Al_53
Topic Starter
yesterday whilst playing a game a program called spyware protection flagged it up as a worm of some sort and denied all access to the program. It also denied all access to websites /my antivirus etc - i rebooted, ran malware anti malbyte and deleted several files (didnt have time for a full scan) - today i ran eset online and wiped out several trojans and various other infections, after the reboot im now running M
3/4 of the "infections" is Spyware.PWS 1 of which is in a program in a .dll i installed as part of a game (one of them, other 2 in system restore) 4th is Rogue.securitycentral
eset picked up:
C:\Documents and Settings\Alex K\Application Data\AVG\Rescue\PC Tuneup 2011\101018145620703.rsc multiple threats deleted - quarantined
C:\Documents and Settings\Alex K\Application Data\Sun\Java\Deployment\cache\6.0\26\1bc86b5a-3b70ac65 multiple threats deleted - quarantined
C:\Documents and Settings\Alex K\Local Settings\temp\jar_cache1145802990989616776.tmp a variant of Java/TrojanDownloader.OpenStream.NAX trojan deleted - quarantined
C:\Documents and Settings\Alex K\Local Settings\temp\jar_cache3935210607245425301.tmp a variant of Java/TrojanDownloader.OpenStream.NAX trojan deleted - quarantined
C:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{05B64610-ED45-40AC-89A3-507F6B6A25B9}\Registry Reviver.msi a variant of Win32/SlowPCfighter application deleted - quarantined
C:\Other\MaDmIRC1\download\daemon288.zip probably a variant of Win32/Agent.CCLFVGJ trojan deleted - quarantined
now for the actual current OTL:
OTL logfile created on: 19/01/2011 21:43:08 - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Alex K\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 76.92 Gb Free Space | 16.51% Space Free | Partition Type: NTFS
Computer Name: ALEX | User Name: Alex K | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
PRC - [2010/12/09 19:28:24 | 001,226,608 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/12/08 21:15:44 | 000,063,360 | —- | M] (DivX, LLC) – C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/12/01 04:14:46 | 001,084,256 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2010/11/23 13:34:16 | 000,724,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/11/23 13:34:14 | 006,128,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:57:54 | 002,745,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/05/14 10:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/07/02 13:20:26 | 000,148,856 | R— | M] (BUFFALO INC.) – C:\Program Files\BUFFALO\SLManagerEasy\Inputps.exe
PRC - [2009/06/16 16:20:26 | 000,095,536 | R— | M] (BUFFALO INC.) – C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe
PRC - [2008/12/17 13:06:06 | 000,079,360 | —- | M] (Autodesk) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
PRC - [2008/04/14 12:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/10 00:04:52 | 000,065,536 | —- | M] () – C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
PRC - [2007/09/12 10:52:18 | 000,172,032 | —- | M] () – C:\Program Files\Razer\Lachesis\razerhid.exe
PRC - [2007/06/05 09:37:12 | 000,163,840 | —- | M] (Razer Inc.) – C:\Program Files\Razer\Lachesis\razerofa.exe
PRC - [2006/12/18 13:34:36 | 000,868,352 | R— | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\Core\smax4pnp.exe
========== Modules (SafeList) ==========
MOD - [2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/11/23 13:34:14 | 006,128,208 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\avgwdsvc.exe – (avgwd)
SRV - [2010/10/06 10:31:48 | 000,517,448 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/10 13:36:33 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/05/14 10:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/06/16 16:20:26 | 000,095,536 | R— | M] (BUFFALO INC.) [Auto | Running] – C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe – (Bufssvr)
SRV - [2009/06/03 17:35:00 | 003,112,284 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\System32\GameMon.des – (npggsvc)
SRV - [2008/12/17 13:06:06 | 000,079,360 | —- | M] (Autodesk) [Auto | Running] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2008/03/10 00:04:52 | 000,065,536 | —- | M] () [Auto | Running] – C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe – (mi-raysat_3dsMax2009_32)
========== Driver Services (SafeList) ==========
DRV - [2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2010/10/16 18:55:00 | 009,623,680 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2010/09/13 15:27:24 | 000,025,680 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2010/09/07 02:48:56 | 000,034,384 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2010/09/07 02:48:50 | 000,026,064 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2010/08/19 20:42:38 | 000,030,288 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2010/08/19 20:42:36 | 000,123,472 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2010/08/19 20:42:34 | 000,026,192 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2008/08/18 17:54:00 | 000,145,952 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\nvgts.sys – (nvgts)
DRV - [2008/08/01 10:36:00 | 000,054,784 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2008/08/01 10:36:00 | 000,022,016 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2008/07/23 05:10:40 | 000,017,280 | —- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bfturboh.sys – (bfturboh)
DRV - [2008/07/14 18:15:30 | 000,716,272 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd)
DRV - [2008/06/19 16:24:30 | 000,028,544 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\pavboot.sys – (pavboot)
DRV - [2008/04/14 12:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/02/01 06:15:36 | 000,560,896 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2870.sys – (rt2870)
DRV - [2007/08/08 10:04:16 | 000,012,032 | —- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Lachesis.sys – (LachesisFltr)
DRV - [2007/06/15 07:52:18 | 000,143,256 | R— | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mv61xx.sys – (mv61xx)
DRV - [2007/04/23 12:54:50 | 000,100,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mgmt.sys – (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/23 12:54:50 | 000,098,568 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115obex.sys – (s115obex)
DRV - [2007/04/23 12:54:48 | 000,108,680 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mdm.sys – (s115mdm)
DRV - [2007/04/23 12:54:48 | 000,015,112 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mdfl.sys – (s115mdfl)
DRV - [2007/04/23 12:54:46 | 000,083,208 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115bus.sys – (s115bus) Sony Ericsson Device 115 driver (WDM)
DRV - [2007/01/16 01:09:06 | 000,293,888 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ADIHdAud.sys – (ADIHdAudAddService)
DRV - [2006/12/08 09:06:00 | 000,139,776 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\adidts.sys – (ADIDTSFiltService)
DRV - [2004/08/13 02:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2004/07/05 21:38:06 | 000,233,472 | —- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZD1211U.sys – (ZD1211U(Sitecom)) Sitecom Wireless Network USB Adapter 54G WL-117(Sitecom)
DRV - [2004/01/14 09:30:00 | 000,017,151 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\ZDPNDIS5.SYS – (ZDPNDIS5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/28 12:07:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/10/25 15:47:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/04 07:27:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/04 07:27:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/07 20:17:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/14 10:16:03 | 000,000,000 | —D | M]
[2009/04/24 21:41:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Extensions
[2010/11/27 00:07:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions
[2009/08/13 09:06:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/30 09:11:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/07/09 19:01:33 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/06/20 14:03:06 | 000,000,000 | —D | M] (ChromEdit Plus) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\[removed]
[2011/01/04 07:26:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/07/07 01:02:02 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/01/08 20:10:47 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 10:16:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/04 07:26:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/22 23:31:50 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/22 23:31:50 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/03/22 23:31:50 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/03/22 23:31:50 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/07/24 15:37:40 | 000,916,030 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 a9rhiwa.cn #[Google.Warning]
O1 - Hosts: 127.0.0.1 www.a9rhiwa.cn
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 26566 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\RunOnce: [Shockwave Updater] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com/lib/portsmouth/supp…s/ebraryRdr.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1223602043015 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Alex K\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Alex K\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/28 03:56:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell - "" = AutoRun
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{8d7ef5ba-60e2-11df-ad2f-001fc6010ba1}\Shell\AutoRun\command - "" = E:\WDSetup.exe
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell - "" = AutoRun
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/19 21:21:34 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
[2011/01/19 21:02:44 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Alex K\Recent
[2011/01/19 20:38:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/18 18:43:36 | 000,647,680 | —- | C] (Sunisoft) – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex.EXE
[2011/01/16 10:52:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\L2Freya
[2011/01/12 19:11:57 | 014,532,608 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvoglnt.dll
[2011/01/12 19:11:57 | 000,813,672 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/01/12 19:11:57 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/01/12 19:11:56 | 004,882,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuda.dll
[2011/01/12 19:11:56 | 002,932,840 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/01/12 19:11:56 | 002,666,600 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/01/12 19:11:56 | 000,888,424 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/01/12 19:11:54 | 013,012,992 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/01/12 19:11:54 | 001,462,272 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvapi.dll
[2011/01/12 19:07:47 | 084,317,576 | —- | C] (NVIDIA Corporation) – C:\Documents and Settings\Alex K\Desktop\260.99_desktop_winxp_32bit_english_whql.exe
[2011/01/09 22:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\tps char
[2011/01/09 22:10:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\music
[2011/01/08 20:10:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 20:10:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 13:41:00 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/04 07:27:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Application Data\Local
[2011/01/04 07:26:00 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/01/04 07:26:00 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/01/04 07:26:00 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/26 00:36:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Local Settings\Application Data\Hpcrtlog
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/19 21:41:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
[2011/01/19 20:38:32 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/19 18:33:26 | 000,064,512 | —- | M] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/19 18:29:23 | 104,559,851 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/01/18 21:56:30 | 000,000,754 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Shortcut to l2.exe.lnk
[2011/01/18 18:43:12 | 000,647,931 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex-Freya.rar
[2011/01/18 18:35:42 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Lineage II.lnk
[2011/01/16 18:06:38 | 000,062,920 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\may2.jpg
[2011/01/16 18:04:03 | 000,048,562 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\may.jpg
[2011/01/16 10:18:19 | 000,013,696 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/16 00:10:09 | 000,045,568 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan1.xls
[2011/01/15 15:59:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/12 22:23:52 | 000,020,108 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xlsx
[2011/01/12 22:07:50 | 000,066,162 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\cal5.jpg
[2011/01/12 22:06:27 | 000,067,125 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\equest.jpg
[2011/01/12 19:12:14 | 000,240,592 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/12 19:12:14 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 19:12:09 | 000,240,592 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/12 19:12:09 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/01/12 19:07:54 | 084,317,576 | —- | M] (NVIDIA Corporation) – C:\Documents and Settings\Alex K\Desktop\260.99_desktop_winxp_32bit_english_whql.exe
[2011/01/12 18:28:58 | 000,050,688 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakende.xls
[2011/01/12 18:27:26 | 000,046,080 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xls
[2011/01/09 22:31:38 | 000,001,572 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Disk Defragmenter.lnk
[2011/01/09 21:14:00 | 001,555,800 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/09 17:55:07 | 000,071,459 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/01/08 20:10:09 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 10:16:41 | 000,000,802 | —- | M] () – C:\Documents and Settings\Alex K\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/01/04 07:27:38 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/28 12:08:13 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/19 20:38:32 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/18 18:43:36 | 000,016,512 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex.URS
[2011/01/18 18:43:11 | 000,647,931 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex-Freya.rar
[2011/01/18 18:35:42 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Lineage II.lnk
[2011/01/16 18:16:03 | 000,062,920 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\may2.jpg
[2011/01/16 18:15:53 | 000,048,562 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\may.jpg
[2011/01/13 19:40:17 | 000,045,568 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan1.xls
[2011/01/12 22:08:02 | 000,066,162 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\cal5.jpg
[2011/01/12 22:06:45 | 000,067,125 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\equest.jpg
[2011/01/12 19:12:14 | 000,240,592 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/12 19:12:09 | 000,240,592 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/12 19:12:09 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 19:12:09 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/01/12 19:11:56 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2011/01/12 18:26:55 | 000,020,108 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xlsx
[2011/01/12 18:19:02 | 000,046,080 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xls
[2011/01/12 17:57:59 | 000,050,688 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakende.xls
[2011/01/09 22:31:38 | 000,001,572 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Disk Defragmenter.lnk
[2011/01/04 07:27:38 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/10/29 13:12:05 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/04/17 11:09:29 | 000,000,036 | —- | C] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\housecall.guid.cache
[2010/04/03 12:48:42 | 000,000,034 | —- | C] () – C:\WINDOWS\ebraryRdr.ini
[2010/03/29 22:54:43 | 000,009,201 | R— | C] () – C:\WINDOWS\UN090430.INI
[2010/03/29 22:52:33 | 000,009,500 | R— | C] () – C:\WINDOWS\UN070618.INI
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/07/04 14:15:04 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/07/04 14:15:03 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/07/04 14:14:54 | 000,000,000 | —- | C] () – C:\Program Files\error.dat
[2009/07/04 14:14:54 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/07/04 14:14:20 | 000,000,074 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/04/27 23:29:59 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/07/14 18:15:30 | 000,716,272 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/07/07 03:12:30 | 000,000,553 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/07/01 19:01:34 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/06/29 22:36:53 | 000,064,512 | —- | C] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/28 04:47:45 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/06/28 04:03:51 | 000,028,216 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2008/06/28 04:03:29 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/06/28 04:03:27 | 000,027,962 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/06/28 04:03:20 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9662AE0
< End of report >
thanks for any assistance ><
3/4 of the "infections" is Spyware.PWS 1 of which is in a program in a .dll i installed as part of a game (one of them, other 2 in system restore) 4th is Rogue.securitycentral
eset picked up:
C:\Documents and Settings\Alex K\Application Data\AVG\Rescue\PC Tuneup 2011\101018145620703.rsc multiple threats deleted - quarantined
C:\Documents and Settings\Alex K\Application Data\Sun\Java\Deployment\cache\6.0\26\1bc86b5a-3b70ac65 multiple threats deleted - quarantined
C:\Documents and Settings\Alex K\Local Settings\temp\jar_cache1145802990989616776.tmp a variant of Java/TrojanDownloader.OpenStream.NAX trojan deleted - quarantined
C:\Documents and Settings\Alex K\Local Settings\temp\jar_cache3935210607245425301.tmp a variant of Java/TrojanDownloader.OpenStream.NAX trojan deleted - quarantined
C:\Documents and Settings\All Users\Application Data\ReviverSoft\Registry Reviver\InstallCache\{05B64610-ED45-40AC-89A3-507F6B6A25B9}\Registry Reviver.msi a variant of Win32/SlowPCfighter application deleted - quarantined
C:\Other\MaDmIRC1\download\daemon288.zip probably a variant of Win32/Agent.CCLFVGJ trojan deleted - quarantined
now for the actual current OTL:
OTL logfile created on: 19/01/2011 21:43:08 - Run 1
OTL by OldTimer - Version 3.2.20.2 Folder = C:\Documents and Settings\Alex K\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy
3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 79.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 91.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465.75 Gb Total Space | 76.92 Gb Free Space | 16.51% Space Free | Partition Type: NTFS
Computer Name: ALEX | User Name: Alex K | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
PRC - [2010/12/09 19:28:24 | 001,226,608 | —- | M] () – C:\Program Files\DivX\DivX Update\DivXUpdate.exe
PRC - [2010/12/08 21:15:44 | 000,063,360 | —- | M] (DivX, LLC) – C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe
PRC - [2010/12/05 16:26:40 | 000,654,176 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgrsx.exe
PRC - [2010/12/05 16:26:12 | 000,650,592 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgchsvx.exe
PRC - [2010/12/01 04:14:46 | 001,084,256 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgnsx.exe
PRC - [2010/11/23 13:34:16 | 000,724,048 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSMonitor.exe
PRC - [2010/11/23 13:34:14 | 006,128,208 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe
PRC - [2010/10/22 04:58:18 | 000,265,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgwdsvc.exe
PRC - [2010/10/22 04:57:54 | 002,745,696 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG10\avgtray.exe
PRC - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/05/14 10:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe
PRC - [2009/07/02 13:20:26 | 000,148,856 | R— | M] (BUFFALO INC.) – C:\Program Files\BUFFALO\SLManagerEasy\Inputps.exe
PRC - [2009/06/16 16:20:26 | 000,095,536 | R— | M] (BUFFALO INC.) – C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe
PRC - [2008/12/17 13:06:06 | 000,079,360 | —- | M] (Autodesk) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
PRC - [2008/04/14 12:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/03/10 00:04:52 | 000,065,536 | —- | M] () – C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe
PRC - [2007/09/12 10:52:18 | 000,172,032 | —- | M] () – C:\Program Files\Razer\Lachesis\razerhid.exe
PRC - [2007/06/05 09:37:12 | 000,163,840 | —- | M] (Razer Inc.) – C:\Program Files\Razer\Lachesis\razerofa.exe
PRC - [2006/12/18 13:34:36 | 000,868,352 | R— | M] (Analog Devices, Inc.) – C:\Program Files\Analog Devices\Core\smax4pnp.exe
========== Modules (SafeList) ==========
MOD - [2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
MOD - [2010/08/23 16:12:02 | 001,054,208 | —- | M] (Microsoft Corporation) – C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2010/11/23 13:34:14 | 006,128,208 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\Identity Protection\Agent\Bin\AVGIDSAgent.exe – (AVGIDSAgent)
SRV - [2010/10/22 04:58:18 | 000,265,400 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG10\avgwdsvc.exe – (avgwd)
SRV - [2010/10/06 10:31:48 | 000,517,448 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2010/06/10 20:03:08 | 000,144,176 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2010/06/10 13:36:33 | 000,654,848 | —- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] – C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe – (FLEXnet Licensing Service)
SRV - [2010/05/14 10:00:26 | 000,249,136 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe – (SeaPort)
SRV - [2009/06/16 16:20:26 | 000,095,536 | R— | M] (BUFFALO INC.) [Auto | Running] – C:\Program Files\BUFFALO\SLManagerEasy\Bufssvr.exe – (Bufssvr)
SRV - [2009/06/03 17:35:00 | 003,112,284 | —- | M] (INCA Internet Co., Ltd.) [On_Demand | Stopped] – C:\WINDOWS\System32\GameMon.des – (npggsvc)
SRV - [2008/12/17 13:06:06 | 000,079,360 | —- | M] (Autodesk) [Auto | Running] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2008/03/10 00:04:52 | 000,065,536 | —- | M] () [Auto | Running] – C:\Program Files\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe – (mi-raysat_3dsMax2009_32)
========== Driver Services (SafeList) ==========
DRV - [2010/12/08 04:12:38 | 000,251,728 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2010/11/12 13:19:38 | 000,299,984 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2010/10/16 18:55:00 | 009,623,680 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nv4_mini.sys – (nv)
DRV - [2010/09/13 15:27:24 | 000,025,680 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\AVGIDSEH.Sys – (AVGIDSEH)
DRV - [2010/09/07 02:48:56 | 000,034,384 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] – C:\WINDOWS\system32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2010/09/07 02:48:50 | 000,026,064 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\WINDOWS\system32\DRIVERS\avgrkx86.sys – (Avgrkx86)
DRV - [2010/08/19 20:42:38 | 000,030,288 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSFilter.sys – (AVGIDSFilter)
DRV - [2010/08/19 20:42:36 | 000,123,472 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSDriver.sys – (AVGIDSDriver)
DRV - [2010/08/19 20:42:34 | 000,026,192 | —- | M] (AVG Technologies CZ, s.r.o. ) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\AVGIDSShim.sys – (AVGIDSShim)
DRV - [2008/08/18 17:54:00 | 000,145,952 | —- | M] (NVIDIA Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\nvgts.sys – (nvgts)
DRV - [2008/08/01 10:36:00 | 000,054,784 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\NVENETFD.sys – (NVENETFD)
DRV - [2008/08/01 10:36:00 | 000,022,016 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\nvnetbus.sys – (nvnetbus)
DRV - [2008/07/23 05:10:40 | 000,017,280 | —- | M] (BUFFALO INC.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\bfturboh.sys – (bfturboh)
DRV - [2008/07/14 18:15:30 | 000,716,272 | —- | M] () [Kernel | Boot | Running] – C:\WINDOWS\System32\Drivers\sptd.sys – (sptd)
DRV - [2008/06/19 16:24:30 | 000,028,544 | —- | M] (Panda Security, S.L.) [File_System | Boot | Running] – C:\WINDOWS\system32\drivers\pavboot.sys – (pavboot)
DRV - [2008/04/14 12:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/02/01 06:15:36 | 000,560,896 | R— | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\rt2870.sys – (rt2870)
DRV - [2007/08/08 10:04:16 | 000,012,032 | —- | M] (Razer (Asia-Pacific) Pte Ltd) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\Lachesis.sys – (LachesisFltr)
DRV - [2007/06/15 07:52:18 | 000,143,256 | R— | M] (Marvell Semiconductor, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mv61xx.sys – (mv61xx)
DRV - [2007/04/23 12:54:50 | 000,100,488 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mgmt.sys – (s115mgmt) Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM)
DRV - [2007/04/23 12:54:50 | 000,098,568 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115obex.sys – (s115obex)
DRV - [2007/04/23 12:54:48 | 000,108,680 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mdm.sys – (s115mdm)
DRV - [2007/04/23 12:54:48 | 000,015,112 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115mdfl.sys – (s115mdfl)
DRV - [2007/04/23 12:54:46 | 000,083,208 | —- | M] (MCCI Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\s115bus.sys – (s115bus) Sony Ericsson Device 115 driver (WDM)
DRV - [2007/01/16 01:09:06 | 000,293,888 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ADIHdAud.sys – (ADIHdAudAddService)
DRV - [2006/12/08 09:06:00 | 000,139,776 | R— | M] (Analog Devices, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\adidts.sys – (ADIDTSFiltService)
DRV - [2004/08/13 02:56:20 | 000,005,810 | R— | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\ASACPI.sys – (MTsensor)
DRV - [2004/07/05 21:38:06 | 000,233,472 | —- | M] (ZyDAS Technology Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\ZD1211U.sys – (ZD1211U(Sitecom)) Sitecom Wireless Network USB Adapter 54G WL-117(Sitecom)
DRV - [2004/01/14 09:30:00 | 000,017,151 | —- | M] (Printing Communications Assoc., Inc. (PCAUSA)) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\ZDPNDIS5.SYS – (ZDPNDIS5)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG10\Firefox\ [2010/12/28 12:07:59 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\avg@igeared: C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2010/10/25 15:47:16 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2011/01/04 07:27:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2011/01/04 07:27:53 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/07/07 20:17:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/14 10:16:03 | 000,000,000 | —D | M]
[2009/04/24 21:41:51 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Extensions
[2010/11/27 00:07:17 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions
[2009/08/13 09:06:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/04/30 09:11:37 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2008/07/09 19:01:33 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2009/06/20 14:03:06 | 000,000,000 | —D | M] (ChromEdit Plus) – C:\Documents and Settings\Alex K\Application Data\Mozilla\Firefox\Profiles\zfw2nx4v.default\extensions\[removed]
[2011/01/04 07:26:03 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2008/07/07 01:02:02 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2011/01/08 20:10:47 | 000,000,000 | —D | M] (Skype extension) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2010/09/14 10:16:04 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/04 07:26:03 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2010/11/12 18:53:06 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
[2010/03/22 23:31:50 | 000,001,538 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\amazon-en-GB.xml
[2010/03/22 23:31:50 | 000,000,947 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\chambers-en-GB.xml
[2010/03/22 23:31:50 | 000,000,769 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\eBay-en-GB.xml
[2010/03/22 23:31:50 | 000,001,135 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\yahoo-en-GB.xml
O1 HOSTS File: ([2009/07/24 15:37:40 | 000,916,030 | R— | M]) - C:\WINDOWS\system32\drivers\etc\HOSTS
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 ad.a8.net
O1 - Hosts: 127.0.0.1 asy.a8ww.net
O1 - Hosts: 127.0.0.1 a9rhiwa.cn #[Google.Warning]
O1 - Hosts: 127.0.0.1 www.a9rhiwa.cn
O1 - Hosts: 127.0.0.1 acezip.net #[SiteAdvisor.acezip.net]
O1 - Hosts: 127.0.0.1 www.acezip.net #[Win32/Adware.180Solutions]
O1 - Hosts: 127.0.0.1 phpadsnew.abac.com
O1 - Hosts: 127.0.0.1 a.abnad.net
O1 - Hosts: 127.0.0.1 b.abnad.net
O1 - Hosts: 127.0.0.1 c.abnad.net #[eTrust.Tracking.Cookie]
O1 - Hosts: 127.0.0.1 d.abnad.net
O1 - Hosts: 127.0.0.1 e.abnad.net
O1 - Hosts: 127.0.0.1 t.abnad.net
O1 - Hosts: 127.0.0.1 z.abnad.net
O1 - Hosts: 127.0.0.1 banners.absolpublisher.com
O1 - Hosts: 127.0.0.1 tracking.absolstats.com
O1 - Hosts: 127.0.0.1 adv.abv.bg
O1 - Hosts: 127.0.0.1 bimg.abv.bg
O1 - Hosts: 127.0.0.1 www2.a-counter.kiev.ua
O1 - Hosts: 127.0.0.1 track.acclaimnetwork.com
O1 - Hosts: 127.0.0.1 accuserveadsystem.com
O1 - Hosts: 127.0.0.1 www.accuserveadsystem.com
O1 - Hosts: 127.0.0.1 gtb5.acecounter.com
O1 - Hosts: 127.0.0.1 gtcc1.acecounter.com
O1 - Hosts: 26566 more lines…
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll (Microsoft Corporation)
O2 - BHO: (AVG Security Toolbar BHO) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (AVG Security Toolbar) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files\AVG\AVG10\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC)
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [KernelFaultCheck] File not found
O4 - HKLM..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe ()
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe ()
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe (Analog Devices, Inc.)
O4 - HKCU..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe (IGN Entertainment)
O4 - HKCU..\RunOnce: [Shockwave Updater] File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 227
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} http://site.ebrary.com/lib/portsmouth/supp…s/ebraryRdr.cab (Reg Error: Key error.)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Reg Error: Key error.)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.com/content/DriverDownlo…sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {2D8ED06D-3C30-438B-96AE-4D110FDC1FB8} http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (Reg Error: Key error.)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.10.115.cab (CDownloadCtrl Object)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.microsoft.com/windowsupd…b?1223602043015 (WUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…r/ultrashim.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O18 - Protocol\Handler\avgsecuritytoolbar {F2DDE6B2-9684-4A55-86D4-E255E237B77C} - C:\Program Files\AVG\AVG10\Toolbar\IEToolbar.dll ()
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Alex K\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Alex K\Application Data\Microsoft\Windows Live Photo Gallery\Windows Live Photo Gallery Wallpaper.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/06/28 03:56:58 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell - "" = AutoRun
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{4513e8ac-46a1-11dd-a40b-001fc6010ba1}\Shell\AutoRun\command - "" = E:\Setup.exe
O33 - MountPoints2\{8d7ef5ba-60e2-11df-ad2f-001fc6010ba1}\Shell\AutoRun\command - "" = E:\WDSetup.exe
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell - "" = AutoRun
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9edae297-35dd-11df-acdb-001fc6010ba1}\Shell\AutoRun\command - "" = E:\Windows\CHECK\DriveNavigator.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgchsvx.exe /sync) - C:\Program Files\AVG\AVG10\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG10\avgrsx.exe /sync /restart) - C:\Program Files\AVG\AVG10\avgrsx.exe (AVG Technologies CZ, s.r.o.)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/01/19 21:21:34 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
[2011/01/19 21:02:44 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Alex K\Recent
[2011/01/19 20:38:32 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\CCleaner
[2011/01/18 18:43:36 | 000,647,680 | —- | C] (Sunisoft) – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex.EXE
[2011/01/16 10:52:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\L2Freya
[2011/01/12 19:11:57 | 014,532,608 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvoglnt.dll
[2011/01/12 19:11:57 | 000,813,672 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvgenco32.dll
[2011/01/12 19:11:57 | 000,061,440 | —- | C] (Khronos Group) – C:\WINDOWS\System32\OpenCL.dll
[2011/01/12 19:11:56 | 004,882,432 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuda.dll
[2011/01/12 19:11:56 | 002,932,840 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvid.dll
[2011/01/12 19:11:56 | 002,666,600 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcuvenc.dll
[2011/01/12 19:11:56 | 000,888,424 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvdispco32.dll
[2011/01/12 19:11:54 | 013,012,992 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvcompiler.dll
[2011/01/12 19:11:54 | 001,462,272 | —- | C] (NVIDIA Corporation) – C:\WINDOWS\System32\nvapi.dll
[2011/01/12 19:07:47 | 084,317,576 | —- | C] (NVIDIA Corporation) – C:\Documents and Settings\Alex K\Desktop\260.99_desktop_winxp_32bit_english_whql.exe
[2011/01/09 22:26:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\tps char
[2011/01/09 22:10:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Desktop\music
[2011/01/08 20:10:08 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2011/01/08 20:10:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Skype
[2011/01/08 13:41:00 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2011/01/04 07:27:57 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Application Data\Local
[2011/01/04 07:26:00 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011/01/04 07:26:00 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011/01/04 07:26:00 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/12/26 00:36:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Alex K\Local Settings\Application Data\Hpcrtlog
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/01/19 21:41:48 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/01/19 21:21:34 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Alex K\Desktop\OTL.exe
[2011/01/19 20:38:32 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/19 18:33:26 | 000,064,512 | —- | M] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/01/19 18:29:23 | 104,559,851 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\incavi.avm
[2011/01/18 21:56:30 | 000,000,754 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Shortcut to l2.exe.lnk
[2011/01/18 18:43:12 | 000,647,931 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex-Freya.rar
[2011/01/18 18:35:42 | 000,001,678 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Lineage II.lnk
[2011/01/16 18:06:38 | 000,062,920 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\may2.jpg
[2011/01/16 18:04:03 | 000,048,562 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\may.jpg
[2011/01/16 10:18:19 | 000,013,696 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/01/16 00:10:09 | 000,045,568 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan1.xls
[2011/01/15 15:59:05 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/01/12 22:23:52 | 000,020,108 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xlsx
[2011/01/12 22:07:50 | 000,066,162 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\cal5.jpg
[2011/01/12 22:06:27 | 000,067,125 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\equest.jpg
[2011/01/12 19:12:14 | 000,240,592 | —- | M] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/12 19:12:14 | 000,000,001 | —- | M] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 19:12:09 | 000,240,592 | —- | M] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/12 19:12:09 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/01/12 19:07:54 | 084,317,576 | —- | M] (NVIDIA Corporation) – C:\Documents and Settings\Alex K\Desktop\260.99_desktop_winxp_32bit_english_whql.exe
[2011/01/12 18:28:58 | 000,050,688 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakende.xls
[2011/01/12 18:27:26 | 000,046,080 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xls
[2011/01/09 22:31:38 | 000,001,572 | —- | M] () – C:\Documents and Settings\Alex K\Desktop\Disk Defragmenter.lnk
[2011/01/09 21:14:00 | 001,555,800 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/01/09 17:55:07 | 000,071,459 | —- | M] () – C:\WINDOWS\System32\drivers\AVG\iavichjg.avm
[2011/01/08 20:10:09 | 000,001,878 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2011/01/08 10:16:41 | 000,000,802 | —- | M] () – C:\Documents and Settings\Alex K\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/01/04 07:27:38 | 000,000,777 | —- | M] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/12/28 12:08:13 | 000,000,690 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AVG 2011.lnk
[4 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/01/19 20:38:32 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2011/01/18 18:43:36 | 000,016,512 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex.URS
[2011/01/18 18:43:11 | 000,647,931 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Lineage2Dex-Freya.rar
[2011/01/18 18:35:42 | 000,001,678 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Lineage II.lnk
[2011/01/16 18:16:03 | 000,062,920 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\may2.jpg
[2011/01/16 18:15:53 | 000,048,562 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\may.jpg
[2011/01/13 19:40:17 | 000,045,568 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan1.xls
[2011/01/12 22:08:02 | 000,066,162 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\cal5.jpg
[2011/01/12 22:06:45 | 000,067,125 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\equest.jpg
[2011/01/12 19:12:14 | 000,240,592 | —- | C] () – C:\WINDOWS\System32\nvdrsdb0.bin
[2011/01/12 19:12:09 | 000,240,592 | —- | C] () – C:\WINDOWS\System32\nvdrsdb1.bin
[2011/01/12 19:12:09 | 000,000,001 | —- | C] () – C:\WINDOWS\System32\nvdrssel.bin
[2011/01/12 19:12:09 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\nvdrswr.lk
[2011/01/12 19:11:56 | 002,293,194 | —- | C] () – C:\WINDOWS\System32\nvdata.bin
[2011/01/12 18:26:55 | 000,020,108 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xlsx
[2011/01/12 18:19:02 | 000,046,080 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakenjan.xls
[2011/01/12 17:57:59 | 000,050,688 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\zakende.xls
[2011/01/09 22:31:38 | 000,001,572 | —- | C] () – C:\Documents and Settings\Alex K\Desktop\Disk Defragmenter.lnk
[2011/01/04 07:27:38 | 000,000,777 | —- | C] () – C:\Documents and Settings\All Users\Desktop\DivX Plus Player.lnk
[2010/10/29 13:12:05 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/04/17 11:09:29 | 000,000,036 | —- | C] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\housecall.guid.cache
[2010/04/03 12:48:42 | 000,000,034 | —- | C] () – C:\WINDOWS\ebraryRdr.ini
[2010/03/29 22:54:43 | 000,009,201 | R— | C] () – C:\WINDOWS\UN090430.INI
[2010/03/29 22:52:33 | 000,009,500 | R— | C] () – C:\WINDOWS\UN070618.INI
[2009/11/06 10:58:04 | 000,178,975 | —- | C] () – C:\WINDOWS\System32\xlive.dll.cat
[2009/07/04 14:15:04 | 000,000,027 | —- | C] () – C:\WINDOWS\BRPP2KA.INI
[2009/07/04 14:15:03 | 000,000,419 | —- | C] () – C:\WINDOWS\BRWMARK.INI
[2009/07/04 14:14:54 | 000,000,000 | —- | C] () – C:\Program Files\error.dat
[2009/07/04 14:14:54 | 000,000,000 | —- | C] () – C:\WINDOWS\brmx2001.ini
[2009/07/04 14:14:20 | 000,000,074 | —- | C] () – C:\WINDOWS\Brownie.ini
[2009/04/27 23:29:59 | 000,354,816 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2008/07/14 18:15:30 | 000,716,272 | —- | C] () – C:\WINDOWS\System32\drivers\sptd.sys
[2008/07/07 03:12:30 | 000,000,553 | —- | C] () – C:\WINDOWS\wininit.ini
[2008/07/01 19:01:34 | 000,028,672 | —- | C] () – C:\WINDOWS\System32\InsDrvZD.dll
[2008/06/29 22:36:53 | 000,064,512 | —- | C] () – C:\Documents and Settings\Alex K\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/06/28 04:47:45 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2008/06/28 04:03:51 | 000,028,216 | —- | C] () – C:\WINDOWS\Ascd_log.ini
[2008/06/28 04:03:29 | 000,005,810 | R— | C] () – C:\WINDOWS\System32\drivers\ASACPI.sys
[2008/06/28 04:03:27 | 000,027,962 | —- | C] () – C:\WINDOWS\Ascd_tmp.ini
[2008/06/28 04:03:20 | 000,012,536 | —- | C] () – C:\WINDOWS\System32\drivers\ASUSHWIO.SYS
========== Alternate Data Streams ==========
@Alternate Data Stream - 151 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:0B4227B4
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
@Alternate Data Stream - 119 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A9662AE0
< End of report >
thanks for any assistance ><