Hello Doris! Thank you much for your help! Below are the logs from the OTL and Rootkit scans. One thing I should probably mention is that the AVG installed on my system kept throwing up "threat detected" warnings. I did not turn off AVG because I was not instructed to do so (following your directions to the letter

I just left the warnings open till the scans finished. This is what the warning said:
C:\Windows\system32\drivers\5Y60104.sys
Trojan horse Agent2.AMIB
Detected on open
Process name=C:\Documents and settings\Us\Desktop\OLT.exe
Process ID: 1764
OLT did it a couple times with varying things in the first line, and the rootkit thing did it once..
Anyway, Logs below and thanks again for you help!
<———– OLT.txt ———————>
OTL logfile created on: 05-Apr-11 PM 07:20:32 - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Us\Desktop
Windows XP Media Center Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: dd-MMM-yy
1.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): C:\pagefile.sys 756 1512 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 144.33 Gb Total Space | 61.03 Gb Free Space | 42.29% Space Free | Partition Type: NTFS
Drive D: | 115.90 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Computer Name: SWEET | User Name: Us | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Us\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
PRC - C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
PRC - C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
PRC - C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Program Files\Sony\SonicStage\SSAAD.exe ()
PRC - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
PRC - C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (TiVo Inc.)
PRC - C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
PRC - C:\Program Files\Common Files\AOL\1136009206\ee\aolsoftware.exe (America Online, Inc.)
PRC - C:\WINDOWS\VM303_STI.EXE (Vimicro)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Us\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\iphlpapi.dll (Microsoft Corporation)
MOD - C:\WINDOWS\AppPatch\AcGenral.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\dbghelp.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\msacm32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\system32\wsock32.dll (Microsoft Corporation)
MOD - C:\WINDOWS\ssleay32.dll ()
MOD - C:\WINDOWS\libeay32.dll ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (TomTomHOMEService) – C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (TomTom)
SRV - (SWGVCSvc) – C:\Program Files\SonicWALL\SonicWALL Global VPN Client\SWGVCSvc.exe (SonicWALL, Inc.)
SRV - (sprtsvc_ddoctorv2) SupportSoft Sprocket Service (ddoctorv2) – C:\Program Files\Comcast\Desktop Doctor\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV - (SSScsiSV) – C:\Program Files\Common Files\Sony Shared\AVLib\SSScsiSV.exe (Sony Corporation)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (MSCSPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe (Sony Corporation)
SRV - (PACSPTISVR) – C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe (Sony Corporation)
SRV - (SPTISRV) – C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe (Sony Corporation)
SRV - (TivoBeacon2) – C:\Program Files\Common Files\TiVo Shared\Beacon\TiVoBeacon.exe (TiVo Inc.)
SRV - (Macromedia Licensing Service) – C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe (Macromedia)
========== Driver Services (SafeList) ==========
DRV - (0000) – C:\WINDOWS\system32\drivers\0000.sys ()
DRV - (5Y60I04) – C:\WINDOWS\system32\drivers\5Y60I04.sys ()
DRV - (bsHsKN7LkPEwc6zTboV3VDYcCuBKkxbwbXb4m3GynxqEEisGEFweuwOPakmwEtE=) – C:\WINDOWS\system32\drivers\bsHsKN7LkPEwc6zTboV3VDYcCuBKkxbwbXb4m3GynxqEEisGEFweuwOPakmwEtE=.sys ()
DRV - (牉⁰稠襛嗐襙) – C:\WINDOWS\system32\drivers\牉⁰稠襛嗐襙.sys [WARNING: C:\WINDOWS\system32\drivers\?°????.sys] ()
DRV - (牉⁰ᗐ袳읨袲) – C:\WINDOWS\system32\drivers\牉⁰ᗐ袳읨袲.sys [WARNING: C:\WINDOWS\system32\drivers\?°????.sys] ()
DRV - (100 VE Network Connection - Packet Scheduler Miniport) – C:\WINDOWS\system32\drivers\100 VE Network Connection - Packet Scheduler Miniport.sys ()
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - ({192BA8EB-E576-4FA3-ABC8-44FF9A18ADEE}) – C:\WINDOWS\system32\drivers\{192BA8EB-E576-4FA3-ABC8-44FF9A18ADEE}.sys ()
DRV - (鉠覽) – C:\WINDOWS\system32\drivers\鉠覽.sys [WARNING: C:\WINDOWS\system32\drivers\??.sys] ()
DRV - (SWVNIC) – C:\WINDOWS\system32\drivers\SWVNIC.sys (SonicWALL, Inc.)
DRV - (DNE) – C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (MPFP) – C:\WINDOWS\system32\drivers\Mpfp.sys (McAfee, Inc.)
DRV - (SSKBFD) – C:\WINDOWS\system32\drivers\sskbfd.sys (Webroot Software Inc (www.webroot.com))
DRV - (DLAUDFAM) – C:\WINDOWS\system32\dla\DLAUDFAM.SYS (Sonic Solutions)
DRV - (DLAUDF_M) – C:\WINDOWS\system32\dla\DLAUDF_M.SYS (Sonic Solutions)
DRV - (DLAIFS_M) – C:\WINDOWS\system32\dla\DLAIFS_M.SYS (Sonic Solutions)
DRV - (DLABOIOM) – C:\WINDOWS\system32\dla\DLABOIOM.SYS (Sonic Solutions)
DRV - (DLAOPIOM) – C:\WINDOWS\system32\dla\DLAOPIOM.SYS (Sonic Solutions)
DRV - (DLAPoolM) – C:\WINDOWS\system32\dla\DLAPoolM.SYS (Sonic Solutions)
DRV - (DLADResN) – C:\WINDOWS\system32\dla\DLADResN.SYS (Sonic Solutions)
DRV - (DLACDBHM) – C:\WINDOWS\system32\drivers\DLACDBHM.SYS (Sonic Solutions)
DRV - (DLARTL_N) – C:\WINDOWS\system32\drivers\DLARTL_N.SYS (Sonic Solutions)
DRV - (tbhsd) – C:\WINDOWS\system32\drivers\tbhsd.sys (RapidSolution Software)
DRV - (STHDA) High Definition Audio Driver (WDM) – C:\WINDOWS\system32\drivers\sthda.sys (SigmaTel, Inc.)
DRV - (ZSMC303) VIMICRO USB PC Camera (ZC0301PLH) – C:\WINDOWS\system32\drivers\usbVM303.sys (Vimicro Corporation)
DRV - (IntelC53) – C:\WINDOWS\system32\drivers\IntelC53.sys (Intel Corporation)
DRV - (WmXlCore) – C:\WINDOWS\system32\drivers\WmXlCore.sys (Logitech Inc.)
DRV - (WmFilter) – C:\WINDOWS\system32\drivers\WmFilter.sys (Logitech Inc.)
DRV - (WmBEnum) – C:\WINDOWS\system32\drivers\WmBEnum.sys (Logitech Inc.)
DRV - (WmVirHid) – C:\WINDOWS\system32\drivers\WmVirHid.sys (Logitech Inc.)
DRV - (IntelC52) – C:\WINDOWS\system32\drivers\IntelC52.sys (Intel Corporation)
DRV - (IntelC51) – C:\WINDOWS\system32\drivers\IntelC51.sys (Intel Corporation)
DRV - (mohfilt) – C:\WINDOWS\system32\drivers\mohfilt.sys (Intel Corporation)
DRV - (ASPI32) – C:\WINDOWS\System32\drivers\Aspi32.sys (Adaptec)
DRV - (DniVap) SafeNet WAN Miniport (VA) – C:\WINDOWS\system32\drivers\vap.sys (Deterministic Networks Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL =
http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages =
http://news.yahoo.com [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Page_URL =
http://www.google.com/ig/dell?hl=en
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Start Page =
http://www.google.com/ig/dell?hl=en
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Google
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL =
http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - Reg Error: Key error. File not found
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..extensions.enabledItems: [removed]:1.7
FF - prefs.js..extensions.enabledItems: [removed]:1.0.2
FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2010-11-24 11:39:34 | 000,000,000 | —D | M]
[2011-03-15 19:23:35 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Us\Application Data\Mozilla\Extensions
[2009-12-18 23:00:41 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Us\Application Data\Mozilla\Extensions\[removed]
[2011-03-15 19:23:53 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2009-12-18 23:00:20 | 000,000,000 | —D | M] (Map status indicator) – C:\PROGRAM FILES\TOMTOM HOME 2\XUL\EXTENSIONS\[removed]
O1 HOSTS File: ([2011-04-05 19:10:34 | 000,000,036 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.2.4204.1700\swg.dll (Google Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [BigDog303] C:\WINDOWS\VM303_STI.EXE (Vimicro)
O4 - HKLM..\Run: [ddoctorv2] C:\Program Files\Comcast\Desktop Doctor\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\dla\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [HostManager] C:\Program Files\Common Files\AOL\1136009206\ee\AOLSoftware.exe (America Online, Inc.)
O4 - HKLM..\Run: [TkBellExe] File not found
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [SsAAD.exe] C:\Program Files\Sony\SonicStage\SSAAD.exe ()
O4 - HKCU..\Run: [TomTomHOME.exe] C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe (TomTom)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe (Adobe Systems, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe (Autodesk, Inc)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE (Microsoft Corporation)
O4 - Startup: C:\Documents and Settings\Us\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallVisualStyle = C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles (Microsoft)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: InstallTheme = C:\WINDOWS\Resources\Themes\Royale.theme ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLegacyLogonScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideLogoffScripts = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunLogonScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: RunStartupScriptSync = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideStartupScripts = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O15 - HKLM\..Trusted Domains: musicmatch.com ([online] https in Trusted sites)
O15 - HKCU\..Trusted Domains: internet ([]about in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: mcafee.com ([]https in Trusted sites)
O16 - DPF: {00000055-9980-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/fhg.CAB (Reg Error: Key error.)
O16 - DPF: {3DCEC959-378A-4922-AD7E-FD5C925D927F} http://disney.go.com/pirates/online/testAc…OnlineGames.cab (Disney Online Games ActiveX Control)
O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E}
http://www.linkedin.com/cab/LinkedInContactFinderControl.cab (LinkedIn ContactFinderControl)
O16 - DPF: {56762DEC-6B0D-4AB4-A8AD-989993B5D08B} http://www.eset.eu/buxus/docs/OnlineScanner.cab (Reg Error: Key error.)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab (Windows Live Safety Center Base Module)
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B}
https://www.gamespyid.com/alaunch.cab (Reg Error: Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {D4323BF2-006A-4440-A2F5-27E3E7AB25F8} http://a532.g.akamai.net/f/532/6712/5m/vir…l/installer.exe (Reg Error: Key error.)
O16 - DPF: {DE625294-70E6-45ED-B895-CFFA13AEB044}
http://24.213.36.254/activex/AMC.cab (Reg Error: Key error.)
O16 - DPF: {F127B9BA-89EA-4B04-9C67-2074A9DF61FD}
http://cvs.pnimedia.com/upload/activex/v2_…tupv2.0.0.9.cab? (Photo Upload Plugin Class)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Us\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {091EB208-39DD-417D-A5DD-7E2C2D8FB9CB} - C:\Program Files\Windows Defender\MpShHook.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005-08-16 06:43:04 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (SsiEfr.e) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: msacm.voxacm160 - vct3216.acm File not found
Drivers32: MSVideo - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: MSVideo8 - C:\WINDOWS\System32\vfwwdm32.dll (Microsoft Corporation)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.DRAW - DVIDEO.DLL File not found
Drivers32: VIDC.FPS1 - frapsvid.dll File not found
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.MSUD - msulvc05.dll File not found
Drivers32: VIDC.VP40 - vp4vfw.dll File not found
Drivers32: vidc.VP60 - vp6vfw.dll File not found
Drivers32: vidc.VP61 - vp6vfw.dll File not found
Drivers32: vidc.VP62 - vp6vfw.dll File not found
Drivers32: vidc.VP70 - vp7vfw.dll File not found
Drivers32: VIDC.WMV3 - wmv9vcm.dll File not found
Drivers32: vidc.X264 - x264vfw.dll File not found
Drivers32: VIDC.YV12 - C:\WINDOWS\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Error starting restore point: 126
Error closing restore point: The sequence number is invalid.
========== Files/Folders - Created Within 30 Days ==========
[2011-04-05 19:10:34 | 000,000,000 | —D | C] – C:\Documents and Settings\Us\Desktop\backups
[2011-04-04 20:00:36 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Us\Desktop\HiJackThis.exe
[2011-04-04 19:53:08 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Us\Desktop\OTL.exe
[2011-04-04 19:49:49 | 000,157,472 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2011-04-04 19:49:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2011-04-04 19:49:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2011-03-31 18:48:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Us\Desktop\BOGO
[2011-03-25 19:38:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Us\Application Data\OpenOffice.org
[2011-03-25 19:24:25 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Start Menu\Programs\OpenOffice.org 3.2
[2011-03-25 19:20:09 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2011-03-25 19:19:16 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2011-03-24 20:16:17 | 000,000,000 | —D | C] – C:\Documents and Settings\Us\Desktop\Nagy
[2011-03-18 00:40:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Us\Application Data\FileZilla
[2011-03-18 00:40:28 | 000,000,000 | —D | C] – C:\Program Files\FileZilla FTP Client
[2011-03-16 19:31:26 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011-03-10 00:54:34 | 008,588,616 | —- | C] (Mozilla) – C:\Documents and Settings\Us\Desktop\Firefox Setup 3.6.15.exe
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-04-05 19:12:45 | 000,133,632 | —- | M] () – C:\Documents and Settings\Us\Desktop\RKUnhookerLE.EXE
[2011-04-05 19:10:34 | 000,000,036 | —- | M] () – C:\WINDOWS\System32\drivers\etc\hosts
[2011-04-05 19:07:47 | 074,258,893 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011-04-05 19:04:28 | 000,002,515 | —- | M] () – C:\Documents and Settings\Us\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Outlook.lnk
[2011-04-05 19:03:49 | 000,002,206 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011-04-05 19:03:07 | 000,000,868 | —- | M] () – C:\WINDOWS\tasks\Google Software Updater.job
[2011-04-05 19:02:33 | 000,000,874 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job
[2011-04-05 19:02:25 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011-04-05 19:02:24 | 1331,843,072 | -HS- | M] () – C:\hiberfil.sys
[2011-04-04 23:32:00 | 000,000,878 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job
[2011-04-04 23:02:00 | 000,000,966 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1953154806-233011894-1200954095-1005UA.job
[2011-04-04 20:01:15 | 000,359,929 | —- | M] () – C:\Documents and Settings\Us\Desktop\dds.scr
[2011-04-04 20:00:31 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Us\Desktop\HiJackThis.exe
[2011-04-04 19:53:10 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Us\Desktop\OTL.exe
[2011-04-03 00:02:00 | 000,000,914 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1953154806-233011894-1200954095-1005Core.job
[2011-04-02 15:59:01 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011-03-30 18:32:19 | 000,000,000 | —- | M] () – C:\WINDOWS\System32\drivers\0000.sys
[2011-03-26 21:23:27 | 000,075,264 | —- | M] () – C:\WINDOWS\System32\drivers\5Y60I04.sys
[2011-03-26 11:10:53 | 000,411,080 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011-03-25 19:38:52 | 000,000,897 | —- | M] () – C:\Documents and Settings\Us\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2011-03-24 18:47:01 | 000,289,624 | —- | M] () – C:\Documents and Settings\Us\Desktop\ipad.jpg
[2011-03-16 16:13:33 | 000,009,421 | —- | M] () – C:\Documents and Settings\Us\Desktop\iestyles.css
[2011-03-15 18:35:09 | 000,440,488 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011-03-15 18:35:07 | 000,070,588 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011-03-14 18:52:35 | 000,115,200 | —- | M] () – C:\Documents and Settings\Us\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011-03-12 16:14:42 | 000,164,075 | —- | M] () – C:\Documents and Settings\Us\Desktop\Kitchen.skp
[2011-03-10 00:54:33 | 008,588,616 | —- | M] (Mozilla) – C:\Documents and Settings\Us\Desktop\Firefox Setup 3.6.15.exe
[2011-03-09 21:57:20 | 001,273,344 | —- | M] () – C:\Documents and Settings\Us\Desktop\Header-1.fla
[2011-03-09 21:55:14 | 000,114,376 | —- | M] () – C:\Documents and Settings\Us\Desktop\header.swf
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\*.tmp files -> C:\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-04-05 19:12:56 | 000,133,632 | —- | C] () – C:\Documents and Settings\Us\Desktop\RKUnhookerLE.EXE
[2011-04-04 20:01:17 | 000,359,929 | —- | C] () – C:\Documents and Settings\Us\Desktop\dds.scr
[2011-03-30 18:32:19 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\0000.sys
[2011-03-25 19:38:52 | 000,000,897 | —- | C] () – C:\Documents and Settings\Us\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2011-03-24 18:46:59 | 000,289,624 | —- | C] () – C:\Documents and Settings\Us\Desktop\ipad.jpg
[2011-03-16 16:13:33 | 000,009,421 | —- | C] () – C:\Documents and Settings\Us\Desktop\iestyles.css
[2011-03-12 16:14:42 | 000,164,075 | —- | C] () – C:\Documents and Settings\Us\Desktop\Kitchen.skp
[2011-03-09 21:52:36 | 000,114,376 | —- | C] () – C:\Documents and Settings\Us\Desktop\header.swf
[2010-12-31 14:56:17 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\bsHsKN7LkPEwc6zTboV3VDYcCuBKkxbwbXb4m3GynxqEEisGEFweuwOPakmwEtE=.sys
[2010-10-15 18:50:33 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\100 VE Network Connection - Packet Scheduler Miniport.sys
[2010-03-24 18:16:15 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\.sys
[2010-02-05 19:50:50 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\drivers\{192BA8EB-E576-4FA3-ABC8-44FF9A18ADEE}.sys
[2010-02-03 00:35:29 | 000,075,264 | —- | C] () – C:\WINDOWS\System32\drivers\5Y60I04.sys
[2010-01-26 00:56:20 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010-01-01 23:26:48 | 000,075,428 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2009-10-14 00:38:16 | 000,000,127 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2009-09-20 07:50:25 | 000,000,036 | —- | C] () – C:\WINDOWS\System32\sysnet.dat
[2009-09-20 07:44:56 | 000,000,068 | —- | C] () – C:\WINDOWS\System32\gasfkyunkhrjsm.dat
[2009-09-20 07:38:58 | 000,107,979 | —- | C] () – C:\WINDOWS\System32\gasfkymkwumpow.dat
[2009-02-18 23:46:31 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\lame_enc.dll
[2008-03-09 15:11:53 | 000,003,654 | —- | C] () – C:\WINDOWS\System32\drivers\Sonyhcp.dll
[2007-01-08 16:47:22 | 000,028,672 | —- | C] () – C:\WINDOWS\VMPipe.dll
[2007-01-08 16:47:20 | 000,024,576 | —- | C] () – C:\WINDOWS\RunSetup.dll
[2006-12-30 13:05:03 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\CddbPlaylist2Sony.dll
[2006-11-15 16:34:14 | 000,000,289 | —- | C] () – C:\WINDOWS\SPV.INI
[2006-11-13 10:47:09 | 000,081,920 | —- | C] () – C:\WINDOWS\System32\cpwmon2k.dll
[2006-11-13 10:47:09 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\uninscpw.exe
[2006-09-12 23:59:09 | 000,000,116 | —- | C] () – C:\WINDOWS\asym.ini
[2006-09-01 21:22:15 | 000,002,471 | —- | C] () – C:\WINDOWS\mozver.dat
[2006-08-09 16:47:21 | 000,000,000 | —- | C] () – C:\WINDOWS\mtstack16.INI
[2006-07-27 13:28:42 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2006-07-23 15:42:56 | 000,002,661 | —- | C] () – C:\WINDOWS\EC_55.INI
[2006-07-11 19:40:17 | 000,520,192 | —- | C] () – C:\WINDOWS\System32\DivXsm.exe
[2006-07-11 18:33:49 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006-06-11 16:24:30 | 000,015,840 | —- | C] () – C:\WINDOWS\System32\Machnm1.exe
[2006-06-09 19:04:34 | 000,000,126 | R— | C] () – C:\WINDOWS\hpw9600k.ini
[2006-06-09 19:04:33 | 000,102,400 | R— | C] () – C:\WINDOWS\scrub2k.exe
[2006-06-09 19:03:18 | 000,014,471 | —- | C] () – C:\WINDOWS\hpdj9600.ini
[2006-05-25 19:18:14 | 000,000,664 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2006-05-09 00:59:45 | 000,000,323 | —- | C] () – C:\WINDOWS\PowerReg.dat
[2006-04-24 21:35:24 | 000,000,144 | —- | C] () – C:\WINDOWS\AoADVDRipper.INI
[2006-03-31 21:24:20 | 000,684,032 | —- | C] () – C:\WINDOWS\libeay32.dll
[2006-03-31 21:24:20 | 000,155,648 | —- | C] () – C:\WINDOWS\ssleay32.dll
[2006-02-23 20:14:58 | 000,029,969 | —- | C] () – C:\WINDOWS\SETUPJC.EXE
[2006-02-22 01:38:53 | 000,003,250 | —- | C] () – C:\WINDOWS\CDPLAYER.INI
[2006-01-14 10:33:35 | 000,006,550 | —- | C] () – C:\WINDOWS\jautoexp.dat
[2006-01-11 00:59:14 | 000,000,298 | —- | C] () – C:\WINDOWS\thug2.ini
[2005-12-31 01:59:46 | 000,000,028 | —- | C] () – C:\WINDOWS\atid.ini
[2005-12-31 00:55:32 | 000,115,200 | —- | C] () – C:\Documents and Settings\Us\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2005-12-31 00:45:31 | 000,002,516 | -HS- | C] () – C:\WINDOWS\System32\KGyGaAvL.sys
[2005-12-30 17:29:34 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2005-12-30 16:57:02 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2005-12-30 16:52:12 | 000,000,125 | —- | C] () – C:\Documents and Settings\Us\Local Settings\Application Data\fusioncache.dat
[2005-12-28 17:14:22 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2005-12-28 17:08:13 | 000,149,504 | —- | C] () – C:\WINDOWS\UNWISE.EXE
[2005-12-28 17:04:26 | 000,000,494 | —- | C] () – C:\WINDOWS\wininit.ini
[2005-12-28 17:01:49 | 000,000,335 | —- | C] () – C:\WINDOWS\nsreg.dat
[2005-12-28 16:39:16 | 000,049,152 | —- | C] () – C:\WINDOWS\setpwrcg.exe
[2005-12-28 16:38:50 | 000,000,392 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2005-08-31 12:43:32 | 000,098,304 | —- | C] () – C:\WINDOWS\System32\resourceGeneric.dll
[2005-08-16 06:48:31 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2005-08-16 06:38:45 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2005-08-16 06:37:24 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini
[2005-08-16 06:33:38 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2005-08-16 06:27:59 | 000,411,080 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005-08-16 06:18:35 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2005-08-16 06:18:33 | 000,440,488 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2005-08-16 06:18:33 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2005-08-16 06:18:33 | 000,070,588 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2005-08-16 06:18:33 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2005-08-16 06:18:32 | 000,004,627 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2005-08-16 06:18:30 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2005-08-16 06:18:28 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
[2005-08-16 06:18:23 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2005-08-16 06:18:23 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2005-08-16 06:18:15 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2005-08-16 06:18:08 | 000,001,788 | —- | C] () – C:\WINDOWS\System32\Dcache.bin
[2005-08-05 16:01:54 | 000,239,104 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2005-04-09 19:04:54 | 000,000,000 | —- | C] () – C:\WINDOWS\System32\px.ini
[2003-01-30 08:04:00 | 000,618,496 | —- | C] () – C:\WINDOWS\System32\StlpMt45.dll
[1999-01-22 14:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
[1998-01-12 04:00:00 | 000,040,448 | —- | C] () – C:\WINDOWS\System32\REGOBJ.DLL
========== LOP Check ==========
[2006-11-09 22:38:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Autodesk
[2010-02-10 11:06:35 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2008-08-16 15:19:03 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Comcast
[2011-03-16 19:31:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2007-12-08 12:15:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Grisoft
[2011-01-23 18:08:21 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Musicnotes
[2006-10-09 19:10:58 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Napster
[2007-12-08 23:58:43 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Prevx
[2006-08-04 09:27:05 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SBT
[2008-08-16 11:13:52 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SupportSoft
[2007-12-09 02:49:08 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2009-12-18 23:01:16 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TomTom
[2005-12-28 17:02:50 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2006-01-14 10:35:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Visual Networks
[2010-09-19 13:59:51 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010-01-01 22:51:40 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\{755AC846-7372-4AC8-8550-C52491DAA8BD}
[2009-08-14 22:42:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\4Media Software Studio
[2005-12-31 02:12:39 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\acccore
[2006-11-09 22:38:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Autodesk
[2010-02-27 21:13:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\CoffeeCup Software
[2011-04-03 18:04:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\CoreFTP
[2010-02-04 23:18:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Desktopicon
[2011-03-18 01:55:42 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\FileZilla
[2006-02-12 04:01:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Kontiki
[2005-12-31 03:01:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Leadertech
[2010-01-28 23:55:33 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\LEGO Company
[2008-05-07 20:30:10 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\LinkedIn
[2011-03-25 19:38:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\OpenOffice.org
[2007-12-08 23:59:08 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\PrevxCSI
[2007-12-08 22:57:34 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Simply Super Software
[2006-01-24 00:29:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\STOIK
[2009-12-18 23:00:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\TomTom
[2009-02-17 19:17:12 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\tunebite
[2008-06-04 21:37:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Uniblue
[2010-10-10 20:24:32 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\uTorrent
[2007-01-23 11:31:00 | 000,000,000 | —D | M] – C:\Documents and Settings\Us\Application Data\Viewpoint
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010-11-20 15:32:35 | 000,072,189 | —- | M] () – C:\acadminidump.dmp
[2008-06-05 08:12:18 | 000,215,552 | —- | M] () – C:\Archive Log.xls
[2005-08-16 06:43:04 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2005-12-30 16:51:49 | 000,000,209 | RHS- | M] () – C:\boot.ini
[2008-07-04 12:51:07 | 000,003,590 | —- | M] () – C:\Bug.txt
[2009-10-27 23:42:23 | 000,103,579 | —- | M] () – C:\capture.wma
[2008-07-04 12:37:14 | 000,009,304 | —- | M] () – C:\ComboFix.txt
[2007-12-10 21:21:39 | 000,010,975 | —- | M] () – C:\ComboFix2.txt
[2005-08-16 06:43:04 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[1999-08-18 13:13:48 | 000,061,552 | —- | M] () – C:\COPRGTB.TTF
[1999-08-18 13:13:48 | 000,062,716 | —- | M] () – C:\COPRGTL.TTF
[2005-12-28 16:42:34 | 000,005,985 | RH– | M] () – C:\dell.sdr
[2007-01-12 15:21:54 | 000,021,504 | —- | M] () – C:\Employee Evaluation Form.doc
[2006-09-14 13:53:54 | 006,561,360 | —- | M] () – C:\FinalRevised.tif
[2006-07-28 13:12:13 | 000,005,759 | —- | M] () – C:\GroupVPN_00401018671B.spd
[2006-07-28 12:48:15 | 000,001,127 | —- | M] () – C:\GroupVPN_00401018671B[1].rcf
[2011-04-05 19:02:24 | 1331,843,072 | -HS- | M] () – C:\hiberfil.sys
[2005-12-30 17:04:04 | 000,004,128 | —- | M] () – C:\INFCACHE.1
[2005-08-16 06:43:04 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2009-05-21 15:33:07 | 000,714,240 | —- | M] () – C:\Job Log.xls
[2006-06-06 14:10:33 | 000,475,557 | —- | M] () – C:\LeeHall.jpg
[2006-01-08 22:03:20 | 000,002,785 | —- | M] () – C:\LGSInst.Log
[2005-08-16 06:43:04 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2009-09-12 12:27:31 | 000,001,049 | —- | M] () – C:\net_save.dna
[2004-08-10 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2004-08-10 07:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2011-04-05 19:02:22 | 792,723,456 | -HS- | M] () – C:\pagefile.sys
[2007-10-17 23:14:50 | 000,606,266 | —- | M] () – C:\record_1.wav
[2006-03-09 11:45:55 | 000,022,998 | —- | M] () – C:\sonicwall.exp
[2006-10-08 02:39:38 | 000,000,161 | —- | M] () – C:\Spyware removal Registration.txt
[2005-10-31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2005-12-28 17:03:01 | 000,000,087 | —- | M] () – C:\SystemInfo.ini
[2010-10-17 19:04:37 | 000,000,319 | —- | M] () – C:\VRayLog.txt
[2007-12-08 23:43:32 | 000,006,803 | —- | M] () – C:\VundoFix.txt
[2009-09-05 13:04:21 | 000,054,516 | —- | M] () – C:\WaxCrash.dmp
[2009-09-05 13:04:21 | 000,100,726 | —- | M] () – C:\WaxCrash.txt
[2007-01-08 16:59:30 | 000,000,146 | —- | M] () – C:\YServer.txt
[1 C:\*.tmp files -> C:\*.tmp -> ]
< %systemroot%\Fonts\*.com >
[2006-04-18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006-06-29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006-04-18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
[2006-06-29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2005-08-16 06:42:12 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008-07-06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2002-03-11 11:00:06 | 000,081,408 | —- | M] (Lexmark International) – C:\WINDOWS\system32\spool\prtprocs\w32x86\LXAIPP5C.DLL
[2003-06-18 18:31:48 | 000,018,944 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\mdippr.dll
[2008-07-06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2005-08-16 06:27:08 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2005-08-16 06:27:08 | 000,659,456 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2005-08-16 06:27:08 | 000,876,544 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2005-08-16 06:43:10 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2005-12-30 16:52:27 | 000,000,170 | -HS- | M] () – C:\Documents and Settings\Us\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2005-08-16 06:50:28 | 000,000,079 | —- | M] () – C:\Documents and Settings\Us\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2011-03-10 00:54:33 | 008,588,616 | —- | M] (Mozilla) – C:\Documents and Settings\Us\Desktop\Firefox Setup 3.6.15.exe
[2011-04-04 20:00:31 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Us\Desktop\HiJackThis.exe
[2011-04-04 19:53:10 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Us\Desktop\OTL.exe
[2011-04-05 19:12:45 | 000,133,632 | —- | M] () – C:\Documents and Settings\Us\Desktop\RKUnhookerLE.EXE
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-03-09 04:41:56
========== Files - Unicode (All) ==========
[2010-10-22 14:24:04 | 000,000,000 | —- | M] ()(C:\WINDOWS\System32\drivers\?°????.sys) – C:\WINDOWS\System32\drivers\牉⁰稠襛嗐襙.sys
[2010-10-22 14:24:04 | 000,000,000 | —- | C] ()(C:\WINDOWS\System32\drivers\?°????.sys) – C:\WINDOWS\System32\drivers\牉⁰稠襛嗐襙.sys
[2010-10-18 11:21:11 | 000,000,000 | —- | M] ()(C:\WINDOWS\System32\drivers\?°????.sys) – C:\WINDOWS\System32\drivers\牉⁰ᗐ袳읨袲.sys
[2010-10-18 11:21:11 | 000,000,000 | —- | C] ()(C:\WINDOWS\System32\drivers\?°????.sys) – C:\WINDOWS\System32\drivers\牉⁰ᗐ袳읨袲.sys
[2010-02-03 19:30:18 | 000,000,000 | —- | M] ()(C:\WINDOWS\System32\drivers\??.sys) – C:\WINDOWS\System32\drivers\鉠覽.sys
[2010-02-03 19:30:18 | 000,000,000 | —- | C] ()(C:\WINDOWS\System32\drivers\??.sys) – C:\WINDOWS\System32\drivers\鉠覽.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 108 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:CB0AACC9
< End of report >