recently, a "connect" button started appearing on the sides of my web browser (firefox), and sometimes when i reload the page, it would redirect me to a different website with a pop up window saying:
"Warning! On your computer detected the malicious code. Should immediately make sure that your system is safe! Killing Hazard (R) for Microsoft Windows XP immediately started to work"
then no matter what option i choose, it would start scanning my computer.
i've tried scanning with ad-aware and malwarebytes now, both only found cookies.
OTL scan log:
OTL logfile created on: 9/27/2010 4:54:51 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\zhe\Desktop\New Folder (3)
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.51 Gb Total Space | 86.73 Gb Free Space | 79.93% Space Free | Partition Type: NTFS
Drive D: | 590.12 Gb Total Space | 262.56 Gb Free Space | 44.49% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ZHEE
Current User Name: zhe
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/09/27 04:45:35 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zhe\Desktop\New Folder (3)\OTL.com
PRC - [2010/02/18 12:49:40 | 000,357,448 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
PRC - [2010/02/18 12:47:34 | 003,203,144 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
PRC - [2009/04/22 21:11:32 | 001,675,776 | ---- | M] (Flagship Industries, Inc.) -- C:\Program Files\Ventrilo\Ventrilo.exe
PRC - [2009/02/06 17:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/05/02 02:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/05/02 02:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/14 00:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
========== Modules (SafeList) ==========
MOD - [2010/09/27 04:45:35 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zhe\Desktop\New Folder (3)\OTL.com
MOD - [2009/07/12 01:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008/05/02 02:42:50 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2008/04/14 00:41:52 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll
MOD - [2008/04/14 00:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2010/03/01 16:38:11 | 001,029,456 | ---- | M] (Lavasoft) [Disabled | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009/08/03 20:46:15 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/06/22 10:48:16 | 000,170,736 | ---- | M] (Rogers) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe -- (Radialpoint Security Services)
SRV - [2009/06/22 10:47:20 | 000,371,440 | ---- | M] (Rogers) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe -- (RP_FWS)
SRV - [2008/11/18 12:18:38 | 000,262,144 | ---- | M] (ASUSTeK COMPUTER INC.) [Disabled | Stopped] -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)
SRV - [2008/11/14 18:28:10 | 004,937,752 | R--- | M] (Sana Security) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaAgent.exe -- (RadialpointSafeConnectAgent)
SRV - [2008/09/22 16:58:48 | 000,910,600 | ---- | M] (Raxco Software, Inc.) [Disabled | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe -- (PD91Engine)
SRV - [2008/09/22 16:58:44 | 000,693,512 | ---- | M] (Raxco Software, Inc.) [Disabled | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe -- (PD91Agent)
SRV - [2008/05/02 02:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/03/27 10:17:38 | 000,055,816 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\GIGABYTE\GEST\GSvr.exe -- (GEST Service)
SRV - [2007/11/06 16:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [Disabled | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) [Disabled | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\vvftUVC.sys -- (vvftUVC)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\VMUVC.sys -- (VMUVC)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
DRV - [2010/07/09 18:38:00 | 010,604,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010/06/24 03:11:14 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\etdrv.sys -- (etdrv)
DRV - [2010/06/24 03:10:51 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2009/11/23 17:37:18 | 000,014,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LGVirHid.sys -- (LGVirHid)
DRV - [2009/11/23 17:37:08 | 000,019,720 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV - [2009/07/28 08:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/06/02 06:02:46 | 005,085,184 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/04/03 14:51:32 | 000,179,984 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2009/02/23 00:16:22 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\GIGABYTE\ET6\i386\AODDriver.sys -- (AODDriver)
DRV - [2009/02/13 15:02:52 | 000,011,520 | R--- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/11/26 15:19:56 | 000,053,192 | ---- | M] (Radialpoint Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rp_skt32.sys -- (RPSKT) Security Services Driver (x86)
DRV - [2008/11/18 12:18:40 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asusgsb.sys -- (asusgsb)
DRV - [2008/11/18 12:18:40 | 000,010,752 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Video3D32.sys -- (Video3D)
DRV - [2008/11/18 12:18:38 | 000,011,136 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt)
DRV - [2008/11/14 18:28:36 | 000,161,304 | R--- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectDriver.sys -- (RadialpointSafeConnectDriver)
DRV - [2008/11/14 18:28:36 | 000,029,720 | R--- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectFilter.sys -- (RadialpointSafeConnectFilter)
DRV - [2008/11/14 18:28:36 | 000,027,376 | ---- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectShim.sys -- (RadialpointSafeConnectShim)
DRV - [2008/08/28 13:16:40 | 000,071,184 | ---- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\DefragFS.sys -- (DefragFS)
DRV - [2008/08/05 08:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 19:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 17:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/02/29 03:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008/02/29 03:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008/02/29 03:12:48 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/11/06 16:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/10/11 11:10:52 | 000,030,008 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2007/09/04 19:26:32 | 000,029,696 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev)
DRV - [2007/01/29 17:12:52 | 000,018,432 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AsusVRC.sys -- (ASUSVRC)
DRV - [2007/01/17 15:30:00 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Spyder2.sys -- (Spyder2)
DRV - [2006/11/22 08:01:00 | 000,250,496 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006/06/14 13:44:30 | 000,012,288 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EIO_XP.sys -- (EIO_XP)
DRV - [2006/03/28 17:56:06 | 000,027,008 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidKE.Sys -- (LHidKe)
DRV - [2006/03/28 17:55:58 | 000,069,760 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2006/03/28 17:55:04 | 000,055,808 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042MOU.SYS -- (L8042mou)
DRV - [2006/01/04 03:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004/10/15 13:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2004/05/27 11:47:16 | 000,019,968 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2004/05/21 15:16:14 | 000,471,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvcm.sys -- (QCMerced)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/25 17:03:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/17 01:26:20 | 000,000,000 | ---D | M]
[2009/08/12 02:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Extensions
[2009/08/12 02:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/09/25 11:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions
[2010/04/27 15:04:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/03 14:54:24 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010/06/07 19:11:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/25 11:03:32 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/17 04:40:12 | 000,704,512 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
O1 HOSTS File: ([2007/08/11 02:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Rogers Online Protection\Rogers Online Protection\pkR.dll (Rogers)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [YY] C:\Program Files\duowan\yy-2.0\Start.exe (广州多玩信息技术有限公司)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\zhe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\zhe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/03 05:28:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell - "" = AutoRun
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell\AutoRun\command - "" = G:\Startme.exe -- File not found
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell - "" = AutoRun
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell\AutoRun\command - "" = G:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/09/27 04:45:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder (3)
[2010/09/26 04:06:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/26 04:06:08 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/26 04:06:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/26 04:05:40 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\zhe\Desktop\mbam-setup-1.46.exe
[2010/09/25 16:55:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder (2)
[2010/09/23 00:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder
[2010/09/16 22:27:56 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/09/08 00:01:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\LogiShrd
[2010/09/07 23:57:47 | 000,301,656 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\BtCoreIf.dll
[2010/09/07 23:57:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd
[2010/09/07 23:57:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Application Data\InstallShield
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/27 04:54:22 | 002,384,160 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2010/09/27 04:52:46 | 093,334,560 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2010/09/27 04:28:55 | 004,980,736 | -H-- | M] () -- C:\Documents and Settings\zhe\NTUSER.DAT
[2010/09/27 04:14:45 | 000,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/27 04:14:45 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/27 04:14:45 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/09/27 03:45:43 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/09/26 15:45:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/26 15:45:38 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/26 15:45:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/26 15:44:25 | 001,256,756 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2010/09/26 15:44:25 | 000,231,464 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2010/09/26 04:06:12 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/26 04:05:44 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\zhe\Desktop\mbam-setup-1.46.exe
[2010/09/26 03:47:56 | 003,171,036 | -H-- | M] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\IconCache.db
[2010/09/25 16:53:44 | 002,314,977 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\IMG_1350.jpg
[2010/09/25 15:39:33 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/25 02:29:02 | 001,534,701 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\IMG_1341.jpg
[2010/09/21 14:20:01 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\02+-+Chapter+01+%28part+2%29.ppt
[2010/09/13 20:29:57 | 000,170,496 | ---- | M] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/08 14:43:47 | 000,002,225 | ---- | M] () -- C:\Documents and Settings\zhe\Application Data\Microsoft\Internet Explorer\Quick Launch\Steam.lnk
[2010/09/07 23:58:45 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2010/09/07 23:58:41 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/09/07 23:57:47 | 000,001,687 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/26 04:06:12 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/25 16:53:44 | 002,314,977 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\IMG_1350.jpg
[2010/09/25 02:29:02 | 001,534,701 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\IMG_1341.jpg
[2010/09/21 14:20:01 | 000,146,432 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\02+-+Chapter+01+%28part+2%29.ppt
[2010/09/07 23:58:45 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2010/09/07 23:58:41 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/04/19 03:08:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\System32\Sx5363.ini
[2010/03/07 11:59:58 | 000,014,832 | -HS- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\fwSG76dUmwJ
[2010/02/18 22:01:56 | 000,002,072 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/01/09 10:08:15 | 000,000,410 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/01/09 10:06:57 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2009/10/18 18:04:33 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/10/11 16:05:38 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2009/09/08 18:24:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mj.INI
[2009/08/10 19:58:59 | 000,024,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\GVTDrv.sys
[2009/08/04 16:30:33 | 000,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2009/08/04 16:30:32 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/08/04 16:30:32 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/08/04 16:30:32 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2009/08/03 17:26:59 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\PUTTY.RND
[2009/08/03 15:42:31 | 000,170,496 | ---- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 14:18:32 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2009/08/03 14:18:32 | 000,005,993 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 14:18:31 | 000,471,232 | ---- | C] () -- C:\WINDOWS\System32\drivers\lvcm.sys
[2009/08/03 14:18:11 | 000,000,252 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2009/08/03 14:06:18 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/08/03 05:50:06 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/08/03 05:48:59 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\tasrtli.dll
[2008/10/14 16:09:12 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen_x86.sys
[2007/11/06 16:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/03/12 12:01:30 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/02/13 18:16:04 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\Spyder2.sys
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/08/03 01:16:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/08/03 01:16:56 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/08/03 01:16:56 | 000,942,080 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2001/08/23 07:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2008/11/18 12:18:40 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) -- C:\WINDOWS\system32\asusgsb.sys
[2001/08/23 07:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2001/08/23 07:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2001/08/23 07:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2008/04/13 17:20:56 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2001/08/23 07:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2001/08/23 07:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2001/08/23 07:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2001/08/23 07:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2001/08/23 07:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2008/04/13 17:19:40 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2008/04/13 17:19:44 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2008/04/13 17:19:40 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2008/04/13 17:19:44 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2008/04/13 17:19:42 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 19:15:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2009/04/17 08:26:40 | 001,847,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2010/09/26 15:45:33 | 000,198,637 | ---- | M] () -- C:\aaw7boot.log
[2009/08/03 05:28:05 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/09/27 04:14:45 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2009/08/03 05:28:05 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/08/03 05:28:05 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/08/03 14:16:25 | 000,000,090 | ---- | M] () -- C:\LogiSetup.log
[2009/08/03 05:28:05 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/04/13 17:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 19:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/26 15:45:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2009/08/03 19:50:26 | 000,000,122 | ---- | M] () -- C:\service.log
< %PROGRAMFILES%\*. >
[2009/09/01 14:28:04 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica MP3 Audio Mixer
[2010/07/31 19:14:08 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/10/18 17:34:18 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead
[2009/08/04 16:31:46 | 000,000,000 | ---D | M] -- C:\Program Files\ASUS
[2010/08/20 06:15:58 | 000,000,000 | ---D | M] -- C:\Program Files\BitComet
[2009/08/03 20:50:34 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/01/09 10:18:20 | 000,000,000 | ---D | M] -- C:\Program Files\Brother
[2010/09/07 23:57:29 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/08/03 05:25:32 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/07/30 04:26:31 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/05/25 03:22:10 | 000,000,000 | ---D | M] -- C:\Program Files\duowan
[2010/04/19 03:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Gameforge4D
[2009/08/10 19:58:43 | 000,000,000 | ---D | M] -- C:\Program Files\GIGABYTE
[2010/02/27 09:55:14 | 000,000,000 | ---D | M] -- C:\Program Files\ImTOO
[2010/09/07 23:57:31 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/08/03 01:51:46 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/08/03 02:24:44 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/08/10 16:38:44 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2009/08/08 15:37:02 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/08/12 02:21:07 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2010/06/29 20:06:55 | 000,000,000 | ---D | M] -- C:\Program Files\Logitech
[2010/09/26 04:06:12 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/10 05:18:41 | 000,000,000 | ---D | M] -- C:\Program Files\Marvell
[2009/08/03 02:05:50 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/09/15 21:15:58 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2009/08/03 05:28:22 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/08/03 05:26:31 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/09/27 04:28:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/08/03 02:25:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2009/08/03 05:24:39 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2009/08/03 05:25:14 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/08/17 19:20:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/08/04 16:27:15 | 000,000,000 | ---D | M] -- C:\Program Files\My Company Name
[2009/10/18 16:41:45 | 000,000,000 | ---D | M] -- C:\Program Files\Nero
[2009/08/03 05:26:44 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/01/09 10:05:38 | 000,000,000 | ---D | M] -- C:\Program Files\Nuance
[2010/08/20 17:00:53 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2010/06/28 03:31:07 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA nTune Performance Application
[2009/08/03 05:25:22 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/08/17 19:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/04/25 18:11:02 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTax 2009
[2009/09/06 23:39:18 | 000,000,000 | ---D | M] -- C:\Program Files\Raxco
[2009/08/03 05:50:05 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2009/08/03 02:25:27 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/02/22 17:49:50 | 000,000,000 | ---D | M] -- C:\Program Files\Rogers Online Protection
[2010/02/25 02:37:33 | 000,000,000 | ---D | M] -- C:\Program Files\Sony Ericsson
[2010/09/10 12:59:38 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/04/30 05:58:04 | 000,000,000 | ---D | M] -- C:\Program Files\Subagames
[2009/08/03 05:31:41 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/08/03 14:06:34 | 000,000,000 | ---D | M] -- C:\Program Files\Ventrilo
[2009/08/03 15:22:04 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2010/09/25 11:36:23 | 000,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2009/08/03 14:33:17 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2009/09/15 21:15:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2010/09/23 15:49:42 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Safety Center
[2009/09/15 21:15:43 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2009/08/03 02:23:41 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/08/03 02:23:41 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/08/03 05:25:06 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/08/03 05:27:12 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2009/09/02 04:02:39 | 000,000,000 | ---D | M] -- C:\Program Files\WinPcap
[2009/08/03 21:33:23 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2009/08/03 05:28:22 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< %appdata%\*.* >
[2009/08/03 01:20:07 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\zhe\Application Data\desktop.ini
< MD5 for: AGP440.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 19:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2008/04/13 19:10:48 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 00:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 00:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 00:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 00:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008/04/14 00:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 00:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2008/04/14 00:15:40 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2008/04/14 00:15:40 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-08-03 06:17:28
========== Files - Unicode (All) ==========
[2009/09/06 23:40:13 | 000,000,040 | ---- | M] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
[2009/09/06 23:40:13 | 000,000,040 | ---- | C] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
< End of report >
"Warning! On your computer detected the malicious code. Should immediately make sure that your system is safe! Killing Hazard (R) for Microsoft Windows XP immediately started to work"
then no matter what option i choose, it would start scanning my computer.
i've tried scanning with ad-aware and malwarebytes now, both only found cookies.
OTL scan log:
OTL logfile created on: 9/27/2010 4:54:51 AM - Run 1
OTL by OldTimer - Version 3.2.14.1 Folder = C:\Documents and Settings\zhe\Desktop\New Folder (3)
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.00 Gb Total Physical Memory | 3.00 Gb Available Physical Memory | 84.00% Memory free
5.00 Gb Paging File | 5.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 108.51 Gb Total Space | 86.73 Gb Free Space | 79.93% Space Free | Partition Type: NTFS
Drive D: | 590.12 Gb Total Space | 262.56 Gb Free Space | 44.49% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ZHEE
Current User Name: zhe
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard
========== Processes (SafeList) ==========
PRC - [2010/09/27 04:45:35 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zhe\Desktop\New Folder (3)\OTL.com
PRC - [2010/02/18 12:49:40 | 000,357,448 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\GamePanel Software\LGDevAgt.exe
PRC - [2010/02/18 12:47:34 | 003,203,144 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
PRC - [2009/04/22 21:11:32 | 001,675,776 | ---- | M] (Flagship Industries, Inc.) -- C:\Program Files\Ventrilo\Ventrilo.exe
PRC - [2009/02/06 17:07:48 | 000,027,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Live\Contacts\wlcomm.exe
PRC - [2008/05/02 02:44:08 | 000,805,392 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\SetPoint.exe
PRC - [2008/05/02 02:40:56 | 000,076,304 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
PRC - [2008/04/14 00:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
========== Modules (SafeList) ==========
MOD - [2010/09/27 04:45:35 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\zhe\Desktop\New Folder (3)\OTL.com
MOD - [2009/07/12 01:12:06 | 000,632,656 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.VC80.CRT_1fc8b3b9a1e18e3b_8.0.50727.4053_x-ww_e6967989\msvcr80.dll
MOD - [2008/05/02 02:42:50 | 000,045,584 | ---- | M] (Logitech, Inc.) -- C:\Program Files\Logitech\SetPoint\lgscroll.dll
MOD - [2008/04/14 00:41:52 | 000,060,416 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\cabinet.dll
MOD - [2008/04/14 00:40:22 | 000,110,592 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\msscript.ocx
========== Win32 Services (SafeList) ==========
SRV - File not found [Disabled | Stopped] -- C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe -- (NMIndexingService)
SRV - [2010/03/01 16:38:11 | 001,029,456 | ---- | M] (Lavasoft) [Disabled | Stopped] -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe -- (Lavasoft Ad-Aware Service)
SRV - [2009/08/03 20:46:15 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [Disabled | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2009/06/22 10:48:16 | 000,170,736 | ---- | M] (Rogers) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\RpsSecurityAwareR.exe -- (Radialpoint Security Services)
SRV - [2009/06/22 10:47:20 | 000,371,440 | ---- | M] (Rogers) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\Fws.exe -- (RP_FWS)
SRV - [2008/11/18 12:18:38 | 000,262,144 | ---- | M] (ASUSTeK COMPUTER INC.) [Disabled | Stopped] -- C:\WINDOWS\ATKKBService.exe -- (ATKKeyboardService)
SRV - [2008/11/14 18:28:10 | 004,937,752 | R--- | M] (Sana Security) [Disabled | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Bin\SanaAgent.exe -- (RadialpointSafeConnectAgent)
SRV - [2008/09/22 16:58:48 | 000,910,600 | ---- | M] (Raxco Software, Inc.) [Disabled | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe -- (PD91Engine)
SRV - [2008/09/22 16:58:44 | 000,693,512 | ---- | M] (Raxco Software, Inc.) [Disabled | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe -- (PD91Agent)
SRV - [2008/05/02 02:42:06 | 000,121,360 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logitech\Bluetooth\LBTServ.exe -- (LBTServ)
SRV - [2008/03/27 10:17:38 | 000,055,816 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\GIGABYTE\GEST\GSvr.exe -- (GEST Service)
SRV - [2007/11/06 16:22:26 | 000,092,792 | ---- | M] (CACE Technologies) [Disabled | Stopped] -- C:\Program Files\WinPcap\rpcapd.exe -- (rpcapd) Remote Packet Capture Protocol v.0 (experimental)
SRV - [2007/09/04 19:25:44 | 000,131,072 | ---- | M] (NVIDIA) [Disabled | Running] -- C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe -- (nTuneService)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\vvftUVC.sys -- (vvftUVC)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\Drivers\VMUVC.sys -- (VMUVC)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\EagleNT.sys -- (EagleNT)
DRV - [2010/07/09 18:38:00 | 010,604,128 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv)
DRV - [2010/06/24 03:11:14 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\etdrv.sys -- (etdrv)
DRV - [2010/06/24 03:10:51 | 000,017,488 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\gdrv.sys -- (gdrv)
DRV - [2009/11/23 17:37:18 | 000,014,856 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LGVirHid.sys -- (LGVirHid)
DRV - [2009/11/23 17:37:08 | 000,019,720 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LGBusEnum.sys -- (LGBusEnum)
DRV - [2009/07/28 08:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009/06/02 06:02:46 | 005,085,184 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2009/04/03 14:51:32 | 000,179,984 | ---- | M] (Kaspersky Lab) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\klif.sys -- (KLIF)
DRV - [2009/02/23 00:16:22 | 000,007,168 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\GIGABYTE\ET6\i386\AODDriver.sys -- (AODDriver)
DRV - [2009/02/13 15:02:52 | 000,011,520 | R--- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\wdcsam.sys -- (WDC_SAM)
DRV - [2008/11/26 15:19:56 | 000,053,192 | ---- | M] (Radialpoint Inc.) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\rp_skt32.sys -- (RPSKT) Security Services Driver (x86)
DRV - [2008/11/18 12:18:40 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\asusgsb.sys -- (asusgsb)
DRV - [2008/11/18 12:18:40 | 000,010,752 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Video3D32.sys -- (Video3D)
DRV - [2008/11/18 12:18:38 | 000,011,136 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\atkkbnt.sys -- (asuskbnt)
DRV - [2008/11/14 18:28:36 | 000,161,304 | R--- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectDriver.sys -- (RadialpointSafeConnectDriver)
DRV - [2008/11/14 18:28:36 | 000,029,720 | R--- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectFilter.sys -- (RadialpointSafeConnectFilter)
DRV - [2008/11/14 18:28:36 | 000,027,376 | ---- | M] (Sana Security, Inc. ) [Kernel | On_Demand | Stopped] -- C:\Program Files\Rogers Online Protection\Rogers Online Protection\SafeConnect\Driver\platform_XP\SafeConnectShim.sys -- (RadialpointSafeConnectShim)
DRV - [2008/08/28 13:16:40 | 000,071,184 | ---- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\WINDOWS\System32\drivers\DefragFS.sys -- (DefragFS)
DRV - [2008/08/05 08:10:12 | 001,684,736 | ---- | M] (Creative) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Ambfilt.sys -- (Ambfilt)
DRV - [2008/04/14 00:15:14 | 000,060,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio) USB Audio Driver (WDM)
DRV - [2008/04/13 19:23:10 | 000,040,320 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\nmnt.sys -- (nm)
DRV - [2008/04/13 17:06:06 | 000,144,384 | ---- | M] (Windows (R) Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)
DRV - [2008/02/29 03:13:24 | 000,036,880 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LMouFilt.Sys -- (LMouFilt)
DRV - [2008/02/29 03:13:16 | 000,035,344 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LHidFilt.Sys -- (LHidFilt)
DRV - [2008/02/29 03:12:48 | 000,020,240 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\L8042Kbd.sys -- (L8042Kbd)
DRV - [2007/11/06 16:22:06 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\npf.sys -- (NPF)
DRV - [2007/10/11 11:10:52 | 000,030,008 | ---- | M] (Windows (R) 2000 DDK provider) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ET5Drv.sys -- (ET5Drv)
DRV - [2007/09/04 19:26:32 | 000,029,696 | ---- | M] (NVidia Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\nvoclock.sys -- (NVR0Dev)
DRV - [2007/01/29 17:12:52 | 000,018,432 | ---- | M] (ASUSTeK COMPUTER INC.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\AsusVRC.sys -- (ASUSVRC)
DRV - [2007/01/17 15:30:00 | 000,012,288 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Spyder2.sys -- (Spyder2)
DRV - [2006/11/22 08:01:00 | 000,250,496 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\yk51x86.sys -- (yukonwxp)
DRV - [2006/06/14 13:44:30 | 000,012,288 | R--- | M] (ASUSTeK Computer Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\EIO_XP.sys -- (EIO_XP)
DRV - [2006/03/28 17:56:06 | 000,027,008 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LHidKE.Sys -- (LHidKe)
DRV - [2006/03/28 17:55:58 | 000,069,760 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LMouKE.Sys -- (LMouKE)
DRV - [2006/03/28 17:55:04 | 000,055,808 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L8042MOU.SYS -- (L8042mou)
DRV - [2006/01/04 03:41:48 | 001,389,056 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\Monfilt.sys -- (Monfilt)
DRV - [2004/10/15 13:50:20 | 000,015,295 | ---- | M] (Brother Industries Ltd.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\BrScnUsb.sys -- (BrScnUsb)
DRV - [2004/05/27 11:47:16 | 000,019,968 | ---- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2004/05/21 15:16:14 | 000,471,232 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\lvcm.sys -- (QCMerced)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "www.google.ca"
FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.2
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/09/25 17:03:38 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.13\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/09/17 01:26:20 | 000,000,000 | ---D | M]
[2009/08/12 02:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Extensions
[2009/08/12 02:21:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Extensions\mozswing@mozswing.org
[2010/09/25 11:03:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions
[2010/04/27 15:04:29 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/03 14:54:24 | 000,000,000 | ---D | M] (BitComet Video Downloader) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{B042753D-F57E-4e8e-A01B-7379A6D4CEFB}
[2010/06/07 19:11:18 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Documents and Settings\zhe\Application Data\Mozilla\Firefox\Profiles\0kqmfyxs.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/09/25 11:03:32 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
[2009/07/17 04:40:12 | 000,704,512 | ---- | M] (BitComet) -- C:\Program Files\Mozilla Firefox\plugins\npBitCometAgent.dll
O1 HOSTS File: ([2007/08/11 02:58:33 | 000,000,768 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 mpa.one.microsoft.com
O2 - BHO: (AcroIEHlprObj Class) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (PopKill Class) - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Rogers Online Protection\Rogers Online Protection\pkR.dll (Rogers)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Kernel and Hardware Abstraction Layer] C:\WINDOWS\KHALMNPR.Exe (Logitech, Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LgDeviceAgent] C:\Program Files\Logitech\GamePanel Software\LgDevAgt.exe (Logitech Inc.)
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKCU..\Run: [NVIDIA nTune] C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe (NVIDIA)
O4 - HKCU..\Run: [YY] C:\Program Files\duowan\yy-2.0\Start.exe (广州多玩信息技术有限公司)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to existing PDF - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Computer, Inc.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\LBTWlgn: DllName - c:\program files\common files\logitech\bluetooth\LBTWlgn.dll - c:\Program Files\Common Files\Logitech\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\zhe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\zhe\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/08/03 05:28:05 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell - "" = AutoRun
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{7fe02cc2-2239-11df-b086-001d7d0bf9c8}\Shell\AutoRun\command - "" = G:\Startme.exe -- File not found
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell - "" = AutoRun
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a4090948-c06c-11de-9004-001d7d0bf9c8}\Shell\AutoRun\command - "" = G:\WD SmartWare.exe -- File not found
O34 - HKLM BootExecute: (PDBoot.exe) - C:\WINDOWS\System32\PDBoot.exe (Raxco Software, Inc.)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKCU\...exe [@ = exefile] -- Reg Error: Key error. File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/09/27 04:45:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder (3)
[2010/09/26 04:06:09 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/09/26 04:06:08 | 000,020,952 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys
[2010/09/26 04:06:08 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/09/26 04:05:40 | 006,153,352 | ---- | C] (Malwarebytes Corporation ) -- C:\Documents and Settings\zhe\Desktop\mbam-setup-1.46.exe
[2010/09/25 16:55:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder (2)
[2010/09/23 00:08:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Desktop\New Folder
[2010/09/16 22:27:56 | 000,007,552 | ---- | C] (Sony Corporation) -- C:\WINDOWS\System32\dllcache\sonypvu1.sys
[2010/09/08 00:01:47 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\LogiShrd
[2010/09/07 23:57:47 | 000,301,656 | ---- | C] (Broadcom Corporation.) -- C:\WINDOWS\System32\BtCoreIf.dll
[2010/09/07 23:57:29 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Logishrd
[2010/09/07 23:57:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\zhe\Application Data\InstallShield
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/09/27 04:54:22 | 002,384,160 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.dat
[2010/09/27 04:52:46 | 093,334,560 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.dat
[2010/09/27 04:28:55 | 004,980,736 | -H-- | M] () -- C:\Documents and Settings\zhe\NTUSER.DAT
[2010/09/27 04:14:45 | 000,000,507 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/09/27 04:14:45 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/09/27 04:14:45 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2010/09/27 03:45:43 | 000,000,069 | ---- | M] () -- C:\WINDOWS\NeroDigital.ini
[2010/09/26 15:45:52 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/09/26 15:45:38 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/09/26 15:45:35 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/09/26 15:44:25 | 001,256,756 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox.idx
[2010/09/26 15:44:25 | 000,231,464 | -HS- | M] () -- C:\WINDOWS\System32\drivers\fidbox2.idx
[2010/09/26 04:06:12 | 000,000,696 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/26 04:05:44 | 006,153,352 | ---- | M] (Malwarebytes Corporation ) -- C:\Documents and Settings\zhe\Desktop\mbam-setup-1.46.exe
[2010/09/26 03:47:56 | 003,171,036 | -H-- | M] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\IconCache.db
[2010/09/25 16:53:44 | 002,314,977 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\IMG_1350.jpg
[2010/09/25 15:39:33 | 000,000,472 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/09/25 02:29:02 | 001,534,701 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\IMG_1341.jpg
[2010/09/21 14:20:01 | 000,146,432 | ---- | M] () -- C:\Documents and Settings\zhe\Desktop\02+-+Chapter+01+%28part+2%29.ppt
[2010/09/13 20:29:57 | 000,170,496 | ---- | M] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/08 14:43:47 | 000,002,225 | ---- | M] () -- C:\Documents and Settings\zhe\Application Data\Microsoft\Internet Explorer\Quick Launch\Steam.lnk
[2010/09/07 23:58:45 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2010/09/07 23:58:41 | 000,000,000 | -H-- | M] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/09/07 23:57:47 | 000,001,687 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Logitech SetPoint.lnk
[3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/09/26 04:06:12 | 000,000,696 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/09/25 16:53:44 | 002,314,977 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\IMG_1350.jpg
[2010/09/25 02:29:02 | 001,534,701 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\IMG_1341.jpg
[2010/09/21 14:20:01 | 000,146,432 | ---- | C] () -- C:\Documents and Settings\zhe\Desktop\02+-+Chapter+01+%28part+2%29.ppt
[2010/09/07 23:58:45 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\Msft_Kernel_LMouFilt_01005.Wdf
[2010/09/07 23:58:41 | 000,000,000 | -H-- | C] () -- C:\WINDOWS\System32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
[2010/04/19 03:08:33 | 000,000,040 | ---- | C] () -- C:\WINDOWS\System32\Sx5363.ini
[2010/03/07 11:59:58 | 000,014,832 | -HS- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\fwSG76dUmwJ
[2010/02/18 22:01:56 | 000,002,072 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2010/01/09 10:08:15 | 000,000,410 | ---- | C] () -- C:\WINDOWS\BRWMARK.INI
[2010/01/09 10:06:57 | 000,000,114 | ---- | C] () -- C:\WINDOWS\System32\BRLMW03A.INI
[2009/10/18 18:04:33 | 000,000,069 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2009/10/11 16:05:38 | 000,000,025 | ---- | C] () -- C:\WINDOWS\libem.INI
[2009/09/08 18:24:32 | 000,000,000 | ---- | C] () -- C:\WINDOWS\mj.INI
[2009/08/10 19:58:59 | 000,024,944 | ---- | C] () -- C:\WINDOWS\System32\drivers\GVTDrv.sys
[2009/08/04 16:30:33 | 000,000,018 | ---- | C] () -- C:\WINDOWS\System32\atkid.ini
[2009/08/04 16:30:32 | 000,761,856 | ---- | C] () -- C:\WINDOWS\System32\xvidcore.dll
[2009/08/04 16:30:32 | 000,180,224 | ---- | C] () -- C:\WINDOWS\System32\xvidvfw.dll
[2009/08/04 16:30:32 | 000,046,592 | ---- | C] () -- C:\WINDOWS\System32\asfrench.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asrussian.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\asgerman.dll
[2009/08/04 16:30:32 | 000,046,080 | ---- | C] () -- C:\WINDOWS\System32\aseng.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\askorean.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\asjapan.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\ASCHT.dll
[2009/08/04 16:30:32 | 000,045,568 | ---- | C] () -- C:\WINDOWS\System32\aschs.dll
[2009/08/03 17:26:59 | 000,000,600 | ---- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\PUTTY.RND
[2009/08/03 15:42:31 | 000,170,496 | ---- | C] () -- C:\Documents and Settings\zhe\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/03 14:18:32 | 000,019,968 | ---- | C] () -- C:\WINDOWS\System32\drivers\LVUSBSta.sys
[2009/08/03 14:18:32 | 000,005,993 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2009/08/03 14:18:31 | 000,471,232 | ---- | C] () -- C:\WINDOWS\System32\drivers\lvcm.sys
[2009/08/03 14:18:11 | 000,000,252 | ---- | C] () -- C:\WINDOWS\_delis32.ini
[2009/08/03 14:06:18 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/08/03 05:50:06 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2009/08/03 05:48:59 | 000,034,816 | ---- | C] () -- C:\WINDOWS\System32\tasrtli.dll
[2008/10/14 16:09:12 | 000,005,504 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen_x86.sys
[2007/11/06 16:19:28 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007/03/12 12:01:30 | 000,217,088 | ---- | C] () -- C:\WINDOWS\NVGfxOgl.dll
[2007/02/13 18:16:04 | 000,012,288 | ---- | C] () -- C:\WINDOWS\System32\drivers\Spyder2.sys
[1999/01/27 13:39:06 | 000,065,024 | ---- | C] () -- C:\WINDOWS\System32\indounin.dll
[1997/06/13 07:56:08 | 000,056,832 | ---- | C] () -- C:\WINDOWS\System32\Iyvu9_32.dll
========== Custom Scans ==========
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\*.exe /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2009/08/03 01:16:56 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2009/08/03 01:16:56 | 001,089,536 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2009/08/03 01:16:56 | 000,942,080 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
< %systemroot%\system32\*.sys >
[2001/08/23 07:00:00 | 000,009,029 | ---- | M] () -- C:\WINDOWS\system32\ansi.sys
[2008/11/18 12:18:40 | 000,012,416 | ---- | M] (ASUSTeK Computer Inc.) -- C:\WINDOWS\system32\asusgsb.sys
[2001/08/23 07:00:00 | 000,027,097 | ---- | M] () -- C:\WINDOWS\system32\country.sys
[2001/08/23 07:00:00 | 000,004,768 | ---- | M] () -- C:\WINDOWS\system32\himem.sys
[2001/08/23 07:00:00 | 000,042,809 | ---- | M] () -- C:\WINDOWS\system32\key01.sys
[2008/04/13 17:20:56 | 000,042,537 | ---- | M] () -- C:\WINDOWS\system32\keyboard.sys
[2001/08/23 07:00:00 | 000,027,866 | ---- | M] () -- C:\WINDOWS\system32\ntdos.sys
[2001/08/23 07:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos404.sys
[2001/08/23 07:00:00 | 000,029,370 | ---- | M] () -- C:\WINDOWS\system32\ntdos411.sys
[2001/08/23 07:00:00 | 000,029,274 | ---- | M] () -- C:\WINDOWS\system32\ntdos412.sys
[2001/08/23 07:00:00 | 000,029,146 | ---- | M] () -- C:\WINDOWS\system32\ntdos804.sys
[2008/04/13 17:19:40 | 000,033,840 | ---- | M] () -- C:\WINDOWS\system32\ntio.sys
[2008/04/13 17:19:44 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio404.sys
[2008/04/13 17:19:40 | 000,035,648 | ---- | M] () -- C:\WINDOWS\system32\ntio411.sys
[2008/04/13 17:19:44 | 000,035,424 | ---- | M] () -- C:\WINDOWS\system32\ntio412.sys
[2008/04/13 17:19:42 | 000,034,560 | ---- | M] () -- C:\WINDOWS\system32\ntio804.sys
[2008/04/13 19:15:00 | 000,017,664 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\watchdog.sys
[2009/04/17 08:26:40 | 001,847,168 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\win32k.sys
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\system32\drivers\*.dll >
< %systemroot%\system32\drivers\*.ini >
< %systemroot%\system32\drivers\*.exe >
< %SYSTEMDRIVE%\*.* >
[2010/09/26 15:45:33 | 000,198,637 | ---- | M] () -- C:\aaw7boot.log
[2009/08/03 05:28:05 | 000,000,000 | ---- | M] () -- C:\AUTOEXEC.BAT
[2010/09/27 04:14:45 | 000,000,211 | -HS- | M] () -- C:\boot.ini
[2009/08/03 05:28:05 | 000,000,000 | ---- | M] () -- C:\CONFIG.SYS
[2009/08/03 05:28:05 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2009/08/03 14:16:25 | 000,000,090 | ---- | M] () -- C:\LogiSetup.log
[2009/08/03 05:28:05 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2008/04/13 17:13:04 | 000,047,564 | RHS- | M] () -- C:\NTDETECT.COM
[2008/04/13 19:01:44 | 000,250,048 | RHS- | M] () -- C:\ntldr
[2010/09/26 15:45:33 | 2145,386,496 | -HS- | M] () -- C:\pagefile.sys
[2009/08/03 19:50:26 | 000,000,122 | ---- | M] () -- C:\service.log
< %PROGRAMFILES%\*. >
[2009/09/01 14:28:04 | 000,000,000 | ---D | M] -- C:\Program Files\Acoustica MP3 Audio Mixer
[2010/07/31 19:14:08 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2009/10/18 17:34:18 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead
[2009/08/04 16:31:46 | 000,000,000 | ---D | M] -- C:\Program Files\ASUS
[2010/08/20 06:15:58 | 000,000,000 | ---D | M] -- C:\Program Files\BitComet
[2009/08/03 20:50:34 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010/01/09 10:18:20 | 000,000,000 | ---D | M] -- C:\Program Files\Brother
[2010/09/07 23:57:29 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2009/08/03 05:25:32 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010/07/30 04:26:31 | 000,000,000 | ---D | M] -- C:\Program Files\DivX
[2010/05/25 03:22:10 | 000,000,000 | ---D | M] -- C:\Program Files\duowan
[2010/04/19 03:08:33 | 000,000,000 | ---D | M] -- C:\Program Files\Gameforge4D
[2009/08/10 19:58:43 | 000,000,000 | ---D | M] -- C:\Program Files\GIGABYTE
[2010/02/27 09:55:14 | 000,000,000 | ---D | M] -- C:\Program Files\ImTOO
[2010/09/07 23:57:31 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2009/08/03 01:51:46 | 000,000,000 | ---D | M] -- C:\Program Files\Intel
[2009/08/03 02:24:44 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2009/08/10 16:38:44 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2009/08/08 15:37:02 | 000,000,000 | ---D | M] -- C:\Program Files\Lavasoft
[2009/08/12 02:21:07 | 000,000,000 | ---D | M] -- C:\Program Files\LimeWire
[2010/06/29 20:06:55 | 000,000,000 | ---D | M] -- C:\Program Files\Logitech
[2010/09/26 04:06:12 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/08/10 05:18:41 | 000,000,000 | ---D | M] -- C:\Program Files\Marvell
[2009/08/03 02:05:50 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2009/09/15 21:15:58 | 000,000,000 | ---D | M] -- C:\Program Files\Microsoft
[2009/08/03 05:28:22 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2009/08/03 05:26:31 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2010/09/27 04:28:59 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2009/08/03 02:25:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2009/08/03 05:24:39 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2009/08/03 05:25:14 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2009/08/17 19:20:30 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2009/08/04 16:27:15 | 000,000,000 | ---D | M] -- C:\Program Files\My Company Name
[2009/10/18 16:41:45 | 000,000,000 | ---D | M] -- C:\Program Files\Nero
[2009/08/03 05:26:44 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010/01/09 10:05:38 | 000,000,000 | ---D | M] -- C:\Program Files\Nuance
[2010/08/20 17:00:53 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA Corporation
[2010/06/28 03:31:07 | 000,000,000 | ---D | M] -- C:\Program Files\NVIDIA nTune Performance Application
[2009/08/03 05:25:22 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2009/08/17 19:21:42 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010/04/25 18:11:02 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTax 2009
[2009/09/06 23:39:18 | 000,000,000 | ---D | M] -- C:\Program Files\Raxco
[2009/08/03 05:50:05 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2009/08/03 02:25:27 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2010/02/22 17:49:50 | 000,000,000 | ---D | M] -- C:\Program Files\Rogers Online Protection
[2010/02/25 02:37:33 | 000,000,000 | ---D | M] -- C:\Program Files\Sony Ericsson
[2010/09/10 12:59:38 | 000,000,000 | ---D | M] -- C:\Program Files\Steam
[2010/04/30 05:58:04 | 000,000,000 | ---D | M] -- C:\Program Files\Subagames
[2009/08/03 05:31:41 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2009/08/03 14:06:34 | 000,000,000 | ---D | M] -- C:\Program Files\Ventrilo
[2009/08/03 15:22:04 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2010/09/25 11:36:23 | 000,000,000 | ---D | M] -- C:\Program Files\Warcraft III
[2009/08/03 14:33:17 | 000,000,000 | ---D | M] -- C:\Program Files\Winamp
[2009/09/15 21:15:53 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live
[2010/09/23 15:49:42 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live Safety Center
[2009/09/15 21:15:43 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Live SkyDrive
[2009/08/03 02:23:41 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2009/08/03 02:23:41 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2009/08/03 05:25:06 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2009/08/03 05:27:12 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2009/09/02 04:02:39 | 000,000,000 | ---D | M] -- C:\Program Files\WinPcap
[2009/08/03 21:33:23 | 000,000,000 | ---D | M] -- C:\Program Files\WinRAR
[2009/08/03 05:28:22 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< %appdata%\*.* >
[2009/08/03 01:20:07 | 000,000,062 | -HS- | M] () -- C:\Documents and Settings\zhe\Application Data\desktop.ini
< MD5 for: AGP440.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/13 19:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0006\DriverFiles\i386\atapi.sys
[2008/04/14 00:10:32 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\system32\ReinstallBackups\0007\DriverFiles\i386\atapi.sys
< MD5 for: DISK.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:disk.sys
[2008/04/13 19:10:48 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\system32\drivers\disk.sys
< MD5 for: EVENTLOG.DLL >
[2008/04/14 00:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 00:41:54 | 000,056,320 | ---- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: NETLOGON.DLL >
[2008/04/14 00:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 00:42:02 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: SCECLI.DLL >
[2008/04/14 00:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 00:42:06 | 000,181,248 | ---- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 -- C:\WINDOWS\system32\scecli.dll
< MD5 for: USBSTOR.SYS >
[2008/04/14 00:51:44 | 020,056,462 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp3.cab:usbstor.sys
[2008/04/14 00:15:40 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\dllcache\usbstor.sys
[2008/04/14 00:15:40 | 000,026,368 | ---- | M] (Microsoft Corporation) MD5=A32426D9B14A089EAA1D922E0C5801A9 -- C:\WINDOWS\system32\drivers\USBSTOR.SYS
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2009-08-03 06:17:28
========== Files - Unicode (All) ==========
[2009/09/06 23:40:13 | 000,000,040 | ---- | M] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
[2009/09/06 23:40:13 | 000,000,040 | ---- | C] ()(C:\WINDOWS\System32\?????????????????????????????????????????????????) -- C:\WINDOWS\System32\㩃停潲牧浡䘠汩獥剜杯牥湏楬敮倠潲整瑣潩屮潒敧獲传汮湩牐瑯捥楴湯卜晡䍥湯敮瑣䍜湯楦屧噘敩潣普杩
< End of report >