ARCHellraiser
2010-03-27, 17:17
Morning
Being one who needs to know I always show all files and folders hidden
and all and just checked and all were checked including show hidden files and folders.
Here is something odd.. IE would not start yesterday but today I after i clicked on it to see if it would start and it did.:confused: Closed it and tried to start
windows Explorer (start-right click) and it would not start i quickly did a restart and this program " Explorer Proxy Desktop was still running and needs to be shut down" never saw that before.
after reboot tried Explorer (start-right click) opened but the top control bar was missing (Files Edit View Fav Tools Help) closed it and tried it again won't open ...tried IE will not open so IE opens only once after reboot.
just an FYI
Followed your instructions:
Virus Total Log
Antivirus Version Last Update Result
a-squared 4.5.0.50 2010.03.27 -
AhnLab-V3 5.0.0.2 2010.03.27 -
AntiVir 7.10.5.241 2010.03.26 TR/Dropper.Gen
Antiy-AVL 2.0.3.7 2010.03.26 -
Authentium 5.2.0.5 2010.03.27 -
Avast 4.8.1351.0 2010.03.27 -
Avast5 5.0.332.0 2010.03.27 -
AVG 9.0.0.787 2010.03.27 -
BitDefender 7.2 2010.03.27 -
CAT-QuickHeal 10.00 2010.03.27 -
ClamAV 0.96.0.0-git 2010.03.27 -
Comodo 4403 2010.03.27 -
DrWeb 5.0.1.12222 2010.03.27 -
eSafe 7.0.17.0 2010.03.25 -
eTrust-Vet 35.2.7391 2010.03.26 -
F-Prot 4.5.1.85 2010.03.26 -
F-Secure 9.0.15370.0 2010.03.27 -
Fortinet 4.0.14.0 2010.03.27 -
GData 19 2010.03.27 -
Ikarus T3.1.1.80.0 2010.03.27 -
Jiangmin 13.0.900 2010.03.27 -
K7AntiVirus 7.10.1004 2010.03.22 -
Kaspersky 7.0.0.125 2010.03.27 -
McAfee 5932 2010.03.26 -
McAfee+Artemis 5932 2010.03.26 -
McAfee-GW-Edition 6.8.5 2010.03.27 Trojan.Dropper.Gen
Microsoft 1.5605 2010.03.27 -
NOD32 4978 2010.03.26 -
Norman 6.04.10 2010.03.27 -
nProtect 2009.1.8.0 2010.03.27 -
Panda 10.0.2.2 2010.03.26 -
PCTools 7.0.3.5 2010.03.27 -
Prevx 3.0 2010.03.27 High Risk Fraudulent Security Program
Rising 22.40.05.04 2010.03.27 -
Sophos 4.52.0 2010.03.27 -
Sunbelt 6101 2010.03.26 -
Symantec 20091.2.0.41 2010.03.27 Suspicious.Insight
TheHacker 6.5.2.0.245 2010.03.26 -
TrendMicro 9.120.0.1004 2010.03.27 PAK_Generic.001
VBA32 3.12.12.2 2010.03.27 -
ViRobot 2010.3.27.2248 2010.03.27 -
VirusBuster 5.0.27.0 2010.03.27 -
Additional information
File size: 29184 bytes
MD5...: 8ecbf0afa3ef94f3b3a78f328699536c
SHA1..: 38316a35db1783df39487eaad5fc95b975c41a2e
SHA256: 02b96a3963d8a802843167ab118a40f9842712e71f952f6425f3aed427452f3d
ssdeep: 768:wQpqiZFLvkS1Dx3QDNbajsLy30TG/9rBqGG:npFLvkS1Dx3oBaok0K7j
PEiD..: -
PEInfo: PE Structure information
( base data )
entrypointaddress.: 0x10990
timedatestamp.....: 0x4bab5741 (Thu Mar 25 12:29:53 2010)
machinetype.......: 0x14c (I386)
( 3 sections )
name viradd virsiz rawdsiz ntrpy md5
UPX0 0x1000 0x9000 0x0 0.00 d41d8cd98f00b204e9800998ecf8427e
UPX1 0xa000 0x7000 0x6c00 7.85 518d2b8bd7c4bb075de782cf7515e175
.rsrc 0x11000 0x1000 0x200 3.02 5d718fbc722f981a162645e101220687
( 3 imports )
> KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
> ADVAPI32.dll: RegEnumKeyExA
> USER32.dll: GetMessageA
( 0 exports )
RDS...: NSRL Reference Data Set
-
pdfid.: -
trid..: UPX compressed Win32 Executable (39.5%)
Win32 EXE Yoda's Crypter (34.3%)
Win32 Executable Generic (11.0%)
Win32 Dynamic Link Library (generic) (9.8%)
Generic Win/DOS Executable (2.5%)
packers (Kaspersky): PE_Patch.UPX, UPX
<a href='http://info.prevx.com/aboutprogramtext.asp?PX5=374DBC6A0094A877723F00094826820041BEA1F9' target='_blank'>http://info.prevx.com/aboutprogramtext.asp?PX5=374DBC6A0094A877723F00094826820041BEA1F9</a>
packers (F-Prot): UPX, embedded
sigcheck:
publisher....: n/a
copyright....: n/a
product......: n/a
description..: n/a
original name: n/a
internal name: n/a
file version.: n/a
comments.....: n/a
signers......: -
signing date.: -
verified.....: Unsigned
OTL LOGS
OTL logfile created on: 3/27/2010 10:41:00 AM - Run 1
OTL by OldTimer - Version 3.1.37.3 Folder = C:\DOWNLOADS\DOwnloads Firefox
Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.2180)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1,023.00 Mb Total Physical Memory | 657.00 Mb Available Physical Memory | 64.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 89.00% Paging File free
Paging file location(s): C:\pagefile.sys 2000 3072
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 12.29 Gb Free Space | 16.49% Space Free | Partition Type: NTFS
Drive D: | 118.82 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: ED-MASTER
Current User Name: Administrator
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\DOWNLOADS\DOwnloads Firefox\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Administrator\Application Data\PnPDeviceMonitor\pnpdevicemon.exe ()
PRC - C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
PRC - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
PRC - C:\Program Files\UltraVNC\winvnc.exe (UltraVNC)
PRC - C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDClock.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\Applets\LCDMedia.exe (Logitech Inc.)
PRC - C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe (Lexmark International, Inc.)
PRC - C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
========== Modules (SafeList) ==========
MOD - C:\DOWNLOADS\DOwnloads Firefox\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\system32\bootnsvr.dll ()
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (fsssvc) -- C:\Program Files\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (SeaPort) -- C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corp.)
SRV - (CVPND) -- C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (winvnc) -- C:\Program Files\UltraVNC\winvnc.exe (UltraVNC)
========== Driver Services (SafeList) ==========
DRV - (ati2mtag) -- C:\WINDOWS\system32\drivers\ati2mtag.sys (ATI Technologies Inc.)
DRV - (fssfltr) -- C:\WINDOWS\system32\drivers\fssfltr_tdi.sys (Microsoft Corporation)
DRV - (MQAC) -- C:\WINDOWS\system32\drivers\mqac.sys (Microsoft Corporation)
DRV - (CVPNDRVA) -- C:\WINDOWS\system32\drivers\CVPNDRVA.sys (Cisco Systems, Inc.)
DRV - (ALCXWDM) Service for Realtek AC97 Audio (WDM) -- C:\WINDOWS\system32\drivers\alcxwdm.sys (Realtek Semiconductor Corp.)
DRV - (DNE) -- C:\WINDOWS\system32\drivers\dne2000.sys (Deterministic Networks, Inc.)
DRV - (nvnetbus) -- C:\WINDOWS\system32\drivers\nvnetbus.sys (NVIDIA Corporation)
DRV - (NVENETFD) -- C:\WINDOWS\system32\drivers\NVENETFD.sys (NVIDIA Corporation)
DRV - (RMCAST) -- C:\WINDOWS\system32\drivers\rmcast.sys (Microsoft Corporation)
DRV - (AmdPPM) -- C:\WINDOWS\system32\drivers\AmdPPM.sys (Advanced Micro Devices)
DRV - (CVirtA) -- C:\WINDOWS\system32\drivers\CVirtA.sys (Cisco Systems, Inc.)
DRV - (nvatabus) -- C:\WINDOWS\system32\DRIVERS\nvatabus.sys (NVIDIA Corporation)
DRV - (MarvinBus) -- C:\WINDOWS\system32\drivers\MarvinBus.sys (Pinnacle Systems GmbH)
DRV - (nvata) -- C:\WINDOWS\system32\DRIVERS\nvata.sys (NVIDIA Corporation)
DRV - (nvnforce) Service for NVIDIA(R) nForce(TM) -- C:\WINDOWS\system32\drivers\nvapu.sys (NVIDIA Corporation)
DRV - (nvax) Service for NVIDIA(R) nForce(TM) -- C:\WINDOWS\system32\drivers\nvax.sys (NVIDIA Corporation)
DRV - (vnccom) -- C:\WINDOWS\system32\drivers\vnccom.SYS (RDV Soft)
DRV - (vncdrv) -- C:\WINDOWS\system32\drivers\vncdrv.sys (RDV Soft)
DRV - (LMouFlt2) -- C:\WINDOWS\system32\drivers\LMouFlt2.Sys (Logitech, Inc.)
DRV - (L8042pr2) -- C:\WINDOWS\system32\drivers\L8042pr2.Sys (Logitech, Inc.)
DRV - (vobiw) -- C:\WINDOWS\system32\drivers\vobIW.sys (VOB Computersysteme GmbH)
DRV - (VOBID) -- C:\WINDOWS\system32\DRIVERS\vobid.sys (Pinnacle Systems)
DRV - (Sentinel) -- C:\WINDOWS\System32\Drivers\SENTINEL.SYS (Rainbow Technologies, Inc.)
DRV - (SNTNLUSB) -- C:\WINDOWS\system32\drivers\SNTNLUSB.SYS (Rainbow Technologies Inc.)
DRV - (cdrdrv) -- C:\WINDOWS\system32\drivers\Cdrdrv.sys (VOB Computersysteme GmbH)
DRV - (ASAPIW2K) -- C:\WINDOWS\system32\drivers\asapiW2k.sys (VOB Computersysteme GmbH)
DRV - (vobcom) -- C:\WINDOWS\system32\drivers\vobcom.sys (VOB Computersysteme GmbH)
DRV - (Aspi32) -- C:\WINDOWS\system32\drivers\aspi32.sys (Adaptec)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=20008&gct=&gc=1&q=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ycomp/defaults/sp/*http://www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\URLSearchHook: {C94E154B-1459-4A47-966B-4B843BEFC7DB} - C:\Program Files\AskSearch\bin\DefaultSearch.dll ()
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-i3752"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-i3752"
FF - prefs.js..browser.startup.homepage: "http://home.jzip.com"
FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/26 21:04:34 | 000,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/25 19:51:06 | 000,000,000 | ---D | M]
[2009/08/29 11:12:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Extensions
[2010/03/26 21:30:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hd0rjl1v.default\extensions
[2009/08/29 11:13:39 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hd0rjl1v.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/10/18 08:16:35 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hd0rjl1v.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2010/01/26 22:05:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Mozilla\Firefox\Profiles\hd0rjl1v.default\extensions\browserhighlighter@ebay.com
[2010/03/26 21:30:30 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions
O1 HOSTS File: ([2010/01/31 10:42:16 | 000,377,048 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13022 more lines...
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Skype add-on (mastermind)) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O2 - BHO: (Smart-Shopper) - {4A7C84E2-E95C-43C6-8DD3-03ABCD0EB60E} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Search Helper) - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll (Microsoft Corp.)
O2 - BHO: (Windows Live Toolbar Helper) - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (no name) - - No CLSID value found.
O3 - HKLM\..\Toolbar: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (&Windows Live Toolbar) - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll (Microsoft Corporation)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Program Files\AskBarDis\bar\bin\askBar.dll (Ask.com)
O4 - HKLM..\Run: [Launch LCDMon] C:\Program Files\Logitech\G-series Software\LCDMon.exe (Logitech Inc.)
O4 - HKLM..\Run: [Launch LGDCore] C:\Program Files\Logitech\G-series Software\LGDCore.exe (Logitech Inc.)
O4 - HKLM..\Run: [Lexmark X1100 Series] C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe (Lexmark International, Inc.)
O4 - HKLM..\Run: [MsmqIntCert] C:\WINDOWS\System32\mqrt.dll (Microsoft Corporation)
O4 - HKLM..\Run: [SoundMan] C:\WINDOWS\soundman.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Gadwin PrintScreen] C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe (Gadwin Systems, Inc)
O4 - HKCU..\Run: [pnpdevicemon] C:\Documents and Settings\Administrator\Application Data\PnPDeviceMonitor\pnpdevicemon.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Registration-INSDVD.lnk = C:\Program Files\Pinnacle\InstantCDDVD\SharedFiles\Pixie\RegTool.exe (Pinnacle Systems, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: SmartShopper - Compare product prices - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEBF} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
O9 - Extra Button: SmartShopper - Compare travel rates - {3CC3D8FE-F0E0-4dd1-A69A-8C56BCC7BEC0} - C:\Program Files\Smart-Shopper\Bin\2.5.1\Smrt-Shpr.dll (SmartShopper Networks)
O9 - Extra 'Tools' menuitem : Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra Button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O15 - HKCU\..Trusted Domains: //@install.mar@ ([]msni in My Computer)
O15 - HKCU\..Trusted Domains: //@mail.mar@ ([]msni in Local intranet)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1269188900343 (WUWebControl Class)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1269188890109 (MUWebControl Class)
O16 - DPF: {74DBCB52-F298-4110-951D-AD2FF67BC8AB} http://www.nvidia.com/content/DriverDownload/nforce/NvidiaSmartScan.cab (NVIDIA Smart Scan)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.2.1
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop WallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Administrator\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/04/30 15:35:18 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2002/08/06 17:21:42 | 000,000,025 | R--- | M] () - D:\Autorun.inf -- [ CDFS ]
O33 - MountPoints2\{53d35542-f71e-11db-b1bc-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{53d35542-f71e-11db-b1bc-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{53d35542-f71e-11db-b1bc-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe -- [2002/08/06 17:41:08 | 000,131,072 | R--- | M] (Microsoft Corporation)
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O36 - AppCertDlls: dplaover - (C:\WINDOWS\system32\bootnsvr.dll) - C:\WINDOWS\system32\bootnsvr.dll ()
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2007/04/30 15:34:51 | 000,000,000 | ---D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: WmdmPmSp - File not found
========== Files/Folders - Created Within 30 Days ==========
[2010/03/26 21:44:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\jZip
[2010/03/26 21:30:22 | 000,000,000 | ---D | C] -- C:\Program Files\Smart-Shopper
[2010/03/26 21:30:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Smart-Shopper
[2010/03/26 21:30:01 | 000,000,000 | ---D | C] -- C:\Program Files\jZip
[2010/03/25 21:39:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\PnPDeviceMonitor
[2010/03/22 19:56:49 | 000,000,000 | ---D | C] -- C:\Program Files\Trend Micro
[2010/03/21 12:28:42 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui
[2010/03/20 11:25:33 | 000,000,000 | ---D | C] -- C:\Avenger
[2010/03/18 23:58:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Windows Server
[2010/03/13 00:46:59 | 000,014,848 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhid.sys
[2010/03/13 00:46:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Local Settings\Application Data\Logitech
[2010/03/13 00:46:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Logitech
[2010/03/13 00:34:59 | 000,021,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/03/01 21:53:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2010/01/12 00:18:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple
[2009/10/10 17:25:02 | 000,000,000 | --SD | M] -- C:\Documents and Settings\LocalService\Application Data\Microsoft
[2009/08/11 23:43:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Application Data\Xfire
[2007/04/30 15:38:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Microsoft
[2007/04/30 15:37:49 | 000,000,000 | --SD | M] -- C:\Documents and Settings\NetworkService\Application Data\Microsoft
[2007/04/30 15:37:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Microsoft
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/03/27 10:36:49 | 000,000,670 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to OTL.exe.lnk
[2010/03/27 10:34:29 | 008,126,464 | -H-- | M] () -- C:\Documents and Settings\Administrator\NTUSER.DAT
[2010/03/27 10:34:10 | 000,002,473 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Microsoft Word.lnk
[2010/03/27 10:15:37 | 000,539,556 | ---- | M] () -- C:\WINDOWS\System32\PerfStringBackup.INI
[2010/03/27 10:15:37 | 000,454,652 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2010/03/27 10:15:37 | 000,075,338 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2010/03/27 10:10:49 | 000,000,006 | -H-- | M] () -- C:\WINDOWS\tasks\SA.DAT
[2010/03/27 10:10:44 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2010/03/26 21:57:45 | 000,000,178 | -HS- | M] () -- C:\Documents and Settings\Administrator\ntuser.ini
[2010/03/26 21:45:30 | 000,004,252 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Attach.zip
[2010/03/26 21:45:30 | 000,004,252 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Attach.zip
[2010/03/26 21:30:23 | 000,000,153 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Emoticons for your messenger!.url
[2010/03/26 21:30:18 | 000,000,626 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\jZip.lnk
[2010/03/26 19:53:14 | 000,000,716 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to ATF-Cleaner.exe.lnk
[2010/03/26 19:35:52 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 6.doc
[2010/03/25 22:44:27 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 7.doc
[2010/03/25 22:43:30 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 5.doc
[2010/03/25 00:13:13 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Mike.doc
[2010/03/25 00:12:50 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 4.doc
[2010/03/25 00:12:44 | 000,019,968 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 3.doc
[2010/03/25 00:12:38 | 000,020,992 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 2.doc
[2010/03/24 22:44:49 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2010/03/23 22:35:05 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Arc2.doc
[2010/03/23 22:34:34 | 000,023,552 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 1.doc
[2010/03/23 21:14:12 | 000,000,550 | ---- | M] () -- C:\WINDOWS\lexstat.ini
[2010/03/23 20:59:31 | 000,002,207 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Steam.lnk
[2010/03/22 22:03:30 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document.doc
[2010/03/22 21:33:23 | 000,000,603 | ---- | M] () -- C:\WINDOWS\win.ini
[2010/03/22 21:33:23 | 000,000,281 | RHS- | M] () -- C:\boot.ini
[2010/03/22 21:33:23 | 000,000,227 | ---- | M] () -- C:\WINDOWS\system.ini
[2010/03/22 20:33:50 | 000,000,074 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Application failed to initialize properly (0xc0000005) - Safer-Networking Forums.URL
[2010/03/22 20:01:32 | 000,000,836 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to HijackThis.exe.lnk
[2010/03/22 19:56:49 | 000,001,734 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2010/03/21 13:30:18 | 000,000,233 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Help with removal..Application failed to initialize - Safer-Networking Forums.url
[2010/03/21 12:46:20 | 000,188,200 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2010/03/21 12:42:11 | 000,001,374 | ---- | M] () -- C:\WINDOWS\imsins.BAK
[2010/03/20 13:25:09 | 000,002,217 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/03/20 09:43:54 | 000,044,544 | -H-- | M] () -- C:\WINDOWS\System32\bootnsvr.dll
[2010/03/18 20:21:07 | 000,033,792 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\T%20A%20197%20enthaply%20calculator(1).xls
[2010/03/15 23:50:37 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\http.doc
[2010/03/15 23:18:00 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/03/13 11:37:48 | 000,019,456 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\GAME Start at around.doc
[2010/03/07 04:22:02 | 000,029,184 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\URL SAMPLES.doc
[2010/03/07 03:32:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\tasks\Driver Robot.job
[2010/03/06 10:06:25 | 000,050,688 | ---- | M] () -- C:\Documents and Settings\Administrator\My Documents\AvP pic.doc
[2010/03/04 20:11:22 | 000,041,872 | ---- | M] () -- C:\WINDOWS\System32\xfcodec.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
[1 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/27 10:36:49 | 000,000,670 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to OTL.exe.lnk
[2010/03/26 21:45:58 | 000,004,252 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Attach.zip
[2010/03/26 21:45:30 | 000,004,252 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Attach.zip
[2010/03/26 21:30:23 | 000,076,407 | ---- | C] () -- C:\Documents and Settings\Administrator\Application Data\Smiley.ico
[2010/03/26 21:30:23 | 000,000,153 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Emoticons for your messenger!.url
[2010/03/26 21:30:18 | 000,000,626 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\jZip.lnk
[2010/03/26 19:53:14 | 000,000,716 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to ATF-Cleaner.exe.lnk
[2010/03/26 19:35:52 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 6.doc
[2010/03/25 22:44:27 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 7.doc
[2010/03/25 22:43:30 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 5.doc
[2010/03/25 00:13:13 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Mike.doc
[2010/03/25 00:12:50 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 4.doc
[2010/03/25 00:12:44 | 000,019,968 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 3.doc
[2010/03/25 00:12:38 | 000,020,992 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 2.doc
[2010/03/23 22:35:05 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Arc2.doc
[2010/03/23 22:34:34 | 000,023,552 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document 1.doc
[2010/03/22 22:03:30 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\Rescued document.doc
[2010/03/22 20:33:50 | 000,000,074 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Application failed to initialize properly (0xc0000005) - Safer-Networking Forums.URL
[2010/03/22 20:01:32 | 000,000,836 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to HijackThis.exe.lnk
[2010/03/22 19:56:49 | 000,001,734 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\HijackThis.lnk
[2010/03/21 13:29:37 | 000,000,233 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Help with removal..Application failed to initialize - Safer-Networking Forums.url
[2010/03/20 09:43:54 | 000,044,544 | -H-- | C] () -- C:\WINDOWS\System32\bootnsvr.dll
[2010/03/18 20:21:07 | 000,033,792 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\T%20A%20197%20enthaply%20calculator(1).xls
[2010/03/15 23:50:36 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\http.doc
[2010/03/13 11:37:48 | 000,019,456 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\GAME Start at around.doc
[2010/03/06 10:06:25 | 000,050,688 | ---- | C] () -- C:\Documents and Settings\Administrator\My Documents\AvP pic.doc
[2010/03/04 20:11:22 | 000,041,872 | ---- | C] () -- C:\WINDOWS\System32\xfcodec.dll
[2010/02/14 13:00:28 | 000,000,169 | ---- | C] () -- C:\WINDOWS\RtlRack.ini
[2010/02/14 12:21:32 | 000,000,164 | ---- | C] () -- C:\WINDOWS\avrack.ini
[2009/12/24 22:57:18 | 000,005,052 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\xqkcebzs.dik
[2009/10/18 11:14:12 | 000,237,568 | R--- | C] () -- C:\WINDOWS\System32\qtmlClient.dll
[2009/10/18 11:14:12 | 000,000,000 | ---- | C] () -- C:\WINDOWS\Graffiti5.2Pin.ini
[2009/09/07 23:32:37 | 000,000,136 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\fusioncache.dat
[2009/09/03 23:20:53 | 000,009,216 | ---- | C] () -- C:\Documents and Settings\Administrator\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/27 20:23:34 | 000,138,240 | ---- | C] () -- C:\WINDOWS\System32\Viasetup.dll
[2009/08/18 23:54:58 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\RtlCPAPI.dll
[2009/08/14 15:40:01 | 000,000,010 | ---- | C] () -- C:\WINDOWS\WININIT.INI
[2009/08/14 02:16:18 | 000,021,840 | ---- | C] () -- C:\WINDOWS\System32\SIntfNT.dll
[2009/08/14 02:16:18 | 000,017,212 | ---- | C] () -- C:\WINDOWS\System32\SIntf32.dll
[2009/08/14 02:16:18 | 000,012,067 | ---- | C] () -- C:\WINDOWS\System32\SIntf16.dll
[2009/01/29 13:54:16 | 000,004,819 | ---- | C] () -- C:\WINDOWS\PlainEnglish.INI
[2009/01/29 13:49:22 | 000,000,000 | ---- | C] () -- C:\WINDOWS\CmdLine.INI
[2009/01/28 19:12:56 | 000,002,473 | ---- | C] () -- C:\WINDOWS\PINPOINT.INI
[2009/01/28 16:19:31 | 000,806,912 | ---- | C] () -- C:\WINDOWS\System32\rvctl.dll
[2009/01/13 12:29:00 | 000,197,408 | ---- | C] () -- C:\WINDOWS\System32\vpnapi.dll
[2009/01/13 12:28:44 | 000,193,312 | ---- | C] () -- C:\WINDOWS\System32\CSGina.dll
[2008/10/15 18:54:36 | 000,001,024 | ---- | C] () -- C:\WINDOWS\System32\ASPRTMM0.DLL
[2008/02/08 17:13:44 | 000,319,488 | ---- | C] () -- C:\WINDOWS\System32\LS3Renderer.dll
[2007/05/14 11:13:20 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\rview.dll
[2007/05/03 18:30:24 | 000,000,369 | ---- | C] () -- C:\WINDOWS\ListView.INI
[2007/05/01 09:47:55 | 000,000,080 | ---- | C] () -- C:\WINDOWS\Continuum.INI
[2007/05/01 09:18:32 | 000,000,565 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2007/05/01 09:06:45 | 000,122,880 | ---- | C] () -- C:\WINDOWS\System32\Lfkodak.dll
[2007/05/01 09:06:44 | 000,338,944 | ---- | C] () -- C:\WINDOWS\System32\lffpx7.dll
[2007/05/01 09:06:41 | 000,145,408 | ---- | C] () -- C:\WINDOWS\System32\Bclw32.dll
[2006/01/02 09:54:37 | 000,000,550 | ---- | C] () -- C:\WINDOWS\lexstat.ini
[2006/01/02 09:54:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\lxbkvs.dll
[2006/01/02 09:54:25 | 000,077,824 | ---- | C] () -- C:\WINDOWS\System32\LXBKLCNP.DLL
[2006/01/02 09:54:14 | 000,000,266 | ---- | C] () -- C:\WINDOWS\System32\lxbkcoin.ini
[2002/02/27 17:28:16 | 000,138,752 | ---- | C] () -- C:\WINDOWS\System32\MASE32.DLL
[2002/02/27 17:28:16 | 000,057,856 | ---- | C] () -- C:\WINDOWS\System32\MASD32.DLL
[2002/02/27 17:28:14 | 000,196,096 | ---- | C] () -- C:\WINDOWS\System32\MACD32.DLL
[2002/02/27 17:28:14 | 000,136,192 | ---- | C] () -- C:\WINDOWS\System32\MAMC32.DLL
[2002/02/27 17:28:14 | 000,027,648 | ---- | C] () -- C:\WINDOWS\System32\MA32.DLL
========== LOP Check ==========
[2009/08/18 23:12:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Blitware
[2010/02/06 18:13:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Facebook
[2009/08/09 06:30:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\GetRightToGo
[2010/02/19 23:14:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\NCH Swift Sound
[2010/03/25 21:39:54 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\PnPDeviceMonitor
[2009/10/18 11:14:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\proDAD
[2009/12/02 23:54:08 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Radmin
[2009/10/15 20:57:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Recordpad
[2010/03/26 21:35:37 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Administrator\Application Data\Smart-Shopper
[2006/01/02 09:56:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BVRP Software
[2009/10/15 20:49:39 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\NCH Swift Sound
[2009/08/09 06:30:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Drivers HeadQuarters
[2009/10/18 10:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle
[2009/10/18 10:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Plus
[2009/10/18 11:03:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Pinnacle Studio Ultimate
[2009/10/18 10:58:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Studio 12
[2007/05/01 09:47:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TAC
[2010/03/26 21:21:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP
[2010/03/07 03:32:00 | 000,000,456 | ---- | M] () -- C:\WINDOWS\Tasks\Driver Robot.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2004/08/04 01:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:AGP440.sys
< MD5 for: ATAPI.SYS >
[2004/08/04 01:05:44 | 018,738,937 | ---- | M] () .cab file -- C:\WINDOWS\Driver Cache\i386\sp2.cab:atapi.sys
[2004/08/03 22:59:44 | 000,095,360 | ---- | M] (Microsoft Corporation) MD5=CDFE4411A69C224BD1D11B2DA92DAC51 -- C:\WINDOWS\system32\drivers\atapi.sys
< MD5 for: EVENTLOG.DLL >
[2004/08/04 00:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\ERDNT\cache\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\dllcache\eventlog.dll
[2004/08/04 00:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\eventlog.dll
< MD5 for: IASTOR.SYS >
[2005/12/17 17:42:04 | 000,874,240 | ---- | M] (Intel Corporation) MD5=309C4D86D989FB1FCF64BD30DC81C51B -- C:\WINDOWS\OEMDIR\iastor.sys
< MD5 for: LOGEVENT.DLL >
[2004/08/04 00:56:44 | 000,055,808 | ---- | M] (Microsoft Corporation) MD5=82B24CB70E5944E6E34662205A2A5B78 -- C:\WINDOWS\system32\logevent.dll
< MD5 for: NETLOGON.DLL >
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB968389\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\$hf_mig$\KB975467\SP2QFE\netlogon.dll
[2009/02/06 14:46:09 | 000,408,064 | ---- | M] (Microsoft Corporation) MD5=6C476D33D82F1054849790181E8F7772 -- C:\WINDOWS\SoftwareDistribution\Download\fbdd9f75315c1cf9ff63f37aaca267d3\sp2qfe\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\ERDNT\cache\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\dllcache\netlogon.dll
[2004/08/04 00:56:46 | 000,407,040 | ---- | M] (Microsoft Corporation) MD5=96353FCECBA774BB8DA74A1C6507015A -- C:\WINDOWS\system32\netlogon.dll
< MD5 for: NVATA.SYS >
[2005/08/18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\Backup\MB\IDE\NVATA.SYS
[2006/07/14 14:55:34 | 000,105,088 | R--- | M] (NVIDIA Corporation) MD5=7D960340BE5B0E008BB94E4C3B991339 -- C:\WINDOWS\system32\ReinstallBackups\0018\DriverFiles\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\drivers\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\ReinstallBackups\0011\DriverFiles\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\ReinstallBackups\0012\DriverFiles\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\ReinstallBackups\0017\DriverFiles\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\ReinstallBackups\0025\DriverFiles\nvata.sys
[2005/05/17 17:45:08 | 000,092,800 | R--- | M] (NVIDIA Corporation) MD5=DCE353985C988BFB7E84FD942068151F -- C:\WINDOWS\system32\ReinstallBackups\0026\DriverFiles\nvata.sys
< MD5 for: NVATABUS.SYS >
[2005/08/18 16:52:06 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\Backup\MB\SATA\NVATABUS.SYS
[2005/12/17 17:42:22 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\OEMDIR\nvatabus.sys
[2005/12/17 17:42:22 | 000,093,568 | ---- | M] (NVIDIA Corporation) MD5=0344AA9113DC16EEC379F4652020849D -- C:\WINDOWS\system32\drivers\nvatabus.sys
< MD5 for: NVGTS.SYS >
[2008/08/18 18:54:52 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sataraid\nvgts.sys
[2008/08/18 18:54:52 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\XP\nvgts.sys
[2008/08/18 18:54:52 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sataraid\nvgts.sys
[2008/08/18 18:54:52 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\XP\nvgts.sys
[2008/08/18 17:54:52 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=37954CD1D0AFC11BECD149F7C3EC88C2 -- C:\NVIDIA\nForceWinXPInt\20.09\IDE\WinXP\sataraid\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sata_ide\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\AHCI\XP\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sata_ide\nvgts.sys
[2008/08/18 18:54:24 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\AHCI\XP\nvgts.sys
[2008/08/18 17:54:24 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=EA98BFE4931BD13D747D647C1859796E -- C:\NVIDIA\nForceWinXPInt\20.09\IDE\WinXP\sata_ide\nvgts.sys
< MD5 for: NVRD32.SYS >
[2008/08/18 18:58:42 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=7894FFC354DDD5A0600BC112FFEC2DD0 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sataraid\nvrd32.sys
[2008/08/18 18:58:42 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=7894FFC354DDD5A0600BC112FFEC2DD0 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\Vista32\nvrd32.sys
[2008/08/18 18:58:42 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=7894FFC354DDD5A0600BC112FFEC2DD0 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sataraid\nvrd32.sys
[2008/08/18 18:58:42 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=7894FFC354DDD5A0600BC112FFEC2DD0 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\Vista32\nvrd32.sys
[2008/08/18 18:54:52 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sataraid\nvrd32.sys
[2008/08/18 18:54:52 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\XP\nvrd32.sys
[2008/08/18 18:54:52 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_XP32\IDE\WinXP\sataraid\nvrd32.sys
[2008/08/18 18:54:52 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\XP\nvrd32.sys
[2008/08/18 17:54:52 | 000,133,152 | ---- | M] (NVIDIA Corporation) MD5=BEF704AA9E17D176A46DDF77C6A52194 -- C:\NVIDIA\nForceWinXPInt\20.09\IDE\WinXP\sataraid\nvrd32.sys
< MD5 for: NVSTOR32.SYS >
[2008/08/18 18:58:42 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=2A0CC26D67B38460CC7563BC8313C1D6 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sataraid\nvstor32.sys
[2008/08/18 18:58:42 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=2A0CC26D67B38460CC7563BC8313C1D6 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\Vista32\nvstor32.sys
[2008/08/18 18:58:42 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=2A0CC26D67B38460CC7563BC8313C1D6 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sataraid\nvstor32.sys
[2008/08/18 18:58:42 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=2A0CC26D67B38460CC7563BC8313C1D6 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\RAID\Vista32\nvstor32.sys
[2008/08/18 18:58:16 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=8EE374B6FB3CB2BB8D70395218B464A5 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sata_ide\nvstor32.sys
[2008/08/18 18:58:16 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=8EE374B6FB3CB2BB8D70395218B464A5 -- C:\Documents and Settings\Administrator\Application Data\Blitware\DriverRobot\downloads\d9c4a57b918754ecdaf6de1aa782a0b5\NVIDIAnForceMCP78_Chipset_V1524_XPVista\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\AHCI\Vista32\nvstor32.sys
[2008/08/18 18:58:16 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=8EE374B6FB3CB2BB8D70395218B464A5 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\1524_Vista32\IDE\WinVista\sata_ide\nvstor32.sys
[2008/08/18 18:58:16 | 000,145,952 | ---- | M] (NVIDIA Corporation) MD5=8EE374B6FB3CB2BB8D70395218B464A5 -- C:\DRIVERS_MASTER\NVIDIAnForceMCP78_Chipset_V1524_XPVista\Disk\AHCI\Vista32\nvstor32.sys
< MD5 for: SCECLI.DLL >
[2004/08/04 00:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\ERDNT\cache\scecli.dll
[2004/08/04 00:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\dllcache\scecli.dll
[2004/08/04 00:56:46 | 000,180,224 | ---- | M] (Microsoft Corporation) MD5=0F78E27F563F2AAF74B91A49E2ABF19A -- C:\WINDOWS\system32\scecli.dll
< MD5 for: VIAMRAID.SYS >
[2005/12/17 17:42:26 | 000,060,928 | ---- | M] (VIA Technologies inc,.ltd) MD5=0363E216E4EB5052969C96608934DBDE -- C:\WINDOWS\OEMDIR\viamraid.sys
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/09/29 22:20:58 | 000,442,368 | ---- | M] (Advanced Micro Devices, Inc.)[b] Unable to obtain MD5 -- C:\WINDOWS\system32\ATIDEMGX.dll
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2007/04/30 09:25:15 | 000,094,208 | ---- | M] () -- C:\WINDOWS\system32\config\default.sav
[2007/04/30 09:25:15 | 000,659,456 | ---- | M] () -- C:\WINDOWS\system32\config\software.sav
[2007/04/30 09:25:15 | 000,888,832 | ---- | M] () -- C:\WINDOWS\system32\config\system.sav
========== Alternate Data Streams ==========
@Alternate Data Stream - 125 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:5C321E34
< End of report >