This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] AntiVirus XP and Your Protection

40 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Tom - F8 (Last good) fails also to let me log in.

From a quick inspection of the Qoobox logs, ComboFix removed userinit.exe (saved it as userinit.exe.vir). That copy is all wrong - wrong size, wrong attributes, wrong date, wrong everything.

Question: Will you be able to assist me further with the XP problem - log-in/log-out problem? Or should I go elsewhere to solve it and then return when I'm able to log on again?

Important Note: I have to apologize sincerely for whining in the update note. As I pointed out, I failed to see there was a reply at page 2. I'll know better next time to look more carefully. When you refresh page 1 it always returns just to page 1 (naturally) so if you're not aware that page 2 is sitting there…. Fully my fault and I'm so embarrassed! I don't want or need to tick anybody off…

H
Ok,

Please boot into the recovery console, press 1 when you get asked which windows installation you will choose and type in the admin password if you have set one. At the command prompt, type the following line by line:


cd erdnt\subs
and hit enter

batch erdnt.con and hit enter

copy c:\windows\ServicePackFiles\i386\userinit.exe c:\windows\SYSTEM32 and hit enter.



If you get a message if you will overwrite an existing file, choose yes. Then type in exit and the system will reboot. Are you able to boot now?
Progress (sort of…): Able to log on and stay logged on now. First time through showed me: Windows cannot open rundll32.exe. Would you like to search the net or browse to a file to open it (paraphased). Logged off and restarted. It installed 8 updates of some kind and restarted. Now faced with the standard NT style log on screen rather than the username/icon combination. Apparently userinit.exe (though it had all the same attributes as other userinits I have around here), was corrupt. Second log on - When I log on now, I get a CF error probably due to a leftover from CF. "Windows cannot find C:\CF\cf26651.cfxxe". Dismiss it. The desktop is totally different - a sign that the user profile has been damaged. Wallpaper diff - Dell standard wallpap - no problem. Most folders/files/shortcuts out of the My Document and Desktop objects are gone. Located them in a folder called "ERDUndoCache". Also, I was able to get most of those copied off to an external HDD way back when anyway. IE icon appears it's normal blue self but double-click fails to launch and just creates another shortcut to it on the desktop. Hit it again and a third shortcut appears and so forth. Dbl-click on the MBAM icon and it starts to install it. Cancel out. Right click any desktop icon, no "Open" option. Dbl-click a folder on the desktop and it opens OK. Unable to Start > Run - immediately yields a "Run is not a valid Win32 command". Am able to hit WindowsKey-R > "command" and open a DOS window. But not able to execute "cmd" from this point. Also, in Control Panel, and various other spots, most of the applets/apps respond with "Rundll32.exe is not a valid Win32 application". This thing is really hosed, man…. At some point are we due to say, "Bag it and reinstall"? I hate giving up on these things! How about you? Standing by… for supper and your next words. H
Nah, reinstall is not my thing :)

Please run OTL again, under the custom scan paste in the following and hit the run scan button:

netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
eventlog.dll
scecli.dll
netlogon.dll
cngaudit.dll
sceclt.dll
ntelogon.dll
logevent.dll
iaStor.sys
nvstor.sys
atapi.sys
IdeChnDr.sys
viasraid.sys
AGP440.sys
vaxscsi.sys
nvatabus.sys
viamraid.sys
nvata.sys
nvgts.sys
iastorv.sys
ViPrt.sys
eNetHook.dll
ahcix86.sys
KR10N.sys
nvstor32.sys
ahcix86s.sys
nvrd32.sys
symmpi.sys
adp3132.sys
mv61xx.sys
userinit.exe
rundll32.exe
winlogon.exe
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\System32\config\*.sav
Hello and good morning Tom - Stymied again…. The CF error no longer appears. The unable to associate rundll32 with an app no longer appears. Because we've lost the ability to launch any apps in normal mode, I went to Safe Mode - no networking, no command. So, in Safe Mode: Dbl-left-clik on OTL yields: OTL.exe is not a valid Win32 application. Rt-clik on OTL and Run as () yields: A device attached is not running Rt-clik on OTL and Run as (Administrator) yields: The service cannot be started in Safe Mode. Observations: In Safe mode I can launch apps like MBAM, FireFox whereas in Normal Mode I can't. Note that I have a few resources here: Hiren's BCD, BartPE and Ultimate Boot CD but I believe these aren't much good if we can't load registry hives and get some sort of working copy of Windows up and running. I then used a restore point utility (ERD) to only look for any restore points earlier than 4/15. None exists. Quit. OK, I'm around all day. Will be out back chopping/sawing some deadfall. H
We can try something different, if you haven't dialup connection.


OK this file is big Print these instruction out so that you know what you are doing

Two programmes to download

First

ISOBurner this will allow you to burn OTLPE ISO to a cd and make it bootable. Just install the programme, from there on in it is fairly automatic. Instructions

Second
  • Download OTLPE.iso and burn to a CD using ISO Burner. NOTE: This file is 292Mb in size so it may take some time to download.
  • When downloaded double click and this will then open ISOBurner to burn the file to CD
  • Reboot your system using the boot CD you just created.

    Note : If you do not know how to set your computer to boot from CD follow the steps here
  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to Non-Microsoft
  • Under the custom scan box, please paste in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    userinit.exe
    rundll32.exe
    winlogon.exe
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\_OTL\MovedFiles
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the OTL.txt file in your reply.
OK, Tom. Soldiering on… Three issues now with REATOGO - First, I'm skilled with burning CDs so I took the liberty of using another .ISO program I have that burns images. Burned this image at 4X. Second, REATOGO's desktop took about 10 minutes to boot up. I believe this is Normal (though painfully long! :-) ). Scan/Command list in a .txt file on a thumb drive. Launched OTL from this desktop. I did watch very carefully what I was doing. I do not get the "Load Remote Registry" prompt. I do get the remote user profile/Auto selection. I do not see any where in this version (vers 3.1.37.2) to Change Drivers to Non-Microsoft. I do see three choices: None, Safe List. All. I do not see a custom scan box (as I remember seeing with the first version). Attempted to see if I could launch first version: gets me - OTL is not a valid Win32 app. Let me show what the screen and app look like by attaching an image. Maybe you can show/tell me where these options are. Since this took so long to boot, I've left it as is until…. Standing by… H I keep looking for "Page 3"… :-)

Attachments:

Hi, Please put every box to "use safe list", also at the bottom of the program, there is the great custom scan/fixes box :) Are you able to launch the tool now?
OH DUHH!
You just paste the commands/parms INTO that box at the bottom. I was looking for some sort of additional input box.
What a dunce!

Set all the Safe Lists and scanning is now underway. I'll be back shortly with the results.

The results:

OTL logfile created on: 4/20/2010 8:01:38 AM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 231.00 Mb Available Physical Memory | 45.00% Memory free
459.00 Mb Paging File | 280.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 23.33 Gb Free Space | 61.00% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 458.86 Gb Free Space | 98.52% Space Free | Partition Type: NTFS
Drive E: | 981.05 Mb Total Space | 962.00 Mb Free Space | 98.06% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet004

========== Win32 Services (SafeList) ==========

SRV - File not found [On_Demand] – – (TuneUp.Defrag)
SRV - File not found [On_Demand] – – (getPlus® Helper) getPlus®
SRV - File not found [Auto] – – (aawservice)
SRV - [2009/04/27 01:22:08 | 000,020,680 | —- | M] (ESET) [On_Demand] – C:\Program Files\ESET\ESET Smart Security\EHttpSrv.exe – (EhttpSrv)
SRV - [2009/04/27 01:22:04 | 000,731,840 | —- | M] (ESET) [Auto] – C:\Program Files\ESET\ESET Smart Security\ekrn.exe – (ekrn)
SRV - [2008/07/26 08:25:36 | 000,150,040 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe – (LVPrcSrv)
SRV - [2008/07/26 08:23:42 | 000,186,904 | —- | M] (Logitech Inc.) [Auto] – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe – (LVCOMSer)
SRV - [2008/02/23 15:45:17 | 000,658,432 | —- | M] (Macrovision Europe Ltd.) [On_Demand] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2007/09/11 00:45:04 | 000,124,832 | —- | M] () [Auto] – C:\Program Files\Adobe\Photoshop Elements 6.0\PhotoshopElementsFileAgent.exe – (AdobeActiveFileMonitor6.0)
SRV - [2007/08/09 03:27:52 | 000,098,304 | —- | M] (HP) [Auto] – C:\WINDOWS\SYSTEM32\HPZipm12.exe – (Pml Driver HPZ12)
SRV - [2007/03/07 16:47:46 | 000,076,848 | —- | M] () [On_Demand] – C:\Program Files\DellSupport\brkrsvc.exe – (DSBrokerService)
SRV - [2007/01/04 17:38:08 | 000,049,152 | —- | M] (Viewpoint Corporation) [Disabled] – C:\Program Files\Viewpoint\Common\ViewpointService.exe – (Viewpoint Manager Service)
SRV - [2005/04/27 14:59:24 | 000,266,240 | —- | M] (Microsoft Corporation) [Auto] – C:\Program Files\UPHClean\uphclean.exe – (UPHClean)
SRV - [2003/03/03 14:33:40 | 000,143,360 | —- | M] (Intel® Corporation) [On_Demand] – C:\Program Files\Intel\NCS\Sync\NetSvc.exe – (NetSvc)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] – – (WDICA)
DRV - File not found [Kernel | Boot] – – (vkquwexg)
DRV - File not found [Kernel | On_Demand] – – (PDRFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDRELI)
DRV - File not found [Kernel | On_Demand] – – (PDFRAME)
DRV - File not found [Kernel | On_Demand] – – (PDCOMP)
DRV - File not found [Kernel | System] – – (PCIDump)
DRV - File not found [Kernel | System] – – (lbrtfdc)
DRV - File not found [Kernel | System] – – (easdrv)
DRV - File not found [Kernel | System] – – (Changer)
DRV - File not found [Kernel | On_Demand] – – (catchme)
DRV - File not found [Kernel | On_Demand] – – (bvrp_pci)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Registry Filter)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Real-Time Scanner)
DRV - File not found [Kernel | On_Demand] – – (Ad-Watch Connect Filter)
DRV - [2009/04/27 01:22:12 | 000,113,960 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\eamon.sys – (eamon)
DRV - [2009/04/27 01:22:08 | 000,033,096 | —- | M] (ESET) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwndis.sys – (Epfwndis)
DRV - [2009/04/27 01:22:04 | 000,131,976 | —- | M] (ESET) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\epfw.sys – (epfw)
DRV - [2009/04/27 01:22:04 | 000,055,768 | —- | M] (ESET) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\epfwtdi.sys – (epfwtdi)
DRV - [2008/07/26 11:26:56 | 000,023,832 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvcflt.sys – (FilterService)
DRV - [2008/07/26 11:26:44 | 004,658,584 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvuvc.sys – (LVUVC) Logitech QuickCam S5500(UVC)
DRV - [2008/07/26 11:26:22 | 000,041,752 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVUSBSta.sys – (LVUSBSta)
DRV - [2008/07/26 11:25:48 | 000,627,864 | R— | M] (Logitech Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\lvrs.sys – (LVRS)
DRV - [2008/07/26 08:25:02 | 000,025,624 | —- | M] () [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\LVPr2Mon.sys – (LVPr2Mon)
DRV - [2008/05/02 22:46:00 | 006,554,496 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys – (nv)
DRV - [2008/04/13 14:45:12 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\usbaudio.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 14:36:39 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/13 14:36:39 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2007/04/23 14:11:54 | 000,224,896 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wg111v3.sys – (RTL8187B)
DRV - [2007/02/25 13:10:48 | 000,005,376 | –S- | M] (Gteko Ltd.) [Kernel | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\dsunidrv.sys – (dsunidrv)
DRV - [2006/10/05 17:07:28 | 000,004,736 | —- | M] (Gteko Ltd.) [Kernel | On_Demand] – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys – (DSproct)
DRV - [2005/02/23 14:58:56 | 000,011,776 | —- | M] (Arcsoft, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\afc.sys – (Afc)
DRV - [2004/08/04 01:29:49 | 000,019,455 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wvchntxx.sys – (iAimFP4)
DRV - [2004/08/04 01:29:47 | 000,012,063 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wsiintxx.sys – (iAimFP3)
DRV - [2004/08/04 01:29:45 | 000,023,615 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wch7xxnt.sys – (iAimTV4)
DRV - [2004/08/04 01:29:43 | 000,033,599 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv04nt.sys – (iAimTV3)
DRV - [2004/08/04 01:29:42 | 000,019,551 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv02nt.sys – (iAimTV1)
DRV - [2004/08/04 01:29:41 | 000,029,311 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\watv01nt.sys – (iAimTV0)
DRV - [2004/08/04 01:29:37 | 000,012,415 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv01nt.sys – (iAimFP0)
DRV - [2004/08/04 01:29:37 | 000,012,127 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv02nt.sys – (iAimFP1)
DRV - [2004/08/04 01:29:37 | 000,011,775 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wadv05nt.sys – (iAimFP2)
DRV - [2004/08/04 01:29:36 | 000,161,020 | —- | M] (Intel® Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\i81xnt5.sys – (i81x)
DRV - [2003/08/29 04:59:24 | 001,101,696 | —- | M] (Broadcom Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\BCMSM.sys – (BCMModem)
DRV - [2003/08/06 02:04:00 | 000,100,373 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudfa.sys – (tfsnudfa)
DRV - [2003/08/06 02:04:00 | 000,098,068 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnudf.sys – (tfsnudf)
DRV - [2003/08/06 02:04:00 | 000,083,284 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnifs.sys – (tfsnifs)
DRV - [2003/08/06 02:04:00 | 000,034,837 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsncofs.sys – (tfsncofs)
DRV - [2003/08/06 02:04:00 | 000,025,685 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnboio.sys – (tfsnboio)
DRV - [2003/08/06 02:04:00 | 000,014,229 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnopio.sys – (tfsnopio)
DRV - [2003/08/06 02:04:00 | 000,006,357 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsnpool.sys – (tfsnpool)
DRV - [2003/08/06 02:04:00 | 000,004,117 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndrct.sys – (tfsndrct)
DRV - [2003/08/06 02:04:00 | 000,002,233 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\dla\tfsndres.sys – (tfsndres)
DRV - [2003/07/31 04:21:00 | 000,084,576 | —- | M] (Sonic Solutions) [Kernel | Boot] – C:\WINDOWS\SYSTEM32\DRIVERS\drvmcdb.sys – (drvmcdb)
DRV - [2003/07/14 12:28:40 | 000,005,621 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\sscdbhk5.sys – (sscdbhk5)
DRV - [2003/07/14 12:28:22 | 000,023,219 | —- | M] (Sonic Solutions) [File_System | System] – C:\WINDOWS\SYSTEM32\DRIVERS\ssrtln.sys – (ssrtln)
DRV - [2003/06/20 03:56:00 | 000,040,448 | —- | M] (Sonic Solutions) [File_System | Auto] – C:\WINDOWS\SYSTEM32\DRIVERS\drvnddm.sys – (drvnddm)
DRV - [2002/11/08 14:45:06 | 000,017,217 | —- | M] (Dell Computer Corporation) [Kernel | System] – C:\WINDOWS\SYSTEM32\DRIVERS\omci.sys – (omci)
DRV - [2002/10/08 12:57:40 | 000,033,588 | —- | M] (America Online, Inc.) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\wanatw4.sys – (wanatw) WAN Miniport (ATW)
DRV - [2001/08/17 15:07:44 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2001/08/17 15:07:42 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2001/08/17 15:07:40 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2001/08/17 15:07:36 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2001/08/17 15:07:34 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\symc810.sys – (symc810)
DRV - [2001/08/17 14:57:38 | 000,016,128 | —- | M] (Microsoft Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys – (MODEMCSA)
DRV - [2001/08/17 14:52:22 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ultra.sys – (ultra)
DRV - [2001/08/17 14:52:20 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2001/08/17 14:52:20 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2001/08/17 14:52:18 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2001/08/17 14:52:16 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2001/08/17 14:52:12 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2001/08/17 14:52:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc.sys – (asc)
DRV - [2001/08/17 14:51:58 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2001/08/17 14:51:56 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\aliide.sys – (AliIde)
DRV - [2001/08/17 14:51:54 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Disabled] – C:\WINDOWS\System32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2001/08/17 13:11:06 | 000,066,591 | —- | M] (3Com Corporation) [Kernel | On_Demand] – C:\WINDOWS\SYSTEM32\DRIVERS\EL90XBC5.SYS – (EL90XBC)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com


IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Andrew_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\Cynthia_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\LocalService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,First Home Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
IE - HKU\NetworkService_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF - prefs.js..extensions.enabledItems: [removed]:1.0

FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/17 22:40:30 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/03 10:15:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2010/04/15 19:11:34 | 000,000,000 | —D | M]

[2010/04/17 22:40:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Extensions
[2010/04/17 22:40:44 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions
[2010/04/17 22:40:49 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/17 22:40:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Andrew\Application Data\Mozilla\Firefox\Profiles\m9b8jnuc.default\extensions\staged-xpis
[2010/04/08 16:42:56 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2010/04/18 09:57:24 | 000,000,027 | —- | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 www.Brenz.pl
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKU\.DEFAULT\..\Toolbar\WebBrowser: (AOL Toolbar) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll (AOL LLC)
O4 - HKLM..\Run: [combofix] C:\CF\CF26651.cfx File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [qyfvwm] C:\WINDOWS\System32\msejfzrl.DLL File not found
O4 - HKU\Andrew_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Andrew_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\Cynthia_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\Cynthia_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\LocalService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\LocalService_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKU\NetworkService_ON_C..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKU\NetworkService_ON_C..\Run: [Sonic RecordNow!] File not found
O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
F3 - HKU\.DEFAULT WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
F3 - HKU\.DEFAULT WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
F3 - HKU\Andrew_ON_C WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
F3 - HKU\Andrew_ON_C WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Main present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: mslivemsn = C:\Program Files\Windows NT\Accessories\svchost.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: exec = C:\WINDOWS\fonts\services.exe ()
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKU\Andrew_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\Cynthia_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll File not found
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\SYSTEM32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/e/7…/OGAControl.cab (Office Genuine Advantage Validation Tool)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.microsoft.com/download/E/5…heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {193C772A-87BE-4B19-A7BB-445B226FE9A1} http://downloads.ewido.net/ewidoOnlineScan.cab (ewidoOnlineScan Control)
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} http://download.microsoft.com/download/0/5…b?1076002397078 (MSSecurityAdvisor Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1120230108640 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: B:\Documents and Settings\Default User\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/09/03 14:36:02 | 000,000,000 | -HS- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/10/13 17:19:36 | 000,000,067 | —- | M] () - D:\autorun.inf – [ NTFS ]
O32 - AutoRun File - [2010/04/18 09:54:24 | 000,000,028 | —- | M] () - E:\AUTORUN.INF – [ FAT32 ]
O32 - AutoRun File - [2006/03/24 07:06:41 | 000,000,053 | R— | M] () - X:\AUTORUN.INF – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (stera) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/04/18 09:54:16 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Mozilla
[2010/04/17 22:40:24 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Mozilla
[2010/04/17 22:40:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Malwarebytes
[2010/04/17 22:38:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\GTek
[2010/04/17 18:57:50 | 000,200,192 | —- | C] (-) – C:\WINDOWS\System32\3308329.exe
[2010/04/17 18:55:54 | 000,000,000 | -HSD | C] – C:\Documents and Settings\NetworkService\Cookies
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Macromedia
[2010/04/17 18:47:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Identities
[2010/04/17 18:47:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\Cynthia\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\SendTo
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Recent
[2010/04/17 18:47:41 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Cynthia\Application Data
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Start Menu
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Pictures
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents\My Music
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\My Documents
[2010/04/17 18:47:41 | 000,000,000 | R–D | C] – C:\Documents and Settings\Cynthia\Favorites
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Templates
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\PrintHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\NetHood
[2010/04/17 18:47:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Cynthia\Local Settings
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sun
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Sonic
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Application Data\Real
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\Microsoft
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Desktop
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\ApplicationHistory
[2010/04/17 18:47:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Cynthia\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Utilities
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Unused Desktop Shortcuts
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\TomAdamczyk
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\The Letter
[2010/04/17 18:46:00 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\SeacoastOrientalRugEnvlogo
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\sallie
[2010/04/17 18:45:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\R. conley
[2010/04/17 18:45:58 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\PPS Files
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\patti
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\P. Montrone
[2010/04/17 18:45:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Nilsson
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\m
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Kremans
[2010/04/17 18:45:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\joe
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Izabelle's 8th Bday & jumping Pandy 07 054
[2010/04/17 18:45:55 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Humor
[2010/04/17 18:45:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\Hide These Temp
[2010/04/17 18:45:35 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop\elena
[2010/04/17 18:44:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\My Documents\Advanta_files
[2010/04/17 18:39:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Share-to-Web Upload Folder
[2010/04/17 18:36:51 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ESET
[2010/04/17 18:36:34 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\ESET
[2010/04/17 18:16:56 | 000,000,000 | —D | C] – C:\~ErdUserProfile.$$$
[2010/04/17 17:58:17 | 000,000,000 | -HSD | C] – C:\Documents and Settings\Andrew\Cookies
[2010/04/17 17:58:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google
[2010/04/17 17:57:47 | 000,000,000 | –SD | C] – C:\Documents and Settings\Andrew\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\SendTo
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Recent
[2010/04/17 17:57:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Andrew\Application Data
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Start Menu
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Pictures
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents\My Music
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\My Documents
[2010/04/17 17:57:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\Andrew\Favorites
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Templates
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\PrintHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\NetHood
[2010/04/17 17:57:47 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Andrew\Local Settings
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sun
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Sonic
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Real
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Macromedia
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Application Data\Identities
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Desktop
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\ApplicationHistory
[2010/04/17 17:57:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Andrew\Local Settings\Application Data\{7148F0A6-6813-11D6-A77B-00B0D0142000}
[2010/04/17 17:57:43 | 000,000,000 | -HSD | C] – C:\Documents and Settings\LocalService\Cookies
[2010/04/17 17:57:41 | 000,000,000 | –SD | C] – C:\Documents and Settings\LocalService\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | -H-D | C] – C:\Documents and Settings\LocalService\Local Settings
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:41 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data
[2010/04/17 17:57:37 | 000,000,000 | –SD | C] – C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Local Settings
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[2010/04/17 17:57:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data
[2010/04/17 09:35:05 | 000,200,192 | —- | C] (-) – C:\WINDOWS\System32\4081797.exe
[2010/04/17 09:34:19 | 000,093,184 | —- | C] (icon company) – C:\WINDOWS\System32\w.exe
[2010/04/17 05:24:24 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\userinit.exe
[2010/04/17 04:35:31 | 000,000,000 | -H-D | C] – C:\ErdUndoCache
[2010/04/16 07:21:01 | 000,044,544 | —- | C] (lowest systems) – C:\WINDOWS\System32\so.bin
[2010/04/16 07:21:01 | 000,036,864 | —- | C] (irbg fmt hapu nyusqyan) – C:\WINDOWS\System32\d.bin
[2010/04/16 07:21:01 | 000,034,304 | —- | C] (dreas company) – C:\WINDOWS\System32\ms.bin
[2010/04/16 07:20:49 | 000,000,000 | —D | C] – C:\Program Files\Protection System
[2010/04/15 19:32:45 | 000,000,000 | —D | C] – C:\Program Files\Raxco
[2010/04/15 19:15:47 | 000,000,000 | —D | C] – C:\Program Files\Glary Utilities
[2010/04/15 17:58:59 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/12 23:40:08 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/04/12 22:57:38 | 000,000,000 | —D | C] – C:\WINDOWS\temp
[2010/04/12 22:36:43 | 000,000,000 | RHSD | C] – C:\cmdcons
[2010/04/12 22:33:20 | 000,057,856 | —- | C] (NirSoft) – C:\WINDOWS\NIRCMD.exe
[2010/04/12 08:26:57 | 000,000,000 | —D | C] – C:\OEMSettings
[2010/04/12 08:25:41 | 000,000,000 | —D | C] – C:\Program Files\NETGEAR
[2010/04/11 23:24:06 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/11 23:24:01 | 000,020,824 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/11 23:23:59 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/04/10 14:18:54 | 000,212,480 | —- | C] (SteelWerX) – C:\WINDOWS\SWXCACLS.exe
[2010/04/10 14:18:54 | 000,161,792 | —- | C] (SteelWerX) – C:\WINDOWS\SWREG.exe
[2010/04/10 14:18:54 | 000,136,704 | —- | C] (SteelWerX) – C:\WINDOWS\SWSC.exe
[2010/04/10 14:18:34 | 000,000,000 | —D | C] – C:\WINDOWS\ERDNT
[2010/04/10 14:16:49 | 000,000,000 | —D | C] – C:\Qoobox
[2010/04/09 07:21:46 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/04/09 06:59:38 | 000,000,000 | —D | C] – C:\Infection
[2005/05/11 23:36:48 | 000,012,288 | —- | C] (Hewlett-Packard Co.) – C:\WINDOWS\Fonts\RandFont.dll

========== Files - Modified Within 30 Days ==========

[2010/04/18 12:30:53 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/18 11:09:58 | 000,786,432 | -H– | M] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/18 11:09:40 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/04/18 11:09:38 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/18 11:09:34 | 004,240,656 | -H– | M] () – C:\Documents and Settings\Andrew\Local Settings\Application Data\IconCache.db
[2010/04/18 09:57:31 | 000,001,170 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/04/18 09:57:24 | 000,000,027 | —- | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/04/18 09:56:12 | 000,786,432 | -H– | M] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/18 09:55:51 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/04/18 09:54:19 | 000,000,882 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2010/04/18 09:54:18 | 000,000,488 | —- | M] () – C:\WINDOWS\tasks\1-Click Maintenance.job
[2010/04/18 09:54:18 | 000,000,314 | —- | M] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/17 22:30:00 | 000,000,886 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2010/04/17 22:24:00 | 000,000,982 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007UA.job
[2010/04/17 21:06:07 | 000,036,864 | —- | M] (irbg fmt hapu nyusqyan) – C:\WINDOWS\System32\d.bin
[2010/04/17 21:00:52 | 000,093,184 | —- | M] (icon company) – C:\WINDOWS\System32\w.exe
[2010/04/17 21:00:28 | 000,044,544 | —- | M] (lowest systems) – C:\WINDOWS\System32\so.bin
[2010/04/17 21:00:28 | 000,034,304 | —- | M] (dreas company) – C:\WINDOWS\System32\ms.bin
[2010/04/17 18:57:56 | 000,000,098 | —- | M] () – C:\auywg93w108.bat
[2010/04/17 18:57:50 | 000,200,192 | —- | M] (-) – C:\WINDOWS\System32\3308329.exe
[2010/04/17 18:57:43 | 000,048,640 | —- | M] () – C:\WINDOWS\System32\5992788.exe
[2010/04/17 18:57:43 | 000,000,120 | —- | M] () – C:\WINDOWS\System32\221953.BAT
[2010/04/17 18:57:39 | 000,167,842 | —- | M] () – C:\WINDOWS\System32\9529993.exe
[2010/04/17 18:48:03 | 000,786,432 | -H– | M] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:48:03 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:38:47 | 000,000,104 | —- | M] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:07:10 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/17 09:35:05 | 000,200,192 | —- | M] (-) – C:\WINDOWS\System32\4081797.exe
[2010/04/17 09:34:27 | 000,000,120 | —- | M] () – C:\WINDOWS\System32\258468.BAT
[2010/04/17 09:34:24 | 000,048,640 | —- | M] () – C:\WINDOWS\System32\7490743.exe
[2010/04/17 09:34:24 | 000,036,865 | —- | M] () – C:\WINDOWS\System32\mshwolkt.dll
[2010/04/17 09:34:18 | 000,167,842 | —- | M] () – C:\WINDOWS\System32\9965326.exe
[2010/04/16 07:23:47 | 000,000,098 | —- | M] () – C:\dt5rwef3c108.bat
[2010/04/16 07:23:44 | 000,175,616 | —- | M] () – C:\WINDOWS\System32\1445689.EXE
[2010/04/16 07:21:00 | 000,166,735 | —- | M] () – C:\WINDOWS\System32\2607364.exe
[2010/04/16 07:20:49 | 000,000,000 | —- | M] () – C:\WINDOWS\SC.INS
[2010/04/16 07:20:49 | 000,000,000 | —- | M] () – C:\WINDOWS\sc.exe
[2010/04/15 19:06:39 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\598736.exe
[2010/04/15 19:06:24 | 000,182,038 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2010/04/15 18:58:03 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\1762964.exe
[2010/04/15 18:28:48 | 000,001,964 | —- | M] () – C:\WINDOWS\disney.ini
[2010/04/15 18:02:04 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\960657.exe
[2010/04/14 18:31:58 | 000,000,664 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/14 18:31:16 | 000,007,680 | —- | M] () – C:\WINDOWS\System32\8833994.exe
[2010/04/14 18:31:05 | 000,036,865 | —- | M] () – C:\WINDOWS\System32\mslgqlaj.dll
[2010/04/14 18:30:56 | 000,167,773 | —- | M] () – C:\WINDOWS\System32\7473871.exe
[2010/04/14 18:14:01 | 000,000,292 | —- | M] () – C:\WINDOWS\system.ini
[2010/04/12 22:36:56 | 000,000,281 | RHS- | M] () – C:\BOOT.INI
[2010/04/11 10:24:00 | 000,000,930 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-217248739-2920639104-3160564834-1007Core.job
[2010/04/10 14:53:20 | 000,006,456 | -H– | M] () – C:\WINDOWS\System32\wolejifu
[2010/04/09 17:14:00 | 000,000,749 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/04/09 17:14:00 | 000,000,211 | —- | M] () – C:\Boot.bak
[2010/04/08 20:17:45 | 000,000,882 | —- | M] () – C:\WINDOWS\orun32.ini
[2010/04/05 15:04:51 | 000,000,127 | —- | M] () – C:\WINDOWS\wininit.ini
[2010/04/05 12:02:32 | 000,077,062 | —- | M] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/05 11:59:02 | 000,004,017 | —- | M] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/03/30 00:46:30 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/03/30 00:45:52 | 000,020,824 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/03/26 05:23:51 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\lvuvc.hs
[2010/03/26 05:23:49 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\logiflt.iad
[2010/03/25 14:05:47 | 000,000,293 | —- | M] () – C:\WINDOWS\iPlayer.INI

========== Files Created - No Company Name ==========

[2010/04/17 18:57:43 | 000,048,640 | —- | C] () – C:\WINDOWS\System32\5992788.exe
[2010/04/17 18:57:43 | 000,000,120 | —- | C] () – C:\WINDOWS\System32\221953.BAT
[2010/04/17 18:57:39 | 000,167,842 | —- | C] () – C:\WINDOWS\System32\9529993.exe
[2010/04/17 18:47:41 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Cynthia\NTUSER.DAT
[2010/04/17 18:47:41 | 000,008,192 | -H– | C] () – C:\Documents and Settings\Cynthia\ntuser.dat.LOG
[2010/04/17 18:47:41 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Cynthia\NTUSER.INI
[2010/04/17 18:44:34 | 002,392,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Ey Iran.pps
[2010/04/17 18:44:34 | 000,728,850 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ISLAMICOSCARGOESTO.wmv
[2010/04/17 18:44:34 | 000,460,690 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Cash002.zip
[2010/04/17 18:44:34 | 000,455,999 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Heriz ka.pdf
[2010/04/17 18:44:34 | 000,301,056 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ANDREWSLIST.xls
[2010/04/17 18:44:34 | 000,226,340 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Andrewslist.123
[2010/04/17 18:44:34 | 000,068,096 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Invoice.doc
[2010/04/17 18:44:34 | 000,025,600 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Gift Certificate.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Espacio Design 4.doc
[2010/04/17 18:44:34 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Appraisal letter March 30.doc
[2010/04/17 18:44:34 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\ITALIAN.doc
[2010/04/17 18:44:34 | 000,000,794 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Bidjar 11.7 X18.9.lnk
[2010/04/17 18:44:34 | 000,000,761 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Get High Speed Internet!.lnk
[2010/04/17 18:44:33 | 000,486,272 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Speedsters.jpg
[2010/04/17 18:44:33 | 000,438,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Vahid.zip
[2010/04/17 18:44:33 | 000,430,592 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\123.pps
[2010/04/17 18:44:33 | 000,383,424 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\2008 Tagavi A Form 1040 Individual Tax Return.tax2008
[2010/04/17 18:44:33 | 000,227,684 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\5.5 X 7.9.JPG
[2010/04/17 18:44:33 | 000,154,870 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\AhundovFamilyTree.zip
[2010/04/17 18:44:33 | 000,122,300 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Setade_Koodeta.pdf
[2010/04/17 18:44:33 | 000,092,672 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\rug cleaning certificate.doc
[2010/04/17 18:44:33 | 000,077,062 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\SeacoastOrientalRugEnvlogo.zip
[2010/04/17 18:44:33 | 000,060,587 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\pelosinowruzletter_3.08.pdf
[2010/04/17 18:44:33 | 000,050,176 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\warm up certificate.doc
[2010/04/17 18:44:33 | 000,040,960 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\saddle fitting.doc
[2010/04/17 18:44:33 | 000,034,775 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\LtrtoclientwithdraftlettertoAttyMiller9-6-07.wpd.zip
[2010/04/17 18:44:33 | 000,029,184 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News.doc
[2010/04/17 18:44:33 | 000,026,624 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Nicker News #3 2nd edition.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Taylor.doc
[2010/04/17 18:44:33 | 000,026,112 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\seacoast media.doc
[2010/04/17 18:44:33 | 000,025,088 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tonry.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\TUFTED.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted rugs.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Tufted 2.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Sale.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\sale sideways.doc
[2010/04/17 18:44:33 | 000,024,064 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Persian.doc
[2010/04/17 18:44:33 | 000,022,090 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Advanta.htm
[2010/04/17 18:44:33 | 000,020,992 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\nicker news3.doc
[2010/04/17 18:44:33 | 000,004,017 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\OrientalRugLogo-Letterhead.htm
[2010/04/17 18:44:33 | 000,000,440 | —- | C] () – C:\Documents and Settings\Andrew\My Documents\Shortcut to Vendors.lnk
[2010/04/17 18:38:47 | 000,000,104 | —- | C] () – C:\Documents and Settings\Andrew\Desktop\Shortcut to Internet Explorer.lnk
[2010/04/17 18:01:18 | 000,001,374 | —- | C] () – C:\WINDOWS\imsins.BAK
[2010/04/17 17:57:47 | 000,012,288 | -H– | C] () – C:\Documents and Settings\Andrew\ntuser.dat.LOG
[2010/04/17 17:57:47 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\Andrew\NTUSER.INI
[2010/04/17 17:57:46 | 000,786,432 | -H– | C] () – C:\Documents and Settings\Andrew\NTUSER.DAT
[2010/04/17 17:57:40 | 000,786,432 | -H– | C] () – C:\Documents and Settings\LocalService\NTUSER.DAT
[2010/04/17 17:57:40 | 000,008,192 | -H– | C] () – C:\Documents and Settings\LocalService\ntuser.dat.LOG
[2010/04/17 17:57:40 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\LocalService\NTUSER.INI
[2010/04/17 17:57:37 | 000,008,192 | -H– | C] () – C:\Documents and Settings\NetworkService\ntuser.dat.LOG
[2010/04/17 17:57:37 | 000,000,180 | -HS- | C] () – C:\Documents and Settings\NetworkService\NTUSER.INI
[2010/04/17 17:57:36 | 000,786,432 | -H– | C] () – C:\Documents and Settings\NetworkService\NTUSER.DAT
[2010/04/17 09:35:12 | 000,000,098 | —- | C] () – C:\auywg93w108.bat
[2010/04/17 09:34:27 | 000,000,120 | —- | C] () – C:\WINDOWS\System32\258468.BAT
[2010/04/17 09:34:24 | 000,048,640 | —- | C] () – C:\WINDOWS\System32\7490743.exe
[2010/04/17 09:34:24 | 000,036,865 | —- | C] () – C:\WINDOWS\System32\mshwolkt.dll
[2010/04/17 09:34:18 | 000,167,842 | —- | C] () – C:\WINDOWS\System32\9965326.exe
[2010/04/17 04:35:35 | 000,168,140 | —- | C] () – C:\WINDOWS\System32\960657.exe
[2010/04/17 04:35:35 | 000,168,140 | —- | C] () – C:\WINDOWS\System32\1762964.exe
[2010/04/17 04:35:34 | 000,168,140 | —- | C] () – C:\WINDOWS\System32\598736.exe
[2010/04/16 13:34:24 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NtUser.dat.bartbackup1
[2010/04/16 07:23:47 | 000,000,098 | —- | C] () – C:\dt5rwef3c108.bat
[2010/04/16 07:23:44 | 000,175,616 | —- | C] () – C:\WINDOWS\System32\1445689.EXE
[2010/04/16 07:21:00 | 000,166,735 | —- | C] () – C:\WINDOWS\System32\2607364.exe
[2010/04/16 07:20:49 | 000,000,000 | —- | C] () – C:\WINDOWS\SC.INS
[2010/04/16 07:20:49 | 000,000,000 | —- | C] () – C:\WINDOWS\sc.exe
[2010/04/15 19:15:53 | 000,000,314 | —- | C] () – C:\WINDOWS\tasks\GlaryInitialize.job
[2010/04/14 18:31:16 | 000,007,680 | —- | C] () – C:\WINDOWS\System32\8833994.exe
[2010/04/14 18:31:05 | 000,036,865 | —- | C] () – C:\WINDOWS\System32\mslgqlaj.dll
[2010/04/14 18:30:56 | 000,167,773 | —- | C] () – C:\WINDOWS\System32\7473871.exe
[2010/04/12 22:36:55 | 000,000,211 | —- | C] () – C:\Boot.bak
[2010/04/12 22:36:48 | 000,260,272 | —- | C] () – C:\cmldr
[2010/04/10 14:18:54 | 000,261,632 | —- | C] () – C:\WINDOWS\PEV.exe
[2010/04/10 14:18:54 | 000,098,816 | —- | C] () – C:\WINDOWS\sed.exe
[2010/04/10 14:18:54 | 000,080,412 | —- | C] () – C:\WINDOWS\grep.exe
[2010/04/10 14:18:54 | 000,077,312 | —- | C] () – C:\WINDOWS\MBR.exe
[2010/04/10 14:18:54 | 000,068,096 | —- | C] () – C:\WINDOWS\zip.exe
[2010/04/07 17:05:10 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/04/05 15:04:51 | 000,000,127 | —- | C] () – C:\WINDOWS\wininit.ini
[2009/06/17 10:32:47 | 000,066,482 | R— | C] () – C:\WINDOWS\System32\lvcoinst.ini
[2008/07/26 08:25:02 | 000,025,624 | —- | C] () – C:\WINDOWS\System32\drivers\LVPr2Mon.sys
[2008/05/02 22:46:00 | 001,703,936 | —- | C] () – C:\WINDOWS\System32\nvwdmcpl.dll
[2008/05/02 22:46:00 | 001,486,848 | —- | C] () – C:\WINDOWS\System32\nview.dll
[2008/05/02 22:46:00 | 001,019,904 | —- | C] () – C:\WINDOWS\System32\nvwimg.dll
[2008/05/02 22:46:00 | 000,466,944 | —- | C] () – C:\WINDOWS\System32\nvshell.dll
[2008/05/02 22:46:00 | 000,286,720 | —- | C] () – C:\WINDOWS\System32\nvnt4cpl.dll
[2007/11/14 20:15:10 | 000,000,206 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2007/08/01 14:13:44 | 000,000,344 | —- | C] () – C:\WINDOWS\QTW.INI
[2007/06/08 12:28:18 | 000,000,227 | —- | C] () – C:\WINDOWS\HP_CounterReport_Update_HPSU.ini
[2007/06/08 12:27:56 | 000,000,214 | —- | C] () – C:\WINDOWS\HP_48BitScanUpdatePatch.ini
[2007/06/08 12:23:33 | 000,000,221 | —- | C] () – C:\WINDOWS\HP_RedboxHprblog_HPSU.ini
[2007/03/05 14:34:28 | 000,676,224 | —- | C] () – C:\WINDOWS\System32\OGACheckControl.DLL
[2006/09/28 15:36:44 | 000,000,000 | —- | C] () – C:\WINDOWS\hpqEmlSz.INI
[2006/09/18 14:56:55 | 000,000,221 | —- | C] () – C:\WINDOWS\NCLogConfig.ini
[2005/06/30 10:17:00 | 000,000,000 | —- | C] () – C:\WINDOWS\SETUP32.INI
[2005/04/13 11:38:24 | 000,004,560 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2004/11/18 12:20:46 | 000,000,026 | —- | C] () – C:\WINDOWS\UP9ASP.INI
[2004/11/18 12:11:29 | 000,000,024 | —- | C] () – C:\WINDOWS\atid.ini
[2004/11/18 12:11:28 | 000,000,365 | —- | C] () – C:\WINDOWS\upst.ini
[2004/10/30 15:14:45 | 000,000,032 | —- | C] () – C:\WINDOWS\CD_Start.INI
[2004/08/24 13:39:18 | 000,000,844 | —- | C] () – C:\WINDOWS\hegames.ini
[2004/08/24 13:39:14 | 000,000,080 | —- | C] () – C:\WINDOWS\encore_launcher.ini
[2004/08/07 15:31:23 | 000,000,024 | —- | C] () – C:\WINDOWS\RVBOOK.INI
[2004/01/23 11:29:51 | 000,335,872 | —- | C] () – C:\WINDOWS\System32\ldf252.dll
[2004/01/23 11:25:39 | 000,000,034 | —- | C] () – C:\WINDOWS\hpfsched.ini
[2003/12/29 11:42:06 | 000,001,964 | —- | C] () – C:\WINDOWS\disney.ini
[2003/12/05 17:22:04 | 000,000,293 | —- | C] () – C:\WINDOWS\iPlayer.INI
[2003/11/01 16:42:01 | 000,000,174 | —- | C] () – C:\WINDOWS\System32\mcini.ini
[2003/10/29 17:31:35 | 000,000,024 | —- | C] () – C:\WINDOWS\msoffice.ini
[2003/10/23 03:48:03 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2003/10/23 03:46:15 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2003/10/23 03:35:08 | 000,000,882 | —- | C] () – C:\WINDOWS\orun32.ini
[2003/10/23 03:19:35 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/10/23 03:19:19 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2003/10/23 03:15:39 | 000,262,144 | —- | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\ntuser.dat
[2003/10/23 03:15:39 | 000,008,192 | -H– | C] () – C:\WINDOWS\SYSTEM32\CONFIG\systemprofile\NTUSER.DAT.LOG
[2003/10/23 03:07:02 | 000,000,546 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2003/08/14 00:13:00 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003/01/07 16:05:08 | 000,002,695 | —- | C] () – C:\WINDOWS\System32\OUTLPERF.INI
[2002/08/29 06:00:00 | 000,151,552 | -H– | C] () – C:\WINDOWS\Fonts\services.exe
[2002/08/29 06:00:00 | 000,000,008 | —- | C] () – C:\WINDOWS\System32\FInstall.sys
[2001/07/06 16:30:00 | 000,003,399 | —- | C] () – C:\WINDOWS\System32\hptcpmon.ini
[1980/01/01 01:00:00 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\e100bmsg.dll

========== LOP Check ==========

[2010/04/18 09:54:18 | 000,000,488 | —- | M] () – C:\WINDOWS\Tasks\1-Click Maintenance.job
[2010/04/18 09:54:18 | 000,000,314 | —- | M] () – C:\WINDOWS\Tasks\GlaryInitialize.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >
[2008/02/16 13:09:20 | 023,454,528 | —- | M] ( ) – C:\AdbeRdr812_en_US.exe
[2005/12/06 10:37:30 | 000,010,920 | —- | M] () – C:\aolconnfix.exe
[2007/05/23 13:35:47 | 011,470,608 | —- | M] () – C:\avgas-setup-7.5.0.50.exe
[2006/06/08 11:20:38 | 000,274,432 | —- | M] (Versis) – C:\c0.exe
[2004/08/31 11:15:49 | 009,663,488 | —- | M] (Skype Software S.A. ) – C:\SkypeSetup.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) – C:\userinit.exe
[2006/12/27 17:21:52 | 002,035,200 | —- | M] () – C:\ventrilo-2.3.0-Windows-i386.exe


< MD5 for: AGP440.SYS >
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:AGP440.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:AGP440.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:AGP440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ERDNT\cache\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\ServicePackFiles\i386\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\agp440.sys
[2008/04/13 14:36:38 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\SYSTEM32\DRIVERS\agp440.sys
[2004/08/04 02:07:41 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=2C428FA0C3E3A01ED93C9B2A27D8D4BB – C:\WINDOWS\$NtServicePackUninstall$\agp440.sys
[2001/08/17 14:58:00 | 000,025,472 | —- | M] (Microsoft Corporation) MD5=65880045C51AA36184841CEE915A61DF – C:\I386\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\I386\sp1.cab:atapi.sys
[2002/08/29 06:00:00 | 010,158,890 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp1.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\Driver Cache\I386\sp3.cab:atapi.sys
[2004/09/18 13:21:10 | 022,245,337 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp2.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\ServicePackFiles\i386\sp3.cab:atapi.sys
[2008/10/04 13:45:21 | 023,852,652 | —- | M] () .cab file – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\sp3.cab:atapi.sys
[2003/01/31 16:43:30 | 000,087,040 | —- | M] (Microsoft Corporation) MD5=3C33F5479520844A186C2D43ECFFD477 – C:\I386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0003\DriverFiles\i386\atapi.sys
[2002/08/29 02:27:50 | 000,086,912 | —- | M] (Microsoft Corporation) MD5=95B858761A00E1D4F81F79A0DA019ACA – C:\WINDOWS\SYSTEM32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ERDNT\cache\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\ServicePackFiles\i386\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\atapi.sys
[2008/04/13 14:40:30 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\SYSTEM32\DRIVERS\atapi.sys
[2004/08/04 01:59:42 | 000,095,360 | —- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 – C:\WINDOWS\$NtServicePackUninstall$\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ERDNT\cache\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\ServicePackFiles\i386\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\eventlog.dll
[2008/04/13 20:11:53 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\SYSTEM32\eventlog.dll
[2004/08/04 03:56:42 | 000,055,808 | —- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 – C:\WINDOWS\$NtServicePackUninstall$\eventlog.dll
[2002/08/29 06:00:00 | 000,049,152 | —- | M] (Microsoft Corporation) MD5=BF3C8CF53C77B48206B39910B6D6CBCC – C:\I386\EVENTLOG.DLL

< MD5 for: NETLOGON.DLL >
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ERDNT\cache\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\ServicePackFiles\i386\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\netlogon.dll
[2008/04/13 20:12:01 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\SYSTEM32\netlogon.dll
[2002/08/29 06:00:00 | 000,399,360 | —- | M] (Microsoft Corporation) MD5=3ADD563ED7A1C66E6F5E0F7A661AA96D – C:\I386\NETLOGON.DLL
[2004/08/04 03:56:44 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A – C:\WINDOWS\$NtServicePackUninstall$\netlogon.dll

< MD5 for: RUNDLL32.EXE >
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=037B1E7798960E0420003D05BB577EE6 – C:\WINDOWS\ServicePackFiles\i386\rundll32.exe
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=037B1E7798960E0420003D05BB577EE6 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\rundll32.exe
[2008/04/13 20:12:33 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=09263C41BEE92C17D663BF487BCF2962 – C:\WINDOWS\SYSTEM32\rundll32.exe
[2002/08/29 06:00:00 | 000,031,744 | —- | M] (Microsoft Corporation) MD5=0FB22DD37C17F80AD71316049F725170 – C:\I386\RUNDLL32.EXE
[2004/08/04 03:56:55 | 000,033,280 | —- | M] (Microsoft Corporation) MD5=DA285490BBD8A1D0CE6623577D5BA1FF – C:\WINDOWS\$NtServicePackUninstall$\rundll32.exe

< MD5 for: SCECLI.DLL >
[2004/08/04 03:56:44 | 000,180,224 | —- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A – C:\WINDOWS\$NtServicePackUninstall$\scecli.dll
[2002/08/29 06:00:00 | 000,174,592 | —- | M] (Microsoft Corporation) MD5=97418A5C642A5C748A28BD7CF6860B57 – C:\I386\SCECLI.DLL
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ERDNT\cache\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\ServicePackFiles\i386\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\scecli.dll
[2008/04/13 20:12:05 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\SYSTEM32\scecli.dll

< MD5 for: USERINIT.EXE >
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=3833FA6B1774DDCAC290CE0643CFCD1B – C:\userinit.exe
[2004/08/04 03:56:57 | 000,024,576 | —- | M] (Microsoft Corporation) MD5=39B1FFB03C2296323832ACBAE50D2AFF – C:\WINDOWS\$NtServicePackUninstall$\userinit.exe
[2008/04/13 20:12:38 | 000,050,688 | —- | M] (Microsoft Corporation) MD5=A0B3BE24EB75AA0A08C14C1682D3DC56 – C:\WINDOWS\SYSTEM32\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\ServicePackFiles\i386\userinit.exe
[2008/04/13 20:12:38 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=A93AEE1928A9D7CE3E16D24EC7380F89 – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\userinit.exe
[2002/08/29 06:00:00 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=E931E0A2B8BF0019DB902E98D03662CB – C:\I386\USERINIT.EXE

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINDOWS\$NtServicePackUninstall$\winlogon.exe
[2002/08/29 06:00:00 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=2246D8D8F4714A2CEDB21AB9B1849ABB – C:\I386\WINLOGON.EXE
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SoftwareDistribution\Download\dd9ab5193501484cf5e6884fa1d22f9e\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINDOWS\SYSTEM32\winlogon.exe

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[2008/06/20 13:46:57 | 000,147,968 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dnsapi.dll
[2010/03/11 08:38:52 | 006,067,200 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ieframe.dll
[2010/03/11 08:38:52 | 000,268,288 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\iertutil.dll
[2008/04/13 20:12:00 | 000,274,944 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\mstask.dll
[2008/04/13 20:12:02 | 000,067,072 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ntdsapi.dll
[2008/04/13 20:12:03 | 000,023,040 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\psapi.dll
[2008/06/17 15:02:19 | 008,461,312 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\shell32.dll
[2010/03/11 08:38:54 | 001,168,384 | —- | M] (Microsoft Corporation) Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\urlmon.dll

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\System32\config\*.sav >
[2002/09/03 14:22:52 | 000,094,208 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\DEFAULT.SAV
[2002/09/03 14:22:52 | 000,626,688 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SOFTWARE.SAV
[2002/09/03 14:22:52 | 000,397,312 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\SYSTEM.SAV
< End of report >


OTL Extras logfile created on: 4/20/2010 8:01:38 AM - Run
OTLPE by OldTimer - Version 3.1.37.2 Folder = X:\Programs\OTLPE
Microsoft Windows XP Service Pack 3 (Version = 5.1.2600) - Type = SYSTEM
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.00 Mb Total Physical Memory | 231.00 Mb Available Physical Memory | 45.00% Memory free
459.00 Mb Paging File | 280.00 Mb Available in Paging File | 61.00% Paging File free
Paging file location(s): C:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 38.24 Gb Total Space | 23.33 Gb Free Space | 61.00% Space Free | Partition Type: NTFS
Drive D: | 465.76 Gb Total Space | 458.86 Gb Free Space | 98.52% Space Free | Partition Type: NTFS
Drive E: | 981.05 Mb Total Space | 962.00 Mb Free Space | 98.06% Space Free | Partition Type: FAT32
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Drive X: | 276.80 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Computer Name: REATOGO
Current User Name: SYSTEM
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
Using ControlSet: ControlSet004

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_USERS\.DEFAULT\SOFTWARE\Classes\]
.exe [@ = secfile] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\ave.exe File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [ACDBrowse] – "C:\PROGRA~1\ACDSYS~1\ACDSee\ACDSee.exe" "%1" (ACD Systems, Ltd.)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 1
"FirewallOverride" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 0
"" =
"DisableNotifications" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"26675:TCP" = 26675:TCP:169.254.2.0/255.255.255.0:Enabled:ActiveSync Service
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002
"" =

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DoNotAllowExceptions" = 0
"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"" =

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\America Online 9.0\waol.exe" = C:\Program Files\America Online 9.0\waol.exe:*:Enabled:America Online 9.0 – File not found
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Common Files\aol\Loader\aolload.exe" = C:\Program Files\Common Files\aol\Loader\aolload.exe:*:Enabled:AOL Application Loader – (AOL LLC)
"C:\Program Files\Common Files\aol\System Information\sinf.exe" = C:\Program Files\Common Files\aol\System Information\sinf.exe:*:Enabled:AOL – (America Online Inc.)
"C:\WINDOWS\SYSTEM32\fxsclnt.exe" = C:\WINDOWS\SYSTEM32\fxsclnt.exe:*:Enabled:Microsoft Fax Console – (Microsoft Corporation)
"C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe" = C:\Program Files\HP\Digital Imaging\bin\hpofxm08.exe:*:Enabled:hpofxm08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe" = C:\Program Files\HP\Digital Imaging\bin\hposfx08.exe:*:Enabled:hposfx08.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hposid01.exe" = C:\Program Files\HP\Digital Imaging\bin\hposid01.exe:*:Enabled:hposid01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpqCopy.exe:*:Enabled:hpqcopy.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe" = C:\Program Files\HP\Digital Imaging\bin\hpfccopy.exe:*:Enabled:hpfccopy.exe – (Hewlett-Packard)
"C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpzwiz01.exe:*:Enabled:hpzwiz01.exe – (Hewlett-Packard Co.)
"C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqPhUnl.exe:*:Enabled:hpqphunl.exe – ()
"C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe" = C:\Program Files\HP\Digital Imaging\Unload\HpqDIA.exe:*:Enabled:hpqdia.exe – ( )
"C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe" = C:\Program Files\HP\Digital Imaging\bin\hpoews01.exe:*:Enabled:hpoews01.exe – (Hewlett-Packard Co.)
"C:\Program Files\Microsoft ActiveSync\rapimgr.exe" = C:\Program Files\Microsoft ActiveSync\rapimgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync RAPI Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\wcescomm.exe" = C:\Program Files\Microsoft ActiveSync\wcescomm.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Connection Manager – (Microsoft Corporation)
"C:\Program Files\Microsoft ActiveSync\WCESMgr.exe" = C:\Program Files\Microsoft ActiveSync\WCESMgr.exe:169.254.2.0/255.255.255.0:Enabled:ActiveSync Application – (Microsoft Corporation)
"C:\Program Files\Real\RealPlayer\trueplay.exe" = C:\Program Files\Real\RealPlayer\trueplay.exe:*:Disabled:RealOne Player – (RealNetworks, Inc.)
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\RosettaStoneVersion3.exe:*:Enabled:Rosetta Stone V3 DEMO Application – File not found
"C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe" = C:\Program Files\Rosetta Stone\Rosetta Stone V3 DEMO\support\bin\RosettaStoneLtdServices.exe:*:Enabled:Rosetta Stone Online Component – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.dll:*:Enabled:Google Talk Plugin – File not found
"C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe" = C:\Documents and Settings\Andrew\Local Settings\Application Data\Google\Google Talk Plugin\googletalkplugin.exe:*:Enabled:Google Talk Plugin – File not found
"C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\ttax.exe:LocalSubNet:Enabled:TurboTax – (Intuit, Inc.)
"C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe" = C:\Program Files\TurboTax\Home & Business 2007\32bit\updatemgr.exe:LocalSubNet:Enabled:TurboTax Update Manager – (Intuit, Inc.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{00F0588F-5F9C-4661-84E0-176790BDF709}" = ESET Smart Security
"{0143CF89-5CF2-4F2D-80D5-BFAE64E1BA00}" = Media Wizard 3.0
"{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery
"{0611BD4E-4FE4-4a62-B0C0-18A4CC463428}" = CP_Package_Variety1
"{06230E02-2B7E-11D2-92D0-0040051BD005}" = OLYMPUS CAMEDIA Master 2.5
"{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations
"{09DA4F91-2A09-4232-AB8C-6BC740096DE3}" = Sonic Update Manager
"{0B33B738-AD79-4E32-90C5-E67BFB10BBFF}" = AiO_Scan
"{11F1920A-56A2-4642-B6E0-3B31A12C9288}" = Dell Solution Center
"{1206EF92-2E83-4859-ACCB-2048C3CB7DA6}" = Sonic DLA
"{151C555A-A9E7-4A2E-B6D7-165D04A3C956}" = Dell Picture Studio - Dell Image Expert
"{1C139D7D-9FEA-468d-A9C8-2A6E3BDE564A}" = CP_Package_Variety3
"{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK
"{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config
"{2466E904-7E48-4597-9321-722CF02930EB}" = 5600
"{26A24AE4-039D-4CA4-87B4-2F83216013FF}" = Java™ 6 Update 13
"{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload
"{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp
"{3248F0A8-6813-11D6-A77B-00B0D0160060}" = Java™ 6 Update 6
"{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3AF8FCCD-F51A-4014-9002-F195E1CBC876}" = Logitech QuickCam
"{410438A3-B591-4028-B70A-3CC0B33FBCD1}" =
"{4B9F45E8-E3CE-40B4-9463-80A9B3481DEF}" = Banctec Service Agreement
"{53735ECE-E461-4FD0-B742-23A352436D3A}" = Logitech Updater
"{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder
"{541DEAC0-5F3D-45E6-B7CB-94ECF3B96748}" = Skype web features
"{54E3707F-808E-4fd4-95C9-15D1AB077E5D}" = NewCopy
"{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap
"{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg
"{5888428E-699C-4E71-BF71-94EE06B497DA}" = TuneUp Utilities 2008
"{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1
"{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch
"{5B79CFD1-6845-4158-9D7D-6BE89DF2C135}" = HP PSC & OfficeJet 5.3.B
"{5E835305-63BB-4E55-BBB7-EEBBE67774DB}" = Sonic MyDVD
"{60859BF2-5151-473C-8F76-7F3A232CF7E7}" = MM Number Heroes
"{64116298-93C5-401D-B06C-39D8E3338508}" = DAO
"{64658686-0CD4-4CF6-983D-0A6BE32007DB}" = Business Complete Care Services Agreement
"{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{68D60342-7686-45C9-B8EB-40EF843D0460}" = Dell Networking Guide
"{6994491D-D491-48F1-AE1F-E179C1FFFC2F}" = HP Photosmart Essential
"{6BB6627C-694F-4FDC-A3E5-C7F4BED4C724}" = DocProc
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{70C002F0-5308-42D8-A65A-91436B90255C}" = MakeAMov
"{7148F0A8-6813-11D6-A77B-00B0D0142000}" = Java 2 Runtime Environment, SE v1.4.2
"{748F4870-8350-11D3-B0BF-080009FB4A19}" = HP Share-to-Web
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"{7850A6D2-CBEA-4728-9877-F1BEDEA9F619}" = AiOSoftware
"{7C9B95B7-B598-4398-B30F-7F6827192E6C}" = ProductContext
"{7DD9A065-2C86-4A9F-A5FF-796EC1B99DCA}" = AnswerWorks 4.0 Runtime - English
"{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config
"{7EFA5E6F-74F7-4AFB-8AEA-AA790BD3A76D}" = DellSupport
"{7F142D56-3326-11D5-B229-002078017FBF}" = Modem Helper
"{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}" = Musicmatch® Jukebox
"{90AF0409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office PowerPoint Viewer 2003
"{90D55A3F-1D99-4C94-A77E-46DC14F0BF08}" = Help and Support Customization
"{91130409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Basic Edition 2003
"{923A7F5A-1E8C-4FBE-8DF6-85940A60A79F}" = Readme
"{9541FED0-327F-4DF0-8B96-EF57EF622F19}" = Sonic RecordNow!
"{98DF85D9-96C0-4F57-A92E-C3539477EF5E}" = DVDSentry
"{9B79DCB0-AAD7-456B-8D07-433C936FA24B}" = DS21Patch
"{A195B13E-A5E3-4BAF-A995-7F70F445CD06}" = ScannerCopy
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour
"{A790BEB1-BCCF-4EC6-807B-5708B36E8A79}" = Intel® PROSet
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-A90000000001}" = Adobe Reader 9
"{AEAEEAD6-38EC-4321-92A7-599367E21FF2}" = Rosetta Stone V3 DEMO
"{B208806F-A231-4FA0-AB3F-5C1B8979223E}" = Microsoft ActiveSync 4.0
"{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1" = Spybot - Search & Destroy
"{B824B5C9-849F-4b9e-9EA7-6FD8CD8116DA}" = CP_Package_Variety2
"{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm
"{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"{BBF6D0CD-A081-369F-B0B8-F168594CBB6B}" = Google Talk Plugin
"{BFD5AC8A-5884-4da8-9873-3DF8E3DCCE18}" = 5600Trb
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C506A18C-1469-4678-B094-F4EC9DAE6DB7}" = Scan
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CC7984C5-020D-4944-85A0-58D09D4A8BFB}" = 5600_Help
"{CE24344F-DFD8-40C8-8FD8-C9740B5F25AC}" = Fax
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF40ACC5-E1BB-4aff-AC72-04C2F616BCA7}" = getPlus®
"{D103C4BA-F905-437A-8049-DB24763BBE36}" = Skype™ 4.1
"{D6DE02C7-1F47-11D4-9515-00105AE4B89A}" = Paint Shop Pro 7
"{DD2F0FE7-A3FD-45AE-92A6-DA46166B3158}" = Find Rugs
"{DED53B0B-B67C-4244-AE6A-D6FD3C28D1EF}" = Ad-Aware 2007
"{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant
"{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter
"{EF6F70D0-C242-4047-946B-98EA8208481A}" = ArcSoft TotalMedia Backup & Record
"{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8}" = QuickTime
"{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status
"{F54AC413-D2C6-4A24-B324-370C223C6250}" = Adobe Photoshop Elements 6.0
"{FC4ED75D-916C-4A8C-BB67-3C6F6E06D62B}" = Banctec Service Agreement
"{FF77941A-2BFA-4A18-BE2E-69B9498E4D55}" = User Profile Hive Cleanup Service
"102 Dalmatians Activity Center" = 102 Dalmatians Activity Center
"ACDSee" = ACDSee
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 6" = Adobe Photoshop Elements 6.0
"AOL Toolbar 5.0" =
"BCM V.92 56K Modem" = BCM V.92 56K Modem
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"Dell Digital Jukebox Driver" = Dell Digital Jukebox Driver
"Excel Invoice Manager_is1" = Excel Invoice Manager 2.12.1016
"Full Speed2.1" = Full Speed
"HP Imaging Device Functions" = HP Imaging Device Functions 5.3
"HP Photo & Imaging" = HP Image Zone 5.3
"HP Photo Imaging Software" = HP Photo Imaging Software
"HP Photo Printing Software" = HP Photo Printing Software
"HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.3
"HPExtendedCapabilities" = HP Extended Capabilities 5.3
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"InstallShield_{5396FBD8-8BD7-47F9-92AE-F62F13D5A11D}" = NETGEAR WG111v3 wireless USB 2.0 adapter
"InstallShield_{70C002F0-5308-42D8-A65A-91436B90255C}" = Make a Movie
"InstallShield_{77FCC1D4-E78E-46A4-80A6-7F456FA9AC90}" = Finding Nemo: Nemo's Underwater World of Fun Special Edition
"InstallShield_{BBA67AB4-94E3-4818-8104-7B6CF7F8538C}" = DesignPro 5.0 Sign Edition
"InterActual Player" = InterActual Player
"Knowmad" = Knowmad
"lvdrivers_11.80" = Logitech QuickCam Driver Package
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"NetAlyzer_is1" = NetAlyzer 0.3
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"NVIDIA Drivers" = NVIDIA Drivers
"PROSet" = Intel® PRO Network Adapters and Drivers
"RealPlayer 6.0" = RealOne Player
"Revo Uninstaller" = Revo Uninstaller 1.85
"Shockwave" = Shockwave
"StreetPlugin" = Learn2 Player (Uninstall Only)
"The ClueFinders Reading Adventures Ages 9-12" = The ClueFinders Reading Adventures Ages 9-12
"TS2AC" = Toy Story 2 Activity Center
"TurboTax Home & Business 2007" = TurboTax Home & Business 2007
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinRAR archiver" = WinRAR archiver
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Your Uninstaller! 2008_is1" = Your Uninstaller! 2008 Version 6.0

< End of report >





H
Hi,

Run OTLPE
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    DRV - File not found [Kernel | Boot] – – (vkquwexg)
    O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
    O4 - HKLM..\Run: [combofix] C:\CF\CF26651.cfx File not found
    O4 - HKLM..\Run: [qyfvwm] C:\WINDOWS\System32\msejfzrl.DLL File not found
    O4 - HKU\Andrew_ON_C..\Run: [Sonic RecordNow!] File not found
    O4 - HKU\Cynthia_ON_C..\Run: [Sonic RecordNow!] File not found
    O4 - HKU\LocalService_ON_C..\Run: [Sonic RecordNow!] File not found
    O4 - HKU\NetworkService_ON_C..\Run: [Sonic RecordNow!] File not found
    O4 - HKLM..\RunOnceEx: [flags] Reg Error: Invalid data type. File not found
    F3 - HKU\.DEFAULT WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
    F3 - HKU\.DEFAULT WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
    F3 - HKU\Andrew_ON_C WinNT: Load - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
    F3 - HKU\Andrew_ON_C WinNT: Run - (C:\WINDOWS\fonts\services.exe) - C:\WINDOWS\Fonts\services.exe ()
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: mslivemsn = C:\Program Files\Windows NT\Accessories\svchost.exe File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\run: exec = C:\WINDOWS\fonts\services.exe ()
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab  (Java Plug-in 1.6.0_13)
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} http://download.av.aol.com/molbin/shared/m…,20/mcgdmgr.cab (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/autodl…indows-i586.cab (Java Plug-in 1.4.2)
    O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_06)
    O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
    O32 - AutoRun File - [2009/10/13 17:19:36 | 000,000,067 | —- | M] () - D:\autorun.inf – [ NTFS ]
    O32 - AutoRun File - [2010/04/18 09:54:24 | 000,000,028 | —- | M] () - E:\AUTORUN.INF – [ FAT32 ]
    [2010/04/17 18:57:50 | 000,200,192 | —- | C] (-) – C:\WINDOWS\System32\3308329.exe
    [2010/04/17 09:35:05 | 000,200,192 | —- | C] (-) – C:\WINDOWS\System32\4081797.exe
    [2010/04/17 09:34:19 | 000,093,184 | —- | C] (icon company) – C:\WINDOWS\System32\w.exe
    [2010/04/17 05:24:24 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\userinit.exe
    [2010/04/16 07:21:01 | 000,044,544 | —- | C] (lowest systems) – C:\WINDOWS\System32\so.bin
    [2010/04/16 07:21:01 | 000,036,864 | —- | C] (irbg fmt hapu nyusqyan) – C:\WINDOWS\System32\d.bin
    [2010/04/16 07:21:01 | 000,034,304 | —- | C] (dreas company) – C:\WINDOWS\System32\ms.bin
    [2010/04/17 21:06:07 | 000,036,864 | —- | M] (irbg fmt hapu nyusqyan) – C:\WINDOWS\System32\d.bin
    [2010/04/17 21:00:52 | 000,093,184 | —- | M] (icon company) – C:\WINDOWS\System32\w.exe
    [2010/04/17 21:00:28 | 000,044,544 | —- | M] (lowest systems) – C:\WINDOWS\System32\so.bin
    [2010/04/17 21:00:28 | 000,034,304 | —- | M] (dreas company) – C:\WINDOWS\System32\ms.bin
    [2010/04/17 18:57:56 | 000,000,098 | —- | M] () – C:\auywg93w108.bat
    [2010/04/17 18:57:50 | 000,200,192 | —- | M] (-) – C:\WINDOWS\System32\3308329.exe
    [2010/04/17 18:57:43 | 000,048,640 | —- | M] () – C:\WINDOWS\System32\5992788.exe
    [2010/04/17 18:57:43 | 000,000,120 | —- | M] () – C:\WINDOWS\System32\221953.BAT
    [2010/04/17 18:57:39 | 000,167,842 | —- | M] () – C:\WINDOWS\System32\9529993.exe
    [2010/04/17 09:35:05 | 000,200,192 | —- | M] (-) – C:\WINDOWS\System32\4081797.exe
    [2010/04/17 09:34:27 | 000,000,120 | —- | M] () – C:\WINDOWS\System32\258468.BAT
    [2010/04/17 09:34:24 | 000,048,640 | —- | M] () – C:\WINDOWS\System32\7490743.exe
    [2010/04/17 09:34:24 | 000,036,865 | —- | M] () – C:\WINDOWS\System32\mshwolkt.dll
    [2010/04/17 09:34:18 | 000,167,842 | —- | M] () – C:\WINDOWS\System32\9965326.exe
    [2010/04/16 07:23:47 | 000,000,098 | —- | M] () – C:\dt5rwef3c108.bat
    [2010/04/16 07:23:44 | 000,175,616 | —- | M] () – C:\WINDOWS\System32\1445689.EXE
    [2010/04/16 07:21:00 | 000,166,735 | —- | M] () – C:\WINDOWS\System32\2607364.exe
    [2010/04/16 07:20:49 | 000,000,000 | —- | M] () – C:\WINDOWS\SC.INS
    [2010/04/16 07:20:49 | 000,000,000 | —- | M] () – C:\WINDOWS\sc.exe
    [2010/04/15 19:06:39 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\598736.exe
    [2010/04/15 18:58:03 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\1762964.exe
    [2010/04/15 18:02:04 | 000,168,140 | —- | M] () – C:\WINDOWS\System32\960657.exe
    [2010/04/14 18:31:16 | 000,007,680 | —- | M] () – C:\WINDOWS\System32\8833994.exe
    [2010/04/14 18:31:05 | 000,036,865 | —- | M] () – C:\WINDOWS\System32\mslgqlaj.dll
    [2010/04/14 18:30:56 | 000,167,773 | —- | M] () – C:\WINDOWS\System32\7473871.exe
    [2010/04/10 14:53:20 | 000,006,456 | -H– | M] () – C:\WINDOWS\System32\wolejifu
    [2010/04/17 18:57:43 | 000,048,640 | —- | C] () – C:\WINDOWS\System32\5992788.exe
    [2010/04/17 18:57:43 | 000,000,120 | —- | C] () – C:\WINDOWS\System32\221953.BAT
    [2010/04/17 18:57:39 | 000,167,842 | —- | C] () – C:\WINDOWS\System32\9529993.exe
    :reg
    [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet004\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
    "" =-
    :Commands
    [emptytemp]
    [emptyflash]
    [resethosts]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"


Please try to boot normally.
Not good news. Followed the instructions. Rebooted. Log in. Desktop and icons appear then "Windows cannot find C:\Windows\fonts\services.exe" Hit OK, and the error stays on screen with no further life apparent. Only way out, hard reset. Tried again, desktop and icons appear, same error message, same reaction. Hard reset, this time through, try Safe Mode to see if I can see any startup for services.exe. Log in - but no desktop, no icons, just a black screen with "Safe Mode" in all 4 corners. Mouse moves but no further evidence of life. No ctl-alt-del. It's just hung up big time. Left it alone for a while, came back to a classic log in box, log back in. But this time there's the Dell desktop, no icons and the hourglass when hovering over the task bar. Hard reset again. Left it come back up normal. No services.exe error but no icons and no task bar. Ctl-Alt-Del gets me Task Mgr but "Shut Down" won't fly and neither will a Run > Explorer.exe to call up the desktop environment. Says, "Explorer.exe is not a valid Win 32 App". That's all I can say at this point. Ready to try something else? H
Sure :)
Boot with OTLPE again.

  • Your system should now display a REATOGO-X-PE desktop.
  • Double-click on the OTLPE icon.
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start. Change the following settings
    • Change Drivers to Use Safe List
  • Under the custom scan box, please paste in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    userinit.exe
    rundll32.exe
    winlogon.exe
    /md5stop
    %systemroot%\*. /mp /s
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\System32\config\*.sav
    HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services
  • Press Run Scan to start the scan.
  • When finished, the file will be saved in drive C:\_OTL\MovedFiles
  • Copy this file to your USB drive if you do not have internet connection on this system
  • Please post the contents of the OTL.txt file in your reply.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI