This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Blasted with unknown services going online -- many gigs of I/O data

9 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello,

For the past several (well, several several) months I've been seeing an increasing number of, uhm, "anomalies" on my system, and have been trying to fix things myself, using the DIY malware removal procedures on quite a few forums like this – but this week things have really gotten out of hand, and I clearly need serious help!

Several times by now I've re-installed Windows 7 (an upgrade from XP, on which I first noticed the beginnings of the problem), always having zero-filled the HD, dumped the RAM, cleared the CMOS, and installed a freshly downloaded BIOS from Dell. I was hoping that all of this would effectively give the computer amnesia, but clearly the seeds of the malware have been hiding somewhere which has allowed it to survive all of this. Each time, within a few days things have returned to their previous state. (If anyone could suggest some non-volatile memory into which the malware could somehow be writing itself I'd be grateful, if only to satisfy my curiosity – even my monitor's and nVidia card's firmware have been suggested, but that's a bit hard to buy. As one security forum techie said, "If someone's figured out how to infect a mouse I want in, even if I go down in flames!" Though another security expert did say that with certain mice it is theoretically possible.)

Anyway, here are some symptoms …

Constant logons and secondary logons, some as expected by Built-in security principals, others anonymous or unknown, and even papilio$ (this usually after 2 or 3 unsuccessful logon attempts) according to Events Viewer Security audits. (I frequently change my strong user password, though I hear that this isn't much help with today's password grinders). I understand that at least most of these are internally generated, though I don't know what frequency is normal – it's a bit hard to believe that these are all legitimate system processes, but they may be.

There's frequent lowering of my initially high password-protected security settings of Avast Internet Security, plus having my advanced Internet Options all set to disabled (I use Firefox, always updated to latest build). The same with ZoneAlarm (used previously to Avast). These internet protection programs have sometimes been completely uninstalled, as well as has been Firefox, which also often crashes when I click links to malware help sites. Frequently, my clock is suddenly many hours off. My services configuration is constantly being modified, such as Remote Assistance being changed from disabled to manual (17 RA sessions currently reported), also reactivation of the Bluetooth adapter service (what use could be made of that ??). I configure these services through their Start keys in the registry (value 4). I often end up having access denied to my own documents – I can of course regain access with ICACLS, taking back ownership etc. (most of the time!), but that's not really the point, it's never permanent and of course isn't the root of the problem. And this may be normal too, but I (as a user) am very rarely listed on files' or directories' ACLs – Administrators, yes, but evidently that doesn't include me as a user administrator, judging by my own effective permissions. (Should I be included? I'd have thought so.)

There's been an explosion of running services, most of which I've never heard of before, usually in fact giving zero Google results. Along side of this the number of connections shown on TCPview has suddenly gone as high as 500. I use a wired Belkin router, which seems to be effective in keeping anything from getting in of its own initiative, but all of my problems seem to be originating from the inside out, presumably hijacked or bogus services connecting to malicious URLs and downloading stuff, inviting more friends in to party – I never know which services to allow out, having Avast set to ask me about everything. I need to find out which services absolutely must be allowed onto the web merely in order for me to access the internet, and keep the rest in – except that Avast never indicates more than that it's just that d*mn svchost requesting web access. They are always getting out when even I can't get access to the web myself with Firefox, nor successfully ping my router running the Command Prompt as Administrator. According to Avast and TCPview many internet connections are loopbacks – I understand that these are normal for some legit system programs, but often indicate malware trying to elevate its privileges. I don't know what is normal, but Procmon.exe is berserk with activity, say a million or two entries within less than half an hour.

I realize that I could just delete those services which show a filepath (few of them show up in the registry and so can't be disabled), but I doubt that this would do anything to eliminate the malware which is spawning them, so wouldn't be likely to rid my system of the problem. Very many of these connections are running under [System Process]:0, which I understand represents System Idle. IPsec keeps reporting that it was not able to detect all network adapters, even after I use the suggested snap-in, and a lot of adapters and UPnP devices are under "hidden devices" in Device Manager, enumerated ROOT – this last is not inherently suspicious I know, just makes them impossible to remove most of the time.

A few days ago, just after I had downloaded and installed SUPERAntiSpyware, (had not yet run it, and it was not set to start with Windows) Taskmanager indicated that it was taking up about 50% of my CPU resources. Looking up the stack thread, this program was actually at the bottom of a process headed by a dozen instances of ntkrnlpa.exe, parent: (2676).

My usual scans, Malwarebytes and Avast, invariably show my machine as being entirely clean. But my newer scanners are finding a few new hidden files with each scan, typically adware cookies in my Temp folder. But the real troublemaker is still with me, and has been for months as far as I can tell. How it could survive a zero-fill I can't imagine, but even local techies agree, based on the symptoms, it's the same bug. Before these past 2 or 3 months, I'd always had completely trouble-free computing and surfing since the days of the 4800 dial-ups!


Possibly a partial explanation for some other things showing up …

ALL of my directories are being scanned several times a day, sometimes being modified. A lot of my documents have been deleted, though of course all but the newest ones are backed up – often these are still listed in Explorer, but as containing 0 bytes. And one thing I just discovered, Explorer shows my file structure as expected, but looking at the filesystem in gmer shows that the sub-directories beneath them have disappeared. I can navigate to and open them and their files as normal with Explorer. However, entries in various MS logs indicate that they've been moved to an unkown virtual drive (not just copied to a shadow backup volume). Many log entries record the creation of a "side by side" file system, also creation of dual ownership – not indicated in any file or dir properties. sfc /scannow displays notice of many shared files and directories as well. I've not seen any of this before, and nothing on my computer is set to "shared", file sharing is disabled as a service in the registry as well as in my adapter properties. I'm not on a network.

What purposes these things accomplish I can't guess, but it's quite possible that MS is indeed responsible for some of the strange things I'm seeing, though surely not the more malicious stuff – for quite some time their WU setup logs indicated that the installation was unable to find my product key, though its query confirmed that Windows 7 had been signed and authenticated by MS. I called the Microsoft Store about this (where I had bought Win 7), and they told me to download and run the MGA Diagnostic and a couple of re-validation programs. This seems to have stopped the MS problem, according to logs they are *finally* uninstalling a lot of services and devices which I've long been suspicious of, apparently packing up and going home. The MGA diagnostic reported that my product key had been "tampered with".

Several days ago I also installed Sophos rootkit scanner, which so far appears to be much more effective than earlier scanners. My first scan with it revealed just one hidden file, sptd.sys, in its correct filepath. And it had these rather suspicious timestamps (I had earlier disabled persistent timestamps in the registry):

Created: Sun 27 Jun 2010 11:57:06 PM
Modified: Sun 27 Jun 2010 11:57:06 PM
Accessed: Sun 27 Jun 2010 11:57:06 PM

I contacted the vendor about this, they had me download the sptd.sys installation file and run it, but just up to the first window, where it should have said that an installation already exists unless it had been a silent install, which turned out to be the indication. I also discovered another reference to sptd.sys in the registry, but this one with a legacy ROOT enumerator. I un-installed the /sustem32/drivers/sptd.sys, but the legacy ROOT file (which of course I'm unable to locate in my filesystem) remained.

After I had un-installed /system32/drivers/sptd.sys, I began having frequent crashes of explorer (particularly as soon as I'd tried opening folders with thumbnails of my photos), and so re-installed the file, stopped those crashes. Perhaps just a coincidence, but literally seconds after I had finished re-installing it, Microsoft installed another update. If there's anything to my earlier idea of MS having created a virtual drive, they may have installed sptd.sys themselves for obvious reasons.

BTW, is it normal for HKLM/SECURITY to be inaccessible, can't be expanded? I can expand it with gmer.



One thing which might be helpful here, I've found that by using a LiveCD session of ubuntu, I seem to be able to have full access (copy, delete, read, write, modify) to anything in Windows.

Thanks for making your help available!
papilio



p.s. The first time I ran OTL, Event Service was not running – happens quite a bit, is fixed by repairing permissions on a particular file, they keep getting corrupted. Then after several attempts, including using Safe Mode, OTL would only generate OTL.txt file, so I ended up including the first run anyway. Also, your instructions did not say to include the HijackThis log, I assumed that you intended us to so it's here. Let me know if you still need the events report, which *.evt file you'd like, and I'll send it.

As mentioned above, the sfc /scannow which I ran a couple of days ago showed many "shared files, and had to fix at least a hundred files. Ran it again just now, not a single thing wrong to report.


>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>


OTL logfile created on: 7/16/2010 9:54:51 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\papilio\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 71.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): f:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 14.85 Gb Free Space | 30.42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 416.93 Gb Total Space | 307.74 Gb Free Space | 73.81% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VERSICOLOR
Current User Name: papilio
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Users\papilio\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\afwServ.exe (AVAST Software)
PRC - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files\Stardock\CursorFX\CursorFX.exe (Stardock Corporation)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Windows\UnsignedThemesSvc.exe (The Within Network, LLC)
PRC - C:\Program Files\Stardock\Object Desktop\WindowBlinds\WBVista.exe ()
PRC - C:\Program Files\Stardock\Object Desktop\WindowBlinds\VistaSrv.exe (Stardock Corporation)
PRC - C:\Program Files\ShortKeys2\shklite.exe (Insight Software Solutions)


========== Modules (SafeList) ==========

MOD - C:\Users\papilio\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\Stardock\CursorFX\CurXP0.dll ( )
MOD - C:\Windows\System32\sspicli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\sechost.dll (Microsoft Corporation)
MOD - C:\Windows\System32\samcli.dll (Microsoft Corporation)
MOD - C:\Windows\System32\profapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\netutils.dll (Microsoft Corporation)
MOD - C:\Windows\System32\KernelBase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\dwmapi.dll (Microsoft Corporation)
MOD - C:\Windows\System32\devobj.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cryptbase.dll (Microsoft Corporation)
MOD - C:\Windows\System32\cfgmgr32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16385_none_421189da2b7fabfc\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\ShortKeys2\shkhook.dll (Insight Software Solutions)


========== Win32 Services (SafeList) ==========

SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Firewall) – C:\Program Files\Alwil Software\Avast5\afwServ.exe (AVAST Software)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (rpcapd) Remote Packet Capture Protocol v.0 (experimental) – C:\Program Files\WinPcap\rpcapd.exe (CACE Technologies, Inc.)
SRV - (WwanSvc) – C:\Windows\System32\wwansvc.dll (Microsoft Corporation)
SRV - (WinHttpAutoProxySvc) – winhttp.dll (Microsoft Corporation)
SRV - (WbioSrvc) – C:\Windows\System32\wbiosrvc.dll (Microsoft Corporation)
SRV - (Power) – C:\Windows\System32\umpo.dll (Microsoft Corporation)
SRV - (Themes) – C:\Windows\System32\themeservice.dll (Microsoft Corporation)
SRV - (sppuinotify) – C:\Windows\System32\sppuinotify.dll (Microsoft Corporation)
SRV - (RpcEptMapper) – C:\Windows\System32\RpcEpMap.dll (Microsoft Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (PNRPsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (p2pimsvc) – C:\Windows\System32\pnrpsvc.dll (Microsoft Corporation)
SRV - (HomeGroupProvider) – C:\Windows\System32\provsvc.dll (Microsoft Corporation)
SRV - (PNRPAutoReg) – C:\Windows\System32\pnrpauto.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (HomeGroupListener) – C:\Windows\System32\ListSvc.dll (Microsoft Corporation)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (Dhcp) – C:\Windows\System32\dhcpcore.dll (Microsoft Corporation)
SRV - (defragsvc) – C:\Windows\System32\defragsvc.dll (Microsoft Corporation)
SRV - (BDESVC) – C:\Windows\System32\bdesvc.dll (Microsoft Corporation)
SRV - (AxInstSV) ActiveX Installer (AxInstSV) – C:\Windows\System32\AxInstSv.dll (Microsoft Corporation)
SRV - (AppIDSvc) – C:\Windows\System32\appidsvc.dll (Microsoft Corporation)
SRV - (sppsvc) – C:\Windows\System32\sppsvc.exe (Microsoft Corporation)
SRV - (UnsignedThemes) – C:\Windows\UnsignedThemesSvc.exe (The Within Network, LLC)
SRV - (WindowBlinds) – C:\Program Files\Stardock\Object Desktop\WindowBlinds\VistaSrv.exe (Stardock Corporation)


========== Driver Services (SafeList) ==========

DRV - (PORTMON) – C:\Users\papilio\Downloads\SysinternalsSuite\PORTMSYS.SYS File not found
DRV - (cpuz132) – C:\Users\papilio\AppData\Local\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (sptd) – C:\Windows\System32\Drivers\sptd.sys ()
DRV - (aswFW) – C:\Windows\System32\drivers\aswFW.sys (ALWIL Software)
DRV - (aswSnx) – C:\Windows\System32\drivers\aswSnx.sys (ALWIL Software)
DRV - (aswNdis2) – C:\Windows\System32\drivers\aswNdis2.sys (ALWIL Software)
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (MEMSWEEP2) – C:\Windows\System32\F9EB.tmp (Sophos Plc)
DRV - (aswNdis) – C:\Windows\system32\DRIVERS\aswNdis.sys (ALWIL Software)
DRV - (epmntdrv) – C:\Windows\System32\epmntdrv.sys ()
DRV - (EuGdiDrv) – C:\Windows\System32\EuGdiDrv.sys ()
DRV - (KSecPkg) – C:\Windows\System32\Drivers\ksecpkg.sys (Microsoft Corporation)
DRV - (NPF) – C:\Windows\System32\drivers\npf.sys (CACE Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (adpahci) – C:\Windows\system32\DRIVERS\adpahci.sys (Adaptec, Inc.)
DRV - (adp94xx) – C:\Windows\system32\DRIVERS\adp94xx.sys (Adaptec, Inc.)
DRV - (amdsbs) – C:\Windows\system32\DRIVERS\amdsbs.sys (AMD Technologies Inc.)
DRV - (adpu320) – C:\Windows\system32\DRIVERS\adpu320.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\DRIVERS\arcsas.sys (Adaptec, Inc.)
DRV - (amdsata) – C:\Windows\system32\DRIVERS\amdsata.sys (Advanced Micro Devices)
DRV - (arc) – C:\Windows\system32\DRIVERS\arc.sys (Adaptec, Inc.)
DRV - (amdxata) – C:\Windows\system32\DRIVERS\amdxata.sys (Advanced Micro Devices)
DRV - (aliide) – C:\Windows\system32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (nfrd960) – C:\Windows\system32\DRIVERS\nfrd960.sys (IBM Corporation)
DRV - (LSI_SAS) – C:\Windows\system32\DRIVERS\lsi_sas.sys (LSI Corporation)
DRV - (iaStorV) – C:\Windows\system32\DRIVERS\iaStorV.sys (Intel Corporation)
DRV - (MegaSR) – C:\Windows\system32\DRIVERS\MegaSR.sys (LSI Corporation, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\DRIVERS\lsi_scsi.sys (LSI Corporation)
DRV - (LSI_FC) – C:\Windows\system32\DRIVERS\lsi_fc.sys (LSI Corporation)
DRV - (LSI_SAS2) – C:\Windows\system32\DRIVERS\lsi_sas2.sys (LSI Corporation)
DRV - (iirsp) – C:\Windows\system32\DRIVERS\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (megasas) – C:\Windows\system32\DRIVERS\megasas.sys (LSI Corporation)
DRV - (hwpolicy) – C:\Windows\System32\drivers\hwpolicy.sys (Microsoft Corporation)
DRV - (elxstor) – C:\Windows\system32\DRIVERS\elxstor.sys (Emulex)
DRV - (aic78xx) – C:\Windows\system32\DRIVERS\djsvs.sys (Adaptec, Inc.)
DRV - (HpSAMD) – C:\Windows\system32\DRIVERS\HpSAMD.sys (Hewlett-Packard Company)
DRV - (FsDepends) – C:\Windows\System32\drivers\fsdepends.sys (Microsoft Corporation)
DRV - (vsmraid) – C:\Windows\system32\DRIVERS\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (vhdmp) – C:\Windows\system32\DRIVERS\vhdmp.sys (Microsoft Corporation)
DRV - (vdrvroot) – C:\Windows\system32\DRIVERS\vdrvroot.sys (Microsoft Corporation)
DRV - (WIMMount) – C:\Windows\System32\drivers\wimmount.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\DRIVERS\viaide.sys (VIA Technologies, Inc.)
DRV - (ql2300) – C:\Windows\system32\DRIVERS\ql2300.sys (QLogic Corporation)
DRV - (rdyboost) – C:\Windows\System32\drivers\rdyboost.sys (Microsoft Corporation)
DRV - (ql40xx) – C:\Windows\system32\DRIVERS\ql40xx.sys (QLogic Corporation)
DRV - (SiSRaid4) – C:\Windows\system32\DRIVERS\sisraid4.sys (Silicon Integrated Systems)
DRV - (pcw) – C:\Windows\System32\drivers\pcw.sys (Microsoft Corporation)
DRV - (SiSRaid2) – C:\Windows\system32\DRIVERS\SiSRaid2.sys (Silicon Integrated Systems Corp.)
DRV - (stexstor) – C:\Windows\system32\DRIVERS\stexstor.sys (Promise Technology)
DRV - (CNG) – C:\Windows\System32\Drivers\cng.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\System32\Drivers\Brserid.sys (Brother Industries Ltd.)
DRV - (rdpbus) – C:\Windows\system32\DRIVERS\rdpbus.sys (Microsoft Corporation)
DRV - (RDPREFMP) – C:\Windows\System32\drivers\RDPREFMP.sys (Microsoft Corporation)
DRV - (RasAgileVpn) WAN Miniport (IKEv2) – C:\Windows\System32\drivers\agilevpn.sys (Microsoft Corporation)
DRV - (WfpLwf) – C:\Windows\System32\drivers\wfplwf.sys (Microsoft Corporation)
DRV - (NdisCap) – C:\Windows\System32\drivers\ndiscap.sys (Microsoft Corporation)
DRV - (vwifibus) – C:\Windows\System32\drivers\vwifibus.sys (Microsoft Corporation)
DRV - (1394ohci) – C:\Windows\system32\DRIVERS\1394ohci.sys (Microsoft Corporation)
DRV - (UmPass) – C:\Windows\system32\DRIVERS\umpass.sys (Microsoft Corporation)
DRV - (mshidkmdf) – C:\Windows\System32\drivers\mshidkmdf.sys (Microsoft Corporation)
DRV - (MTConfig) – C:\Windows\system32\DRIVERS\MTConfig.sys (Microsoft Corporation)
DRV - (CompositeBus) – C:\Windows\System32\drivers\CompositeBus.sys (Microsoft Corporation)
DRV - (AppID) – C:\Windows\system32\drivers\appid.sys (Microsoft Corporation)
DRV - (scfilter) – C:\Windows\System32\drivers\scfilter.sys (Microsoft Corporation)
DRV - (discache) – C:\Windows\System32\drivers\discache.sys (Microsoft Corporation)
DRV - (HidBatt) – C:\Windows\system32\DRIVERS\HidBatt.sys (Microsoft Corporation)
DRV - (AcpiPmi) – C:\Windows\system32\DRIVERS\acpipmi.sys (Microsoft Corporation)
DRV - (AmdPPM) – C:\Windows\system32\DRIVERS\amdppm.sys (Microsoft Corporation)
DRV - (hcw85cir) – C:\Windows\system32\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (BrUsbMdm) – C:\Windows\System32\Drivers\BrUsbMdm.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\System32\Drivers\BrUsbSer.sys (Brother Industries Ltd.)
DRV - (BrSerWdm) – C:\Windows\System32\Drivers\BrSerWdm.sys (Brother Industries Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\DRIVERS\BrFiltLo.sys (Brother Industries, Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\DRIVERS\BrFiltUp.sys (Brother Industries, Ltd.)
DRV - (b57nd60x) – C:\Windows\System32\drivers\b57nd60x.sys (Broadcom Corporation)
DRV - (ebdrv) – C:\Windows\system32\DRIVERS\evbdx.sys (Broadcom Corporation)
DRV - (b06bdrv) – C:\Windows\system32\DRIVERS\bxvbdx.sys (Broadcom Corporation)
DRV - (uxpatch) – C:\Windows\System32\drivers\uxpatch.sys ()
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6232.sys (Intel Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://radarsync.netvibes.com


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-881942326-2776305613-4268095126-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://radarsync.netvibes.com
IE - HKU\S-1-5-21-881942326-2776305613-4268095126-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-881942326-2776305613-4268095126-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKU\S-1-5-21-881942326-2776305613-4268095126-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 1C 2E 3F AB 52 15 CB 01 [binary data]
IE - HKU\S-1-5-21-881942326-2776305613-4268095126-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.addSBtoToolbar: false
FF - prefs.js..browser.search.autosizerwizard: ""
FF - prefs.js..browser.search.maxwidth: 291
FF - prefs.js..browser.search.minwidth: 291
FF - prefs.js..browser.search.openintab: true
FF - prefs.js..browser.search.update: false
FF - prefs.js..extensions.enabledItems: {dc572301-7619-498c-a57d-39143191b318}:0.3.8.4
FF - prefs.js..extensions.enabledItems: {097d3191-e6fa-4728-9826-b533d755359d}:0.7.11
FF - prefs.js..extensions.enabledItems: {8b86149f-01fb-4842-9dd8-4d7eb02fd055}:0.21.1
FF - prefs.js..extensions.enabledItems: {1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}:0.4.4
FF - prefs.js..extensions.enabledItems: {21cfaec0-dbb3-11dc-95ff-0800200c9a66}:[removed]
FF - prefs.js..extensions.enabledItems: {F645A8C9-E969-42D9-B3F3-F325537222FD}:1.1.6
FF - prefs.js..extensions.enabledItems: {03B08592-E5B4-45ff-A0BE-C1D975458688}:0.6.0.8
FF - prefs.js..extensions.enabledItems: {655397ca-4766-496b-b7a8-3a5b176ee4c2}:1.4.5
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: {113c2360-15a3-11de-8c30-0800200c9a66}:0.9
FF - prefs.js..extensions.enabledItems: {5b175400-2368-11de-8c30-0800200c9a66}:1.9


FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/05 14:50:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/07/12 18:10:04 | 000,000,000 | —D | M]

[2010/06/26 12:32:45 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\Mozilla\Extensions
[2010/07/12 18:20:28 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions
[2010/07/06 18:36:23 | 000,000,000 | —D | M] (Toolbar Buttons) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{03B08592-E5B4-45ff-A0BE-C1D975458688}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (All-in-One Sidebar) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{097d3191-e6fa-4728-9826-b533d755359d}
[2010/06/26 12:36:31 | 000,000,000 | —D | M] (No name found) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{113c2360-15a3-11de-8c30-0800200c9a66}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (Image Zoom) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{1A2D0EC4-75F5-4c91-89C4-3656F6E44B68}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (Easy DragToGo) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{21cfaec0-dbb3-11dc-95ff-0800200c9a66}
[2010/07/06 09:30:40 | 000,000,000 | —D | M] (Stylish) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}
[2010/07/06 16:19:00 | 000,000,000 | —D | M] (Oskar) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{5b175400-2368-11de-8c30-0800200c9a66}
[2010/07/12 18:10:43 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/07/08 20:40:25 | 000,000,000 | —D | M] (Searchbar Autosizer) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{655397ca-4766-496b-b7a8-3a5b176ee4c2}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (All-in-One Gestures) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (No name found) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{dc572301-7619-498c-a57d-39143191b318}
[2010/06/26 12:36:45 | 000,000,000 | —D | M] (QuickRestart) – C:\Users\papilio\AppData\Roaming\Mozilla\Firefox\Profiles\7g5slwig.default\extensions\{F645A8C9-E969-42D9-B3F3-F325537222FD}
[2010/07/12 18:10:06 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/07/12 18:10:06 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/07/12 18:09:58 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll

O1 HOSTS File: ([2009/06/10 16:39:37 | 000,000,824 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\avastUI.exe (AVAST Software)
O4 - HKU\S-1-5-21-881942326-2776305613-4268095126-1000..\Run: [CursorFX] C:\Program Files\Stardock\CursorFX\CursorFX.exe (Stardock Corporation)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Filter\application/octet-stream {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-complus {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O18 - Protocol\Filter\application/x-msdownload {1E66F26B-79EE-11D2-8710-00C04F79ED0D} - mscoree.dll (Microsoft Corporation)
O20 - AppInit_DLLs: (wbsys.dll) - wbsys.dll (Stardock.Net, Inc)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - Winlogon\Notify\WBSrv: DllName - C:\Program Files\Stardock\Object Desktop\WindowBlinds\wbsrv.dll - C:\Program Files\Stardock\Object Desktop\WindowBlinds\WbSrv.dll (Stardock Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O29 - HKLM SecurityProviders - (credssp.dll) - credssp.dll (Microsoft Corporation)
O30 - LSA: Security Packages - (pku2u) - C:\Windows\System32\pku2u.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 16:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{7931d0ca-8154-11df-962b-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7931d0ca-8154-11df-962b-806e6f6e6963}\Shell\AutoRun\command - "" = D:\CaptureNXSetup.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/07/16 21:10:58 | 000,574,976 | —- | C] (OldTimer Tools) – C:\Users\papilio\Desktop\OTL.exe
[2010/07/16 21:06:51 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Users\papilio\Desktop\HiJackThis.exe
[2010/07/15 18:56:46 | 000,000,000 | —D | C] – C:\New folder (2)
[2010/07/15 18:31:21 | 000,000,000 | —D | C] – C:\Users\papilio\Desktop\Devine_Icons_Part_2_by_ipapun
[2010/07/15 10:04:17 | 000,173,119 | —- | C] (Eric_71) – C:\Users\papilio\Desktop\Rooter.exe
[2010/07/15 00:21:22 | 000,000,000 | —D | C] – C:\Users\papilio\Desktop\RootRepeal
[2010/07/13 18:27:29 | 000,000,000 | —D | C] – C:\Program Files\yzsdw109
[2010/07/13 03:24:11 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/07/13 03:24:09 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/07/13 03:24:09 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/07/12 21:30:14 | 000,000,000 | —D | C] – C:\Users\papilio\Desktop\gmer
[2010/07/12 18:39:18 | 006,153,376 | —- | C] (Malwarebytes Corporation ) – C:\Users\papilio\Desktop\mb.exe
[2010/07/12 18:27:41 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/07/12 18:24:40 | 001,154,616 | —- | C] (Piriform Ltd) – C:\Users\papilio\Desktop\ccsetup233_slim.exe
[2010/07/12 18:10:57 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/07/12 18:10:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/07/12 18:10:04 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/07/12 18:10:04 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/07/12 18:10:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/07/12 18:10:04 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/07/12 18:09:57 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/07/12 18:07:08 | 000,921,376 | —- | C] (Sun Microsystems, Inc.) – C:\Users\papilio\Desktop\JavaSetup6u20.exe
[2010/07/12 17:34:59 | 000,165,456 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/07/12 17:34:59 | 000,017,744 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/07/12 17:34:57 | 000,312,912 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswSnx.sys
[2010/07/12 17:34:56 | 000,099,280 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswFW.sys
[2010/07/12 17:34:45 | 000,188,168 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis2.sys
[2010/07/12 17:34:44 | 000,023,376 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/07/12 17:34:39 | 000,046,672 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/07/12 17:34:37 | 000,050,256 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/07/12 17:34:27 | 000,012,112 | —- | C] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis.sys
[2010/07/12 17:34:26 | 000,165,032 | —- | C] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/07/11 22:09:22 | 000,000,000 | —D | C] – C:\Program Files\RocketDock
[2010/07/10 13:32:12 | 000,000,000 | —D | C] – C:\Program Files\Sophos
[2010/07/10 12:30:14 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2010/07/10 09:30:54 | 000,000,000 | —D | C] – C:\ProgramData\Extensions
[2010/07/09 19:41:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Jasc Software Inc
[2010/07/09 19:41:37 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Jasc Software Inc
[2010/07/09 19:40:49 | 000,000,000 | —D | C] – C:\Program Files\Jasc Software Inc
[2010/07/09 19:16:56 | 000,000,000 | —D | C] – C:\New folder
[2010/07/09 00:57:49 | 000,000,000 | —D | C] – C:\.Trash-1000
[2010/07/08 12:09:19 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\gtk-2.0
[2010/07/08 12:06:57 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Wireshark
[2010/07/08 11:46:45 | 000,000,000 | —D | C] – C:\Program Files\WinPcap
[2010/07/08 11:46:27 | 000,000,000 | —D | C] – C:\Program Files\Wireshark
[2010/07/07 20:28:52 | 000,000,000 | -HSD | C] – C:\found.000
[2010/07/07 03:52:25 | 000,042,672 | —- | C] (Stardock.Net, Inc) – C:\Windows\System32\wbsys.dll
[2010/07/06 19:25:23 | 000,198,504 | —- | C] (Sysinternals - www.sysinternals.com) – C:\Users\papilio\Desktop\Tcpview - Copy.exe
[2010/07/06 11:59:44 | 000,299,520 | —- | C] (InstallShield Corporation, Inc.) – C:\Windows\uninst.exe
[2010/07/06 11:58:10 | 000,212,480 | —- | C] (Eastman Kodak) – C:\Windows\PCDLIB32.DLL
[2010/07/06 11:57:47 | 000,306,688 | —- | C] (InstallShield Software Corporation) – C:\Windows\IsUninst.exe
[2010/07/06 11:10:21 | 000,339,968 | —- | C] (CANON INC.) – C:\Windows\System32\N124UFW.dll
[2010/07/06 11:10:21 | 000,114,688 | —- | C] (CANON INC.) – C:\Windows\System32\SG62UUD.DLL
[2010/07/06 11:10:21 | 000,028,720 | —- | C] (CANON INC.) – C:\Windows\System32\SG62CPL.DLL
[2010/07/06 02:23:01 | 000,000,000 | R–D | C] – C:\Users\papilio\Desktop\[____NEF
[2010/07/05 22:25:23 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2010/07/05 21:19:15 | 010,888,168 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2010/07/05 21:19:15 | 004,967,528 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvwgf2um.dll
[2010/07/05 21:19:13 | 015,764,072 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2010/07/05 21:19:13 | 009,712,744 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvd3dum.dll
[2010/07/05 21:19:13 | 004,513,384 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2010/07/05 21:19:11 | 001,592,424 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvapi.dll
[2010/07/05 21:19:11 | 000,232,040 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcod1921.dll
[2010/07/05 21:19:11 | 000,232,040 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcod.dll
[2010/07/05 21:19:06 | 000,000,000 | —D | C] – C:\NVIDIA
[2010/07/05 21:13:45 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA
[2010/07/05 21:11:27 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Registry Mechanic
[2010/07/05 20:57:59 | 000,000,000 | —D | C] – C:\Program Files\Phyxion.net
[2010/07/05 17:43:22 | 000,000,000 | R–D | C] – C:\Users\papilio\Documents\Scanned Documents
[2010/07/05 17:43:22 | 000,000,000 | —D | C] – C:\Users\papilio\Documents\Fax
[2010/07/05 16:29:21 | 000,000,000 | —D | C] – C:\ProgramData\TEMP
[2010/07/05 14:53:09 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Help
[2010/07/05 14:53:09 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Help
[2010/07/05 14:52:21 | 000,296,960 | —- | C] (Microsoft Corporation) – C:\Windows\winhlp32.exe
[2010/07/05 14:52:21 | 000,195,072 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftsrch.dll
[2010/07/05 14:52:21 | 000,010,240 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftlx041e.dll
[2010/07/05 14:52:21 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ftlx0411.dll
[2010/07/05 14:50:56 | 000,000,000 | —D | C] – C:\ProgramData\Windows Genuine Advantage
[2010/07/05 12:42:14 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\RadarSync
[2010/07/05 11:44:26 | 000,154,496 | —- | C] (Gibson Research Corp.) – C:\Users\papilio\Desktop\DNSBench.exe
[2010/07/05 10:13:00 | 000,000,000 | —D | C] – C:\MGADiagToolOutput
[2010/07/05 10:12:25 | 000,000,000 | —D | C] – C:\ProgramData\Office Genuine Advantage
[2010/07/05 02:31:27 | 000,000,000 | —D | C] – C:\Program Files\7-Zip
[2010/07/05 02:18:39 | 000,000,000 | —D | C] – C:\Program Files\The Weather Channel FW
[2010/07/05 02:14:29 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\The Weather Channel
[2010/07/05 02:14:28 | 000,000,000 | —D | C] – C:\Program Files\Conduit
[2010/07/05 02:10:11 | 000,000,000 | —D | C] – C:\Program Files\RadarSync
[2010/07/05 01:20:56 | 000,053,248 | —- | C] (Windows XP Bundled build C-Centric Single User) – C:\Windows\System32\CSVer.dll
[2010/07/05 01:20:44 | 000,000,000 | —D | C] – C:\Intel
[2010/07/05 00:55:59 | 000,038,848 | —- | C] (ALWIL Software) – C:\Windows\avastSS.scr
[2010/07/05 00:51:51 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/07/04 23:36:10 | 000,000,000 | —D | C] – C:\Windows\System32\vmm32
[2010/07/04 23:36:09 | 000,000,000 | —D | C] – C:\Program Files\Dell
[2010/07/04 23:10:33 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Diagnostics
[2010/07/04 21:33:28 | 000,000,000 | —D | C] – C:\Program Files\MSN Toolbar Installer
[2010/07/04 21:33:27 | 000,000,000 | —D | C] – C:\ProgramData\Driver Inspector
[2010/07/04 21:17:26 | 000,000,000 | —D | C] – C:\Users\papilio\Desktop\lide20lide30n670un676un1240uvst7031a_xpen
[2010/07/04 21:16:58 | 001,070,527 | —- | C] (AKSoft) – C:\Users\papilio\Desktop\dj889mu.exe
[2010/07/04 07:58:13 | 000,157,232 | —- | C] (Alwil Software) – C:\Users\papilio\Desktop\aswclear5.exe
[2010/07/03 16:50:14 | 000,000,000 | —D | C] – C:\Program Files\Intel
[2010/07/03 16:50:14 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\InstallShield
[2010/07/03 14:50:14 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Apps
[2010/07/03 14:50:13 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Deployment
[2010/07/03 14:32:54 | 000,000,000 | —D | C] – C:\ProgramData\PC Drivers HeadQuarters
[2010/07/03 14:27:24 | 000,000,000 | —D | C] – C:\ProgramData\NVIDIA Corporation
[2010/07/03 14:27:21 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2010/07/03 14:26:55 | 000,795,104 | —- | C] (Microsoft Corporation) – C:\Windows\System32\dpinst.exe
[2010/07/03 14:26:55 | 000,056,936 | —- | C] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2010/07/03 14:26:55 | 000,010,920 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvBridge.kmd
[2010/07/03 14:26:53 | 002,890,856 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvencodemft.dll
[2010/07/03 14:26:53 | 002,632,296 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2010/07/03 14:26:53 | 002,145,896 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2010/07/03 14:26:53 | 000,332,392 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvdecodemft.dll
[2010/07/03 14:26:50 | 010,263,144 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2010/07/03 14:02:06 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\ElevatedDiagnostics
[2010/07/03 13:52:05 | 000,000,000 | —D | C] – C:\ProgramData\Driver Whiz
[2010/07/02 12:31:21 | 000,000,000 | —D | C] – C:\Windows\Minidump
[2010/07/02 12:24:26 | 000,389,180 | —- | C] (Canon) – C:\Windows\System32\UCS32P.DLL
[2010/07/02 12:24:26 | 000,036,864 | —- | C] (CANON INC.) – C:\Windows\System32\CNQU70.DLL
[2010/06/30 15:48:08 | 000,000,000 | —D | C] – C:\Users\papilio\Tracing
[2010/06/30 15:47:01 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/06/30 15:41:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2010/06/28 00:20:19 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\vlc
[2010/06/27 23:56:39 | 000,000,000 | -H-D | C] – C:\Program Files\InstallShield Installation Information
[2010/06/27 21:30:20 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\dvdcss
[2010/06/27 21:27:38 | 000,000,000 | —D | C] – C:\Program Files\VideoLAN
[2010/06/27 09:39:54 | 000,000,000 | —D | C] – C:\Program Files\MSXML 4.0
[2010/06/27 04:59:32 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Adobe
[2010/06/27 04:59:13 | 000,000,000 | —D | C] – C:\ProgramData\Adobe
[2010/06/27 04:59:10 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2010/06/27 04:59:10 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2010/06/27 03:50:12 | 000,000,000 | —D | C] – C:\Windows\System32\Wat
[2010/06/27 03:40:17 | 000,000,000 | —D | C] – C:\Program Files\Microsoft.NET
[2010/06/27 03:39:46 | 000,295,264 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHost.exe
[2010/06/27 03:39:46 | 000,099,176 | —- | C] (Microsoft Corporation) – C:\Windows\System32\PresentationHostProxy.dll
[2010/06/27 03:39:46 | 000,049,472 | —- | C] (Microsoft Corporation) – C:\Windows\System32\netfxperf.dll
[2010/06/27 03:16:48 | 000,067,584 | —- | C] (Microsoft Corporation) – C:\Windows\System32\asycfilt.dll
[2010/06/27 03:16:47 | 000,641,536 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CPFilters.dll
[2010/06/27 03:16:46 | 000,465,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\psisdecd.dll
[2010/06/27 03:16:46 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msdri.dll
[2010/06/27 03:16:46 | 000,204,288 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MSNP.ax
[2010/06/27 03:16:46 | 000,199,680 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mpg2splt.ax
[2010/06/27 03:16:36 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jscript.dll
[2010/06/27 03:16:36 | 000,108,544 | —- | C] (Microsoft Corporation) – C:\Windows\System32\t2embed.dll
[2010/06/27 03:16:33 | 000,606,208 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mstime.dll
[2010/06/27 03:16:33 | 000,381,440 | —- | C] (Microsoft Corporation) – C:\Windows\System32\iedkcs32.dll
[2010/06/27 03:16:33 | 000,064,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\msfeedsbs.dll
[2010/06/27 03:16:33 | 000,048,128 | —- | C] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2010/06/27 03:16:32 | 001,328,640 | —- | C] (Microsoft Corporation) – C:\Windows\System32\quartz.dll
[2010/06/27 03:16:32 | 000,091,648 | —- | C] (Microsoft Corporation) – C:\Windows\System32\avifil32.dll
[2010/06/27 03:16:32 | 000,084,480 | —- | C] (Microsoft Corporation) – C:\Windows\System32\mciavi32.dll
[2010/06/27 03:16:31 | 003,954,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntkrnlpa.exe
[2010/06/27 03:16:31 | 003,899,280 | —- | C] (Microsoft Corporation) – C:\Windows\System32\ntoskrnl.exe
[2010/06/27 03:16:22 | 002,614,272 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2010/06/27 03:16:19 | 001,037,312 | —- | C] (Microsoft Corporation) – C:\Windows\System32\lsasrv.dll
[2010/06/27 03:16:19 | 000,133,720 | —- | C] (Microsoft Corporation) – C:\Windows\System32\drivers\ksecpkg.sys
[2010/06/27 03:16:14 | 002,326,528 | —- | C] (Microsoft Corporation) – C:\Windows\System32\win32k.sys
[2010/06/27 03:16:11 | 001,320,960 | —- | C] (Microsoft Corporation) – C:\Windows\System32\CertEnroll.dll
[2010/06/27 03:16:11 | 000,507,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winload.exe
[2010/06/27 03:16:11 | 000,442,920 | —- | C] (Microsoft Corporation) – C:\Windows\System32\winresume.exe
[2010/06/27 03:16:10 | 012,625,408 | —- | C] (Microsoft Corporation) – C:\Windows\System32\wmploc.DLL
[2010/06/27 03:15:09 | 000,369,152 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc.dll
[2010/06/27 03:15:09 | 000,365,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_isv.dll
[2010/06/27 03:15:09 | 000,324,608 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_isv.exe
[2010/06/27 03:15:09 | 000,320,512 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate.exe
[2010/06/27 03:15:09 | 000,280,064 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp.exe
[2010/06/27 03:15:09 | 000,277,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\RMActivate_ssp_isv.exe
[2010/06/27 03:15:09 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp_isv.dll
[2010/06/27 03:15:09 | 000,085,504 | —- | C] (Microsoft Corporation) – C:\Windows\System32\secproc_ssp.dll
[2010/06/27 03:15:07 | 000,427,520 | —- | C] (Microsoft Corporation) – C:\Windows\System32\vbscript.dll
[2010/06/27 03:14:58 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/06/27 03:14:54 | 000,293,888 | —- | C] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/06/27 03:14:54 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\System32\fontsub.dll
[2010/06/27 03:14:54 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/06/26 18:19:50 | 000,000,000 | R–D | C] – C:\KB
[2010/06/26 17:34:01 | 000,000,000 | —D | C] – C:\Program Files\EASEUS
[2010/06/26 14:55:31 | 000,000,000 | —D | C] – C:\Windows\Panther
[2010/06/26 14:50:44 | 000,000,000 | —D | C] – C:\Windows.old
[2010/06/26 14:50:35 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Stardock
[2010/06/26 14:48:31 | 000,000,000 | -H-D | C] – C:\ProgramData\{E568B6A0-8E02-46C8-8954-00ECD7CD3554}
[2010/06/26 14:48:30 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Stardock
[2010/06/26 14:48:30 | 000,000,000 | —D | C] – C:\Program Files\Stardock
[2010/06/26 14:44:41 | 008,876,032 | —- | C] (Acclaim Software Ltd) – C:\Windows\System32\FocusMag.dll
[2010/06/26 14:44:40 | 000,000,000 | —D | C] – C:\Program Files\Focus Magic
[2010/06/26 14:40:23 | 000,000,000 | —D | C] – C:\Program Files\WinRoll
[2010/06/26 14:34:11 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Malwarebytes
[2010/06/26 14:34:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/06/26 14:17:01 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\AVP 2009
[2010/06/26 14:12:26 | 000,000,000 | —D | C] – C:\ProgramData\InstallShield
[2010/06/26 14:12:03 | 000,000,000 | —D | C] – C:\Users\papilio\Documents\My PSP Files
[2010/06/26 13:57:42 | 000,000,000 | —D | C] – C:\Users\Public\Documents\Insight Software
[2010/06/26 13:57:40 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Insight Software Solutions
[2010/06/26 13:57:39 | 000,000,000 | —D | C] – C:\Program Files\ShortKeys2
[2010/06/26 13:56:50 | 000,000,000 | —D | C] – C:\Windows\Prefetch
[2010/06/26 13:56:31 | 000,000,000 | —D | C] – C:\Program Files\IrfanView
[2010/06/26 13:43:52 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Nikon
[2010/06/26 13:40:55 | 000,000,000 | —D | C] – C:\Program Files\Common Files\InstallShield
[2010/06/26 13:40:30 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Nikon
[2010/06/26 13:40:30 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Nikon
[2010/06/26 13:40:24 | 000,000,000 | —D | C] – C:\Program Files\Nikon
[2010/06/26 13:39:54 | 000,000,000 | —D | C] – C:\ProgramData\Ultima_T15
[2010/06/26 13:39:54 | 000,000,000 | —D | C] – C:\ProgramData\EnterNHelp
[2010/06/26 12:51:54 | 000,000,000 | —D | C] – C:\_SPC1
[2010/06/26 12:46:05 | 000,221,568 | —- | C] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/06/26 12:32:40 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Mozilla
[2010/06/26 12:32:40 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Mozilla
[2010/06/26 12:32:33 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2010/06/26 12:24:31 | 000,000,000 | -HSD | C] – C:\Windows\Installer
[2010/06/26 12:24:26 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/06/26 12:14:31 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Macromedia
[2010/06/26 12:14:31 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Adobe
[2010/06/26 12:13:39 | 000,000,000 | —D | C] – C:\Windows\System32\Macromed
[2010/06/26 12:05:38 | 000,000,000 | R–D | C] – C:\Users\papilio\Searches
[2010/06/26 12:05:37 | 000,000,000 | -H-D | C] – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2010/06/26 12:05:28 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Identities
[2010/06/26 12:05:27 | 000,000,000 | R–D | C] – C:\Users\papilio\Contacts
[2010/06/26 12:05:21 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\VirtualStore
[2010/06/26 12:05:20 | 000,000,000 | –SD | C] – C:\Users\papilio\AppData\Roaming\Microsoft
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Videos
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Saved Games
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Pictures
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Music
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Links
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Favorites
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Downloads
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\My Documents
[2010/06/26 12:05:20 | 000,000,000 | R–D | C] – C:\Users\papilio\Desktop
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\AppData\Local\Temporary Internet Files
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Templates
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Start Menu
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\SendTo
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Recent
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\PrintHood
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\NetHood
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Documents\My Videos
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Documents\My Pictures
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Documents\My Music
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\My Documents
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Local Settings
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\AppData\Local\History
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Cookies
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\Application Data
[2010/06/26 12:05:20 | 000,000,000 | -HSD | C] – C:\Users\papilio\AppData\Local\Application Data
[2010/06/26 12:05:20 | 000,000,000 | -H-D | C] – C:\Users\papilio\AppData
[2010/06/26 12:05:20 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Temp
[2010/06/26 12:05:20 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Local\Microsoft
[2010/06/26 12:05:20 | 000,000,000 | —D | C] – C:\Users\papilio\AppData\Roaming\Media Center Programs
[2010/06/26 12:05:08 | 000,000,000 | -HSD | C] – C:\Recovery
[2010/06/26 12:05:05 | 000,000,000 | —D | C] – C:\Windows\SoftwareDistribution
[2010/06/26 11:49:01 | 000,000,000 | -HSD | C] – C:\Boot
[2010/06/26 00:57:21 | 000,000,000 | —D | C] – C:\TEMP
[2010/06/25 02:07:07 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/06/25 01:43:46 | 000,000,000 | —D | C] – C:\DELL
[2010/06/09 07:11:26 | 000,737,280 | —- | C] (Ciansoft) – C:\Windows\System32\TwainControlX.ocx
[2010/06/07 17:48:04 | 013,917,800 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvcpl.dll
[2010/06/07 17:48:04 | 001,331,816 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvsvc.dll
[2010/06/07 17:48:04 | 000,110,696 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvmctray.dll
[2010/06/07 17:48:04 | 000,066,664 | —- | C] (NVIDIA Corporation) – C:\Windows\System32\nvshext.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/07/16 21:33:19 | 001,835,008 | -HS- | M] () – C:\Users\papilio\NTUSER.DAT
[2010/07/16 21:21:34 | 000,359,929 | —- | M] () – C:\Users\papilio\Desktop\dds.scr
[2010/07/16 21:10:00 | 000,574,976 | —- | M] (OldTimer Tools) – C:\Users\papilio\Desktop\OTL.exe
[2010/07/16 21:06:56 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Users\papilio\Desktop\HiJackThis.exe
[2010/07/16 01:50:02 | 000,019,312 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2010/07/16 01:50:02 | 000,019,312 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2010/07/15 12:49:42 | 000,000,175 | —- | M] () – C:\Users\papilio\Desktop\Hopeless__by_Lyon106.7z
[2010/07/15 12:48:55 | 000,726,316 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/07/15 12:48:55 | 000,623,940 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/07/15 12:48:55 | 000,106,316 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/07/15 12:44:37 | 000,000,330 | —- | M] () – C:\Windows\tasks\Anti_Malware_Pro.job
[2010/07/15 12:44:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/07/15 12:44:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/07/15 12:44:11 | 2414,284,800 | -HS- | M] () – C:\hiberfil.sys
[2010/07/15 12:42:30 | 001,262,108 | -H– | M] () – C:\Users\papilio\AppData\Local\IconCache.db
[2010/07/15 11:12:42 | 000,000,167 | —- | M] () – C:\Users\papilio\AppData\Roaming\PLGComp.ini
[2010/07/15 10:27:13 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2010/07/15 10:04:18 | 000,173,119 | —- | M] (Eric_71) – C:\Users\papilio\Desktop\Rooter.exe
[2010/07/15 09:30:54 | 001,059,885 | —- | M] () – C:\Users\papilio\Desktop\Aphotic_CAD_by_murasaki55.zip
[2010/07/15 09:19:29 | 004,749,591 | —- | M] () – C:\Users\papilio\Desktop\World_hold_on_by_art_styles.zip
[2010/07/15 09:17:25 | 003,298,846 | —- | M] () – C:\Users\papilio\Desktop\Revolution_in_Paradise_by_art_styles.zip
[2010/07/15 09:09:29 | 051,585,091 | —- | M] () – C:\Users\papilio\Desktop\Devine_Icons_Part_2_by_ipapun.zip
[2010/07/15 09:04:31 | 003,186,864 | —- | M] () – C:\Users\papilio\Desktop\Relaxet__Wallpapers_2_by_ipapun.zip
[2010/07/15 08:50:46 | 000,702,512 | —- | M] () – C:\Users\papilio\Desktop\Mini_Calendar_by_murasaki55.rar
[2010/07/15 08:43:59 | 000,000,026 | —- | M] () – C:\Users\papilio\Desktop\Hopeless__by_Lyon106.png
[2010/07/15 07:02:04 | 012,228,493 | —- | M] () – C:\Users\papilio\Desktop\APPOWS2010_by_neiio.7z
[2010/07/15 00:33:55 | 000,007,764 | —- | M] () – C:\Users\papilio\Documents\cc_20100715_003137.reg
[2010/07/15 00:24:11 | 000,000,969 | —- | M] () – C:\Users\papilio\Desktop\CCleaner.lnk
[2010/07/15 00:07:50 | 000,465,298 | —- | M] () – C:\Users\papilio\Desktop\RootRepeal.rar
[2010/07/14 23:01:27 | 000,000,000 | —- | M] () – C:\Windows\System32\settings.dat
[2010/07/14 17:59:38 | 000,268,184 | —- | M] () – C:\Windows\System32\FNTCACHE.DAT
[2010/07/14 17:56:07 | 000,697,328 | —- | M] () – C:\Windows\System32\drivers\sptd.sys
[2010/07/14 15:18:30 | 000,866,107 | —- | M] () – C:\Users\papilio\Desktop\Image3b.jpg
[2010/07/14 15:16:58 | 002,025,645 | —- | M] () – C:\Users\papilio\Desktop\Lightness5.pspimage
[2010/07/14 13:38:09 | 082,325,439 | —- | M] () – C:\Users\papilio\Desktop\Image7.pspimage
[2010/07/14 10:54:12 | 000,915,882 | —- | M] () – C:\Users\papilio\Desktop\Image3.jpg
[2010/07/14 08:25:05 | 000,058,040 | —- | M] () – C:\Users\papilio\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/07/14 01:04:26 | 000,000,937 | —- | M] () – C:\Users\papilio\Desktop\RocketDock.lnk
[2010/07/13 10:25:51 | 017,250,800 | —- | M] () – C:\Users\papilio\Documents\XWD_Create_his_skin_tutorial_by_RajTheeban95.pdf
[2010/07/13 03:24:13 | 000,000,983 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/13 02:54:13 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/07/12 21:28:50 | 000,284,915 | —- | M] () – C:\Users\papilio\Desktop\gmer.zip
[2010/07/12 18:42:45 | 002,396,509 | —- | M] () – C:\Users\papilio\Desktop\MGtools.exe
[2010/07/12 18:42:03 | 003,737,917 | —- | M] () – C:\Users\papilio\Desktop\ComboFix.exe
[2010/07/12 18:39:58 | 006,153,376 | —- | M] (Malwarebytes Corporation ) – C:\Users\papilio\Desktop\mb.exe
[2010/07/12 18:36:58 | 000,000,000 | —- | M] () – C:\Users\papilio\defogger_reenable
[2010/07/12 18:36:39 | 000,050,477 | —- | M] () – C:\Users\papilio\Desktop\Defogger.exe
[2010/07/12 18:24:49 | 001,154,616 | —- | M] (Piriform Ltd) – C:\Users\papilio\Desktop\ccsetup233_slim.exe
[2010/07/12 18:09:58 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\deployJava1.dll
[2010/07/12 18:09:58 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaws.exe
[2010/07/12 18:09:58 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\javaw.exe
[2010/07/12 18:09:58 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\java.exe
[2010/07/12 18:07:11 | 000,921,376 | —- | M] (Sun Microsystems, Inc.) – C:\Users\papilio\Desktop\JavaSetup6u20.exe
[2010/07/12 17:34:59 | 000,002,009 | —- | M] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2010/07/11 22:49:14 | 000,000,199 | —- | M] () – C:\Users\papilio\Desktop\Event log error 4201 - ERROR_WMI_INSTANCE_NOT_FOUND.url
[2010/07/11 20:32:08 | 000,001,357 | —- | M] () – C:\Users\papilio\Desktop\autoruns.exe - Shortcut.lnk
[2010/07/11 20:01:21 | 000,000,164 | —- | M] () – C:\Users\papilio\Desktop\taskeng.exe and Dwm.exe.url
[2010/07/11 17:35:36 | 000,001,344 | —- | M] () – C:\Users\papilio\Desktop\Procmon.exe - Shortcut.lnk
[2010/07/11 17:21:00 | 219,973,696 | —- | M] () – C:\Users\papilio\Documents\7.10.PML
[2010/07/11 17:21:00 | 014,589,663 | —- | M] () – C:\Users\papilio\Documents\7.10-1.PML
[2010/07/11 17:17:09 | 000,007,605 | —- | M] () – C:\Users\papilio\AppData\Local\Resmon.ResmonCfg
[2010/07/10 15:04:45 | 003,814,578 | —- | M] () – C:\Users\papilio\Desktop\hklu serv.reg
[2010/07/10 14:55:09 | 000,001,146 | —- | M] () – C:\Users\papilio\Desktop\hm.reg
[2010/07/10 09:30:55 | 000,000,020 | -H– | M] () – C:\ProgramData\PKP_DLbx.DAT
[2010/07/10 09:30:54 | 000,000,268 | RH– | M] () – C:\ProgramData\Basic Track
[2010/07/10 09:30:54 | 000,000,268 | RH– | M] () – C:\Users\papilio\AppData\Roaming\Automatic Filter
[2010/07/10 09:29:45 | 000,001,155 | —- | M] () – C:\Users\Public\Desktop\Capture NX 2.lnk
[2010/07/10 08:49:57 | 027,651,915 | —- | M] () – C:\Users\papilio\Desktop\Image10.tif
[2010/07/10 08:47:14 | 006,913,515 | —- | M] () – C:\Users\papilio\Desktop\Image9.tif
[2010/07/10 07:31:47 | 009,427,457 | —- | M] () – C:\Users\papilio\Desktop\!_Image7.tif
[2010/07/10 07:31:24 | 011,366,710 | —- | M] () – C:\Users\papilio\Desktop\Image3.pspimage
[2010/07/10 02:29:14 | 129,239,324 | —- | M] () – C:\Users\papilio\Desktop\Image4.pspimage
[2010/07/10 00:27:03 | 000,000,942 | —- | M] () – C:\Users\Public\Desktop\Focus Magic.lnk
[2010/07/09 23:35:03 | 003,394,102 | —- | M] () – C:\Users\papilio\Desktop\13.bmp
[2010/07/09 21:52:37 | 000,087,800 | —- | M] () – C:\Users\papilio\Desktop\point.htm
[2010/07/09 20:02:44 | 000,672,309 | —- | M] () – C:\Users\papilio\Desktop\preview-1-7144.jpg
[2010/07/09 19:41:57 | 000,002,671 | —- | M] () – C:\Users\Public\Desktop\Jasc Paint Shop Pro 9.lnk
[2010/07/08 15:54:34 | 000,000,218 | —- | M] () – C:\Users\papilio\.recently-used.xbel
[2010/07/08 14:05:43 | 000,000,066 | —- | M] () – C:\Users\papilio\Desktop\acl access
[2010/07/08 14:04:22 | 000,000,066 | —- | M] () – C:\Users\papilio\Desktop\acl2
[2010/07/08 12:09:19 | 000,000,066 | —- | M] () – C:\Users\papilio\Documents\enable acl
[2010/07/08 11:46:34 | 000,001,688 | —- | M] () – C:\Users\Public\Desktop\Wireshark.lnk
[2010/07/07 04:06:36 | 000,000,455 | —- | M] () – C:\Windows\win.ini
[2010/07/07 03:53:17 | 000,002,166 | —- | M] () – C:\Users\Public\Desktop\WindowBlinds.lnk
[2010/07/06 19:48:30 | 000,000,024 | —- | M] () – C:\Windows\pstudio.ini
[2010/07/06 19:48:30 | 000,000,011 | —- | M] () – C:\Windows\album.ini
[2010/07/06 19:48:07 | 000,000,008 | —- | M] () – C:\Windows\phbase.ini
[2010/07/06 12:01:07 | 000,000,572 | —- | M] () – C:\Windows\maxlink.ini
[2010/07/06 12:00:20 | 000,000,000 | —- | M] () – C:\Windows\OP70.INI
[2010/07/06 09:24:45 | 000,000,000 | —- | M] () – C:\ProgramData\Sounds
[2010/07/05 11:44:26 | 000,154,496 | —- | M] (Gibson Research Corp.) – C:\Users\papilio\Desktop\DNSBench.exe
[2010/07/05 11:41:34 | 000,000,714 | —- | M] () – C:\Users\papilio\Desktop\releaserenew.zip
[2010/07/05 11:26:50 | 000,451,584 | —- | M] () – C:\Users\papilio\Desktop\CKScanner.exe
[2010/07/05 02:34:48 | 000,000,570 | —- | M] () – C:\Users\papilio\Desktop\papilio.PspWorkspace - Shortcut.lnk
[2010/07/04 21:10:27 | 001,070,527 | —- | M] (AKSoft) – C:\Users\papilio\Desktop\dj889mu.exe
[2010/07/04 07:10:04 | 000,157,232 | —- | M] (Alwil Software) – C:\Users\papilio\Desktop\aswclear5.exe
[2010/07/04 06:19:39 | 000,001,669 | —- | M] () – C:\Users\papilio\Desktop\license.avastlic
[2010/07/03 01:56:57 | 000,000,000 | -H– | M] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/06/28 15:57:33 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\avastSS.scr
[2010/06/28 15:57:12 | 000,165,032 | —- | M] (AVAST Software) – C:\Windows\System32\aswBoot.exe
[2010/06/28 15:39:55 | 000,099,280 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFW.sys
[2010/06/28 15:39:38 | 000,312,912 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSnx.sys
[2010/06/28 15:38:56 | 000,188,168 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswNdis2.sys
[2010/06/28 15:37:52 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/06/28 15:37:30 | 000,165,456 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/06/28 15:33:13 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/06/28 15:32:56 | 000,050,256 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/06/28 15:32:33 | 000,017,744 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/06/27 23:56:39 | 000,001,024 | —- | M] () – C:\Users\papilio\Desktop\Active@ ISO Burner.lnk
[2010/06/27 21:26:34 | 000,000,209 | —- | M] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\FREE GAMES!.url
[2010/06/27 21:26:34 | 000,000,205 | —- | M] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\1000 Free Songs!.url
[2010/06/26 17:34:07 | 000,001,392 | —- | M] () – C:\Users\Public\Desktop\EASEUS Partition Master 5.8.1 Home Edition.lnk
[2010/06/26 14:55:19 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2010/06/26 14:55:18 | 000,000,355 | RHS- | M] () – C:\Boot.ini.saved
[2010/06/26 13:59:25 | 000,041,962 | —- | M] () – C:\Windows\System32\license.rtf
[2010/06/26 13:57:40 | 000,000,573 | —- | M] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
[2010/06/26 12:32:36 | 000,001,913 | —- | M] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/06/26 12:11:40 | 000,001,411 | —- | M] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/26 12:07:50 | 000,524,288 | -HS- | M] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/06/26 12:07:50 | 000,524,288 | -HS- | M] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/06/26 12:07:50 | 000,065,536 | -HS- | M] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/06/26 12:05:20 | 000,000,020 | -HS- | M] () – C:\Users\papilio\ntuser.ini
[2010/06/25 01:43:31 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/06/25 01:43:31 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/06/25 01:40:01 | 000,000,211 | -H– | M] () – C:\Boot.BAK
[2010/06/07 18:57:00 | 015,764,072 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvoglv32.dll
[2010/06/07 18:57:00 | 010,888,168 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvlddmkm.sys
[2010/06/07 18:57:00 | 010,263,144 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcompiler.dll
[2010/06/07 18:57:00 | 009,712,744 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvd3dum.dll
[2010/06/07 18:57:00 | 004,967,528 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvwgf2um.dll
[2010/06/07 18:57:00 | 004,513,384 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuda.dll
[2010/06/07 18:57:00 | 002,890,856 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvencodemft.dll
[2010/06/07 18:57:00 | 002,632,296 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuvenc.dll
[2010/06/07 18:57:00 | 002,145,896 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcuvid.dll
[2010/06/07 18:57:00 | 001,592,424 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvapi.dll
[2010/06/07 18:57:00 | 000,795,104 | —- | M] (Microsoft Corporation) – C:\Windows\System32\dpinst.exe
[2010/06/07 18:57:00 | 000,332,392 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvdecodemft.dll
[2010/06/07 18:57:00 | 000,232,040 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcod1921.dll
[2010/06/07 18:57:00 | 000,232,040 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcod.dll
[2010/06/07 18:57:00 | 000,056,936 | —- | M] (Khronos Group) – C:\Windows\System32\OpenCL.dll
[2010/06/07 18:57:00 | 000,010,920 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\drivers\nvBridge.kmd
[2010/06/07 18:57:00 | 000,009,633 | —- | M] () – C:\Windows\System32\nvinfo.pb
[2010/06/07 17:48:04 | 013,917,800 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvcpl.dll
[2010/06/07 17:48:04 | 001,331,816 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvsvc.dll
[2010/06/07 17:48:04 | 000,110,696 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvmctray.dll
[2010/06/07 17:48:04 | 000,066,664 | —- | M] (NVIDIA Corporation) – C:\Windows\System32\nvshext.dll
[2010/06/07 15:59:46 | 000,057,904 | —- | M] () – C:\Windows\System32\wbload.dll
[2010/05/27 02:24:13 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\System32\atmlib.dll
[2010/05/26 22:49:37 | 000,293,888 | —- | M] (Adobe Systems Incorporated) – C:\Windows\System32\atmfd.dll
[2010/05/21 14:14:28 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/21 00:14:50 | 000,048,128 | —- | M] (Microsoft Corporation) – C:\Windows\System32\jsproxy.dll
[2 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/07/16 21:21:33 | 000,359,929 | —- | C] () – C:\Users\papilio\Desktop\dds.scr
[2010/07/15 12:49:42 | 000,000,175 | —- | C] () – C:\Users\papilio\Desktop\Hopeless__by_Lyon106.7z
[2010/07/15 10:27:13 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2010/07/15 09:30:47 | 001,059,885 | —- | C] () – C:\Users\papilio\Desktop\Aphotic_CAD_by_murasaki55.zip
[2010/07/15 09:18:44 | 004,749,591 | —- | C] () – C:\Users\papilio\Desktop\World_hold_on_by_art_styles.zip
[2010/07/15 09:17:12 | 003,298,846 | —- | C] () – C:\Users\papilio\Desktop\Revolution_in_Paradise_by_art_styles.zip
[2010/07/15 09:03:29 | 003,186,864 | —- | C] () – C:\Users\papilio\Desktop\Relaxet__Wallpapers_2_by_ipapun.zip
[2010/07/15 09:00:21 | 051,585,091 | —- | C] () – C:\Users\papilio\Desktop\Devine_Icons_Part_2_by_ipapun.zip
[2010/07/15 08:50:41 | 000,702,512 | —- | C] () – C:\Users\papilio\Desktop\Mini_Calendar_by_murasaki55.rar
[2010/07/15 08:43:59 | 000,000,026 | —- | C] () – C:\Users\papilio\Desktop\Hopeless__by_Lyon106.png
[2010/07/15 07:00:21 | 012,228,493 | —- | C] () – C:\Users\papilio\Desktop\APPOWS2010_by_neiio.7z
[2010/07/15 00:31:39 | 000,007,764 | —- | C] () – C:\Users\papilio\Documents\cc_20100715_003137.reg
[2010/07/15 00:07:46 | 000,465,298 | —- | C] () – C:\Users\papilio\Desktop\RootRepeal.rar
[2010/07/14 23:01:27 | 000,000,000 | —- | C] () – C:\Windows\System32\settings.dat
[2010/07/14 17:56:07 | 000,697,328 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2010/07/14 15:18:30 | 000,866,107 | —- | C] () – C:\Users\papilio\Desktop\Image3b.jpg
[2010/07/14 15:16:57 | 002,025,645 | —- | C] () – C:\Users\papilio\Desktop\Lightness5.pspimage
[2010/07/14 13:37:50 | 082,325,439 | —- | C] () – C:\Users\papilio\Desktop\Image7.pspimage
[2010/07/14 10:52:43 | 000,915,882 | —- | C] () – C:\Users\papilio\Desktop\Image3.jpg
[2010/07/13 10:25:51 | 017,250,800 | —- | C] () – C:\Users\papilio\Documents\XWD_Create_his_skin_tutorial_by_RajTheeban95.pdf
[2010/07/13 03:24:13 | 000,000,983 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/07/12 21:28:49 | 000,284,915 | —- | C] () – C:\Users\papilio\Desktop\gmer.zip
[2010/07/12 18:42:32 | 002,396,509 | —- | C] () – C:\Users\papilio\Desktop\MGtools.exe
[2010/07/12 18:41:35 | 003,737,917 | —- | C] () – C:\Users\papilio\Desktop\ComboFix.exe
[2010/07/12 18:36:58 | 000,000,000 | —- | C] () – C:\Users\papilio\defogger_reenable
[2010/07/12 18:36:39 | 000,050,477 | —- | C] () – C:\Users\papilio\Desktop\Defogger.exe
[2010/07/12 18:27:46 | 000,000,969 | —- | C] () – C:\Users\papilio\Desktop\CCleaner.lnk
[2010/07/12 17:34:59 | 000,002,009 | —- | C] () – C:\Users\Public\Desktop\avast! Internet Security.lnk
[2010/07/11 22:49:14 | 000,000,199 | —- | C] () – C:\Users\papilio\Desktop\Event log error 4201 - ERROR_WMI_INSTANCE_NOT_FOUND.url
[2010/07/11 22:09:25 | 000,000,937 | —- | C] () – C:\Users\papilio\Desktop\RocketDock.lnk
[2010/07/11 20:32:08 | 000,001,357 | —- | C] () – C:\Users\papilio\Desktop\autoruns.exe - Shortcut.lnk
[2010/07/11 20:01:21 | 000,000,164 | —- | C] () – C:\Users\papilio\Desktop\taskeng.exe and Dwm.exe.url
[2010/07/11 17:35:36 | 000,001,344 | —- | C] () – C:\Users\papilio\Desktop\Procmon.exe - Shortcut.lnk
[2010/07/11 17:20:25 | 014,589,663 | —- | C] () – C:\Users\papilio\Documents\7.10-1.PML
[2010/07/11 17:19:47 | 219,973,696 | —- | C] () – C:\Users\papilio\Documents\7.10.PML
[2010/07/11 17:17:09 | 000,007,605 | —- | C] () – C:\Users\papilio\AppData\Local\Resmon.ResmonCfg
[2010/07/10 15:04:45 | 003,814,578 | —- | C] () – C:\Users\papilio\Desktop\hklu serv.reg
[2010/07/10 14:55:09 | 000,001,146 | —- | C] () – C:\Users\papilio\Desktop\hm.reg
[2010/07/10 09:30:54 | 000,000,268 | RH– | C] () – C:\ProgramData\Basic Track
[2010/07/10 09:29:45 | 000,001,155 | —- | C] () – C:\Users\Public\Desktop\Capture NX 2.lnk
[2010/07/10 08:47:31 | 027,651,915 | —- | C] () – C:\Users\papilio\Desktop\Image10.tif
[2010/07/10 08:47:14 | 006,913,515 | —- | C] () – C:\Users\papilio\Desktop\Image9.tif
[2010/07/10 07:28:27 | 009,427,457 | —- | C] () – C:\Users\papilio\Desktop\!_Image7.tif
[2010/07/10 02:28:41 | 129,239,324 | —- | C] () – C:\Users\papilio\Desktop\Image4.pspimage
[2010/07/10 00:31:02 | 011,366,710 | —- | C] () – C:\Users\papilio\Desktop\Image3.pspimage
[2010/07/09 23:35:03 | 003,394,102 | —- | C] () – C:\Users\papilio\Desktop\13.bmp
[2010/07/09 23:21:34 | 009,458,400 | —- | C] () – C:\Users\papilio\Desktop\13017.tif
[2010/07/09 21:52:36 | 000,087,800 | —- | C] () – C:\Users\papilio\Desktop\point.htm
[2010/07/09 20:02:44 | 000,672,309 | —- | C] () – C:\Users\papilio\Desktop\preview-1-7144.jpg
[2010/07/09 19:42:15 | 000,002,671 | —- | C] () – C:\Users\Public\Desktop\Jasc Paint Shop Pro 9.lnk
[2010/07/08 15:54:34 | 000,000,218 | —- | C] () – C:\Users\papilio\.recently-used.xbel
[2010/07/08 14:04:22 | 000,000,066 | —- | C] () – C:\Users\papilio\Desktop\acl2
[2010/07/08 12:10:23 | 000,000,066 | —- | C] () – C:\Users\papilio\Desktop\acl access
[2010/07/08 12:09:19 | 000,000,066 | —- | C] () – C:\Users\papilio\Documents\enable acl
[2010/07/08 11:46:34 | 000,001,688 | —- | C] () – C:\Users\Public\Desktop\Wireshark.lnk
[2010/07/07 03:53:17 | 000,002,166 | —- | C] () – C:\Users\Public\Desktop\WindowBlinds.lnk
[2010/07/07 03:52:26 | 000,057,904 | —- | C] () – C:\Windows\System32\wbload.dll
[2010/07/06 20:17:20 | 000,086,016 | —- | C] () – C:\Windows\OPDIRDEL.exe
[2010/07/06 12:01:07 | 000,000,572 | —- | C] () – C:\Windows\maxlink.ini
[2010/07/06 12:00:20 | 000,000,000 | —- | C] () – C:\Windows\OP70.INI
[2010/07/06 11:59:17 | 000,000,008 | —- | C] () – C:\Windows\phbase.ini
[2010/07/06 11:58:10 | 000,000,024 | —- | C] () – C:\Windows\pstudio.ini
[2010/07/06 11:58:10 | 000,000,011 | —- | C] () – C:\Windows\album.ini
[2010/07/06 09:24:45 | 000,000,000 | —- | C] () – C:\ProgramData\Sounds
[2010/07/05 11:41:34 | 000,000,714 | —- | C] () – C:\Users\papilio\Desktop\releaserenew.zip
[2010/07/05 11:26:50 | 000,451,584 | —- | C] () – C:\Users\papilio\Desktop\CKScanner.exe
[2010/07/05 02:34:48 | 000,000,570 | —- | C] () – C:\Users\papilio\Desktop\papilio.PspWorkspace - Shortcut.lnk
[2010/07/04 06:19:39 | 000,001,669 | —- | C] () – C:\Users\papilio\Desktop\license.avastlic
[2010/07/03 14:26:55 | 000,009,633 | —- | C] () – C:\Windows\System32\nvinfo.pb
[2010/07/03 01:56:57 | 000,000,000 | -H– | C] () – C:\Windows\System32\drivers\Msft_User_WpdFs_01_09_00.Wdf
[2010/06/28 00:06:11 | 000,001,024 | —- | C] () – C:\Users\papilio\Desktop\Active@ ISO Burner.lnk
[2010/06/27 21:26:34 | 000,000,209 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\FREE GAMES!.url
[2010/06/27 21:26:34 | 000,000,205 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\1000 Free Songs!.url
[2010/06/26 17:34:07 | 000,001,392 | —- | C] () – C:\Users\Public\Desktop\EASEUS Partition Master 5.8.1 Home Edition.lnk
[2010/06/26 17:34:06 | 001,718,912 | —- | C] () – C:\Windows\System32\BootMan.exe
[2010/06/26 17:34:06 | 000,086,408 | —- | C] () – C:\Windows\System32\setupempdrv03.exe
[2010/06/26 17:34:06 | 000,014,848 | —- | C] () – C:\Windows\System32\EuEpmGdi.dll
[2010/06/26 17:34:06 | 000,014,216 | —- | C] () – C:\Windows\System32\epmntdrv.sys
[2010/06/26 17:34:06 | 000,008,456 | —- | C] () – C:\Windows\System32\EuGdiDrv.sys
[2010/06/26 14:55:18 | 000,000,211 | -H– | C] () – C:\Boot.BAK
[2010/06/26 14:49:32 | 000,396,416 | —- | C] () – C:\Users\papilio\Desktop\papilio.PspWorkspace
[2010/06/26 14:44:41 | 000,000,942 | —- | C] () – C:\Users\Public\Desktop\Focus Magic.lnk
[2010/06/26 14:44:41 | 000,000,167 | —- | C] () – C:\Users\papilio\AppData\Roaming\PLGComp.ini
[2010/06/26 14:17:01 | 000,000,330 | —- | C] () – C:\Windows\tasks\Anti_Malware_Pro.job
[2010/06/26 13:57:40 | 000,000,573 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ShortKeys Lite.lnk
[2010/06/26 13:56:11 | 2414,284,800 | -HS- | C] () – C:\hiberfil.sys
[2010/06/26 13:43:39 | 000,000,268 | RH– | C] () – C:\Users\papilio\AppData\Roaming\Automatic Filter
[2010/06/26 13:39:54 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLbx.DAT
[2010/06/26 12:32:36 | 000,001,913 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2010/06/26 12:11:39 | 000,001,411 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2010/06/26 12:05:20 | 001,835,008 | -HS- | C] () – C:\Users\papilio\NTUSER.DAT
[2010/06/26 12:05:20 | 000,524,288 | -HS- | C] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000002.regtrans-ms
[2010/06/26 12:05:20 | 000,524,288 | -HS- | C] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TMContainer00000000000000000001.regtrans-ms
[2010/06/26 12:05:20 | 000,262,144 | -HS- | C] () – C:\Users\papilio\ntuser.dat.LOG1
[2010/06/26 12:05:20 | 000,065,536 | -HS- | C] () – C:\Users\papilio\NTUSER.DAT{6cced2f1-6e01-11de-8bed-001e0bcd1824}.TM.blf
[2010/06/26 12:05:20 | 000,000,290 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2010/06/26 12:05:20 | 000,000,272 | —- | C] () – C:\Users\papilio\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2010/06/26 12:05:20 | 000,000,020 | -HS- | C] () – C:\Users\papilio\ntuser.ini
[2010/06/26 12:05:20 | 000,000,000 | -HS- | C] () – C:\Users\papilio\ntuser.dat.LOG2
[2010/06/26 11:49:05 | 000,008,192 | RHS- | C] () – C:\BOOTSECT.BAK
[2010/06/26 11:49:01 | 000,383,562 | RHS- | C] () – C:\bootmgr
[2010/06/25 01:43:31 | 000,000,000 | RHS- | C] () – C:\MSDOS.SYS
[2010/06/25 01:43:31 | 000,000,000 | RHS- | C] () – C:\IO.SYS
[2009/10/20 13:19:30 | 000,053,299 | —- | C] () – C:\Windows\System32\pthreadVC.dll
[2009/07/13 18:51:43 | 000,073,728 | —- | C] () – C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 18:42:10 | 000,064,000 | —- | C] () – C:\Windows\System32\BWContextHandler.dll
[2009/07/13 01:07:46 | 000,025,448 | —- | C] () – C:\Windows\System32\drivers\uxpatch.sys

========== LOP Check ==========

[2010/06/26 14:26:42 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\AVP 2009
[2010/07/08 14:05:43 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\gtk-2.0
[2010/06/26 13:44:15 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\Nikon
[2010/07/05 21:11:27 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\Registry Mechanic
[2010/07/08 15:54:34 | 000,000,000 | —D | M] – C:\Users\papilio\AppData\Roaming\Wireshark
[2010/07/15 12:44:37 | 000,000,330 | —- | M] () – C:\Windows\Tasks\Anti_Malware_Pro.job
[2009/07/13 23:53:46 | 000,022,318 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 162 bytes -> C:\ProgramData\TEMP:D1B5B4F1
< End of report >



OTL Extras logfile created on: 7/16/2010 9:54:51 PM - Run 1
OTL by OldTimer - Version 3.2.9.0 Folder = C:\Users\papilio\Desktop
Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 72.00% Memory free
7.00 Gb Paging File | 6.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): f:\pagefile.sys 4000 4000 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.83 Gb Total Space | 14.86 Gb Free Space | 30.42% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
Drive F: | 416.93 Gb Total Space | 307.74 Gb Free Space | 73.81% Space Free | Partition Type: NTFS
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: VERSICOLOR
Current User Name: papilio
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: All users
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\Windows\winhlp32.exe (Microsoft Corporation)

[HKEY_USERS\S-1-5-21-881942326-2776305613-4268095126-1000\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E363055-15E5-4D8A-9C69-A0A9DE9A3337}" = UxStyle Core Beta
"{A89768CF-CD21-44FD-A723-16D5A8557415}" = NEF Codec
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.3
"{B4F3A360-E1E2-479D-ADE7-9BE3B07F4539}" = NVIDIA PhysX
"{C1080852-065E-4991-9260-F3756E3CC182}" = CursorFX
"{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}" = Nikon Message Center
"{F843C6A3-224D-4615-94F8-3C461BD9AEA0}" = Jasc Paint Shop Pro 9
"{FCD9CD52-7222-4672-94A0-A722BA702FD0}" = Dell Resource CD
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"avast5" = avast! Internet Security
"Capture NX 2" = Capture NX 2
"CCleaner" = CCleaner
"CursorFX" = CursorFX
"EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 5.8.1 Home Edition
"Focus Magic_is1" = Focus Magic 3.02
"IrfanView" = IrfanView (remove only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Mozilla Firefox (3.6.6)" = Mozilla Firefox (3.6.6)
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"RocketDock_is1" = RocketDock 1.3.5
"ShortKeys Lite" = ShortKeys Lite
"Sophos-AntiRootkit" = Sophos Anti-Rootkit 1.5.4
"VLC media player" = VLC media player 1.1.0
"WindowBlinds" = WindowBlinds
"WinPcapInst" = WinPcap 4.1.1
"Wireshark" = Wireshark 1.2.9

========== Last 10 Event Log Errors ==========

Error reading Event Logs: The Event Service is not operating properly or the Event Logs are corrupt!

< End of report >



Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 10:45:50 PM, on 7/16/2010
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16385)
Boot mode: Normal

Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\PROGRA~1\SHORTK~1\shklite.exe
C:\Windows\system32\Dwm.exe
C:\Windows\system32\ctfmon.exe
C:\Users\papilio\Desktop\hjt.exe
C:\Windows\system32\SearchFilterHost.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://radarsync.netvibes.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://radarsync.netvibes.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [avast5] "C:\Program Files\Alwil Software\Avast5\avastUI.exe" /nogui
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [CursorFX] "C:\Program Files\Stardock\CursorFX\CursorFX.exe"
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: ShortKeys Lite.lnk = ?
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\Program Files\Alwil Software\Avast5\afwServ.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies, Inc. - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: Unsigned Themes (UnsignedThemes) - The Within Network, LLC - C:\Windows\UnsignedThemesSvc.exe
O23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\VistaSrv.exe

–
End of file - 4090 bytes





DDS (Ver_10-03-17.01) - NTFSx86
Run by [removed] at 22:22:48.09 on Fri 07/16/2010
Internet Explorer: 8.0.7600.16385 BrowserJavaVersion: 1.6.0_20
Microsoft Windows 7 Home Premium 6.1.7600.0.1252.1.1033.18.3070.1756 [GMT -5:00]

============== Running Processes ===============

C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\nvvsvc.exe
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\svchost.exe -k LocalService
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\VistaSrv.exe
C:\PROGRA~1\Stardock\OBJECT~1\WINDOW~1\WBVista.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Program Files\Alwil Software\Avast5\afwServ.exe
C:\Windows\system32\nvvsvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\System32\alg.exe
C:\Windows\system32\dllhost.exe
C:\Windows\System32\svchost.exe -k NetworkServiceAndNoImpersonation
C:\Windows\System32\msdtc.exe
C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\system32\UI0Detect.exe
C:\Windows\system32\svchost.exe -k wcssvc
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskhost.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Stardock\CursorFX\CursorFX.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\PROGRA~1\SHORTK~1\shklite.exe
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\WUDFHost.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\system32\taskhost.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\papilio\Desktop\dds.scr
C:\Windows\system32\conhost.exe
C:\Windows\system32\wbem\wmiprvse.exe

============== Pseudo HJT Report ===============

uStart Page = hxxp://radarsync.netvibes.com
mStart Page = hxxp://radarsync.netvibes.com
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
uRun: [CursorFX] "c:\program files\stardock\cursorfx\CursorFX.exe"
mRun: [Malwarebytes Anti-Malware (reboot)] "c:\program files\malwarebytes' anti-malware\mbam.exe" /runcleanupscript
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"
mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\shortk~1.lnk - c:\progra~1\shortk~1\shklite.exe
mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0)
mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3)
mPolicies-system: EnableLUA = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
mPolicies-system: PromptOnSecureDesktop = 0 (0x0)
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Notify: WBSrv - c:\program files\stardock\object desktop\windowblinds\wbsrv.dll
AppInit_DLLs: wbsys.dll

================= FIREFOX ===================

FF - ProfilePath - c:\users\papilio\appdata\roaming\mozilla\firefox\profiles\7g5slwig.default\
FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dv.dll
FF - plugin: c:\program files\nvidia corporation\3d vision\npnv3dvstreaming.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}

—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - truec:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);
c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.lu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nu", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.nz", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgberp4a5d4ar", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–p1ai", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.xn–mgbayh7gpa", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.IDN.whitelist.tel", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("network.proxy.type", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("dom.ipc.plugins.timeoutSecs", 45);
c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);
c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);
c:\program files\mozilla firefox\greprefs\all.js - pref("accelerometer.enabled", true);
c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr
ef", true);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", "");
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false);
c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");
c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.nptest.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npswf32.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npctrl.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled.npqtplugin.dll", true);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("dom.ipc.plugins.enabled", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);
c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

============= SERVICES / DRIVERS ===============

R0 aswNdis;avast! Firewall NDIS Filter Service;c:\windows\system32\drivers\aswNdis.sys [2010-7-12 12112]
R0 aswNdis2;avast! Firewall Core Firewall Service;c:\windows\system32\drivers\aswNdis2.sys [2010-7-12 190416]
R1 aswFW;avast! TDI Firewall driver;c:\windows\system32\drivers\aswFW.sys [2010-7-12 99280]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2010-7-12 307280]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-7-12 164048]
R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\sasdifsv.sys [2010-2-17 12872]
R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2010-5-10 67656]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-7-12 19024]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-7-12 51792]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-12 40384]
R2 avast! Firewall;avast! Firewall;c:\program files\alwil software\avast5\afwServ.exe [2010-7-12 119200]
R2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;c:\program files\nvidia corporation\3d vision\nvSCPAPISvr.exe [2010-6-7 240232]
R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-12 40384]
R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-7-12 40384]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2010-6-26 14216]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2010-6-26 8456]
S3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\wat\WatAdminSvc.exe [2010-6-27 1343400]

=============== Created Last 30 ================

2010-07-12 23:36:58 0 —-a-w- c:\users\papilio\defogger_reenable
2010-07-12 23:27:41 0 d—–w- c:\program files\CCleaner
2010-07-12 23:10:57 0 d—–w- c:\programdata\Sun
2010-07-12 23:10:04 411368 —-a-w- c:\windows\system32\deployJava1.dll
2010-07-12 22:34:57 307280 —-a-w- c:\windows\system32\drivers\aswSnx.sys
2010-07-12 22:34:56 99280 —-a-w- c:\windows\system32\drivers\aswFW.sys
2010-07-12 22:34:45 190416 —-a-w- c:\windows\system32\drivers\aswNdis2.sys
2010-07-12 22:34:37 51792 —-a-w- c:\windows\system32\drivers\aswMonFlt.sys
2010-07-12 22:34:27 12112 —-a-w- c:\windows\system32\drivers\aswNdis.sys
2010-07-12 18:49:39 292864 —-a-w- c:\windows\system32\apphelp.dll
2010-07-12 03:09:22 0 d—–w- c:\program files\RocketDock
2010-07-10 18:32:12 0 d—–w- c:\program files\Sophos
2010-07-10 17:30:14 0 d—–w- c:\users\papilio\appdata\roaming\SUPERAntiSpyware.com
2010-07-10 17:30:14 0 d—–w- c:\programdata\SUPERAntiSpyware.com
2010-07-10 17:30:06 0 d—–w- c:\program files\SUPERAntiSpyware
2010-07-10 14:30:54 0 d—–w- c:\programdata\Extensions
2010-07-10 00:41:44 0 d—–w- c:\program files\common files\Jasc Software Inc
2010-07-10 00:40:49 0 d—–w- c:\program files\Jasc Software Inc
2010-07-10 00:16:56 0 d—–w- C:\New folder
2010-07-09 05:57:49 0 d—–w- C:\.Trash-1000
2010-07-08 20:54:34 218 —-a-w- c:\users\papilio\.recently-used.xbel
2010-07-08 17:06:57 0 d—–w- c:\users\papilio\appdata\roaming\Wireshark
2010-07-08 16:46:45 0 d—–w- c:\program files\WinPcap
2010-07-08 16:46:27 0 d—–w- c:\program files\Wireshark
2010-07-08 01:28:52 0 d-sh–w- C:\found.000
2010-07-07 08:52:26 57904 —-a-w- c:\windows\system32\wbload.dll
2010-07-07 08:52:25 42672 —-a-w- c:\windows\system32\wbsys.dll
2010-07-07 01:17:20 86016 —-a-w- c:\windows\OPDIRDEL.exe
2010-07-06 17:01:07 572 —-a-w- c:\windows\maxlink.ini
2010-07-06 17:00:20 0 —-a-w- c:\windows\OP70.INI
2010-07-06 16:59:44 299520 —-a-w- c:\windows\uninst.exe
2010-07-06 16:59:17 8 —-a-w- c:\windows\phbase.ini
2010-07-06 16:58:10 24 —-a-w- c:\windows\pstudio.ini
2010-07-06 16:58:10 212480 —-a-w- c:\windows\PCDLIB32.DLL
2010-07-06 16:58:10 11 —-a-w- c:\windows\album.ini
2010-07-06 16:57:47 306688 —-a-w- c:\windows\IsUninst.exe
2010-07-06 16:10:21 339968 —-a-w- c:\windows\system32\N124UFW.dll
2010-07-06 16:10:21 28720 —-a-w- c:\windows\system32\SG62CPL.DLL
2010-07-06 16:10:21 114688 —-a-w- c:\windows\system32\SG62UUD.DLL
2010-07-06 14:47:48 0 d—–w- c:\temp\SGCSU622
2010-07-06 02:19:15 4967528 —-a-w- c:\windows\system32\nvwgf2um.dll
2010-07-06 02:19:15 10888168 —-a-w- c:\windows\system32\drivers\nvlddmkm.sys
2010-07-06 02:19:13 9712744 —-a-w- c:\windows\system32\nvd3dum.dll
2010-07-06 02:19:13 4513384 —-a-w- c:\windows\system32\nvcuda.dll
2010-07-06 02:19:13 15764072 —-a-w- c:\windows\system32\nvoglv32.dll
2010-07-06 02:19:11 232040 —-a-w- c:\windows\system32\nvcod1921.dll
2010-07-06 02:19:11 232040 —-a-w- c:\windows\system32\nvcod.dll
2010-07-06 02:19:11 1592424 —-a-w- c:\windows\system32\nvapi.dll
2010-07-06 02:19:06 0 d—–w- C:\NVIDIA
2010-07-06 02:13:45 0 d—–w- c:\programdata\NVIDIA
2010-07-06 02:11:27 0 d—–w- c:\users\papilio\appdata\roaming\Registry Mechanic
2010-07-06 01:57:59 0 d—–w- c:\program files\Phyxion.net
2010-07-05 21:29:21 0 d—a-w- c:\programdata\TEMP
2010-07-05 19:52:21 9216 —-a-w- c:\windows\system32\ftlx0411.dll
2010-07-05 19:52:21 296960 —-a-w- c:\windows\winhlp32.exe
2010-07-05 19:52:21 195072 —-a-w- c:\windows\system32\ftsrch.dll
2010-07-05 19:52:21 10240 —-a-w- c:\windows\system32\ftlx041e.dll
2010-07-05 19:50:56 0 d—–w- c:\programdata\Windows Genuine Advantage
2010-07-05 15:13:00 0 d—–w- C:\MGADiagToolOutput
2010-07-05 15:12:25 0 d—–w- c:\programdata\Office Genuine Advantage
2010-07-05 07:18:39 0 d—–w- c:\program files\The Weather Channel FW
2010-07-05 07:14:28 0 d—–w- c:\program files\Conduit
2010-07-05 07:10:11 0 d—–w- c:\program files\RadarSync
2010-07-05 06:20:56 53248 —-a-w- c:\windows\system32\CSVer.dll
2010-07-05 06:20:44 0 d—–w- C:\Intel
2010-07-05 05:55:59 38848 —-a-w- c:\windows\avastSS.scr
2010-07-05 04:36:10 0 d—–w- c:\windows\system32\vmm32
2010-07-05 04:36:09 0 d—–w- c:\program files\Dell
2010-07-05 02:33:28 0 d—–w- c:\program files\MSN Toolbar Installer
2010-07-05 02:33:27 0 d—–w- c:\programdata\Driver Inspector
2010-07-03 19:32:54 0 d—–w- c:\programdata\PC Drivers HeadQuarters
2010-07-03 19:27:24 0 d—–w- c:\programdata\NVIDIA Corporation
2010-07-03 19:27:21 0 d—–w- c:\program files\NVIDIA Corporation
2010-07-03 19:26:55 9633 —-a-w- c:\windows\system32\nvinfo.pb
2010-07-03 19:26:55 795104 —-a-w- c:\windows\system32\dpinst.exe
2010-07-03 19:26:55 56936 —-a-w- c:\windows\system32\OpenCL.dll
2010-07-03 19:26:55 10920 —-a-w- c:\windows\system32\drivers\nvBridge.kmd
2010-07-03 19:26:53 332392 —-a-w- c:\windows\system32\nvdecodemft.dll
2010-07-03 19:26:53 2890856 —-a-w- c:\windows\system32\nvencodemft.dll
2010-07-03 19:26:53 2632296 —-a-w- c:\windows\system32\nvcuvenc.dll
2010-07-03 19:26:53 2145896 —-a-w- c:\windows\system32\nvcuvid.dll
2010-07-03 19:26:50 10263144 —-a-w- c:\windows\system32\nvcompiler.dll
2010-07-03 18:52:05 0 d—–w- c:\programdata\Driver Whiz
2010-07-03 06:56:57 0 —ha-w- c:\windows\system32\drivers\Msft_User_WpdFs_01_09_00.Wdf
2010-07-02 17:24:26 389180 —-a-w- c:\windows\system32\UCS32P.DLL
2010-07-02 17:24:26 36864 —-a-w- c:\windows\system32\CNQU70.DLL
2010-06-30 20:48:08 0 d—–w- c:\users\papilio\Tracing
2010-06-30 20:41:36 0 d—–w- c:\program files\common files\Windows Live
2010-06-28 15:39:34 12800 —-a-w- c:\windows\system32\drivers\sffp_sd.sys
2010-06-28 02:27:38 0 d—–w- c:\program files\VideoLAN
2010-06-27 14:39:54 0 d—–w- c:\program files\MSXML 4.0
2010-06-27 09:59:13 0 d—–w- c:\programdata\Adobe
2010-06-27 08:52:34 0 d—–w- c:\temp\_asw_aisI.tm~a00664
2010-06-27 08:50:12 0 d—–w- c:\windows\system32\Wat
2010-06-27 08:44:58 257024 —-a-w- c:\windows\system32\msv1_0.dll
2010-06-27 08:39:46 99176 —-a-w- c:\windows\system32\PresentationHostProxy.dll
2010-06-27 08:39:46 49472 —-a-w- c:\windows\system32\netfxperf.dll
2010-06-27 08:39:46 297808 —-a-w- c:\windows\system32\mscoree.dll
2010-06-27 08:39:46 295264 —-a-w- c:\windows\system32\PresentationHost.exe
2010-06-27 08:39:46 1130824 —-a-w- c:\windows\system32\dfshim.dll
2010-06-27 08:15:09 85504 —-a-w- c:\windows\system32\secproc_ssp_isv.dll
2010-06-27 08:15:09 85504 —-a-w- c:\windows\system32\secproc_ssp.dll
2010-06-27 08:15:09 369152 —-a-w- c:\windows\system32\secproc.dll
2010-06-27 08:15:09 365568 —-a-w- c:\windows\system32\secproc_isv.dll
2010-06-27 08:15:09 324608 —-a-w- c:\windows\system32\RMActivate_isv.exe
2010-06-27 08:15:09 320512 —-a-w- c:\windows\system32\RMActivate.exe
2010-06-27 08:15:09 280064 —-a-w- c:\windows\system32\RMActivate_ssp.exe
2010-06-27 08:15:09 277504 —-a-w- c:\windows\system32\RMActivate_ssp_isv.exe
2010-06-27 08:15:08 95744 —-a-w- c:\windows\system32\drivers\mrxsmb20.sys
2010-06-27 08:15:08 221696 —-a-w- c:\windows\system32\drivers\mrxsmb10.sys
2010-06-27 08:15:08 123392 —-a-w- c:\windows\system32\drivers\mrxsmb.sys
2010-06-27 08:15:07 427520 —-a-w- c:\windows\system32\vbscript.dll
2010-06-27 08:14:58 2048 —-a-w- c:\windows\system32\tzres.dll
2010-06-27 08:14:54 70656 —-a-w- c:\windows\system32\fontsub.dll
2010-06-27 08:14:54 34304 —-a-w- c:\windows\system32\atmlib.dll
2010-06-27 08:14:54 293888 —-a-w- c:\windows\system32\atmfd.dll
2010-06-26 23:19:50 0 d—–r- C:\KB
2010-06-26 22:34:06 86408 —-a-w- c:\windows\system32\setupempdrv03.exe
2010-06-26 22:34:06 8456 —-a-w- c:\windows\system32\EuGdiDrv.sys
2010-06-26 22:34:06 1718912 —-a-w- c:\windows\system32\BootMan.exe
2010-06-26 22:34:06 14848 —-a-w- c:\windows\system32\EuEpmGdi.dll
2010-06-26 22:34:06 14216 —-a-w- c:\windows\system32\epmntdrv.sys
2010-06-26 22:34:01 0 d—–w- c:\program files\EASEUS
2010-06-26 19:55:31 0 d—–w- c:\windows\Panther
2010-06-26 19:50:44 0 d—–w- C:\Windows.old
2010-06-26 19:48:31 0 dc-h–w- c:\programdata\{E568B6A0-8E02-46C8-8954-00ECD7CD3554}
2010-06-26 19:48:30 0 d—–w- c:\program files\Stardock
2010-06-26 19:44:41 8876032 —-a-w- c:\windows\system32\FocusMag.dll
2010-06-26 19:44:40 0 d—–w- c:\program files\Focus Magic
2010-06-26 19:40:23 0 d—–w- c:\program files\WinRoll
2010-06-26 19:34:11 0 d—–w- c:\users\papilio\appdata\roaming\Malwarebytes
2010-06-26 19:34:03 0 d—–w- c:\programdata\Malwarebytes
2010-06-26 19:17:01 0 d—–w- c:\users\papilio\appdata\roaming\AVP 2009
2010-06-26 19:12:26 0 d—–w- c:\programdata\InstallShield
2010-06-26 18:57:40 0 d—–w- c:\program files\common files\Insight Software Solutions
2010-06-26 18:57:39 0 d—–w- c:\program files\ShortKeys2
2010-06-26 18:56:31 0 d—–w- c:\program files\IrfanView
2010-06-26 18:40:30 0 d—–w- c:\program files\common files\Nikon
2010-06-26 18:40:24 0 d—–w- c:\program files\Nikon
2010-06-26 18:39:54 20 —h–w- c:\programdata\PKP_DLbx.DAT
2010-06-26 18:39:54 0 d—–w- c:\programdata\Ultima_T15
2010-06-26 18:39:54 0 d—–w- c:\programdata\EnterNHelp
2010-06-26 17:51:54 0 d—–w- C:\_SPC1
2010-06-26 17:46:05 221568 ——w- c:\windows\system32\MpSigStub.exe
2010-06-26 17:24:31 0 d-sh–w- c:\windows\Installer
2010-06-26 17:24:26 0 d—–w- c:\programdata\Alwil Software
2010-06-26 17:07:50 726316 —-a-w- c:\windows\system32\PerfStringBackup.INI
2010-06-26 17:07:38 0 d—–w- c:\windows\system32\wbem\Performance
2010-06-26 17:06:12 172032 —-a-w- c:\windows\system32\wintrust.dll
2010-06-26 17:06:07 132608 —-a-w- c:\windows\system32\cabview.dll
2010-06-26 16:49:05 8192 –sha-r- C:\BOOTSECT.BAK
2010-06-26 16:49:01 383562 –sha-r- C:\bootmgr
2010-06-26 16:49:01 0 d-sh–w- C:\Boot
2010-06-26 16:34:26 0 d—–w- c:\temp\_av_sfx.tm~a00456
2010-06-26 05:57:21 0 d—–w- C:\TEMP
2010-06-25 06:43:46 0 d—–w- C:\DELL

==================== Find3M ====================

2010-06-07 22:48:04 66664 —-a-w- c:\windows\system32\nvshext.dll
2010-06-07 22:48:04 13917800 —-a-w- c:\windows\system32\nvcpl.dll
2010-06-07 22:48:04 1331816 —-a-w- c:\windows\system32\nvsvc.dll
2010-06-07 22:48:04 129640 —-a-w- c:\windows\system32\nvvsvc.exe
2010-06-07 22:48:04 110696 —-a-w- c:\windows\system32\nvmctray.dll
2010-05-21 05:18:06 977920 —-a-w- c:\windows\system32\wininet.dll
2010-05-09 09:14:55 641536 —-a-w- c:\windows\system32\CPFilters.dll
2010-05-09 09:14:50 417792 —-a-w- c:\windows\system32\msdri.dll
2010-05-01 14:49:25 2326528 —-a-w- c:\windows\system32\win32k.sys
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfd.dat
2009-07-14 04:56:42 31548 —-a-w- c:\windows\inf\perflib\0409\perfc.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfi.dat
2009-07-14 04:56:42 291294 —-a-w- c:\windows\inf\perflib\0409\perfh.dat
2009-07-14 04:41:57 174 –sha-w- c:\program files\desktop.ini
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfi.dat
2009-07-14 00:34:40 291294 —-a-w- c:\windows\inf\perflib\0000\perfh.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfd.dat
2009-07-14 00:34:38 31548 —-a-w- c:\windows\inf\perflib\0000\perfc.dat
2009-06-10 21:26:35 9633792 –sha-r- c:\windows\fonts\StaticCache.dat
2009-07-14 01:14:45 396800 –sha-w- c:\windows\winsxs\x86_microsoft-windows-mail-app_31bf3856ad364e35_6.1.7600.16385_none_f12e83abb108c86c\WinMail.exe

============= FINISH: 21:23:21.22 ===============
:welcome:

Lets do a few things.

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and post it in your next reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries








Please do a scan with Kaspersky Online Scanner or from Here.
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
    • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
    • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
  • Then, click: Save
  • Please post the Kaspersky Online Scanner Report in your reply.

[external image: Posted Image]

Hi ken, thanks for the reply!

First a dumb question … I've probably just not looked hard enough (though it does say below that I should be getting them), but how does one subscribe to / receive auto email notifications of replies? I only caught your reply as I happened to come by here to check. Thanks.

Well … looks like a rather nasty trojan I've got here! Glad to have found it, first time in any scan. But then if I understand the www.securelist.com report it's only been out a short while, yes? Avast and Malwarebytes scans typically come up clean, though a few new items pop up each time I do a rootkit scan. I've not done any cleaning since I first posted this thread.

A few other details / updates …

Avast was again disabled Tuesday, saying that my "trial" (this is licensed) had expired, so I was without a firewall for several hours before I caught it, then a new download and re-install of Avast, they kindly provided me with a fresh license. This, or complete un-installation, has happened quite a few times in the past couple of months.

I had to install the Kaspersky program files with Avast running, otherwise Firefox would crash – in fact it took several reboots to get back online w/Firefox, though as usual there was always considerable I/O activity seen on the DSL modem and the wired router. (The digital signature of Kaspersky's Java applet had expired, BTW.) Then before starting the scan I started Windows Firewall and disabled Avast's shields. The scan was at 17% after one hour, surprisingly finished an hour later.

Good news, the endless scanning of all directories and denied access to my own files and documents has indeed ceased since the Microsoft product key thing was cleared up. A bit difficult to believe though, that they would be so invasive. Logs have also been recording the removal of quite a few of those suspicious services, as well as "hidden" devices. If most of the trouble was in fact Microsoft-related, what might you suggest could have been a reason for having seen so much of the same behavior toward the end of using XP, before deciding to try a fix by switching to Win 7? Both legit Windows systems (OEM on the XP), no pirated software on either OS.

So anyway, here are the logs. As the instructions indicated "posting" them in the next reply, please let me know if I was incorrect in not simply attaching them. Thanks for your help ken!

** Hmm, final note…as I hit the button to post this reply several minutes ago, I was once again offline. Had been successfully using Firefox during the scan, which Kaspersky said was alright.

>>>>>>>>>>>>>>>>>>

GMER 1.0.15.15281 - http://www.gmer.net
Rootkit scan 2010-07-21 20:27:39
Windows 6.1.7600
Running: gmer.exe; Driver: C:\Users\papilio\AppData\Local\Temp\pxlyruoc.sys


—- System - GMER 1.0.15 —-

SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwAddBootEntry [0x90D1F130]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwAlpcSendWaitReceivePort [0x90D2131C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateEvent [0x90D20CE2]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateEventPair [0x90D20D3A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateIoCompletion [0x90D20E50]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateMutant [0x90D20C38]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateSection [0x90D20D8A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateSemaphore [0x90D20C8C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwCreateTimer [0x90D20DFE]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwDeleteBootEntry [0x90D1F154]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwLoadDriver [0x90D1EF5C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwModifyBootEntry [0x90D1F178]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenEvent [0x90D20D12]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenEventPair [0x90D20D62]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenIoCompletion [0x90D20E7A]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenMutant [0x90D20C64]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenSection [0x90D20DCA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenSemaphore [0x90D20CBA]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwOpenTimer [0x90D20E28]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwQueryObject [0x90D1FB48]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwReplyWaitReceivePort [0x90D216F6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwReplyWaitReceivePortEx [0x90D212F0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwSetBootEntryOrder [0x90D1F19C]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwSetBootOptions [0x90D1F1C0]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwSetSystemInformation [0x90D1EFB6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwShutdownSystem [0x90D1F0C6]
SSDT \SystemRoot\System32\Drivers\aswSnx.SYS (avast! Virtualization Driver/ALWIL Software) ZwSystemDebugControl [0x90D1F0D8]

INT 0x1F \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322FAF8
INT 0x37 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F104
INT 0xC1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F3F4
INT 0xD1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832182D8
INT 0xD2 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 83217898
INT 0xDF \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F1DC
INT 0xE1 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F958
INT 0xE3 \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322F6F8
INT 0xFD \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 8322FF2C
INT 0xFE \SystemRoot\system32\halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation) 832301A8

Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ZwCreateProcessEx [0x9078CB9C]
Code \SystemRoot\System32\Drivers\aswSP.SYS (avast! self protection module/ALWIL Software) ObMakeTemporaryObject

—- Devices - GMER 1.0.15 —-

Device \FileSystem\Ntfs \Ntfs 8623E1F8
Device \FileSystem\udfs \UdfsCdRom 86EB8470
Device \FileSystem\udfs \UdfsDisk 86EB8470
Device \Driver\volmgr \Device\VolMgrControl 855791F8
Device \Driver\ACPI_HAL \Device\00000050 halmacpi.dll (Hardware Abstraction Layer DLL/Microsoft Corporation)
Device \Driver\usbuhci \Device\USBPDO-0 86FC61F8
Device \Driver\usbuhci \Device\USBPDO-1 86FC61F8
Device \Driver\NetBT \Device\NetBT_Tcpip_{4EEE4742-0B13-451E-9D37-D51A8A02FE25} 86F631F8
Device \Driver\usbehci \Device\USBPDO-2 855AA470
Device \Driver\usbuhci \Device\USBPDO-3 86FC61F8
Device \Driver\usbuhci \Device\USBPDO-4 86FC61F8

AttachedDevice \Driver\tdx \Device\Tcp aswFW.SYS (avast! Filtering TDI driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBPDO-5 86FC61F8
Device \Driver\usbehci \Device\USBPDO-6 855AA470
Device \Driver\volmgr \Device\HarddiskVolume1 855791F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\volmgr \Device\HarddiskVolume2 855791F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\cdrom \Device\CdRom0 86E73470
Device \Driver\cdrom \Device\CdRom1 86E73470
Device \Driver\iaStorV \Device\Ide\iaStor0 8557B1F8
Device \Driver\iaStorV \Device\Ide\IAAStorageDevice-0 8557B1F8
Device \Driver\iaStorV \Device\Ide\IAAStorageDevice-1 8557B1F8
Device \Driver\iaStorV \Device\Ide\IAAStorageDevice-2 8557B1F8
Device \Driver\volmgr \Device\HarddiskVolume7 855791F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume7 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\NetBT \Device\NetBt_Wins_Export 86F631F8
Device \Driver\volmgr \Device\HarddiskVolume8 855791F8

AttachedDevice \Driver\volmgr \Device\HarddiskVolume8 fvevol.sys (BitLocker Drive Encryption Driver/Microsoft Corporation)

Device \Driver\USBSTOR \Device\00000091 878781F8
Device \Driver\USBSTOR \Device\00000092 878781F8
Device \Driver\USBSTOR \Device\00000093 878781F8

AttachedDevice \Driver\tdx \Device\Udp aswFW.SYS (avast! Filtering TDI driver/ALWIL Software)

Device \Driver\usbuhci \Device\USBFDO-0 86FC61F8
Device \Driver\usbuhci \Device\USBFDO-1 86FC61F8
Device \Driver\usbehci \Device\USBFDO-2 855AA470
Device \Driver\usbuhci \Device\USBFDO-3 86FC61F8
Device \Driver\usbuhci \Device\USBFDO-4 86FC61F8
Device \Driver\usbuhci \Device\USBFDO-5 86FC61F8
Device \Driver\usbehci \Device\USBFDO-6 855AA470

—- Registry - GMER 1.0.15 —-

Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792

—- EOF - GMER 1.0.15 —-



——————————————————————————–
KASPERSKY ONLINE SCANNER 7.0: scan report
Wednesday, July 21, 2010
Operating system: Microsoft Home Edition (build 7600)
Kaspersky Online Scanner version: 7.0.26.13
Last database update: Wednesday, July 21, 2010 23:56:37
Records in database: 4232093
——————————————————————————–

Scan settings:
scan using the following database: extended
Scan archives: yes
Scan e-mail databases: yes

Scan area - My Computer:
C:\
D:\
E:\
F:\
G:\
H:\

Scan statistics:
Objects scanned: 123320
Threats found: 1
Infected objects found: 1
Suspicious objects found: 0
Scan duration: 01:58:43


File name / Threat / Threats count
C:\Users\papilio\Desktop\MGtools.exe Infected: Trojan-Dropper.Win32.Agent.ckcd 1

Selected area has been scanned.


>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>


For what it's worth, this file's details (am not removing it) …

Created: Monday, July 12, 2010, 6:42:32 PM
Modified: Monday, July 12, 2010, 6:43:45 PM (not my own action)
Accessed: Yesterday, July 21, 2010, 9:40:53 PM

Right now, at least ( 7/22 12:50 AM), SYSTEM, Administrators and I (papilio (versicolor\papilio)) all have full permissions, I have ownership.



Okaay, this is getting wierd! lol … I was also going to take a quick look at the registry to check whether it still showed persistent timestamps as disabled (though according to the report of this trojan it may have some sort of control over the registry), had clicked RUN, only msconfig was in the field, nothing in the drop-down (I assume the action of ccleaner), came back to Firefox to check something (didn't click on anything but its title bar), went back to the RUN window and the only thing in it was now not msconfig but regedit!

* Kicked off the web again, one reboot *

And …… just now as I clicked my bookmark to come back to this page and complete my reply, I was redirected to [http - video - google - com - videoplay?docid=-8101654281814261149&q=phototechedu#] (I'm sure this is just being paranoid, but just in case … I removed the obvious slashes and dots so as not to make this a link ;) I've *never* been obviously redirected before, nor ever been to that site.

Well ken, have fun! I'm going to bed :)
Hi,

On the top of the thread click on My Controls and then under the Options tab click on Email setting and have it set to receive notifications

Not looking at anything bad, let me ask you, when you upgraded to Win 7, did you do an upgrade or a format and clean install of windows ?




You need to enable windows to show all files and folders, instructions Here

Go to VirusTotal and submit this file for analysis, just use the browse feature and then Send File, you will get a report back, post the report into this thread for me to see. If the site says this file has been checked before, have them check it again


C:\Users\papilio\Desktop\MGtools.exe

If the site is busy you can try this one

http://virusscan.jotti.org/en





Try this other scanner and see what it finds


Please run this free online virus scanner from ESET
  • Note: You will need to use Internet explorer for this scan
  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Click Start
  • Make sure that the option Remove found threats is ticked, and the option Scan unwanted applications is checked
  • Click Scan
  • Wait for the scan to finish
  • Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
  • Copy and paste that log as a reply to this topic
Hi Ken,

Just got back from your site, thanks for creating and running it! Good to have another good help site which I know I can trust. One thing I learned on this quick skim of your site, I'll start reading EULAs!

> I did get the auto email notification of your previous post without having done anything, just a quirk I guess not getting one from your first post.

> I always have all files and folders shown. (Any problem with this?)

> I've installed Win 7 many times in the few months I've had it, just to get my privileges back. It's an Upgrade, so the first (as per EULA) was on top of the existing XP. I actually reinstalled XP and then Win 7 over it the next several times, since I quickly realized that, for whatever reason, MS was miffed at me, and I wanted to be sure to play nice. Then a couple of clean installs (I was getting really mad at Microsoft and just wanted them to show their faces), the current one is on top of Win 7, on top of XP!

Can I please do a clean install without inviting MS back into my box??

And … a serious question … does MS allow an Upgrade disc to be used setting up a dual-boot machine or not? My impression from the EULA was no. Hard to imagine that though.

>>>>>>>>>>>>>>

I opened IE as Admin to start the ESET scan, but kept getting "errors on page" messages, so tried with Firefox and it appeared to run properly. I never use IE, so probably some settings are getting in the way. There were LOTS of IE "Wanna run this script? They're usually safe!" Kind of funny but that didn't sound like MS to me … but at this point, whatever, I clicked OK anyway. Never got to the download part with IE.

ESETSmartInstaller@High as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6211
# api_version=3.0.2
# EOSSerial=b5894f326fdef643a411d3bee8090599
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2010-07-23 02:39:52
# local_time=2010-07-23 09:39:52 (-0600, Central Daylight Time)
# country="United States"
# lang=1033
# osver=6.1.7600 NT
# compatibility_mode=512 16777215 100 0 0 0 0 0
# compatibility_mode=768 16777215 100 0 829236 829236 0 0
# compatibility_mode=5893 16776573 100 94 0 31438090 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=104398
# found=1
# cleaned=0
# scan_time=2692
C:\Windows.old\Program Files\vReveal\QTSourcePXT.dll Win32/Packed.Themida.AAA trojan 00000000000000000000000000000000 I




Didn't flag MGtools.exe.

(Oh, and I caught the dumb mistake I made in reading SecureList's description of the file, thinking it had just come out last month … June *2005* I see. Sorry! But this way at least it becomes feasible that this trojan may have been the problem all along, boy I hope!)


Here's the report on MGtools.exe from VirusTotal (Under "Base Data" is > timedatestamp…..: 0x4677edce (Tue Jun 19 14:53:02 2007) < on my computer? That's not what my files properties says, so just wondering.)

Antivirus Version Last Update Result
AhnLab-V3 2010.07.23.01 2010.07.23 -
AntiVir 8.2.4.26 2010.07.23 TR/Drop.Agent.ckcd
Antiy-AVL 2.0.3.7 2010.07.23 -
Authentium 5.2.0.5 2010.07.21 -
Avast 4.8.1351.0 2010.07.23 -
Avast5 5.0.332.0 2010.07.23 -
AVG 9.0.0.851 2010.07.23 -
BitDefender 7.2 2010.07.23 -
CAT-QuickHeal 11.00 2010.07.23 -
ClamAV 0.96.0.3-git 2010.07.23 -
Comodo 5517 2010.07.23 Heur.Suspicious
DrWeb 5.0.2.03300 2010.07.23 -
Emsisoft 5.0.0.34 2010.07.23 Trojan-Dropper.Agent!IK
eSafe 7.0.17.0 2010.07.22 -
eTrust-Vet 36.1.7732 2010.07.23 -
F-Prot 4.6.1.107 2010.07.23 -
F-Secure 9.0.15370.0 2010.07.23 -
Fortinet 4.1.143.0 2010.07.23 -
GData 21 2010.07.23 -
Ikarus T3.1.1.84.0 2010.07.23 Trojan-Dropper.Agent
Jiangmin 13.0.900 2010.07.23 -
Kaspersky 7.0.0.125 2010.07.23 Trojan-Dropper.Win32.Agent.ckcd
McAfee 5.400.0.1158 2010.07.23 -
McAfee-GW-Edition 2010.1 2010.07.23 -
Microsoft 1.6004 2010.07.23 -
NOD32 5305 2010.07.23 -
Norman 6.05.11 2010.07.23 -
nProtect 2010-07-23.02 2010.07.23 -
Panda 10.0.2.7 2010.07.23 Suspicious file
PCTools 7.0.3.5 2010.07.23 -
Prevx 3.0 2010.07.23 -
Rising 22.57.03.08 2010.07.23 -
Sophos 4.55.0 2010.07.23 -
Sunbelt 6624 2010.07.23 -
SUPERAntiSpyware 4.40.0.1006 2010.07.23 -
Symantec 20101.1.1.7 2010.07.23 -
TheHacker 6.5.2.1.324 2010.07.23 Trojan/Dropper.Agent.atlx
TrendMicro 9.120.0.1004 2010.07.23 -
TrendMicro-HouseCall 9.120.0.1004 2010.07.23 -
VBA32 3.12.12.6 2010.07.23 -
ViRobot 2010.7.23.3956 2010.07.23 Dropper.S.Agent.2396509
VirusBuster 5.0.27.0 2010.07.22 -

Additional information
File size: 2396509 bytes
MD5…: f212c71703e927741d02170bb62ef741
SHA1..: d260c1aea51c27389d24eadeaf6d187f656366e6
SHA256: 7094d11fcaa4050b06c16209d587597726d2df57529c8b8668fe9b963f5ca9f9
ssdeep: 49152:OHmu9sFckmK4vbYVtAU8q1NTHyx/n9UcWx9WjguXm92:PuuFD4vbYVt+q/
HW/mRbW0zk
PEiD..: -
PEInfo: PE Structure information

( base data )
entrypointaddress.: 0x1add4
timedatestamp…..: 0x4677edce (Tue Jun 19 14:53:02 2007)
machinetype…….: 0x14c (I386)

( 4 sections )
name viradd virsiz rawdsiz ntrpy md5
.text 0x1000 0x3c1b6 0x3d000 6.51 a39a3237c1edafb4753c032780e8a89d
.rdata 0x3e000 0x88c8 0x9000 5.18 675d490771e4ef56f689208b957f68b7
.data 0x47000 0x14d78 0x11000 6.06 86366ccb3ca12cc07c39b52c596791ce
.rsrc 0x5c000 0x1050 0x2000 3.09 3dbef7d2a8383162c22a75c84fcb8524

( 3 imports )
> KERNEL32.dll: GetExitCodeProcess, WaitForSingleObject, GetCurrentDirectoryW, SetEnvironmentVariableA, CompareStringW, CompareStringA, SetEndOfFile, GetStringTypeW, GetStringTypeA, LoadLibraryA, GetCPInfo, FlushFileBuffers, SetStdHandle, VirtualAlloc, IsBadCodePtr, IsBadWritePtr, IsBadReadPtr, SetUnhandledExceptionFilter, LCMapStringW, LCMapStringA, MultiByteToWideChar, VirtualFree, HeapCreate, HeapDestroy, GetEnvironmentVariableA, GetFileType, GetStdHandle, SetHandleCount, GetEnvironmentStringsW, GetEnvironmentStrings, WideCharToMultiByte, FreeEnvironmentStringsW, FreeEnvironmentStringsA, UnhandledExceptionFilter, GetProcAddress, HeapSize, GetCurrentProcess, TerminateProcess, HeapAlloc, HeapReAlloc, HeapFree, GetLocalTime, ExitProcess, GetACP, ReadFile, GetFileSize, GetLastError, LocalFree, FormatMessageA, SetFileTime, GetSystemTime, CloseHandle, SetFilePointer, GetCurrentDirectoryA, GetTempPathW, GetTempPathA, GetModuleFileNameW, GetModuleFileNameA, DeleteFileA, CreateDirectoryW, CreateDirectoryA, SetCurrentDirectoryW, SetCurrentDirectoryA, SetFileAttributesW, SetFileAttributesA, GetFileTime, GetTickCount, WriteFile, GetOEMCP, GetTimeZoneInformation, Sleep, CreateFileA, CreateFileW, GetFileAttributesA, GetFileAttributesW, GetVersionExA, RtlUnwind, GetModuleHandleA, GetStartupInfoA, GetCommandLineA, GetVersion
> USER32.dll: SetTimer, GetDlgItemTextW, SetWindowTextW, EnableWindow, EndDialog, PostQuitMessage, MessageBoxW, GetDesktopWindow, PostMessageA, CopyRect, OffsetRect, SetWindowPos, CreateWindowExW, DialogBoxParamA, LoadCursorA, RegisterClassExW, LoadStringW, GetMessageA, TranslateMessage, DispatchMessageA, MessageBoxA, SetDlgItemTextW, GetDlgItem, SendMessageA, EndPaint, BeginPaint, DestroyWindow, DefWindowProcA, LoadStringA, GetDlgItemTextA, SetDlgItemTextA, SetWindowTextA, GetWindowRect
> SHELL32.dll: SHGetPathFromIDListW, SHBrowseForFolderW, ShellExecuteExW, SHGetMalloc

( 0 exports )
RDS…: NSRL Reference Data Set
-
trid..: Win64 Executable Generic (40.0%)
Win32 Executable MS Visual C++ (generic) (17.6%)
UPX compressed Win32 Executable (14.3%)
Win32 EXE Yoda's Crypter (12.4%)
Windows Screen Saver (6.1%)
Symantec Reputation Network: Suspicious.Insight http://www.symantec.com/security_response/…-021223-0550-99
pdfid.: -
sigcheck:
publisher….: n/a
copyright….: n/a
product……: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments…..: n/a
signers……: -
signing date.: -
verified…..: Unsigned


Thanks Ken!
Michael
p.s. This is what VirusTotal gave me on the file found by ESET Antivirus Version Last Update Result AhnLab-V3 2010.07.23.01 2010.07.23 - AntiVir 8.2.4.26 2010.07.23 - Antiy-AVL 2.0.3.7 2010.07.23 - Authentium 5.2.0.5 2010.07.23 - Avast 4.8.1351.0 2010.07.23 - Avast5 5.0.332.0 2010.07.23 - AVG 9.0.0.851 2010.07.23 - BitDefender 7.2 2010.07.23 - CAT-QuickHeal 11.00 2010.07.23 - ClamAV 0.96.0.3-git 2010.07.23 - Comodo 5520 2010.07.23 - DrWeb 5.0.2.03300 2010.07.23 - Emsisoft 5.0.0.34 2010.07.23 - eSafe 7.0.17.0 2010.07.22 - eTrust-Vet 36.1.7732 2010.07.23 - F-Prot 4.6.1.107 2010.07.23 - F-Secure 9.0.15370.0 2010.07.23 - Fortinet 4.1.143.0 2010.07.23 - GData 21 2010.07.23 - Ikarus T3.1.1.84.0 2010.07.23 - Jiangmin 13.0.900 2010.07.23 - Kaspersky 7.0.0.125 2010.07.23 - McAfee 5.400.0.1158 2010.07.23 - McAfee-GW-Edition 2010.1 2010.07.23 - Microsoft 1.6004 2010.07.23 - NOD32 5306 2010.07.23 - Norman 6.05.11 2010.07.23 - nProtect 2010-07-23.02 2010.07.23 - Panda 10.0.2.7 2010.07.23 - PCTools 7.0.3.5 2010.07.23 - Prevx 3.0 2010.07.23 - Rising 22.57.03.08 2010.07.23 - Sophos 4.55.0 2010.07.23 - Sunbelt 6626 2010.07.23 - SUPERAntiSpyware 4.40.0.1006 2010.07.23 - Symantec 20101.1.1.7 2010.07.23 - TheHacker 6.5.2.1.324 2010.07.23 - TrendMicro 9.120.0.1004 2010.07.23 - TrendMicro-HouseCall 9.120.0.1004 2010.07.23 - VBA32 3.12.12.6 2010.07.23 - ViRobot 2010.7.23.3956 2010.07.23 - VirusBuster 5.0.27.0 2010.07.23 - Additional information File size: 1118208 bytes MD5…: dc70dc26d4023587740a4752de733c18 SHA1..: 61251859a96246967e08fd933660110ba85314d0 SHA256: 085d72f58bb23d29ebe9ccfed00bc9d4ef5841403ac160833c81662ac8e322db ssdeep: 24576:ewXvCXrjuZtEWvWrKo/Q7EC2jApS19Wc1FUD5zu5G6AO7JPRi:eU+nuZtE 5BQniQG8WNJPRi PEiD..: - PEInfo: PE Structure information ( base data ) entrypointaddress.: 0x35d000 timedatestamp…..: 0x499f2598 (Fri Feb 20 21:50:16 2009) machinetype…….: 0x14c (I386) ( 5 sections ) name viradd virsiz rawdsiz ntrpy md5 ovfaffii 0x1000 0x232000 0x88000 7.99 3f413214ffb3d2acff1af9536c777558 .rsrc 0x233000 0xdd8c 0xe000 3.49 268fbdc516d949e3a1ae0d1d1c18c666 dwcjnxok 0x241000 0x1000 0x1000 0.24 c9316e98082f4c4800ba72469c1b120b rwfmfjhl 0x242000 0x11b000 0x78000 7.90 42f72dfde4d1786bfa8755709229dfb0 tqbmuldl 0x35d000 0x1000 0x1000 7.05 83afa7dd50b8bd4d11502a4093421c07 ( 2 imports ) > KERNEL32.dll: CreateFileA, lstrcpy > COMCTL32.dll: InitCommonControls ( 12 exports ) DllCanUnloadNow, DllGetClassObject, DllIsQTInstalled, DllQTClose, DllQTInit, DllRegisterServer, DllUnregisterServer, QTRegisterExtensions, QTShowProps, QTUnregisterExtensions, RunDLL_QTRegisterExtensions, RunDLL_QTUnregisterExtensions RDS…: NSRL Reference Data Set - pdfid.: - trid..: Win32 Executable Generic (42.3%) Win32 Dynamic Link Library (generic) (37.6%) Generic Win/DOS Executable (9.9%) DOS Executable Generic (9.9%) Autodesk FLIC Image File (extensions: flc, fli, cel) (0.0%) sigcheck: publisher….: MediaLooks Company copyright….: Copyright 2005-09 MediaLooks product……: QuickTime DirectShow Source description..: QuickTime DirectShow Source original name: QTSource.DLL internal name: QTSource file version.: 1, 7, 0, 4 comments…..: n/a signers……: - signing date.: - verified…..: Unsigned packers (F-Prot): Themida
Hi,

C:\Users\papilio\Desktop\MGtools.exe <–I would go ahead and delete this, redownload it if its something you need.

I suspect that the problems your having are not malware related, might be due to installing , reinstalling windows so many times. As far as a dual boot, not sure, but this forum is for malware removal , we dont deal with windows problems

I do know that if you had problems before with XP and just did an win 7 upgrade , any problems malwarewise could be carried over to the new system, whats needed is to back up all your data, do a format, even delete the partition, create a new partition, format it, install windows clean.

I have to be honest with you, you have run so many programs and have done so many reinstalls that I really dont know where the problem is, dont know what files you deleted in the process or even if you installed windows correctly.

What I would do is post here in our windows forum, have them run you through a complete format and reinstall, then run DDS and post the log back here.
http://forums.whatthetech.com/index.php?showforum=119
Thanks Ken,

Great, just Shift+Deleted MGtools.exe. Certainly no need for it. Just as an aside, this evening I found this posted in Kaspersky's malware forum

"The program named MGtools.exe is a tool used to aid in the removal of malware. It was developed by me
and has been in use for years over at forums.majorgeeks.com. I have recently been getting reports by
Kasperky users that MGtools.exe is being detected as Trojan-Dropper.Win32.Agent. Please correct your
detections as this is a false detection. "



In any case, The Windows 7 era problems evidently began with some malware "tampering with" my Windows product code, as was revealed by the MS tool which the Microsoft Store specifically recommended when I called, and at this point it's quite certain – once I got that Windows activation problem cleared up, I've now begun seeing logs of MS uninstalling a lot of those ROOT-enumerated strange services, hidden devices and so on, evidently returning my machine back to its default. (These services had been specifically set up so as not to show up on scans as running processes.) And I'm finally being allowed to retain ownership of my own files. I can't believe that their activities were so invasive, but the constant scanning and monitoring of my computer, all of the outgoing communications from those services are gone. I have the feeling of being fairly secure again at last – still some trojan, rootkit or whatever is trying to fight my security software, even just this evening. I had been hoping of course that the "MGtools trojan" might account for most remaining troubles, but having now determined that the primary conflict has been cleared up, these are an annoyance at most, removal likely to be a straightforward process.


Before my first installation, I had zero-filled the HD, cleared RAM, CMOS and flashed the BIOS, then re-installed XP from my Dell OEM CD and immediately activated it (as I understood that Win 7 had to be installed over an activated prior system), and finally the Win7 Upgrade. (All apps were reinstalled either from manufacturer's discs or new and scanned downloads.) Yes, as you said, convoluted from the beginning! And then problems compounded by all of the subsequent Windows re-installations.

But now I've read on CNET that the EULA for the Upgrade has since been reworded to allow for clean installs, just as long as there had been a valid prior OS on the machine.

So, now finally a clean install, evidently Microsoft will not object, and I believe I'll be once again in the clear. Once I'm running again, whether I'm seeing problems or not, I'll certainly follow your final instruction of posting the results of DDS, for the record if nothing else. Many years of trouble-free computing behind me, I fully expect a return to that from here on.

And thank you, Ken, for "having to be honest …", that's what I came here for! I certainly had no vested interest in "proving" that it's all been malware.

Thanks again, and best regards,
Michael
Hello Michael,

Yep, read that myself about MGtools.exe , but to be on the safeside it was best to remove it and download it again if you needed it

When your up and running with the new install, post a new DDS log, if the thread is closed just start a new topic as the threads are closed if no response in 4 or 5 days.

  • How did I get infected in the first place ?
    Read these links and find out how to prevent getting infected again.
  • Tutorial for System Restore <– Do this first to prevent yourself from being reinfected.
  • WhattheTech
  • Grinler BleepingComputer
  • GeeksTo Go
  • Dslreports



Keep in mind if you install some of these programs. Only ONE Anti Virus and only ONE Firewall is recommended, more is overkill and can cause you problems. You can install all the Spyware programs I have listed without any problems. If you install Spyware Blaster and Spyware Guard, they will conflict with the TeaTimer in Spybot , you can still install Spybot Search and Destroy but do not enable the TeaTimer .



Here are some free programs to install, all free and highly regarded by the fine people in the Malware Removal Community
  • Spybot Search and Destroy 1.6
    Check for Updates/ Immunize and run a Full System Scan on a regular basis. If you install Spyware Blaster ( Recommended ) then do not enable the TeaTimer in Spybot Search and Destroy.
  • Spyware Blaster It will prevent most spyware from ever being installed. No scan to run, just update about once a week and enable all protection.
  • Spyware Guard It offers realtime protection from spyware installation attempts, again, no scan to run, just install it and let it do its thing.
  • IE-Spyad
    IE-Spyad places over 6000 web sites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • Firefox 3 It has more features and is a lot more secure than IE. It is a very easy and painless download and install, it will no way interfere with IE, you can use them both.


Safe Surfn
Ken

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI