This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

I'm affraid my wireless system is inffected

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I've used a pen drive from a friend of mine that didn't told me at the time I was using it that it had virus…then the next time i started my computer the wireless connection became crazy, so I believe the genesis of the problem might be in my wireless system.
I've downloaded OTL and followed all the steps until the 2 notepad windows appeard with this information:

OTL logfile created on: 22-09-2010 3:19:31 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Chuchu\My Documents
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

503,00 Mb Total Physical Memory | 130,00 Mb Available Physical Memory | 26,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 69,05 Gb Free Space | 46,32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALY
Current User Name: Chuchu
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Chuchu\My Documents\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgupd.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\iFrmewrk.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\ZCfgSvc.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
PRC - C:\Program Files\Intel\Wireless\Bin\1XConfig.exe (Intel)
PRC - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
PRC - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)
PRC - C:\WINDOWS\system32\logoneui.exe ()


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Chuchu\My Documents\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\msscript.ocx (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\windows\System32\hidserv.dll File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (WLANKEEPER) – C:\Program Files\Intel\Wireless\Bin\WLKEEPER.exe (Intel® Corporation)
SRV - (S24EventMonitor) – C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe (Intel Corporation )
SRV - (EvtEng) – C:\Program Files\Intel\Wireless\Bin\EvtEng.exe (Intel Corporation)
SRV - (RegSrvc) – C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV - (UIUSys) – C:\windows\System32\drivers\UIUSys.sys File not found
DRV - (cpuz132) – C:\DOCUME~1\Chuchu\LOCALS~1\Temp\cpuz132\cpuz132_x32.sys File not found
DRV - (BDRsDrv) – C:\Program Files\Softwin\BitDefender10\bdrsdrv.sys File not found
DRV - (BDFsDrv) – C:\Program Files\Softwin\BitDefender10\bdfsdrv.sys File not found
DRV - (VIAudio) Vinyl AC'97 Audio Controller (WDM) – C:\WINDOWS\system32\drivers\vinyl97.sys (VIA Technologies, Inc.)
DRV - (AvgTdiX) – C:\WINDOWS\system32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\system32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\system32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (STAC97) – C:\WINDOWS\system32\drivers\STAC97.sys (SigmaTel, Inc.)
DRV - (w29n51) Driver de conexão de rede Intel® – C:\WINDOWS\system32\drivers\w29n51.sys (Intel® Corporation)
DRV - (s24trans) – C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation)
DRV - (IWCA) – C:\WINDOWS\system32\drivers\iwca.sys (Intel Corporation)
DRV - (HSFHWICH) – C:\WINDOWS\system32\drivers\HSFHWICH.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.)
DRV - (HSF_DP) – C:\WINDOWS\system32\drivers\HSF_DP.sys (Conexant Systems, Inc.)
DRV - (bcm4sbxp) – C:\WINDOWS\system32\drivers\bcm4sbxp.sys (Broadcom Corporation)
DRV - (CCCP106) CIF USB Camera (2110A) – C:\WINDOWS\system32\drivers\cccp106.sys ()


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========


IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird

[2010-08-02 20:17:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Mozilla\Extensions
[2010-08-02 20:17:14 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Mozilla\Extensions\[removed]

O1 HOSTS File: ([2008-04-14 13:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe (Intel Corporation)
O4 - HKLM..\Run: [WinsysMon] C:\DOCUME~1\Chuchu\LOCALS~1\Temp\nsp9D.tmp\googletoolbar.exe File not found
O4 - HKCU..\Run: [ccleaner] C:\Program Files\CCleaner\ccleaner.exe (Piriform Ltd)
O4 - HKCU..\Run: [DriverScanner] C:\Program Files\Uniblue\DriverScanner\launcher.exe File not found
O4 - HKCU..\Run: [firewall 2008] C:\WINDOWS\system32\logoneui.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NofolderOptions = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
O16 - DPF: {4E592651-4590-11D6-BC20-00C095EEAD5D} https://www.mbnet.pt/sidebar/mbnetsidebar.cab (MBNet)
O16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} http://static.slide.com/uploader/SlideImageUploader.cab (Slide Image Uploader Control)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/windowsupdate/…b?1270723720296 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://www.update.microsoft.com/microsoftu…b?1270724367125 (MUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (logoneui.exe) - \logoneui.exe ()
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\windows\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\windows\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\IntelWireless: DllName - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll - C:\Program Files\Intel\Wireless\Bin\LgNotify.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Chuchu\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Chuchu\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-04-08 10:26:50 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2010-09-19 23:56:16 | 000,000,103 | RHS- | M] () - C:\autorun.inf – [ NTFS ]
O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell - "" = Autorun
O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell\AutoRun\command - "" = E:\logoneui.exe – File not found
O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell\Open\command - "" = E:\logoneui.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - C:\windows\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found

Drivers32: msacm.ac3acm - C:\windows\System32\ac3acm.acm (fccHandler)
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.lameacm - C:\windows\System32\lameACM.acm (http://www.mp3dev.org/)
Drivers32: msacm.siren - C:\windows\System32\sirenacm.dll (Microsoft Corporation)
Drivers32: msacm.sl_anet - C:\windows\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\windows\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: MSVideo8 - C:\windows\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\windows\System32\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FFDS - C:\windows\System32\ff_vfw.dll ()
Drivers32: vidc.iv31 - C:\windows\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\windows\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\windows\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\windows\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.XVID - C:\windows\System32\xvidvfw.dll ()
Drivers32: VIDC.YV12 - C:\windows\System32\yv12vfw.dll (www.helixcommunity.org)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)

========== Files/Folders - Created Within 30 Days ==========

[2010-09-22 03:16:57 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Chuchu\My Documents\OTL.exe
[2010-09-22 02:35:45 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Chuchu\My Documents\HiJackThis.exe
[2010-09-22 02:02:40 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Chuchu\Recent
[2010-09-19 23:58:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Desktop\BOSSAC
[2010-09-19 23:56:16 | 000,000,000 | —D | C] – C:\windows\System32\boote
[2010-09-19 01:34:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Desktop\New Folder
[2010-09-13 23:50:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\My Documents\My Received Files
[2010-09-08 02:16:16 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Local Settings\Application Data\Deployment
[2010-09-08 01:58:29 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Uniblue
[2010-09-08 01:39:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Application Data\Uniblue
[2010-09-08 00:29:47 | 000,000,000 | —D | C] – C:\cabs
[2010-09-07 23:50:15 | 000,207,488 | R— | C] (VIA Technologies, Inc.) – C:\windows\System32\drivers\vinyl97.sys
[2010-09-07 23:50:04 | 000,000,000 | —D | C] – C:\windows\System32\ReinstallBackups
[2010-09-07 23:49:52 | 000,000,000 | —D | C] – C:\windows\System32\DRVSTORE
[2010-09-07 23:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\My Documents\My Drivers
[2010-09-07 23:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Local Settings\Application Data\Innovative Solutions
[2010-09-07 23:40:53 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2010-09-07 23:35:48 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010-09-07 21:13:17 | 000,000,000 | -H-D | C] – C:\$AVG
[2010-09-07 21:00:00 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\avgrsstx.dll
[2010-09-07 20:59:59 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgtdix.sys
[2010-09-07 20:59:53 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgldx86.sys
[2010-09-07 20:59:51 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgmfx86.sys
[2010-09-07 20:59:27 | 000,000,000 | —D | C] – C:\windows\System32\drivers\Avg
[2010-09-07 20:59:09 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2010-09-07 20:59:09 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2010-09-07 20:44:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010-09-07 20:42:40 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\PC Tools
[2010-09-07 20:18:48 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Local Settings\Application Data\VS Revo Group
[2010-09-07 20:18:21 | 000,027,064 | —- | C] (VS Revo Group) – C:\windows\System32\drivers\revoflt.sys
[2010-09-07 20:18:18 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010-09-03 10:10:25 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\My Documents\Teoria musical bass
[2010-09-03 09:42:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\My Documents\Teoria musical
[2010-09-01 03:45:02 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010-09-01 03:23:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Kaspersky Lab Setup Files
[2010-09-01 01:16:37 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2010-09-01 01:16:29 | 000,000,000 | —D | C] – C:\Program Files\PCSecurityShield
[2010-09-01 01:15:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Local Settings\Application Data\ApplicationHistory
[2010-09-01 01:10:01 | 000,000,000 | —D | C] – C:\windows\System32\URTTEMP
[2010-08-30 20:09:23 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010-08-30 18:39:15 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010-08-30 00:43:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2010-08-30 00:32:37 | 000,000,000 | —D | C] – C:\Program Files\Common Files\BitDefender
[2010-08-28 15:25:03 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Application Data\ESET
[2010-08-28 15:21:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010-08-26 22:52:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\My Documents\Bohumil_Med_-_Teoria_da_Musica
[2010-05-07 01:19:38 | 002,131,336 | —- | C] (Ask.com ) – C:\Program Files\Common Files\AskToolbarInstaller.exe
[6 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010-09-22 03:20:35 | 065,130,209 | —- | M] () – C:\windows\System32\drivers\Avg\incavi.avm
[2010-09-22 03:17:08 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Chuchu\My Documents\OTL.exe
[2010-09-22 02:46:07 | 005,242,880 | -H– | M] () – C:\Documents and Settings\Chuchu\NTUSER.DAT
[2010-09-22 02:35:54 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Chuchu\My Documents\HiJackThis.exe
[2010-09-22 02:02:25 | 000,002,059 | —- | M] () – C:\info.bat
[2010-09-22 02:02:23 | 000,000,350 | —- | M] () – C:\windows\tasks\At1.job
[2010-09-22 02:02:13 | 000,002,206 | —- | M] () – C:\windows\System32\wpa.dbl
[2010-09-22 02:02:01 | 000,000,006 | -H– | M] () – C:\windows\tasks\SA.DAT
[2010-09-22 02:01:55 | 000,002,048 | –S- | M] () – C:\windows\bootstat.dat
[2010-09-22 02:00:57 | 000,000,278 | -HS- | M] () – C:\Documents and Settings\Chuchu\ntuser.ini
[2010-09-21 04:57:33 | 000,028,624 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Jammy cullum umbrela.mp3.sfk
[2010-09-19 23:56:16 | 000,000,103 | RHS- | M] () – C:\windows\System32\autorun.ini
[2010-09-19 23:56:16 | 000,000,103 | RHS- | M] () – C:\autorun.inf
[2010-09-19 07:06:22 | 732,693,716 | —- | M] () – C:\Documents and Settings\Chuchu\Desktop\Boss Ac-Festival Stª Maria 2010.wav
[2010-09-14 20:28:16 | 000,027,136 | —- | M] () – C:\Documents and Settings\Chuchu\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-09-14 19:06:16 | 000,129,534 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\r&b 14.09.10.rns
[2010-09-14 00:32:50 | 000,185,568 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\house beat 14.09.10.rns
[2010-09-13 03:15:44 | 000,034,816 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\news13.09.doc
[2010-09-10 02:23:03 | 000,047,607 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\DeclaracoesFiscaisBPI.pdf
[2010-09-10 00:29:41 | 000,183,942 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Semba Groove.rns
[2010-09-07 23:49:01 | 000,207,488 | R— | M] (VIA Technologies, Inc.) – C:\windows\System32\drivers\vinyl97.sys
[2010-09-07 21:00:00 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\avgrsstx.dll
[2010-09-07 20:59:59 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgtdix.sys
[2010-09-07 20:59:53 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgldx86.sys
[2010-09-07 20:59:51 | 000,113,461 | —- | M] () – C:\windows\System32\drivers\Avg\iavichjw.avm
[2010-09-07 20:59:51 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\windows\System32\drivers\avgmfx86.sys
[2010-09-07 20:46:56 | 005,892,394 | -H– | M] () – C:\Documents and Settings\Chuchu\Local Settings\Application Data\IconCache.db
[2010-09-07 20:45:34 | 000,002,577 | —- | M] () – C:\windows\System32\CONFIG.NT
[2010-09-05 21:03:03 | 007,988,224 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\convite[1].pub
[2010-09-05 20:55:05 | 010,726,912 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\exposição..[1].pub
[2010-09-01 09:55:04 | 002,653,521 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Jammy cullum umbrela.mp3
[2010-09-01 09:37:50 | 000,093,252 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\default song.rns
[2010-09-01 05:13:53 | 000,000,104 | —- | M] () – C:\Documents and Settings\Chuchu\Desktop\Shortcut to My Computer.lnk
[2010-09-01 04:34:51 | 053,785,488 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\setup_av_free.exe
[2010-08-31 04:26:52 | 005,113,344 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Justin Timberlake - Rock Your Body HBO Concert Live from MSG.mp3
[2010-08-31 04:09:13 | 008,874,977 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Justin Timberlake Live HBO 2007 - Senorita.mp3
[2010-08-30 18:10:31 | 000,000,052 | —- | M] () – C:\windows\System32\ashttpstats.csv
[2010-08-30 17:45:59 | 000,000,385 | —- | M] () – C:\windows\System32\user_gensett.xml
[2010-08-30 17:14:18 | 000,514,286 | —- | M] () – C:\windows\System32\PerfStringBackup.INI
[2010-08-30 17:14:18 | 000,443,922 | —- | M] () – C:\windows\System32\perfh009.dat
[2010-08-30 17:14:18 | 000,072,180 | —- | M] () – C:\windows\System32\perfc009.dat
[2010-08-30 16:54:22 | 000,000,000 | —- | M] () – C:\windows\System32\wsbl.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\phar_unmip.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\phar_histprot.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_white.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_summ.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_spoof.sig
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_sign.slf
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_fuzzy.sig
[2010-08-30 16:54:21 | 000,000,000 | —- | M] () – C:\windows\System32\ph_black.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pcwords2.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pcwords.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_webproxy.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_video.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_tabloids.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_socialnetworks.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_sign.slf
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_searchengines.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_regionaltlds.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_pornography.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_onlineshop.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_onlinepay.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_onlinedating.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_news.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_im.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_illegal.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_hate.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_games.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_gambling.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | M] () – C:\windows\System32\pc_drugs.dat
[2010-08-30 16:41:32 | 000,000,376 | —- | M] () – C:\Documents and Settings\Chuchu\Application Dataprivacy.xml
[2010-08-30 04:27:33 | 000,000,850 | —- | M] () – C:\Documents and Settings\Chuchu\Application DataProductTweaks.xml
[2010-08-30 04:27:33 | 000,000,385 | —- | M] () – C:\Documents and Settings\Chuchu\Application Datauser_gensett.xml
[2010-08-30 04:27:33 | 000,000,025 | —- | M] () – C:\Documents and Settings\Chuchu\Application Data\bdfvconp.ini
[2010-08-30 04:09:37 | 000,000,004 | —- | M] () – C:\windows\System32\aspdict-en.dat
[2010-08-30 04:09:36 | 000,000,016 | —- | M] () – C:\windows\System32\asdict.dat
[2010-08-30 03:50:31 | 000,000,132 | —- | M] () – C:\windows\System32\rezumatenoi.dat
[2010-08-28 14:53:03 | 000,081,984 | —- | M] () – C:\windows\System32\bdod.bin
[2010-08-28 14:50:21 | 000,000,635 | —- | M] () – C:\windows\win.ini
[2010-08-28 05:43:02 | 005,356,596 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\Mariah Carey - Emotions (Butterfly Tour).mp3
[2010-08-27 16:47:48 | 000,023,040 | —- | M] () – C:\Documents and Settings\Chuchu\My Documents\ALINHAMENTO MONKEY ROOTS.doc
[6 C:\windows\System32\*.tmp files -> C:\windows\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010-09-21 04:52:22 | 000,028,624 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Jammy cullum umbrela.mp3.sfk
[2010-09-19 23:57:51 | 732,693,716 | —- | C] () – C:\Documents and Settings\Chuchu\Desktop\Boss Ac-Festival Stª Maria 2010.wav
[2010-09-19 23:56:20 | 000,390,144 | RHS- | C] () – C:\logoneui.exe
[2010-09-19 23:56:20 | 000,000,103 | RHS- | C] () – C:\autorun.inf
[2010-09-19 23:56:16 | 000,390,144 | —- | C] () – C:\Jojo.exe
[2010-09-19 23:56:16 | 000,002,059 | —- | C] () – C:\info.bat
[2010-09-19 23:56:16 | 000,000,350 | —- | C] () – C:\windows\tasks\At1.job
[2010-09-19 23:56:16 | 000,000,103 | RHS- | C] () – C:\windows\System32\autorun.ini
[2010-09-19 23:56:14 | 000,390,144 | RHS- | C] () – C:\windows\System32\logoneui.exe
[2010-09-14 18:57:03 | 000,129,534 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\r&b 14.09.10.rns
[2010-09-14 00:32:49 | 000,185,568 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\house beat 14.09.10.rns
[2010-09-13 01:44:58 | 000,034,816 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\news13.09.doc
[2010-09-10 02:23:00 | 000,047,607 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\DeclaracoesFiscaisBPI.pdf
[2010-09-07 20:59:50 | 000,113,461 | —- | C] () – C:\windows\System32\drivers\Avg\iavichjw.avm
[2010-09-07 20:59:27 | 065,130,209 | —- | C] () – C:\windows\System32\drivers\Avg\incavi.avm
[2010-09-05 21:03:02 | 007,988,224 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\convite[1].pub
[2010-09-05 20:55:05 | 010,726,912 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\exposição..[1].pub
[2010-09-01 09:55:01 | 002,653,521 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Jammy cullum umbrela.mp3
[2010-09-01 09:37:49 | 000,093,252 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\default song.rns
[2010-09-01 05:13:53 | 000,000,104 | —- | C] () – C:\Documents and Settings\Chuchu\Desktop\Shortcut to My Computer.lnk
[2010-09-01 04:34:36 | 053,785,488 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\setup_av_free.exe
[2010-08-31 04:26:24 | 005,113,344 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Justin Timberlake - Rock Your Body HBO Concert Live from MSG.mp3
[2010-08-31 04:08:29 | 008,874,977 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Justin Timberlake Live HBO 2007 - Senorita.mp3
[2010-08-30 18:10:31 | 000,000,052 | —- | C] () – C:\windows\System32\ashttpstats.csv
[2010-08-30 17:45:59 | 000,000,385 | —- | C] () – C:\windows\System32\user_gensett.xml
[2010-08-30 16:54:22 | 000,000,000 | —- | C] () – C:\windows\System32\wsbl.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\phar_unmip.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\phar_histprot.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_white.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_summ.dat
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_spoof.sig
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_sign.slf
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_fuzzy.sig
[2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_black.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pcwords2.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pcwords.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_webproxy.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_video.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_tabloids.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_socialnetworks.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_sign.slf
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_searchengines.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_regionaltlds.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_pornography.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlineshop.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlinepay.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlinedating.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_news.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_im.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_illegal.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_hate.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_games.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_gambling.dat
[2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_drugs.dat
[2010-08-30 04:27:33 | 000,000,850 | —- | C] () – C:\Documents and Settings\Chuchu\Application DataProductTweaks.xml
[2010-08-30 04:27:33 | 000,000,385 | —- | C] () – C:\Documents and Settings\Chuchu\Application Datauser_gensett.xml
[2010-08-30 04:27:33 | 000,000,025 | —- | C] () – C:\Documents and Settings\Chuchu\Application Data\bdfvconp.ini
[2010-08-30 04:09:37 | 000,000,004 | —- | C] () – C:\windows\System32\aspdict-en.dat
[2010-08-30 04:09:36 | 000,000,016 | —- | C] () – C:\windows\System32\asdict.dat
[2010-08-30 04:07:10 | 000,000,376 | —- | C] () – C:\Documents and Settings\Chuchu\Application Dataprivacy.xml
[2010-08-30 00:59:30 | 000,000,132 | —- | C] () – C:\windows\System32\rezumatenoi.dat
[2010-08-28 05:42:21 | 005,356,596 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Mariah Carey - Emotions (Butterfly Tour).mp3
[2010-08-27 00:43:10 | 000,023,040 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\ALINHAMENTO MONKEY ROOTS.doc
[2010-08-26 22:52:34 | 001,909,729 | —- | C] () – C:\Documents and Settings\Chuchu\My Documents\Teoria_Musical__Viol_o_e_Guitarra.pdf
[2010-08-12 04:36:41 | 000,002,612 | —- | C] () – C:\windows\DevMgr.ini
[2010-08-12 04:29:19 | 000,000,020 | —- | C] () – C:\windows\Hposcv07.INI
[2010-07-01 06:00:08 | 000,411,360 | —- | C] () – C:\Documents and Settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat
[2010-05-05 23:23:27 | 000,227,200 | —- | C] () – C:\windows\System32\drivers\cccp106.sys
[2010-05-05 23:23:26 | 000,036,864 | —- | C] () – C:\windows\JPGL.DLL
[2010-05-05 23:23:26 | 000,032,768 | —- | C] () – C:\windows\DIV_IYUV.DLL
[2010-05-05 23:23:25 | 000,061,440 | —- | C] () – C:\windows\System32\dcccp106.dll
[2010-05-05 23:23:25 | 000,045,056 | —- | C] () – C:\windows\System32\vcccp106.dll
[2010-05-05 23:23:25 | 000,015,542 | —- | C] () – C:\windows\cccp106.ini
[2010-05-05 23:23:25 | 000,000,321 | —- | C] () – C:\windows\DC2110a.ini
[2010-04-22 04:15:38 | 000,027,136 | —- | C] () – C:\Documents and Settings\Chuchu\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-04-22 01:39:18 | 000,000,077 | —- | C] () – C:\Documents and Settings\Chuchu\Local Settings\Application Data\FASTWiz.log
[2010-04-08 11:39:01 | 000,165,376 | —- | C] () – C:\windows\System32\unrar.dll
[2010-04-08 11:39:01 | 000,000,038 | —- | C] () – C:\windows\avisplitter.ini
[2010-04-08 11:38:59 | 000,881,664 | —- | C] () – C:\windows\System32\xvidcore.dll
[2010-04-08 11:38:59 | 000,205,824 | —- | C] () – C:\windows\System32\xvidvfw.dll
[2010-04-08 11:38:58 | 000,085,504 | —- | C] () – C:\windows\System32\ff_vfw.dll
[2010-04-08 11:38:58 | 000,000,547 | —- | C] () – C:\windows\System32\ff_vfw.dll.manifest
[2010-04-08 11:29:57 | 000,000,376 | —- | C] () – C:\windows\ODBC.INI
[2007-11-14 18:42:27 | 000,237,568 | —- | C] () – C:\windows\System32\lame_enc.dll
[2007-11-09 12:01:59 | 000,000,164 | —- | C] () – C:\windows\System32\psyswin32.dll
[2004-08-12 08:44:10 | 000,016,384 | —- | C] () – C:\windows\System32\iwca.dll
[2004-07-20 12:14:06 | 000,192,512 | —- | C] () – C:\windows\System32\stac97co.dll
[2003-01-07 15:05:08 | 000,002,695 | —- | C] () – C:\windows\System32\OUTLPERF.INI
[2002-11-20 18:51:34 | 000,159,744 | —- | C] () – C:\windows\System32\win2000.dll

========== LOP Check ==========

[2010-09-01 04:41:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010-09-07 21:56:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2010-09-01 01:10:30 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\BitDefender
[2010-08-28 15:21:57 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ESET
[2010-09-07 23:40:53 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Innovative Solutions
[2010-08-03 03:12:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2010-09-07 23:35:48 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2010-04-24 04:52:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Propellerhead Software
[2010-08-03 04:48:17 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Sony
[2010-09-07 20:44:24 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010-05-07 05:03:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\AnvSoft
[2010-08-28 15:25:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\ESET
[2010-04-08 11:38:27 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Foxit
[2010-08-13 00:45:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Foxit Software
[2010-06-20 01:47:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Music Editor Free
[2010-04-24 05:03:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Propellerhead Software
[2010-06-20 01:44:40 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Publish Providers
[2010-06-20 01:44:55 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Sony
[2010-09-08 01:39:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\Uniblue
[2010-09-12 13:03:03 | 000,000,000 | —D | M] – C:\Documents and Settings\Chuchu\Application Data\uTorrent
[2010-09-22 02:02:23 | 000,000,350 | —- | M] () – C:\windows\Tasks\At1.job

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2010-04-08 10:26:50 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010-09-19 23:56:16 | 000,000,103 | RHS- | M] () – C:\autorun.inf
[2010-08-30 18:10:38 | 000,004,316 | —- | M] () – C:\bdlog.txt
[2010-04-08 10:26:50 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010-09-22 02:02:25 | 000,002,059 | —- | M] () – C:\info.bat
[2010-04-08 10:26:50 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2002-12-20 09:46:22 | 000,390,144 | —- | M] () – C:\Jojo.exe
[2010-09-07 21:51:10 | 000,116,241 | —- | M] () – C:\log.txt
[2002-12-20 09:46:22 | 000,390,144 | RHS- | M] () – C:\logoneui.exe
[2010-04-08 10:26:50 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008-04-14 13:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008-04-14 13:00:00 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010-09-22 02:01:53 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2010-06-02 18:39:06 | 000,000,516 | —- | M] () – C:\Settings.ini

< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2010-04-08 10:26:20 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008-07-06 13:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2007-04-09 13:23:54 | 000,028,552 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008-07-06 11:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >
[2010-04-08 11:55:30 | 000,088,868 | —- | M] () – C:\WINDOWS\apple_mac_leopard_1440x900.jpg
[2010-04-08 11:43:46 | 000,163,543 | —- | M] () – C:\WINDOWS\benfica4.jpg

< %systemroot%\*.png >

< %systemroot%\*.scr >

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2010-04-08 11:07:45 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2010-04-08 11:07:44 | 001,089,536 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2010-04-08 11:07:44 | 000,913,408 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2010-04-08 10:26:57 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010-04-08 11:14:31 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Chuchu\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2010-04-08 11:14:31 | 000,000,079 | —- | M] () – C:\Documents and Settings\Chuchu\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >
[2010-02-10 11:18:42 | 002,131,336 | —- | M] (Ask.com ) – C:\Program Files\Common Files\AskToolbarInstaller.exe

< %systemroot%\*.src >
[2003-02-18 14:48:08 | 000,013,023 | —- | M] () – C:\WINDOWS\cccp106.src

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-09-14 18:11:33
< End of report >


OTL Extras logfile created on: 22-09-2010 3:19:31 - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\Chuchu\My Documents
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000816 | Country: Portugal | Language: PTG | Date Format: dd-MM-yyyy

503,00 Mb Total Physical Memory | 130,00 Mb Available Physical Memory | 26,00% Memory free
1,00 Gb Paging File | 1,00 Gb Available in Paging File | 63,00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 149,05 Gb Total Space | 69,05 Gb Free Space | 46,32% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: ALY
Current User Name: Chuchu
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" /p %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent – (BitTorrent, Inc.)
"C:\Program Files\eMule\emule.exe" = C:\Program Files\eMule\emule.exe:*:Enabled:eMule – File not found
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{06BE8AFD-A8E2-4B63-BAE7-287016D16ACB}" = mSSO
"{0800E395-4DD7-3A93-BB96-08596C0D725F}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - PTG
"{0E2B0B41-7E08-4F9F-B21F-41C4133F43B7}" = mLogView
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{23FB368F-1399-4EAC-817C-4B83ECBE3D83}" = mProSafe
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{28BE306E-5DA6-4F9C-BDB0-DBA3C8C6FFFD}" = QuickTime
"{28DA872A-0848-48CF-B749-19A198157A2A}" = mDriver
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3E9D596A-61D4-4239-BD19-2DB984D2A16F}" = mIWA
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{49D687E5-6784-431B-A0A2-2F23B8CC5A1B}" = mHlpDell
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{520A8627-E1B7-4808-8F04-03A013CBBD10}" = Noise Reduction Plug-in 2.0i
"{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"{553255F3-78FD-40F1-A6F8-6882140265FE}" = Apple Application Support
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.4.1
"{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update
"{6DE14BE4-6F04-4935-8ABD-A0A19FE2E55A}" = mCore
"{6FFFE74E-3FBD-4E2E-97F9-5E9A2A077626}" = mIWCA
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7B1DBCBE-DF17-3B58-844C-F572F70EF5C4}" = Microsoft .NET Framework 3.5 Language Pack SP1 - ptg
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{88528F28-E04A-3A93-B3C0-14651148FE82}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - PTG
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel® Graphics Media Accelerator Driver for Mobile
"{8B928BA1-EDEC-4227-A2DA-DD83026C36F5}" = mPfMgr
"{90110409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Professional Edition 2003
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90B0D222-8C21-4B35-9262-53B042F18AF9}" = mPfWiz
"{94658027-9F16-4509-BBD7-A59FE57C3023}" = mZConfig
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9CC89556-3578-48DD-8408-04E66EBEF401}" = mXML
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}" = C-Major Audio
"{A7E19604-93AF-4611-8C9F-CE509C2B286E}_is1" = VDownloader 2.7.322
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{CA9BAADB-C262-4E05-B2E2-CEE8CE9809EC}" = mToolkit
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D1E632A6-CE8B-436B-BC03-009851802E82}" = Sound Forge Pro 10.0
"{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform
"{F0BFC7EF-9CF8-44EE-91B0-158884CD87C5}" = mMHouse
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F6090A17-0967-4A8A-B3C3-422A1B514D49}" = mDrWiFi
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{FCA651F3-5BDA-4DDA-9E4A-5D87D6914CC4}" = mWlsSafe
"7-Zip" = 7-Zip 9.12 beta
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"AVG9Uninstall" = AVG Free 9.0
"CCleaner" = CCleaner
"CIF USB Camera (2110A)" = CIF USB Camera (2110A)
"CNXT_MODEM_PCI_VEN_8086&DEV_24x6&SUBSYS_542214F1" = Conexant D110 MDC V.9x Modem
"Foxit Reader" = Foxit Reader
"hp officejet g series 1281584198" = hp officejet g series
"ie8" = Windows Internet Explorer 8
"InstallShield_{52504CE6-E909-4113-B232-4AFEC6543A61}" = Broadcom 440x 10/100 Integrated Controller
"KLiteCodecPack_is1" = K-Lite Codec Pack 5.8.3 (Full)
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 Language Pack SP1 - ptg" = Microsoft .NET Framework 3.5 Language Pack SP1 - PTG
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSNINST" = MSN
"ProInst" = Intel® PROSet/Wireless Software
"Reason4_is1" = Reason 4.0
"uTorrent" = µTorrent
"Veetle TV" = Veetle TV 0.9.17
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = Arquivo do WinRAR
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"f031ef6ac137efc5" = Dell Driver Download Manager

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 21-09-2010 12:36:48 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 14:21:42 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 14:26:25 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iexplore.exe, version 8.0.6001.18702, hang module
hungapp, version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 20:30:18 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 20:30:19 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 20:30:25 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 20:55:21 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 20:55:21 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 21:47:59 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

Error - 21-09-2010 21:48:04 | Computer Name = ALY | Source = Application Hang | ID = 1002
Description = Hanging application iFrmewrk.exe, version 9.0.1.19, hang module hungapp,
version 0.0.0.0, hang address 0x00000000.

[ System Events ]
Error - 20-09-2010 19:42:01 | Computer Name = ALY | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 120 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 20-09-2010 19:42:01 | Computer Name = ALY | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 119 minutes. NtpClient has no source of accurate
time.

Error - 20-09-2010 20:29:23 | Computer Name = ALY | Source = DCOM | ID = 10010
Description = The server {0002DF01-0000-0000-C000-000000000046} did not register
with DCOM within the required timeout.

Error - 21-09-2010 11:55:54 | Computer Name = ALY | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 15 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 21-09-2010 11:55:54 | Computer Name = ALY | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 14 minutes. NtpClient has no source of accurate
time.

Error - 21-09-2010 12:10:53 | Computer Name = ALY | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 30 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 21-09-2010 12:10:53 | Computer Name = ALY | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 29 minutes. NtpClient has no source of accurate
time.

Error - 21-09-2010 12:40:56 | Computer Name = ALY | Source = W32Time | ID = 39452689
Description = Time Provider NtpClient: An error occurred during DNS lookup of the
manually configured peer 'time.windows.com,0x1'. NtpClient will try the DNS lookup
again in 60 minutes. The error was: A socket operation was attempted to an unreachable
host. (0x80072751)

Error - 21-09-2010 12:40:56 | Computer Name = ALY | Source = W32Time | ID = 39452701
Description = The time provider NtpClient is configured to acquire time from one
or more time sources, however none of the sources are currently accessible. No attempt
to contact a source will be made for 59 minutes. NtpClient has no source of accurate
time.

Error - 21-09-2010 21:03:56 | Computer Name = ALY | Source = Dhcp | ID = 1001
Description = Your computer was not assigned an address from the network (by the
DHCP Server) for the Network Card with network address 0013CE5EC537. The following
error occurred: %%1223. Your computer will continue to try and obtain an address
on its own from the network address (DHCP) server.


< End of report >



Can anybody help me about this?

Best regards

Aly
Hello,
Welcome to WhatTheTech. My name is mowman, and I will be helping you fix your problems.

If you do not make a reply in 3 days, we will have to close your topic.

You may want to keep the link to this topic in your favorites. Alternatively, you can click the Options button at the top bar of this topic and Track this topic. The topics you are tracking can be found by clicking on My Topics at the top of any page.

Please take note of some guidelines for this fix:

•Refrain from making any changes to your computer including installing/uninstall programs, deleting files, modifying the registry, and running scanners or tools. Doing so could cause changes to the directions I have to give you and prolong the time required. Further more, you should not be taking any advice relating to this computer from any other source throughout the course of this fix.
•If you do not understand any step(s) provided, please do not hesitate to ask before continuing. I would much rather clarify instructions or explain them differently than have something important broken.
•Even if things appear to be better, it might not mean we are finished. Please continue to follow my instructions and reply back until I give you the "all clean". We do not want to clean you part-way, only to have the system re-infect itself.
•Please reply using the button in the lower right hand corner of your screen. Do not start a new topic. The logs that you post should be pasted directly into the reply.
Only attach them if requested or if they do not fit into the post
•Please be aware that I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
•This may cause a delay in response time, but I will do my best to keep it as short as possible.
•I will reply back shortly with instructions.
Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :Services
    
    :Otl
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
    O4 - HKLM..\Run: [] File not found
    O4 - HKCU..\Run: [firewall 2008] C:\WINDOWS\system32\logoneui.exe ()
    O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NofolderOptions = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 1
    O20 - HKLM Winlogon: Shell - (logoneui.exe) - \logoneui.exe ()
    O32 - AutoRun File - [2010-09-19 23:56:16 | 000,000,103 | RHS- | M] () - C:\autorun.inf – [ NTFS ]
    O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell - "" = Autorun
    O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell\AutoRun\command - "" = E:\logoneui.exe – File not found
    O33 - MountPoints2\{fc4537f0-c440-11df-87d2-0013ce5ec537}\Shell\Open\command - "" = E:\logoneui.exe – File not found
    [2010-09-19 23:58:36 | 000,000,000 | —D | C] – C:\Documents and Settings\Chuchu\Desktop\BOSSAC
    [2010-09-19 23:56:16 | 000,000,000 | —D | C] – C:\windows\System32\boote
    [2010-09-19 23:56:20 | 000,390,144 | RHS- | C] () – C:\logoneui.exe
    [2010-09-19 23:56:20 | 000,000,103 | RHS- | C] () – C:\autorun.inf
    [2010-09-19 23:56:16 | 000,390,144 | —- | C] () – C:\Jojo.exe
    [2010-09-19 23:56:16 | 000,002,059 | —- | C] () – C:\info.bat
    [2010-09-19 23:56:16 | 000,000,350 | —- | C] () – C:\windows\tasks\At1.job
    [2010-09-19 23:56:16 | 000,000,103 | RHS- | C] () – C:\windows\System32\autorun.ini
    [2010-09-19 23:56:14 | 000,390,144 | RHS- | C] () – C:\windows\System32\logoneui.exe
    [2010-08-30 16:54:22 | 000,000,000 | —- | C] () – C:\windows\System32\wsbl.dat
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\phar_unmip.dat
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\phar_histprot.dat
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_white.dat
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_summ.dat
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_spoof.sig
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_sign.slf
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_fuzzy.sig
    [2010-08-30 16:54:21 | 000,000,000 | —- | C] () – C:\windows\System32\ph_black.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pcwords2.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pcwords.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_webproxy.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_video.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_tabloids.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_socialnetworks.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_sign.slf
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_searchengines.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_regionaltlds.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_pornography.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlineshop.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlinepay.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_onlinedating.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_news.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_im.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_illegal.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_hate.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_games.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_gambling.dat
    [2010-08-30 16:54:20 | 000,000,000 | —- | C] () – C:\windows\System32\pc_drugs.dat
    
    :Commands
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post a new OTL log ( don't check the boxes beside LOP Check or Purity this time )






[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.
**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries


If GMER won't run try with devices unchecked.If still no go try in safe mode.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI