Zdac
Topic Starter
Hello,
And thanks in advance for this forum and any help you might provide.
I developed a slow operating system with stalls and freezes a few days ago. While it was annoying, I didn't bother to react right away as it could have been anything. But now I have browser redirects and several programs that refuse to open. I use PC tools, but it is mostly turned off because it interferes with gaming. I turned it on and scanned and it cleaned a lot of problems but didn't solve anything. Then I used TDSSKiller and it found 3 or 4 more issues. But the problem persists. So I have followed the instructions for "Are you infected?" The logs follow as requested. I downloaded HiJack This and DDS also. Do you want those files too?
OTL logfile created on: 12/1/2011 7:29:58 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 341.15 Mb Available Physical Memory | 33.33% Memory free
2.40 Gb Paging File | 1.84 Gb Available in Paging File | 76.52% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 79.77 Gb Free Space | 71.36% Space Free | Partition Type: NTFS
Computer Name: M-A192F4C1027D4 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\PC Tools Security\BDT\BSPatch.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\WlanDll.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
========== Driver Services (SafeList) ==========
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (PCTBD) – C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (Htsysm) – C:\WINDOWS\system32\HtsysmNT.sys ()
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (W8335XP) NETGEAR WG311v3 802.11g Wireless PCI Adapter for Windows XP (8335) – C:\WINDOWS\system32\drivers\WG311v3XP.sys (Marvell Semiconductor, Inc)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:54808
========== FireFox ==========
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/11/11 06:20:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/28 17:47:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/01 23:54:16 | 000,000,000 | —D | M]
[2010/09/10 04:05:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/03/12 08:16:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/03 13:25:15 | 000,000,000 | —D | M] (vShare Plugin) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\vshare@toolbar
[2010/10/09 19:55:42 | 000,001,820 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\searchplugins\bing.xml
[2011/11/28 17:47:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/28 17:47:23 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 11:07:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/28 17:47:23 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [408809432] C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.EXE /r "C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.rpd" File not found
O4 - HKLM..\Run: [MozillaAgent] C:\WINDOWS\Temp\_ex-68.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [2230012402] C:\Documents and Settings\Owner\Local Settings\Application Data\xsb.exe File not found
O4 - HKCU..\Run: [Spyware Doctor with AntiVirus] C:\Documents and Settings\Owner\Desktop\sdasetup.exe -min File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA0992D5-09CD-4887-8AA3-0DE0C21E8169}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (MrvGINA.dll) -C:\WINDOWS\System32\MrvGINA.dll (Marvell®)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/03 12:38:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/01 19:26:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:33 | 004,731,432 | —- | C] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 18:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/11/30 13:29:11 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/24 12:33:42 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/11 06:38:02 | 000,574,424 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/11/11 06:38:02 | 000,054,328 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/11/11 06:38:02 | 000,035,264 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/11/11 06:20:40 | 002,291,664 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/11/11 06:20:40 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/11/11 06:20:40 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/11/11 06:20:40 | 000,056,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTBD.sys
[2011/11/11 06:20:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/11/11 06:20:27 | 000,017,848 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2011/11/11 06:18:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\TestApp
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/01 19:28:56 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/01 19:26:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:45 | 004,731,432 | —- | M] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 17:59:27 | 000,868,017 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/01 17:59:20 | 000,029,204 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/01 17:57:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/01 06:52:44 | 226,189,610 | —- | M] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/30 13:29:11 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/30 13:04:03 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/28 17:46:48 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/27 21:19:42 | 000,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/27 21:19:42 | 000,071,250 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/27 21:10:39 | 1073,299,456 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/11/15 11:33:00 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/11 06:34:48 | 000,341,656 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/11/09 23:08:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/08 17:25:28 | 000,002,935 | —- | M] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/01 06:28:46 | 226,189,610 | —- | C] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/11 06:20:40 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/11/11 06:20:40 | 000,003,488 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/11/11 06:20:40 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/11/11 06:20:40 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/11/11 06:20:40 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/11/08 17:17:30 | 000,002,935 | —- | C] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[2011/09/09 18:44:20 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:23 | 000,004,109 | —- | C] () – C:\Documents and Settings\Owner\Application Data\267E.B5F
[2011/05/30 06:37:30 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/04/30 07:55:27 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2011/01/07 19:36:56 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\HtsysmNT.sys
[2010/12/10 21:14:27 | 000,000,070 | —- | C] () – C:\WINDOWS\Esv44JBS5X2.dll
[2010/12/10 21:14:27 | 000,000,004 | —- | C] () – C:\WINDOWS\Esv44JBS5X.dll
[2010/09/10 04:05:00 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/09/09 21:32:20 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/03 17:33:38 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2010/09/03 12:58:58 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/09/03 12:58:55 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/09/03 12:58:55 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/09/03 12:40:34 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/09/03 12:36:37 | 000,023,348 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/09/03 08:28:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/09/03 08:27:13 | 000,118,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/07/20 23:07:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,441,124 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,071,250 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/12/01 18:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/19 19:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2010/12/30 11:35:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2010/12/04 19:01:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Magic Match
[2010/09/06 15:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/09/05 06:25:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/04/30 08:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment
[2011/09/09 19:09:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/11/11 06:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TestApp
[2011/06/30 19:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Turbine
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/09/05 07:26:55 | 000,000,211 | -HS- | M] () – C:\boot.ini.old
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/26 05:00:23 | 003,607,552 | —- | M] () – C:\NETGEAR WG311v3 802.11g Wireless PCI Adapter.msi
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/04 08:28:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/01 17:57:28 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2011/06/06 04:07:06 | 000,034,998 | —- | M] () – C:\TDSSKiller.2.5.3.0_06.06.2011_05.06.49_log.txt
[2011/11/30 13:02:24 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.3.0_30.11.2011_13.02.13_log.txt
[2011/05/31 18:19:51 | 000,035,958 | —- | M] () – C:\TDSSKiller.2.5.3.0_31.05.2011_19.19.13_log.txt
[2011/12/01 05:24:21 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_05.23.47_log.txt
[2011/12/01 07:03:10 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_06.44.55_log.txt
[2011/12/01 17:59:45 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_17.59.32_log.txt
[2011/11/30 13:05:27 | 000,045,304 | —- | M] () – C:\TDSSKiller.2.6.21.0_30.11.2011_13.04.25_log.txt
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2011/09/08 11:30:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/09/08 17:02:12 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/09/08 07:16:10 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/09/08 10:46:34 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2011/09/08 07:16:10 | 020,709,376 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/09/08 07:16:10 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/09/08 22:12:01 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All LS\x00\x00\x00\x00
And thanks in advance for this forum and any help you might provide.
I developed a slow operating system with stalls and freezes a few days ago. While it was annoying, I didn't bother to react right away as it could have been anything. But now I have browser redirects and several programs that refuse to open. I use PC tools, but it is mostly turned off because it interferes with gaming. I turned it on and scanned and it cleaned a lot of problems but didn't solve anything. Then I used TDSSKiller and it found 3 or 4 more issues. But the problem persists. So I have followed the instructions for "Are you infected?" The logs follow as requested. I downloaded HiJack This and DDS also. Do you want those files too?
OTL logfile created on: 12/1/2011 7:29:58 PM - Run 1
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18702)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1023.48 Mb Total Physical Memory | 341.15 Mb Available Physical Memory | 33.33% Memory free
2.40 Gb Paging File | 1.84 Gb Available in Paging File | 76.52% Paging File free
Paging file location(s): c:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 111.79 Gb Total Space | 79.77 Gb Free Space | 71.36% Space Free | Partition Type: NTFS
Computer Name: M-A192F4C1027D4 | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
PRC - C:\WINDOWS\system32\ping.exe (Microsoft Corporation)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
PRC - C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files\Mozilla Firefox\mozjs.dll ()
MOD - C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
MOD - C:\Program Files\PC Tools Security\BDT\BSPatch.dll ()
MOD - \\?\globalroot\systemroot\system32\mswsock.dll ()
MOD - \\.\globalroot\systemroot\system32\mswsock.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\WlanDll.dll ()
MOD - C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
========== Win32 Services (SafeList) ==========
SRV - (HidServ) – File not found
SRV - (AppMgmt) – File not found
SRV - (sdCoreService) – C:\Program Files\PC Tools Security\pctsSvc.exe (PC Tools)
SRV - (sdAuxService) – C:\Program Files\PC Tools Security\pctsAuxs.exe (PC Tools)
SRV - (ThreatFire) – C:\Program Files\PC Tools Security\TFEngine\TFService.exe (PC Tools)
SRV - (Browser Defender Update Service) – C:\Program Files\PC Tools Security\BDT\BDTUpdateService.exe (Threat Expert Ltd.)
========== Driver Services (SafeList) ==========
DRV - (pctDS) – C:\WINDOWS\system32\drivers\pctDS.sys (PC Tools)
DRV - (pctplsg) – C:\WINDOWS\system32\drivers\pctplsg.sys (PC Tools)
DRV - (PCTSD) – C:\WINDOWS\system32\drivers\PCTSD.sys (PC Tools)
DRV - (pctgntdi) – C:\WINDOWS\system32\drivers\pctgntdi.sys (PC Tools)
DRV - (TfSysMon) – C:\WINDOWS\system32\drivers\TfSysMon.sys (PC Tools)
DRV - (TfFsMon) – C:\WINDOWS\system32\drivers\TfFsMon.sys (PC Tools)
DRV - (TfNetMon) – C:\WINDOWS\system32\drivers\TfNetMon.sys (PC Tools)
DRV - (PCTCore) – C:\WINDOWS\system32\drivers\PCTCore.sys (PC Tools)
DRV - (pctEFA) – C:\WINDOWS\system32\drivers\pctEFA.sys (PC Tools)
DRV - (PCTBD) – C:\WINDOWS\system32\drivers\PCTBD.sys (PC Tools)
DRV - (Htsysm) – C:\WINDOWS\system32\HtsysmNT.sys ()
DRV - (nvgts) – C:\WINDOWS\system32\DRIVERS\nvgts.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (nvnetbus) – C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (gameenum) – C:\WINDOWS\system32\drivers\gameenum.sys (Microsoft Corporation)
DRV - (W8335XP) NETGEAR WG311v3 802.11g Wireless PCI Adapter for Windows XP (8335) – C:\WINDOWS\system32\drivers\WG311v3XP.sys (Marvell Semiconductor, Inc)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) – C:\WINDOWS\system32\drivers\ALCXWDM.SYS (Realtek Semiconductor Corp.)
DRV - (ms_mpu401) – C:\WINDOWS\system32\drivers\msmpu401.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKCU\..\URLSearchHook: {472734EA-242A-422b-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.lotro.com;*.turbine.com;12.130.63.*;206.17.109.*
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:54808
========== FireFox ==========
FF - prefs.js..network.proxy.type: 4
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\WINDOWS\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.0.50826.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{38AB6A6C-CC4C-4f9e-A3DD-3C5681EF18A1}\plugins\npsoe.dll File not found
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\extensions\\{cb84136f-9c44-433a-9048-c5cd9df1dc16}: C:\Program Files\PC Tools Security\BDT\Firefox\ [2011/11/11 06:20:41 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011/11/28 17:47:24 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 8.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011/10/01 23:54:16 | 000,000,000 | —D | M]
[2010/09/10 04:05:11 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (No name found) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions
[2011/09/06 11:28:13 | 000,000,000 | —D | M] (Garmin Communicator) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E}
[2011/03/12 08:16:35 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/10/03 13:25:15 | 000,000,000 | —D | M] (vShare Plugin) – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\extensions\vshare@toolbar
[2010/10/09 19:55:42 | 000,001,820 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Mozilla\Firefox\Profiles\przs92wx.default\searchplugins\bing.xml
[2011/11/28 17:47:27 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2011/11/28 17:47:23 | 000,134,104 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010/09/15 03:50:38 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011/10/04 11:07:11 | 000,002,252 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011/11/28 17:47:23 | 000,002,040 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml
Hosts file not found
O2 - BHO: (PC Tools Browser Defender BHO) - {2A0F3D1B-0909-4FF4-B272-609CCE6054E7} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKLM\..\Toolbar: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (PC Tools Browser Defender) - {472734EA-242A-422B-ADF8-83D1E48CC825} - C:\Program Files\PC Tools Security\BDT\PCTBrowserDefender.dll (Threat Expert Ltd.)
O4 - HKLM..\Run: [408809432] C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.EXE /r "C:\PROGRA~1\eGames\POKERM~1\Register\EGAMES~1.rpd" File not found
O4 - HKLM..\Run: [MozillaAgent] C:\WINDOWS\Temp\_ex-68.exe File not found
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe (NVIDIA Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\SOUNDMAN.EXE (Realtek Semiconductor Corp.)
O4 - HKCU..\Run: [2230012402] C:\Documents and Settings\Owner\Local Settings\Application Data\xsb.exe File not found
O4 - HKCU..\Run: [Spyware Doctor with AntiVirus] C:\Documents and Settings\Owner\Desktop\sdasetup.exe -min File not found
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\NETGEAR WG311v3 Smart Wizard.lnk = C:\Program Files\NETGEAR\WG311v3\wlancfg5.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files\Common Files\PC Tools\Lsp\PCTLsp.dll (PC Tools Research Pty Ltd.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000016 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000017 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000018 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000020 - mswsock.dll File not found
O10 - Protocol_Catalog9\Catalog_Entries\000000000021 - mswsock.dll File not found
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{FA0992D5-09CD-4887-8AA3-0DE0C21E8169}: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) -C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (MrvGINA.dll) -C:\WINDOWS\System32\MrvGINA.dll (Marvell®)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/09/03 12:38:57 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O35 - HKCU\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKCU\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - File not found
NetSvcs: HidServ - File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2011/12/01 19:26:49 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:33 | 004,731,432 | —- | C] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 18:12:33 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2011/11/30 13:29:11 | 000,281,104 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | C] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | C] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/24 12:33:42 | 001,566,512 | —- | C] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/11 06:38:02 | 000,574,424 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfSysMon.sys
[2011/11/11 06:38:02 | 000,054,328 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfFsMon.sys
[2011/11/11 06:38:02 | 000,035,264 | –S- | C] (PC Tools) – C:\WINDOWS\System32\drivers\TfNetMon.sys
[2011/11/11 06:20:40 | 002,291,664 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDCore.dll
[2011/11/11 06:20:40 | 001,681,360 | —- | C] (Threat Expert Ltd.) – C:\WINDOWS\PCTBDRes.dll
[2011/11/11 06:20:40 | 000,149,456 | —- | C] (PC Tools) – C:\WINDOWS\SGDetectionTool.dll
[2011/11/11 06:20:40 | 000,056,840 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\PCTBD.sys
[2011/11/11 06:20:28 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Start Menu\Programs\PC Tools Security
[2011/11/11 06:20:27 | 000,017,848 | —- | C] (PC Tools) – C:\WINDOWS\System32\drivers\pctBTFix.sys
[2011/11/11 06:18:47 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\TestApp
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/12/01 19:28:56 | 000,001,324 | —- | M] () – C:\WINDOWS\System32\d3d9caps.dat
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/12/01 19:26:49 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2011/12/01 19:26:14 | 000,584,192 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2011/12/01 19:06:45 | 004,731,432 | —- | M] (SpeedyPC Software Inc.) – C:\Documents and Settings\Owner\Desktop\RepairTool.exe
[2011/12/01 17:59:27 | 000,868,017 | —- | M] () – C:\WINDOWS\System32\drivers\Cat.DB
[2011/12/01 17:59:20 | 000,029,204 | —- | M] () – C:\WINDOWS\System32\nvapps.xml
[2011/12/01 17:57:34 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2011/12/01 06:52:44 | 226,189,610 | —- | M] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/30 13:29:11 | 000,281,104 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\wpcap.dll
[2011/11/30 13:29:11 | 000,050,704 | —- | M] (CACE Technologies, Inc.) – C:\WINDOWS\System32\drivers\npf.sys
[2011/11/30 13:05:18 | 000,094,896 | —- | M] (Kaspersky Lab, GERT) – C:\WINDOWS\System32\drivers\40107822.sys
[2011/11/30 13:04:03 | 001,566,512 | —- | M] (Kaspersky Lab ZAO) – C:\Documents and Settings\Owner\Desktop\TDSSKiller.exe
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:55:11 | 000,012,254 | -HS- | M] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/28 17:46:48 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2011/11/27 21:19:42 | 000,441,124 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2011/11/27 21:19:42 | 000,071,250 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2011/11/27 21:10:39 | 1073,299,456 | —- | M] () – C:\WINDOWS\MEMORY.DMP
[2011/11/15 11:33:00 | 000,414,368 | —- | M] (Adobe Systems Incorporated) – C:\WINDOWS\System32\FlashPlayerCPLApp.cpl
[2011/11/11 06:34:48 | 000,341,656 | —- | M] (PC Tools) – C:\WINDOWS\System32\drivers\pctDS.sys
[2011/11/09 23:08:11 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2011/11/08 17:25:28 | 000,002,935 | —- | M] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[8 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/12/01 06:28:46 | 226,189,610 | —- | C] () – C:\Documents and Settings\Owner\Desktop\populationsc17900006unit.pdf
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/29 17:47:35 | 000,012,254 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\560565g1r632l844h356t3bdg5p5
[2011/11/11 06:20:40 | 000,767,952 | —- | C] () – C:\WINDOWS\BDTSupport.dll
[2011/11/11 06:20:40 | 000,003,488 | —- | C] () – C:\WINDOWS\UDB.zip
[2011/11/11 06:20:40 | 000,000,882 | —- | C] () – C:\WINDOWS\RegSDImport.xml
[2011/11/11 06:20:40 | 000,000,879 | —- | C] () – C:\WINDOWS\RegISSImport.xml
[2011/11/11 06:20:40 | 000,000,131 | —- | C] () – C:\WINDOWS\IDB.zip
[2011/11/08 17:17:30 | 000,002,935 | —- | C] () – C:\Documents and Settings\Owner\My Documents\S-61.odb
[2011/09/09 18:44:20 | 000,004,984 | —- | C] () – C:\WINDOWS\System32\drivers\nvphy.bin
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/16 06:19:05 | 000,012,102 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\14ia86d3hvi14h517x44tn37jf182bje5512
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:28 | 000,001,626 | -HS- | C] () – C:\Documents and Settings\All Users\Application Data\734ic5kl480kc2nvg31
[2011/06/05 21:01:23 | 000,004,109 | —- | C] () – C:\Documents and Settings\Owner\Application Data\267E.B5F
[2011/05/30 06:37:30 | 000,000,262 | —- | C] () – C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2011/04/30 07:55:27 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2011/01/07 19:36:56 | 000,002,304 | —- | C] () – C:\WINDOWS\System32\HtsysmNT.sys
[2010/12/10 21:14:27 | 000,000,070 | —- | C] () – C:\WINDOWS\Esv44JBS5X2.dll
[2010/12/10 21:14:27 | 000,000,004 | —- | C] () – C:\WINDOWS\Esv44JBS5X.dll
[2010/09/10 04:05:00 | 000,000,000 | —- | C] () – C:\WINDOWS\nsreg.dat
[2010/09/09 21:32:20 | 000,001,324 | —- | C] () – C:\WINDOWS\System32\d3d9caps.dat
[2010/09/03 17:33:38 | 000,000,169 | —- | C] () – C:\WINDOWS\RtlRack.ini
[2010/09/03 12:58:58 | 000,000,164 | —- | C] () – C:\WINDOWS\avrack.ini
[2010/09/03 12:58:55 | 000,156,672 | —- | C] () – C:\WINDOWS\System32\RTLCPAPI.dll
[2010/09/03 12:58:55 | 000,040,960 | —- | C] () – C:\WINDOWS\System32\ChCfg.exe
[2010/09/03 12:40:34 | 000,002,048 | –S- | C] () – C:\WINDOWS\bootstat.dat
[2010/09/03 12:36:37 | 000,023,348 | —- | C] () – C:\WINDOWS\System32\emptyregdb.dat
[2010/09/03 08:28:15 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2010/09/03 08:27:13 | 000,118,952 | —- | C] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2005/07/20 23:07:00 | 000,540,672 | —- | C] () – C:\WINDOWS\System32\nvhwvid.dll
[2004/08/04 07:00:00 | 013,107,200 | —- | C] () – C:\WINDOWS\System32\oembios.bin
[2004/08/04 07:00:00 | 000,673,088 | —- | C] () – C:\WINDOWS\System32\mlang.dat
[2004/08/04 07:00:00 | 000,441,124 | —- | C] () – C:\WINDOWS\System32\perfh009.dat
[2004/08/04 07:00:00 | 000,272,128 | —- | C] () – C:\WINDOWS\System32\perfi009.dat
[2004/08/04 07:00:00 | 000,218,003 | —- | C] () – C:\WINDOWS\System32\dssec.dat
[2004/08/04 07:00:00 | 000,071,250 | —- | C] () – C:\WINDOWS\System32\perfc009.dat
[2004/08/04 07:00:00 | 000,046,258 | —- | C] () – C:\WINDOWS\System32\mib.bin
[2004/08/04 07:00:00 | 000,028,626 | —- | C] () – C:\WINDOWS\System32\perfd009.dat
[2004/08/04 07:00:00 | 000,004,569 | —- | C] () – C:\WINDOWS\System32\secupd.dat
[2004/08/04 07:00:00 | 000,004,461 | —- | C] () – C:\WINDOWS\System32\oembios.dat
[2004/08/04 07:00:00 | 000,001,804 | —- | C] () – C:\WINDOWS\System32\dcache.bin
[2004/08/04 07:00:00 | 000,000,741 | —- | C] () – C:\WINDOWS\System32\noise.dat
========== LOP Check ==========
[2011/12/01 18:37:46 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\TEMP
[2010/10/19 19:22:30 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GARMIN
[2010/12/30 11:35:31 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\GetRightToGo
[2010/12/04 19:01:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Magic Match
[2010/09/06 15:12:38 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\OpenOffice.org
[2011/09/05 06:25:25 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\PCTools
[2011/04/30 08:15:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Sony Online Entertainment
[2011/09/09 19:09:18 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SystemRequirementsLab
[2011/11/11 06:18:47 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\TestApp
[2011/06/30 19:36:22 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Turbine
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2011/12/01 19:27:39 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2011/09/05 07:26:55 | 000,000,211 | -HS- | M] () – C:\boot.ini.old
[2010/09/03 12:38:57 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2010/09/03 12:38:57 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/09/26 05:00:23 | 003,607,552 | —- | M] () – C:\NETGEAR WG311v3 802.11g Wireless PCI Adapter.msi
[2004/08/04 07:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2010/09/04 08:28:15 | 000,250,048 | RHS- | M] () – C:\ntldr
[2011/12/01 17:57:28 | 1610,612,736 | -HS- | M] () – C:\pagefile.sys
[2011/06/06 04:07:06 | 000,034,998 | —- | M] () – C:\TDSSKiller.2.5.3.0_06.06.2011_05.06.49_log.txt
[2011/11/30 13:02:24 | 000,000,412 | —- | M] () – C:\TDSSKiller.2.5.3.0_30.11.2011_13.02.13_log.txt
[2011/05/31 18:19:51 | 000,035,958 | —- | M] () – C:\TDSSKiller.2.5.3.0_31.05.2011_19.19.13_log.txt
[2011/12/01 05:24:21 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_05.23.47_log.txt
[2011/12/01 07:03:10 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_06.44.55_log.txt
[2011/12/01 17:59:45 | 000,043,866 | —- | M] () – C:\TDSSKiller.2.6.21.0_01.12.2011_17.59.32_log.txt
[2011/11/30 13:05:27 | 000,045,304 | —- | M] () – C:\TDSSKiller.2.6.21.0_30.11.2011_13.04.25_log.txt
< %systemroot%\Fonts\*.com >
[2006/06/29 14:58:52 | 000,030,808 | —- | M] () – C:\WINDOWS\Fonts\GlobalUserInterface.CompositeFont
[2006/04/18 15:39:28 | 000,026,040 | —- | M] () – C:\WINDOWS\Fonts\GlobalMonospace.CompositeFont
[2006/06/29 14:53:56 | 000,026,489 | —- | M] () – C:\WINDOWS\Fonts\GlobalSansSerif.CompositeFont
[2006/04/18 15:39:28 | 000,029,779 | —- | M] () – C:\WINDOWS\Fonts\GlobalSerif.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2011/09/08 11:30:13 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2008/07/06 07:06:10 | 000,089,088 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\filterpipelineprintproc.dll
[2008/07/06 05:50:03 | 000,597,504 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\spool\prtprocs\w32x86\printfilterpipelinesvc.exe
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/09/08 17:02:12 | 000,001,546 | -H– | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\LastFlashConfig.WFC
< %PROGRAMFILES%\*.* >
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2011/09/08 07:16:10 | 000,524,288 | —- | M] () – C:\WINDOWS\System32\config\default.sav
[2011/09/08 10:46:34 | 000,262,144 | —- | M] () – C:\WINDOWS\System32\config\security.sav
[2011/09/08 07:16:10 | 020,709,376 | —- | M] () – C:\WINDOWS\System32\config\software.sav
[2011/09/08 07:16:10 | 006,553,600 | —- | M] () – C:\WINDOWS\System32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2011/09/08 22:12:01 | 000,000,272 | -HS- | M] () – C:\Documents and Settings\All LS\x00\x00\x00\x00