This is part 1/2 since the logs are to long and I am not able to enter all in one post.
Hi,
A friend of mine got great help from you guys, it's why I am trying my luck!
Here's my problem. Usually, I don't have any trouble protecting myself since I am very aware of what not to do to get infected. But this computer is used mainly by my wife and my 4 kids. Maybe they done something...! My system hangs randomly since 2-3 weeks. It started as trouble to reach our file server (ip conflict). Reparing of the network connection usually does the job. If not, reboting the router would be the answer. But now, the computer is acting weird. Time to time, I ear the inside speaker giving a beep like when the old antivirus was warning ourselves that there was somethings wrong. After that, I can't open anything. The system is running, but any program I try to open just doesn't work. I am also redirected to "www.quizfinddomain.com" time to time. If I try to open the run command, the keyboard seam very very slow. I can restart the computer in safe mode with networking and everythings work fine for a long period.
I tried to restore to many older points, but none of them worked.
I passed many tools (avira, antimalwarebyte, spybot, combofix, housecall) and cleaned a little bit with hijackthis. I did remove a lot of trojan/virus, but I seem to get the same problems (system working for a while, but as soon as nobody is using it, we can't start anything.
During those last weeks, someone called many times with the phone number "unavailable". It was always haging before I could talked to someone. But on aug 22, I got the call again and the guy told me he was calling from microsoft to help me fix my computer. I laughed and I asked many questions about my personnal info (wich computer was under problem (I have 5), wich version of windows, my validation key, my activation date). Anyway, of course he did not have any of those info, but he had my ip and adress and telephone. I asked a number where I can call back, and he gave me 315-636-0916 (wich is bad) and he passed me his supervisor. He told me the compagny was working in conjunction with microsoft and it's why he did not have any more info about my system. The compagny is www.microsystemtech.com He wanted me click run and enter some commands. I laughed and he cut the line! What a scam... Good things my wife did not got the call! Since then , I am more worried about fixing this computer.
I was to reformat and reinstall windows, but maybe you can help me? Thanks so much in advance, here are my logs. Note that I was able to get everything except extras.txt. But I got only this one while running in safemode, it's still fine?
OTL logfile created on: 2011-08-25 09:55:53 - Run 3
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Yanick\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
3,25 Gb Total Physical Memory | 2,35 Gb Available Physical Memory | 72,47% Memory free
5,09 Gb Paging File | 4,17 Gb Available in Paging File | 81,93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465,75 Gb Total Space | 399,00 Gb Free Space | 85,67% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive E: | 4,06 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: CUISINE | User Name: Yanick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-08-25 08:38:45 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
PRC - [2011-06-28 13:59:17 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011-04-27 12:24:07 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010-11-02 09:16:41 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010-05-21 00:58:48 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010-05-21 00:58:46 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2010-01-14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009-03-25 18:07:10 | 000,926,720 | ---- | M] (LX London) -- C:\BandwidthMeter\BandwidthMeter.exe
PRC - [2009-03-05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2006-07-12 05:58:02 | 001,397,760 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2005-07-08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2004-11-02 21:24:46 | 000,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
PRC - [2004-08-03 18:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011-03-21 17:30:06 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010-10-14 11:38:39 | 011,797,504 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
MOD - [2010-10-14 11:37:50 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010-10-14 11:37:46 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll
MOD - [2010-10-14 09:16:08 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010-10-14 09:16:04 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010-10-14 09:15:56 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010-10-14 09:15:07 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2010-10-14 09:15:03 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2010-10-14 09:12:52 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2010-08-25 21:44:50 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010-08-10 00:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010-08-04 15:58:06 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2010-05-04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2010-03-16 12:22:12 | 000,014,848 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
MOD - [2010-01-28 13:57:58 | 000,355,688 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
========== Win32 Services (SafeList) ==========
SRV - [2011-06-28 13:59:17 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011-04-27 12:24:07 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010-07-01 11:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Disabled | Stopped] -- C:\Documents and Settings\Yanick\Application Data\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
SRV - [2010-03-04 23:38:00 | 000,071,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2005-07-08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
========== Driver Services (SafeList) ==========
DRV - [2011-06-28 13:59:17 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011-06-28 13:59:17 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011-04-28 22:16:24 | 000,580,096 | ---- | M] (Line 6) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L6PODHD5.sys -- (L6PODHD5)
DRV - [2011-02-15 23:29:39 | 000,094,208 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ezplay.sys -- (ezplay)
DRV - [2010-08-25 23:33:38 | 005,386,752 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010-01-11 18:00:10 | 002,106,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009-11-12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009-07-28 16:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009-05-11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009-05-11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008-06-01 03:13:10 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2007-05-09 22:51:34 | 000,041,888 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007-05-09 22:47:00 | 001,276,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007-02-06 09:27:02 | 000,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) [23|25|26]xxx) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcwPP2.sys -- (hcwPP2)
DRV - [2006-07-12 05:58:02 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005-12-18 20:42:12 | 000,008,801 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\DScaler\DSDrv4.sys -- (DSDrv4)
DRV - [2005-07-08 18:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005-07-08 18:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2166.3772\npCIDetect14.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Yanick\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Yanick\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Yanick\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Yanick\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-06-23 08:05:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-03 21:08:41 | 000,000,000 | ---D | M]
[2011-08-23 16:23:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Yanick\Application Data\Mozilla\Extensions
[2011-05-03 08:40:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010-10-11 08:07:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) --
[2010-10-11 08:07:49 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011-03-02 04:01:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011-06-23 08:05:06 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010-10-11 08:07:49 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011-06-23 08:05:04 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2011-06-23 08:05:04 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011-06-23 08:05:04 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2011-06-23 08:05:04 | 000,001,154 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2011-06-23 08:05:04 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2011-06-23 08:05:04 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
Hosts file not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [ShaPlus Bandwidth Meter] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bandwidth Meter.lnk = C:\WINDOWS\Installer\{297849A8-EEC6-4ABA-AAE5-C66A093FEDE3}\_4AFD87D2B7DF2077867725.exe ()
O4 - Startup: C:\Documents and Settings\Yanick\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {13149882-F480-4F6B-8C6A-0764F75B99ED} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.200.241.37 24.200.243.189 24.201.245.77
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Yanick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-10-10 22:51:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-08-25 08:59:16 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-25 08:38:45 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
[2011-08-25 08:34:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011-08-23 16:23:59 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011-08-23 16:06:31 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011-08-23 08:01:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2011-08-23 07:59:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011-08-11 13:10:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Mozilla
[2011-08-11 09:16:44 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011-08-11 09:05:44 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2011-08-11 09:01:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011-08-11 08:51:56 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011-08-11 08:44:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011-08-11 08:44:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011-08-11 08:44:46 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011-08-11 08:44:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011-08-11 08:44:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011-08-11 08:44:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-08-11 08:44:10 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\Administrative Tools
[2011-08-11 08:43:43 | 004,170,012 | R--- | C] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-11 00:42:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011-08-11 00:37:29 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011-08-11 00:37:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\HiJackThis
[2011-08-08 14:01:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011-08-08 14:01:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011-08-08 14:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Tysu
[2011-08-08 14:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Agdak
[2011-08-06 07:38:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011-07-28 08:05:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Yanick\My Documents\Dropbox
[2011-07-28 08:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\Dropbox
[2011-07-28 08:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Dropbox
[2011-02-15 23:29:39 | 000,094,208 | ---- | C] (VSO Software) -- C:\Documents and Settings\Yanick\Application Data\ezplay.sys
[2010-10-10 23:30:03 | 000,254,000 | ---- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
[2010-10-10 23:30:03 | 000,254,000 | ---- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-08-25 09:11:13 | 000,001,152 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-412668190-725345543-1003UA.job
[2011-08-25 09:09:44 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-08-25 09:02:48 | 000,879,225 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-08-25 09:01:42 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\MBR.dat
[2011-08-25 08:59:23 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-25 08:54:19 | 000,440,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-08-25 08:54:19 | 000,071,002 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-08-25 08:50:26 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011-08-25 08:50:05 | 000,002,181 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bandwidth Meter.lnk
[2011-08-25 08:49:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-08-25 08:38:45 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
[2011-08-25 07:37:54 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-08-23 19:11:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-412668190-725345543-1003Core.job
[2011-08-23 17:59:10 | 000,415,161 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\census.cache
[2011-08-23 17:59:09 | 000,193,845 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\ars.cache
[2011-08-11 17:33:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011-08-11 11:50:30 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\housecall.guid.cache
[2011-08-11 09:18:45 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-08-11 08:52:00 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011-08-11 08:43:47 | 004,170,012 | R--- | M] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-11 07:53:25 | 000,000,137 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011-08-11 00:37:29 | 000,001,986 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\HiJackThis.lnk
[2011-08-11 00:27:43 | 000,000,294 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2011-08-11 00:24:12 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Akejupodo.bin
[2011-08-11 00:24:11 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wwoqurixuqu.dat
[2011-08-11 00:23:38 | 000,022,572 | ---- | M] () -- C:\Documents and Settings\Yanick\Application Data\EF76.7AC
[2011-08-06 07:38:08 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011-08-06 07:37:05 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
[2011-08-02 10:39:09 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\switchDowngrade.job
[2011-07-30 22:33:52 | 000,059,347 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\yanreg.pdf
[2011-07-30 22:32:35 | 000,059,293 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\yanick2000.pdf
[2011-07-28 08:05:12 | 000,000,999 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\Dropbox.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-08-25 09:02:47 | 000,879,225 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-08-25 09:01:42 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\MBR.dat
[2011-08-11 11:55:56 | 000,415,161 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\census.cache
[2011-08-11 11:55:42 | 000,193,845 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\ars.cache
[2011-08-11 11:50:30 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\housecall.guid.cache
[2011-08-11 08:52:00 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011-08-11 08:51:57 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011-08-11 08:44:46 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011-08-11 08:44:46 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011-08-11 08:44:46 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011-08-11 08:44:46 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011-08-11 08:44:46 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-08-11 00:37:29 | 000,001,986 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\HiJackThis.lnk
[2011-08-11 00:27:43 | 000,000,294 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2011-08-08 13:51:01 | 000,022,572 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\EF76.7AC
[2011-08-06 07:38:08 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011-08-06 07:36:25 | 021,073,936 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
[2011-07-30 22:33:52 | 000,059,347 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\yanreg.pdf
[2011-07-30 22:32:35 | 000,059,293 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\yanick2000.pdf
[2011-07-28 08:05:12 | 000,000,999 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\Dropbox.lnk
[2011-07-01 12:59:43 | 000,000,358 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2011-05-24 20:57:02 | 000,000,137 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011-05-22 16:21:48 | 000,015,958 | -HS- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\mssfsi1vlq8g1bx8lmkcbl8
[2011-05-22 16:21:48 | 000,015,958 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\mssfsi1vlq8g1bx8lmkcbl8
[2011-04-14 16:59:26 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Wwoqurixuqu.dat
[2011-04-14 16:59:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Akejupodo.bin
[2011-02-15 23:29:39 | 000,007,861 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.cat
[2011-02-15 23:29:39 | 000,001,103 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.inf
[2011-02-15 23:29:39 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.ini
[2011-01-07 00:20:16 | 000,019,528 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-01-03 14:56:18 | 000,000,109 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2010-11-16 22:21:49 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-11-16 22:00:39 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2010-11-12 21:40:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2010-11-06 16:17:37 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010-11-02 20:51:03 | 000,029,696 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-10-30 09:10:02 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\fusioncache.dat
[2010-10-28 16:32:26 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010-10-11 00:13:39 | 000,007,342 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2010-10-11 00:12:33 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2010-10-10 23:34:46 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2010-10-10 23:26:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-10-10 23:26:22 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2010-10-10 23:26:22 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe
[2010-10-10 23:26:22 | 000,219,348 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010-10-10 23:26:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe
[2010-10-10 23:26:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010-10-10 23:18:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010-10-10 23:14:39 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010-10-10 22:53:39 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-10-10 22:48:55 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-10-10 18:42:23 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-10-10 18:37:08 | 000,123,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008-06-01 03:13:10 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007-05-09 21:35:54 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2004-08-03 19:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004-08-02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004-07-17 05:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-08-23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-08-23 11:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-08-23 11:00:00 | 000,440,684 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-08-23 11:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-08-23 11:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-08-23 11:00:00 | 000,071,002 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-08-23 11:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-08-23 11:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-08-23 11:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
[2011-08-25 08:59:23 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-11 08:43:47 | 004,170,012 | R--- | M] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-25 09:02:48 | 000,879,225 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-06-16 21:13:25 | 021,022,914 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\vlc-1.1.10-win32.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
[2011-08-06 07:37:05 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2011-06-23 08:05:06 | 000,125,912 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2011-06-23 08:05:04 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2011-06-23 08:05:04 | 000,265,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2010-10-12 07:28:56 | 000,000,000 | ---D | M] -- C:\Program Files\7-Zip
[2010-12-02 10:09:30 | 000,000,000 | ---D | M] -- C:\Program Files\Activision
[2010-10-12 09:40:10 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010-11-16 22:03:00 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead
[2011-07-05 10:07:51 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010-10-10 23:26:48 | 000,000,000 | ---D | M] -- C:\Program Files\ATI
[2010-10-10 23:26:40 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2010-11-02 09:44:37 | 000,000,000 | ---D | M] -- C:\Program Files\Avery Dennison
[2010-10-10 23:33:25 | 000,000,000 | ---D | M] -- C:\Program Files\Avira
[2011-04-28 08:53:20 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010-10-28 16:32:27 | 000,000,000 | ---D | M] -- C:\Program Files\CDBurnerXP
[2011-08-11 08:56:12 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2010-10-10 22:48:42 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010-11-16 22:01:09 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2010-11-16 22:01:59 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink DVD Solution
[2010-10-11 00:24:39 | 000,000,000 | ---D | M] -- C:\Program Files\Devnz
[2011-08-25 07:47:32 | 000,000,000 | ---D | M] -- C:\Program Files\DScaler
[2011-02-15 23:27:01 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Shrink
[2010-10-14 09:26:57 | 000,000,000 | ---D | M] -- C:\Program Files\EASEUS
[2010-11-30 22:11:08 | 000,000,000 | ---D | M] -- C:\Program Files\Elaborate Bytes
[2011-01-04 19:31:29 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2011-02-01 23:24:38 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2011-02-15 23:25:48 | 000,000,000 | ---D | M] -- C:\Program Files\ImgBurn
[2011-04-05 08:44:56 | 000,000,000 | ---D | M] -- C:\Program Files\ImpotExpert 2010
[2010-11-16 22:01:59 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2010-10-14 03:01:57 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2011-06-30 21:28:46 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2011-06-30 21:29:23 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010-10-11 08:07:47 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010-10-11 08:08:09 | 000,000,000 | ---D | M] -- C:\Program Files\JRE
[2011-06-11 18:56:17 | 000,000,000 | ---D | M] -- C:\Program Files\Kutoka
[2011-05-24 10:40:36 | 000,000,000 | ---D | M] -- C:\Program Files\Line6
[2011-08-11 09:18:45 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-10-11 00:42:28 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2010-10-10 22:52:13 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010-10-11 00:33:28 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011-08-25 09:12:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010-10-14 03:03:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010-10-10 22:47:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2010-10-10 22:48:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2011-03-24 03:00:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010-10-14 03:01:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2010-10-28 08:32:06 | 000,000,000 | ---D | M] -- C:\Program Files\NCH Swift Sound
[2010-10-10 22:50:03 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010-10-19 08:23:25 | 000,000,000 | ---D | M] -- C:\Program Files\OneSwarm
[2010-10-10 22:48:27 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010-10-11 08:08:08 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 3
[2010-10-11 01:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010-10-16 17:46:03 | 000,000,000 | ---D | M] -- C:\Program Files\PlayPianoTODAY
[2010-12-25 12:47:03 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2010-10-10 23:14:38 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2010-10-14 03:03:08 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2011-06-30 21:24:06 | 000,000,000 | ---D | M] -- C:\Program Files\Safari
[2011-05-24 20:40:04 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2011-01-06 22:53:26 | 000,000,000 | ---D | M] -- C:\Program Files\Tansee iPhone Transfer Contact
[2011-08-11 00:37:29 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010-10-30 08:45:13 | 000,000,000 | ---D | M] -- C:\Program Files\Turbine
[2010-10-10 22:55:27 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010-10-10 23:35:19 | 000,000,000 | ---D | M] -- C:\Program Files\VIA
[2010-11-02 20:52:37 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2011-02-15 23:29:30 | 000,000,000 | ---D | M] -- C:\Program Files\VSO
[2010-10-10 23:47:45 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2010-10-11 00:07:17 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2010-10-10 22:48:06 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2010-10-10 22:51:01 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2010-11-16 09:46:51 | 000,000,000 | ---D | M] -- C:\Program Files\WinPcap
[2010-10-11 00:14:14 | 000,000,000 | ---D | M] -- C:\Program Files\WinTV
[2010-10-10 22:52:13 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< MD5 for: AGP440.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008-04-13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
< MD5 for: ATAPI.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008-04-13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004-08-03 16:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004-08-03 16:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: DISK.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2004-08-03 16:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008-04-13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\disk.sys
< MD5 for: NETLOGON.DLL >
[2008-04-13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2009-02-06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009-02-06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-11 04:27:44
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2004-08-03 18:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2004-08-03 18:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
< End of report >
Rest of logs in part 2/2 on anothe message
Hi,
A friend of mine got great help from you guys, it's why I am trying my luck!
Here's my problem. Usually, I don't have any trouble protecting myself since I am very aware of what not to do to get infected. But this computer is used mainly by my wife and my 4 kids. Maybe they done something...! My system hangs randomly since 2-3 weeks. It started as trouble to reach our file server (ip conflict). Reparing of the network connection usually does the job. If not, reboting the router would be the answer. But now, the computer is acting weird. Time to time, I ear the inside speaker giving a beep like when the old antivirus was warning ourselves that there was somethings wrong. After that, I can't open anything. The system is running, but any program I try to open just doesn't work. I am also redirected to "www.quizfinddomain.com" time to time. If I try to open the run command, the keyboard seam very very slow. I can restart the computer in safe mode with networking and everythings work fine for a long period.
I tried to restore to many older points, but none of them worked.
I passed many tools (avira, antimalwarebyte, spybot, combofix, housecall) and cleaned a little bit with hijackthis. I did remove a lot of trojan/virus, but I seem to get the same problems (system working for a while, but as soon as nobody is using it, we can't start anything.
During those last weeks, someone called many times with the phone number "unavailable". It was always haging before I could talked to someone. But on aug 22, I got the call again and the guy told me he was calling from microsoft to help me fix my computer. I laughed and I asked many questions about my personnal info (wich computer was under problem (I have 5), wich version of windows, my validation key, my activation date). Anyway, of course he did not have any of those info, but he had my ip and adress and telephone. I asked a number where I can call back, and he gave me 315-636-0916 (wich is bad) and he passed me his supervisor. He told me the compagny was working in conjunction with microsoft and it's why he did not have any more info about my system. The compagny is www.microsystemtech.com He wanted me click run and enter some commands. I laughed and he cut the line! What a scam... Good things my wife did not got the call! Since then , I am more worried about fixing this computer.
I was to reformat and reinstall windows, but maybe you can help me? Thanks so much in advance, here are my logs. Note that I was able to get everything except extras.txt. But I got only this one while running in safemode, it's still fine?
OTL logfile created on: 2011-08-25 09:55:53 - Run 3
OTL by OldTimer - Version 3.2.26.5 Folder = C:\Documents and Settings\Yanick\Desktop
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000C0C | Country: Canada | Language: FRC | Date Format: yyyy-MM-dd
3,25 Gb Total Physical Memory | 2,35 Gb Available Physical Memory | 72,47% Memory free
5,09 Gb Paging File | 4,17 Gb Available in Paging File | 81,93% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 465,75 Gb Total Space | 399,00 Gb Free Space | 85,67% Space Free | Partition Type: NTFS
Unable to calculate disk information.
Drive E: | 4,06 Gb Total Space | 0,00 Gb Free Space | 0,00% Space Free | Partition Type: UDF
Computer Name: CUISINE | User Name: Yanick | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011-08-25 08:38:45 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
PRC - [2011-06-28 13:59:17 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011-04-27 12:24:07 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2010-11-02 09:16:41 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010-05-21 00:58:48 | 011,312,128 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010-05-21 00:58:46 | 011,318,784 | ---- | M] (OpenOffice.org) -- C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2010-01-14 22:11:00 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2009-03-25 18:07:10 | 000,926,720 | ---- | M] (LX London) -- C:\BandwidthMeter\BandwidthMeter.exe
PRC - [2009-03-05 16:07:20 | 002,260,480 | RHS- | M] (Safer-Networking Ltd.) -- C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
PRC - [2006-07-12 05:58:02 | 001,397,760 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCD.exe
PRC - [2005-07-08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) -- C:\Program Files\Ahead\InCD\InCDsrv.exe
PRC - [2004-11-02 21:24:46 | 000,032,768 | ---- | M] (Cyberlink Corp.) -- C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe
PRC - [2004-08-03 18:56:50 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
========== Modules (No Company Name) ==========
MOD - [2011-03-21 17:30:06 | 001,241,888 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010-10-14 11:38:39 | 011,797,504 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Web\d987cf1de4ba688da92e212a374232c2\System.Web.ni.dll
MOD - [2010-10-14 11:37:50 | 000,971,264 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Configuration\631b3eba1ba5bd3c3f027f34011cadeb\System.Configuration.ni.dll
MOD - [2010-10-14 11:37:46 | 000,025,600 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\Accessibility\e63d6d26b8a664cfdfbd4ad75e03c14d\Accessibility.ni.dll
MOD - [2010-10-14 09:16:08 | 005,450,752 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Xml\563a54b98adb70fae862974042298348\System.Xml.ni.dll
MOD - [2010-10-14 09:16:04 | 012,430,848 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\2dfe045e4b1577fdea9a2f456db0afc2\System.Windows.Forms.ni.dll
MOD - [2010-10-14 09:15:56 | 001,587,200 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System.Drawing\f3440ea00eb3c40dc073b2fe03843638\System.Drawing.ni.dll
MOD - [2010-10-14 09:15:07 | 007,949,824 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\System\37217abe2c5164e59aba251860f4c79e\System.ni.dll
MOD - [2010-10-14 09:15:03 | 011,486,720 | ---- | M] () -- C:\WINDOWS\assembly\NativeImages_v2.0.50727_32\mscorlib\7124a40b9998f7b63c86bd1a2125ce26\mscorlib.ni.dll
MOD - [2010-10-14 09:12:52 | 000,303,104 | ---- | M] () -- C:\WINDOWS\assembly\GAC_MSIL\System.Runtime.Remoting\2.0.0.0__b77a5c561934e089\System.Runtime.Remoting.dll
MOD - [2010-08-25 21:44:50 | 000,270,336 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2010-08-10 00:01:06 | 000,067,872 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2010-08-04 15:58:06 | 000,016,384 | R--- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2010-05-04 15:36:28 | 000,970,752 | ---- | M] () -- C:\Program Files\OpenOffice.org 3\program\libxml2.dll
MOD - [2010-03-16 12:22:12 | 000,014,848 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\AxInterop.WBOCXLib.dll
MOD - [2010-01-28 13:57:58 | 000,355,688 | ---- | M] () -- C:\Program Files\Avira\AntiVir Desktop\sqlite3.dll
========== Win32 Services (SafeList) ==========
SRV - [2011-06-28 13:59:17 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2011-04-27 12:24:07 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2010-07-01 11:38:26 | 000,083,512 | ---- | M] (ArcSoft, Inc.) [Disabled | Stopped] -- C:\Documents and Settings\Yanick\Application Data\HP SimpleSave Application\uUACTokenSvc.exe -- (BackupService)
SRV - [2010-03-04 23:38:00 | 000,071,096 | ---- | M] () [Disabled | Stopped] -- C:\Program Files\CDBurnerXP\NMSAccessU.exe -- (NMSAccess)
SRV - [2005-07-08 18:24:46 | 000,871,424 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Ahead\InCD\InCDsrv.exe -- (InCDsrv)
========== Driver Services (SafeList) ==========
DRV - [2011-06-28 13:59:17 | 000,138,192 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011-06-28 13:59:17 | 000,066,616 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2011-04-28 22:16:24 | 000,580,096 | ---- | M] (Line 6) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\L6PODHD5.sys -- (L6PODHD5)
DRV - [2011-02-15 23:29:39 | 000,094,208 | ---- | M] (VSO Software) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ezplay.sys -- (ezplay)
DRV - [2010-08-25 23:33:38 | 005,386,752 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2010-01-11 18:00:10 | 002,106,880 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2009-11-12 14:48:56 | 000,007,168 | ---- | M] () [File_System | On_Demand | Stopped] -- C:\WINDOWS\System32\drivers\StarOpen.sys -- (StarOpen)
DRV - [2009-07-28 16:55:00 | 000,143,360 | ---- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Rtenicxp.sys -- (RTLE8023xp)
DRV - [2009-05-11 12:49:19 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2009-05-11 10:12:49 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2008-06-01 03:13:10 | 000,034,064 | ---- | M] (CACE Technologies) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\npf.sys -- (npf)
DRV - [2007-07-20 18:40:10 | 000,084,992 | ---- | M] (ATI Research Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\AtiHdmi.sys -- (AtiHdmiService)
DRV - [2007-05-09 22:51:34 | 000,041,888 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LVUSBSta.sys -- (LVUSBSta)
DRV - [2007-05-09 22:47:00 | 001,276,832 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\LV302V32.SYS -- (PID_PEPI) Logitech QuickCam IM(PID_PEPI)
DRV - [2007-02-06 09:27:02 | 000,185,728 | ---- | M] (Hauppauge Computer Works, Inc.) [23|25|26]xxx) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hcwPP2.sys -- (hcwPP2)
DRV - [2006-07-12 05:58:02 | 000,028,672 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\System32\drivers\InCDrm.sys -- (incdrm)
DRV - [2005-12-18 20:42:12 | 000,008,801 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files\DScaler\DSDrv4.sys -- (DSDrv4)
DRV - [2005-07-08 18:17:54 | 000,099,584 | ---- | M] (Nero AG) [File_System | Disabled | Running] -- C:\WINDOWS\System32\drivers\InCDfs.sys -- (InCDfs)
DRV - [2005-07-08 18:17:36 | 000,029,696 | ---- | M] (Nero AG) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\InCDpass.sys -- (InCDPass)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\WINDOWS\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\WINDOWS\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pack.google.com/Google Updater;version=14: C:\Program Files\Google\Google Updater\2.4.2166.3772\npCIDetect14.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Documents and Settings\Yanick\Application Data\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Documents and Settings\Yanick\Application Data\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Documents and Settings\Yanick\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Documents and Settings\Yanick\Local Settings\Application Data\Google\Update\1.3.21.65\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011-06-23 08:05:07 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 5.0\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011-05-03 21:08:41 | 000,000,000 | ---D | M]
[2011-08-23 16:23:57 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Yanick\Application Data\Mozilla\Extensions
[2011-05-03 08:40:03 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010-10-11 08:07:56 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
File not found (No name found) --
[2010-10-11 08:07:49 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2011-03-02 04:01:05 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
[2011-06-23 08:05:06 | 000,142,296 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2010-10-11 08:07:49 | 000,411,368 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\mozilla firefox\plugins\npdeployJava1.dll
[2011-06-23 08:05:04 | 000,001,516 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazon-france.xml
[2011-06-23 08:05:04 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2011-06-23 08:05:04 | 000,001,822 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\cnrtl-tlfi-fr.xml
[2011-06-23 08:05:04 | 000,001,154 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-france.xml
[2011-06-23 08:05:04 | 000,001,426 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-fr.xml
[2011-06-23 08:05:04 | 000,000,956 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-france.xml
Hosts file not found
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe (Nero AG)
O4 - HKLM..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe (Ahead Software Gmbh)
O4 - HKLM..\Run: [RemoteControl] C:\Program Files\CyberLink DVD Solution\PowerDVD\PDVDServ.exe (Cyberlink Corp.)
O4 - HKLM..\Run: [ShaPlus Bandwidth Meter] File not found
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bandwidth Meter.lnk = C:\WINDOWS\Installer\{297849A8-EEC6-4ABA-AAE5-C66A093FEDE3}\_4AFD87D2B7DF2077867725.exe ()
O4 - Startup: C:\Documents and Settings\Yanick\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {13149882-F480-4F6B-8C6A-0764F75B99ED} Reg Error: Value error. (Reg Error: Key error.)
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://go.microsoft.com/fwlink/?linkid=39204 (Windows Genuine Advantage Validation Tool)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 24.200.241.37 24.200.243.189 24.201.245.77
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\WINDOWS\system32\userinit.exe) - C:\WINDOWS\system32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper:
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Yanick\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010-10-10 22:51:58 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011-08-25 08:59:16 | 001,916,416 | ---- | C] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-25 08:38:45 | 000,580,096 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
[2011-08-25 08:34:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2011-08-23 16:23:59 | 000,000,000 | -H-D | C] -- C:\WINDOWS\System32\GroupPolicy
[2011-08-23 16:06:31 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2011-08-23 08:01:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Sun
[2011-08-23 07:59:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Macromedia
[2011-08-11 13:10:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Mozilla
[2011-08-11 09:16:44 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2011-08-11 09:05:44 | 000,000,000 | ---D | C] -- C:\VundoFix Backups
[2011-08-11 09:01:26 | 000,000,000 | ---D | C] -- C:\WINDOWS\temp
[2011-08-11 08:51:56 | 000,000,000 | RHSD | C] -- C:\cmdcons
[2011-08-11 08:44:46 | 000,518,144 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe
[2011-08-11 08:44:46 | 000,406,528 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe
[2011-08-11 08:44:46 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe
[2011-08-11 08:44:46 | 000,060,416 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe
[2011-08-11 08:44:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011-08-11 08:44:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2011-08-11 08:44:10 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\Administrative Tools
[2011-08-11 08:43:43 | 004,170,012 | R--- | C] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-11 00:42:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Sun
[2011-08-11 00:37:29 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2011-08-11 00:37:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\HiJackThis
[2011-08-08 14:01:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2011-08-08 14:01:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\NetworkService\Application Data\Adobe
[2011-08-08 14:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Tysu
[2011-08-08 14:01:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Agdak
[2011-08-06 07:38:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\VideoLAN
[2011-07-28 08:05:12 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Yanick\My Documents\Dropbox
[2011-07-28 08:03:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Start Menu\Programs\Dropbox
[2011-07-28 08:02:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Yanick\Application Data\Dropbox
[2011-02-15 23:29:39 | 000,094,208 | ---- | C] (VSO Software) -- C:\Documents and Settings\Yanick\Application Data\ezplay.sys
[2010-10-10 23:30:03 | 000,254,000 | ---- | C] ( ) -- C:\WINDOWS\System32\Audio3D.dll
[2010-10-10 23:30:03 | 000,254,000 | ---- | C] ( ) -- C:\WINDOWS\System32\A3D.dll
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011-08-25 09:11:13 | 000,001,152 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-412668190-725345543-1003UA.job
[2011-08-25 09:09:44 | 000,001,324 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[2011-08-25 09:02:48 | 000,879,225 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-08-25 09:01:42 | 000,000,512 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\MBR.dat
[2011-08-25 08:59:23 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-25 08:54:19 | 000,440,684 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011-08-25 08:54:19 | 000,071,002 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011-08-25 08:50:26 | 000,000,868 | ---- | M] () -- C:\WINDOWS\tasks\Google Software Updater.job
[2011-08-25 08:50:05 | 000,002,181 | ---- | M] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bandwidth Meter.lnk
[2011-08-25 08:49:54 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011-08-25 08:38:45 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Yanick\Desktop\OTL.com
[2011-08-25 07:37:54 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011-08-23 19:11:00 | 000,001,100 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-73586283-412668190-725345543-1003Core.job
[2011-08-23 17:59:10 | 000,415,161 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\census.cache
[2011-08-23 17:59:09 | 000,193,845 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\ars.cache
[2011-08-11 17:33:05 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011-08-11 11:50:30 | 000,000,036 | ---- | M] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\housecall.guid.cache
[2011-08-11 09:18:45 | 000,000,784 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2011-08-11 08:52:00 | 000,000,327 | RHS- | M] () -- C:\boot.ini
[2011-08-11 08:43:47 | 004,170,012 | R--- | M] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-11 07:53:25 | 000,000,137 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011-08-11 00:37:29 | 000,001,986 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\HiJackThis.lnk
[2011-08-11 00:27:43 | 000,000,294 | ---- | M] () -- C:\WINDOWS\System32\MRT.INI
[2011-08-11 00:24:12 | 000,000,000 | ---- | M] () -- C:\WINDOWS\Akejupodo.bin
[2011-08-11 00:24:11 | 000,000,120 | ---- | M] () -- C:\WINDOWS\Wwoqurixuqu.dat
[2011-08-11 00:23:38 | 000,022,572 | ---- | M] () -- C:\Documents and Settings\Yanick\Application Data\EF76.7AC
[2011-08-06 07:38:08 | 000,000,719 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011-08-06 07:37:05 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
[2011-08-02 10:39:09 | 000,000,280 | ---- | M] () -- C:\WINDOWS\tasks\switchDowngrade.job
[2011-07-30 22:33:52 | 000,059,347 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\yanreg.pdf
[2011-07-30 22:32:35 | 000,059,293 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\yanick2000.pdf
[2011-07-28 08:05:12 | 000,000,999 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\Dropbox.lnk
[7 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[5 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011-08-25 09:02:47 | 000,879,225 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-08-25 09:01:42 | 000,000,512 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\MBR.dat
[2011-08-11 11:55:56 | 000,415,161 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\census.cache
[2011-08-11 11:55:42 | 000,193,845 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\ars.cache
[2011-08-11 11:50:30 | 000,000,036 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\housecall.guid.cache
[2011-08-11 08:52:00 | 000,000,211 | ---- | C] () -- C:\Boot.bak
[2011-08-11 08:51:57 | 000,260,272 | RHS- | C] () -- C:\cmldr
[2011-08-11 08:44:46 | 000,256,000 | ---- | C] () -- C:\WINDOWS\PEV.exe
[2011-08-11 08:44:46 | 000,208,896 | ---- | C] () -- C:\WINDOWS\MBR.exe
[2011-08-11 08:44:46 | 000,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe
[2011-08-11 08:44:46 | 000,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe
[2011-08-11 08:44:46 | 000,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe
[2011-08-11 00:37:29 | 000,001,986 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\HiJackThis.lnk
[2011-08-11 00:27:43 | 000,000,294 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI
[2011-08-08 13:51:01 | 000,022,572 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\EF76.7AC
[2011-08-06 07:38:08 | 000,000,719 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\VLC media player.lnk
[2011-08-06 07:36:25 | 021,073,936 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
[2011-07-30 22:33:52 | 000,059,347 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\yanreg.pdf
[2011-07-30 22:32:35 | 000,059,293 | ---- | C] () -- C:\Documents and Settings\Yanick\My Documents\yanick2000.pdf
[2011-07-28 08:05:12 | 000,000,999 | ---- | C] () -- C:\Documents and Settings\Yanick\Desktop\Dropbox.lnk
[2011-07-01 12:59:43 | 000,000,358 | ---- | C] () -- C:\WINDOWS\hegames.ini
[2011-05-24 20:57:02 | 000,000,137 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2011-05-22 16:21:48 | 000,015,958 | -HS- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\mssfsi1vlq8g1bx8lmkcbl8
[2011-05-22 16:21:48 | 000,015,958 | -HS- | C] () -- C:\Documents and Settings\All Users\Application Data\mssfsi1vlq8g1bx8lmkcbl8
[2011-04-14 16:59:26 | 000,000,120 | ---- | C] () -- C:\WINDOWS\Wwoqurixuqu.dat
[2011-04-14 16:59:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Akejupodo.bin
[2011-02-15 23:29:39 | 000,007,861 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.cat
[2011-02-15 23:29:39 | 000,001,103 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.inf
[2011-02-15 23:29:39 | 000,000,125 | ---- | C] () -- C:\Documents and Settings\Yanick\Application Data\ezplay.ini
[2011-01-07 00:20:16 | 000,019,528 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2011-01-03 14:56:18 | 000,000,109 | ---- | C] () -- C:\WINDOWS\TLCAPPS.INI
[2010-11-16 22:21:49 | 000,000,116 | ---- | C] () -- C:\WINDOWS\NeroDigital.ini
[2010-11-16 22:00:39 | 000,040,960 | ---- | C] () -- C:\Program Files\Uninstall_CDS.exe
[2010-11-12 21:40:37 | 000,000,000 | ---- | C] () -- C:\WINDOWS\SETUP32.INI
[2010-11-06 16:17:37 | 000,001,324 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010-11-02 20:51:03 | 000,029,696 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010-10-30 09:10:02 | 000,000,129 | ---- | C] () -- C:\Documents and Settings\Yanick\Local Settings\Application Data\fusioncache.dat
[2010-10-28 16:32:26 | 000,007,168 | ---- | C] () -- C:\WINDOWS\System32\drivers\StarOpen.sys
[2010-10-11 00:13:39 | 000,007,342 | ---- | C] () -- C:\WINDOWS\HCWPNP.INI
[2010-10-11 00:12:33 | 000,066,048 | ---- | C] () -- C:\WINDOWS\System32\hcwXDS.dll
[2010-10-10 23:34:46 | 000,001,769 | ---- | C] () -- C:\WINDOWS\Language_trs.ini
[2010-10-10 23:26:30 | 000,000,000 | ---- | C] () -- C:\WINDOWS\ativpsrm.bin
[2010-10-10 23:26:22 | 000,887,724 | ---- | C] () -- C:\WINDOWS\System32\ativva6x.dat
[2010-10-10 23:26:22 | 000,294,912 | ---- | C] () -- C:\WINDOWS\System32\ATIODE.exe
[2010-10-10 23:26:22 | 000,219,348 | ---- | C] () -- C:\WINDOWS\System32\atiicdxx.dat
[2010-10-10 23:26:22 | 000,045,056 | ---- | C] () -- C:\WINDOWS\System32\ATIODCLI.exe
[2010-10-10 23:26:22 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\ativva5x.dat
[2010-10-10 23:18:24 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat
[2010-10-10 23:14:39 | 000,073,728 | ---- | C] () -- C:\WINDOWS\System32\RtNicProp32.dll
[2010-10-10 22:53:39 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2010-10-10 22:48:55 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2010-10-10 18:42:23 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2010-10-10 18:37:08 | 000,123,728 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2008-06-01 03:13:10 | 000,053,299 | ---- | C] () -- C:\WINDOWS\System32\pthreadVC.dll
[2007-05-09 21:35:54 | 000,057,126 | ---- | C] () -- C:\WINDOWS\System32\lvcoinst.ini
[2004-08-03 19:07:22 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin
[2004-08-02 08:20:40 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004-07-17 05:36:38 | 000,027,440 | ---- | C] () -- C:\WINDOWS\System32\drivers\secdrv.sys
[2001-08-23 12:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2001-08-23 12:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2001-08-23 11:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2001-08-23 11:00:00 | 000,440,684 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2001-08-23 11:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2001-08-23 11:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2001-08-23 11:00:00 | 000,071,002 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2001-08-23 11:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2001-08-23 11:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2001-08-23 11:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
========== Custom Scans ==========
< %APPDATA%\Microsoft\*.* >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %USERPROFILE%\Desktop\*.exe >
[2011-08-25 08:59:23 | 001,916,416 | ---- | M] (AVAST Software) -- C:\Documents and Settings\Yanick\Desktop\aswMBR.exe
[2011-08-11 08:43:47 | 004,170,012 | R--- | M] (Swearware) -- C:\Documents and Settings\Yanick\Desktop\ComboFix.exe
[2011-08-25 09:02:48 | 000,879,225 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\SecurityCheck.exe
[2011-06-16 21:13:25 | 021,022,914 | ---- | M] () -- C:\Documents and Settings\Yanick\Desktop\vlc-1.1.10-win32.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\winn32\*.* >
< %USERPROFILE%\My Documents\*.exe >
[2011-08-06 07:37:05 | 021,073,936 | ---- | M] () -- C:\Documents and Settings\Yanick\My Documents\vlc-1.1.11-win32.exe
< %USERPROFILE%\*.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.exe >
[2011-06-23 08:05:06 | 000,125,912 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\crashreporter.exe
[2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\firefox.exe
[2011-06-23 08:05:04 | 000,016,856 | ---- | M] (Mozilla Corporation) -- C:\Program Files\Mozilla Firefox\plugin-container.exe
[2011-06-23 08:05:04 | 000,265,176 | ---- | M] (Mozilla Foundation) -- C:\Program Files\Mozilla Firefox\updater.exe
< %ProgramFiles%\TinyProxy. >
< %systemroot%\system32\*.* /lockedfiles >
[5 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.* /lockedfiles >
< %PROGRAMFILES%\*. >
[2010-10-12 07:28:56 | 000,000,000 | ---D | M] -- C:\Program Files\7-Zip
[2010-12-02 10:09:30 | 000,000,000 | ---D | M] -- C:\Program Files\Activision
[2010-10-12 09:40:10 | 000,000,000 | ---D | M] -- C:\Program Files\Adobe
[2010-11-16 22:03:00 | 000,000,000 | ---D | M] -- C:\Program Files\Ahead
[2011-07-05 10:07:51 | 000,000,000 | ---D | M] -- C:\Program Files\Apple Software Update
[2010-10-10 23:26:48 | 000,000,000 | ---D | M] -- C:\Program Files\ATI
[2010-10-10 23:26:40 | 000,000,000 | ---D | M] -- C:\Program Files\ATI Technologies
[2010-11-02 09:44:37 | 000,000,000 | ---D | M] -- C:\Program Files\Avery Dennison
[2010-10-10 23:33:25 | 000,000,000 | ---D | M] -- C:\Program Files\Avira
[2011-04-28 08:53:20 | 000,000,000 | ---D | M] -- C:\Program Files\Bonjour
[2010-10-28 16:32:27 | 000,000,000 | ---D | M] -- C:\Program Files\CDBurnerXP
[2011-08-11 08:56:12 | 000,000,000 | ---D | M] -- C:\Program Files\Common Files
[2010-10-10 22:48:42 | 000,000,000 | ---D | M] -- C:\Program Files\ComPlus Applications
[2010-11-16 22:01:09 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink
[2010-11-16 22:01:59 | 000,000,000 | ---D | M] -- C:\Program Files\CyberLink DVD Solution
[2010-10-11 00:24:39 | 000,000,000 | ---D | M] -- C:\Program Files\Devnz
[2011-08-25 07:47:32 | 000,000,000 | ---D | M] -- C:\Program Files\DScaler
[2011-02-15 23:27:01 | 000,000,000 | ---D | M] -- C:\Program Files\DVD Shrink
[2010-10-14 09:26:57 | 000,000,000 | ---D | M] -- C:\Program Files\EASEUS
[2010-11-30 22:11:08 | 000,000,000 | ---D | M] -- C:\Program Files\Elaborate Bytes
[2011-01-04 19:31:29 | 000,000,000 | ---D | M] -- C:\Program Files\Google
[2011-02-01 23:24:38 | 000,000,000 | ---D | M] -- C:\Program Files\HP
[2011-02-15 23:25:48 | 000,000,000 | ---D | M] -- C:\Program Files\ImgBurn
[2011-04-05 08:44:56 | 000,000,000 | ---D | M] -- C:\Program Files\ImpotExpert 2010
[2010-11-16 22:01:59 | 000,000,000 | -H-D | M] -- C:\Program Files\InstallShield Installation Information
[2010-10-14 03:01:57 | 000,000,000 | ---D | M] -- C:\Program Files\Internet Explorer
[2011-06-30 21:28:46 | 000,000,000 | ---D | M] -- C:\Program Files\iPod
[2011-06-30 21:29:23 | 000,000,000 | ---D | M] -- C:\Program Files\iTunes
[2010-10-11 08:07:47 | 000,000,000 | ---D | M] -- C:\Program Files\Java
[2010-10-11 08:08:09 | 000,000,000 | ---D | M] -- C:\Program Files\JRE
[2011-06-11 18:56:17 | 000,000,000 | ---D | M] -- C:\Program Files\Kutoka
[2011-05-24 10:40:36 | 000,000,000 | ---D | M] -- C:\Program Files\Line6
[2011-08-11 09:18:45 | 000,000,000 | ---D | M] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010-10-11 00:42:28 | 000,000,000 | ---D | M] -- C:\Program Files\Messenger
[2010-10-10 22:52:13 | 000,000,000 | ---D | M] -- C:\Program Files\microsoft frontpage
[2010-10-11 00:33:28 | 000,000,000 | ---D | M] -- C:\Program Files\Movie Maker
[2011-08-25 09:12:23 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox
[2010-10-14 03:03:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSBuild
[2010-10-10 22:47:31 | 000,000,000 | ---D | M] -- C:\Program Files\MSN
[2010-10-10 22:48:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSN Gaming Zone
[2011-03-24 03:00:16 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 4.0
[2010-10-14 03:01:12 | 000,000,000 | ---D | M] -- C:\Program Files\MSXML 6.0
[2010-10-28 08:32:06 | 000,000,000 | ---D | M] -- C:\Program Files\NCH Swift Sound
[2010-10-10 22:50:03 | 000,000,000 | ---D | M] -- C:\Program Files\NetMeeting
[2010-10-19 08:23:25 | 000,000,000 | ---D | M] -- C:\Program Files\OneSwarm
[2010-10-10 22:48:27 | 000,000,000 | ---D | M] -- C:\Program Files\Online Services
[2010-10-11 08:08:08 | 000,000,000 | ---D | M] -- C:\Program Files\OpenOffice.org 3
[2010-10-11 01:01:24 | 000,000,000 | ---D | M] -- C:\Program Files\Outlook Express
[2010-10-16 17:46:03 | 000,000,000 | ---D | M] -- C:\Program Files\PlayPianoTODAY
[2010-12-25 12:47:03 | 000,000,000 | ---D | M] -- C:\Program Files\QuickTime
[2010-10-10 23:14:38 | 000,000,000 | ---D | M] -- C:\Program Files\Realtek
[2010-10-14 03:03:08 | 000,000,000 | ---D | M] -- C:\Program Files\Reference Assemblies
[2011-06-30 21:24:06 | 000,000,000 | ---D | M] -- C:\Program Files\Safari
[2011-05-24 20:40:04 | 000,000,000 | ---D | M] -- C:\Program Files\Spybot - Search & Destroy
[2011-01-06 22:53:26 | 000,000,000 | ---D | M] -- C:\Program Files\Tansee iPhone Transfer Contact
[2011-08-11 00:37:29 | 000,000,000 | ---D | M] -- C:\Program Files\Trend Micro
[2010-10-30 08:45:13 | 000,000,000 | ---D | M] -- C:\Program Files\Turbine
[2010-10-10 22:55:27 | 000,000,000 | -H-D | M] -- C:\Program Files\Uninstall Information
[2010-10-10 23:35:19 | 000,000,000 | ---D | M] -- C:\Program Files\VIA
[2010-11-02 20:52:37 | 000,000,000 | ---D | M] -- C:\Program Files\VideoLAN
[2011-02-15 23:29:30 | 000,000,000 | ---D | M] -- C:\Program Files\VSO
[2010-10-10 23:47:45 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Connect 2
[2010-10-11 00:07:17 | 000,000,000 | ---D | M] -- C:\Program Files\Windows Media Player
[2010-10-10 22:48:06 | 000,000,000 | ---D | M] -- C:\Program Files\Windows NT
[2010-10-10 22:51:01 | 000,000,000 | -H-D | M] -- C:\Program Files\WindowsUpdate
[2010-11-16 09:46:51 | 000,000,000 | ---D | M] -- C:\Program Files\WinPcap
[2010-10-11 00:14:14 | 000,000,000 | ---D | M] -- C:\Program Files\WinTV
[2010-10-10 22:52:13 | 000,000,000 | ---D | M] -- C:\Program Files\xerox
< MD5 for: AGP440.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
[2008-04-13 14:36:38 | 000,042,368 | ---- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\agp440.sys
< MD5 for: ATAPI.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2008-04-13 14:40:30 | 000,096,512 | ---- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\atapi.sys
[2004-08-03 16:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\ERDNT\cache\atapi.sys
[2004-08-03 16:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: DISK.SYS >
[2004-08-03 19:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:disk.sys
[2004-08-03 16:59:56 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=00CA44E4534865F8A3B64F7C0984BFF0 -- C:\WINDOWS\system32\drivers\disk.sys
[2008-04-13 14:40:47 | 000,036,352 | ---- | M] (Microsoft Corporation) MD5=044452051F3E02E7963599FC8F4F3E25 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\disk.sys
< MD5 for: NETLOGON.DLL >
[2008-04-13 20:12:01 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 -- C:\WINDOWS\SoftwareDistribution\Download\9866fb57abdc0ea2f5d4e132d055ba4e\netlogon.dll
[2009-02-06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009-02-06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004-08-03 18:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2011-08-11 04:27:44
< hklm\software\clients\startmenuinternet|command /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2004-08-03 18:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
< hklm\software\clients\startmenuinternet|command /64 /rs >
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\HideIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /HideShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ShowIconsCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /ShowShortcuts [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\InstallInfo\\ReinstallCommand: "C:\Program Files\Mozilla Firefox\uninstall\helper.exe" /SetAsDefaultAppGlobal [2011-06-23 08:05:04 | 000,715,104 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\open\command\\: C:\Program Files\Mozilla Firefox\firefox.exe [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\properties\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -preferences [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\FIREFOX.EXE\shell\safemode\command\\: "C:\Program Files\Mozilla Firefox\firefox.exe" -safe-mode [2011-06-23 08:05:06 | 000,924,632 | ---- | M] (Mozilla Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ReinstallCommand: %systemroot%\system32\shmgrate.exe OCInstallReinstallIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\HideIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallHideIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\InstallInfo\\ShowIconsCommand: %systemroot%\system32\shmgrate.exe OCInstallShowIE [2004-08-03 18:56:58 | 000,042,496 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\IEXPLORE.EXE\shell\open\command\\: "C:\Program Files\Internet Explorer\iexplore.exe" [2004-08-03 18:56:52 | 000,093,184 | ---- | M] (Microsoft Corporation)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ReinstallCommand: "C:\Program Files\Safari\Safari.exe" /reinstall [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\HideIconsCommand: "C:\Program Files\Safari\Safari.exe" /hideicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\InstallInfo\\ShowIconsCommand: "C:\Program Files\Safari\Safari.exe" /showicons [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
HKEY_LOCAL_MACHINE\software\clients\startmenuinternet\Safari.exe\shell\open\command\\: "C:\Program Files\Safari\Safari.exe" [2011-03-21 20:10:48 | 002,388,264 | ---- | M] (Apple Inc.)
< End of report >
Rest of logs in part 2/2 on anothe message