Jump to content

Virus XP security!


Recommended Posts

I have virus named "xp security" C:\Documents and Settings\Vartotojas\Local Settings\Application Data\ave.exe he is there but when i go to C:\Documents and Settings\Vartotojas\Local Settings\Application Data\ there is no file ave.exe. + i malware bytes isint updating i get error error code 732 (12007, 0) . so i cant delete that virus. some one please respond!

here's hijack

MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Process Blocker\Process Blocker.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Process Blocker\Tray Informer.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

C:\Program Files\Thomson SpeedTouch\PPPoE\fts.exe

C:\WINDOWS\FixCamera.exe

C:\WINDOWS\tsnp2std.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe

C:\Program Files\Messenger\msmsgs.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\JDK\jdk\bin\javaw.exe

C:\WINDOWS\System32\alg.exe

C:\Program Files\Spyware Doctor\pctsTray.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\ashSimpl.exe

C:\Documents and Settings\Vartotojas\Local Settings\Application Data\ave.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\WINDOWS\system32\msiexec.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\Program Files\TrendMicro\HiJackThis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: GdfrDUEn - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll

O2 - BHO: HP Smart Web Printing 1.0 - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll

O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll

O4 - HKLM\..\Run: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE

O4 - HKLM\..\Run: [skyTel] SkyTel.EXE

O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE

O4 - HKLM\..\Run: [%FP%PPPoE fts.exe] "C:\Program Files\Thomson SpeedTouch\PPPoE\fts.exe"

O4 - HKLM\..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe

O4 - HKLM\..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe

O4 - HKLM\..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [NT Update] C:\Program Files\Common Files\Microsoft Services\Console\ntupd.exe

O4 - HKLM\..\Run: [Regedit32] C:\WINDOWS\system32\regedit.exe

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\freda.exe" /runcleanupscript

O4 - HKLM\..\Run: [syncman] c:\windows\system32\wuaucldt.exe

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [iSTray] "C:\Program Files\Spyware Doctor\pctsTray.exe"

O4 - HKLM\..\Run: [spyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe

O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hidden

O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized

O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background

O4 - HKCU\..\Run: [NT Update] C:\Program Files\Common Files\Microsoft Services\Console\ntupd.exe

O4 - HKCU\..\Run: [syncman] c:\documents and settings\vartotojas\wuaucldt.exe

O4 - HKCU\..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe

O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKCU\..\Run: [eMuleAutoStart] C:\zMule\zmule.exe -AutoStart

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: monnwb32.exe

O4 - Startup: SDK Tray Menu.lnk = ?

O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe

O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

O4 - Global Startup: Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm

O9 - Extra 'Tools' menuitem: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/...lscbase8942.cab

O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL

O18 - Filter hijack: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - C:\Documents and Settings\Vartotojas\AppData\LocalLow\Micro

Edited by Maurice Naggar
emphasis added
Link to post
Share on other sites

Forum rules do not allow other members to reply to a malware removal case. This thread is for xryckaxx. All others may not post. I have deleted the other posts by others.

@xryckaxx

Review and do as much as you can of the required preliminaries, as per forum requirements.

http://forums.malwarebytes.org/index.php?showtopic=9573

Reply back with log files. Again, do as much as possible of the listed directions in the topic.

and please have -patience- there are many, many other members ahead of you. This forum is super-busy.

Most of the authorized helpers are volunteers, so keep that in mind as well.

Link to post
Share on other sites

P.S. I must insist you un-install utorrent + emule/zmule and any other peer-to-peer programs before proceeding further.

Peer-to-peer apps are one of the leading causes of transmission of malware.

File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

P2P file sharing: Know the risks

It is also forum policy to not support cases having P-2P programs.

and also, turn OFF Spybot's Tea Timer as it will interfere with malware removal.

Just so you are aware, forum policy requires removal of any peer-to-peer programs.

We will not be party to obvious use of key gens, cracks, warez or other illegal means of downloading software, music, videos ect. This means no P2P evidence will be supported. Logs that show these in them, will given the option to remove the P2P items.

Keygens, cracks, warez and similar will have the thread closed period. It's theft and against the law.

Link to post
Share on other sites

Is this pc the same as the one in your other thread --> http://forums.malwarebytes.org/index.php?showtopic=43703

I suspect so, and it would appear it has multiple infections onboard.

I would urge you to do what I suggested AND to do the preliminary steps & reports (reply back here)

as outlined in I'm infected - What do I do now?

Link to post
Share on other sites

This is dds Log:

DDS (Ver_10-03-17.01) - NTFSx86

Run by Vartotojas at 12:37:09.67 on Thu 03/19/2009

Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_16

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1919.1160 [GMT 2:00]

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

svchost.exe

C:\WINDOWS\system32\svchost.exe -k hpdevmgmt

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\Common Files\LightScribe\LSSrvc.exe

C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\WINDOWS\System32\svchost.exe -k HPZ12

C:\Program Files\Process Blocker\Process Blocker.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\WINDOWS\explorer.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Malwarebytes' Anti-Malwares\mbam.exe

C:\Program Files\Skype\Plugin Manager\skypePM.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Windows Media Player\wmplayer.exe

C:\Documents and Settings\Vartotojas\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = about:blank

BHO: GdfrDUEn Class: {a3cf7606-e683-4375-a372-96b75da0aef7} - c:\program files\get styles\enlbrdr.dll

BHO: CPrintEnhancer Object: {ae84a6aa-a333-4b92-b276-c11e2212e4fe} - c:\program files\hp\smart web printing\SmartWebPrinting.dll

BHO: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll

BHO: Java Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: Ask Toolbar: {d4027c7f-154a-4066-a1ad-4243d8127440} - c:\program files\ask.com\GenericAskToolbar.dll

uRun: [LightScribe Control Panel] c:\program files\common files\lightscribe\LightScribeControlPanel.exe -hidden

uRun: [EleFunAnimatedWallpaper]

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

uRun: [MSMSGS] "c:\program files\messenger\msmsgs.exe" /background

uRun: [NT Update] c:\program files\common files\microsoft services\console\ntupd.exe

uRun: [sUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe

uRun: [PC Suite Tray] "c:\program files\nokia\nokia pc suite 7\PCSuite.exe" -onlytray

uRun: [eMuleAutoStart] c:\zmule\zmule.exe -AutoStart

uRun: [uTorrent] "c:\program files\utorrent\uTorrent.exe"

mRun: [siSPower] Rundll32.exe SiSPower.dll,ModeAgent

mRun: [RTHDCPL] RTHDCPL.EXE

mRun: [skyTel] SkyTel.EXE

mRun: [Alcmtr] ALCMTR.EXE

mRun: [%FP%PPPoE fts.exe] "c:\program files\thomson speedtouch\pppoe\fts.exe"

mRun: [FixCamera] c:\windows\FixCamera.exe

mRun: [sunJavaUpdateSched] "c:\program files\java\jre6\bin\jusched.exe"

mRun: [HP Software Update] c:\program files\hp\hp software update\HPWuSchd2.exe

mRun: [tsnp2std] c:\windows\tsnp2std.exe

mRun: [snp2std] c:\windows\vsnp2std.exe

mRun: [Amazing3DAquariumWallpaper]

mRun: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

mRun: [NT Update] c:\program files\common files\microsoft services\console\ntupd.exe

mRun: [iSTray] "c:\program files\spyware doctor\pctsTray.exe"

mRun: [spyHunter Security Suite] c:\program files\enigma software group\spyhunter\SpyHunter3.exe

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

StartupFolder: c:\docume~1\vartot~1\startm~1\programs\startup\sdktra~1.lnk - c:\program files\jdk\jdk\bin\javaw.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\hpdigi~1.lnk - c:\program files\hp\digital imaging\bin\hpqtra08.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\interv~1.lnk - c:\program files\intervideo\common\bin\WinCinemaMgr.exe

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\utilit~1.lnk - c:\windows\system32\sistray.exe

IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000

IE: {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\get styles\ct.htm

IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL

DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase8942.cab

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_16-windows-i586.cab

Filter: text/html - {574940E0-1B7A-4881-8FA3-1E809714B156} - c:\documents and settings\vartotojas\appdata\locallow\micro

Attach.zip

Link to post
Share on other sites

Set Windows to show all files and all folders.

On your Desktop, double click My Computer, from the menu options, select tools, then Folder Options, and then select VIEW Tab and look at all of settings listed.

"CHECK" (turn on) Display the contents of system folders.

Under column, Hidden files and folders----choose ( *select* ) Show hidden files and folders.

Next, un-check Hide extensions for known file types.

Next un-check Hide protected operating system files.

Please download Rooter.exe and save to your desktop.

alternate download link

  • Double-click on Rooter.exe to start the tool. If using Vista, right-click and Run as Administrator...
  • Click the Scan button to begin.
  • Once the scan is complete, Notepad will open with a report named Rooter_#.txt (where # is the number assigned to the report).
  • A folder will be created at the %systemdrive% (usually, C:\Rooter$) where the log will be saved.
  • Rooter will automatically close. If it doesn't, just press the Close button.
  • Copy and paste the contents of Rooter_#.txt in your next reply.

Important: Before performing a scan it is recommended to do the following to ensure more accurate results and avoid common issues that may cause false detections.

  • Disconnect from the Internet or physically unplug you Internet cable connection.
  • Close all open programs, scheduling/updating tasks and background processes that might activate during the scan including the screensaver.
  • Temporarily disable your anti-virus and real-time anti-spyware protection.
  • After starting the scan, do not use the computer until the scan has completed.
  • When finished, re-enable your anti-virus/anti-malware (or reboot) and then you can reconnect to the Internet.

Copy & Paste the contents of Rooter log

Link to post
Share on other sites

Rooter.exe (v1.0.2) by Eric_71

.

SeDebugPrivilege granted successfully ...

.

Windows XP . (5.1.2600) Service Pack 2

[32_bits] - x86 Family 6 Model 15 Stepping 2, GenuineIntel

.

[wscsvc] STOPPED (state:1) : Security Center -> Disabled !

[sharedAccess] STOPPED (state:1) : Windows Firewall -> Disabled !

.

Internet Explorer 6.0.2900.2180

Mozilla Firefox 3.6 (en-US)

.

C:\ [Fixed-NTFS] .. ( Total:39 Go - Free:5 Go )

D:\ [Fixed-NTFS] .. ( Total:333 Go - Free:136 Go )

E:\ [Removable]

F:\ [Removable]

G:\ [Removable]

H:\ [Removable]

.

Scan : 13:37.07

Path : C:\Documents and Settings\Vartotojas\Desktop\Rooter.exe

User : Vartotojas ( Administrator -> YES )

.

----------------------\\ Processes

.

Locked [system Process] (0)

______ System (4)

______ \SystemRoot\System32\smss.exe (672)

______ \??\C:\WINDOWS\system32\csrss.exe (720)

______ \??\C:\WINDOWS\system32\winlogon.exe (744)

______ C:\WINDOWS\system32\services.exe (788)

______ C:\WINDOWS\system32\lsass.exe (800)

______ C:\WINDOWS\system32\svchost.exe (976)

______ C:\WINDOWS\system32\svchost.exe (1024)

______ C:\WINDOWS\System32\svchost.exe (1120)

______ C:\WINDOWS\system32\svchost.exe (1240)

______ C:\WINDOWS\system32\svchost.exe (1280)

______ C:\WINDOWS\system32\spoolsv.exe (1520)

______ C:\Program Files\TortoiseSVN\bin\TSVNCache.exe (1888)

______ C:\WINDOWS\system32\svchost.exe (1988)

______ C:\WINDOWS\system32\svchost.exe (172)

______ C:\Program Files\Java\jre6\bin\jqs.exe (200)

______ C:\Program Files\Common Files\LightScribe\LSSrvc.exe (232)

______ C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (284)

______ C:\WINDOWS\System32\svchost.exe (528)

______ C:\WINDOWS\System32\svchost.exe (540)

______ C:\Program Files\Process Blocker\Process Blocker.exe (556)

______ C:\WINDOWS\system32\svchost.exe (644)

______ C:\WINDOWS\explorer.exe (1864)

______ C:\Program Files\Skype\Phone\Skype.exe (2236)

______ C:\Program Files\Skype\Plugin Manager\skypePM.exe (2336)

______ C:\Documents and Settings\Vartotojas\Desktop\Rooter.exe (2184)

.

----------------------\\ Device\Harddisk0\

.

\Device\Harddisk0 [sectors : 63 x 512 Bytes]

.

\Device\Harddisk0\Partition1 --[ MBR ]-- (Start_Offset:32256 | Length:41940670464)

\Device\Harddisk0\Partition0 (Start_Offset:41940702720 | Length:358136916480)

\Device\Harddisk0\Partition2 (Start_Offset:41940734976 | Length:358136884224)

.

----------------------\\ Scheduled Tasks

.

C:\WINDOWS\Tasks\desktop.ini

C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job

C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job

C:\WINDOWS\Tasks\SA.DAT

C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

C:\WINDOWS\Tasks\WGASetup.job

.

----------------------\\ Registry

.

.

----------------------\\ Files & Folders

.

----------------------\\ Scan completed at 13:37.09

.

C:\Rooter$\Rooter_2.txt - (19/03/2009 | 13:37.09)

Link to post
Share on other sites

Close the programs that you have started.

Start HijackThis. Look for these lines and place a checkmark against each of the following, if still present

O4 - HKLM\..\Run: [NT Update] C:\Program Files\Common Files\Microsoft Services\Console\ntupd.exe

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"

O4 - HKCU\..\Run: [eMuleAutoStart] C:\zMule\zmule.exe -AutoStart

Click on Fix Checked when finished and exit HijackThis.

Make sure your Internet Explorer (& or any other window) is closed when you click Fix Checked!

I must insist you un-install utorrent + emule/zmule and any other peer-to-peer programs before proceeding further.

Peer-to-peer apps are one of the leading causes of transmission of malware.

File-Sharing, otherwise known as Peer To Peer and Risks of File-Sharing Technology.

P2P file sharing: Know the risks

It is also forum policy to not support cases having P-2P programs.

Go To Control Panel > Add-or-Remove Programs.

Look for emule

uTorrent

zmule

Remove (de-install) each of those.

Make a confirmation in your reply that these are removed.

More needs to be done to look for any leftover malware, but you must remove peer-to-peer first.

Otherwise, I cannot help you further.

Link to post
Share on other sites

Step 1

1. Go >> Here << and download ERUNT

(ERUNT (Emergency Recovery Utility NT) is a free program that allows you to keep a complete backup of your registry and restore it when needed.)

2. Install ERUNT by following the prompts

(use the default install settings but say no to the portion that asks you to add ERUNT to the start-up folder, if you like you can enable this option later)

3. Start ERUNT

(either by double clicking on the desktop icon or choosing to start the program at the end of the setup)

4. Choose a location for the backup

(the default location is C:\WINDOWS\ERDNT which is acceptable).

5. Make sure that at least the first two check boxes are ticked

6. Press OK

7. Press YES to create the folder.

Step 2

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

For directions on how, see How To Temporarily Disable Your Anti-virus, Firewall And Anti-malware Programs

Do NOT turn off the firewall

If you have a prior copy of Combofix, delete it now !

Download Combofix from any of the links below. You must rename it before saving it. Save it to your Desktop.

Link 1

Link 2

Link 3

CF_download_FF.gif

CF_download_rename.gif

* IMPORTANT !!! SAVE AS Combo-Fix.exe to your Desktop

If your I.E. browser shows a warning message at the top, do a Right-Click on the bar and select Download, saving it to the Desktop.

  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • Double click on Combo-Fix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.

RcAuto1.gif

Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

whatnext.png

Click on Yes, to continue scanning for malware.

Please watch Combofix as it runs, as you may see messages which require your response, or the pressing of OK button.

When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.

-------------------------------------------------------

A caution - Do not run Combofix more than once.

Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock.

The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled.

If this occurs, please reboot to restore the desktop.

RE-Enable your AntiVirus and AntiSpyware applications.

Use NOTEPAD. Copy and Paste the contents of C:\Combofix.txt in your next reply

Link to post
Share on other sites

Attaching because list is very big.. Reply fast as you can :)

ComboFix 10-03-18.02 - Vartotojas 03/19/2009 16:05:08.1.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1919.1301 [GMT 2:00]

Running from: c:\documents and settings\Vartotojas\Desktop\Combo-Fix.exe

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

c:\documents and settings\Vartotojas\Local Settings\Temporary Internet Files\86U781VAn.jpg

c:\documents and settings\Vartotojas\Local Settings\Temporary Internet Files\rDT31vaw3.jpg

c:\documents and settings\Vartotojas\Local Settings\Temporary Internet Files\rEn45J.jpg

c:\documents and settings\Vartotojas\Local Settings\Temporary Internet Files\xGe1xKQD1.jpg

c:\program files\Cheat Engine\dbk32.sys

C:\tmp.tmp

C:\tmp2.tmp

c:\windows\f96ac0e5-19d2-42c5-8f68-eb7a99861769.ocx

c:\windows\install.exe

c:\windows\system32\2d2ca2ce-704a-428c-8cbe-0736b29190aa.dll

c:\windows\system32\404Fix.exe

c:\windows\system32\Agent.OMZ.Fix.exe

c:\windows\system32\config\systemprofile\oashdihasidhasuidhiasdhiashdiuasdhasd

c:\windows\system32\detoured.dll

c:\windows\system32\dumphive.exe

c:\windows\system32\IEDFix.C.exe

c:\windows\system32\IEDFix.exe

c:\windows\system32\o4Patch.exe

c:\windows\system32\Process.exe

c:\windows\system32\SrchSTS.exe

c:\windows\system32\system.dll

c:\windows\system32\tmp.reg

c:\windows\system32\VACFix.exe

c:\windows\system32\VCCLSID.exe

c:\windows\system32\WS2Fix.exe

c:\windows\system32\drivers\cdrom.sys was missing

Restored copy from - c:\system volume information\_restore{65FDBE99-7781-4DA7-8FA9-79B1712C1C85}\RP16\A0015596.sys

.

((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))

.

2020-01-28 17:59 . 2020-01-28 17:59 50354 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\uninstall.exe

2020-01-28 17:59 . 2020-01-28 17:59 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Facebook

2020-01-27 14:48 . 2020-01-27 14:48 -------- d-----w- C:\Phenomedia AG

2020-01-24 19:14 . 2020-01-24 19:14 116792 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2020-01-24 16:48 . 2020-01-24 16:48 -------- d-----w- c:\program files\Zeallsoft

2020-01-24 16:32 . 2020-01-24 16:32 85643 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_6FEFF9B68218417F98F549.exe

2020-01-24 16:32 . 2020-01-24 16:32 370070 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_BF3C002E03AB416E34DB8F.exe

2020-01-24 16:32 . 2020-01-24 16:32 370070 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_36C7B9CDD08DEADA24A112.exe

2020-01-24 16:32 . 2020-01-24 16:32 -------- d-----w- c:\program files\FogelSoft

2020-01-20 09:22 . 2020-01-20 09:22 -------- d-----w- c:\program files\Infogrames

2012-02-17 12:34 . 2012-02-17 12:34 -------- d-----w- c:\program files\Common Files\Skype

2012-02-15 10:19 . 2012-02-15 10:19 -------- d-----w- c:\program files\Common Files\3DO Shared

2012-02-15 10:19 . 2012-02-15 10:19 -------- d-----w- c:\program files\3DO

2012-02-14 17:14 . 2012-02-14 17:20 -------- d-----w- C:\.takerevenge_v8

2012-02-14 11:00 . 2012-02-14 11:00 16286 ----a-w- c:\documents and settings\Vartotojas\Application Data\Sun\Java\Deployment\cache\6.0\5\42c06805-2faf84f7-n\ShoddyHelper.dll

2012-02-12 17:47 . 2012-02-12 17:47 -------- d-----w- c:\program files\GetFLV

2012-02-12 15:48 . 2012-02-12 15:48 -------- d-----w- C:\landofescape_file_store_32

2010-02-26 06:41 . 2010-02-26 06:41 847040 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\axfbootloader.dll

2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\npfbplugin_1_0_3.dll

2010-02-06 12:10 . 2010-02-06 12:10 -------- d-----w- c:\program files\Get Styles

2010-02-06 12:10 . 2010-02-06 12:10 -------- d-----w- c:\documents and settings\Vartotojas\AppData

2010-02-04 17:21 . 2010-02-04 17:21 -------- d-----w- c:\program files\TikGames

2010-02-04 12:39 . 2010-02-04 12:57 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\DC++

2010-02-04 12:39 . 2010-02-04 12:39 -------- d-----w- c:\documents and settings\Vartotojas\Local Settings\Application Data\DC++

2010-02-02 15:38 . 2010-02-02 15:38 -------- d-----w- c:\program files\RS2Botv2

2010-02-02 15:38 . 2010-02-02 15:38 -------- d-----w- c:\documents and settings\Vart

2010-02-02 13:13 . 2010-02-02 13:14 151552 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\sysinfo.exe

2010-02-02 13:13 . 2010-02-02 13:14 1153816 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\flash.exe

2010-02-02 13:13 . 2010-02-02 13:14 1638404 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\swfplayer.exe

2010-02-02 13:13 . 2010-02-02 13:13 98304 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\wallpaper.exe

2010-02-02 13:13 . 2010-02-02 13:13 57344 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\wallpaper.dll

2010-02-02 13:13 . 2010-02-02 13:13 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\elefundesktops

2010-02-02 12:59 . 2010-02-02 13:05 -------- d-----w- c:\program files\Tetris 5000

2010-01-26 18:32 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll

2010-01-26 18:32 . 2010-01-26 18:32 -------- d-----w- C:\Games

2010-01-26 14:59 . 2020-01-23 15:32 -------- d-----w- c:\program files\CrisisX

2010-01-26 12:29 . 2010-01-26 12:29 -------- d-----w- c:\documents and settings\Vartotojas\50_Funny_Computer_Pranks_All_In_One

2010-01-26 12:26 . 2009-03-06 18:07 -------- d-----w- c:\documents and settings\Vartotojas\.tucan

2010-01-26 12:26 . 2010-01-26 12:26 -------- d-----w- C:\Tucan

2010-01-26 12:24 . 2010-01-26 12:24 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\URSoft

2010-01-26 12:18 . 2002-12-03 01:10 158208 ----a-w- c:\windows\system32\NCTTextToAudio.dll

2010-01-26 12:18 . 2002-12-03 01:02 491520 ----a-w- c:\windows\system32\NCTAudioFile.dll

2010-01-26 12:18 . 2002-03-19 05:18 120832 ----a-w- c:\windows\system32\lame_enc.dll

2010-01-26 12:18 . 2010-01-26 12:18 -------- d-----w- c:\program files\AliveMedia

2010-01-23 16:36 . 2010-01-23 16:43 -------- d-----w- C:\.trinitypk_file_store_32

2010-01-23 16:35 . 2010-01-23 16:35 -------- d-----w- c:\program files\TrinityPk Client 2.8

2010-01-23 12:01 . 2010-01-23 12:07 -------- d-----w- C:\.sabsabi_store_32

2010-01-23 11:54 . 2010-01-23 12:52 -------- d-----w- C:\.SabsabiOnline_file_store_32

2010-01-22 18:00 . 2010-01-22 18:00 -------- d-----w- c:\program files\BestPractice

2010-01-22 17:42 . 2010-01-22 17:45 118383 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\wimood-plugins-uninstall.exe

2010-01-22 17:42 . 2010-01-22 17:42 1412608 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\WiMood.exe

2010-01-22 17:42 . 2010-01-22 17:42 13312 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\iTunesCollector.dll

2010-01-22 17:42 . 2010-01-22 17:42 1095299 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\wimood-plugins-setup.exe

2010-01-22 17:36 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll

2010-01-22 17:36 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll

2010-01-22 17:36 . 2010-01-22 17:36 -------- d-----w- c:\windows\Logs

2010-01-22 17:29 . 2010-01-22 17:29 -------- d-----w- c:\program files\WiMood

2010-01-22 13:01 . 2010-01-22 13:01 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\UNOUndercover

2010-01-21 16:16 . 2010-01-21 16:16 98304 ----a-w- c:\windows\system32\CmdLineExt.dll

2010-01-18 18:58 . 2010-01-18 18:58 557107 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\RichChat4.exe

2010-01-18 18:58 . 2010-01-18 18:58 53248 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\EmoticonOle.dll

2010-01-18 18:58 . 2010-01-18 18:58 433664 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\riched20.dll

2010-01-18 18:58 . 2010-01-18 18:58 1712128 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\GdiPlus.dll

2010-01-18 18:57 . 2010-01-18 18:57 147456 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Interop.SKYPE4COMLib.dll

2010-01-18 18:57 . 2010-01-18 18:57 14328 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Skype_uzrasai_ENG.vshost.exe

2010-01-18 18:57 . 2010-01-18 18:57 119808 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Skype_uzrasai_ENG.exe

2010-01-18 17:01 . 2010-02-02 15:00 -------- d-----w- C:\rscache

2010-01-16 17:06 . 2010-01-16 17:06 -------- d-----w- C:\tob_cache_32

2010-01-14 17:18 . 2010-01-14 17:24 -------- d-----w- c:\documents and settings\Vartotojas\Local Settings\Application Data\Adobe

2010-01-14 17:18 . 2010-01-14 17:18 -------- d-----w- c:\program files\Common Files\Adobe

2010-01-12 16:50 . 2010-01-12 16:50 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\ArcticLine

2010-01-12 16:50 . 2010-01-12 16:50 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Thinstall

2010-01-12 16:45 . 2010-01-12 16:45 -------- d-----w- c:\program files\Common Files\Totem Shared

2010-01-11 13:53 . 2010-01-11 13:53 -------- d-----w- c:\windows\cache554

2010-01-10 16:37 . 2010-01-10 16:37 -------- d-----w- C:\.jagex_cache_32

2010-01-10 08:54 . 2010-01-18 12:58 69 ----a-w- c:\documents and settings\Vartotojas\jagex_runescape_preferences2.dat

2010-01-09 20:04 . 2010-01-11 13:53 -------- d-----w- C:\cache554

2010-01-09 19:08 . 2010-01-09 19:08 -------- d-----w- c:\program files\Yamicsoft

2010-01-05 10:22 . 2010-01-05 10:22 -------- d-----w- c:\program files\SystemRequirementsLab

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll

2010-01-05 10:22 . 2010-01-05 10:22 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab

2010-01-03 14:48 . 2020-01-31 08:12 -------- d-----w- c:\windows\Governor of Poker

2010-01-03 14:48 . 2010-01-03 14:48 -------- d-----w- c:\program files\Governor of Poker

2009-12-31 21:00 . 2009-12-31 21:05 -------- d-----w- C:\tobex_bluurr_32

2009-12-31 19:14 . 2009-12-31 19:14 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\fltk.org

2009-12-28 14:47 . 2009-12-28 14:48 -------- d-----w- c:\program files\Quake III Arena

2009-12-28 14:44 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe

2009-12-25 20:09 . 2005-01-26 13:45 349472 ----a-w- c:\windows\WindowsXP-KB822603-x86.exe

2009-12-25 20:09 . 2006-11-29 14:11 258048 ----a-w- c:\windows\tsnp2std.exe

2009-12-25 20:09 . 2006-09-15 11:21 675840 ----a-w- c:\windows\vsnp2std.exe

2009-12-25 20:09 . 2007-01-26 14:48 12028032 ----a-w- c:\windows\system32\drivers\snp2sxp.sys

2009-12-25 20:09 . 2007-01-25 16:48 25472 ----a-w- c:\windows\system32\drivers\sncamd.sys

2009-12-25 20:09 . 2007-02-05 13:25 151552 ----a-w- c:\windows\system32\rsnp2std.dll

2009-12-25 20:09 . 2006-10-03 12:35 249856 ----a-w- c:\windows\system32\vsnp2std.dll

2009-12-25 20:09 . 2009-12-25 20:09 -------- d-----w- c:\program files\Common Files\snp2std

2009-12-25 20:09 . 2006-11-16 13:57 77824 ----a-w- c:\windows\system32\csnp2std.dll

2009-12-22 16:52 . 2009-12-22 16:57 -------- d-----w- C:\.paradise_file_store_32

2009-12-22 10:19 . 2009-12-22 10:38 -------- d-----w- C:\DF

2009-12-21 12:30 . 2009-12-21 12:39 -------- d-----w- C:\massacred_store_32

2009-12-17 17:18 . 2009-12-17 17:18 -------- d-----w- c:\program files\GhostMouse 2.0

2009-12-17 17:18 . 1997-01-04 10:23 246272 ----a-w- c:\program files\Gmouse.exe

2009-12-17 17:18 . 1996-02-07 06:07 24576 ----a-w- c:\program files\_ISREG32.DLL

2009-12-17 17:03 . 2009-12-17 17:03 2008576 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\04B85A4AD92F471CB8EC199BEBD26C57\Emotion_detector.dll

2009-12-17 14:34 . 2010-01-14 17:55 -------- d-----w- c:\documents and settings\Vartotojas\hs_cachefiles

2009-12-17 09:58 . 2009-12-13 21:42 364320 ----a-w- C:\WindowsXP-KB825033-x86-ENU.exe

2009-12-17 09:58 . 2009-12-13 21:42 147232 ----a-w- C:\WindowsXP-KB825033-x86-ENU-Symbols.exe

2009-12-16 10:56 . 2009-03-18 08:08 -------- d--h--w- c:\windows\PIF

2009-12-13 18:18 . 2009-12-13 18:18 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Printer Info Cache

2009-12-13 18:18 . 2009-12-13 18:18 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Image Zone Express

2009-12-13 18:17 . 2009-12-13 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG

2009-12-13 18:16 . 2009-12-13 08:33 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\HP

2009-12-13 18:15 . 2009-12-13 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY

2009-12-13 18:14 . 2009-12-13 18:16 -------- d-----w- c:\program files\Common Files\HP

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\program files\Hewlett-Packard

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\program files\Common Files\Hewlett-Packard

2009-12-13 18:13 . 2009-12-13 18:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard

2009-12-13 18:13 . 2006-12-15 16:04 258048 ----a-r- c:\windows\system32\hpzids01.dll

2009-12-13 18:13 . 2006-12-30 13:49 117760 ----a-w- c:\windows\system32\hpzll4v2.dll

2009-12-13 18:13 . 2006-12-29 07:57 273920 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp4v2.dll

2009-12-13 18:13 . 2006-12-06 06:02 364544 ----a-r- c:\windows\system32\hppldcoi.dll

2009-12-13 18:13 . 2006-12-06 06:02 309760 ----a-r- c:\windows\system32\difxapi.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2020-01-27 14:20 . 2009-09-28 16:57 39 ----a-w- c:\documents and settings\Vartotojas\jagex_runescape_preferences.dat

2020-01-20 09:17 . 2020-01-20 09:17 339 ----a-w- c:\documents and settings\Vartotojas\Application Data\settings.dat

2012-02-17 12:34 . 2009-09-28 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2010-02-05 07:25 . 2009-03-17 14:52 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-02-05 07:17 . 2009-03-17 14:52 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-01-23 08:29 . 2010-01-22 17:35 -------- d-----w- c:\program files\Winamp

2010-01-18 18:56 . 2010-01-18 18:56 32 ----a-w- c:\documents and settings\All Users\Application Data\ezsid.dat

2010-01-07 14:07 . 2009-03-18 08:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-07 14:07 . 2009-03-18 08:01 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-31 15:06 . 2005-10-13 20:36 352640 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-22 05:35 . 2006-03-02 07:28 668672 ----a-w- c:\windows\system32\wininet.dll

2009-12-22 05:35 . 2004-08-03 23:56 81920 ----a-w- c:\windows\system32\ieencode.dll

2009-12-17 17:19 . 2009-12-17 17:18 1685 ----a-w- c:\program files\DeIsL1.isu

2009-12-16 12:58 . 2009-09-28 10:00 343040 ----a-w- c:\windows\system32\mspaint.exe

2009-12-14 07:35 . 2004-08-03 23:56 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-08 18:11 . 2006-02-18 23:47 2142720 ----a-w- c:\windows\system32\ntoskrnl.exe

2009-12-08 17:35 . 2005-10-19 18:35 2020864 ----a-w- c:\windows\system32\ntkrnlpa.exe

2009-12-04 13:37 . 2006-01-16 20:39 456832 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2009-11-27 17:04 . 2006-01-16 20:39 1291776 ----a-w- c:\windows\system32\quartz.dll

2009-11-27 17:04 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll

2009-11-27 16:37 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll

2009-11-27 16:37 . 2004-08-03 23:56 11264 ----a-w- c:\windows\system32\msrle32.dll

2009-11-27 16:37 . 2004-08-03 23:56 84992 ----a-w- c:\windows\system32\avifil32.dll

2009-11-27 16:37 . 2001-08-23 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll

2009-11-27 16:37 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll

2009-11-21 16:36 . 2004-08-03 23:56 470528 ----a-w- c:\windows\AppPatch\aclayers.dll

2009-10-21 05:50 . 2004-08-03 23:56 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:50 . 2004-08-03 23:56 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 14:41 . 2005-10-14 16:17 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-15 16:56 . 2006-01-16 20:39 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-10-15 16:56 . 2006-01-16 20:39 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-10-15 12:46 . 2009-09-28 10:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-10-13 10:53 . 2004-08-03 23:56 266752 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:54 . 2004-08-03 23:56 69632 ----a-w- c:\windows\system32\raschap.dll

2009-10-12 13:54 . 2004-08-03 23:56 112128 ----a-w- c:\windows\system32\rastls.dll

2009-10-06 14:31 . 2009-03-17 14:52 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-09-29 09:49 . 2009-09-29 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Astroburn Lite

2009-09-29 09:40 . 2009-09-29 09:40 -------- d-----w- c:\program files\Astroburn Toolbar

2009-09-29 09:40 . 2009-09-29 09:40 -------- d-----w- c:\program files\Astroburn Lite

2009-09-29 09:39 . 2009-09-29 09:39 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Astroburn Lite

2009-09-29 09:29 . 2009-09-28 19:41 -------- d-----w- c:\program files\Common Files\Nero

2009-09-29 09:22 . 2009-09-29 09:22 -------- d-----w- c:\program files\Common Files\LightScribe

2009-09-29 09:08 . 2009-09-29 09:07 -------- d-----w- c:\program files\Philips

2009-09-29 09:07 . 2009-09-29 09:07 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\InstallShield

2009-09-29 07:13 . 2009-09-28 19:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero

2009-09-29 06:39 . 2009-09-29 06:39 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Nero

2009-09-28 19:56 . 2009-09-28 19:41 -------- d-----w- c:\program files\Nero

2009-09-28 19:55 . 2009-09-28 19:55 -------- d-----w- c:\program files\Windows Sidebar

2009-09-28 17:44 . 2009-09-28 17:44 -------- d-----w- c:\program files\AT Screen Thief 3.8

2009-09-28 17:19 . 2009-09-28 13:26 -------- d-----w- c:\program files\InterVideo

2009-09-28 17:11 . 2009-09-28 17:11 -------- d-----w- c:\program files\Ask.com

2009-09-28 17:07 . 2009-09-28 17:07 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Ahead

2009-09-28 16:30 . 2009-09-28 16:30 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-09-28 16:21 . 2009-09-28 16:21 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\vlc

2009-09-28 16:18 . 2009-09-28 16:18 -------- d-----w- c:\program files\Common Files\FTL Shared

2009-09-28 16:18 . 2009-09-28 16:09 -------- d-----w- c:\program files\Thomson SpeedTouch

2009-09-28 14:02 . 2009-09-28 14:02 -------- d-----w- c:\program files\Realtek

2009-09-28 14:02 . 2009-09-28 14:02 315392 ----a-w- c:\windows\HideWin.exe

2009-09-28 13:58 . 2009-09-28 13:58 -------- d-----w- c:\program files\SiS VGA Utilities V3.80

2009-09-28 13:58 . 2009-09-28 13:58 -------- d-----w- c:\program files\sisagp

2009-09-28 13:34 . 2009-09-28 13:34 -------- d-----w- c:\program files\Microsoft.NET

2009-09-28 13:34 . 2009-09-28 13:34 -------- d-----w- c:\program files\Microsoft ActiveSync

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\program files\VideoLAN

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\InterVideo

2009-09-28 13:26 . 2009-09-28 13:58 -------- d-----w- c:\program files\Common Files\InstallShield

2009-09-28 10:04 . 2009-09-28 10:04 -------- d-----w- c:\program files\microsoft frontpage

2009-09-28 10:01 . 2009-09-28 10:01 21640 ----a-w- c:\windows\system32\emptyregdb.dat

2009-09-28 10:01 . 2009-09-28 10:01 -------- d-----w- c:\program files\Windows Media Connect 2

2009-09-23 14:10 . 2009-03-17 14:52 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-09-16 01:20 . 2009-03-17 14:52 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat

2009-09-15 04:20 . 2009-03-17 14:52 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat

2009-09-15 00:12 . 2009-03-17 14:52 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat

2009-09-15 00:01 . 2009-03-17 14:52 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat

2009-09-11 14:03 . 2004-08-03 23:56 136192 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-04 20:45 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-08-26 08:16 . 2004-08-03 23:56 247326 ----a-w- c:\windows\system32\strmdll.dll

2009-08-25 09:47 . 2004-08-03 23:56 352256 ----a-w- c:\windows\system32\winhttp.dll

2009-08-19 15:07 . 2009-08-19 15:07 1415000 ----a-w- c:\windows\system32\msxml6.dll

2009-08-14 11:22 . 2005-11-08 22:13 1859328 ----a-w- c:\windows\system32\win32k.sys

2009-08-14 07:59 . 2009-03-17 13:22 33662272 ----a-r- c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Setup.exe

2009-08-06 17:24 . 2009-09-28 10:02 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 17:24 . 2009-09-28 10:02 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 17:24 . 2009-09-28 10:02 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 17:24 . 2005-10-12 08:00 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 17:24 . 2009-09-28 10:02 53472 ----a-w- c:\windows\system32\wuauclt.exe

2009-08-06 17:24 . 2005-10-12 08:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 17:23 . 2009-09-28 10:02 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 17:23 . 2009-09-28 10:02 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-06 17:23 . 2005-10-12 08:00 215920 ----a-w- c:\windows\system32\muweb.dll

2009-08-05 09:11 . 2004-08-03 23:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL

2009-07-31 13:23 . 2009-09-28 16:46 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-07-31 04:57 . 2005-10-12 16:14 1172480 ----a-w- c:\windows\system32\msxml3.dll

2009-07-20 22:05 . 2009-07-20 22:05 1348432 ----a-w- c:\windows\system32\msxml4.dll

2009-07-17 18:55 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\atl.dll

2009-07-17 16:27 . 2004-08-03 23:56 1435648 ----a-w- c:\windows\system32\query.dll

2009-07-13 08:08 . 2006-01-13 18:15 286720 ----a-w- c:\windows\system32\wmpdxm.dll

2009-06-25 18:36 . 2004-08-03 23:56 95744 ----a-w- c:\windows\system32\mqsec.dll

2009-06-25 18:36 . 2004-08-03 23:56 661504 ----a-w- c:\windows\system32\mqqm.dll

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]

2010-02-05 17:23 185856 ----a-w- c:\program files\Get Styles\enlbrdr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]

2009-09-02 11:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-05-18 2363392]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]

"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SiSPower"="SiSPower.dll" [2007-04-10 53248]

"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 16125440]

"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]

"%FP%PPPoE fts.exe"="c:\program files\Thomson SpeedTouch\PPPoE\fts.exe" [2004-01-07 77312]

"FixCamera"="c:\windows\FixCamera.exe" [2007-01-30 20480]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]

"tsnp2std"="c:\windows\tsnp2std.exe" [2006-11-29 258048]

"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]

"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]

"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\

SDK Tray Menu.lnk - c:\program files\JDK\jdk\bin\javaw.exe [2009-11-19 139264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-9-28 303104]

Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-9-28 262144]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Vartotojas^Start Menu^Programs^Startup^Ftwscape 508 Client.lnk]

path=c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\Ftwscape 508 Client.lnk

backup=c:\windows\pss\Ftwscape 508 Client.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Vartotojas^Start Menu^Programs^Startup^Ftwscpe 508 Client.lnk]

path=c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\Ftwscpe 508 Client.lnk

backup=c:\windows\pss\Ftwscpe 508 Client.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\cs 2\\hl.exe"=

"d:\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe"=

"d:\\Empire Earth\\Empire Earth.exe"=

"d:\\cs copy\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"d:\\kiets zaidas\\Geimas\\age2_x1.exe"=

"d:\\Copyof ECSROeris\\SilkErrSender.exe"=

"c:\\Documents and Settings\\Vartotojas\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=

"c:\\WINDOWS\\system32\\java.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

"d:\\Counter-Strike Source\\hl2.exe"=

"c:\\Sun\\SDK\\jdk\\bin\\java.exe"=

"c:\\Program Files\\JDK\\jdk\\bin\\java.exe"=

"d:\\Strongholdcrusaders\\Stronghold Crusader.exe"=

"c:\\Documents and Settings\\Vartotojas\\My Documents\\Downloads\\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\\Stronghold Crusader\\Stronghold_Crusader_Extreme.exe"=

"c:\\Documents and Settings\\Vartotojas\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=

"c:\\Documents and Settings\\Vartotojas\\My Documents\\Downloads\\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\\Stronghold Crusader\\Stronghold Crusader.exe"=

"d:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=

"c:\\WINDOWS\\system32\\dplaysvr.exe"=

"d:\\sad nub\\WOGAI\\Heroes3.exe"=

"c:\\WINDOWS\\system32\\dpnsvr.exe"=

"d:\\Konami\\Yu-Gi-Oh! Power of Chaos JOEY THE PASSION\\joey_pc.exe"=

"d:\\Left 4 Dead\\left4dead.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

"d:\\wormsarm\\WA.exe"=

"d:\\kveikas\\Quake3\\quake3.exe"=

"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Documents and Settings\\Vartotojas\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"d:\\Earth`s Special Forces\\esfas\\ESF\\hl.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4749:TCP"= 4749:TCP:faxdypp

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]

R2 Process Blocker;Process Blocker;c:\program files\Process Blocker\Process Blocker.exe [5/20/2009 6:14 PM 96472]

R3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]

S0 muxv;muxv;c:\windows\system32\drivers\utfyu.sys --> c:\windows\system32\drivers\utfyu.sys [?]

S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/29/2009 7:35 PM 722416]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/3/2009 11:57 AM 133104]

S3 XDva279;XDva279;\??\c:\windows\system32\XDva279.sys --> c:\windows\system32\XDva279.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

uvkftj

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-05-18 14:54 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

2009-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 09:57]

2020-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 09:57]

2009-03-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 11:56]

2009-03-19 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-12-13 20:18]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Get Styles\ct.htm

FF - ProfilePath - c:\documents and settings\Vartotojas\Application Data\Mozilla\Firefox\Profiles\nnfj11aw.default\

FF - prefs.js: browser.startup.homepage - google.lt

FF - plugin: c:\documents and settings\Vartotojas\Application Data\Facebook\npfbplugin_1_0_3.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

.

- - - - ORPHANS REMOVED - - - -

HKCU-Run-EleFunAnimatedWallpaper - (no file)

HKLM-Run-Amazing3DAquariumWallpaper - (no file)

HKLM-Run-NT Update - c:\program files\Common Files\Microsoft Services\Console\ntupd.exe

MSConfigStartUp-ares - c:\program files\Ares\Ares.exe

MSConfigStartUp-uTorrent - c:\program files\uTorrent\uTorrent.exe

MSConfigStartUp-WinampAgent - c:\program files\Winamp\winampa.exe

MSConfigStartUp-yahoo! - c:\docume~1\VARTOT~1\LOCALS~1\Temp\5910312956don.dll

AddRemove-Astroburn Toolbar - c:\program files\Astroburn Toolbar\uninst.exe

AddRemove-BoxRune 525 - c:\documents and settings\Vartotojas\Desktop\BoxRune 525\Uninstal.exe

AddRemove-CrisisX_0 - c:\program files\CrisisX\CrisisX Client v8.2.5\Uninstall.exe

AddRemove-CrisisX_1 - c:\program files\CrisisX\CrisisX Client v8.5\Uninstall.exe

AddRemove-CrisisX_2 - c:\program files\CrisisX\CrisisX Client v8.6\Uninstall.exe

AddRemove-DAEMON Tools Toolbar - c:\program files\DAEMON Tools Toolbar\uninst.exe

AddRemove-FarmVille Tools_is1 - c:\farmvilletools\unins000.exe

AddRemove-Magic Ball 3_is1 - c:\documents and settings\Vartotojas\Desktop\Magic Ball 1

AddRemove-ProPilkki2 - c:\program files\ProPilkki2\uninstall.exe

AddRemove-Ricochet Infinity_is1 - c:\documents and settings\Vartotojas\My Documents\Downloads\Reflexive Arcade\Ricochet Infinity 3.68\ReflexiveArcade\unins000.exe

AddRemove-Wild Tangent - Fate - c:\documents and settings\Vartotojas\My Documents\Downloads\FATE 1&2\Fate 1\Uninstal.exe

AddRemove-{8C3727F2-8E37-49E4-820C-03B1677F53B6} - c:\program files\InstallShield Installation Information\{8C3727F2-8E37-49E4-820C-03B1677F53B6}\setup.exe

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-19 16:09

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(744)

c:\program files\SUPERAntiSpyware\SASWINLO.dll

.

Completion time: 2009-03-19 16:11:26

ComboFix-quarantined-files.txt 2009-03-19 14:11

Pre-Run: 5,427,249,152 bytes free

Post-Run: 5,490,040,832 bytes free

Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5

- - End Of File - - 851FBE73B906F1C7813FF6669131BAF6

Edited by Maurice Naggar
CF log place In-line
Link to post
Share on other sites

Do NOT use the attach mechanism to put your reports. Always use Copy & Paste and put the report into the body of reply box. The other way adds extra steps for your helper AND is unwanted because your system is an infection case.

You will want to print out or copy these instructions to Notepad for offline reference!

Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools

Close any open browsers and any other program you started.

Open notepad and copy/paste the text in the quotebox below into it:

http://forums.malwarebytes.org/index.php?showtopic=43642

Suspect::

c:\program files\Common Files\Microsoft Services\Console\ntupd.exe

DirLook::

c:\program files\Common Files\Microsoft Services\Console

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

Note:

Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

**Note**

When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture files to submit for analysis.

Ensure you are connected to the internet and click OK on the message box.

Please let me know if the file was successfully submitted . Thanks.

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

=

Use your browser to go here at Virustotal website

Click the Browse button and then navigate to c:\program files\Common Files\Microsoft Services\Console\ntupd.exe, then click the Submit button.

The various virus scanners will identify the file and if it is not identified, the AV vendors will then have a copy of it for analysis. Save the results, and post back here in a reply.

Save the results, and post back here in a reply.

=

Start your MBAM MalwareBytes' Anti-Malware.

Click the Settings Tab. Make sure all option lines have a checkmark.

Next, Click the Update tab. Press the "Check for Updates" button.

When done, click the Scanner tab.

Do a FULL Scan.

When the scan is complete, click OK, then Show Results to view the results.

Make sure that everything is checked, and click Remove Selected.

When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)

The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Reply with the latest C:\Combofix.txt

the Virustotal report

and the latest MBAM scan log

and tell me, How is your system now ?

Link to post
Share on other sites

ComboFix 10-03-18.02 - Vartotojas 03/19/2009 17:34:55.2.2 - x86

Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1919.1405 [GMT 2:00]

Running from: c:\documents and settings\Vartotojas\Desktop\Combo-Fix.exe

Command switches used :: c:\documents and settings\Vartotojas\Desktop\CFScript.txt

AV: AVG Anti-Virus plus Firewall *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FW: AVG Firewall *disabled* {8decf618-9569-4340-b34a-d78d28969b66}

.

((((((((((((((((((((((((( Files Created from 2009-02-19 to 2009-03-19 )))))))))))))))))))))))))))))))

.

2020-01-28 17:59 . 2020-01-28 17:59 50354 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\uninstall.exe

2020-01-28 17:59 . 2020-01-28 17:59 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Facebook

2020-01-27 14:48 . 2020-01-27 14:48 -------- d-----w- C:\Phenomedia AG

2020-01-24 19:14 . 2020-01-24 19:14 116792 ----a-w- c:\documents and settings\LocalService\Local Settings\Application Data\FontCache3.0.0.0.dat

2020-01-24 16:48 . 2020-01-24 16:48 -------- d-----w- c:\program files\Zeallsoft

2020-01-24 16:32 . 2020-01-24 16:32 85643 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_6FEFF9B68218417F98F549.exe

2020-01-24 16:32 . 2020-01-24 16:32 370070 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_BF3C002E03AB416E34DB8F.exe

2020-01-24 16:32 . 2020-01-24 16:32 370070 ----a-r- c:\documents and settings\Vartotojas\Application Data\Microsoft\Installer\{05FA911F-E9CE-4C36-A272-A45CCE52C1C0}\_36C7B9CDD08DEADA24A112.exe

2020-01-24 16:32 . 2020-01-24 16:32 -------- d-----w- c:\program files\FogelSoft

2020-01-20 09:22 . 2020-01-20 09:22 -------- d-----w- c:\program files\Infogrames

2012-02-17 12:34 . 2012-02-17 12:34 -------- d-----w- c:\program files\Common Files\Skype

2012-02-15 10:19 . 2012-02-15 10:19 -------- d-----w- c:\program files\Common Files\3DO Shared

2012-02-15 10:19 . 2012-02-15 10:19 -------- d-----w- c:\program files\3DO

2012-02-14 17:14 . 2012-02-14 17:20 -------- d-----w- C:\.takerevenge_v8

2012-02-14 11:00 . 2012-02-14 11:00 16286 ----a-w- c:\documents and settings\Vartotojas\Application Data\Sun\Java\Deployment\cache\6.0\5\42c06805-2faf84f7-n\ShoddyHelper.dll

2012-02-12 17:47 . 2012-02-12 17:47 -------- d-----w- c:\program files\GetFLV

2012-02-12 15:48 . 2012-02-12 15:48 -------- d-----w- C:\landofescape_file_store_32

2010-02-26 06:41 . 2010-02-26 06:41 847040 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\axfbootloader.dll

2010-02-26 06:41 . 2010-02-26 06:41 5582848 ----a-w- c:\documents and settings\Vartotojas\Application Data\Facebook\npfbplugin_1_0_3.dll

2010-02-06 12:10 . 2010-02-06 12:10 -------- d-----w- c:\program files\Get Styles

2010-02-06 12:10 . 2010-02-06 12:10 -------- d-----w- c:\documents and settings\Vartotojas\AppData

2010-02-04 17:21 . 2010-02-04 17:21 -------- d-----w- c:\program files\TikGames

2010-02-04 12:39 . 2010-02-04 12:57 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\DC++

2010-02-04 12:39 . 2010-02-04 12:39 -------- d-----w- c:\documents and settings\Vartotojas\Local Settings\Application Data\DC++

2010-02-02 15:38 . 2010-02-02 15:38 -------- d-----w- c:\program files\RS2Botv2

2010-02-02 15:38 . 2010-02-02 15:38 -------- d-----w- c:\documents and settings\Vart

2010-02-02 13:13 . 2010-02-02 13:14 151552 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\sysinfo.exe

2010-02-02 13:13 . 2010-02-02 13:14 1153816 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\flash.exe

2010-02-02 13:13 . 2010-02-02 13:14 1638404 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\swfplayer.exe

2010-02-02 13:13 . 2010-02-02 13:13 98304 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\wallpaper.exe

2010-02-02 13:13 . 2010-02-02 13:13 57344 ----a-w- c:\documents and settings\Vartotojas\Application Data\elefundesktops\dragonfly_wallpaper\wallpaper.dll

2010-02-02 13:13 . 2010-02-02 13:13 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\elefundesktops

2010-02-02 12:59 . 2010-02-02 13:05 -------- d-----w- c:\program files\Tetris 5000

2010-01-26 18:32 . 2008-03-05 13:56 3786760 ----a-w- c:\windows\system32\D3DX9_37.dll

2010-01-26 18:32 . 2010-01-26 18:32 -------- d-----w- C:\Games

2010-01-26 14:59 . 2020-01-23 15:32 -------- d-----w- c:\program files\CrisisX

2010-01-26 12:29 . 2010-01-26 12:29 -------- d-----w- c:\documents and settings\Vartotojas\50_Funny_Computer_Pranks_All_In_One

2010-01-26 12:26 . 2009-03-06 18:07 -------- d-----w- c:\documents and settings\Vartotojas\.tucan

2010-01-26 12:26 . 2010-01-26 12:26 -------- d-----w- C:\Tucan

2010-01-26 12:24 . 2010-01-26 12:24 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\URSoft

2010-01-26 12:18 . 2002-12-03 01:10 158208 ----a-w- c:\windows\system32\NCTTextToAudio.dll

2010-01-26 12:18 . 2002-12-03 01:02 491520 ----a-w- c:\windows\system32\NCTAudioFile.dll

2010-01-26 12:18 . 2002-03-19 05:18 120832 ----a-w- c:\windows\system32\lame_enc.dll

2010-01-26 12:18 . 2010-01-26 12:18 -------- d-----w- c:\program files\AliveMedia

2010-01-23 16:36 . 2010-01-23 16:43 -------- d-----w- C:\.trinitypk_file_store_32

2010-01-23 16:35 . 2010-01-23 16:35 -------- d-----w- c:\program files\TrinityPk Client 2.8

2010-01-23 12:01 . 2010-01-23 12:07 -------- d-----w- C:\.sabsabi_store_32

2010-01-23 11:54 . 2010-01-23 12:52 -------- d-----w- C:\.SabsabiOnline_file_store_32

2010-01-22 18:00 . 2010-01-22 18:00 -------- d-----w- c:\program files\BestPractice

2010-01-22 17:42 . 2010-01-22 17:45 118383 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\wimood-plugins-uninstall.exe

2010-01-22 17:42 . 2010-01-22 17:42 1412608 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\WiMood.exe

2010-01-22 17:42 . 2010-01-22 17:42 13312 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\iTunesCollector.dll

2010-01-22 17:42 . 2010-01-22 17:42 1095299 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\2B83EECD4CF4910A0260B914BA281BA\wimood-plugins-setup.exe

2010-01-22 17:36 . 2009-09-04 15:29 1892184 ----a-w- c:\windows\system32\D3DX9_42.dll

2010-01-22 17:36 . 2006-09-28 14:05 2414360 ----a-w- c:\windows\system32\d3dx9_31.dll

2010-01-22 17:36 . 2010-01-22 17:36 -------- d-----w- c:\windows\Logs

2010-01-22 17:29 . 2010-01-22 17:29 -------- d-----w- c:\program files\WiMood

2010-01-22 13:01 . 2010-01-22 13:01 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\UNOUndercover

2010-01-21 16:16 . 2010-01-21 16:16 98304 ----a-w- c:\windows\system32\CmdLineExt.dll

2010-01-18 18:58 . 2010-01-18 18:58 557107 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\RichChat4.exe

2010-01-18 18:58 . 2010-01-18 18:58 53248 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\EmoticonOle.dll

2010-01-18 18:58 . 2010-01-18 18:58 433664 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\riched20.dll

2010-01-18 18:58 . 2010-01-18 18:58 1712128 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\F6E4F248A04D453E940CFCED80F21C48\GdiPlus.dll

2010-01-18 18:57 . 2010-01-18 18:57 147456 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Interop.SKYPE4COMLib.dll

2010-01-18 18:57 . 2010-01-18 18:57 14328 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Skype_uzrasai_ENG.vshost.exe

2010-01-18 18:57 . 2010-01-18 18:57 119808 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\FAD056AD55AA4877BB40184CF49E754C\Skype_uzrasai_ENG.exe

2010-01-18 17:01 . 2010-02-02 15:00 -------- d-----w- C:\rscache

2010-01-16 17:06 . 2010-01-16 17:06 -------- d-----w- C:\tob_cache_32

2010-01-14 17:18 . 2010-01-14 17:24 -------- d-----w- c:\documents and settings\Vartotojas\Local Settings\Application Data\Adobe

2010-01-14 17:18 . 2010-01-14 17:18 -------- d-----w- c:\program files\Common Files\Adobe

2010-01-12 16:50 . 2010-01-12 16:50 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\ArcticLine

2010-01-12 16:50 . 2010-01-12 16:50 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Thinstall

2010-01-12 16:45 . 2010-01-12 16:45 -------- d-----w- c:\program files\Common Files\Totem Shared

2010-01-11 13:53 . 2010-01-11 13:53 -------- d-----w- c:\windows\cache554

2010-01-10 16:37 . 2010-01-10 16:37 -------- d-----w- C:\.jagex_cache_32

2010-01-10 08:54 . 2010-01-18 12:58 69 ----a-w- c:\documents and settings\Vartotojas\jagex_runescape_preferences2.dat

2010-01-09 20:04 . 2010-01-11 13:53 -------- d-----w- C:\cache554

2010-01-09 19:08 . 2010-01-09 19:08 -------- d-----w- c:\program files\Yamicsoft

2010-01-05 10:22 . 2010-01-05 10:22 -------- d-----w- c:\program files\SystemRequirementsLab

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_d.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_c.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_b.dll

2010-01-05 10:22 . 2010-01-05 10:22 138240 ----a-w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab\SRLProxy_srl_4_1_14_0_a.dll

2010-01-05 10:22 . 2010-01-05 10:22 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\SystemRequirementsLab

2010-01-03 14:48 . 2020-01-31 08:12 -------- d-----w- c:\windows\Governor of Poker

2010-01-03 14:48 . 2010-01-03 14:48 -------- d-----w- c:\program files\Governor of Poker

2009-12-31 21:00 . 2009-12-31 21:05 -------- d-----w- C:\tobex_bluurr_32

2009-12-31 19:14 . 2009-12-31 19:14 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\fltk.org

2009-12-28 14:47 . 2009-12-28 14:48 -------- d-----w- c:\program files\Quake III Arena

2009-12-28 14:44 . 1998-10-29 14:45 306688 ----a-w- c:\windows\IsUninst.exe

2009-12-25 20:09 . 2005-01-26 13:45 349472 ----a-w- c:\windows\WindowsXP-KB822603-x86.exe

2009-12-25 20:09 . 2006-11-29 14:11 258048 ----a-w- c:\windows\tsnp2std.exe

2009-12-25 20:09 . 2006-09-15 11:21 675840 ----a-w- c:\windows\vsnp2std.exe

2009-12-25 20:09 . 2007-01-26 14:48 12028032 ----a-w- c:\windows\system32\drivers\snp2sxp.sys

2009-12-25 20:09 . 2007-01-25 16:48 25472 ----a-w- c:\windows\system32\drivers\sncamd.sys

2009-12-25 20:09 . 2007-02-05 13:25 151552 ----a-w- c:\windows\system32\rsnp2std.dll

2009-12-25 20:09 . 2006-10-03 12:35 249856 ----a-w- c:\windows\system32\vsnp2std.dll

2009-12-25 20:09 . 2009-12-25 20:09 -------- d-----w- c:\program files\Common Files\snp2std

2009-12-25 20:09 . 2006-11-16 13:57 77824 ----a-w- c:\windows\system32\csnp2std.dll

2009-12-22 16:52 . 2009-12-22 16:57 -------- d-----w- C:\.paradise_file_store_32

2009-12-22 10:19 . 2009-12-22 10:38 -------- d-----w- C:\DF

2009-12-21 12:30 . 2009-12-21 12:39 -------- d-----w- C:\massacred_store_32

2009-12-17 17:18 . 2009-12-17 17:18 -------- d-----w- c:\program files\GhostMouse 2.0

2009-12-17 17:18 . 1997-01-04 10:23 246272 ----a-w- c:\program files\Gmouse.exe

2009-12-17 17:18 . 1996-02-07 06:07 24576 ----a-w- c:\program files\_ISREG32.DLL

2009-12-17 17:03 . 2009-12-17 17:03 2008576 ----a-w- c:\documents and settings\All Users\Application Data\Skype\Plugins\Plugins\04B85A4AD92F471CB8EC199BEBD26C57\Emotion_detector.dll

2009-12-17 14:34 . 2010-01-14 17:55 -------- d-----w- c:\documents and settings\Vartotojas\hs_cachefiles

2009-12-17 09:58 . 2009-12-13 21:42 364320 ----a-w- C:\WindowsXP-KB825033-x86-ENU.exe

2009-12-17 09:58 . 2009-12-13 21:42 147232 ----a-w- C:\WindowsXP-KB825033-x86-ENU-Symbols.exe

2009-12-16 10:56 . 2009-03-18 08:08 -------- d--h--w- c:\windows\PIF

2009-12-13 18:18 . 2009-12-13 18:18 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Printer Info Cache

2009-12-13 18:18 . 2009-12-13 18:18 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Image Zone Express

2009-12-13 18:17 . 2009-12-13 18:17 -------- d-----w- c:\documents and settings\All Users\Application Data\WEBREG

2009-12-13 18:16 . 2009-12-13 08:33 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\HP

2009-12-13 18:15 . 2009-12-13 18:15 -------- d-----w- c:\documents and settings\All Users\Application Data\HP

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\documents and settings\All Users\Application Data\HPSSUPPLY

2009-12-13 18:14 . 2009-12-13 18:16 -------- d-----w- c:\program files\Common Files\HP

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\program files\Hewlett-Packard

2009-12-13 18:14 . 2009-12-13 18:14 -------- d-----w- c:\program files\Common Files\Hewlett-Packard

2009-12-13 18:13 . 2009-12-13 18:13 -------- d-----w- c:\documents and settings\All Users\Application Data\Hewlett-Packard

2009-12-13 18:13 . 2006-12-15 16:04 258048 ----a-r- c:\windows\system32\hpzids01.dll

2009-12-13 18:13 . 2006-12-30 13:49 117760 ----a-w- c:\windows\system32\hpzll4v2.dll

2009-12-13 18:13 . 2006-12-29 07:57 273920 ----a-w- c:\windows\system32\Spool\prtprocs\w32x86\hpzpp4v2.dll

2009-12-13 18:13 . 2006-12-06 06:02 364544 ----a-r- c:\windows\system32\hppldcoi.dll

2009-12-13 18:13 . 2006-12-06 06:02 309760 ----a-r- c:\windows\system32\difxapi.dll

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2020-01-27 14:20 . 2009-09-28 16:57 39 ----a-w- c:\documents and settings\Vartotojas\jagex_runescape_preferences.dat

2020-01-20 09:17 . 2020-01-20 09:17 339 ----a-w- c:\documents and settings\Vartotojas\Application Data\settings.dat

2012-02-17 12:34 . 2009-09-28 16:29 -------- d-----w- c:\documents and settings\All Users\Application Data\Skype

2010-02-05 07:25 . 2009-03-17 14:52 70408 ----a-w- c:\windows\system32\drivers\pctplsg.sys

2010-02-05 07:17 . 2009-03-17 14:52 233136 ----a-w- c:\windows\system32\drivers\pctgntdi.sys

2010-01-23 08:29 . 2010-01-22 17:35 -------- d-----w- c:\program files\Winamp

2010-01-18 18:56 . 2010-01-18 18:56 32 ----a-w- c:\documents and settings\All Users\Application Data\ezsid.dat

2010-01-07 14:07 . 2009-03-18 08:01 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys

2010-01-07 14:07 . 2009-03-18 08:01 19160 ----a-w- c:\windows\system32\drivers\mbam.sys

2009-12-31 15:06 . 2005-10-13 20:36 352640 ----a-w- c:\windows\system32\drivers\srv.sys

2009-12-22 05:35 . 2006-03-02 07:28 668672 ------w- c:\windows\system32\wininet.dll

2009-12-22 05:35 . 2004-08-03 23:56 81920 ----a-w- c:\windows\system32\ieencode.dll

2009-12-17 17:19 . 2009-12-17 17:18 1685 ----a-w- c:\program files\DeIsL1.isu

2009-12-16 12:58 . 2009-09-28 10:00 343040 ----a-w- c:\windows\system32\mspaint.exe

2009-12-14 07:35 . 2004-08-03 23:56 33280 ----a-w- c:\windows\system32\csrsrv.dll

2009-12-08 18:11 . 2006-02-18 23:47 2142720 ------w- c:\windows\system32\ntoskrnl.exe

2009-12-08 17:35 . 2005-10-19 18:35 2020864 ------w- c:\windows\system32\ntkrnlpa.exe

2009-12-04 13:37 . 2006-01-16 20:39 456832 ----a-w- c:\windows\system32\drivers\mrxsmb.sys

2009-11-27 17:04 . 2006-01-16 20:39 1291776 ----a-w- c:\windows\system32\quartz.dll

2009-11-27 17:04 . 2004-08-04 00:56 17920 ----a-w- c:\windows\system32\msyuv.dll

2009-11-27 16:37 . 2004-08-04 00:56 48128 ----a-w- c:\windows\system32\iyuv_32.dll

2009-11-27 16:37 . 2004-08-03 23:56 11264 ----a-w- c:\windows\system32\msrle32.dll

2009-11-27 16:37 . 2004-08-03 23:56 84992 ----a-w- c:\windows\system32\avifil32.dll

2009-11-27 16:37 . 2001-08-23 12:00 28672 ----a-w- c:\windows\system32\msvidc32.dll

2009-11-27 16:37 . 2001-08-17 22:36 8704 ----a-w- c:\windows\system32\tsbyuv.dll

2009-11-21 16:36 . 2004-08-03 23:56 470528 ----a-w- c:\windows\AppPatch\aclayers.dll

2009-10-21 05:50 . 2004-08-03 23:56 75776 ----a-w- c:\windows\system32\strmfilt.dll

2009-10-21 05:50 . 2004-08-03 23:56 25088 ----a-w- c:\windows\system32\httpapi.dll

2009-10-20 14:41 . 2005-10-14 16:17 265728 ----a-w- c:\windows\system32\drivers\http.sys

2009-10-15 16:56 . 2006-01-16 20:39 119808 ----a-w- c:\windows\system32\t2embed.dll

2009-10-15 16:56 . 2006-01-16 20:39 81920 ----a-w- c:\windows\system32\fontsub.dll

2009-10-15 12:46 . 2009-09-28 10:03 86327 ----a-w- c:\windows\pchealth\helpctr\OfflineCache\index.dat

2009-10-13 10:53 . 2004-08-03 23:56 266752 ----a-w- c:\windows\system32\oakley.dll

2009-10-12 13:54 . 2004-08-03 23:56 69632 ----a-w- c:\windows\system32\raschap.dll

2009-10-12 13:54 . 2004-08-03 23:56 112128 ----a-w- c:\windows\system32\rastls.dll

2009-10-06 14:31 . 2009-03-17 14:52 87784 ----a-w- c:\windows\system32\drivers\PCTAppEvent.sys

2009-09-29 09:49 . 2009-09-29 09:39 -------- d-----w- c:\documents and settings\All Users\Application Data\Astroburn Lite

2009-09-29 09:40 . 2009-09-29 09:40 -------- d-----w- c:\program files\Astroburn Toolbar

2009-09-29 09:40 . 2009-09-29 09:40 -------- d-----w- c:\program files\Astroburn Lite

2009-09-29 09:39 . 2009-09-29 09:39 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Astroburn Lite

2009-09-29 09:29 . 2009-09-28 19:41 -------- d-----w- c:\program files\Common Files\Nero

2009-09-29 09:22 . 2009-09-29 09:22 -------- d-----w- c:\program files\Common Files\LightScribe

2009-09-29 09:08 . 2009-09-29 09:07 -------- d-----w- c:\program files\Philips

2009-09-29 09:07 . 2009-09-29 09:07 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\InstallShield

2009-09-29 07:13 . 2009-09-28 19:41 -------- d-----w- c:\documents and settings\All Users\Application Data\Nero

2009-09-29 06:39 . 2009-09-29 06:39 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Nero

2009-09-28 19:56 . 2009-09-28 19:41 -------- d-----w- c:\program files\Nero

2009-09-28 19:55 . 2009-09-28 19:55 -------- d-----w- c:\program files\Windows Sidebar

2009-09-28 17:44 . 2009-09-28 17:44 -------- d-----w- c:\program files\AT Screen Thief 3.8

2009-09-28 17:19 . 2009-09-28 13:26 -------- d-----w- c:\program files\InterVideo

2009-09-28 17:11 . 2009-09-28 17:11 -------- d-----w- c:\program files\Ask.com

2009-09-28 17:07 . 2009-09-28 17:07 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\Ahead

2009-09-28 16:30 . 2009-09-28 16:30 56 ---ha-w- c:\windows\system32\ezsidmv.dat

2009-09-28 16:21 . 2009-09-28 16:21 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\vlc

2009-09-28 16:18 . 2009-09-28 16:18 -------- d-----w- c:\program files\Common Files\FTL Shared

2009-09-28 16:18 . 2009-09-28 16:09 -------- d-----w- c:\program files\Thomson SpeedTouch

2009-09-28 14:02 . 2009-09-28 14:02 -------- d-----w- c:\program files\Realtek

2009-09-28 14:02 . 2009-09-28 14:02 315392 ----a-w- c:\windows\HideWin.exe

2009-09-28 13:58 . 2009-09-28 13:58 -------- d-----w- c:\program files\SiS VGA Utilities V3.80

2009-09-28 13:58 . 2009-09-28 13:58 -------- d-----w- c:\program files\sisagp

2009-09-28 13:34 . 2009-09-28 13:34 -------- d-----w- c:\program files\Microsoft.NET

2009-09-28 13:34 . 2009-09-28 13:34 -------- d-----w- c:\program files\Microsoft ActiveSync

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\program files\VideoLAN

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\documents and settings\All Users\Application Data\InterVideo

2009-09-28 13:29 . 2009-09-28 13:29 -------- d-----w- c:\documents and settings\Vartotojas\Application Data\InterVideo

2009-09-28 13:26 . 2009-09-28 13:58 -------- d-----w- c:\program files\Common Files\InstallShield

2009-09-28 10:04 . 2009-09-28 10:04 -------- d-----w- c:\program files\microsoft frontpage

2009-09-28 10:01 . 2009-09-28 10:01 21640 ----a-w- c:\windows\system32\emptyregdb.dat

2009-09-28 10:01 . 2009-09-28 10:01 -------- d-----w- c:\program files\Windows Media Connect 2

2009-09-23 14:10 . 2009-03-17 14:52 207280 ----a-w- c:\windows\system32\drivers\PCTCore.sys

2009-09-16 01:20 . 2009-03-17 14:52 7383 ----a-w- c:\windows\system32\drivers\pctcore.cat

2009-09-15 04:20 . 2009-03-17 14:52 7383 ----a-w- c:\windows\system32\drivers\pctplsg.cat

2009-09-15 00:12 . 2009-03-17 14:52 7412 ----a-w- c:\windows\system32\drivers\PCTAppEvent.cat

2009-09-15 00:01 . 2009-03-17 14:52 7387 ----a-w- c:\windows\system32\drivers\pctgntdi.cat

2009-09-11 14:03 . 2004-08-03 23:56 136192 ----a-w- c:\windows\system32\msv1_0.dll

2009-09-04 20:45 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\msasn1.dll

2009-08-26 08:16 . 2004-08-03 23:56 247326 ----a-w- c:\windows\system32\strmdll.dll

2009-08-25 09:47 . 2004-08-03 23:56 352256 ----a-w- c:\windows\system32\winhttp.dll

2009-08-19 15:07 . 2009-08-19 15:07 1415000 ----a-w- c:\windows\system32\msxml6.dll

2009-08-14 11:22 . 2005-11-08 22:13 1859328 ----a-w- c:\windows\system32\win32k.sys

2009-08-14 07:59 . 2009-03-17 13:22 33662272 ----a-r- c:\documents and settings\All Users\Application Data\Installations\{58FB2F9A-5F2D-40E8-82DF-4987E60AD8BD}\Setup.exe

2009-08-06 17:24 . 2009-09-28 10:02 327896 ----a-w- c:\windows\system32\wucltui.dll

2009-08-06 17:24 . 2009-09-28 10:02 209632 ----a-w- c:\windows\system32\wuweb.dll

2009-08-06 17:24 . 2009-09-28 10:02 35552 ----a-w- c:\windows\system32\wups.dll

2009-08-06 17:24 . 2005-10-12 08:00 44768 ----a-w- c:\windows\system32\wups2.dll

2009-08-06 17:24 . 2009-09-28 10:02 53472 ------w- c:\windows\system32\wuauclt.exe

2009-08-06 17:24 . 2005-10-12 08:00 96480 ----a-w- c:\windows\system32\cdm.dll

2009-08-06 17:23 . 2009-09-28 10:02 575704 ----a-w- c:\windows\system32\wuapi.dll

2009-08-06 17:23 . 2009-09-28 10:02 1929952 ----a-w- c:\windows\system32\wuaueng.dll

2009-08-06 17:23 . 2005-10-12 08:00 215920 ----a-w- c:\windows\system32\muweb.dll

2009-08-05 09:11 . 2004-08-03 23:56 204800 ----a-w- c:\windows\system32\mswebdvd.dll

2009-08-04 17:52 . 2009-08-04 17:52 1193832 ----a-w- c:\windows\system32\FM20.DLL

2009-07-31 13:23 . 2009-09-28 16:46 411368 ----a-w- c:\windows\system32\deploytk.dll

2009-07-31 04:57 . 2005-10-12 16:14 1172480 ----a-w- c:\windows\system32\msxml3.dll

2009-07-20 22:05 . 2009-07-20 22:05 1348432 ----a-w- c:\windows\system32\msxml4.dll

2009-07-17 18:55 . 2004-08-03 23:56 58880 ----a-w- c:\windows\system32\atl.dll

2009-07-17 16:27 . 2004-08-03 23:56 1435648 ----a-w- c:\windows\system32\query.dll

2009-07-13 08:08 . 2006-01-13 18:15 286720 ----a-w- c:\windows\system32\wmpdxm.dll

2009-06-25 18:36 . 2004-08-03 23:56 95744 ----a-w- c:\windows\system32\mqsec.dll

2009-06-25 18:36 . 2004-08-03 23:56 661504 ----a-w- c:\windows\system32\mqqm.dll

.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))

.

---- Directory of c:\program files\Common Files\Microsoft Services\Console ----

((((((((((((((((((((((((((((( SnapShot@2009-03-19_14.09.56 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-03-19 15:33 . 2009-03-19 15:33 16384 c:\windows\Temp\Perflib_Perfdata_5c4.dat

+ 2009-03-19 14:38 . 2009-03-19 15:16 12552 c:\windows\system32\drivers\avgrkx86.sys

+ 2009-03-19 14:38 . 2009-03-19 15:16 27784 c:\windows\system32\drivers\avgmfx86.sys

+ 2009-03-19 14:37 . 2009-03-19 15:16 29208 c:\windows\system32\drivers\avgfwdx.sys

+ 2009-03-19 14:38 . 2009-03-19 15:16 11952 c:\windows\system32\avgrsstx.dll

+ 2009-03-19 14:37 . 2009-03-19 15:16 50968 c:\windows\system32\avgfwdx.dll

+ 2009-03-19 14:38 . 2009-03-19 15:16 108552 c:\windows\system32\drivers\avgtdix.sys

+ 2009-03-19 14:38 . 2009-03-19 15:16 335240 c:\windows\system32\drivers\avgldx86.sys

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{A3CF7606-E683-4375-A372-96B75DA0AEF7}]

2010-02-05 17:23 185856 ----a-w- c:\program files\Get Styles\enlbrdr.dll

[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]

2009-09-02 11:56 1175944 ----a-w- c:\program files\Ask.com\GenericAskToolbar.dll

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser]

"{D4027C7F-154A-4066-A1AD-4243D8127440}"= "c:\program files\Ask.com\GenericAskToolbar.dll" [2009-09-02 1175944]

[HKEY_CLASSES_ROOT\clsid\{d4027c7f-154a-4066-a1ad-4243d8127440}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd.1]

[HKEY_CLASSES_ROOT\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56}]

[HKEY_CLASSES_ROOT\GenericAskToolbar.ToolbarWnd]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseNormal]

@="{C5994560-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994560-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseModified]

@="{C5994561-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994561-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseConflict]

@="{C5994562-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994562-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseLocked]

@="{C5994563-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994563-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseReadOnly]

@="{C5994564-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994564-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseDeleted]

@="{C5994565-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994565-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseAdded]

@="{C5994566-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994566-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\8TortoiseIgnored]

@="{C5994567-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994567-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\9TortoiseUnversioned]

@="{C5994568-53D9-4125-87C9-F193FC689CB2}"

[HKEY_CLASSES_ROOT\CLSID\{C5994568-53D9-4125-87C9-F193FC689CB2}]

2009-08-13 15:55 85768 ----a-w- c:\program files\Common Files\TortoiseOverlays\TortoiseOverlays.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"LightScribe Control Panel"="c:\program files\Common Files\LightScribe\LightScribeControlPanel.exe" [2009-05-18 2363392]

"Skype"="c:\program files\Skype\Phone\Skype.exe" [2009-10-09 25623336]

"SUPERAntiSpyware"="c:\program files\SUPERAntiSpyware\SUPERAntiSpyware.exe" [2010-02-18 2012912]

"PC Suite Tray"="c:\program files\Nokia\Nokia PC Suite 7\PCSuite.exe" [2008-12-03 1205760]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"SiSPower"="SiSPower.dll" [2007-04-10 53248]

"RTHDCPL"="RTHDCPL.EXE" [2007-02-26 16125440]

"SkyTel"="SkyTel.EXE" [2006-05-16 2879488]

"%FP%PPPoE fts.exe"="c:\program files\Thomson SpeedTouch\PPPoE\fts.exe" [2004-01-07 77312]

"FixCamera"="c:\windows\FixCamera.exe" [2007-01-30 20480]

"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2009-07-31 149280]

"HP Software Update"="c:\program files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]

"tsnp2std"="c:\windows\tsnp2std.exe" [2006-11-29 258048]

"snp2std"="c:\windows\vsnp2std.exe" [2006-09-15 675840]

"ISTray"="c:\program files\Spyware Doctor\pctsTray.exe" [2010-01-18 1286608]

"SpyHunter Security Suite"="c:\program files\Enigma Software Group\SpyHunter\SpyHunter3.exe" [2009-12-09 866200]

"PWRISOVM.EXE"="c:\program files\PowerISO\PWRISOVM.EXE" [2009-11-09 180224]

"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2009-03-19 2046816]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2004-08-03 15360]

c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\

SDK Tray Menu.lnk - c:\program files\JDK\jdk\bin\javaw.exe [2009-11-19 139264]

c:\documents and settings\All Users\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2007-1-2 210520]

InterVideo WinCinema Manager.lnk - c:\program files\InterVideo\Common\Bin\WinCinemaMgr.exe [2009-9-28 303104]

Utility Tray.lnk - c:\windows\system32\sistray.exe [2009-9-28 262144]

[hkey_local_machine\software\microsoft\windows\currentversion\explorer\ShellExecuteHooks]

"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"= "c:\program files\SUPERAntiSpyware\SASSEH.DLL" [2008-05-13 77824]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\!SASWinLogon]

2009-09-03 12:21 548352 ----a-w- c:\program files\SUPERAntiSpyware\SASWINLO.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\avgrsstarter]

2009-03-19 15:16 11952 ----a-w- c:\windows\system32\avgrsstx.dll

[HKLM\~\startupfolder\C:^Documents and Settings^Vartotojas^Start Menu^Programs^Startup^Ftwscape 508 Client.lnk]

path=c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\Ftwscape 508 Client.lnk

backup=c:\windows\pss\Ftwscape 508 Client.lnkStartup

[HKLM\~\startupfolder\C:^Documents and Settings^Vartotojas^Start Menu^Programs^Startup^Ftwscpe 508 Client.lnk]

path=c:\documents and settings\Vartotojas\Start Menu\Programs\Startup\Ftwscpe 508 Client.lnk

backup=c:\windows\pss\Ftwscpe 508 Client.lnkStartup

[HKEY_LOCAL_MACHINE\software\microsoft\security center]

"AntiVirusOverride"=dword:00000001

"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]

"EnableFirewall"= 0 (0x0)

"DisableNotifications"= 1 (0x1)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]

"%windir%\\system32\\sessmgr.exe"=

"d:\\cs 2\\hl.exe"=

"d:\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe"=

"d:\\Empire Earth\\Empire Earth.exe"=

"d:\\cs copy\\XTCS Counter-Strike 1.6 Final Release\\cstrike.exe"=

"c:\\Program Files\\Mozilla Firefox\\firefox.exe"=

"d:\\kiets zaidas\\Geimas\\age2_x1.exe"=

"d:\\Copyof ECSROeris\\SilkErrSender.exe"=

"c:\\Documents and Settings\\Vartotojas\\temp\\TeamViewer\\Version4\\TeamViewer.exe"=

"c:\\WINDOWS\\system32\\java.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\java.exe"=

"d:\\Counter-Strike Source\\hl2.exe"=

"c:\\Sun\\SDK\\jdk\\bin\\java.exe"=

"c:\\Program Files\\JDK\\jdk\\bin\\java.exe"=

"d:\\Strongholdcrusaders\\Stronghold Crusader.exe"=

"c:\\Documents and Settings\\Vartotojas\\My Documents\\Downloads\\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\\Stronghold Crusader\\Stronghold_Crusader_Extreme.exe"=

"c:\\Documents and Settings\\Vartotojas\\Application Data\\GameRanger\\GameRanger\\GameRanger.exe"=

"c:\\Documents and Settings\\Vartotojas\\My Documents\\Downloads\\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\\Stronghold Crusader\\Stronghold Crusader.exe"=

"d:\\Program Files\\Microsoft Games\\Age of Mythology\\aomx.exe"=

"c:\\WINDOWS\\system32\\dplaysvr.exe"=

"d:\\sad nub\\WOGAI\\Heroes3.exe"=

"c:\\WINDOWS\\system32\\dpnsvr.exe"=

"d:\\Konami\\Yu-Gi-Oh! Power of Chaos JOEY THE PASSION\\joey_pc.exe"=

"d:\\Left 4 Dead\\left4dead.exe"=

"c:\\Program Files\\Java\\jre6\\bin\\javaw.exe"=

"d:\\wormsarm\\WA.exe"=

"d:\\kveikas\\Quake3\\quake3.exe"=

"c:\\Program Files\\TeamViewer\\Version5\\TeamViewer.exe"=

"c:\\Documents and Settings\\Vartotojas\\temp\\TeamViewer\\Version5\\TeamViewer.exe"=

"d:\\Earth`s Special Forces\\esfas\\ESF\\hl.exe"=

"c:\\Program Files\\Skype\\Plugin Manager\\skypePM.exe"=

"c:\\Program Files\\Skype\\Phone\\Skype.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgam.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgdiag.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgdiagex.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

"c:\\Program Files\\AVG\\AVG8\\avgnsx.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]

"4749:TCP"= 4749:TCP:faxdypp

R0 AvgRkx86;avgrkx86.sys;c:\windows\system32\drivers\avgrkx86.sys [3/19/2009 4:38 PM 12552]

R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [3/19/2009 4:38 PM 335240]

R1 AvgTdiX;AVG8 Network Redirector;c:\windows\system32\drivers\avgtdix.sys [3/19/2009 4:38 PM 108552]

R1 SASDIFSV;SASDIFSV;c:\program files\SUPERAntiSpyware\sasdifsv.sys [2/17/2010 10:25 AM 12872]

R1 SASKUTIL;SASKUTIL;c:\program files\SUPERAntiSpyware\SASKUTIL.SYS [2/17/2010 10:15 AM 66632]

R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [3/19/2009 5:16 PM 297752]

R2 avgfws8;AVG8 Firewall;c:\progra~1\AVG\AVG8\avgfws8.exe [3/19/2009 5:16 PM 1370488]

R2 Process Blocker;Process Blocker;c:\program files\Process Blocker\Process Blocker.exe [5/20/2009 6:14 PM 96472]

R3 Avgfwdx;Avgfwdx;c:\windows\system32\drivers\avgfwdx.sys [3/19/2009 4:37 PM 29208]

S0 muxv;muxv;c:\windows\system32\drivers\utfyu.sys --> c:\windows\system32\drivers\utfyu.sys [?]

S0 sptd;sptd;c:\windows\system32\drivers\sptd.sys [9/29/2009 7:35 PM 722416]

S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [11/3/2009 11:57 AM 133104]

S3 Avgfwfd;AVG network filter service;c:\windows\system32\drivers\avgfwdx.sys [3/19/2009 4:37 PM 29208]

S3 SASENUM;SASENUM;c:\program files\SUPERAntiSpyware\SASENUM.SYS [2/17/2010 10:15 AM 12872]

S3 XDva279;XDva279;\??\c:\windows\system32\XDva279.sys --> c:\windows\system32\XDva279.sys [?]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]

HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs

uvkftj

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}]

2009-05-18 14:54 451872 ----a-w- c:\program files\Common Files\LightScribe\LSRunOnce.exe

.

Contents of the 'Scheduled Tasks' folder

2009-03-19 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 09:57]

2020-02-03 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job

- c:\program files\Google\Update\GoogleUpdate.exe [2009-11-03 09:57]

2009-03-19 c:\windows\Tasks\Scheduled Update for Ask Toolbar.job

- c:\program files\Ask.com\UpdateTask.exe [2009-09-02 11:56]

2009-03-19 c:\windows\Tasks\WGASetup.job

- c:\windows\system32\KB905474\wgasetup.exe [2009-12-13 20:18]

.

.

------- Supplementary Scan -------

.

uStart Page = about:blank

IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

IE: {{14CD42DD-ABCD-3586-DCAB-40E3693E3737} - c:\program files\Get Styles\ct.htm

FF - ProfilePath - c:\documents and settings\Vartotojas\Application Data\Mozilla\Firefox\Profiles\nnfj11aw.default\

FF - prefs.js: browser.startup.homepage - google.lt

FF - plugin: c:\documents and settings\Vartotojas\Application Data\Facebook\npfbplugin_1_0_3.dll

FF - plugin: c:\program files\Google\Google Earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\Google\Update\1.2.183.17\npGoogleOneClick8.dll

FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\

---- FIREFOX POLICIES ----

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_colors", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("svg.smil.enabled", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.debug", false);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5);

c:\program files\Mozilla Firefox\greprefs\all.js - pref("html5.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600);

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com");

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20);

c:\program files\Mozilla Firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20);

.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net

Rootkit scan 2009-03-19 17:40

Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully

hidden files: 0

**************************************************************************

.

--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(1132)

c:\program files\SUPERAntiSpyware\SASWINLO.dll

.

Completion time: 2009-03-19 17:42:19

ComboFix-quarantined-files.txt 2009-03-19 15:42

ComboFix2.txt 2009-03-19 14:11

Pre-Run: 5,246,230,528 bytes free

Post-Run: 5,209,534,464 bytes free

Current=4 Default=4 Failed=3 LastKnownGood=5 Sets=1,2,3,4,5

- - End Of File - - 570438C6E192973EA9DAD37C062C8446

here combo fix..

now scanning with malwarebytes.

i cant find c:\program files\Common Files\Microsoft Services\Console\ntupd.exe

Link to post
Share on other sites

Files Infected:

C:\Program Files\Adobe\Adobe Photoshop CS3\Msvcrt.dll (Malware.Packer.Gen) -> No action taken.

C:\Program Files\Adobe\Adobe Photoshop CS3\Shfolder.dll (Trojan.Agent) -> No action taken.

C:\Program Files\FarmVilleBot\parcer.exe (Trojan.Agent) -> No action taken.

D:\cabalas\dp1.fne (Worm.AutoRun) -> No action taken.

D:\shmmmm\unl-shltrn.exe (Malware.Packer) -> No action taken.

Link to post
Share on other sites

Why didn't you select to have MBAM delete those items ? ?

We're going to need some reports.

Download OTL by OldTimer & SAVE to your Desktop: from one of the following links:

Link1 or

Link2

  • Close all open windows on the Task Bar. Double-Click OTL (for Vista, right click the icon and Run as Administrator) to start the program.
  • In the lower right corner of the Top Panel, checkmark "LOP Check" and checkmark "Purity Check".
  • Now click Run Scan at Top left and let the program run uninterrupted. It will take about 4 minutes.
  • It will produce two logs for you, one will pop up called OTL.txt, the other will be saved on your desktop and called Extras.txt.
  • Exit Notepad. Remember where you've saved these 2 files as we will need both of them shortly!
  • Exit OTL by clicking the X at top right.

Download Security Check by screen317 and save it to your Desktop: here or here

  • Run Security Check
  • Follow the onscreen instructions inside of the command window.
  • A Notepad document should open automatically called checkup.txt; close Notepad. We will need this log, too, so remember where you've saved it!

eusa_hand.gifIf one of your security applications (e.g., third-party firewall) requests permission to allow DIG.EXE access the Internet, allow it to do so.

Then copy/paste the following into your post (in order):

  • the contents of OTL.txt
  • Extras.txt
  • checkup.txt

Be sure to do a Preview prior to pressing Submit because all reports may not fit into 1 single reply. You may have to do more than 1 reply.

Do not use the attachment feature to place any of your reports. Always put them in-line inside the body of reply.

Link to post
Share on other sites

Results of screen317's Security Check version 0.99.1

Windows XP Service Pack 2

Out of date service pack!!

``````````````````````````````

Antivirus/Firewall Check:

Windows Firewall Disabled!

AVG 8.5

Antivirus up to date!

``````````````````````````````

Anti-malware/Other Utilities Check:

Spyware Doctor 7.0

SpyHunter

SUPERAntiSpyware Free Edition

CCleaner

Java Platform, Enterprise Edition 5 SDK

Java 6 Update 16

Java SE Development Kit 6 Update 11

Java SE Development Kit 6 Update 16

JavaFX 1.2 SDK

Java DB 10.4.2.1

Out of date Java installed!

Adobe Flash Player 10

``````````````````````````````

Process Check:

objlist.exe by Laurent

AVG avgwdsvc.exe

AVG avgrsx.exe

AVG avgnsx.exe

AVG avgemc.exe

``````````````````````````````

DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

OTL Extras logfile created on: 3/19/2009 10:31:16 PM - Run 1

OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Vartotojas\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free

4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 39.06 Gb Total Space | 4.83 Gb Free Space | 12.37% Space Free | Partition Type: NTFS

Drive D: | 333.54 Gb Total Space | 136.12 Gb Free Space | 40.81% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: VART-1C72F97A8F

Current User Name: Vartotojas

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Extra Registry (SafeList) ==========

========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]

.html [@ = FirefoxHTML] -- C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

htmlfile [edit] -- "C:\Program Files\Microsoft Office\OFFICE11\msohtmed.exe" %1 (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)

Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirstRunDisabled" = 1

"AntiVirusOverride" = 1

"FirewallOverride" = 1

"AntiVirusDisableNotify" = 0

"FirewallDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"EnableFirewall" = 0

"DoNotAllowExceptions" = 0

"DisableNotifications" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007

"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008

"10280:UDP" = 10280:UDP:LocalSubNet:Enabled:Windows Media Connect

"10281:UDP" = 10281:UDP:LocalSubNet:Enabled:Windows Media Connect

"10282:UDP" = 10282:UDP:LocalSubNet:Enabled:Windows Media Connect

"10283:UDP" = 10283:UDP:LocalSubNet:Enabled:Windows Media Connect

"10284:UDP" = 10284:UDP:LocalSubNet:Enabled:Windows Media Connect

"10243:TCP" = 10243:TCP:LocalSubNet:Enabled:Windows Media Connect

"4749:TCP" = 4749:TCP:*:Enabled:faxdypp

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

"D:\cs 2\hl.exe" = D:\cs 2\hl.exe:*:Enabled:Half-Life Launcher -- (Valve)

"D:\XTCS Counter-Strike 1.6 Final Release\cstrike.exe" = D:\XTCS Counter-Strike 1.6 Final Release\cstrike.exe:*:Enabled:XTCS Counter-Strike 1.6 Final Release -- (XTreme-CStrike)

"D:\Empire Earth\Empire Earth.exe" = D:\Empire Earth\Empire Earth.exe:*:Enabled:Empire Earth -- ()

"D:\cs copy\XTCS Counter-Strike 1.6 Final Release\cstrike.exe" = D:\cs copy\XTCS Counter-Strike 1.6 Final Release\cstrike.exe:*:Enabled:XTCS Counter-Strike 1.6 Final Release -- (XTreme-CStrike)

"C:\Program Files\Mozilla Firefox\firefox.exe" = C:\Program Files\Mozilla Firefox\firefox.exe:*:Enabled:Firefox -- (Mozilla Corporation)

"D:\kiets zaidas\Geimas\age2_x1.exe" = D:\kiets zaidas\Geimas\age2_x1.exe:*:Enabled:Age of Empires II Expansion -- (Microsoft Corporation)

"D:\Copyof ECSROeris\SilkErrSender.exe" = D:\Copyof ECSROeris\SilkErrSender.exe:*:Enabled:FTPSender MFC ?? ???? -- ()

"C:\Documents and Settings\Vartotojas\temp\TeamViewer\Version4\TeamViewer.exe" = C:\Documents and Settings\Vartotojas\temp\TeamViewer\Version4\TeamViewer.exe:*:Enabled:TeamViewer Remote Control Application -- (TeamViewer GmbH)

"C:\WINDOWS\system32\java.exe" = C:\WINDOWS\system32\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Program Files\Java\jre6\bin\java.exe" = C:\Program Files\Java\jre6\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"D:\Counter-Strike Source\hl2.exe" = D:\Counter-Strike Source\hl2.exe:*:Enabled:hl2 -- ()

"C:\Sun\SDK\jdk\bin\java.exe" = C:\Sun\SDK\jdk\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"C:\Program Files\JDK\jdk\bin\java.exe" = C:\Program Files\JDK\jdk\bin\java.exe:*:Enabled:Java Platform SE binary -- (Sun Microsystems, Inc.)

"D:\Strongholdcrusaders\Stronghold Crusader.exe" = D:\Strongholdcrusaders\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader -- ()

"C:\Documents and Settings\Vartotojas\My Documents\Downloads\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\Stronghold Crusader\Stronghold_Crusader_Extreme.exe" = C:\Documents and Settings\Vartotojas\My Documents\Downloads\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\Stronghold Crusader\Stronghold_Crusader_Extreme.exe:*:Enabled:Stronghold Crusader -- ( )

"C:\Documents and Settings\Vartotojas\Application Data\GameRanger\GameRanger\GameRanger.exe" = C:\Documents and Settings\Vartotojas\Application Data\GameRanger\GameRanger\GameRanger.exe:*:Enabled:GameRanger -- (GameRanger Technologies)

"C:\Documents and Settings\Vartotojas\My Documents\Downloads\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\Stronghold Crusader\Stronghold Crusader.exe" = C:\Documents and Settings\Vartotojas\My Documents\Downloads\Stronghold.Crusader.Extreme.Full-Rip.Skullptura\Stronghold Crusader\Stronghold Crusader.exe:*:Enabled:Stronghold Crusader -- ( )

"D:\Program Files\Microsoft Games\Age of Mythology\aomx.exe" = D:\Program Files\Microsoft Games\Age of Mythology\aomx.exe:*:Enabled:Age of Mythology - The Titans Expansion -- (Ensemble Studios)

"C:\WINDOWS\system32\dplaysvr.exe" = C:\WINDOWS\system32\dplaysvr.exe:*:Enabled:Microsoft DirectPlay Helper -- (Microsoft Corporation)

"D:\sad nub\WOGAI\Heroes3.exe" = D:\sad nub\WOGAI\Heroes3.exe:*:Enabled:Heroes of Might and Magic

Link to post
Share on other sites

OTL logfile created on: 3/19/2009 10:31:16 PM - Run 1

OTL by OldTimer - Version 3.1.37.3 Folder = C:\Documents and Settings\Vartotojas\Desktop

Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation

Internet Explorer (Version = 6.0.2900.2180)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 64.00% Memory free

4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free

Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files

Drive C: | 39.06 Gb Total Space | 4.83 Gb Free Space | 12.37% Space Free | Partition Type: NTFS

Drive D: | 333.54 Gb Total Space | 136.12 Gb Free Space | 40.81% Space Free | Partition Type: NTFS

E: Drive not present or media not loaded

F: Drive not present or media not loaded

G: Drive not present or media not loaded

H: Drive not present or media not loaded

I: Drive not present or media not loaded

Computer Name: VART-1C72F97A8F

Current User Name: Vartotojas

Logged in as Administrator.

Current Boot Mode: Normal

Scan Mode: Current user

Company Name Whitelist: Off

Skip Microsoft Files: Off

File Age = 30 Days

Output = Standard

========== Processes (SafeList) ==========

PRC - [2009/08/20 11:44:38 | 000,615,688 | ---- | M] (http://tortoisesvn.net) -- C:\Program Files\TortoiseSVN\bin\TSVNCache.exe

PRC - [2009/05/20 18:14:26 | 000,096,472 | ---- | M] (Softros Systems, Inc.) -- C:\Program Files\Process Blocker\Process Blocker.exe

PRC - [2009/03/19 22:30:00 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vartotojas\Desktop\OTL.com

PRC - [2009/03/19 17:16:28 | 000,486,680 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgrsx.exe

PRC - [2009/03/19 17:16:27 | 000,693,016 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgcsrvx.exe

PRC - [2009/03/19 17:16:23 | 000,595,736 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgnsx.exe

PRC - [2009/03/19 17:16:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgwdsvc.exe

PRC - [2009/03/19 17:16:19 | 001,370,488 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgfws8.exe

PRC - [2009/03/19 17:16:19 | 000,832,792 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files\AVG\AVG8\avgam.exe

PRC - [2008/12/05 15:11:54 | 000,935,208 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe

PRC - [2005/10/15 10:07:16 | 001,032,192 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe

========== Modules (SafeList) ==========

MOD - [2009/03/19 22:30:00 | 000,555,520 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Vartotojas\Desktop\OTL.com

MOD - [2005/10/16 14:55:06 | 001,053,696 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2649_x-ww_aac16c8b\comctl32.dll

========== Win32 Services (SafeList) ==========

SRV - [2009/05/20 18:14:26 | 000,096,472 | ---- | M] (Softros Systems, Inc.) [Auto | Running] -- C:\Program Files\Process Blocker\Process Blocker.exe -- (Process Blocker)

SRV - [2009/03/19 17:16:21 | 000,297,752 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgwdsvc.exe -- (avg8wd)

SRV - [2009/03/19 17:16:19 | 001,370,488 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files\AVG\AVG8\avgfws8.exe -- (avgfws8)

SRV - [2008/12/05 15:11:54 | 000,935,208 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe -- (Nero BackItUp Scheduler 4.0)

SRV - [2008/11/11 09:38:06 | 000,620,544 | ---- | M] (Nokia.) [On_Demand | Stopped] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)

========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Running] -- -- (catchme)

DRV - [2010/02/17 10:25:50 | 000,012,872 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv.sys -- (SASDIFSV)

DRV - [2010/02/17 10:15:58 | 000,066,632 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\SASKUTIL.SYS -- (SASKUTIL)

DRV - [2010/02/17 10:15:58 | 000,012,872 | R--- | M] ( SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | On_Demand | Stopped] -- C:\Program Files\SUPERAntiSpyware\SASENUM.SYS -- (SASENUM)

DRV - [2009/11/09 05:21:18 | 000,059,388 | ---- | M] (PowerISO Computing, Inc.) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\scdemu.sys -- (SCDEmu)

DRV - [2009/09/29 19:37:43 | 000,722,416 | ---- | M] (Duplex Secure Ltd.) [Kernel | Boot | Stopped] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)

DRV - [2009/03/19 17:16:27 | 000,335,240 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgldx86.sys -- (AvgLdx86)

DRV - [2009/03/19 17:16:27 | 000,027,784 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\WINDOWS\System32\Drivers\avgmfx86.sys -- (AvgMfx86)

DRV - [2009/03/19 17:16:24 | 000,108,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\WINDOWS\System32\Drivers\avgtdix.sys -- (AvgTdiX)

DRV - [2009/03/19 17:16:20 | 000,029,208 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwfd)

DRV - [2009/03/19 17:16:20 | 000,029,208 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\avgfwdx.sys -- (Avgfwdx)

DRV - [2009/03/19 17:16:19 | 000,012,552 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\WINDOWS\System32\Drivers\avgrkx86.sys -- (AvgRkx86)

DRV - [2008/08/26 09:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\pccsmcfd.sys -- (pccsmcfd)

DRV - [2007/04/10 21:30:16 | 000,018,304 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\srvkp.sys -- (SiSkp)

DRV - [2007/04/10 21:09:08 | 000,321,024 | R--- | M] (Silicon Integrated Systems Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sisgrp.sys -- (SiS315)

DRV - [2007/03/01 11:27:00 | 004,484,608 | R--- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\RtkHDAud.sys -- (IntcAzAudAddService) Service for Realtek HD Audio (WDM)

DRV - [2007/01/26 16:48:28 | 012,028,032 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\snp2sxp.sys -- (SNP2STD) USB2.0 PC Camera (SNP2STD)

DRV - [2006/12/20 06:00:00 | 000,041,600 | R--- | M] (Silicon Integrated Systems Corp.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\SiSGbeXP.sys -- (SiSGbeXP)

DRV - [2005/11/15 23:42:48 | 000,045,056 | ---- | M] (InterVideo) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\iviVD.sys -- (iviVD)

DRV - [2005/10/13 22:35:58 | 000,138,752 | ---- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\hdaudbus.sys -- (HDAudBus)

DRV - [2005/09/20 01:27:20 | 000,010,368 | ---- | M] (InterVideo, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\iviaspi.sys -- (Iviaspi)

DRV - [2004/08/13 04:56:20 | 000,005,810 | R--- | M] () [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\ASACPI.sys -- (MTsensor)

DRV - [2004/01/18 12:16:00 | 000,108,503 | ---- | M] (Friendly Technologies) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\PPPoEWin.SYS -- (PPPoEWin)

DRV - [2002/02/24 06:35:00 | 000,014,604 | ---- | M] (Padus, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\pfc.sys -- (pfc)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,AlwaysUseDefaultPrinter = yes

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank

IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "google.lt"

FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:8.5.0.429

FF - HKLM\software\mozilla\Firefox\extensions\\bkmrksync@nokia.com: C:\Program Files\Nokia\Nokia PC Suite 7\bkmrksync\ [2009/03/17 15:23:47 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{3f963a5b-e555-4543-90e2-c3908898db71}: C:\Program Files\AVG\AVG8\Firefox [2009/03/19 17:33:24 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Firefox\extensions\\{1d5287d1-8a92-0001-1f31-1cec198018d8}: C:\Program Files\AVG\AVG8\ToolbarFF [2009/03/19 16:37:49 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2009/03/10 09:47:09 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Mozilla Firefox 3.6\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2009/03/10 09:47:07 | 000,000,000 | ---D | M]

FF - HKLM\software\mozilla\Thunderbird\Extensions\\eplgTb@eset.com: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird

[2009/03/10 09:47:17 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Mozilla\Extensions

[2009/03/19 16:39:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Mozilla\Firefox\Profiles\nnfj11aw.default\extensions

[2009/03/10 09:51:01 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\Vartotojas\Application Data\Mozilla\Firefox\Profiles\nnfj11aw.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}

[2009/03/19 16:39:11 | 000,000,000 | ---D | M] -- C:\Program Files\Mozilla Firefox\extensions

O1 HOSTS File: ([2009/03/17 22:31:34 | 000,393,856 | R--- | M]) - C:\WINDOWS\system32\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 activate.adobe.com localhost

O1 - Hosts: 127.0.0.1 www.007guard.com

O1 - Hosts: 127.0.0.1 007guard.com

O1 - Hosts: 127.0.0.1 008i.com

O1 - Hosts: 127.0.0.1 www.008k.com

O1 - Hosts: 127.0.0.1 008k.com

O1 - Hosts: 127.0.0.1 www.00hq.com

O1 - Hosts: 127.0.0.1 00hq.com

O1 - Hosts: 127.0.0.1 010402.com

O1 - Hosts: 127.0.0.1 www.032439.com

O1 - Hosts: 127.0.0.1 032439.com

O1 - Hosts: 127.0.0.1 www.0scan.com

O1 - Hosts: 127.0.0.1 0scan.com

O1 - Hosts: 127.0.0.1 www.1000gratisproben.com

O1 - Hosts: 127.0.0.1 1000gratisproben.com

O1 - Hosts: 127.0.0.1 www.1001namen.com

O1 - Hosts: 127.0.0.1 1001namen.com

O1 - Hosts: 127.0.0.1 www.100888290cs.com

O1 - Hosts: 127.0.0.1 100888290cs.com

O1 - Hosts: 127.0.0.1 www.100sexlinks.com

O1 - Hosts: 127.0.0.1 100sexlinks.com

O1 - Hosts: 127.0.0.1 10sek.com

O1 - Hosts: 127.0.0.1 www.10sek.com

O1 - Hosts: 127.0.0.1 1-2005-search.com

O1 - Hosts: 127.0.0.1 www.1-2005-search.com

O1 - Hosts: 13116 more lines...

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)

O2 - BHO: (GdfrDUEn Class) - {A3CF7606-E683-4375-A372-96B75DA0AEF7} - C:\Program Files\Get Styles\enlbrdr.dll (TODO: <Company name>)

O2 - BHO: (CPrintEnhancer Object) - {AE84A6AA-A333-4B92-B276-C11E2212E4FE} - C:\Program Files\HP\Smart Web Printing\SmartWebPrinting.dll (Hewlett-Packard Co.)

O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)

O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\Program Files\AVG\AVG8\avgtoolbar.dll ([[[COMPANYNAME]]]----------------------------)

O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)

O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)

O4 - HKLM..\Run: [%FP%PPPoE fts.exe] C:\Program Files\Thomson SpeedTouch\PPPoE\fts.exe (Friendly Technologies)

O4 - HKLM..\Run: [AVG8_TRAY] C:\Program Files\AVG\AVG8\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [FixCamera] C:\WINDOWS\FixCamera.exe ()

O4 - HKLM..\Run: [iSTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools)

O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malwares\mbam.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [PWRISOVM.EXE] C:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.)

O4 - HKLM..\Run: [siSPower] C:\WINDOWS\System32\SiSPower.dll (Silicon Integrated Systems Corporation)

O4 - HKLM..\Run: [skyTel] C:\WINDOWS\SkyTel.exe (Realtek Semiconductor Corp.)

O4 - HKLM..\Run: [snp2std] C:\WINDOWS\vsnp2std.exe (Sonix)

O4 - HKLM..\Run: [spyHunter Security Suite] C:\Program Files\Enigma Software Group\SpyHunter\SpyHunter3.exe (Enigma Software Group USA, LLC.)

O4 - HKLM..\Run: [tsnp2std] C:\WINDOWS\tsnp2std.exe (SONIX)

O4 - HKCU..\Run: [PC Suite Tray] C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe (Nokia)

O4 - HKCU..\Run: [sUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe (InterVideo Inc.)

O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Utility Tray.lnk = C:\WINDOWS\system32\sistray.exe (Silicon Integrated Systems Corporation)

O4 - Startup: C:\Documents and Settings\Vartotojas\Start Menu\Programs\Startup\SDK Tray Menu.lnk = C:\Program Files\JDK\jdk\bin\javaw.exe (Sun Microsystems, Inc.)

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863

O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O9 - Extra Button: GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm ()

O9 - Extra 'Tools' menuitem : GetStyles - {14CD42DD-ABCD-3586-DCAB-40E3693E3737} - C:\Program Files\Get Styles\ct.htm ()

O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} http://cdn.scan.onecare.live.com/resource/...lscbase8942.cab (Windows Live Safety Center Base Module)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Reg Error: Key error.)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-...indows-i586.cab (Java Plug-in 1.6.0_16)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 212.59.1.1 212.59.2.2

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll (AVG Technologies CZ, s.r.o.)

O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)

O20 - Winlogon\Notify\!SASWinLogon: DllName - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll (SUPERAntiSpyware.com)

O20 - Winlogon\Notify\avgrsstarter: DllName - avgrsstx.dll - C:\WINDOWS\System32\avgrsstx.dll (AVG Technologies CZ, s.r.o.)

O24 - Desktop WallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O24 - Desktop BackupWallPaper: C:\WINDOWS\Web\Wallpaper\Bliss.bmp

O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - C:\Program Files\SUPERAntiSpyware\SASSEH.DLL (SuperAdBlocker.com)

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2009/03/12 12:21:17 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]

O34 - HKLM BootExecute: (autocheck autochk *) - File not found

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

Link to post
Share on other sites

========== Files/Folders - Created Within 30 Days ==========

[2020/01/29 15:13:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Decal Converter

[2020/01/28 19:59:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Facebook

[2020/01/27 16:48:38 | 000,000,000 | ---D | C] -- C:\Phenomedia AG

[2020/01/27 16:42:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Atomic Pkz Client v1.21

[2020/01/27 12:20:32 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\BoxRune 562 Client

[2020/01/26 12:11:28 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Vartotojas\Desktop\DailyScape Client V2.0

[2020/01/26 12:06:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Zmule songs

[2020/01/25 18:04:52 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Client

[2020/01/24 18:48:56 | 000,000,000 | ---D | C] -- C:\Program Files\Zeallsoft

[2020/01/24 18:32:14 | 000,000,000 | ---D | C] -- C:\Program Files\FogelSoft

[2020/01/21 15:31:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Copy vogs

[2020/01/20 20:01:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\clientas

[2020/01/20 11:22:52 | 000,000,000 | ---D | C] -- C:\Program Files\Infogrames

[2020/01/20 09:09:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Pop

[2020/01/19 18:55:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\DS Client

[2012/02/17 14:34:50 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Skype

[2012/02/15 15:16:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Max Payne Savegames

[2012/02/15 12:19:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\3DO Shared

[2012/02/15 12:19:34 | 000,000,000 | ---D | C] -- C:\Program Files\3DO

[2012/02/14 19:14:10 | 000,000,000 | ---D | C] -- C:\.takerevenge_v8

[2012/02/14 19:08:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\eva

[2012/02/14 12:00:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\0644_-_Pokemon_Ranger_(U)

[2012/02/12 19:47:13 | 000,000,000 | ---D | C] -- C:\Program Files\GetFLV

[2012/02/12 17:48:29 | 000,000,000 | ---D | C] -- C:\landofescape_file_store_32

[2010/02/12 16:14:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\no$gba-w

[2010/02/10 20:10:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\ft

[2010/02/09 19:47:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\mociute

[2010/02/08 12:09:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\SERVAS SYNERGY

[2010/02/06 21:15:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\New Folder (2)

[2010/02/06 21:13:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\best

[2010/02/06 14:10:58 | 000,000,000 | ---D | C] -- C:\Program Files\Get Styles

[2010/02/06 14:10:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\AppData

[2010/02/04 19:21:11 | 000,000,000 | ---D | C] -- C:\Program Files\TikGames

[2010/02/04 14:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\DC++

[2010/02/04 14:39:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\DC++

[2010/02/02 17:38:05 | 000,000,000 | ---D | C] -- C:\Program Files\RS2Botv2

[2010/02/02 15:13:35 | 002,262,648 | ---- | C] (Adobe Systems, Inc.) -- C:\WINDOWS\System32\Flash9b.ocx

[2010/02/02 15:13:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\elefundesktops

[2010/02/02 14:59:37 | 000,000,000 | ---D | C] -- C:\Program Files\Tetris 5000

[2010/01/31 10:52:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Visi zmules vailai

[2010/01/30 19:43:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Animals (Pack#1)

[2010/01/30 19:08:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\CFGS

[2010/01/30 19:08:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\dainos kakzokios

[2010/01/30 15:20:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\evos

[2010/01/30 10:54:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Dailyscape.lt Clientas V1

[2010/01/26 20:32:36 | 003,786,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_37.dll

[2010/01/26 20:32:20 | 000,000,000 | ---D | C] -- C:\Games

[2010/01/26 16:59:19 | 000,000,000 | ---D | C] -- C:\Program Files\CrisisX

[2010/01/26 16:41:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\pss

[2010/01/26 14:29:37 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\50_Funny_Computer_Pranks_All_In_One

[2010/01/26 14:26:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\.tucan

[2010/01/26 14:26:43 | 000,000,000 | ---D | C] -- C:\Tucan

[2010/01/26 14:24:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\URSoft

[2010/01/26 14:18:57 | 000,491,520 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTAudioFile.dll

[2010/01/26 14:18:57 | 000,158,208 | ---- | C] (NCT Company) -- C:\WINDOWS\System32\NCTTextToAudio.dll

[2010/01/26 14:18:56 | 000,000,000 | ---D | C] -- C:\Program Files\AliveMedia

[2010/01/25 16:26:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Sese dainos

[2010/01/24 15:31:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\facebook

[2010/01/24 15:24:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\fotkes

[2010/01/23 18:36:41 | 000,000,000 | ---D | C] -- C:\.trinitypk_file_store_32

[2010/01/23 18:35:19 | 000,000,000 | ---D | C] -- C:\Program Files\TrinityPk Client 2.8

[2010/01/23 14:01:39 | 000,000,000 | ---D | C] -- C:\.sabsabi_store_32

[2010/01/23 13:54:46 | 000,000,000 | ---D | C] -- C:\.SabsabiOnline_file_store_32

[2010/01/22 20:00:45 | 000,000,000 | ---D | C] -- C:\Program Files\BestPractice

[2010/01/22 19:45:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\WiMood

[2010/01/22 19:36:18 | 001,892,184 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\D3DX9_42.dll

[2010/01/22 19:36:15 | 002,414,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_31.dll

[2010/01/22 19:36:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\Logs

[2010/01/22 19:35:20 | 000,009,200 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdralw2k.sys

[2010/01/22 19:35:20 | 000,009,072 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\drivers\cdr4_xp.sys

[2010/01/22 19:35:19 | 001,858,032 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxsfs.dll

[2010/01/22 19:35:19 | 000,670,192 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\px.dll

[2010/01/22 19:35:19 | 000,551,408 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxdrv.dll

[2010/01/22 19:35:19 | 000,436,720 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxwave.dll

[2010/01/22 19:35:19 | 000,219,632 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxmas.dll

[2010/01/22 19:35:19 | 000,129,520 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxafs.dll

[2010/01/22 19:35:19 | 000,096,752 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\vxblock.dll

[2010/01/22 19:35:19 | 000,072,176 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxhpinst.exe

[2010/01/22 19:35:19 | 000,066,544 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxcpya64.exe

[2010/01/22 19:35:19 | 000,066,032 | ---- | C] (Sonic Solutions) -- C:\WINDOWS\System32\pxinsa64.exe

[2010/01/22 19:35:18 | 000,000,000 | ---D | C] -- C:\Program Files\Winamp

[2010/01/22 19:29:31 | 000,000,000 | ---D | C] -- C:\Program Files\WiMood

[2010/01/22 15:01:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\UNOUndercover

[2010/01/21 18:16:06 | 000,098,304 | ---- | C] (Sony DADC Austria AG.) -- C:\WINDOWS\System32\CmdLineExt.dll

[2010/01/19 18:01:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Harry Potter and the Prisoner of Azkaban

[2010/01/18 19:01:53 | 000,000,000 | ---D | C] -- C:\rscache

[2010/01/17 17:54:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\mikeeclient

[2010/01/16 19:06:00 | 000,000,000 | ---D | C] -- C:\tob_cache_32

[2010/01/16 13:16:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\config

[2010/01/15 18:41:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Magic Ball 1,2,3

[2010/01/14 19:18:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Adobe

[2010/01/14 19:18:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Adobe

[2010/01/14 19:17:59 | 000,000,000 | ---D | C] -- C:\Program Files\Adobe

[2010/01/13 17:09:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Topas

[2010/01/12 18:50:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\ArcticLine

[2010/01/12 18:50:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Thinstall

[2010/01/12 18:45:34 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Totem Shared

[2010/01/11 16:47:02 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Anglonas

[2010/01/11 15:53:08 | 000,000,000 | ---D | C] -- C:\WINDOWS\cache554

[2010/01/10 21:15:36 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\notes

[2010/01/10 18:37:29 | 000,000,000 | ---D | C] -- C:\.jagex_cache_32

[2010/01/10 12:53:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\FOTO

[2010/01/10 12:53:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\assas

[2010/01/10 10:49:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\New Folder

[2010/01/09 22:04:28 | 000,000,000 | ---D | C] -- C:\cache554

[2010/01/09 21:08:35 | 000,000,000 | ---D | C] -- C:\Program Files\Yamicsoft

[2010/01/07 19:29:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Zmule ;o

[2010/01/05 12:22:35 | 000,000,000 | ---D | C] -- C:\Program Files\SystemRequirementsLab

[2010/01/05 12:22:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\SystemRequirementsLab

[2010/01/05 10:14:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\sadddddddddddddddddddddddddddd

[2010/01/03 16:48:19 | 000,000,000 | ---D | C] -- C:\WINDOWS\Governor of Poker

[2010/01/03 16:48:19 | 000,000,000 | ---D | C] -- C:\Program Files\Governor of Poker

[2009/12/31 23:00:20 | 000,000,000 | ---D | C] -- C:\tobex_bluurr_32

[2009/12/31 21:14:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\fltk.org

[2009/12/29 10:32:42 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Kita

[2009/12/28 16:47:58 | 000,000,000 | ---D | C] -- C:\Program Files\Quake III Arena

[2009/12/28 16:44:16 | 000,306,688 | ---- | C] (InstallShield Software Corporation) -- C:\WINDOWS\IsUninst.exe

[2009/12/25 22:09:47 | 000,349,472 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\WindowsXP-KB822603-x86.exe

[2009/12/25 22:09:46 | 000,675,840 | ---- | C] (Sonix) -- C:\WINDOWS\vsnp2std.exe

[2009/12/25 22:09:46 | 000,258,048 | ---- | C] (SONIX) -- C:\WINDOWS\tsnp2std.exe

[2009/12/25 22:09:43 | 000,249,856 | ---- | C] (Sonix) -- C:\WINDOWS\System32\vsnp2std.dll

[2009/12/25 22:09:43 | 000,151,552 | ---- | C] ( ) -- C:\WINDOWS\System32\rsnp2std.dll

[2009/12/25 22:09:42 | 000,077,824 | ---- | C] ( ) -- C:\WINDOWS\System32\csnp2std.dll

[2009/12/25 22:09:42 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\snp2std

[2009/12/22 18:52:01 | 000,000,000 | ---D | C] -- C:\.paradise_file_store_32

[2009/12/22 12:19:25 | 000,000,000 | ---D | C] -- C:\DF

[2009/12/21 14:30:52 | 000,000,000 | ---D | C] -- C:\massacred_store_32

[2009/12/17 19:18:52 | 000,024,576 | ---- | C] (Stirling) -- C:\Program Files\_ISREG32.DLL

[2009/12/17 19:18:52 | 000,000,000 | ---D | C] -- C:\Program Files\GhostMouse 2.0

[2009/12/17 16:34:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\hs_cachefiles

[2009/12/17 11:58:39 | 000,364,320 | ---- | C] (Microsoft Corporation) -- C:\WindowsXP-KB825033-x86-ENU.exe

[2009/12/17 11:58:39 | 000,147,232 | ---- | C] (Microsoft Corporation) -- C:\WindowsXP-KB825033-x86-ENU-Symbols.exe

[2009/12/16 14:11:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Cheatscape client v1 by brad

[2009/12/16 12:56:53 | 000,000,000 | -H-D | C] -- C:\WINDOWS\PIF

[2009/12/15 15:37:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\docs

[2009/12/13 20:18:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Printer Info Cache

[2009/12/13 20:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\My Scans

[2009/12/13 20:18:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Image Zone Express

[2009/12/13 20:17:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WEBREG

[2009/12/13 20:16:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\HP

[2009/12/13 20:15:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HP

[2009/12/13 20:14:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HPSSUPPLY

[2009/12/13 20:14:47 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\HP

[2009/12/13 20:14:33 | 000,000,000 | ---D | C] -- C:\Program Files\Hewlett-Packard

[2009/12/13 20:14:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Hewlett-Packard

[2009/12/13 20:13:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Hewlett-Packard

[2009/12/13 20:13:25 | 000,258,048 | R--- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hpzids01.dll

[2009/12/13 20:13:24 | 000,117,760 | ---- | C] (Hewlett-Packard Company) -- C:\WINDOWS\System32\hpzll4v2.dll

[2009/12/13 20:13:17 | 000,675,840 | R--- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hpowiax3.dll

[2009/12/13 20:13:17 | 000,569,344 | R--- | C] (Hewlett-Packard Co.) -- C:\WINDOWS\System32\hpotscl3.dll

[2009/12/13 20:13:17 | 000,364,544 | R--- | C] (Hewlett-Packard) -- C:\WINDOWS\System32\hppldcoi.dll

[2009/12/13 20:13:17 | 000,309,760 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\difxapi.dll

[2009/12/13 20:13:17 | 000,294,912 | R--- | C] (Hewlett-Packard Co.) -- C:\WINDOWS\System32\hpovst10.dll

[2009/12/13 20:13:16 | 000,015,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbscan.sys

[2009/12/13 20:13:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\DRVSTORE

[2009/12/13 20:12:46 | 000,000,000 | ---D | C] -- C:\Program Files\HP

[2009/12/13 20:01:26 | 000,025,856 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbprint.sys

[2009/12/13 19:58:52 | 000,031,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\usbccgp.sys

[2009/12/13 07:53:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\KB905474

[2009/12/13 07:47:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ServicePackFiles

[2009/12/13 07:46:42 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0

[2009/12/13 07:46:06 | 000,000,000 | -H-D | C] -- C:\WINDOWS\$hf_mig$

[2009/12/12 17:19:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot_bak

[2009/12/12 16:06:39 | 000,000,000 | ---D | C] -- C:\.titana_cache_32

[2009/12/12 15:50:49 | 000,272,128 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\bthport.sys

[2009/12/12 14:19:47 | 000,000,000 | ---D | C] -- C:\Es_E6

[2009/12/12 08:10:33 | 000,456,832 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mrxsmb.sys

[2009/12/12 08:07:30 | 002,142,720 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlmp.exe

[2009/12/12 08:07:29 | 002,185,984 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntoskrnl.exe

[2009/12/12 08:07:29 | 002,063,104 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrnlpa.exe

[2009/12/12 08:07:29 | 002,020,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ntkrpamp.exe

[2009/12/12 07:51:04 | 000,274,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll

[2009/12/12 07:51:04 | 000,016,736 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mucltui.dll.mui

[2009/12/12 07:50:56 | 000,021,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wucltui.dll.mui

[2009/12/12 07:50:56 | 000,017,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaueng.dll.mui

[2009/12/12 07:50:56 | 000,015,072 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuaucpl.cpl.mui

[2009/12/12 07:50:56 | 000,015,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\wuapi.dll.mui

[2009/12/12 07:50:56 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\SoftwareDistribution

[2009/12/11 18:58:26 | 000,000,000 | ---D | C] -- C:\Es_E5

[2009/12/10 15:55:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\RsBot

[2009/12/09 19:47:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Malwarebytes

[2009/12/09 19:47:17 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware

[2009/12/09 19:47:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes

[2009/12/09 18:26:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\LDW

[2009/12/09 18:25:54 | 000,000,000 | ---D | C] -- C:\cache525

[2009/12/09 07:55:00 | 000,265,728 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\http.sys

[2009/12/08 20:32:06 | 000,000,000 | ---D | C] -- C:\Es_E4

[2009/12/08 16:08:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\.rsca

[2009/12/08 13:33:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\GTA San Andreas User Files

[2009/12/08 11:05:50 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\XPSViewer

[2009/12/08 11:05:47 | 000,000,000 | ---D | C] -- C:\Program Files\MSBuild

[2009/12/08 11:05:46 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en-US

[2009/12/07 22:03:05 | 000,000,000 | ---D | C] -- C:\Program Files\Reference Assemblies

[2009/12/07 19:27:10 | 000,000,000 | ---D | C] -- C:\Program Files\Audacity

[2009/12/07 13:50:50 | 000,000,000 | ---D | C] -- C:\.aerix3_file_store_32

[2009/12/05 18:04:40 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\SpOrder.dll

[2009/12/05 14:14:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\cfg

[2009/12/04 18:54:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\exorth.com

[2009/12/04 17:19:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\GameRanger

[2009/12/04 17:13:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Stronghold Crusader

[2009/12/04 14:16:21 | 000,000,000 | ---D | C] -- C:\zee_store

[2009/12/03 12:54:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Scripts

[2009/12/02 18:35:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Camtasia Studio

[2009/12/02 18:32:18 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\QuickTime

[2009/12/02 18:32:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TechSmith

[2009/12/02 18:32:13 | 000,000,000 | ---D | C] -- C:\Program Files\QuickTime

[2009/12/02 18:32:06 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TechSmith Shared

[2009/12/02 18:32:04 | 000,000,000 | ---D | C] -- C:\Program Files\TechSmith

[2009/12/02 18:32:03 | 000,000,000 | ---D | C] -- C:\Config.Msi

[2009/12/01 12:19:50 | 000,000,000 | ---D | C] -- C:\Program Files\Ftwscape 508 Client

[2009/11/30 13:19:39 | 000,000,000 | ---D | C] -- C:\FarmVilleTools

[2009/11/30 13:17:57 | 000,000,000 | ---D | C] -- C:\Program Files\Farm Helper

[2009/11/27 13:07:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\mageris

[2009/11/26 19:56:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\RsBot

[2009/11/23 13:46:52 | 000,000,000 | ---D | C] -- C:\Program Files\FarmVilleBot

[2009/11/23 12:21:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\DailyScape (beta)

[2009/11/21 16:53:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\HipSoft

[2009/11/21 15:51:19 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Trymedia

[2009/11/21 15:51:03 | 000,737,280 | ---- | C] (Indigo Rose Corporation) -- C:\WINDOWS\iun6002.exe

[2009/11/21 15:51:03 | 000,000,000 | ---D | C] -- C:\Program Files\PopCap Games

[2009/11/19 21:06:38 | 000,000,000 | ---D | C] -- C:\Program Files\JDK

[2009/11/19 20:57:45 | 000,000,000 | ---D | C] -- C:\Sun

[2009/11/19 15:55:09 | 000,597,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe

[2009/11/19 15:55:09 | 000,575,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpsshhdr.dll

[2009/11/19 15:55:09 | 000,117,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\prntvpt.dll

[2009/11/19 15:55:09 | 000,089,088 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll

[2009/11/19 15:55:08 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\xpssvcs.dll

[2009/11/19 15:55:08 | 001,676,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\xpssvcs.dll

[2009/11/19 15:54:37 | 000,000,000 | R-SD | C] -- C:\WINDOWS\assembly

[2009/11/19 15:54:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\Microsoft.NET

[2009/11/19 15:53:45 | 000,017,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spmsg.dll

[2009/11/19 15:53:42 | 000,026,488 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\spupdsvc.exe

[2009/11/19 15:53:36 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0

[2009/11/18 20:06:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\da foto

[2009/11/18 20:05:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\logs

[2009/11/18 20:05:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\moreinfo

[2009/11/18 20:05:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\clans

[2009/11/16 12:11:35 | 000,000,000 | ---D | C] -- C:\WINDOWS\.silabclient_store_32

[2009/11/12 17:44:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Any Video Converter

[2009/11/12 17:43:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Any Video Converter

[2009/11/12 17:43:46 | 000,000,000 | ---D | C] -- C:\Program Files\Any Video Converter

[2009/11/10 20:52:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Kures kelt

[2009/11/09 05:21:18 | 000,059,388 | ---- | C] (PowerISO Computing, Inc.) -- C:\WINDOWS\System32\drivers\scdemu.sys

[2009/11/07 17:31:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\GTA Vice City User Files

[2009/11/07 14:22:13 | 000,000,000 | ---D | C] -- C:\Program Files\2speced 10.6 client

[2009/11/06 19:20:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\SwiftKit

[2009/11/06 19:20:20 | 000,000,000 | ---D | C] -- C:\Program Files\SwiftKit

[2009/11/06 15:20:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Electronic Arts

[2009/11/06 12:59:49 | 000,000,000 | ---D | C] -- C:\.dailyscape_file_store_32

[2009/11/06 10:26:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Copy of client

[2009/11/05 18:01:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\4Media Software Studio

[2009/11/05 18:01:27 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\4Media Software Studio

[2009/11/05 17:46:10 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\VISOS FOTKES!!!!!!!

[2009/11/05 13:10:53 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Adobe

[2009/11/03 12:04:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Google

[2009/11/03 12:02:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\NetworkService\Local Settings\Application Data\Google

[2009/11/03 11:57:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Temp

[2009/11/03 11:57:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google

[2009/11/03 11:57:03 | 000,000,000 | ---D | C] -- C:\Program Files\Google

[2009/11/03 11:57:03 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Google

[2009/11/03 11:56:46 | 000,570,208 | ---- | C] (Google Inc.) -- C:\Documents and Settings\Vartotojas\My Documents\googleupdatesetup.exe

[2009/11/02 19:26:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Klientas

[2009/11/01 14:01:54 | 000,000,000 | ---D | C] -- C:\Program Files\RogueX

[2009/10/31 18:02:35 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Copy of Famous

[2009/10/30 17:24:43 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump

[2009/10/26 18:16:13 | 000,000,000 | ---D | C] -- C:\Program Files\TeamViewer

[2009/10/25 12:59:32 | 000,149,280 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe

[2009/10/25 12:59:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe

[2009/10/25 12:59:32 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe

[2009/10/25 09:44:33 | 000,073,728 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javacpl.cpl

[2009/10/25 09:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\Java

[2009/10/25 09:41:15 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\appmgmt

[2009/10/24 17:00:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\LightScribe

[2009/10/17 14:44:11 | 000,000,000 | ---D | C] -- C:\Program Files\JavaFX

[2009/10/17 14:43:51 | 000,000,000 | ---D | C] -- C:\Program Files\Sun

[2009/10/14 18:38:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\TSVNCache

[2009/10/14 18:36:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\TortoiseSVN

[2009/10/14 18:36:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Subversion

[2009/10/14 18:35:19 | 000,000,000 | ---D | C] -- C:\Program Files\TortoiseSVN

[2009/10/14 18:35:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\TortoiseOverlays

[2009/10/13 04:59:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\TikGames

[2009/10/13 04:59:14 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TikGames

[2009/10/13 04:42:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Dungeon Siege

[2009/10/13 04:40:41 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Games

[2009/10/11 22:42:25 | 000,000,000 | ---D | C] -- C:\$AVG8.VAULT$

[2009/10/11 22:18:25 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\avg8

[2009/10/11 22:18:25 | 000,000,000 | ---D | C] -- C:\Program Files\AVG

[2009/10/10 22:31:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\.jagex_cache_32

[2009/10/10 06:38:46 | 000,679,936 | ---- | C] (Generated by JEDI) -- C:\WINDOWS\System32\D3DX81ab.dll

[2009/10/10 06:38:46 | 000,000,000 | ---D | C] -- C:\Program Files\Cheat Engine

[2009/10/10 04:39:39 | 000,147,456 | ---- | C] (VBGold Software) -- C:\WINDOWS\System32\AResizeLite.ocx

[2009/10/09 05:05:49 | 000,000,000 | ---D | C] -- C:\Program Files\Mu-Hobby S4

[2009/10/08 06:19:23 | 000,000,000 | ---D | C] -- C:\Program Files\Alpha Ball

[2009/10/08 06:19:04 | 000,000,000 | ---D | C] -- C:\Program Files\ReflexiveArcade

[2009/10/08 06:11:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\TeamViewer

[2009/10/08 06:10:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\temp

[2009/10/08 04:30:32 | 000,000,000 | ---D | C] -- C:\Es_E3

[2009/10/07 04:16:48 | 000,000,000 | ---D | C] -- C:\WINDOWS\.mpr_file_store_32

[2009/10/05 04:03:33 | 000,000,000 | ---D | C] -- C:\Program Files\HyCam2

[2009/10/04 02:09:54 | 000,005,504 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mstee.sys

[2009/10/04 02:09:52 | 000,010,880 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ndisip.sys

[2009/10/04 02:09:51 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ipsink.ax

[2009/10/04 02:09:51 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ipsink.ax

[2009/10/04 02:09:50 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\streamip.sys

[2009/10/04 02:09:49 | 000,011,136 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\slip.sys

[2009/10/04 02:09:47 | 000,019,328 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wstcodec.sys

[2009/10/04 02:09:45 | 000,085,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\nabtsfec.sys

[2009/10/04 02:09:43 | 000,017,024 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ccdecode.sys

[2009/10/04 02:08:08 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kswdmcap.ax

[2009/10/04 02:08:08 | 000,090,624 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kswdmcap.ax

[2009/10/04 02:08:08 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kstvtune.ax

[2009/10/04 02:08:08 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kstvtune.ax

[2009/10/04 02:08:08 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vfwwdm32.dll

[2009/10/04 02:08:08 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vfwwdm32.dll

[2009/10/04 02:08:08 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksxbar.ax

[2009/10/04 02:08:08 | 000,043,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksxbar.ax

[2009/10/04 02:08:08 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\vidcap.ax

[2009/10/04 02:08:08 | 000,028,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\vidcap.ax

[2009/10/04 01:51:22 | 000,094,208 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\amcap.exe

[2009/10/03 06:23:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Opera

[2009/10/03 06:23:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Opera

[2009/10/03 06:23:44 | 000,000,000 | ---D | C] -- C:\Program Files\Opera

[2009/10/03 04:41:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Help

[2009/10/02 23:52:27 | 000,000,000 | ---D | C] -- C:\GMouse20

[2009/10/02 03:03:01 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Harry Potter II

[2009/10/02 01:15:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\.emps_cache

[2009/09/30 19:47:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Identities

[2009/09/29 19:47:04 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\WING32.DLL

[2009/09/29 19:47:01 | 000,000,000 | ---D | C] -- C:\Program Files\Heroes

[2009/09/29 19:46:57 | 000,299,520 | ---- | C] (InstallShield Corporation, Inc.) -- C:\WINDOWS\uninst.exe

[2009/09/29 19:46:55 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\WINDOWS

[2009/09/29 19:45:50 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

[2009/09/29 19:45:49 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Toolbar

[2009/09/29 19:45:46 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Lite

[2009/09/29 19:45:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\DAEMON Tools Lite

[2009/09/29 19:42:53 | 000,000,000 | ---D | C] -- C:\Program Files\DAEMON Tools Pro

[2009/09/29 19:42:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro

[2009/09/29 19:35:33 | 000,722,416 | ---- | C] (Duplex Secure Ltd.) -- C:\WINDOWS\System32\drivers\sptd.sys

[2009/09/29 19:35:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\DAEMON Tools Pro

[2009/09/29 18:50:22 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Harry Potter

[2009/09/29 14:06:21 | 000,074,240 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\usbui.dll

[2009/09/29 14:06:17 | 000,044,672 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\uagp35.sys

[2009/09/29 14:05:25 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents\My Music

[2009/09/29 14:05:22 | 000,000,000 | -HSD | C] -- C:\WINDOWS\Installer

[2009/09/29 14:05:21 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\ODBC

[2009/09/29 14:05:20 | 000,774,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spttseng.dll

[2009/09/29 14:05:20 | 000,077,824 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcommon.dll

[2009/09/29 14:05:20 | 000,061,440 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\spcplui.dll

[2009/09/29 14:05:19 | 000,741,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapi.dll

[2009/09/29 14:05:19 | 000,155,648 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapi.cpl

[2009/09/29 14:05:19 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sapisvr.exe

[2009/09/29 14:05:19 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\SpeechEngines

[2009/09/29 14:05:18 | 000,000,000 | R--D | C] -- C:\Program Files

[2009/09/29 14:05:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Microsoft Shared

[2009/09/29 14:05:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files

[2009/09/29 14:05:17 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt041f.dll

[2009/09/29 14:05:16 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0419.dll

[2009/09/29 14:05:16 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuq.dll

[2009/09/29 14:05:16 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtuf.dll

[2009/09/29 14:05:16 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuq.dll

[2009/09/29 14:05:16 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtuf.dll

[2009/09/29 14:05:16 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdazel.dll

[2009/09/29 14:05:16 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdazel.dll

[2009/09/29 14:05:15 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbduzb.dll

[2009/09/29 14:05:15 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdtat.dll

[2009/09/29 14:05:15 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdmon.dll

[2009/09/29 14:05:15 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkyr.dll

[2009/09/29 14:05:15 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdaze.dll

[2009/09/29 14:05:15 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbduzb.dll

[2009/09/29 14:05:15 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdtat.dll

[2009/09/29 14:05:15 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdmon.dll

[2009/09/29 14:05:15 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkyr.dll

[2009/09/29 14:05:15 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdaze.dll

[2009/09/29 14:05:14 | 000,022,016 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0408.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycc.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdur.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru1.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdru.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkaz.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdbu.dll

[2009/09/29 14:05:14 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdblr.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycc.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdur.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru1.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdru.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkaz.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdbu.dll

[2009/09/29 14:05:14 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdblr.dll

[2009/09/29 14:05:13 | 000,008,192 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhept.dll

[2009/09/29 14:05:13 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhept.dll

[2009/09/29 14:05:13 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela3.dll

[2009/09/29 14:05:13 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela3.dll

[2009/09/29 14:05:13 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhela2.dll

[2009/09/29 14:05:13 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdgkl.dll

[2009/09/29 14:05:13 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhela2.dll

[2009/09/29 14:05:13 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdgkl.dll

[2009/09/29 14:05:13 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe319.dll

[2009/09/29 14:05:13 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe220.dll

[2009/09/29 14:05:13 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhe.dll

[2009/09/29 14:05:13 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe319.dll

[2009/09/29 14:05:13 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe220.dll

[2009/09/29 14:05:13 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhe.dll

[2009/09/29 14:05:12 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv1.dll

[2009/09/29 14:05:12 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlv.dll

[2009/09/29 14:05:12 | 000,006,144 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdest.dll

[2009/09/29 14:05:12 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv1.dll

[2009/09/29 14:05:12 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlv.dll

[2009/09/29 14:05:12 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdest.dll

[2009/09/29 14:05:12 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt1.dll

[2009/09/29 14:05:12 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdlt.dll

[2009/09/29 14:05:12 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt1.dll

[2009/09/29 14:05:12 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdlt.dll

[2009/09/29 14:05:11 | 000,019,968 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt040e.dll

[2009/09/29 14:05:11 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0415.dll

[2009/09/29 14:05:11 | 000,019,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\agt0405.dll

[2009/09/29 14:05:10 | 000,007,168 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz.dll

[2009/09/29 14:05:10 | 000,007,168 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdycl.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl1.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdsl.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz2.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcz1.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdcr.dll

[2009/09/29 14:05:10 | 000,006,656 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\KBDAL.DLL

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdycl.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl1.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdsl.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz2.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcz1.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdcr.dll

[2009/09/29 14:05:10 | 000,006,656 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdal.dll

[2009/09/29 14:05:10 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdro.dll

[2009/09/29 14:05:10 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdpl1.dll

[2009/09/29 14:05:10 | 000,005,632 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdhu1.dll

[2009/09/29 14:05:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdro.dll

[2009/09/29 14:05:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdpl1.dll

[2009/09/29 14:05:10 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdhu1.dll

[2009/09/29 14:05:08 | 000,176,157 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dllcache\dgrpsetu.dll

[2009/09/29 14:05:08 | 000,176,157 | ---- | C] (Digi International, Inc.) -- C:\WINDOWS\System32\dgrpsetu.dll

[2009/09/29 14:05:08 | 000,103,424 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\EqnClass.Dll

[2009/09/29 14:05:08 | 000,103,424 | ---- | C] (Equinox Systems Inc.) -- C:\WINDOWS\System32\dllcache\eqnclass.dll

[2009/09/29 14:05:08 | 000,085,020 | ---- | C] (Digi International) -- C:\WINDOWS\System32\dllcache\dgsetup.dll

[2009/09/29 14:05:08 | 000,085,020 | ---- | C] (Digi International) -- C:\WINDOWS\System32\dgsetup.dll

[2009/09/29 14:05:08 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\spxcoins.dll

[2009/09/29 14:05:08 | 000,024,661 | ---- | C] (Perle Systems Ltd.) -- C:\WINDOWS\System32\dllcache\spxcoins.dll

[2009/09/29 14:05:08 | 000,013,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WFWNET.DRV

[2009/09/29 14:05:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\irclass.dll

[2009/09/29 14:05:08 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irclass.dll

[2009/09/29 14:05:07 | 000,126,912 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MSVIDEO.DLL

[2009/09/29 14:05:07 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLECLI.DLL

[2009/09/29 14:05:07 | 000,073,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIAVI.DRV

[2009/09/29 14:05:07 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCIWAVE.DRV

[2009/09/29 14:05:07 | 000,025,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MCISEQ.DRV

[2009/09/29 14:05:07 | 000,024,064 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\OLESVR.DLL

[2009/09/29 14:05:07 | 000,019,200 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TAPI.DLL

[2009/09/29 14:05:07 | 000,009,008 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VER.DLL

[2009/09/29 14:05:07 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SHELL.DLL

[2009/09/29 14:05:07 | 000,004,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\TIMER.DRV

[2009/09/29 14:05:07 | 000,003,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SYSTEM.DRV

[2009/09/29 14:05:07 | 000,002,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\VGA.DRV

[2009/09/29 14:05:07 | 000,002,032 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MOUSE.DRV

[2009/09/29 14:05:07 | 000,001,744 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\SOUND.DRV

[2009/09/29 14:05:07 | 000,001,152 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMTASK.TSK

[2009/09/29 14:05:06 | 000,109,456 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVIFILE.DLL

[2009/09/29 14:05:06 | 000,069,584 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\AVICAP.DLL

[2009/09/29 14:05:06 | 000,032,816 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\COMMDLG.DLL

[2009/09/29 14:05:06 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\TASKMAN.EXE

[2009/09/29 14:05:06 | 000,015,360 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\taskman.exe

[2009/09/29 14:05:06 | 000,011,264 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\irenum.sys

[2009/09/29 14:05:06 | 000,009,936 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\LZEXPAND.DLL

[2009/09/29 14:05:06 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\batt.dll

[2009/09/29 14:05:06 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\batt.dll

[2009/09/29 14:05:06 | 000,002,000 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\KEYBOARD.DRV

[2009/09/29 14:05:05 | 000,146,432 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\WINSPOOL.DRV

[2009/09/29 14:05:05 | 000,074,752 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\storprop.dll

[2009/09/29 14:05:05 | 000,068,768 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System\MMSYSTEM.DLL

[2009/09/29 14:05:00 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Start Menu

[2009/09/29 14:05:00 | 000,000,000 | R--D | C] -- C:\Documents and Settings\All Users\Documents

[2009/09/29 14:05:00 | 000,000,000 | -H-D | C] -- C:\Documents and Settings\All Users\Templates

[2009/09/29 14:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Favorites

[2009/09/29 14:05:00 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Desktop

[2009/09/29 14:04:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot2

[2009/09/29 14:04:27 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\CatRoot

[2009/09/29 14:04:22 | 000,000,000 | --SD | C] -- C:\Documents and Settings\All Users\Application Data\Microsoft

[2009/09/29 14:04:22 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\All Users\Application Data

[2009/09/29 14:04:06 | 000,000,000 | -HSD | C] -- C:\System Volume Information

[2009/09/29 14:04:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings

[2009/09/29 13:49:32 | 000,000,000 | R-SD | C] -- C:\WINDOWS\Fonts

[2009/09/29 13:49:32 | 000,000,000 | RHSD | C] -- C:\WINDOWS\System32\dllcache

[2009/09/29 13:49:32 | 000,000,000 | R--D | C] -- C:\WINDOWS\Web

[2009/09/29 13:49:32 | 000,000,000 | -H-D | C] -- C:\WINDOWS\inf

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\WinSxS

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wins

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\wbem

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\usmt

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\twain_32

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Temp

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\system32

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\system

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\spool

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\SoftwareDistribution

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ShellExt

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Setup

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\security

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Resources

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\repair

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ras

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Provisioning

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\PreInstall

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\PeerNet

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\pchealth

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\oobe

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\npp

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\mui

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\mui

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\msapps

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\msagent

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Media

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\java

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\inetsrv

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\IME

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ime

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\icsxml

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ias

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Help

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\export

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\etc

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\en

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\ehome

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Driver Cache

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\drivers\disdn

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\dhcp

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Debug

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Cursors

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Connection Wizard

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\config

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\Config

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\AppPatch

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\addins

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3com_dmi

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\3076

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\2052

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1054

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1042

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1041

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1037

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1033

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1031

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1028

[2009/09/29 13:49:32 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\1025

[2009/09/29 12:57:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\EA Games

[2009/09/29 12:57:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Documents\EA Games

[2009/09/29 12:56:33 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdjpn.dll

[2009/09/29 12:56:33 | 000,008,704 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdjpn.dll

[2009/09/29 12:56:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbdkor.dll

[2009/09/29 12:56:33 | 000,008,192 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbdkor.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd106.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd106.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101c.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101c.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd101b.dll

[2009/09/29 12:56:33 | 000,006,144 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd101b.dll

[2009/09/29 12:56:33 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\kbd103.dll

[2009/09/29 12:56:33 | 000,005,632 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kbd103.dll

[2009/09/29 11:40:08 | 000,000,000 | ---D | C] -- C:\Program Files\Astroburn Toolbar

[2009/09/29 11:40:06 | 000,000,000 | ---D | C] -- C:\Program Files\Astroburn Lite

[2009/09/29 11:39:56 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Astroburn Lite

[2009/09/29 11:39:31 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Astroburn Lite

[2009/09/29 11:22:38 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\LightScribe

[2009/09/29 11:07:47 | 000,000,000 | ---D | C] -- C:\Program Files\Philips

[2009/09/29 11:07:17 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\InstallShield

[2009/09/29 10:18:46 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Shrek 2

[2009/09/29 08:39:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Nero

[2009/09/28 21:55:10 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Sidebar

[2009/09/28 21:41:37 | 000,000,000 | ---D | C] -- C:\Program Files\Nero

[2009/09/28 21:41:06 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Nero

[2009/09/28 21:41:04 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nero

[2009/09/28 21:40:53 | 002,388,176 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\d3dx9_30.dll

[2009/09/28 21:34:43 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2009/09/28 20:39:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Help

[2009/09/28 19:44:49 | 000,000,000 | ---D | C] -- C:\Program Files\AT Screen Thief 3.8

[2009/09/28 19:33:01 | 000,000,000 | ---D | C] -- C:\WINDOWS\Sun

[2009/09/28 19:31:15 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\My Games

[2009/09/28 19:20:19 | 000,010,368 | ---- | C] (InterVideo, Inc.) -- C:\WINDOWS\System32\drivers\iviaspi.sys

[2009/09/28 19:20:14 | 000,010,368 | ---- | C] (InterVideo, Inc.) -- C:\WINDOWS\System32\iviaspi.sys

[2009/09/28 19:19:54 | 000,045,056 | ---- | C] (InterVideo) -- C:\WINDOWS\System32\drivers\iviVD.sys

[2009/09/28 19:11:21 | 000,000,000 | ---D | C] -- C:\Program Files\Ask.com

[2009/09/28 19:10:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\uTorrent

[2009/09/28 19:07:57 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Ahead

[2009/09/28 19:02:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\WinRAR

[2009/09/28 18:57:10 | 000,000,000 | ---D | C] -- C:\WINDOWS\.titana_cache_32

[2009/09/28 18:56:46 | 000,000,000 | ---D | C] -- C:\Program Files\WinRAR

[2009/09/28 18:46:55 | 000,411,368 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\deploytk.dll

[2009/09/28 18:43:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Sun

[2009/09/28 18:30:54 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\skypePM

[2009/09/28 18:30:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Skype

[2009/09/28 18:29:31 | 000,000,000 | R--D | C] -- C:\Program Files\Skype

[2009/09/28 18:29:29 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Skype

[2009/09/28 18:27:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Adobe

[2009/09/28 18:25:51 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\My Documents\Downloads

[2009/09/28 18:25:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Local Settings\Application Data\Mozilla

[2009/09/28 18:25:16 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Mozilla

[2009/09/28 18:25:11 | 000,000,000 | ---D | C] -- C:\Program Files\Mozilla Firefox

[2009/09/28 18:23:11 | 000,000,000 | --SD | C] -- C:\Documents and Settings\Vartotojas\UserData

[2009/09/28 18:23:08 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\Macromedia

[2009/09/28 18:21:48 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Application Data\vlc

[2009/09/28 18:18:27 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\FTL Shared

[2009/09/28 18:09:27 | 000,000,000 | ---D | C] -- C:\Program Files\Thomson SpeedTouch

[2009/09/28 18:09:12 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Vartotojas\Desktop\Best dainos

[2009/09/28 17:42:12 | 000,012,160 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mouhid.sys

[2009/09/28 17:42:08 | 000,009,600 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\hidusb.sys

[2009/09/28 16:08:03 | 000,000,000 | ---D | C] -- C:\Program Files\ESET

[2009/09/28 16:04:37 | 000,041,600 | R--- | C] (Silicon Integrated Systems Corp.) -- C:\WINDOWS\System32\drivers\SiSGbeXP.sys

[2009/09/28 16:04:33 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\Lang

[2009/09/28 16:03:27 | 000,006,400 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\splitter.sys

[2009/09/28 16:03:26 | 000,082,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\wdmaud.sys

[2009/09/28 16:03:25 | 000,052,864 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\dmusic.sys

[2009/09/28 16:03:24 | 000,054,272 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\swmidi.sys

[2009/09/28 16:03:23 | 000,171,776 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\kmixer.sys

[2009/09/28 16:03:23 | 000,142,464 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\aec.sys

[2009/09/28 16:03:22 | 000,002,944 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmkaud.sys

[2009/09/28 16:03:21 | 000,060,800 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\sysaudio.sys

[2009/09/28 16:03:20 | 000,007,552 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mskssrv.sys

[2009/09/28 16:03:19 | 000,004,992 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspqm.sys

[2009/09/28 16:03:18 | 000,005,376 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\mspclock.sys

[2009/09/28 16:03:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\RTCOM

[2009/09/28 16:03:13 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksproxy.ax

[2009/09/28 16:03:13 | 000,130,048 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksproxy.ax

[2009/09/28 16:03:13 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\ksuser.dll

[2009/09/28 16:03:13 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\ksuser.dll

[2009/09/28 16:03:12 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\portcls.sys

[2009/09/28 16:03:12 | 000,145,920 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\portcls.sys

[2009/09/28 16:03:12 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\drivers\drmk.sys

[2009/09/28 16:03:12 | 000,060,288 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\dllcache\drmk.sys

[2009/09/28 16:03:07 | 000,086,016 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SoundMan.exe

[2009/09/28 16:03:06 | 002,879,488 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\SkyTel.exe

[2009/09/28 16:03:05 | 001,191,936 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlUpd.exe

[2009/09/28 16:03:05 | 000,282,624 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\RTSndMgr.cpl

[2009/09/28 16:03:01 | 009,709,568 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RTLCPL.exe

[2009/09/28 16:02:59 | 004,484,608 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\drivers\RtkHDAud.sys

[2009/09/28 16:02:51 | 002,157,568 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\MicCal.exe

[2009/09/28 16:02:48 | 000,069,632 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\Alcmtr.exe

[2009/09/28 16:02:47 | 002,808,832 | R--- | C] (RealTek Semicoductor Corp.) -- C:\WINDOWS\alcwzrd.exe

[2009/09/28 16:02:47 | 000,299,008 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\System32\ALSndMgr.cpl

[2009/09/28 16:02:46 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek

[2009/09/28 16:02:43 | 000,315,392 | ---- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\HideWin.exe

[2009/09/28 16:02:42 | 000,520,192 | R--- | C] (Realtek Semiconductor Corp.) -- C:\WINDOWS\RtlExUpd.dll

[2009/09/28 15:58:52 | 000,000,000 | ---D | C] -- C:\WINDOWS\ASUSInstAll

[2009/09/28 15:58:47 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\ReinstallBackups

[2009/09/28 15:58:44 | 000,000,000 | ---D | C] -- C:\Program Files\sisagp

[2009/09/28 15:58:37 | 000,135,168 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSApCom.dll

[2009/09/28 15:58:37 | 000,110,592 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\TVMode.dll

[2009/09/28 15:58:37 | 000,065,536 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSHook.dll

[2009/09/28 15:58:37 | 000,000,000 | ---D | C] -- C:\WINDOWS\SIS

[2009/09/28 15:58:31 | 000,262,144 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\sistray.exe

[2009/09/28 15:58:31 | 000,053,248 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSPower.dll

[2009/09/28 15:58:30 | 000,337,320 | R--- | C] (Microsoft Corporation) -- C:\WINDOWS\difxapi.dll

[2009/09/28 15:58:29 | 000,012,288 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\InstFunc.dll

[2009/09/28 15:58:29 | 000,000,000 | -H-D | C] -- C:\Program Files\InstallShield Installation Information

[2009/09/28 15:58:26 | 000,258,048 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSParse.dll

[2009/09/28 15:58:26 | 000,172,032 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSInst.dll

[2009/09/28 15:58:26 | 000,049,152 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSBase.dll

[2009/09/28 15:58:26 | 000,018,304 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\srvkp.sys

[2009/09/28 15:58:26 | 000,009,728 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\SiSPIns2.dll

[2009/09/28 15:58:25 | 003,965,440 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\sisgl770.dll

[2009/09/28 15:58:24 | 003,517,952 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\sisgrv.dll

[2009/09/28 15:58:24 | 003,517,952 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrv.dll

[2009/09/28 15:58:24 | 000,321,024 | R--- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\drivers\sisgrp.sys

[2009/09/28 15:58:24 | 000,321,024 | ---- | C] (Silicon Integrated Systems Corporation) -- C:\WINDOWS\System32\dllcache\sisgrp.sys

[2009/09/28 15:58:23 | 000,000,000 | ---D | C] -- C:\Program Files\SiS VGA Utilities V3.80

[2009/09/28 15:58:18 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\InstallShield

[2009/09/28 15:34:39 | 000,028,040 | ---- | C] (Microsoft Corporation) -- C:\WINDOWS\System32\mdimon.dll

[2009/09/28 15:34:11 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft.NET

[2009/09/28 15:34:07 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft ActiveSync

[2009/09/28 15:33:53 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\DESIGNER

[2009/09/28 15:33:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\SHELLNEW

[2009/09/28 15:32:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office

[2009/09/28 15:29:55 | 000,000,000 | ---D | C] -- C:\Program Files\VideoLAN

Link to post
Share on other sites

========== LOP Check ==========

[2009/03/19 12:10:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Alwil Software

[2009/09/29 11:49:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Astroburn Lite

[2009/03/17 15:08:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BitDefender

[2009/09/29 19:45:50 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite

[2009/09/29 19:42:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Pro

[2009/03/18 10:39:01 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\ESET

[2009/11/21 16:53:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\HipSoft

[2009/03/17 15:22:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Installations

[2009/09/28 15:29:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\InterVideo

[2009/03/18 11:04:11 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\IObit

[2009/10/24 17:00:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\LightScribe

[2009/03/17 15:24:12 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\PC Suite

[2009/03/19 14:54:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Simply Super Software

[2009/11/06 19:20:21 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\SwiftKit

[2009/12/02 18:32:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TechSmith

[2009/03/19 16:27:06 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TEMP

[2009/10/13 04:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\TikGames

[2009/11/05 18:01:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\4Media Software Studio

[2009/11/12 17:44:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Any Video Converter

[2010/01/12 18:50:04 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\ArcticLine

[2009/09/29 11:39:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Astroburn Lite

[2009/03/19 16:38:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\AVGTOOLBAR

[2010/01/19 17:08:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\DAEMON Tools Lite

[2009/09/29 19:35:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\DAEMON Tools Pro

[2010/02/04 14:57:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\DC++

[2010/02/02 15:13:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\elefundesktops

[2020/01/28 19:59:41 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Facebook

[2009/03/14 21:21:49 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\fizzy

[2009/12/31 21:14:00 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\fltk.org

[2009/12/04 17:19:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\GameRanger

[2009/03/17 16:52:29 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\GetRightToGo

[2009/12/13 20:18:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Image Zone Express

[2009/09/28 15:29:25 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\InterVideo

[2009/03/17 15:30:18 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Nokia

[2009/10/03 06:23:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Opera

[2009/03/17 15:24:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\PC Suite

[2009/03/16 19:20:48 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\PowerChallenge

[2009/12/13 20:18:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Printer Info Cache

[2009/10/14 18:36:20 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Subversion

[2010/01/05 12:22:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\SystemRequirementsLab

[2009/03/17 21:57:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\TeamViewer

[2010/01/12 18:50:03 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\Thinstall

[2009/10/13 04:59:14 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\TikGames

[2010/01/22 15:01:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\UNOUndercover

[2010/01/26 14:24:27 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\URSoft

[2009/03/17 22:06:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Vartotojas\Application Data\uTorrent

[2009/03/19 22:01:00 | 000,000,244 | ---- | M] () -- C:\WINDOWS\Tasks\Scheduled Update for Ask Toolbar.job

[2009/03/19 17:42:19 | 000,000,260 | ---- | M] () -- C:\WINDOWS\Tasks\WGASetup.job

========== Purity Check ==========

========== Alternate Data Streams ==========

@Alternate Data Stream - 176 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:1CE11B51

@Alternate Data Stream - 159 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:DFC5A2B2

@Alternate Data Stream - 157 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:D3A8AA31

@Alternate Data Stream - 100 bytes -> C:\Documents and Settings\All Users\Application Data\TEMP:A73B0434

< End of report

Link to post
Share on other sites

Step 1

Turn ON the Windows XP Firewall:

Click Start, and click Control Panel.

Click Network and Internet Connections.

If you do not see Network and Internet Connections, click Switch to Category View.

Click Change Windows Firewall Settings.

Select On.

Click OK.

Step 2

Download to your Desktop FixPolicies.exe, by Bill Castner, MS-MVP, a self-extracting ZIP archive from

>>> here <<<

  • Double-click FixPolicies.exe.
  • Click the "Install" button on the bottom toolbar of the box that will open.
  • The program will create a new Folder called FixPolicies.
  • Double-click to Open the new Folder, and then double-click the file within: Fix_Policies.cmd.
  • A black box will briefly appear and then close.
  • This fix may prove temporary. Active malware may revert these changes at your next startup. You can safely run the utility again.

Step 3

  • Please double-click OTL.com otlDesktopIcon.png to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy all the lines in between the **** stars lines **** below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
    *****************************************************************
    :files
    c:\program files\Common Files\Microsoft Services\Console
    C:\Documents and Settings\vartotojas\START MENU\PROGRAMS\STARTUP\monnwb32.exe
    C:\Documents and Settings\Administrator\START MENU\PROGRAMS\STARTUP\monnwb32.exe
    C:\Documents and Settings\Vartotojas\Local Settings\Application Data\ave.exe
    C:\WINDOWS\system32\regedit.exe
    c:\windows\system32\wuaucldt.exe
    c:\documents and settings\vartotojas\wuaucldt.exe
    :Commands
    [purity]
    [emptytemp]
    [CREATERESTOREPOINT]
    *****************************************************************
  • Return to OTL. Right click in the "Custom Scans/Fixes" window (under the aqua-blue bar) and choose Paste.
  • Close any browser(s) windows that may be open.
  • Using your mouse, click on the red-lettered button Run Fix.
  • Once you see a message box "Fix complete! Click OK to open the fix log."
    Click the OK button
  • The log will open in Notepad (your default text editor).
  • Save the log. Post a copy of that log in your next reply.

Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process.

If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

Step 4

Please download DrWeb-CureIt & save it to your desktop. DO NOT perform a scan yet.

Reboot your computer in "SAFE MODE" using the F8 method. To do this, restart your computer and after hearing your computer beep once during startup (but before the Windows icon appears) press the F8 key repeatedly. A menu will appear with several options. Use the arrow keys to navigate and select the option to run Windows in "Safe Mode".

Scan with DrWeb-CureIt as follows:

  • Double-click on cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
  • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan tab" and UNcheck "Heuristic analysis"
  • Back at the main window, click "Select drives" (a red dot will show which drives have been chosen)
  • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
  • When done, a message will be displayed at the bottom advising if any viruses were found.
  • Click "Yes to all" if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable". (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
  • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)

Step 5

Using Internet Explorer browser only, go to ESET Online Scanner website:

Vista users should start IE by Start (Vista Orb) >> Internet Explorer >> Right-Click and select Run As Administrator.

  • Accept the Terms of Use and press Start button;
  • Approve the install of the required ActiveX Control, then follow on-screen instructions;
  • Enable (check) the Remove found threats option, and run the scan.
  • After the scan completes, the Details tab in the Results window will display what was found and removed.
    • A logfile is created and located at C:\Program Files\EsetOnlineScanner\log.txt.

    Look at contents of this file using Notepad or Wordpad.

    The Frequently Asked Questions for ESET Online Scanner can be viewed here

    http://www.eset.com/onlinescan/cac4.php?page=faq

    • From ESET Tech Support: If you have ESET NOD32 installed, you should disable it prior to running this scanner.
      Otherwise the scan will take twice as long to do:
      everytime the ESET online scanner opens a file on your computer to scan it, NOD32 on your machine will rescan the file as a result.
    • It is emphasized to temporarily disable any pc-resident {active} antivirus program prior to any on-line scan by any on-line scanner.
      (And the prompt re-enabling when finished.)
    • If you use Firefox, you have to install IETab, an add-on. This is to enable ActiveX support.

Step 6

Reply with copy of the OTL MovedFiles log

the DrWeb Cure-It log

the Eset scan log

and tell me, How is your system now ?

Please do NOT use the attach feature when posting logs.

Be sure to do a Preview prior to pressing Submit because all reports may not fit into 1 single reply. You may have to do more than 1 reply.

Link to post
Share on other sites

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.