This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Unable to upload HiJackThis log due to very invasive spyware...

20 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello. I tried to upload a HJackThis log a short time ago and when I hit the post button it promptly redirected me to a page with a download link to the newest version. I currently have version 1.99 and I think the latest is 2.08. It did not create the thread. I am not happy about this at all because my PC (Windows XP) has been infected with a very insidious and nasty piece of spyware which almost totally paralyzes the PC. I am typing this in safe mode now because I cannot start a browsing session when the computer boots normally. Therefore, I had to download the installer for the new version of HiJackThis in safe mode. I tried to run the installer in safe mode, but it would not work. I booted the computer in normal mode and I was able to browse using windows explorer and run the installer. But for some reason there was no option to upgrade; it only allowed me to repair or uninstall. I clicked repair and it said that it worked. I ran HiJackThis again but the logfile still said version 1.99. I re-booted again and this spyware has gotten even more insidious. Now, even in safe mode I can browse to C:\Hijack, which is where the HiJackThis log is located, but it does not show any files at all. The same thing happens when I navigate to C:\Documents and Settings. It shows no files at all. I want to try and re-run the installer which is located in C:\Documents and Settings\Downloads, but I cannot see the file even though I know it's there. I tried to upload the v1.99 HiJackThis file but of course Windows Explorer doesn't show any files in those directories. For some odd reason it does allow me to see everything in C:\Program Files. In fact, that is how I am typing this. I had to run Firefox from C:\Program Files\Mozilla Firefox. I am not sure what to do here because I can't upload any files and you guys won't let me post a HiJackThis log from an older version. I have to say that really ticks me off. I doubt the version of HiJackThis will prevent you guys from diagnosing this issue, but you have insisted upon not creating my thread because I don't have the latest. Now, I can't even re-run the installer or upload the file. I can't copy and paste the text because I can't navigate to the log file. Every time a Windows file open/upload dialog box opens it does not show anything in HiJack or My Documents. I don't know how I am going to be able to get you guys what you need. There are two extra program groups listed in the list of programs, one is called Data Restore and the other is something about a cloud. I think it's called AV cloud. It starts up at boot time and prevents me from running anything. It says that it needs to perform a scan and in true spyware fashion it will not stop no matter what you do, and some of the windows it shows do not allow themselves to be minimized or closed. This thing is a real pain! I do have a version of MalWare Bytes on this thing and I am going to let it run in safe mode because this is the only way that the PC will allow anything to work. What else can I do to get rid of this??
Hi CMD4649,

To make cleaning this machine easier
  • Please do not uninstall/install any programs unless asked to
    It is more difficult when files/programs are appearing in/disappearing from the logs.
  • Please do not run any scans other than those requested
  • Please follow all instructions in the order posted
  • All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
  • Do not attach any logs/reports, etc.. unless specifically requested to do so.
  • If you have problems with or do not understand the instructions, Please ask before continuing.
  • Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.

We'll get a better look with this tool.

Download OTL to your desktop.
  • If you are using Firefox, make sure that your download settings are as follows:
    -Tools->Options->Main tab
    -Set to "Always ask me where to Save the files".
  • Double click on OTL.exe to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.


Next

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Please post back with
  • both OTL logs
  • aswMBR log
  • MBR.zip (attached)
Hello and thanks for your reply. I will try this later on tonight when I get home. I have to do everything in safe mode, but I can run Firefox. Since this malware won't let me browse the My Documents directory along with some others, I will have to find a place to download the files to so that I can browse them. This computer has a second drive which is drive D, however it won't let me browse that either. I'll try doing this later on and see what happens. I have malware bytes removal on the PC and I ran that last night and it found 4 bits of malware that I have removed. The problem still persists, however.
Hi CMD4649, If you can access C:\program files you can download and run them from there. Put them in their own folder. The logs should then be saved in those folders.
Hi. I did not have a chance to work on the computer last night; I was too busy watching the Yankees beat up on Detroit 10-1. Go Yanks! I will try the recommendations tonight, so please keep this thread open. Thanks!
Ok. Here is the OTL.Text file:

OTL logfile created on: 10/5/2011 10:19:24 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Program Files\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.48 Mb Total Physical Memory | 351.74 Mb Available Physical Memory | 68.77% Memory free
1.22 Gb Paging File | 1.15 Gb Available in Paging File | 93.87% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 28.63 Gb Total Space | 10.48 Gb Free Space | 36.60% Space Free | Partition Type: NTFS
Drive D: | 76.32 Gb Total Space | 3.75 Gb Free Space | 4.91% Space Free | Partition Type: NTFS

Computer Name: CDHOME | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Program Files\OTL\OTL.exe (OldTimer Tools)
PRC - C:\WINNT\explorer.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========


========== Win32 Services (SafeList) ==========

SRV - (wuauserv) – File not found
SRV - (HidServ) – File not found
SRV - (Bandoo Coordinator) – File not found
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (UtilMan) – C:\WINNT\system32\utilman.exe (Microsoft Corporation)
SRV - (W3SVC) – C:\WINNT\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (IISADMIN) – C:\WINNT\system32\inetsrv\inetinfo.exe (Microsoft Corporation)
SRV - (p2pgasvc) – C:\WINNT\system32\p2pgasvc.dll (Microsoft Corporation)
SRV - (LVSrvLauncher) – C:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exe (Logitech Inc.)
SRV - (LVPrcSrv) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe ()
SRV - (LVCOMSer) – C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exe (Logitech Inc.)
SRV - (ewido security suite control) – C:\Program Files\ewido anti-malware\ewidoctrl.exe (ewido networks)
SRV - (GEARSecurity) – C:\WINNT\system32\gearsec.exe (GEAR Software)
SRV - (CVPND) – C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (MSSQLServerOLAPService) – C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV - (Tcpip6) – C:\WINNT\system32\drivers\tcpip6.sys (Microsoft Corporation)
DRV - (cmpbcgpaxe_pj) – C:\Program Files\Common Files\System\cmpbcgpaxe_pj32.dll ()
DRV - (i8042prt) – C:\WINNT\system32\drivers\i8042prt.sys ()
DRV - (MPE) – C:\WINNT\system32\drivers\mpe.sys (Microsoft Corporation)
DRV - (RTL8023xp) – C:\WINNT\system32\drivers\Rtnicxp.sys (Realtek Semiconductor Corporation )
DRV - (LVcKap) – C:\WINNT\system32\drivers\Lvckap.sys (Logitech Inc.)
DRV - (LVUSBSta) – C:\WINNT\system32\drivers\LVUSBSta.sys (Logitech Inc.)
DRV - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\WINNT\system32\drivers\LV302V32.SYS (Logitech Inc.)
DRV - (pepifilter) – C:\WINNT\system32\drivers\lv302af.sys (Logitech Inc.)
DRV - (LVPr2Mon) – C:\WINNT\system32\drivers\LVPr2Mon.sys ()
DRV - (LVMVDrv) – C:\WINNT\system32\drivers\LVMVdrv.sys (Logitech Inc.)
DRV - (MxlW2k) – C:\WINNT\System32\drivers\MxlW2k.sys (MusicMatch, Inc.)
DRV - (rtl8139) Realtek RTL8139(A/B/C) – C:\WINNT\system32\drivers\rtl8139.sys (Realtek Semiconductor Corporation)
DRV - (itchfltr) – C:\WINNT\system32\drivers\itchfltr.sys (Logitech, Inc.)
DRV - (RTL8023) – C:\WINNT\system32\drivers\Rtlnic51.sys (Realtek Semiconductor Corporation )
DRV - (lmouflt2) – C:\WINNT\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (l8042pr2) – C:\WINNT\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (TwEECer) – C:\WINNT\system32\drivers\FTD2XX.sys (FTDI Ltd.)
DRV - (Cdr4_2K) – C:\WINNT\System32\drivers\cdr4_2K.sys (Roxio)
DRV - (Cdralw2k) – C:\WINNT\System32\drivers\cdralw2k.sys (Roxio)
DRV - (RapNet) – C:\WINNT\system32\drivers\RapNet.sys (Internet Security Systems, Inc.)
DRV - (RapFile) – C:\WINNT\system32\drivers\RapFile.sys (Internet Security Systems, Inc.)
DRV - (BsUDF) – C:\WINNT\System32\drivers\bsudf.sys (ahead software)
DRV - (incdrm) – C:\WINNT\System32\drivers\incdrm.sys (Ahead Software AG)
DRV - (CVPNDRV) – C:\WINNT\system32\drivers\CVPNDrv.sys (Cisco Systems, Inc.)
DRV - (ALCXWDM) Service for Avance AC97 Audio (WDM) – C:\WINNT\system32\drivers\ALCXWDM.SYS (Avance Logic, Inc.)
DRV - (vsdatant) – C:\WINNT\system32\vsdatant.sys (Zone Labs Inc.)
DRV - (WBHWDOCT) – C:\WINNT\System32\drivers\Wbhwdoct.sys (Winbond Electronics Corp.)
DRV - (ac97intc) Intel® 82801DB/DBM Audio Driver Service (WDM) – C:\WINNT\system32\drivers\ac97ich4.sys (Intel Corporation)
DRV - (DNE) – C:\WINNT\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (usbhub20) – C:\WINNT\system32\drivers\usbhub20.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultName = Yahoo! Search
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTe…-8&fr=b1ie7
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {81017EA9-9AA8-4A6A-9734-7AF40E7D593F} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\YTNavAssist.dll (Yahoo! Inc.)
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\yt.dll (Yahoo! Inc.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.yahoo.com/search?fr=ffsp1&p="
FF - prefs.js..browser.search.order.1: "Web Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Web Search"
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "http://www.yahoo.com/"
FF - prefs.js..extensions.enabledItems: [removed]:1.0
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0.%(version)s
FF - prefs.js..extensions.enabledItems: [removed]:1.0.14908
FF - prefs.js..extensions.enabledItems: {635abd67-4fe9-1b23-4f01-e679fa7484c1}:1.6.6.20090220
FF - prefs.js..extensions.enabledItems: [removed]:1.3.4
FF - prefs.js..keyword.URL: "http://www.searchqu.com/web?src=ffb&q="


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINNT\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.1: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8117.0416: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.1864: C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=1.0.2.1924: C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.857: C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@movenetworks.com/Quantum Media Player: C:\Documents and Settings\Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll (Move Networks)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@yahoo.com/BrowserPlus,version=2.9.2: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/04/07 21:57:06 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 4.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/07/01 10:50:57 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[removed]: C:\Documents and Settings\Administrator\Application Data\Move Networks [2010/01/18 00:01:13 | 000,000,000 | -H-D | M]

[2008/09/14 11:03:45 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2011/10/05 22:06:57 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions
[2007/10/19 06:58:09 | 000,000,000 | -H-D | M] ("NASA Normal") – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{00df3690-c341-11da-a94d-0800200c9a66}
[2007/10/19 06:58:09 | 000,000,000 | -H-D | M] ("Azerty I") – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{0441798B-805D-4f2d-9321-F3FCC8171127}
[2007/10/19 06:58:09 | 000,000,000 | -H-D | M] ("Mostly Crystal") – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{0cdfdd5e-eea6-45ff-b035-81243cf02efb}
[2009/09/04 00:01:54 | 000,000,000 | -H-D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2008/02/09 16:49:10 | 000,000,000 | -H-D | M] (Orbit_Grey) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{257b4b90-a3e0-11da-a746-0800200c9a66}
[2006/08/19 22:30:52 | 000,000,000 | -H-D | M] (RedShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{2795f860-8d9e-11da-a72b-0800200c9a66}
[2008/02/09 16:56:45 | 000,000,000 | -H-D | M] (Cobalt Firefox) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{28f708c0-ac24-11db-abbd-0800200c9a66}
[2006/08/19 22:28:32 | 000,000,000 | -H-D | M] (Silver Skin) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{2A10B180-05EF-11D9-8C50-444553540001}
[2008/09/14 11:04:14 | 000,000,000 | -H-D | M] (Abstract Classic) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{2fbc1200-ad13-11db-abbd-0800200c9a66}
[2007/10/19 06:58:09 | 000,000,000 | -H-D | M] ("Adblock") – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{34274bf4-1d97-a289-e984-17e546307e4f}
[2008/02/09 16:57:47 | 000,000,000 | -H-D | M] (Tangerine) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{44851133-3425-48cc-a957-5a29b9396a5f}
[2008/09/14 11:04:15 | 000,000,000 | -H-D | M] (Acid Burn) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{47d1d620-5e5b-11da-8cd6-0800200c9a66}
[2008/09/14 11:04:17 | 000,000,000 | -H-D | M] (Modern Modoki) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{4a428302-5267-4749-bb22-459b3236695f}
[2006/08/19 22:55:52 | 000,000,000 | -H-D | M] (Mozilla.org) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{55041010-54F1-412e-8177-2E411719162D}
[2011/08/02 23:25:51 | 000,000,000 | -H-D | M] (Yahoo! Toolbar) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2006/08/19 22:49:49 | 000,000,000 | -H-D | M] (Aquatint) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{69087485-8EDE-4a6c-91BE-6B882EB268A5}
[2008/02/09 16:52:54 | 000,000,000 | -H-D | M] (INpact Light Orange) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{70a5ac84-0087-11dc-8314-0800200c9a66}
[2006/08/19 22:48:35 | 000,000,000 | -H-D | M] (BlackJapan) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{904524FC-3F89-11DA-8BDE-F66BAD1E3F3A}
[2011/09/20 23:44:19 | 000,000,000 | -H-D | M] (PitchDark) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{c1dffba0-628e-11d9-9669-0800200c9a66}
[2006/08/19 22:56:52 | 000,000,000 | -H-D | M] (Abstract PC) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{caad1bbc-cf5d-9b9b-3a37-a1061684b0a7}
[2007/10/19 06:58:09 | 000,000,000 | -H-D | M] ("Outlook 2003 Blue") – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{e8cba685-830c-1283-6314-a6ae605cc7be}
[2006/08/19 22:34:34 | 000,000,000 | -H-D | M] (Polyesterfox) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\{f3738095-46f3-446e-8311-6637dfa3e6d5}
[2006/08/19 22:39:53 | 000,000,000 | -H-D | M] (BlueShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/08/19 22:43:13 | 000,000,000 | -H-D | M] (EarthShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/08/19 22:42:24 | 000,000,000 | -H-D | M] (GoldShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/08/19 22:41:34 | 000,000,000 | -H-D | M] (GreenShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2008/09/14 11:04:16 | 000,000,000 | -H-D | M] (Kempelton) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/08/19 22:38:51 | 000,000,000 | -H-D | M] (OrangeShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/08/19 22:40:54 | 000,000,000 | -H-D | M] (PinkShift) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\[removed]
[2006/03/25 13:26:55 | 000,000,000 | -H-D | M] (No name found) – C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\3xangg63.default\extensions\TEMP
[2011/07/01 10:51:00 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2010/06/12 14:33:27 | 000,000,000 | —D | M] (Skype extension for Firefox) – C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1}
[2011/07/01 10:51:00 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/04/07 21:54:26 | 000,000,000 | —D | M] (The Browser Highlighter) – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2011/04/07 21:57:06 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\distribution\extensions
[2011/04/07 21:57:06 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Program Files\Mozilla Firefox\distribution\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010/01/18 00:01:13 | 000,000,000 | -H-D | M] (Move Media Player) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOVE NETWORKS
() (No name found) – C:\DOCUMENTS AND SETTINGS\ADMINISTRATOR\APPLICATION DATA\MOZILLA\FIREFOX\PROFILES\3XANGG63.DEFAULT\EXTENSIONS\{3628D7BD-FD0D-47B8-8C8B-865CEB7DD779}.XPI
[2008/12/17 23:51:19 | 000,000,000 | —D | M] (Java Quick Starter) – C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/01/01 04:00:00 | 000,135,168 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/07/17 05:00:04 | 000,423,656 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2010/01/01 04:00:00 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\WINNT\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.210.7 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U21 (Enabled) = C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.0.50917.0\npctrl.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprpjplug.dll
CHR - plugin: Windows Media Player Plug-in Dynamic Link Library (Enabled) = C:\Program Files\Windows Media Player\npdsplay.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Chrome\Application\14.0.835.187\pdf.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npdrmv2.dll
CHR - plugin: Microsoft\u00AE DRM (Enabled) = C:\Program Files\Windows Media Player\npwmsdrm.dll
CHR - plugin: Move Streaming Media Player (Enabled) = C:\Documents and Settings\Administrator\Application Data\Move Networks\plugins\npqmp071505000011.dll
CHR - plugin: Google Update (Enabled) = C:\Documents and Settings\Administrator\Local Settings\Application Data\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\PROGRA~1\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: RealJukebox NS Plugin (Enabled) = C:\Program Files\Real\RealPlayer\Netscape6\nprjplug.dll
CHR - plugin: Windows Live\u00AE Photo Gallery (Enabled) = C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\WINNT\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin

Hosts file not found
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\yt.dll (Yahoo! Inc.)
O2 - BHO: (SpywareGuardDLBLOCK.CBrowserHelper) - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C:\Program Files\SpywareGuard\dlprotect.dll ()
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {C4069E3A-68F1-403E-B40E-20066696354B} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn12\yt.dll (Yahoo! Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINNT\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [oz0c1v3n4m6W7E8234A] C:\WINNT\system32\QuSFpGQ6E8RYjVl.exe ()
O4 - HKLM..\Run: [SoundMan] C:\WINNT\SOUNDMAN.EXE (Avance Logic, Inc.)
O4 - HKLM..\Run: [zBrowser Launcher] C:\Program Files\Logitech\iTouch\iTouch.exe (Logitech Inc.)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKCU..\Run: [NvMediaCenter] C:\WINNT\System32\NVMCTRAY.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [PbOVsnXuaBESx.exe] C:\Documents and Settings\All Users\Application Data\PbOVsnXuaBESx.exe (Daniel Pistelli)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\SpywareGuard.lnk = C:\Program Files\SpywareGuard\sgmain.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: CDRAutoRun = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: SpecifyDefaultButtons = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: Btn_Search = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoBandCustomize = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskMgr = 1
O9 - Extra 'Tools' menuitem : Yahoo! Search Protection - {BBF74FB9-ABCD-4678-880A-2511DAABB5E1} - C:\Program Files\Yahoo!\Search Protection\ysp.dll (Yahoo! Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000022 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000023 - C:\WINNT\system32\pnrpnsp.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000024 - C:\WINNT\system32\pnrpnsp.dll File not found
O16 - DPF: {00000161-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/msaudio.cab (Reg Error: Key error.)
O16 - DPF: {31564D57-0000-0010-8000-00AA00389B71} http://codecs.microsoft.com/codecs/i386/wmvax.cab (Reg Error: Key error.)
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} http://a1540.g.akamai.net/7/1540/52/200305…meInstaller.exe (Reg Error: Key error.)
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} http://a1408.g.akamai.net/7/1408/9955/2003…iTunesSetup.exe (Reg Error: Key error.)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/…7901.8375810185 (Reg Error: Key error.)
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} http://us.dl1.yimg.com/download.yahoo.com/…/ymmapi_416.dll (Yahoo! MailTo)
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.123.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3C4C623C-E11C-4C53-919A-933E96F2A68B}: DhcpNameServer = 192.168.123.254
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINNT\system32\userinit.exe) -C:\WINNT\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\wzcnotif: DllName - (wzcdlg.dll) - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O28 - HKLM ShellExecuteHooks: {54D9498B-CF93-414F-8984-8CE7FDE0D391} - C:\Program Files\ewido anti-malware\shellhook.dll ()
O28 - HKLM ShellExecuteHooks: {81559C35-8464-49F7-BB0E-07A383BEF910} - C:\Program Files\SpywareGuard\spywareguard.dll ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2002/01/07 08:04:54 | 000,000,000 | -H– | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - C:\WINNT\System32\iprip.dll (Microsoft Corporation)
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: wuauserv - File not found
NetSvcs: Ip6FwHlp - File not found

CREATERESTOREPOINT
Error creating restore point.

========== Files/Folders - Created Within 30 Days ==========

[2011/10/05 22:13:08 | 000,000,000 | —D | C] – C:\Program Files\OTL
[2011/10/03 22:22:25 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Administrator\Recent
[2011/10/03 22:21:25 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\jhOS47qzvmEYOSG
[2011/10/03 22:21:23 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\CxbQRUPDHLC
[2011/10/03 22:13:40 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\C0369eyosgk
[2011/10/03 22:13:39 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\GkxFJZV0369eyos
[2011/10/03 22:05:07 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\Evb3QE8R9w
[2011/10/03 22:05:06 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\nBPyAiDoFm5W
[2011/10/03 21:29:11 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\NJLZCVN0235689w
[2011/10/03 21:29:10 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\YYrPiGdRTUIPADF
[2011/10/03 00:48:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\PriceGong
[2011/10/03 00:43:03 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Data Restore
[2011/10/03 00:40:37 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\tSFGdZjt1n6EZ
[2011/10/03 00:40:36 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\oKLXCBN124578hk
[2011/10/03 00:37:05 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Start Menu\Programs\Open Cloud AV
[2011/10/03 00:36:53 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\sISJX049rodkcQT
[2011/10/03 00:36:50 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\yushxnRI27wuahz
[2011/10/03 00:35:37 | 000,348,160 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\1kAlMiG2Kb7FzP.exe
[2011/10/03 00:35:33 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\An4m5W7ELgjCkVz
[2011/10/03 00:33:02 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Local Settings\Application Data\Babylon
[2011/10/03 00:32:48 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Babylon
[2011/10/03 00:32:39 | 000,000,000 | -H-D | C] – C:\Documents and Settings\Administrator\Application Data\Babylon
[2011/10/03 00:32:15 | 000,462,336 | -H– | C] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\PbOVsnXuaBESx.exe
[2011/09/24 18:40:39 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2011/09/18 12:31:34 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011/09/18 12:31:00 | 000,000,000 | -H-D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
[2003/10/08 11:19:11 | 002,045,096 | —- | C] (Symantec Corporation) – C:\Program Files\NAVSetup.exe
[8 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[4 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2011/10/05 22:03:28 | 000,013,096 | —- | M] () – C:\WINNT\System32\wpa.dbl
[2011/10/05 22:03:11 | 000,002,048 | –S- | M] () – C:\WINNT\bootstat.dat
[2011/10/04 00:20:52 | 000,000,065 | —- | M] () – C:\WINNT\iTouch.ini
[2011/10/03 22:22:14 | 000,001,735 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\Open Cloud AV.lnk
[2011/10/03 22:09:11 | 000,000,448 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\1kAlMiG2Kb7FzP
[2011/10/03 22:08:24 | 000,002,819 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/10/03 22:07:29 | 000,000,296 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~1kAlMiG2Kb7FzP
[2011/10/03 22:07:29 | 000,000,224 | -H– | M] () – C:\Documents and Settings\All Users\Application Data\~1kAlMiG2Kb7FzPr
[2011/10/03 22:00:28 | 000,075,776 | -H– | M] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/10/03 21:31:25 | 000,000,853 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/03 00:43:03 | 000,000,835 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\Data Restore.lnk
[2011/10/03 00:41:01 | 000,001,211 | -H– | M] () – C:\Documents and Settings\Administrator\Application Data\ldr.ini
[2011/10/03 00:37:11 | 000,001,010 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-152049171-839522115-500UA.job
[2011/10/03 00:35:37 | 000,348,160 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\1kAlMiG2Kb7FzP.exe
[2011/10/03 00:35:33 | 002,400,768 | —- | M] () – C:\WINNT\System32\QuSFpGQ6E8RYjVl.exe
[2011/10/03 00:30:27 | 000,462,336 | -H– | M] (Daniel Pistelli) – C:\Documents and Settings\All Users\Application Data\PbOVsnXuaBESx.exe
[2011/10/03 00:30:22 | 000,000,000 | —- | M] () – C:\WINNT\1430404087
[2011/10/02 22:37:00 | 000,000,958 | —- | M] () – C:\WINNT\tasks\GoogleUpdateTaskUserS-1-5-21-1757981266-152049171-839522115-500Core.job
[2011/10/02 22:00:33 | 000,054,156 | -H– | M] () – C:\WINNT\QTFont.qfn
[2011/10/02 19:59:17 | 500,208,873 | -H– | M] () – C:\Documents and Settings\Administrator\My Documents\Tara.Holiday-My.First.Sex.Teacher.wmv
[2011/10/02 00:40:24 | 000,002,344 | -H– | M] () – C:\Documents and Settings\Administrator\Desktop\Google Chrome.lnk
[2011/10/01 14:45:30 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\WINNT\System32\FlashPlayerCPLApp.cpl
[2011/09/28 00:15:05 | 000,001,409 | —- | M] () – C:\WINNT\QTFont.for
[2011/09/18 13:37:55 | 000,000,664 | —- | M] () – C:\WINNT\System32\d3d9caps.dat
[2011/09/17 00:01:44 | 000,000,038 | —- | M] () – C:\WINNT\avisplitter.INI
[8 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]
[4 C:\WINNT\System32\*.tmp files -> C:\WINNT\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2011/10/03 22:08:24 | 000,002,819 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\HiJackThis.lnk
[2011/10/03 22:07:29 | 000,000,296 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~1kAlMiG2Kb7FzP
[2011/10/03 22:07:29 | 000,000,224 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\~1kAlMiG2Kb7FzPr
[2011/10/03 21:31:25 | 000,000,853 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Data Restore.lnk
[2011/10/03 00:43:03 | 000,000,835 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\Data Restore.lnk
[2011/10/03 00:42:51 | 000,000,448 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\1kAlMiG2Kb7FzP
[2011/10/03 00:37:13 | 000,001,735 | -H– | C] () – C:\Documents and Settings\Administrator\Desktop\Open Cloud AV.lnk
[2011/10/03 00:36:55 | 000,001,211 | -H– | C] () – C:\Documents and Settings\Administrator\Application Data\ldr.ini
[2011/10/03 00:35:33 | 002,400,768 | —- | C] () – C:\WINNT\System32\QuSFpGQ6E8RYjVl.exe
[2011/10/02 18:48:27 | 500,208,873 | -H– | C] () – C:\Documents and Settings\Administrator\My Documents\Tara.Holiday-My.First.Sex.Teacher.wmv
[2011/09/28 00:15:05 | 000,054,156 | -H– | C] () – C:\WINNT\QTFont.qfn
[2011/09/28 00:15:05 | 000,001,409 | —- | C] () – C:\WINNT\QTFont.for
[2011/09/18 12:18:23 | 000,000,000 | —- | C] () – C:\WINNT\1430404087
[2011/07/31 21:31:33 | 000,000,664 | —- | C] () – C:\WINNT\System32\d3d9caps.dat
[2010/02/14 12:29:55 | 000,000,036 | -H– | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\housecall.guid.cache
[2008/06/10 23:29:47 | 000,000,038 | —- | C] () – C:\WINNT\avisplitter.INI
[2008/06/08 11:08:41 | 000,000,056 | -H– | C] () – C:\WINNT\System32\ezsidmv.dat
[2008/05/18 23:23:12 | 003,596,288 | —- | C] () – C:\WINNT\System32\qt-dx331.dll
[2008/05/18 23:23:12 | 000,282,624 | —- | C] () – C:\WINNT\System32\xvidvfw.dll
[2008/05/18 23:23:10 | 000,007,680 | —- | C] () – C:\WINNT\System32\ff_vfw.dll
[2008/05/18 23:04:41 | 000,164,352 | —- | C] () – C:\WINNT\System32\unrar.dll
[2008/05/18 23:04:40 | 001,559,040 | —- | C] () – C:\WINNT\System32\xvidcore.dll
[2008/05/16 22:34:09 | 000,000,127 | —- | C] () – C:\WINNT\System32\MRT.INI
[2008/01/05 21:07:28 | 000,000,032 | -H– | C] () – C:\Documents and Settings\All Users\Application Data\ezsid.dat
[2007/10/11 18:59:24 | 000,025,624 | —- | C] () – C:\WINNT\System32\drivers\LVPr2Mon.sys
[2007/04/01 20:50:36 | 000,059,500 | —- | C] () – C:\WINNT\System32\lvcoinst.ini
[2006/10/09 22:57:01 | 000,000,000 | —- | C] () – C:\WINNT\System32\00xstemp.exe
[2006/10/08 23:42:49 | 000,000,006 | —- | C] () – C:\WINNT\System32\tick48.bin
[2006/10/08 21:43:37 | 000,000,120 | —- | C] () – C:\WINNT\usrwiz.ini
[2006/01/31 23:20:01 | 000,036,939 | —- | C] () – C:\WINNT\System32\insrepim.exe
[2006/01/27 01:18:52 | 000,000,136 | -H– | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2006/01/27 00:23:19 | 000,000,000 | —- | C] () – C:\WINNT\frontpg.ini
[2006/01/27 00:19:49 | 000,038,576 | —- | C] () – C:\WINNT\System32\w3ctrs.ini
[2006/01/27 00:19:48 | 000,010,225 | —- | C] () – C:\WINNT\System32\axperf.ini
[2006/01/27 00:19:46 | 000,011,435 | —- | C] () – C:\WINNT\System32\infoctrs.ini
[2005/07/23 16:18:55 | 000,000,041 | —- | C] () – C:\WINNT\UltimaSerial.ini
[2005/07/23 14:44:31 | 000,000,787 | —- | C] () – C:\WINNT\CALCON.INI
[2005/03/22 22:39:21 | 000,071,749 | —- | C] () – C:\WINNT\hcextoutput.dll
[2005/03/22 22:39:21 | 000,000,823 | —- | C] () – C:\WINNT\tsc.ini
[2005/03/22 22:39:03 | 000,000,170 | —- | C] () – C:\WINNT\GetServer.ini
[2005/01/09 16:58:28 | 000,000,000 | —- | C] () – C:\WINNT\nsreg.dat
[2005/01/09 16:58:20 | 000,099,965 | —- | C] () – C:\WINNT\UninstallFirefox.exe
[2005/01/09 16:57:44 | 000,004,727 | —- | C] () – C:\WINNT\mozver.dat
[2004/09/18 14:53:39 | 000,004,569 | —- | C] () – C:\WINNT\System32\secupd.dat
[2004/02/10 00:57:03 | 000,000,578 | —- | C] () – C:\WINNT\CE130.INI
[2003/11/19 20:34:31 | 000,075,776 | -H– | C] () – C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2003/10/09 10:23:59 | 000,000,060 | —- | C] () – C:\WINNT\webica.ini
[2003/10/08 00:41:59 | 000,010,240 | —- | C] () – C:\WINNT\System32\vidx16.dll
[2003/10/08 00:41:41 | 000,000,021 | —- | C] () – C:\WINNT\CS_setup.ini
[2003/10/08 00:19:09 | 000,000,000 | —- | C] () – C:\WINNT\OpPrintServer.INI
[2003/10/07 23:46:06 | 000,363,520 | —- | C] () – C:\WINNT\System32\psisdecd.dll
[2003/10/07 23:09:06 | 000,001,804 | —- | C] () – C:\WINNT\System32\dcache.bin
[2003/10/07 22:48:50 | 000,002,048 | –S- | C] () – C:\WINNT\bootstat.dat
[2003/10/06 15:16:00 | 000,027,136 | —- | C] () – C:\WINNT\System32\nvcod.dll
[2003/08/25 21:02:03 | 000,000,085 | —- | C] () – C:\WINNT\WININIT.INI
[2002/10/04 11:17:02 | 000,122,944 | —- | C] () – C:\WINNT\System32\CSGina.dll
[2002/07/24 08:00:00 | 000,512,586 | —- | C] () – C:\WINNT\System32\perfh009.dat
[2002/07/24 08:00:00 | 000,176,400 | —- | C] () – C:\WINNT\System32\qcut.dll
[2002/07/24 08:00:00 | 000,094,376 | —- | C] () – C:\WINNT\System32\perfc009.dat
[2002/07/24 08:00:00 | 000,000,741 | —- | C] () – C:\WINNT\System32\noise.dat
[2002/07/03 11:57:48 | 000,013,203 | —- | C] () – C:\WINNT\System32\drivers\packet.sys
[2002/05/10 20:14:36 | 000,091,136 | —- | C] () – C:\WINNT\System32\mp4fil32.dll
[2002/01/08 09:05:57 | 000,000,065 | —- | C] () – C:\WINNT\iTouch.ini
[2002/01/08 09:02:31 | 000,081,920 | R— | C] () – C:\WINNT\bwUnin-6.1.4.36-8876480L.exe
[2002/01/07 09:25:45 | 000,001,137 | —- | C] () – C:\WINNT\ODBC.INI
[2002/01/07 09:13:41 | 000,000,010 | —- | C] () – C:\WINNT\System32\drivers\tmbi.sys
[2002/01/07 08:24:38 | 000,000,182 | —- | C] () – C:\WINNT\RtlRack.ini
[2002/01/07 08:18:25 | 000,045,056 | —- | C] () – C:\WINNT\System32\Wbcdflsh.dll
[2002/01/07 08:15:14 | 000,000,164 | —- | C] () – C:\WINNT\avrack.ini
[2002/01/07 08:04:11 | 000,021,952 | -H– | C] () – C:\Program Files\folder.htt
[2002/01/07 08:03:35 | 000,022,688 | —- | C] () – C:\WINNT\System32\emptyregdb.dat
[2002/01/07 02:55:20 | 000,004,073 | —- | C] () – C:\WINNT\ODBCINST.INI
[2002/01/07 02:54:50 | 000,126,112 | —- | C] () – C:\WINNT\System32\FNTCACHE.DAT
[2001/12/25 17:49:46 | 000,097,792 | —- | C] () – C:\WINNT\System32\CurveFitPlus.dll
[2001/08/23 08:00:00 | 013,107,200 | —- | C] () – C:\WINNT\System32\oembios.bin
[2001/08/23 08:00:00 | 000,673,088 | —- | C] () – C:\WINNT\System32\mlang.dat
[2001/08/23 08:00:00 | 000,272,128 | —- | C] () – C:\WINNT\System32\perfi009.dat
[2001/08/23 08:00:00 | 000,218,003 | —- | C] () – C:\WINNT\System32\dssec.dat
[2001/08/23 08:00:00 | 000,052,480 | —- | C] () – C:\WINNT\System32\drivers\i8042prt.sys
[2001/08/23 08:00:00 | 000,046,258 | —- | C] () – C:\WINNT\System32\mib.bin
[2001/08/23 08:00:00 | 000,028,626 | —- | C] () – C:\WINNT\System32\perfd009.dat
[2001/08/23 08:00:00 | 000,004,461 | —- | C] () – C:\WINNT\System32\oembios.dat
[1999/09/25 06:36:24 | 000,088,816 | —- | C] () – C:\WINNT\System32\drivers\lvcam.sys
[1999/09/25 06:36:22 | 000,017,424 | —- | C] () – C:\WINNT\System32\drivers\lvsound.sys
[1999/07/23 14:46:48 | 000,000,116 | —- | C] () – C:\WINNT\AuHCcup1.ini
[1999/07/23 11:53:20 | 000,129,536 | —- | C] () – C:\WINNT\AuHCcup1.dll
[1999/01/22 18:46:58 | 000,065,536 | —- | C] () – C:\WINNT\System32\MSRTEDIT.DLL

========== LOP Check ==========

[2011/10/03 00:35:33 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\An4m5W7ELgjCkVz
[2011/10/03 00:32:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\Babylon
[2011/10/03 22:13:40 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\C0369eyosgk
[2011/10/03 22:21:23 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\CxbQRUPDHLC
[2011/10/03 22:05:07 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\Evb3QE8R9w
[2011/10/03 22:13:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\GkxFJZV0369eyos
[2003/10/09 11:05:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\ICAClient
[2011/10/03 22:21:25 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\jhOS47qzvmEYOSG
[2003/06/29 15:37:26 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\Kontiki
[2011/10/03 22:05:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\nBPyAiDoFm5W
[2011/10/03 21:29:11 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\NJLZCVN0235689w
[2011/01/02 12:35:21 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\Notepad++
[2011/10/03 00:40:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\oKLXCBN124578hk
[2011/10/03 00:48:34 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\PriceGong
[2011/02/21 12:09:00 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\RegistryKeys
[2011/10/03 00:36:53 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\sISJX049rodkcQT
[2011/10/03 00:40:37 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\tSFGdZjt1n6EZ
[2011/10/03 00:36:50 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\yushxnRI27wuahz
[2011/10/03 21:29:10 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\Application Data\YYrPiGdRTUIPADF
[2011/10/03 00:32:48 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\Babylon
[2006/12/30 14:58:51 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\MANSION
[2008/07/19 11:49:12 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\SweetIM

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2002/01/07 08:04:54 | 000,000,000 | -H– | M] () – C:\AUTOEXEC.BAT
[2010/08/29 15:22:02 | 000,000,277 | RHS- | M] () – C:\boot.ini
[2004/08/03 23:00:00 | 000,260,272 | —- | M] () – C:\cmldr
[2010/08/29 15:53:18 | 000,014,774 | —- | M] () – C:\ComboFix.txt
[2003/10/09 10:23:59 | 000,000,000 | —- | M] () – C:\COMLOG.txt
[2002/01/07 08:04:54 | 000,000,000 | -H– | M] () – C:\CONFIG.SYS
[2007/04/01 20:37:17 | 000,000,189 | —- | M] () – C:\CtDrvIns.log
[2002/01/07 08:04:54 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2004/12/08 09:34:20 | 000,000,000 | —- | M] () – C:\itouch_crash_info.txt
[2002/01/07 08:04:54 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2004/09/18 15:15:17 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/08/21 23:40:46 | 000,250,048 | RHS- | M] () – C:\ntldr
[2009/04/29 21:05:06 | 000,262,144 | —- | M] () – C:\ntuser.dat
[2009/04/29 21:05:06 | 000,001,024 | -H– | M] () – C:\ntuser.dat.LOG
[2011/10/05 22:03:03 | 805,306,368 | -HS- | M] () – C:\pagefile.sys
[2006/07/02 12:25:44 | 000,013,030 | —- | M] () – C:\PDOXUSRS.NET
[2007/02/11 19:06:31 | 000,001,118 | —- | M] () – C:\rapport.txt
[2008/12/29 23:07:19 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/12/31 21:58:25 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2009/01/01 03:51:56 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2009/01/02 21:49:39 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2009/01/03 13:26:28 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2009/01/10 14:53:23 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2009/01/10 15:02:08 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2009/01/11 00:34:51 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2009/01/18 14:18:57 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2009/01/24 14:54:03 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2009/02/11 07:47:48 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2009/02/14 22:27:09 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2009/02/21 18:54:19 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2009/03/09 23:24:30 | 000,000,268 | -H– | M] () – C:\sqmdata13.sqm
[2009/03/14 11:37:13 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2008/12/06 04:28:35 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2008/12/06 12:58:17 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2008/12/14 01:52:13 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2008/12/14 22:20:11 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2008/12/21 19:38:56 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2008/12/29 23:07:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2008/12/31 21:58:22 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2009/01/01 03:51:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2009/01/02 21:49:39 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2009/01/03 13:26:24 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2009/01/10 14:53:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2009/01/10 15:02:07 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2009/01/11 00:34:51 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2009/01/18 14:18:57 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2009/01/24 14:54:02 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2009/02/11 07:47:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2009/02/14 22:27:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2009/02/21 18:54:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2009/03/09 23:24:30 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2009/03/14 11:37:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2008/12/06 04:28:34 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2008/12/06 12:58:15 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2008/12/14 01:52:12 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2008/12/14 22:20:11 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2008/12/21 19:38:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2008/02/10 22:45:23 | 000,000,146 | —- | M] () – C:\YServer.txt

< %systemroot%\Fonts\*.com >
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINNT\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINNT\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINNT\Fonts\GlobalSerif.CompositeFont
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINNT\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2003/10/07 22:42:15 | 000,000,067 | -HS- | M] () – C:\WINNT\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 08:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 06:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINNT\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/04/17 01:04:40 | 000,306,032 | —- | M] (Microsoft Corporation) – C:\WINNT\WLXPGSS.SCR
[8 C:\WINNT\*.tmp files -> C:\WINNT\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2002/01/07 08:04:11 | 000,000,271 | -HS- | M] () – C:\Program Files\desktop.ini
[2002/01/07 08:04:11 | 000,021,952 | -H– | M] () – C:\Program Files\folder.htt
[2003/08/17 23:34:20 | 002,045,096 | —- | M] (Symantec Corporation) – C:\Program Files\NAVSetup.exe
[2003/08/17 21:07:00 | 000,010,457 | —- | M] () – C:\Program Files\readme.txt

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2003/10/07 18:26:16 | 000,262,144 | —- | M] () – C:\WINNT\System32\config\default.sav
[2003/10/07 19:55:21 | 000,028,672 | —- | M] () – C:\WINNT\System32\config\security.sav
[2003/10/07 18:26:16 | 014,680,064 | —- | M] () – C:\WINNT\System32\config\software.sav
[2003/10/07 18:26:17 | 003,190,784 | —- | M] () – C:\WINNT\System32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-07-14 04:18:37

< %USERPROFILE%\..|smtmp;true;true;true /FP >
[2011/10/03 00:41:36 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\..\Administrator\Local Settings\temp\smtmp
[2011/10/03 00:41:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\..\Administrator\Local Settings\temp\smtmp\1
[2011/10/03 21:30:06 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\..\Administrator\Local Settings\temp\smtmp\2
[2011/10/03 00:41:39 | 000,000,000 | -H-D | M] – C:\Documents and Settings\Administrator\..\Administrator\Local Settings\temp\smtmp\4

< %temp%\smtmp\*.* /s > >


< MD5 for: EXPLORER.BMP >
[2000/11/20 21:18:47 | 000,000,246 | —- | M] () MD5=8B1F634EB6E0918C21D5A14406919171 – C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\bitmaps\Outline\NoMask\EXPLORER.BMP
[2000/11/20 21:18:47 | 000,000,246 | —- | M] () MD5=F5FE89167CE24C072F9BEBBA5E744C2D – C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\bitmaps\Outline\RedMask\EXPLORER.BMP

< MD5 for: EXPLORER.CS >
[2001/08/27 16:39:09 | 000,008,982 | —- | M] () MD5=6F7CC5557ED5A1552A92F130B54EF1C1 – C:\Program Files\Microsoft Visual Studio .NET 2003\SDK\v1.1\Samples\Technologies\Interop\Basic\InternetExplorer\Explorer.cs
[2001/06/26 14:14:00 | 000,007,336 | —- | M] () MD5=C4309B47114B5B0826FC2515BEDF8D97 – C:\Program Files\Microsoft Visual Studio .NET 2003\SDK\v1.1\Tool Developers Guide\Samples\adepends\gui\explorer.cs

< MD5 for: EXPLORER.EXE >
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINNT\ERDNT\cache\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINNT\explorer.exe
[2008/04/13 20:12:19 | 001,033,728 | —- | M] (Microsoft Corporation) MD5=12896823FB95BFB3DC9B46BCAEDC9923 – C:\WINNT\ServicePackFiles\i386\explorer.exe
[2007/06/13 07:26:03 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 – C:\WINNT\$hf_mig$\KB938828\SP2QFE\explorer.exe
[2007/06/13 06:23:07 | 001,033,216 | —- | M] (Microsoft Corporation) MD5=97BD6515465659FF8F3B7BE375B2EA87 – C:\WINNT\$NtServicePackUninstall$\explorer.exe
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINNT\$NtUninstallKB938828$\explorer.exe
[2002/08/29 06:41:24 | 001,004,032 | —- | M] (Microsoft Corporation) MD5=A82B28BFC2E4455FE43022A498C0EF0A – C:\WINNT\$NtUninstallKB820291$\explorer.exe

< MD5 for: EXPLORER.EXE.000 >
[2004/08/04 03:56:49 | 001,032,192 | —- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 – C:\WINNT\$NtServicePackUninstall$\explorer.exe.000

< MD5 for: EXPLORER.EXE-28CE6F94.PF >
[2011/10/03 00:32:10 | 000,077,358 | —- | M] () MD5=05D44FAE27021A5F22631CFB74E3DD8B – C:\WINNT\Prefetch\EXPLORER.EXE-28CE6F94.pf

< MD5 for: EXPLORER.ICO >
[2000/11/20 21:39:46 | 000,001,078 | —- | M] () MD5=59719AC85D096BCB23980CBACAAC5A6D – C:\Program Files\Microsoft Visual Studio .NET 2003\Common7\Graphics\icons\Win95\EXPLORER.ICO

< MD5 for: EXPLORER.SCF >
[2001/08/23 08:00:00 | 000,000,080 | —- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 – C:\WINNT\explorer.scf

< MD5 for: IEXPLORE.CHM >
[2009/02/21 01:21:24 | 000,529,818 | -H– | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\bb81ad9c436fdd7cb2b4c0fd\iexplore.chm
[2009/02/21 01:21:24 | 000,529,818 | —- | M] () MD5=1435F4731719DF5F57D17DC38196245D – C:\WINNT\Help\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINNT\ie7\iexplore.chm
[2004/07/17 14:40:16 | 000,204,810 | —- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE – C:\WINNT\ServicePackFiles\i386\iexplore.chm
[2006/09/01 08:43:50 | 000,503,758 | —- | M] () MD5=652E46500C149D1DC948BF9CEA8C4933 – C:\WINNT\ie8\iexplore.chm

< MD5 for: IEXPLORE.EXE >
[2009/06/29 03:25:31 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=02E2754D3E566C11A4934825920C47DD – C:\WINNT\$hf_mig$\KB972260-IE7\SP3QFE\iexplore.exe
[2008/12/19 01:25:25 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=030D78FE84A086ED376EFCBD2D72C522 – C:\WINNT\ie7updates\KB963027-IE7\iexplore.exe
[2008/10/15 02:34:58 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=056C927CF7207857E8B34F7A8FFD9B9E – C:\WINNT\$hf_mig$\KB958215-IE7\SP2QFE\iexplore.exe
[2009/04/25 01:27:50 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=092A7F2B49A19ECCE5369D3CB2276148 – C:\WINNT\ie7updates\KB972260-IE7\iexplore.exe
[2008/12/19 01:25:30 | 000,634,024 | —- | M] (Microsoft Corporation) MD5=15E8A89499741D5CF59A9CF6463A4339 – C:\WINNT\$hf_mig$\KB961260-IE7\SP2QFE\iexplore.exe
[2008/04/22 04:02:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=197B7E4030CFBD8D2979D375E1787AA2 – C:\WINNT\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[2008/08/23 01:56:15 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=1F03216084447F990AE797317D0A6E70 – C:\WINNT\ie7updates\KB958215-IE7\iexplore.exe
[2008/04/22 03:40:18 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=232B22817B90AE0AFF2D189E3E3735AC – C:\WINNT\ie7updates\KB953838-IE7\iexplore.exe
[2007/12/06 07:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINNT\ie7updates\KB947864-IE7\iexplore.exe
[2007/12/06 07:01:25 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2703D940A62B731AA220529DD7331A78 – C:\WINNT\SoftwareDistribution\Download\e5a204b08ee9dd0f7a20547e61486b27\SP2GDR\iexplore.exe
[2008/02/29 04:55:46 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=2D0E5592AB5A46C27DAF7CCAFF4F5B59 – C:\WINNT\ie7updates\KB950759-IE7\iexplore.exe
[2009/08/27 01:18:42 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=332EC7562F3AA7364F2D4231C56DA986 – C:\WINNT\$hf_mig$\KB974455-IE7\SP3QFE\iexplore.exe
[2009/06/29 04:35:10 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=3CFC56F73D494FC1AA2B6E981DF15ACD – C:\WINNT\ie7updates\KB974455-IE7\iexplore.exe
[2009/10/28 02:54:16 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=4F9B04D546C23A295F3F0AE015BE51DB – C:\WINNT\ie7updates\KB978207-IE7\iexplore.exe
[2009/12/18 09:05:43 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=53C291F3B01EECECBD7FD358EA3ACC94 – C:\WINNT\ie7updates\KB980182-IE7\iexplore.exe
[2008/04/13 20:12:22 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=55794B97A7FAABD2910873C85274F409 – C:\WINNT\ServicePackFiles\i386\iexplore.exe
[2007/10/10 04:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINNT\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[2007/10/10 04:16:56 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=632BDE0179847234433CA50945442ACB – C:\WINNT\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2QFE\iexplore.exe
[2008/06/23 05:20:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=64E376A47763DAEABCDA14BD5B6EA286 – C:\WINNT\ie7updates\KB956390-IE7\iexplore.exe
[2008/02/22 05:40:22 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=6E0888626E0CAC79F57149814E22DB4D – C:\WINNT\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[2009/10/28 02:54:21 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=80675329E0FD54F016C4F8A83C616349 – C:\WINNT\$hf_mig$\KB976325-IE7\SP3QFE\iexplore.exe
[2007/12/06 04:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINNT\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[2007/12/06 04:34:45 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=809D17D8FA0FDAEE07778CD821CAFFDE – C:\WINNT\SoftwareDistribution\Download\e5a204b08ee9dd0f7a20547e61486b27\SP2QFE\iexplore.exe
[2008/10/15 03:06:26 | 000,633,632 | —- | M] (Microsoft Corporation) MD5=9D3DB9ADFABD2F0BC778EC03250A3ABB – C:\WINNT\ie7updates\KB961260-IE7\iexplore.exe
[2009/02/28 00:54:41 | 000,636,072 | —- | M] (Microsoft Corporation) MD5=A251068640DDB69FD7805B57D89D7FF7 – C:\WINNT\ie7updates\KB969897-IE7\iexplore.exe
[2010/04/16 07:08:29 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B24A4E23A2FEDB6976EB04D334AD82B2 – C:\WINNT\$hf_mig$\KB982381-IE7\SP3QFE\iexplore.exe
[2010/02/23 01:20:02 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=B5116340B84824DDD0A641E36B126194 – C:\WINNT\ie7updates\KB982381-IE7\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | -H– | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\bb81ad9c436fdd7cb2b4c0fd\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\Program Files\Internet Explorer\iexplore.exe
[2009/03/08 14:09:26 | 000,638,816 | —- | M] (Microsoft Corporation) MD5=B60DDDD2D63CE41CB8C487FCFBB6419E – C:\WINNT\system32\dllcache\iexplore.exe
[2009/02/28 00:54:44 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=BCD8E48709BE4A79606F0B6E8E9A6162 – C:\WINNT\$hf_mig$\KB963027-IE7\SP3QFE\iexplore.exe
[2009/04/25 01:27:39 | 000,636,088 | —- | M] (Microsoft Corporation) MD5=C0503FD8D163652735C1EE900672A75C – C:\WINNT\$hf_mig$\KB969897-IE7\SP3QFE\iexplore.exe
[2010/04/16 07:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINNT\ERDNT\cache\iexplore.exe
[2010/04/16 07:43:25 | 000,634,656 | —- | M] (Microsoft Corporation) MD5=C4BA5E36FB57F547117305BF1E0FE454 – C:\WINNT\ie8\iexplore.exe
[2008/06/23 04:23:52 | 000,625,664 | —- | M] (Microsoft Corporation) MD5=C52A9EF571E91535EB78DB4B8B95EA07 – C:\WINNT\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[2010/02/23 01:19:59 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=C8DDA4028065D5CE39CBE7A156B72AB9 – C:\WINNT\$hf_mig$\KB980182-IE7\SP3QFE\iexplore.exe
[2009/12/18 03:00:27 | 000,634,632 | —- | M] (Microsoft Corporation) MD5=D19E56D5930C37CF211867DF450C372A – C:\WINNT\$hf_mig$\KB978207-IE7\SP3QFE\iexplore.exe
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINNT\ie7updates\KB942615-IE7\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINNT\$NtServicePackUninstall$\iexplore.exe
[2004/08/04 03:56:50 | 000,093,184 | —- | M] (Microsoft Corporation) MD5=E7484514C0464642BE7B4DC2689354C8 – C:\WINNT\ie7\iexplore.exe
[2008/08/23 01:56:16 | 000,635,848 | —- | M] (Microsoft Corporation) MD5=E8305C30D35E85D6657ED3E9934CB302 – C:\WINNT\$hf_mig$\KB956390-IE7\SP2QFE\iexplore.exe
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINNT\ie7updates\KB944533-IE7\iexplore.exe
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINNT\SoftwareDistribution\Download\e3709fbfd9557a7d083f543d51d38612\SP2GDR\iexplore.exe
[2009/08/27 01:18:44 | 000,634,648 | —- | M] (Microsoft Corporation) MD5=F232BA9F39BC0F722672C7E79E68EBEA – C:\WINNT\ie7updates\KB976325-IE7\iexplore.exe

< MD5 for: IEXPLORE.EXE.000 >
[2007/08/13 18:43:56 | 000,622,080 | —- | M] (Microsoft Corporation) MD5=DE49B348A18369B4626FBA1D49B07FB4 – C:\WINNT\ie7updates\KB942615-IE7\iexplore.exe.000
[2007/10/10 06:59:52 | 000,625,152 | —- | M] (Microsoft Corporation) MD5=E854D02E4231F704D9BE782A424E6D8B – C:\WINNT\ie7updates\KB944533-IE7\iexplore.exe.000

< MD5 for: IEXPLORE.EXE.MUI >
[2009/03/08 14:21:44 | 000,012,288 | -H– | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\bb81ad9c436fdd7cb2b4c0fd\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2009/03/08 14:21:44 | 000,012,288 | —- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 – C:\Program Files\Internet Explorer\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | —- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 – C:\WINNT\ie8\iexplore.exe.mui

< MD5 for: IEXPLORE.EXE-27122324.PF >
[2011/10/03 00:33:30 | 000,097,398 | —- | M] () MD5=5E3CAC5A08E6DF39AE93E74E78B3EADE – C:\WINNT\Prefetch\IEXPLORE.EXE-27122324.pf

< MD5 for: IEXPLORE.HLP >
[2001/08/23 08:00:00 | 000,180,335 | —- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 – C:\WINNT\Help\iexplore.hlp

< MD5 for: WINLOGON.EXE >
[2004/08/04 03:56:57 | 000,502,272 | —- | M] (Microsoft Corporation) MD5=01C3346C241652F43AED8E2149881BFE – C:\WINNT\$NtServicePackUninstall$\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINNT\ERDNT\cache\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINNT\ServicePackFiles\i386\winlogon.exe
[2008/04/13 20:12:39 | 000,507,904 | —- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E – C:\WINNT\system32\winlogon.exe

< MD5 for: WINLOGON.LOG >
[2011/10/03 21:27:03 | 000,020,844 | —- | M] () MD5=495706350E1F36BF047161733CC23297 – C:\WINNT\security\logs\winlogon.log

< MD5 for: WINLOGON.OLD >
[2011/08/30 22:18:13 | 001,048,730 | —- | M] () MD5=B810860AB6A3E3FD2B1C8B73D2C28395 – C:\WINNT\security\logs\winlogon.old

========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\WINNT\$NtUninstallKB19089$] -> Error: Cannot create file handle -> Unknown point type

========== Alternate Data Streams ==========

@Alternate Data Stream - 784 bytes -> C:\WINNT\1430404087:147111338.exe

< End of report >
Here are the contents of Extras.Txt:

OTL Extras logfile created on: 10/5/2011 10:19:24 PM - Run 1
OTL by OldTimer - Version 3.2.29.1 Folder = C:\Program Files\OTL
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

511.48 Mb Total Physical Memory | 351.74 Mb Available Physical Memory | 68.77% Memory free
1.22 Gb Paging File | 1.15 Gb Available in Paging File | 93.87% Paging File free
Paging file location(s): c:\pagefile.sys 768 1536 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 28.63 Gb Total Space | 10.48 Gb Free Space | 36.60% Space Free | Partition Type: NTFS
Drive D: | 76.32 Gb Total Space | 3.75 Gb Free Space | 4.91% Space Free | Partition Type: NTFS

Computer Name: CDHOME | User Name: Administrator | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.chm [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
htmlfile – "C:\Program Files\Microsoft Office\Office\msohtmed.exe" %1 (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – %1
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"139:TCP" = 139:TCP:*:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:*:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:*:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:*:Enabled:@xpsp2res.dll,-22002

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"3587:TCP" = 3587:TCP:*:Enabled:Windows Peer-to-Peer Grouping
"3540:UDP" = 3540:UDP:*:Enabled:Peer Name Resolution Protocol (PNRP)
"139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002
"1903:UDP" = 1903:UDP:*:Enabled:Windows Media Format SDK (wmplayer.exe)
"1902:UDP" = 1902:UDP:*:Enabled:Windows Media Format SDK (wmplayer.exe)

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Real\RealPlayer\realplay.exe" = C:\Program Files\Real\RealPlayer\realplay.exe:*:Disabled:RealPlayer – (RealNetworks, Inc.)
"C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" = C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:*:Enabled:Yahoo! Messenger – (Yahoo! Inc.)
"C:\Program Files\Skype\Plugin Manager\skypePM.exe" = C:\Program Files\Skype\Plugin Manager\skypePM.exe:*:Enabled:Skype Extras Manager
"C:\WINNT\explorer.exe" = C:\WINNT\explorer.exe:*:Enabled:Windows Explorer – (Microsoft Corporation)
"C:\Program Files\Free Download Manager\fdm.exe" = C:\Program Files\Free Download Manager\fdm.exe:*:Enabled:Free Download Manager


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00000409-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Premium
"{036AA4D4-6D32-11D4-9875-00105ACE7734}" = Logitech iTouch Software
"{0D499481-22C6-4B25-8AC2-6D3F6C885FB9}" = OpenOffice.org Installer 1.0
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{17B66E83-1BC9-11D5-A54A-0090278A1BB8}" = Microsoft FrontPage Client - English
"{1A655D51-1423-48A3-B748-8F5A0BE294C8}" = Microsoft Visual J# .NET Redistributable Package 1.1
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216011FF}" = Java™ 6 Update 21
"{3039347B-F7D5-4D67-B15E-C983D0A6474F}" = Academic Student Tools 2003 - English
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3248F0A8-6813-11D6-A77B-00B0D0150070}" = J2SE Runtime Environment 5.0 Update 7
"{3248F0A8-6813-11D6-A77B-00B0D0150090}" = J2SE Runtime Environment 5.0 Update 9
"{3248F0A8-6813-11D6-A77B-00B0D0150110}" = J2SE Runtime Environment 5.0 Update 11
"{3248F0A8-6813-11D6-A77B-00B0D0160010}" = Java™ SE Runtime Environment 6 Update 1
"{3248F0A8-6813-11D6-A77B-00B0D0160020}" = Java™ 6 Update 2
"{3248F0A8-6813-11D6-A77B-00B0D0160030}" = Java™ 6 Update 3
"{3248F0A8-6813-11D6-A77B-00B0D0160050}" = Java™ 6 Update 5
"{3248F0A8-6813-11D6-A77B-00B0D0160070}" = Java™ 6 Update 7
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{35725FBC-A136-4A46-9F29-091759D9BB93}" = MVision
"{3DE5E7D4-7B88-403C-A3FD-2017A8240C5B}" = Google Earth
"{3E5562ED-69AB-4CEC-91E2-64E18EC5ACC6}" = Cisco Systems VPN Client 3.6.2 (A)
"{3FB8348A-CAF2-4B8D-B663-A0D76B26B611}" = iTunes
"{43DCF766-6838-4F9A-8C91-D92DA586DFA7}" = Microsoft Windows Journal Viewer
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EBDA59-D33B-433A-956E-B2F236468B56}" = MUSICMATCH® Jukebox
"{4677AAF8-8D7A-4EE2-BCE4-0068BB052353}" = ArcSoft Camera Suite
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{5757AE1A-1DB4-4898-9806-09F77FBD5E57}" = MSDN Library for Visual Studio .NET 2003
"{5809E7CF-4DCF-11D4-9875-00105ACE7734}" = Logitech MouseWare 9.79.1
"{5ADA9741-0570-4096-B5FE-1D55E57537D4}" = Camera Window
"{63569CE9-FA00-469C-AF5C-E5D4D93ACF91}" = Windows Genuine Advantage v1.3.0254.0
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{755D3B4E-D3A3-4D05-99D8-FC35E26A331C}" = File Viewer Utility 1.2.2
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8E5233E1-7495-44FB-8DEB-4BE906D59619}" = Junk Mail filter update
"{900B1197-53F5-4F46-A882-2CFFFE2EEDCB}" = Logitech Desktop Messenger
"{938DB54D-B302-4594-A782-32219F1734AB}" = Canon Camera WIA Driver
"{9431A631-BFCC-488F-AD74-364A943D4529}" = Microsoft WSE 1.0
"{945AC98B-3DC8-45BE-BAE0-22CEEE37A103}" = Logitech QuickCam
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{981029E0-7FC9-4CF3-AB39-6F133621921A}" = Skype Toolbars
"{a0fe116e-9a8a-466f-aee0-625cb7c207e3}" = Microsoft Visual C++ 2005 Redistributable - KB2467175
"{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI
"{A23866A0-738B-4091-9924-0B0DE3988A15}" = VP6 VFW Codec
"{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2
"{AB3AC39D-9915-435D-ACC4-9881E75326BC}" = RemoteCapture 2.7.2
"{AC76BA86-7AD7-1033-7B44-A70000000000}" = Adobe Reader 7.0.8
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{BEF726DD-4037-4214-8C6A-E625C02D2870}" = Logitech Audio Echo Cancellation Component
"{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2
"{C1600409-B5DC-42AC-9B00-0B5FBB06F7F2}" = Visual Studio .NET Academic 2003 - English
"{C1D76D7A-F3BB-47EA-A746-5B1E2FFC1DF2}" = Canon Utilities ZoomBrowser EX
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D326487D-53D5-4DEC-9578-F7A95B854BB5}" = AdwareAlert
"{D4D24FE5-FAB3-4FE2-AFFC-623955F4DF3A}" = Visual Studio.NET Baseline - English
"{D6F879CC-59D6-4D4B-AE9B-D761E48D25ED}" = Skype™ 5.3
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EA516024-D84D-41F1-814F-83175A6188F2}" = Logitech Video Enumerator
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = PhotoStitch
"{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Avance AC'97 Audio
"{FCE65C4E-B0E8-4FBD-AD16-EDCBE6CD591F}" = HighMAT Extension to Microsoft Windows XP CD Writing Wizard
"7-Zip" = 7-Zip 4.65
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Borland Database Engine [BDE]_is1" = BDE 5.5
"Championship Hearts_is1" = Championship Hearts Pro 5.14
"Citrix ICA Client" = Citrix ICA Client
"DivX Codec" = DivX Pro Codec Adware
"DivX Player" = DivX Player
"ewidoantimalware" = ewido anti-malware
"Get Yahoo! Messenger" = Get Yahoo! Messenger
"Hardware Doctor" = Hardware Doctor
"HijackThis" = HijackThis 1.99.1
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"ie8" = Windows Internet Explorer 8
"InCD!UninstallKey" = Ahead InCD
"InstallShield_{3FB8348A-CAF2-4B8D-B663-A0D76B26B611}" = iTunes
"InstallShield_{5ADA9741-0570-4096-B5FE-1D55E57537D4}" = Canon Camera Window for ZoomBrowser EX
"InstallShield_{755D3B4E-D3A3-4D05-99D8-FC35E26A331C}" = Canon Utilities File Viewer Utility 1.2
"InstallShield_{938DB54D-B302-4594-A782-32219F1734AB}" = Canon PowerShot S45 WIA Driver
"InstallShield_{AB3AC39D-9915-435D-ACC4-9881E75326BC}" = Canon Utilities RemoteCapture 2.7
"InstallShield_{F11A403B-0DE9-4953-B790-7A2F014FBB2B}" = Canon Utilities PhotoStitch 3.1
"KLiteCodecPack_is1" = K-Lite Codec Pack 3.6.2 Full
"Logitech Resource Center" = Logitech Resource Center
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft SQL Server 2000 Analysis Services" = Microsoft SQL Server 2000 Analysis Services
"Mozilla Firefox 4.0 (x86 en-US)" = Mozilla Firefox 4.0 (x86 en-US)
"MRW!UninstallKey" = Ahead InCD EasyWrite Reader
"MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP
"MSN Music Assistant" = MSN Music Assistant
"Nero - Burning Rom!UninstallKey" = Ahead Nero - Burning Rom
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"Notepad++" = Notepad++
"NVIDIA" = NVIDIA Windows 2000/XP Display Drivers
"NVIDIA Display Driver" = NVIDIA Display Driver
"Optimum Online net guide" = Optimum Online net guide
"PhotoRecord" = Canon PhotoRecord
"QcDrv" = Logitech® Camera Driver
"QuickTime" = QuickTime
"RealPlayer 6.0" = RealPlayer
"Registrar Lite 2.00" = Registrar Lite 2.00
"Spybot - Search & Destroy_is1" = Spybot - Search & Destroy 1.3
"SpywareGuard_is1" = SpywareGuard v2.2
"TwEECer" = TwEECer USB Drivers
"TwEECer/TwEECer RT [CalEdit & CalCon]_is1" = CalEdit 1.30[A9] & CalCon 1.0[A7]
"Visual Studio .NET Academic 2003 - English" = Microsoft Visual Studio .NET Academic 2003 - English
"Windows Media Format Runtime" = Windows Media Format 11 runtime
"Windows Media Player" = Windows Media Player 11
"Windows XP Service Pack" = Windows XP Service Pack 3
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WinZip" = WinZip
"WMFDist11" = Windows Media Format 11 runtime
"wmp11" = Windows Media Player 11
"Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
"Yahoo! Search Defender" = Yahoo! Search Protection
"Yahoo! Software Update" = Yahoo! Software Update

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"Move Media Player" = Move Media Player
"Yahoo! BrowserPlus" = Yahoo! BrowserPlus 2.9.2

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/3/2011 9:27:01 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65654
Description = The current configuration no longer matches the licensed configuration.
This may be caused by the expiration of an evaluation license or a change in the
computer configuration such as a different computer name or network card. For configuration
changes, rerun Set

Error - 10/3/2011 9:27:02 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65638
Description = Cannot start the Analysis serv

Error - 10/3/2011 10:04:38 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65654
Description = The current configuration no longer matches the licensed configuration.
This may be caused by the expiration of an evaluation license or a change in the
computer configuration such as a different computer name or network card. For configuration
changes, rerun Set

Error - 10/3/2011 10:04:38 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65638
Description = Cannot start the Analysis serv

Error - 10/3/2011 10:12:52 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65654
Description = The current configuration no longer matches the licensed configuration.
This may be caused by the expiration of an evaluation license or a change in the
computer configuration such as a different computer name or network card. For configuration
changes, rerun Set

Error - 10/3/2011 10:12:52 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65638
Description = Cannot start the Analysis serv

Error - 10/3/2011 10:20:45 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65654
Description = The current configuration no longer matches the licensed configuration.
This may be caused by the expiration of an evaluation license or a change in the
computer configuration such as a different computer name or network card. For configuration
changes, rerun Set

Error - 10/3/2011 10:20:46 PM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65638
Description = Cannot start the Analysis serv

Error - 10/4/2011 12:20:41 AM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65654
Description = The current configuration no longer matches the licensed configuration.
This may be caused by the expiration of an evaluation license or a change in the
computer configuration such as a different computer name or network card. For configuration
changes, rerun Set

Error - 10/4/2011 12:20:41 AM | Computer Name = CDHOME | Source = MSSQLServerOLAPService | ID = 65638
Description = Cannot start the Analysis serv

[ System Events ]
Error - 10/5/2011 10:03:44 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service EventSystem
with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF}

Error - 10/5/2011 10:04:56 PM | Computer Name = CDHOME | Source = Service Control Manager | ID = 7001
Description = The World Wide Web Publishing service depends on the IIS Admin service
which failed to start because of the following error: %%1068

Error - 10/5/2011 10:04:56 PM | Computer Name = CDHOME | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
adwarealert black Fips intelppm

Error - 10/5/2011 10:06:30 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/5/2011 10:07:06 PM | Computer Name = CDHOME | Source = Dhcp | ID = 1002
Description = The IP address lease 192.168.123.100 for the Network Card with network
address 00D0680130CB has been denied by the DHCP server 192.168.123.254 (The DHCP
Server sent a DHCPNACK message).

Error - 10/5/2011 10:12:42 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/5/2011 10:17:38 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/5/2011 10:17:50 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/5/2011 10:17:51 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Error - 10/5/2011 10:18:15 PM | Computer Name = CDHOME | Source = DCOM | ID = 10005
Description = DCOM got error "%1084" attempting to start the service StiSvc with
arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}


< End of report >
Here is the aswMBR log. I have also attached the MBR.zip file: aswMBR version 0.9.8.986 Copyright© 2011 AVAST Software Run date: 2011-10-05 22:38:24 —————————– 22:38:24.093 OS Version: Windows 5.1.2600 Service Pack 3 22:38:24.093 Number of processors: 1 586 0x207 22:38:24.093 ComputerName: CDHOME UserName: 22:38:24.546 Initialize success 22:42:44.281 AVAST engine defs: 11100501 22:43:45.578 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-4 22:43:45.593 Disk 0 Vendor: Maxtor_6E030L0 NAR61590 Size: 29325MB BusType: 3 22:43:45.609 Disk 1 \Device\Harddisk1\DR1 -> \Device\Ide\IdeDeviceP0T1L0-c 22:43:45.625 Disk 1 Vendor: Maxtor_6Y080L0 YAR41BW0 Size: 78167MB BusType: 3 22:43:47.640 Disk 0 MBR read successfully 22:43:47.656 Disk 0 MBR scan 22:43:47.781 Disk 0 Windows XP default MBR code 22:43:47.812 Disk 0 scanning sectors +60034905 22:43:47.859 Disk 0 scanning C:\WINNT\system32\drivers 22:43:52.703 File: C:\WINNT\system32\drivers\i8042prt.sys **INFECTED** Win32:Alureon-FZ 22:44:04.656 File: C:\WINNT\system32\drivers\volsnap.sys **INFECTED** Win32:Alureon-PS 22:44:05.328 Service scanning 22:44:10.390 Service VolSnap C:\WINNT\System32\Drivers\VolSnap.sys **LOCKED** 32 22:44:12.968 Modules scanning 22:44:15.203 Module: C:\WINNT\System32\Drivers\VolSnap.sys **SUSPICIOUS** 22:44:22.265 Disk 0 trace - called modules: 22:44:22.375 ntoskrnl.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll >>UNKNOWN [0x82ed11ed]<< 22:44:22.484 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x82f5eab8] 22:44:22.593 3 CLASSPNP.SYS[f8685fd7] -> nt!IofCallDriver -> \Device\0000005f[0x82f87120] 22:44:22.687 5 ACPI.sys[f85ec620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-4[0x82f4bd98] 22:44:22.796 \Driver\atapi[0x82f864b8] -> IRP_MJ_INTERNAL_DEVICE_CONTROL -> 0x82ed11ed 22:44:23.937 AVAST engine scan C:\WINNT 22:44:29.234 File: C:\WINNT\1430404087:147111338.exe **INFECTED** Win32:Sirefef-O [Rtk] 22:44:47.109 AVAST engine scan C:\WINNT\system32 22:46:24.015 File: C:\WINNT\system32\QuSFpGQ6E8RYjVl.exe **INFECTED** Win32:FakeAlert-BGT [Trj] 22:47:09.843 AVAST engine scan C:\WINNT\system32\drivers 22:47:15.875 File: C:\WINNT\system32\drivers\i8042prt.sys **INFECTED** Win32:Alureon-FZ 22:47:29.656 File: C:\WINNT\system32\drivers\volsnap.sys **INFECTED** Win32:Alureon-PS 22:47:31.250 AVAST engine scan C:\Documents and Settings\Administrator 22:50:26.468 File: C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\40\20fcbc28-47b760a1 **INFECTED** Win32:Alureon-ALV [Rtk] 22:54:06.578 File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\IZK7XPUZ\ex[1].htm **INFECTED** Win32:Malware-gen 22:54:39.328 File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\UST308E0\file[1].exe **INFECTED** Win32:FakeAlert-BGT [Trj] 22:54:43.203 File: C:\Documents and Settings\Administrator\Local Settings\Temporary Internet Files\Content.IE5\YWD2RT3S\ex[1].htm **INFECTED** Win32:Kryptik-FBW [Trj] 22:55:07.656 AVAST engine scan C:\Documents and Settings\All Users 22:55:08.000 File: C:\Documents and Settings\All Users\Application Data\1kAlMiG2Kb7FzP.exe **INFECTED** Win32:Kryptik-FBW [Trj] 22:57:02.406 File: C:\Documents and Settings\All Users\Application Data\PbOVsnXuaBESx.exe **INFECTED** Win32:Kryptik-FBW [Trj] 22:59:01.859 Scan finished successfully 23:08:06.375 Disk 0 MBR has been saved successfully to "C:\Program Files\Aswmbr\MBR.dat" 23:08:06.390 The log file has been saved successfully to "C:\Program Files\Aswmbr\aswMBR.txt"
Hi CMD4649,

Oh my, we have a bit of a mess here.

Please read carefully and follow these steps.
  • Download TDSSKiller and save it to C:\program files in it's own folder .
  • Extract its contents to the folder.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.

    🖼Click to load external image (Posted Image)
  • If an infected file is detected, the default action will be Cure, click on Continue.

    🖼Click to load external image (Posted Image)
  • If a suspicious file is detected, the default action will be Skip, click on Continue.

    🖼Click to load external image (Posted Image)
  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.

    🖼Click to load external image (Posted Image)
  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.


Next

Please read through these instructions to familarize yourself with what to expect when this tool runs

Download ComboFix from one of these locations:

Link 1
Link 2

* IMPORTANT !!! Save ComboFix.exe to your Desktop (if you can not access this then save it to c:program files)

* Note- if you running combofix in safe mode you will not be able to disable your security programs. They will not be running so that will not be a problem. If combofix reboots the computer , boot back into safe mode and let it finish. Save the log and boot back to normal windows and post the log here.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : How to Disable your Security Programs
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

[external image: Posted Image]


Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

[external image: Posted Image]

Click on Yes, to continue scanning for malware.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

Notes:

1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.

Please post back with
  • TDSSKiller log
  • combofix log
How's the computer?

Thanks
Hello. I wanted to do all of this last nhight, but instead I watched the Yankees lose to Detroit so I wasn't able to perform any of the instructions in your last post. I will work on the computer tonight. It's still behaving the same way, however at this time all I have done is run those utilities to have them check for what's wrong. I have not actually removed or cleaned anything. This spyware is really insidious. All of the desktop icons are gone and there are no programs at all int he program group when you click the start button. This is true even in safe mode. At this point, I just want to get this thing to a state where I can copy some of the files from the C: Drive that I want to keep and then I'll just re-format the C: drive with a new installation of Windows XP Pro. Thanks for your help.
Hi CMD4649,

At this point, I just want to get this thing to a state where I can copy some of the files from the C: Drive that I want to keep and then I'll just re-format the C: drive with a new installation of Windows XP Pro.


That may be the best way to go. Do not run the tools in my last post, let's see if we can first restore your files and programs. If your programs are now visible please back up your personal data and post back.

Please do not use any temporary files cleaner as all your files have been moved to a temporary location. We will clean those after we have made sure everything has been restored.

Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:Files
xcopy %Temp%\smtmp\1 "%AllUsersProfile%\Start Menu" /H /I /S /Y /C
xcopy %Temp%\smtmp\2 "%UserProfile%\Application Data\Microsoft\Internet Explorer\Quick Launch" /H /I /S /Y /C
xcopy %Temp%\smtmp\4 "%AllUsersProfile%\Desktop" /H /I /S /Y /C
ipconfig /flushdns /c

:Commands
[purity]
[createresrorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Download RogueKiller to your desktop

  • Quit all running programs
  • When prompted, type 6 and validate

Are your icons and programs back? Can you now back them up?
At this point, there are no programs visible in the programs list at all. I still cannot see anything in the My Documents directory in Windows Explorer, or in the computers second D: drive or in the E: drive which is the USB port. However, for some reason it does allow me to browse to and execute programs and files in the C:\Program Files directory. What I am looking for is the ability to fully browse all of the files on the C: Drive so that I can compress and copy the stuff I need and then just performa re-format. We're not there yet, however. I would assume that you want me to do what you instructed in your last post and skip all the cleaning stuff that you originally told me to do.
Hi CMD4649,

I would assume that you want me to do what you instructed in your last post and skip all the cleaning stuff that you originally told me to do.

Yes the instructions in the last post may unhide enough for you to backup your personal data.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI