\Windows\System32\drivers\pstrip.sys (EnTech Taiwan)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = FB BC DC FF 84 CF CA 01 [binary data]
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Bing"
FF - prefs.js..browser.search.defaulturl: "http://www.bing.com/search?FORM=IEFM1&q;="
FF - prefs.js..browser.search.selectedEngine: "Wikipedia (en)"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://en-US.start3.mozilla.com/firefox?client=firefox-a&rls;=org.mozilla:en-US:official"
FF - prefs.js..extensions.enabledItems: {a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}:20091028
FF - prefs.js..extensions.enabledItems: {73a6fe31-595d-460b-a920-fcc0f8843232}:[removed]
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..keyword.URL: "http://www.bing.com/search?FORM=IEFM1&q;="


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/08 02:14:15 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/24 00:04:08 | 000,000,000 | —D | M]

[2010/03/29 14:44:05 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Extensions
[2010/04/24 00:44:08 | 000,000,000 | —D | M] – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions
[2010/04/24 00:05:46 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/04/22 15:47:53 | 000,000,000 | —D | M] (NoScript) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}
[2010/03/29 16:00:07 | 000,000,000 | —D | M] (WOT) – C:\Users\ZSnake\AppData\Roaming\Mozilla\Firefox\Profiles\o4mmkd9f.default\extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7}
[2010/04/24 00:04:11 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/06/10 14:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk = C:\Program Files\PowerStrip\PStrip.exe (EnTech Taiwan)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_18)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 14:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/24 00:08:46 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/04/24 00:08:45 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/04/24 00:04:08 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deploytk.dll
[2010/04/24 00:04:08 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/04/24 00:04:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/04/24 00:04:08 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/04/24 00:03:42 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/04/07 22:54:57 | 000,458,752 | —- | C] (Apple Computer, Inc.) – C:\Windows\System32\CoreFoundation.dll
[2010/04/07 21:26:37 | 000,000,000 | —D | C] – C:\ProgramData\Last.fm
[2010/04/07 21:24:11 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Last.fm
[2010/04/07 21:23:21 | 000,000,000 | —D | C] – C:\Program Files\Last.fm
[2010/04/07 19:52:35 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/07 19:52:34 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/07 19:52:34 | 000,000,000 | —D | C] – C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/07 19:49:46 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/07 19:47:22 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/03 13:52:03 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\ElevatedDiagnostics
[2010/04/02 14:03:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2010/04/02 14:03:01 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/04/02 14:02:44 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2010/04/02 14:01:59 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/04/02 14:01:38 | 000,000,000 | —D | C] – C:\Windows\PCHEALTH
[2010/04/02 14:01:28 | 003,426,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\d3dx9_32.dll
[2010/04/02 14:00:49 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2010/04/02 13:54:39 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/04/02 13:27:53 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Avira
[2010/04/01 14:41:07 | 000,000,000 | —D | C] – C:\Program Files\Lame for Audacity
[2010/04/01 14:40:43 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Audacity
[2010/04/01 14:40:27 | 000,000,000 | —D | C] – C:\Program Files\Audacity 1.3 Beta (Unicode)
[2010/04/01 14:28:18 | 000,000,000 | —D | C] – C:\Windows\temp
[2010/04/01 14:27:47 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/04/01 14:16:14 | 000,161,792 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2010/04/01 14:16:14 | 000,136,704 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2010/04/01 14:16:14 | 000,031,232 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2010/04/01 14:16:04 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/04/01 14:15:41 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/01 14:15:26 | 000,212,480 | —- | C] (SteelWerX) – C:\Windows\SWXCACLS.exe
[2010/04/01 14:15:22 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/03/30 21:36:00 | 000,000,000 | —D | C] – C:\_OTL
[2010/03/30 17:21:44 | 000,555,520 | —- | C] (OldTimer Tools) – C:\Users\ZSnake\Desktop\OTL.exe
[2010/03/30 12:16:32 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Juce VST Host
[2010/03/30 12:16:02 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Hardcore
[2010/03/29 22:15:29 | 000,000,000 | —D | C] – C:\Program Files\BeatPack
[2010/03/29 21:16:57 | 000,000,000 | —D | C] – C:\Program Files\ASIO4ALL v2
[2010/03/29 21:16:45 | 000,225,280 | —- | C] (Propellerhead Software AB) – C:\Windows\System32\rewire.dll
[2010/03/29 21:16:21 | 001,554,944 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\Windows\System32\vorbis.acm
[2010/03/29 21:15:57 | 000,000,000 | —D | C] – C:\Program Files\VstPlugins
[2010/03/29 21:15:55 | 000,000,000 | —D | C] – C:\Program Files\Outsim
[2010/03/29 21:12:38 | 000,000,000 | —D | C] – C:\Program Files\Image-Line
[2010/03/29 20:39:41 | 000,000,000 | —D | C] – C:\Program Files\TrendMicro
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\DVDVideoSoft
[2010/03/29 20:10:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\DVDVideoSoft
[2010/03/29 19:39:53 | 000,000,000 | —D | C] – C:\Program Files\PowerStrip
[2010/03/29 16:14:48 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Malwarebytes
[2010/03/29 16:14:40 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 16:14:37 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/29 16:14:36 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 16:14:36 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/03/29 16:14:06 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple Computer
[2010/03/29 16:14:05 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Apple Computer
[2010/03/29 16:13:34 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\System32\GEARAspi.dll
[2010/03/29 16:13:34 | 000,000,000 | —D | C] – C:\Windows\System32\DRVSTORE
[2010/03/29 16:12:27 | 000,000,000 | —D | C] – C:\ProgramData\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2010/03/29 16:10:11 | 000,000,000 | —D | C] – C:\ProgramData\Apple Computer
[2010/03/29 16:09:56 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Apple
[2010/03/29 16:09:49 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\ProgramData\Apple
[2010/03/29 16:08:15 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/03/29 15:20:50 | 000,028,520 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\ssmdrv.sys
[2010/03/29 15:20:49 | 000,124,784 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avipbb.sys
[2010/03/29 15:20:49 | 000,060,936 | —- | C] (Avira GmbH) – C:\Windows\System32\drivers\avgntflt.sys
[2010/03/29 15:20:49 | 000,051,992 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntdd.sys
[2010/03/29 15:20:49 | 000,017,016 | —- | C] (AVIRA GmbH) – C:\Windows\System32\drivers\avgntmgr.sys
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2010/03/29 15:20:48 | 000,000,000 | —D | C] – C:\Program Files\Avira
[2010/03/29 15:16:02 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Mozilla
[2010/03/29 14:43:55 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Mozilla
[2010/03/29 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/03/29 14:34:11 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\WinRAR
[2010/03/29 14:32:20 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/03/29 14:26:31 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Diagnostics
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Macromedia
[2010/03/29 14:19:26 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Adobe
[2010/03/29 14:19:07 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/03/29 01:43:29 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/03/29 01:19:54 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Searches
[2010/03/29 01:19:39 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Identities
[2010/03/29 01:19:34 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Contacts
[2010/03/29 01:19:17 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\VirtualStore
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Temporary Internet Files
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Templates
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Start Menu
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\SendTo
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Recent
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\PrintHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\NetHood
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Videos
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Pictures
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Documents\My Music
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\My Documents
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Local Settings
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\History
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Cookies
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\Application Data
[2010/03/29 01:19:12 | 000,000,000 | -HSD | C] – C:\Users\ZSnake\AppData\Local\Application Data
[2010/03/29 01:19:01 | 000,000,000 | –SD | C] – C:\Users\ZSnake\AppData\Roaming\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Videos
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Saved Games
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Pictures
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Music
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Links
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Favorites
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Downloads
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Documents
[2010/03/29 01:19:01 | 000,000,000 | R–D | C] – C:\Users\ZSnake\Desktop
[2010/03/29 01:19:01 | 000,000,000 | -H-D | C] – C:\Users\ZSnake\AppData
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Temp
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Local\Microsoft
[2010/03/29 01:19:01 | 000,000,000 | —D | C] – C:\Users\ZSnake\AppData\Roaming\Media Center Programs
[2010/03/29 00:48:00 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/03/29 00:44:52 | 000,000,000 | —D | C] – C:\Windows\Prefetch

========== Files - Modified Within 30 Days ==========

[2010/04/24 18:21:59 | 001,310,720 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT
[2010/04/24 14:55:52 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/04/24 00:03:46 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deploytk.dll
[2010/04/24 00:03:46 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/04/24 00:03:46 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/04/24 00:03:46 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/04/23 23:47:02 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/04/23 23:47:02 | 000,016,944 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/04/23 23:44:01 | 000,713,888 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/04/23 23:44:01 | 000,615,360 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/04/23 23:44:01 | 000,103,702 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/04/23 23:40:39 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/04/23 23:40:31 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/04/23 23:39:47 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/04/23 23:39:28 | 703,156,224 | -HS- | M] () – C:\hiberfil.sys
[2010/04/23 23:38:19 | 002,038,150 | -H– | M] () – C:\Users\ZSnake\AppData\Local\IconCache.db
[2010/04/23 23:38:14 | 000,008,486 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/04/22 20:19:49 | 000,008,463 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/04/21 13:14:50 | 001,048,576 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.2.regtrans-ms
[2010/04/21 13:14:47 | 001,048,576 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.1.regtrans-ms
[2010/04/21 13:14:46 | 001,048,576 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.0.regtrans-ms
[2010/04/21 13:14:46 | 000,065,536 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.blf
[2010/04/20 20:19:28 | 000,001,208 | —- | M] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/04/17 20:46:21 | 000,001,435 | —- | M] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/04/07 21:23:58 | 000,000,905 | —- | M] () – C:\Users\Public\Desktop\Last.fm.lnk
[2010/04/07 19:53:16 | 000,002,429 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/04/07 19:49:58 | 000,001,826 | —- | M] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/03 14:25:27 | 000,000,375 | —- | M] () – C:\Windows\System32\drivers\etc\hosts.ics
[2010/04/02 14:00:50 | 000,000,020 | —- | M] () – C:\Windows\Èøš
[2010/04/01 20:16:00 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 14:40:39 | 000,001,023 | —- | M] () – C:\Users\ZSnake\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010/04/01 14:25:37 | 000,000,215 | —- | M] () – C:\Windows\system.ini
[2010/04/01 14:07:08 | 003,906,159 | R— | M] () – C:\Users\ZSnake\Desktop\Subsfix.exe
[2010/03/30 23:09:57 | 000,100,908 | —- | M] () – C:\Users\ZSnake\Desktop\SystemLook.exe
[2010/03/30 22:23:30 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/30 17:22:27 | 000,555,520 | —- | M] (OldTimer Tools) – C:\Users\ZSnake\Desktop\OTL.exe
[2010/03/29 22:15:32 | 000,000,994 | —- | M] () – C:\Users\ZSnake\Desktop\BeatPack.lnk
[2010/03/29 21:16:45 | 000,001,108 | —- | M] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | M] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 19:40:04 | 000,000,063 | —- | M] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 15:24:58 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/29 15:24:46 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/29 15:21:16 | 000,002,023 | —- | M] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:46:25 | 000,057,560 | —- | M] () – C:\Users\ZSnake\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/03/29 14:43:49 | 000,001,896 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | M] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | M] () – C:\GQILH
[2010/03/29 01:43:16 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/03/29 01:19:12 | 000,000,020 | -HS- | M] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | M] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 00:58:21 | 000,266,808 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/03/29 00:49:39 | 000,042,045 | —- | M] () – C:\Windows\System32\license.rtf
[2010/03/28 21:16:15 | 000,000,330 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:31 | 000,010,702 | —- | M] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg

========== Files Created - No Company Name ==========

[2010/04/21 13:14:50 | 001,048,576 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.2.regtrans-ms
[2010/04/21 13:14:47 | 001,048,576 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.1.regtrans-ms
[2010/04/21 13:14:46 | 001,048,576 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.0.regtrans-ms
[2010/04/21 13:14:46 | 000,065,536 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f0-6e01-11de-8bed-001e0bcd1824}.TxR.blf
[2010/04/18 17:56:11 | 000,009,994 | -HS- | C] () – C:\Users\ZSnake\Desktop\AlbumArt_{EC416FC5-F3FB-4F85-A4DA-2DFFE9447BBA}_Large.jpg
[2010/04/07 21:23:58 | 000,000,905 | —- | C] () – C:\Users\Public\Desktop\Last.fm.lnk
[2010/04/07 19:53:16 | 000,002,429 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2010/04/07 19:49:58 | 000,001,826 | —- | C] () – C:\Users\Public\Desktop\QuickTime Player.lnk
[2010/04/02 14:00:49 | 000,000,020 | —- | C] () – C:\Windows\Èøš
[2010/04/01 20:16:00 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
[2010/04/01 14:40:39 | 000,001,023 | —- | C] () – C:\Users\ZSnake\Desktop\Audacity 1.3 Beta (Unicode).lnk
[2010/04/01 14:16:14 | 000,261,632 | —- | C] () – C:\Windows\PEV.exe
[2010/04/01 14:16:14 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2010/04/01 14:16:14 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2010/04/01 14:16:14 | 000,077,312 | —- | C] () – C:\Windows\MBR.exe
[2010/04/01 14:16:14 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2010/04/01 14:07:01 | 003,906,159 | R— | C] () – C:\Users\ZSnake\Desktop\Subsfix.exe
[2010/03/30 23:09:55 | 000,100,908 | —- | C] () – C:\Users\ZSnake\Desktop\SystemLook.exe
[2010/03/30 22:23:30 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/03/30 17:45:31 | 000,293,376 | —- | C] () – C:\Users\ZSnake\Desktop\gmer.exe
[2010/03/30 12:15:36 | 000,008,486 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bk!
[2010/03/30 12:15:29 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bko
[2010/03/29 22:15:32 | 000,000,994 | —- | C] () – C:\Users\ZSnake\Desktop\BeatPack.lnk
[2010/03/29 21:16:45 | 000,001,108 | —- | C] () – C:\Users\ZSnake\Desktop\FL Studio 9.lnk
[2010/03/29 20:39:42 | 000,002,967 | —- | C] () – C:\Users\ZSnake\Desktop\HiJackThis.lnk
[2010/03/29 20:23:57 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.bak
[2010/03/29 20:11:13 | 000,001,208 | —- | C] () – C:\Users\ZSnake\Desktop\DVDVideoSoft Free Studio.lnk
[2010/03/29 19:48:38 | 000,001,435 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\PowerStrip.lnk
[2010/03/29 19:48:36 | 000,008,463 | —- | C] () – C:\Users\ZSnake\AppData\Roaming\PStrip.ini
[2010/03/29 19:40:04 | 000,000,063 | —- | C] () – C:\Windows\wininit.ini
[2010/03/29 16:14:43 | 000,000,990 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/29 15:21:16 | 000,002,023 | —- | C] () – C:\Users\Public\Desktop\Avira AntiVir Control Center.lnk
[2010/03/29 14:43:49 | 000,001,896 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/03/29 14:36:21 | 000,000,020 | RHS- | C] () – C:\winx.ld
[2010/03/29 14:36:19 | 000,205,098 | RHS- | C] () – C:\GQILH
[2010/03/29 01:19:12 | 000,000,020 | -HS- | C] () – C:\Users\ZSnake\ntuser.ini
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/03/29 01:19:11 | 000,524,288 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/03/29 01:19:11 | 000,065,536 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/03/29 01:19:01 | 001,310,720 | -HS- | C] () – C:\Users\ZSnake\NTUSER.DAT
[2010/03/29 00:44:23 | 703,156,224 | -HS- | C] () – C:\hiberfil.sys
[2010/03/28 21:15:53 | 000,000,330 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211551.reg
[2010/03/28 21:15:24 | 000,010,702 | —- | C] () – C:\Users\ZSnake\Documents\cc_20100328_211520.reg
[2009/07/13 16:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 16:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI