This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Generic21.BPDJ and disappearing drives. (continued)

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My old thread got locked. No biggie. Sometimes I'm away from the computer for a few days.

Anyway, the old thread is here:
http://forums.whatthetech.com/index.php?showtopic=117958

AVG had been warning me about multiple instances of this trojan but would only ever let me "quarantine" the first one on the list. Those notifications have since stopped, I haven't had that problem now for a week or two. I'd still like to be sure that it's clear, though.

I think I finally got rid of uTorrent; it's not listed in the "Add/Remove Programs" list anymore.

Here are some fresh DDS logs:


DDS (Ver_09-06-26.01) - NTFSx86
Run by [removed] at 6:52:14.95 on Thu 04/28/2011
Internet Explorer: 7.0.5730.13
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.3325.2007 [GMT 9.5:30]


============== Running Processes ===============

C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\AVG\AVG9\avgchsvx.exe
C:\Program Files\AVG\AVG9\avgrsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe
C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Program Files\GIGABYTE\ET6\GUI.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\AVG\AVG9\avgtray.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\TechSmith\Snagit 9\Snagit32.exe
C:\Program Files\AVG\AVG9\avgwdsvc.exe
C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE
C:\Program Files\TechSmith\Snagit 9\TSCHelp.exe
C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe
C:\Program Files\TechSmith\Snagit 9\snagiteditor.exe
C:\Program Files\AVG\AVG9\avgemc.exe
C:\Program Files\AVG\AVG9\avgnsx.exe
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\MediaMonkey\MediaMonkey.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Microsoft Office\Office10\EXCEL.EXE
C:\Program Files\AVG\AVG9\avgcsrvx.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Owner\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/
uURLSearchHooks: DeviceVM Url Search Hook: {0063bf63-bfff-4b8f-9d26-4267df7f17dd} - c:\windows\system32\dvmurl.dll
mWinlogon: SfcDisable=-99 (0xffffff9d)
BHO: SnagIt Toolbar Loader: {00c6482d-c502-44c8-8409-fce54ad9c208} - c:\program files\techsmith\snagit 9\SnagitBHO.dll
BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Windows Live Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll
TB: Snagit: {8ff5e183-abde-46eb-b09e-d2aab95cabe3} - c:\program files\techsmith\snagit 9\SnagitIEAddin.dll
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uRunOnce: [FlashPlayerUpdate] c:\windows\system32\macromed\flash\FlashUtil10o_Plugin.exe -update plugin
mRun: [ANIWZCS2Service] c:\program files\ani\aniwzcs2 service\WZCSLDR2.exe
mRun: [D-Link D-Link Wireless G DWA-510] c:\program files\d-link\d-link wireless g dwa-510\AirGCFG.exe
mRun: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
mRun: [RTHDCPL] RTHDCPL.EXE
mRun: [Alcmtr] ALCMTR.EXE
mRun: [EasyTuneVI] c:\program files\gigabyte\et6\ETcall.exe
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: [GBTUpd] c:\program files\gigabyte\gbtupd\PreRun.exe
mRun: [NeroFilterCheck] c:\windows\system32\NeroCheck.exe
mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe"
dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\micros~1.lnk - c:\program files\microsoft office\office10\OSA.EXE
StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\snagit~1.lnk - c:\program files\techsmith\snagit 9\Snagit32.exe
uPolicies-explorer: NoSMMyDocs = 1 (0x1)
uPolicies-explorer: NoSMMyPictures = 1 (0x1)
uPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
mPolicies-explorer: NoDesktopCleanupWizard = 1 (0x1)
dPolicies-explorer: NoSMMyDocs = 1 (0x1)
dPolicies-explorer: NoSMMyPictures = 1 (0x1)
dPolicies-explorer: NoSMConfigurePrograms = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office10\EXCEL.EXE/3000
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
Handler: cdo - {CD00020A-8B95-11D1-82DB-00C04FB1625D} - c:\program files\common files\microsoft shared\web folders\PKMCDO.DLL
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll
Notify: AtiExtEvent - Ati2evxx.dll
Notify: avgrsstarter - avgrsstx.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\owner\applic~1\mozilla\firefox\profiles\bzti02sn.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bom.gov.au/sa/forecasts/adelaide.shtml
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nppl3260.dll
FF - plugin: c:\program files\k-lite codec pack\real\browser\plugins\nprpjplug.dll
FF - plugin: c:\program files\microsoft silverlight\2.0.31005.0\npctrlui.dll
FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

============= SERVICES / DRIVERS ===============

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2011-4-4 216400]
R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2011-4-4 29584]
R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2011-4-4 243024]
R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2011-4-4 921952]
R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2011-4-4 308136]
R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2011-4-1 68136]
R3 GVTDrv;GVTDrv;c:\windows\system32\drivers\GVTDrv.sys [2011-4-1 24944]
R3 MBAMSwissArmy;MBAMSwissArmy;c:\windows\system32\drivers\mbamswissarmy.sys [2011-4-8 38224]
S3 AtiHdmiService;ATI Function Driver for HDMI Service;c:\windows\system32\drivers\AtiHdmi.sys [2009-4-1 93184]
S3 Revoflt;Revoflt;c:\windows\system32\drivers\revoflt.sys [2011-4-21 27064]

=============== Created Last 30 ================

2011-04-27 12:09 –d-h— C:\$AVG
2011-04-26 15:56 –d—– c:\program files\EA GAMES
2011-04-21 05:21 27,064 a——- c:\windows\system32\drivers\revoflt.sys
2011-04-21 05:21 –d—– c:\program files\VS Revo Group
2011-04-18 15:51 –d—– c:\documents and settings\owner\dwhelper
2011-04-11 03:49 –d—– c:\documents and settings\owner\Tracing
2011-04-11 03:41 –d—– c:\windows\system32\DirectX
2011-04-11 03:40 –d—– c:\program files\Microsoft SQL Server Compact Edition
2011-04-11 03:37 –d—– c:\program files\Microsoft
2011-04-11 03:36 –d—– c:\program files\Windows Live SkyDrive
2011-04-11 03:25 –d—– c:\program files\common files\Windows Live
2011-04-08 02:42 –d—– c:\docume~1\owner\applic~1\Malwarebytes
2011-04-08 02:42 38,224 a——- c:\windows\system32\drivers\mbamswissarmy.sys
2011-04-08 02:42 20,952 a——- c:\windows\system32\drivers\mbam.sys
2011-04-08 02:42 –d—– c:\program files\Malwarebytes' Anti-Malware
2011-04-08 02:42 –d—– c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-04-07 00:27 –d—– c:\program files\common files\Wise Installation Wizard
2011-04-06 23:01 376 a——- c:\windows\ODBC.INI
2011-04-06 23:01 –d—– c:\program files\Microsoft ActiveSync
2011-04-06 23:00 –d—– c:\windows\ShellNew
2011-04-06 21:31 –d—– c:\program files\ImageShack Uploader
2011-04-04 22:00 –d-h— c:\docume~1\alluse~1\applic~1\Common Files
2011-04-04 16:22 –d—– c:\docume~1\owner\applic~1\avidemux
2011-04-04 16:22 –d—– c:\program files\Avidemux 2.5
2011-04-04 15:40 12,536 a——- c:\windows\system32\avgrsstx.dll
2011-04-04 15:33 243,024 a——- c:\windows\system32\drivers\avgtdix.sys
2011-04-04 15:33 216,400 a——- c:\windows\system32\drivers\avgldx86.sys
2011-04-04 15:33 –d—– c:\windows\system32\drivers\Avg
2011-04-04 15:33 –d—– c:\program files\AVG
2011-04-04 15:33 –d—– c:\docume~1\alluse~1\applic~1\avg9
2011-04-04 15:28 –d—– c:\docume~1\alluse~1\applic~1\MFAData
2011-04-02 05:03 69 a——- c:\windows\NeroDigital.ini
2011-04-02 04:17 –d—– c:\program files\ExtractNow
2011-04-02 04:03 –d—– c:\docume~1\owner\applic~1\uTorrent
2011-04-02 04:00 125,184 ——– c:\windows\system32\drivers\imagesrv.sys
2011-04-02 04:00 5,504 ——– c:\windows\system32\drivers\imagedrv.sys
2011-04-02 04:00 155,648 a——- c:\windows\system32\NeroCheck.exe
2011-04-02 04:00 106,496 a——- c:\windows\system32\TwnLib20.dll
2011-04-02 04:00 1,568,768 ——– c:\windows\system32\ImagX7.dll
2011-04-02 04:00 476,320 ——– c:\windows\system32\ImagXpr7.dll
2011-04-02 04:00 471,040 ——– c:\windows\system32\ImagXRA7.dll
2011-04-02 04:00 262,144 ——– c:\windows\system32\ImagXR7.dll
2011-04-02 01:57 –d—– c:\docume~1\alluse~1\applic~1\MediaMonkey
2011-04-02 01:30 –d—– c:\program files\MediaMonkey
2011-04-01 16:09 –d—– c:\program files\K-Lite Codec Pack
2011-04-01 15:23 4,444 a——- c:\windows\system32\pid.PNF
2011-04-01 14:54 3,072 a——- c:\windows\system32\drivers\audstub.sys
2011-04-01 14:53 21,504 a——- c:\windows\system32\hidserv.dll
2011-04-01 14:53 57,600 a——- c:\windows\system32\drivers\redbook.sys
2011-04-01 14:52 6,400 a——- c:\windows\system32\drivers\enum1394.sys
2011-04-01 14:51 –d—– c:\program files\common files\ODBC
2011-04-01 14:50 24,064 a——- c:\windows\system\OLESVR.DLL
2011-04-01 14:50 –d–r– c:\documents and settings\all users\Documents
2011-04-01 14:49 1,088,840 a—-r– c:\windows\SET4.tmp
2011-04-01 14:49 1,296,669 a—-r– c:\windows\SET3.tmp
2011-04-01 14:48 –d—– c:\windows\system32\CatRoot2
2011-04-01 14:48 –d—– c:\windows\system32\CatRoot
2011-04-01 14:48 –d—– C:\Documents and Settings
2011-04-01 14:47 869 a——- c:\windows\system32\$winnt$.inf
2011-04-01 06:23 –d—– c:\program files\Ulead Systems
2011-04-01 06:17 –d—– c:\program files\AMD
2011-04-01 06:17 –d—– c:\program files\Browser Configuration Utility
2011-04-01 06:16 –d—– c:\program files\Gigabyte
2011-04-01 06:13 –d—– c:\program files\common files\Logitech
2011-04-01 06:10 –d—– c:\program files\ANI
2011-04-01 06:10 –d—– c:\program files\D-Link
2011-04-01 06:08 –d—– c:\program files\common files\ATI Technologies
2011-04-01 06:05 –d—– c:\program files\ATI Technologies
2011-04-01 05:58 –dsh— c:\documents and settings\all users\DRM
2011-04-01 05:58 –d-h— c:\program files\WindowsUpdate
2011-04-01 05:58 –d—– c:\program files\Windows Media Connect 2
2011-04-01 05:57 –d—– c:\program files\common files\MSSoap
2011-04-01 05:27 –d—– c:\program files\VideoLAN
2011-04-01 05:18 –d—– c:\program files\Realtek

==================== Find3M ====================

2011-04-17 01:25 24,944 a——- c:\windows\system32\drivers\GVTDrv.sys
2011-04-17 01:24 16,608 a——- c:\windows\gdrv.sys
2011-04-02 13:23 86,327 a——- c:\windows\pchealth\helpctr\offlinecache\index.dat
2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
2011-04-01 06:14 0 a—h— c:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2011-04-01 05:57 21,640 a——- c:\windows\system32\emptyregdb.dat

============= FINISH: 6:52:37.21 ===============


And here's the most recent Malwarebytes Anti-Malware log:

Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4052

Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.13

4/28/2011 6:55:59 AM
mbam-log-2011-04-28 (06-55-59).txt

Scan type: Quick scan
Objects scanned: 110312
Time elapsed: 3 minute(s), 52 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


I couldn't attach any files to this post, so no attach.txt from DDS unless you want me to post it.
:welcome:

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.



OTL by OldTimer
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Click the "Scan All Users" checkbox.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Thanks for helping!

(For the record, I'm pretty computer literate - at the very least, I do know how to copy/paste things.)

Here's the OTL.txt log:

OTL logfile created on: 5/1/2011 11:35:06 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 62.39 Gb Free Space | 83.72% Space Free | Partition Type: NTFS
Drive D: | 74.53 Gb Total Space | 46.11 Gb Free Space | 61.88% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 468.63 Gb Free Space | 50.31% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 620.46 Gb Free Space | 66.61% Space Free | Partition Type: NTFS

Computer Name: BRIAN-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG9\avgchsvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Gigabyte\EasySaver\essvr.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\SnagPriv.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\TscHelp.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\SnagitEditor.exe (TechSmith Corporation)
PRC - C:\Program Files\TechSmith\Snagit 9\Snagit32.exe (TechSmith Corporation)
PRC - C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe (D-Link)
PRC - C:\Program Files\Gigabyte\ET6\GUI.exe ()
PRC - C:\Program Files\MediaMonkey\MediaMonkey.exe (Ventis Media Inc.)
PRC - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.5512_x-ww_35d4ce83\comctl32.dll (Microsoft Corporation)
MOD - C:\Program Files\MediaMonkey\MMHelper.dll ()


========== Win32 Services (SafeList) ==========

SRV - (avg9wd) – C:\Program Files\AVG\AVG9\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (avg9emc) – C:\Program Files\AVG\AVG9\avgemc.exe (AVG Technologies CZ, s.r.o.)
SRV - (ES lite Service) – C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE ()
SRV - (ANIWZCSdService) – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Wireless Service)


========== Driver Services (SafeList) ==========

DRV - (GVTDrv) – C:\WINDOWS\system32\drivers\GVTDrv.sys ()
DRV - (gdrv) – C:\WINDOWS\gdrv.sys (Windows ® 2000 DDK provider)
DRV - (AvgTdiX) – C:\WINDOWS\System32\Drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgMfx86) – C:\WINDOWS\System32\Drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (AvgLdx86) – C:\WINDOWS\System32\Drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Revoflt) – C:\WINDOWS\system32\drivers\revoflt.sys (VS Revo Group)
DRV - (ati2mtag) – C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (AtiHdmiService) – C:\WINDOWS\system32\drivers\AtiHdmi.sys (ATI Research Inc.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\WINDOWS\system32\drivers\RtkHDAud.sys (Realtek Semiconductor Corp.)
DRV - (RTHDMIAzAudService) – C:\WINDOWS\system32\drivers\RtKHDMI.sys (Realtek Semiconductor Corp.)
DRV - (RTLE8023xp) – C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation )
DRV - (RT61) – C:\WINDOWS\system32\drivers\rt61.sys (Ralink Technology, Corp.)
DRV - (AmdPPM) – C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (LHidFilt) – C:\WINDOWS\system32\drivers\LHidFilt.Sys (Logitech, Inc.)
DRV - (LMouFilt) – C:\WINDOWS\system32\drivers\LMouFilt.Sys (Logitech, Inc.)
DRV - (ANIO) – C:\WINDOWS\system32\ANIO.sys (Alpha Networks Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/

IE - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\..\URLSearchHook: {0063BF63-BFFF-4B8F-9D26-4267DF7F17DD} - C:\WINDOWS\system32\dvmurl.dll (DeviceVM Inc.)
IE - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.bom.gov.au/sa/forecasts/adelaide.shtml"

FF - HKLM\software\mozilla\Firefox\Extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG9\Firefox [2011/04/04 21:59:54 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/05/01 05:51:03 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins

[2011/04/01 05:34:25 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/04/18 15:50:09 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bzti02sn.default\extensions
[2011/04/18 15:50:09 | 000,000,000 | —D | M] (DownloadHelper) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\bzti02sn.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2011/04/01 05:38:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) –
[2011/05/01 05:50:59 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files\Mozilla Firefox\components\browsercomps.dll
[2010/01/01 17:30:00 | 000,002,252 | —- | M] () – C:\Program Files\Mozilla Firefox\searchplugins\bing.xml

O1 HOSTS File: ([2011/04/01 05:37:55 | 000,000,781 | RHS- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 9\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 9\SnagitIEAddin.dll (TechSmith Corporation)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Wireless Service)
O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [D-Link D-Link Wireless G DWA-510] C:\Program Files\D-Link\D-Link Wireless G DWA-510\AirGCFG.exe (D-Link)
O4 - HKLM..\Run: [EasyTuneVI] C:\Program Files\Gigabyte\ET6\ETcall.exe ()
O4 - HKLM..\Run: [GBTUpd] C:\Program Files\Gigabyte\GBTUpd\PreRun.exe (PreRun)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech Inc.)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk = C:\Program Files\TechSmith\Snagit 9\Snagit32.exe (TechSmith Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\S-1-5-20\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O7 - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoLowDiskSpaceChecks = 1
O7 - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyDocs = 1
O7 - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMMyPictures = 1
O7 - HKU\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSMConfigurePrograms = 1
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/04/01 05:59:22 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O32 - AutoRun File - [2009/12/01 18:48:08 | 000,000,033 | -HS- | M] () - F:\autorun.inf – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2011/04/29 18:02:58 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/04/29 18:02:53 | 000,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF-Cleaner.exe
[2011/04/29 09:42:19 | 000,045,115 | —- | C] (Alpha Networks Inc.) – C:\WINDOWS\System32\ANICtl.dll
[2011/04/29 04:22:42 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/04/27 12:09:00 | 000,000,000 | -H-D | C] – C:\$AVG
[2011/04/26 19:28:07 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\EA Games
[2011/04/26 16:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\EA GAMES
[2011/04/26 16:09:32 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\EA Games
[2011/04/26 15:56:34 | 000,000,000 | —D | C] – C:\Program Files\EA GAMES
[2011/04/25 19:48:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Adobe
[2011/04/21 05:21:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\VS Revo Group
[2011/04/21 05:21:39 | 000,027,064 | —- | C] (VS Revo Group) – C:\WINDOWS\System32\drivers\revoflt.sys
[2011/04/21 05:21:39 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Revo Uninstaller Pro
[2011/04/21 05:21:37 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2011/04/18 15:51:14 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\dwhelper
[2011/04/17 03:32:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Help
[2011/04/17 03:32:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Help
[2011/04/11 04:46:04 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My Received Files
[2011/04/11 03:49:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Tracing
[2011/04/11 03:41:22 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DirectX
[2011/04/11 03:40:24 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/04/11 03:37:35 | 000,000,000 | —D | C] – C:\Program Files\Microsoft
[2011/04/11 03:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\microsoft
[2011/04/11 03:36:58 | 000,000,000 | —D | C] – C:\Program Files\Windows Live SkyDrive
[2011/04/11 03:36:44 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Windows Live
[2011/04/11 03:36:03 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2011/04/11 03:25:54 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Windows Live
[2011/04/08 14:40:40 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\WinRAR
[2011/04/08 14:40:31 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Start Menu\Programs\WinRAR
[2011/04/08 14:40:31 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\WinRAR
[2011/04/08 14:40:17 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2011/04/08 02:42:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Malwarebytes
[2011/04/08 02:42:57 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/04/08 02:42:55 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2011/04/08 02:42:54 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2011/04/08 02:42:54 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2011/04/08 02:42:54 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2011/04/07 03:23:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\dvdcss
[2011/04/07 00:43:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Snagit
[2011/04/07 00:29:34 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Snagit 9
[2011/04/07 00:29:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/04/07 00:29:27 | 000,000,000 | —D | C] – C:\Program Files\TechSmith
[2011/04/07 00:29:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\TechSmith
[2011/04/07 00:27:32 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Wise Installation Wizard
[2011/04/06 23:01:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Office Tools
[2011/04/06 23:01:08 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ActiveSync
[2011/04/06 23:01:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Designer
[2011/04/06 23:00:49 | 000,000,000 | —D | C] – C:\WINDOWS\ShellNew
[2011/04/06 23:00:48 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2011/04/06 22:58:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2011/04/06 22:53:24 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2011/04/06 22:53:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2011/04/06 22:53:14 | 000,000,000 | —D | C] – C:\Program Files\Adobe
[2011/04/06 21:32:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ImageShack Uploader
[2011/04/06 21:31:59 | 000,000,000 | —D | C] – C:\Program Files\ImageShack Uploader
[2011/04/06 18:28:08 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Avidemux
[2011/04/04 22:00:06 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/04 16:22:53 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\avidemux
[2011/04/04 16:22:36 | 000,000,000 | —D | C] – C:\Program Files\Avidemux 2.5
[2011/04/04 15:40:48 | 000,012,536 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2011/04/04 15:33:11 | 000,243,024 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2011/04/04 15:33:11 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\AVG Free 9.0
[2011/04/04 15:33:10 | 000,216,400 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2011/04/04 15:33:10 | 000,029,584 | —- | C] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2011/04/04 15:33:10 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\Avg
[2011/04/04 15:33:00 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/04/04 15:33:00 | 000,000,000 | —D | C] – C:\Program Files\AVG
[2011/04/04 15:28:33 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/02 05:03:54 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\vlc
[2011/04/02 04:17:38 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\ExtractNow
[2011/04/02 04:17:16 | 000,000,000 | —D | C] – C:\Program Files\ExtractNow
[2011/04/02 04:17:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\ExtractNow
[2011/04/02 04:03:42 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\uTorrent
[2011/04/02 04:00:36 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Nero
[2011/04/02 04:00:33 | 000,125,184 | —- | C] (Ahead Software AG) – C:\WINDOWS\System32\drivers\imagesrv.sys
[2011/04/02 04:00:33 | 000,005,504 | —- | C] (Ahead Software AG) – C:\WINDOWS\System32\drivers\imagedrv.sys
[2011/04/02 04:00:23 | 001,568,768 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagX7.dll
[2011/04/02 04:00:23 | 000,476,320 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXpr7.dll
[2011/04/02 04:00:23 | 000,471,040 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXRA7.dll
[2011/04/02 04:00:23 | 000,262,144 | —- | C] (Pegasus Imaging Corp.) – C:\WINDOWS\System32\ImagXR7.dll
[2011/04/02 04:00:23 | 000,155,648 | —- | C] (Ahead Software Gmbh) – C:\WINDOWS\System32\NeroCheck.exe
[2011/04/02 04:00:23 | 000,106,496 | —- | C] (Pegasus Software) – C:\WINDOWS\System32\TwnLib20.dll
[2011/04/02 04:00:23 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Ahead
[2011/04/02 04:00:20 | 000,000,000 | —D | C] – C:\Program Files\Ahead
[2011/04/02 01:57:10 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2011/04/02 01:54:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011/04/02 01:30:16 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\MediaMonkey
[2011/04/02 01:30:13 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\MediaMonkey
[2011/04/02 01:30:12 | 000,000,000 | —D | C] – C:\Program Files\MediaMonkey
[2011/04/02 01:18:42 | 000,000,000 | R–D | C] – C:\Documents and Settings\Owner\My Documents\My Videos
[2011/04/02 01:18:42 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2011/04/01 18:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Media Player Classic
[2011/04/01 16:09:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\K-Lite Codec Pack
[2011/04/01 16:09:56 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\WINDOWS\System32\pncrt.dll
[2011/04/01 16:09:56 | 000,185,920 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\rmoc3260.dll
[2011/04/01 16:09:56 | 000,006,656 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5016.dll
[2011/04/01 16:09:56 | 000,005,632 | —- | C] (RealNetworks, Inc.) – C:\WINDOWS\System32\pndx5032.dll
[2011/04/01 16:09:54 | 001,294,336 | —- | C] (HMS http://hp.vector.co.jp/authors/VA012897/) – C:\WINDOWS\System32\vorbis.acm
[2011/04/01 16:09:54 | 000,839,680 | —- | C] (http://www.mp3dev.org/) – C:\WINDOWS\System32\lameACM.acm
[2011/04/01 16:09:54 | 000,287,744 | —- | C] (Kristal StudioDFileDescription) – C:\WINDOWS\System32\divxa32.acm
[2011/04/01 16:09:54 | 000,232,448 | —- | C] (Fraunhofer Institut Integrierte Schaltungen IIS) – C:\WINDOWS\System32\mp3fhg.acm
[2011/04/01 16:09:54 | 000,217,088 | —- | C] (www.helixcommunity.org) – C:\WINDOWS\System32\yv12vfw.dll
[2011/04/01 16:09:54 | 000,118,784 | —- | C] (fccHandler) – C:\WINDOWS\System32\ac3acm.acm
[2011/04/01 16:09:54 | 000,039,936 | —- | C] (Disappearing Inc.) – C:\WINDOWS\System32\huffyuv.dll
[2011/04/01 16:09:53 | 000,630,784 | —- | C] (On2.com) – C:\WINDOWS\System32\vp7vfw.dll
[2011/04/01 16:09:53 | 000,442,368 | R— | C] (On2.com) – C:\WINDOWS\System32\vp6vfw.dll
[2011/04/01 16:09:53 | 000,391,680 | —- | C] (Intel Corporation) – C:\WINDOWS\System32\I263_32.drv
[2011/04/01 16:09:53 | 000,090,112 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\dpl100.dll
[2011/04/01 16:09:52 | 000,685,056 | —- | C] (DivX, Inc.) – C:\WINDOWS\System32\divx.dll
[2011/04/01 16:09:50 | 000,000,000 | —D | C] – C:\Program Files\K-Lite Codec Pack
[2011/04/01 15:46:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Softwrap
[2011/04/01 15:46:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Fonts
[2011/04/01 15:46:42 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Documents\Config
[2011/04/01 14:52:32 | 000,006,400 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\enum1394.sys
[2011/04/01 14:51:50 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\usbui.dll
[2011/04/01 14:51:09 | 000,000,000 | R–D | C] – C:\Program Files
[2011/04/01 14:51:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ODBC
[2011/04/01 14:51:09 | 000,000,000 | —D | C] – C:\Program Files\Common Files
[2011/04/01 14:51:00 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irclass.dll
[2011/04/01 14:50:59 | 000,024,064 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\OLESVR.DLL
[2011/04/01 14:50:59 | 000,019,200 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\TAPI.DLL
[2011/04/01 14:50:59 | 000,013,600 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WFWNET.DRV
[2011/04/01 14:50:59 | 000,009,008 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\VER.DLL
[2011/04/01 14:50:59 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SHELL.DLL
[2011/04/01 14:50:59 | 000,004,048 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\TIMER.DRV
[2011/04/01 14:50:59 | 000,003,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SYSTEM.DRV
[2011/04/01 14:50:59 | 000,002,176 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\VGA.DRV
[2011/04/01 14:50:59 | 000,001,744 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\SOUND.DRV
[2011/04/01 14:50:58 | 000,126,912 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MSVIDEO.DLL
[2011/04/01 14:50:58 | 000,082,944 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\OLECLI.DLL
[2011/04/01 14:50:58 | 000,073,376 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCIAVI.DRV
[2011/04/01 14:50:58 | 000,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCIWAVE.DRV
[2011/04/01 14:50:58 | 000,025,264 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MCISEQ.DRV
[2011/04/01 14:50:58 | 000,002,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MOUSE.DRV
[2011/04/01 14:50:58 | 000,001,152 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MMTASK.TSK
[2011/04/01 14:50:57 | 000,109,456 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\AVIFILE.DLL
[2011/04/01 14:50:57 | 000,069,584 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\AVICAP.DLL
[2011/04/01 14:50:57 | 000,032,816 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\COMMDLG.DLL
[2011/04/01 14:50:57 | 000,009,936 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\LZEXPAND.DLL
[2011/04/01 14:50:57 | 000,002,000 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\KEYBOARD.DRV
[2011/04/01 14:50:56 | 000,146,432 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\WINSPOOL.DRV
[2011/04/01 14:50:56 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\WINDOWS\TASKMAN.EXE
[2011/04/01 14:50:56 | 000,008,704 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\batt.dll
[2011/04/01 14:50:55 | 000,074,752 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\storprop.dll
[2011/04/01 14:50:55 | 000,068,768 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System\MMSYSTEM.DLL
[2011/04/01 14:50:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\Startup
[2011/04/01 14:50:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Start Menu
[2011/04/01 14:50:49 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents
[2011/04/01 14:50:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Templates
[2011/04/01 14:50:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Favorites
[2011/04/01 14:50:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Desktop
[2011/04/01 14:48:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot2
[2011/04/01 14:48:57 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot
[2011/04/01 14:48:52 | 000,000,000 | –SD | C] – C:\Documents and Settings\All Users\Application Data\Microsoft
[2011/04/01 14:48:52 | 000,000,000 | RH-D | C] – C:\Documents and Settings\All Users\Application Data
[2011/04/01 14:48:01 | 000,000,000 | —D | C] – C:\Documents and Settings
[2011/04/01 14:48:00 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2011/04/01 14:44:06 | 000,000,000 | –SD | C] – C:\WINDOWS\Downloaded Program Files
[2011/04/01 14:44:06 | 000,000,000 | R-SD | C] – C:\WINDOWS\Fonts
[2011/04/01 14:44:06 | 000,000,000 | R–D | C] – C:\WINDOWS\Web
[2011/04/01 14:44:06 | 000,000,000 | R–D | C] – C:\WINDOWS\Offline Web Pages
[2011/04/01 14:44:06 | 000,000,000 | -HSD | C] – C:\WINDOWS\Installer
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\WinSxS
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wins
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\WBEM
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\wbem
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\usmt
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\UMDF
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\twain_32
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Temp
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\system32
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\system
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\spool
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\SoftwareDistribution
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ShellExt
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\Setup
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\security
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\scripting
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Resources
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\repair
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ras
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Provisioning
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\PeerNet
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\pchealth
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\npp
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Network Diagnostic
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\mui
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\mui
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\msapps
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Microsoft.NET
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Media
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\L2Schemas
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\java
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\inf
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\IME
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\ime
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\ias
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Help
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\export
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\etc
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en-US
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\en
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRM
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Driver Cache
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\drivers\disdn
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\dhcp
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Debug
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Cursors
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Connection Wizard
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\config
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\Config
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\AppPatch
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\addins
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3com_dmi
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\3076
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\2052
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1054
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1042
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1041
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1037
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1033
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1031
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1028
[2011/04/01 14:44:06 | 000,000,000 | —D | C] – C:\WINDOWS\System32\1025
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/05/01 08:46:52 | 075,376,526 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/04/30 19:17:25 | 000,390,116 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/04/30 19:17:24 | 000,057,530 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/04/30 19:13:52 | 000,024,944 | —- | M] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011/04/30 19:13:52 | 000,000,004 | —- | M] () – C:\WINDOWS\System32\GVTunner.ref
[2011/04/30 19:13:49 | 000,002,228 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/04/30 19:13:44 | 000,000,006 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME{481BF629-5360-4445-89A2-F9214E3B2B38}
[2011/04/30 19:13:09 | 000,016,608 | —- | M] (Windows ® 2000 DDK provider) – C:\WINDOWS\gdrv.sys
[2011/04/30 19:12:47 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/04/30 19:12:46 | 000,178,544 | —- | M] () – C:\WINDOWS\System32\ativvaxx.cap
[2011/04/29 18:03:06 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/04/29 18:02:55 | 000,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\Owner\Desktop\ATF-Cleaner.exe
[2011/04/29 09:42:19 | 000,045,115 | —- | M] (Alpha Networks Inc.) – C:\WINDOWS\System32\ANICtl.dll
[2011/04/29 04:52:40 | 000,187,904 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/17 14:12:58 | 000,453,632 | —- | M] () – C:\Documents and Settings\Owner\Desktop\CKScanner.exe
[2011/04/17 01:24:25 | 000,111,784 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/16 03:56:49 | 000,000,069 | —- | M] () – C:\WINDOWS\NeroDigital.ini
[2011/04/08 14:03:24 | 000,359,929 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2011/04/07 00:29:34 | 000,001,754 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
[2011/04/06 23:01:27 | 000,000,376 | —- | M] () – C:\WINDOWS\ODBC.INI
[2011/04/06 23:01:09 | 000,001,730 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/04/04 15:40:49 | 000,243,024 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgtdix.sys
[2011/04/04 15:40:48 | 000,029,584 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgmfx86.sys
[2011/04/04 15:40:48 | 000,012,536 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\avgrsstx.dll
[2011/04/04 15:40:40 | 000,216,400 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\WINDOWS\System32\drivers\avgldx86.sys
[2011/04/04 15:40:39 | 000,142,495 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2011/04/04 15:33:13 | 000,113,461 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2011/04/04 15:33:11 | 006,061,540 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2011/04/04 15:33:11 | 000,492,629 | —- | M] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2011/04/02 01:16:39 | 000,000,560 | —- | M] () – C:\Documents and Settings\All Users\Documents\Global.sw
[2011/04/01 15:23:04 | 000,004,444 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/04/29 04:23:08 | 000,001,804 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Adobe Reader 9.lnk
[2011/04/17 14:12:51 | 000,453,632 | —- | C] () – C:\Documents and Settings\Owner\Desktop\CKScanner.exe
[2011/04/08 14:03:22 | 000,359,929 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.scr
[2011/04/07 00:29:34 | 000,001,754 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Snagit 9.lnk
[2011/04/06 23:01:27 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2011/04/06 23:01:09 | 000,002,489 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Word.lnk
[2011/04/06 23:01:09 | 000,002,487 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft Excel.lnk
[2011/04/06 23:01:09 | 000,002,002 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Microsoft PowerPoint.lnk
[2011/04/06 23:01:09 | 000,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2011/04/06 22:59:06 | 000,000,740 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Acrobat.com.lnk
[2011/04/04 15:33:13 | 000,113,461 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\iavichjw.avm
[2011/04/04 15:33:11 | 075,376,526 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\incavi.avm
[2011/04/04 15:33:11 | 006,061,540 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\avi7.avg
[2011/04/04 15:33:11 | 000,492,629 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\miniavi.avg
[2011/04/04 15:33:11 | 000,142,495 | —- | C] () – C:\WINDOWS\System32\drivers\Avg\microavi.avg
[2011/04/02 05:03:40 | 000,000,069 | —- | C] () – C:\WINDOWS\NeroDigital.ini
[2011/04/02 01:17:04 | 000,001,511 | —- | C] () – C:\Documents and Settings\Owner\Start Menu\Programs\Shortcut to Ulead GIF Animator 5.05 TBYB Softwrap - Patch by Bidjan.lnk
[2011/04/01 16:09:55 | 000,178,176 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2011/04/01 16:09:55 | 000,000,038 | —- | C] () – C:\WINDOWS\avisplitter.ini
[2011/04/01 16:09:54 | 000,000,414 | —- | C] () – C:\WINDOWS\System32\lame_acm.xml
[2011/04/01 16:09:53 | 003,596,288 | —- | C] () – C:\WINDOWS\System32\qt-dx331.dll
[2011/04/01 16:09:53 | 002,378,752 | —- | C] () – C:\WINDOWS\System32\x264vfw.dll
[2011/04/01 16:09:53 | 000,881,664 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2011/04/01 16:09:53 | 000,205,824 | —- | C] () – C:\WINDOWS\System32\xvidvfw.dll
[2011/04/01 16:09:51 | 000,085,504 | —- | C] () – C:\WINDOWS\System32\ff_vfw.dll
[2011/04/01 15:46:42 | 000,000,560 | —- | C] () – C:\Documents and Settings\All Users\Documents\Global.sw
[2011/04/01 15:23:04 | 000,004,444 | —- | C] () – C:\WINDOWS\System32\pid.PNF
[2011/04/01 14:51:09 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2011/04/01 14:50:56 | 000,001,688 | —- | C] () – C:\WINDOWS\System32\AUTOEXEC.NT
[2011/04/01 14:48:00 | 000,111,784 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2011/04/01 14:47:09 | 000,000,223 | RHS- | C] () – C:\boot.ini
[2011/04/01 14:47:05 | 000,000,869 | —- | C] () – C:\WINDOWS\System32\$winnt$.inf
[2011/04/01 06:24:54 | 000,187,904 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/04/01 06:10:49 | 000,245,760 | —- | C] () – C:\WINDOWS\System32\WlanApp.dll
[2011/04/01 06:10:49 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\JJAKEn.dll
[2011/04/01 06:06:11 | 000,593,920 | —- | C] () – C:\WINDOWS\System32\ati2sgag.exe
[2011/04/01 06:06:00 | 000,887,724 | R— | C] () – C:\WINDOWS\System32\ativva6x.dat
[2011/04/01 06:05:59 | 000,189,051 | R— | C] () – C:\WINDOWS\System32\atiicdxx.dat
[2011/04/01 06:05:59 | 000,000,003 | R— | C] () – C:\WINDOWS\System32\ativva5x.dat
[2011/04/01 05:59:44 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2011/04/01 05:57:23 | 000,021,640 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2011/04/01 05:56:25 | 000,162,304 | —- | C] () – C:\WINDOWS\System32\libpng13.dll
[2011/04/01 05:56:23 | 000,394,752 | —- | C] () – C:\WINDOWS\System32\cygwinb19.dll
[2011/04/01 05:56:21 | 000,059,904 | —- | C] () – C:\WINDOWS\System32\zlib1.dll
[2011/04/01 05:34:27 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2011/04/01 05:30:12 | 000,024,944 | —- | C] () – C:\WINDOWS\System32\drivers\GVTDrv.sys
[2011/04/01 05:19:38 | 000,000,000 | —- | C] () – C:\WINDOWS\ativpsrm.bin
[2009/02/19 03:25:20 | 000,294,912 | —- | C] () – C:\WINDOWS\System32\ATIODE.exe
[2009/02/04 06:22:02 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ATIODCLI.exe
[2008/04/14 19:30:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2008/04/14 19:30:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2008/04/14 19:30:00 | 000,390,116 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2008/04/14 19:30:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2008/04/14 19:30:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2008/04/14 19:30:00 | 000,057,530 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2008/04/14 19:30:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2008/04/14 19:30:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2008/04/14 19:30:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2008/04/14 19:30:00 | 000,004,463 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2008/04/14 19:30:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\Dcache.bin

========== LOP Check ==========

[2011/04/04 15:33:00 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\avg9
[2011/04/05 08:14:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Common Files
[2011/04/02 01:57:10 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MediaMonkey
[2011/04/04 15:30:39 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\MFAData
[2011/04/07 00:29:28 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TechSmith
[2011/04/01 06:24:06 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Ulead Systems
[2011/04/04 16:25:49 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\avidemux
[2011/04/01 06:24:07 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Ulead Systems
[2011/04/17 01:25:29 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\uTorrent

========== Purity Check ==========



< End of report >
And here's extras.txt:

OTL Extras logfile created on: 5/1/2011 11:35:06 AM - Run 1
OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 76.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 85.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 62.39 Gb Free Space | 83.72% Space Free | Partition Type: NTFS
Drive D: | 74.53 Gb Total Space | 46.11 Gb Free Space | 61.88% Space Free | Partition Type: NTFS
Drive E: | 931.51 Gb Total Space | 468.63 Gb Free Space | 50.31% Space Free | Partition Type: NTFS
Drive F: | 931.51 Gb Total Space | 620.46 Gb Free Space | 66.61% Space Free | Partition Type: NTFS

Computer Name: BRIAN-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.url [@ = InternetShortcut] – rundll32.exe ieframe.dll,OpenURL %l

[HKEY_USERS\S-1-5-21-1757981266-113007714-1801674531-1003\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
InternetShortcut [open] – rundll32.exe ieframe.dll,OpenURL %l
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe" = C:\Program Files\Gigabyte\GBTUpd\RunUpd.exe:*:Enabled:RunUpd – (Gigabyte)
"C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\AVG\AVG9\avgemc.exe" = C:\Program Files\AVG\AVG9\avgemc.exe:*:Enabled:avgemc.exe – (AVG Technologies CZ, s.r.o.)
"C:\Program Files\uTorrent\uTorrent.exe" = C:\Program Files\uTorrent\uTorrent.exe:*:Enabled:µTorrent


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00203668-8170-44A0-BE44-B632FA4D780F}" = Adobe AIR
"{07300F01-89CA-4CF8-92BD-2A605EB83C95}" = EasySaver B9.0205.1
"{0E6ED660-498C-42F7-9EF4-FB0C96DFC01A}" = Snagit 9.1
"{1A2A15C2-6780-49c1-B296-503230E9DE00}" = The Sims™ 2 Mansion and Garden Stuff
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{32477761-57AE-4D26-A493-9AA1658B6615}" = ATI AVIVO Codecs
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3EE1008C-11A1-4F4F-8DB7-27573924DE78}" = DMIView B8.0717.01
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B09.0216.1
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B08.1027.1
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.5.1
"{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0
"{77DCDCE3-2DED-62F3-8154-05E745472D07}" = Acrobat.com
"{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8AF3E926-ED59-11D4-A44B-0000E86D2305}" = Ulead GIF Animator 5 TBYB
"{8BCD7AE7-F713-4D50-BAB9-7839B9386870}" = ImageShack Uploader 2.2.0
"{8FD3F4BA-A4A6-4380-00A6-CC6853AB2DC2}" = The Sims 2 University
"{90280409-6000-11D3-8CFE-0050048383C9}" = Microsoft Office XP Professional with FrontPage
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{AC76BA86-7AD7-1033-7B44-A92000000001}" = Adobe Reader 9.2
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B2DC3F08-2EB2-49A5-AA24-15DFC8B1CB83}" = @BIOS Ver.2.05
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BADEDF59-389D-49CA-AD06-7EF12C5C13CD}" = D-Link Wireless G DWA-510
"{BDCF27CA-BFC4-4F49-8D24-A925C9505AB8}" = Windows Rights Management Client with Service Pack 2
"{C151CE54-E7EA-4804-854B-F515368B0798}" = AMD Processor Driver
"{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{E76FCE6B-9999-4250-8C75-B2DA4AD41268}" = Face_Wizard B08.0908.01
"{E8AEA11B-E60A-455E-B008-E4E763604612}" = Browser Configuration Utility
"{EC905264-BCFE-423B-9C42-C3A106266790}" = Windows Rights Management Client Backwards Compatibility SP2
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"All ATI Software" = ATI - Software Uninstall Utility
"ATI Display Driver" = ATI Display Driver
"AVG9Uninstall" = AVG Free 9.0
"Avidemux 2.5" = Avidemux 2.5
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"ExtractNow_is1" = ExtractNow
"InstallShield_{457D7505-D665-4F95-91C3-ECB8C56E9ACA}" = Easy Tune 6 B09.0216.1
"InstallShield_{4E25C468-7745-4051-8B37-4A2C6635BA8B}" = Update Manager B08.1027.1
"KLiteCodecPack_is1" = K-Lite Mega Codec Pack 5.5.1
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"MediaMonkey_is1" = MediaMonkey 3.0
"Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0
"Microsoft Silverlight" = Microsoft Silverlight
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Nero - Burning Rom!UninstallKey" = Nero 6 Enterprise Edition
"VLC media player" = VLC media player 0.9.4
"Wdf01005" = Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
"Windows Rights Management Client" = Windows Rights Management Client with Service Pack 2
"Windows Rights Management Client Backwards" = Windows Rights Management Client Backwards Compatibility SP2
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver

========== Last 10 Event Log Errors ==========

[ System Events ]
Error - 4/8/2011 2:30:28 AM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/12/2011 10:39:57 PM | Computer Name = BRIAN-PC | Source = Ntfs | ID = 262199
Description = The file system structure on the disk is corrupt and unusable. Please
run the chkdsk utility on the volume E:.

Error - 4/13/2011 2:45:47 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:45:50 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:45:53 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:45:56 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:45:59 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:46:03 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 2:46:06 PM | Computer Name = BRIAN-PC | Source = Disk | ID = 262151
Description = The device, \Device\Harddisk0\D, has a bad block.

Error - 4/13/2011 9:32:42 PM | Computer Name = BRIAN-PC | Source = Dhcp | ID = 1000
Description = Your computer has lost the lease to its IP address 192.168.1.3 on
the Network Card with network address 002401A6C3B4.


< End of report >
Hi,

Lets run this scan

Download CKScanner
  • Important - Save it to your desktop.
  • Doubleclick CKScanner.exe and click Search For Files.
  • After a very short time, when the cursor hourglass disappears, click Save List To File.
  • A message box will verify the file saved.
  • Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
CKScanner - Additional Security Risks - These are not necessarily bad scanner sequence 3.RP.11 —– EOF —– That was it. Also, I haven't had any warnings about the trojan from AVG in a while.
Hi,

Lets check a bit further

Please download ATF Cleaner by Atribune to your desktop.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
Your system may start up slower after running ATF Cleaner, this is expected but will be back to normal after the first or second boot up
Please note: If you use online banking or are registered online with any other organizations, ensure you have memorized password and other personal information as removing cookies will temporarily disable the auto-login facility.




Please download Malwarebytes from Here or Here

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please
Hey! I'll do this in about 3 days - I'm not staying at home at the moment so I don't have access to my PC. I'll keep you posted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI