OTL logfile created on: 11/17/2010 2:56:39 PM - Run 1
OTL by OldTimer - Version 3.2.17.3 Folder = C:\Documents and Settings\Administrator\Desktop\virus_et_al
Windows 2000 Professional Edition Service Pack 4 (Version = 5.0.2195) - Type = NTWorkstation
Internet Explorer (Version = 5.00.3700.1000)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
3.00 Gb Paging File | 3.00 Gb Available in Paging File | 93.00% Paging File free
Paging file location(s): C:\pagefile.sys 1524 3048 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINNT | %ProgramFiles% = C:\Program Files
Drive C: | 14.06 Gb Total Space | 10.89 Gb Free Space | 77.46% Space Free | Partition Type: NTFS
Drive D: | 854.99 Mb Total Space | 483.45 Mb Free Space | 56.54% Space Free | Partition Type: NTFS
Drive E: | 74.53 Gb Total Space | 73.12 Gb Free Space | 98.11% Space Free | Partition Type: NTFS
Drive F: | 1.86 Gb Total Space | 1.50 Gb Free Space | 80.77% Space Free | Partition Type: FAT32
Drive Z: | 30.92 Mb Total Space | 30.92 Mb Free Space | 100.00% Space Free | Partition Type: FAT
Computer Name: RTM-II | User Name: Administrator | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2010/11/17 09:51:18 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\virus_et_al\OTL.exe
PRC - [2008/05/15 23:19:31 | 000,079,224 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2008/05/15 23:19:24 | 000,144,760 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2008/05/15 23:19:00 | 000,247,160 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2008/05/15 23:16:59 | 000,349,560 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2008/05/15 23:06:57 | 000,017,272 | ---- | M] (ALWIL Software) -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2006/06/01 11:14:16 | 001,827,640 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe
PRC - [2006/06/01 11:08:28 | 000,126,976 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe
PRC - [2006/06/01 11:08:26 | 000,204,800 | ---- | M] (Acronis) -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe
PRC - [2006/06/01 11:06:42 | 001,106,562 | ---- | M] (Acronis) -- C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe
PRC - [2006/05/12 15:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) -- C:\Program Files\RealVNC\VNC4\winvnc4.exe
PRC - [2003/06/19 16:05:04 | 000,243,472 | ---- | M] (Microsoft Corporation) -- C:\WINNT\explorer.exe
PRC - [2003/06/19 16:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\wbem\WinMgmt.exe
PRC - [2003/06/19 16:05:04 | 000,119,568 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\mstask.exe
PRC - [2003/06/19 16:05:04 | 000,068,368 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\regsvc.exe
PRC - [2003/06/19 16:05:04 | 000,019,728 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\hidserv.exe
========== Modules (SafeList) ==========
MOD - [2010/11/17 09:51:18 | 000,575,488 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Administrator\Desktop\virus_et_al\OTL.exe
MOD - [2003/06/19 16:05:04 | 000,021,776 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\wsock32.dll
MOD - [2003/06/19 16:05:04 | 000,010,000 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\lz32.dll
MOD - [2001/05/08 12:00:00 | 000,011,536 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\netrap.dll
========== Win32 Services (SafeList) ==========
SRV - [2008/05/15 23:19:24 | 000,144,760 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\ashServ.exe -- (avast! Antivirus)
SRV - [2008/05/15 23:19:00 | 000,247,160 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe -- (avast! Mail Scanner)
SRV - [2008/05/15 23:16:59 | 000,349,560 | ---- | M] (ALWIL Software) [On_Demand | Running] -- C:\Program Files\Alwil Software\Avast4\ashWebSv.exe -- (avast! Web Scanner)
SRV - [2008/05/15 23:06:57 | 000,017,272 | ---- | M] (ALWIL Software) [Auto | Running] -- C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe -- (aswUpdSv)
SRV - [2006/06/01 11:08:26 | 000,204,800 | ---- | M] (Acronis) [Auto | Running] -- C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe -- (AcrSch2Svc)
SRV - [2006/05/12 15:04:08 | 000,439,248 | ---- | M] (RealVNC Ltd.) [Auto | Running] -- C:\Program Files\RealVNC\VNC4\WinVNC4.exe -- (WinVNC4)
SRV - [2003/06/19 16:05:04 | 000,196,706 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\wbem\WinMgmt.exe -- (WinMgmt)
SRV - [2003/06/19 16:05:04 | 000,147,728 | ---- | M] (VERITAS Software Corp.) [On_Demand | Stopped] -- C:\WINNT\System32\dmadmin.exe -- (dmadmin)
SRV - [2003/06/19 16:05:04 | 000,119,568 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\mstask.exe -- (Schedule)
SRV - [2003/06/19 16:05:04 | 000,094,992 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\FAXSVC.EXE -- (Fax)
SRV - [2003/06/19 16:05:04 | 000,068,368 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\regsvc.exe -- (RemoteRegistry)
SRV - [2003/06/19 16:05:04 | 000,022,800 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\WINNT\system32\utilman.exe -- (UtilMan)
SRV - [2003/06/19 16:05:04 | 000,019,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\WINNT\system32\hidserv.exe -- (HidServ)
========== Driver Services (SafeList) ==========
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\WINNT\System32\drivers\DMusic.sys -- (DMusic)
DRV - File not found [Kernel | On_Demand | Stopped] -- C:\ComboFix\catchme.sys -- (catchme)
DRV - [2008/05/15 23:20:32 | 000,078,416 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINNT\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2008/05/15 23:15:29 | 000,023,152 | ---- | M] (ALWIL Software) [Kernel | On_Demand | Running] -- C:\WINNT\System32\drivers\aswRdr.sys -- (aswRdr)
DRV - [2008/05/15 23:14:11 | 000,042,912 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINNT\System32\drivers\aswTdi.sys -- (aswTdi)
DRV - [2008/05/15 23:13:26 | 000,026,944 | ---- | M] (ALWIL Software) [Kernel | System | Running] -- C:\WINNT\System32\drivers\aavmker4.sys -- (Aavmker4)
DRV - [2008/01/17 17:34:01 | 000,093,264 | ---- | M] (ALWIL Software) [File_System | Auto | Running] -- C:\WINNT\System32\drivers\aswmon.sys -- (aswMon)
DRV - [2007/08/06 19:38:11 | 000,387,520 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINNT\system32\DRIVERS\timntr.sys -- (timounter)
DRV - [2007/08/06 19:38:11 | 000,032,224 | ---- | M] (Acronis) [File_System | Auto | Running] -- C:\WINNT\system32\drivers\tifsfilt.sys -- (tifsfilter)
DRV - [2007/08/06 19:38:08 | 000,099,776 | ---- | M] (Acronis) [Kernel | Boot | Running] -- C:\WINNT\system32\DRIVERS\snapman.sys -- (snapman)
DRV - [2006/05/16 08:53:00 | 000,243,840 | ---- | M] (Marvell) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\yk50x86.sys -- (yukonw2k)
DRV - [2005/02/09 14:11:14 | 000,316,040 | ---- | M] (Jungo) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\windrvr6.sys -- (WinDriver6)
DRV - [2003/09/18 16:50:02 | 000,129,904 | R--- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\e10002ke.sys -- (E1000) Intel(R)
DRV - [2003/09/12 13:41:20 | 000,018,176 | R--- | M] (Datel, Inc.) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\dtl5933w.sys -- (dtl5933w)
DRV - [2003/06/19 16:05:04 | 000,369,104 | ---- | M] (VERITAS Software Corp.) [Kernel | Disabled | Stopped] -- C:\WINNT\system32\drivers\dmboot.sys -- (dmboot)
DRV - [2003/06/19 16:05:04 | 000,137,936 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmio.sys -- (dmio)
DRV - [2003/06/19 16:05:04 | 000,060,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\parallel.sys -- (Parallel)
DRV - [2003/06/19 16:05:04 | 000,049,776 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\usbhub20.sys -- (usbhub20)
DRV - [2003/06/19 16:05:04 | 000,032,848 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\uhcd.sys -- (uhcd)
DRV - [2003/06/19 16:05:04 | 000,027,440 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Running] -- C:\WINNT\System32\drivers\efs.sys -- (EFS)
DRV - [2003/06/19 16:05:04 | 000,007,728 | ---- | M] (Microsoft Corporation) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\diskperf.sys -- (Diskperf)
DRV - [2003/06/19 16:05:04 | 000,007,312 | ---- | M] (VERITAS Software Corp.) [Kernel | Boot | Running] -- C:\WINNT\System32\drivers\dmload.sys -- (dmload)
DRV - [2001/06/12 02:01:10 | 000,052,512 | ---- | M] (Microsoft Corporation) [Kernel | Auto | Running] -- C:\WINNT\System32\Drivers\driverx.sys -- (DriverX)
DRV - [2001/05/08 12:00:00 | 000,021,712 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\rca.sys -- (RCA)
DRV - [2001/05/08 12:00:00 | 000,009,680 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\WINNT\system32\drivers\netdtect.sys -- (NetDetect)
DRV - [2000/04/20 03:00:02 | 000,006,995 | ---- | M] () [Kernel | Boot | Running] -- C:\WINNT\system32\DRIVERS\ramdisk.sys -- (Ramdisk)
DRV - [1999/05/27 16:13:40 | 000,025,360 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINNT\system32\drivers\E100ENT.sys -- (E100E)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINNT\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.msn.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
O1 HOSTS File: ([2010/11/16 08:53:33 | 000,000,027 | ---- | M]) - C:\WINNT\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx ()
O4 - HKLM..\Run: [Acronis Scheduler2 Service] C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe (Acronis)
O4 - HKLM..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImage\TimounterMonitor.exe (Acronis)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImage\TrueImageMonitor.exe (Acronis)
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to begininstr.bat.lnk = C:\Documents and Settings\Administrator\Desktop\begininstr.bat ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to scanner.exe.lnk = D:\ahs\GUI_AMS_03\debug\scanner.exe ()
O4 - Startup: C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to tftpd32.exe.lnk = C:\Program Files\Argon ST\tftpd32.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\related.htm ()
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\Web\related.htm ()
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\WINNT\system32\RNR20.DLL (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000011 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000012 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000013 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000014 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O10 - Protocol_Catalog9\Catalog_Entries\000000000015 - C:\WINNT\system32\msafd.dll (Microsoft Corporation)
O16 - DPF: DirectAnimation Java Classes file://C:\WINNT\Java\classes\dajava.cab (Reg Error: Key error.)
O16 - DPF: Microsoft XML Parser for Java file://C:\WINNT\Java\classes\xmldso.cab (Reg Error: Key error.)
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\WINNT\system32\msdxm.ocx ()
O18 - Protocol\Filter\Class Install Handler - No CLSID value found
O18 - Protocol\Filter\deflate - No CLSID value found
O18 - Protocol\Filter\gzip - No CLSID value found
O18 - Protocol\Filter\lzdhtml - No CLSID value found
O18 - Protocol\Filter\text/webviewhtml - No CLSID value found
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINNT\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxsrvc.dll - C:\WINNT\System32\igfxsrvc.dll (Intel Corporation)
O20 - Winlogon\Notify\wzcnotif: DllName - wzcdlg.dll - C:\WINNT\System32\wzcdlg.dll (Microsoft Corporation)
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/04/06 17:41:49 | 000,000,000 | -H-- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Nwsapagent - File not found
Drivers32: aux - C:\WINNT\System32\mmdrv.dll (Microsoft Corporation)
Drivers32: aux1 - File not found
Drivers32: aux2 - File not found
Drivers32: aux3 - File not found
Drivers32: aux4 - File not found
Drivers32: aux5 - File not found
Drivers32: aux6 - File not found
Drivers32: aux7 - File not found
Drivers32: aux8 - File not found
Drivers32: aux9 - File not found
Drivers32: midi1 - File not found
Drivers32: midi2 - File not found
Drivers32: midi3 - File not found
Drivers32: midi4 - File not found
Drivers32: midi5 - File not found
Drivers32: midi6 - File not found
Drivers32: midi7 - File not found
Drivers32: midi8 - File not found
Drivers32: midi9 - File not found
Drivers32: mixer1 - File not found
Drivers32: mixer2 - File not found
Drivers32: mixer3 - File not found
Drivers32: mixer4 - File not found
Drivers32: mixer5 - File not found
Drivers32: mixer6 - File not found
Drivers32: mixer7 - File not found
Drivers32: mixer8 - File not found
Drivers32: mixer9 - File not found
Drivers32: msacm.iac2 - C:\WINNT\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.lhacm - C:\WINNT\System32\lhacm.acm (Microsoft Corporation)
Drivers32: msacm.trspch - C:\WINNT\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINNT\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINNT\System32\ir32_32.dll ()
Drivers32: vidc.iv50 - C:\WINNT\System32\ir50_32.dll (Intel Corporation)
Drivers32: VIDC.UYVY - msyuv.dll File not found
Drivers32: wave1 - File not found
Drivers32: wave2 - File not found
Drivers32: wave3 - File not found
Drivers32: wave4 - File not found
Drivers32: wave5 - File not found
Drivers32: wave6 - File not found
Drivers32: wave7 - File not found
Drivers32: wave8 - File not found
Drivers32: wave9 - File not found
Drivers32: wdmaud.drv - wdmaud.drv File not found
SystemRestore not available.
========== Files/Folders - Created Within 30 Days ==========
[2010/11/16 09:01:33 | 000,000,000 | -HSD | C] -- C:\RECYCLER
[2010/11/16 08:51:58 | 000,000,000 | ---D | C] -- C:\WINNT\temp
[2010/11/15 12:12:34 | 000,212,480 | ---- | C] (SteelWerX) -- C:\WINNT\SWXCACLS.exe
[2010/11/15 12:12:34 | 000,161,792 | ---- | C] (SteelWerX) -- C:\WINNT\SWREG.exe
[2010/11/15 12:12:34 | 000,136,704 | ---- | C] (SteelWerX) -- C:\WINNT\SWSC.exe
[2010/11/15 12:12:34 | 000,031,232 | ---- | C] (NirSoft) -- C:\WINNT\NIRCMD.exe
[2010/11/15 12:12:30 | 000,000,000 | ---D | C] -- C:\WINNT\ERDNT
[2010/11/15 12:12:12 | 000,000,000 | ---D | C] -- C:\Qoobox
[2010/11/12 12:45:30 | 000,023,152 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aswRdr.sys
[2010/11/12 12:45:29 | 000,042,912 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aswTdi.sys
[2010/11/12 12:45:28 | 000,026,944 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aavmker4.sys
[2010/11/12 12:45:25 | 000,095,608 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\AvastSS.scr
[2010/11/12 12:45:25 | 000,094,416 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aswmon2.sys
[2010/11/12 12:45:25 | 000,093,264 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aswmon.sys
[2010/11/12 12:45:25 | 000,078,416 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\drivers\aswSP.sys
[2010/11/12 12:45:12 | 001,152,888 | ---- | C] (ALWIL Software) -- C:\WINNT\System32\aswBoot.exe
[2010/11/12 12:41:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Desktop\AvastInstall
[2010/11/12 12:32:07 | 000,000,000 | R--D | C] -- C:\Documents and Settings\Administrator\Desktop\virus_et_al
[2010/11/11 16:08:21 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Administrator\Application Data\Malwarebytes
[2010/11/11 16:08:08 | 000,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbamswissarmy.sys
[2010/11/11 16:08:07 | 000,019,288 | ---- | C] (Malwarebytes Corporation) -- C:\WINNT\System32\drivers\mbam.sys
[2010/11/11 16:08:07 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2010/11/11 16:08:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes
========== Files - Modified Within 30 Days ==========
[2010/11/17 14:54:21 | 000,000,383 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to virus_et_al.lnk
[2010/11/17 14:42:56 | 000,016,384 | ---- | M] () -- C:\WINNT\System32\Perflib_Perfdata_268.dat
[2010/11/17 13:15:17 | 000,922,094 | -H-- | M] () -- C:\WINNT\ShellIconCache
[2010/11/17 12:53:34 | 000,000,498 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to scanner.exe.lnk
[2010/11/17 12:52:12 | 000,000,477 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to acquire.exe.lnk
[2010/11/16 18:52:33 | 000,000,539 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to weekly.lnk
[2010/11/16 08:53:33 | 000,000,027 | ---- | M] () -- C:\WINNT\System32\drivers\etc\hosts
[2010/11/15 06:39:50 | 003,910,027 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/11/13 13:58:02 | 000,000,615 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to Startup.lnk
[2010/11/13 10:53:59 | 000,000,382 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2010/11/12 12:45:30 | 000,001,584 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2010/11/12 12:45:28 | 000,002,626 | ---- | M] () -- C:\WINNT\System32\CONFIG.NT
[2010/11/11 16:08:10 | 000,000,603 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/11 15:28:07 | 000,000,428 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to inst.exe.lnk
[2010/11/11 15:26:02 | 000,000,439 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut (2) to acquire.dsw.lnk
[2010/11/11 12:59:23 | 000,000,498 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to scanner.exe.lnk
[2010/11/09 20:31:44 | 000,000,525 | ---- | M] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to begininstr.bat.lnk
[2010/11/09 20:31:44 | 000,000,525 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to begininstr.bat.lnk
[2010/11/09 15:25:03 | 000,000,459 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to scanner.dsw.lnk
[2010/11/09 15:22:48 | 000,000,084 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\begininstr.bat
[2010/11/09 15:19:59 | 000,000,339 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to ahs.lnk
[2010/11/09 14:32:31 | 000,000,421 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to inst.dsw.lnk
[2010/11/08 01:20:24 | 000,089,088 | ---- | M] () -- C:\WINNT\MBR.exe
========== Files Created - No Company Name ==========
[2010/11/17 14:42:56 | 000,016,384 | ---- | C] () -- C:\WINNT\System32\Perflib_Perfdata_268.dat
[2010/11/17 12:53:34 | 000,000,498 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to scanner.exe.lnk
[2010/11/16 09:23:40 | 000,000,607 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to tftpd32.exe.lnk
[2010/11/16 09:23:37 | 000,000,525 | ---- | C] () -- C:\Documents and Settings\Administrator\Start Menu\Programs\Startup\Shortcut to begininstr.bat.lnk
[2010/11/15 12:12:34 | 000,256,512 | ---- | C] () -- C:\WINNT\PEV.exe
[2010/11/15 12:12:34 | 000,098,816 | ---- | C] () -- C:\WINNT\sed.exe
[2010/11/15 12:12:34 | 000,089,088 | ---- | C] () -- C:\WINNT\MBR.exe
[2010/11/15 12:12:34 | 000,080,412 | ---- | C] () -- C:\WINNT\grep.exe
[2010/11/15 12:12:34 | 000,068,096 | ---- | C] () -- C:\WINNT\zip.exe
[2010/11/15 11:54:41 | 003,910,027 | R--- | C] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2010/11/13 13:58:02 | 000,000,615 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to Startup.lnk
[2010/11/13 10:53:59 | 000,000,382 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\WinZip.lnk
[2010/11/12 17:46:21 | 000,000,383 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut to virus_et_al.lnk
[2010/11/12 12:45:30 | 000,001,584 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\avast! Antivirus.lnk
[2010/11/12 12:45:12 | 000,380,928 | ---- | C] () -- C:\WINNT\System32\actskin4.ocx
[2010/11/11 16:08:10 | 000,000,603 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/11/11 15:26:02 | 000,000,439 | ---- | C] () -- C:\Documents and Settings\Administrator\Desktop\Shortcut (2) to acquire.dsw.lnk
[2006/06/05 12:22:05 | 000,000,010 | ---- | C] () -- C:\WINNT\WININIT.INI
[2006/05/15 13:06:52 | 000,006,995 | ---- | C] () -- C:\WINNT\System32\drivers\ramdisk.sys
[2006/04/06 18:19:48 | 000,000,000 | ---- | C] () -- C:\WINNT\Devcon.INI
[2006/04/06 18:01:02 | 000,053,248 | ---- | C] () -- C:\WINNT\System32\AISS44AO4 Driver C.dll
[2006/04/06 18:01:01 | 000,057,344 | ---- | C] () -- C:\WINNT\System32\GSApi.dll
[2006/04/06 17:40:44 | 000,021,952 | -H-- | C] () -- C:\Program Files\folder.htt
[2006/04/06 13:26:54 | 000,004,073 | ---- | C] () -- C:\WINNT\ODBCINST.INI
[2001/05/08 12:00:00 | 000,176,400 | ---- | C] () -- C:\WINNT\System32\qcut.dll
[2001/05/08 12:00:00 | 000,033,552 | ---- | C] () -- C:\WINNT\System32\efsadu.dll
[2001/05/08 12:00:00 | 000,007,265 | ---- | C] () -- C:\WINNT\System32\iasperf.ini
[2001/05/08 12:00:00 | 000,001,505 | ---- | C] () -- C:\WINNT\System32\faxperf.ini
[2001/05/08 12:00:00 | 000,000,023 | ---- | C] () -- C:\WINNT\welcome.ini
[1999/09/25 10:36:24 | 000,088,816 | ---- | C] () -- C:\WINNT\System32\drivers\lvcam.sys
[1999/09/25 10:36:22 | 000,017,424 | ---- | C] () -- C:\WINNT\System32\drivers\lvsound.sys
[1997/07/11 04:00:00 | 000,031,232 | ---- | C] () -- C:\WINNT\System32\XLREC.DLL
[1997/07/11 04:00:00 | 000,025,600 | ---- | C] () -- C:\WINNT\System32\RECNCL.DLL
[1997/07/11 04:00:00 | 000,022,016 | ---- | C] () -- C:\WINNT\System32\DOCOBJ.DLL
[1997/07/11 04:00:00 | 000,012,288 | ---- | C] () -- C:\WINNT\System32\HLINKPRX.DLL
========== LOP Check ==========
[2006/09/07 01:26:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Acronis
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2009/05/06 12:11:00 | 000,581,814 | ---- | M] () -- C:\5_6_9_2nd.bmp
[2003/06/19 16:05:04 | 000,150,528 | RHS- | M] () -- C:\arcldr.exe
[2003/06/19 16:05:04 | 000,163,840 | RHS- | M] () -- C:\arcsetup.exe
[2006/04/06 17:41:49 | 000,000,000 | -H-- | M] () -- C:\AUTOEXEC.BAT
[2009/11/18 14:23:45 | 000,921,654 | ---- | M] () -- C:\bit.bmp
[2006/04/06 13:36:58 | 000,000,192 | -HS- | M] () -- C:\boot.ini
[2009/10/28 14:56:12 | 000,635,238 | ---- | M] () -- C:\cheat_dbr.bmp
[2010/11/16 08:55:58 | 000,006,335 | ---- | M] () -- C:\ComboFix.txt
[2006/04/06 17:41:49 | 000,000,000 | -H-- | M] () -- C:\CONFIG.SYS
[2009/04/10 18:17:07 | 000,581,814 | ---- | M] () -- C:\ehternet_1.bmp
[2009/04/10 18:17:43 | 000,581,814 | ---- | M] () -- C:\ehternet_2.bmp
[2009/05/06 12:07:46 | 000,581,814 | ---- | M] () -- C:\enet_5_6_9.bmp
[2010/08/17 12:02:24 | 001,825,086 | ---- | M] () -- C:\full.bmp
[2009/11/18 14:25:21 | 000,921,654 | ---- | M] () -- C:\gui.bmp
[2006/04/06 17:41:49 | 000,000,000 | RHS- | M] () -- C:\IO.SYS
[2010/08/12 17:43:46 | 000,587,910 | ---- | M] () -- C:\ipconfig_8_12_10.bmp
[2006/04/06 17:41:49 | 000,000,000 | RHS- | M] () -- C:\MSDOS.SYS
[2006/05/10 16:27:46 | 000,034,724 | RHS- | M] () -- C:\NTDETECT.COM
[2006/05/10 16:27:46 | 000,214,432 | RHS- | M] () -- C:\ntldr
[2010/11/17 14:42:45 | 1598,029,824 | -HS- | M] () -- C:\pagefile.sys
[2007/11/27 20:11:00 | 000,000,420 | ---- | M] () -- C:\pipe.txt
[2009/05/07 16:47:46 | 001,810,614 | ---- | M] () -- C:\railed_1.bmp
[2010/11/13 10:57:28 | 000,027,638 | ---- | M] () -- C:\TDSSKiller.2.4.7.0_13.11.2010_10.55.29_log.txt
[2008/10/07 13:44:46 | 000,714,544 | ---- | M] () -- C:\vnc-4_1_2-x86_win32.zip
< %systemroot%\Fonts\*.com >
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/04/06 17:41:11 | 000,000,067 | -HS- | M] () -- C:\WINNT\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2003/06/19 16:05:04 | 000,006,928 | ---- | M] (Microsoft Corporation) -- C:\WINNT\system32\spool\prtprocs\w32x86\sfmpsprt.dll
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2006/04/06 17:40:44 | 000,000,271 | -H-- | M] () -- C:\Program Files\desktop.ini
[2006/04/06 17:40:44 | 000,021,952 | -H-- | M] () -- C:\Program Files\folder.htt
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
[2006/04/06 13:23:38 | 000,081,920 | ---- | M] () -- C:\WINNT\system32\config\default.sav
[2006/04/06 13:23:38 | 000,540,672 | ---- | M] () -- C:\WINNT\system32\config\software.sav
[2006/04/06 13:23:38 | 000,393,216 | ---- | M] () -- C:\WINNT\system32\config\system.sav
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2006/05/10 16:37:09 | 000,000,079 | ---- | M] () -- C:\Documents and Settings\Administrator\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf
< %USERPROFILE%\Desktop\*.exe >
[2010/11/15 06:39:50 | 003,910,027 | R--- | M] () -- C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
[2004/10/12 18:58:32 | 000,126,976 | ---- | M] () -- C:\Documents and Settings\Administrator\Desktop\DrxPortIo.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< %APPDATA%\Roaming\Microsoft\Windows\Recent\*.lnk /x >
< %PROGRAMFILES%\PC-Doctor\Downloads\*.* >
< %PROGRAMFILES%\Internet Explorer\*.tmp >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %USERPROFILE%\My Documents\*.exe >
< %USERPROFILE%\*.exe >
< %systemroot%\ADDINS\*.* >
[2001/05/08 12:00:00 | 000,000,777 | ---- | M] () -- C:\WINNT\addins\faxext.ecf
< %systemroot%\assembly\*.bak2 >
< %systemroot%\Config\*.* >
[2001/05/08 12:00:00 | 000,000,654 | ---- | M] () -- C:\WINNT\Config\general.idf
[2001/05/08 12:00:00 | 000,000,658 | ---- | M] () -- C:\WINNT\Config\hindered.idf
[2001/05/08 12:00:00 | 000,000,302 | ---- | M] () -- C:\WINNT\Config\msadlib.idf
< %systemroot%\REPAIR\*.bak2 >
< %systemroot%\SECURITY\Database\*.sdb /x >
< %systemroot%\SYSTEM\*.bak2 >
< %systemroot%\Web\*.bak2 >
< %systemroot%\Driver Cache\*.* >
< %PROGRAMFILES%\Mozilla Firefox\0*.exe >
< %ProgramFiles%\Microsoft Common\*.* >
< %ProgramFiles%\TinyProxy. >
< %USERPROFILE%\Favorites\*.url /x >
[2006/05/10 16:37:09 | 000,000,083 | -HS- | M] () -- C:\Documents and Settings\Administrator\Favorites\Desktop.ini
[2006/04/06 19:15:39 | 000,000,571 | ---- | M] () -- C:\Documents and Settings\Administrator\Favorites\My Documents.lnk
< %systemroot%\system32\*.bk >
< %systemroot%\*.te >
< %systemroot%\system32\system32\*.* >
< %ALLUSERSPROFILE%\*.dat /x >
[2006/05/10 16:36:56 | 000,002,370 | RHS- | M] () -- C:\Documents and Settings\All Users\ntuser.pol
< %systemroot%\system32\drivers\*.rmv >
< dir /b "%systemroot%\system32\*.exe" | find /i " " /c >
< dir /b "%systemroot%\*.exe" | find /i " " /c >
< %PROGRAMFILES%\Microsoft\*.* >
< %systemroot%\System32\Wbem\proquota.exe >
< %PROGRAMFILES%\Mozilla Firefox\*.dat >
< %USERPROFILE%\Cookies\*.txt /x >
[2010/11/17 14:57:29 | 000,032,768 | ---- | M] () -- C:\Documents and Settings\Administrator\Cookies\index.dat
< %SystemRoot%\system32\fonts\*.* >
< %systemroot%\system32\winlog\*.* >
< %systemroot%\system32\Language\*.* >
< %systemroot%\system32\Settings\*.* >
< %systemroot%\system32\*.quo >
< %SYSTEMROOT%\AppPatch\*.exe >
< %SYSTEMROOT%\inf\*.exe >
[2003/06/19 16:05:04 | 000,221,184 | ---- | M] () -- C:\WINNT\inf\unregmp2.exe
< %SYSTEMROOT%\Installer\*.exe >
< %systemroot%\system32\config\*.bak2 >
< %systemroot%\system32\Computers\*.* >
< %SystemRoot%\system32\Sound\*.* >
< %SystemRoot%\system32\SpecialImg\*.* >
< %SystemRoot%\system32\code\*.* >
< %SystemRoot%\system32\draft\*.* >
< %SystemRoot%\system32\MSSSys\*.* >
< %ProgramFiles%\Javascript\*.* >
< %systemroot%\pchealth\helpctr\System\*.exe /s >
< %systemroot%\Web\*.exe >
< %systemroot%\system32\msn\*.* >
< %systemroot%\system32\*.tro >
< %AppData%\Microsoft\Installer\msupdates\*.* >
< %ProgramFiles%\Messenger\*.* >
< %systemroot%\system32\systhem32\*.* >
< %systemroot%\system\*.exe >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >