
I was recently directed here from a different forum when I, while trying to diagnose a computer issue involving randomly spiking CPU and screen static, it was made clear that my system was infected. The virus was called Agobot, and seems to be located in my csrss.exe file, the boot startup of which, incidentally, I disabled just this morning when I began to receive error messages that csrss.exe was crashing. I'm not sure what this means exactly, but one of my concerns is that there are other viruses or whatnots in my computer and I am anxious to see them gone and to prevent further entry into my system. I do not know how it was obtained, and I figured that if there were any viruses, my Avira Free Anti-Virus might have picked them up. Before Avira, I was running Avast, and I still had the same situation where, when playing movies or games, my computer's CPU would spike and horizontal static would appear every few minutes or so. I have also run Spybot S&D, just to be thorough in describing what I've tried so far.
This computer is a laptop; a Dell Latitude D620, running Windows XP Professional.
Let me know if I can provide any more information. Below I have included my OTL report:
---
OTL logfile created on: 5/23/2011 4:34:50 PM - Run 1
OTL by OldTimer - Version 3.2.23.0 Folder = C:\Documents and Settings\Dioscuri\My Documents\Downloads
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 0.87 Gb Available Physical Memory | 43.74% Memory free
3.84 Gb Paging File | 2.76 Gb Available in Paging File | 71.68% Paging File free
Paging file location(s): C:\pagefile.sys 0 0 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 149.05 Gb Total Space | 13.09 Gb Free Space | 8.78% Space Free | Partition Type: NTFS
Drive F: | 465.76 Gb Total Space | 275.01 Gb Free Space | 59.05% Space Free | Partition Type: NTFS
Computer Name: THXSEAGATE | User Name: Dioscuri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2011/05/23 16:34:38 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dioscuri\My Documents\Downloads\OTL.exe
PRC - [2011/05/23 15:32:22 | 000,216,576 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Local Settings\Temp\csrss.exe
PRC - [2011/05/23 13:38:05 | 000,206,336 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\dwm.exe
PRC - [2011/05/19 19:19:50 | 000,196,608 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\Microsoft\conhost.exe
PRC - [2011/05/07 04:57:16 | 001,010,232 | ---- | M] (Google Inc.) -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\Google\Chrome\Application\chrome.exe
PRC - [2011/03/28 16:15:53 | 000,076,968 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
PRC - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe
PRC - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/03/28 16:15:29 | 000,281,768 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
PRC - [2010/03/05 10:01:46 | 000,862,480 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe
PRC - [2010/03/05 09:57:28 | 001,396,736 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe
PRC - [2010/03/05 09:54:20 | 000,954,368 | ---- | M] (Intel® Corporation) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe
PRC - [2010/03/05 09:46:22 | 001,206,544 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
PRC - [2010/03/05 09:43:50 | 000,473,360 | ---- | M] (Intel® Corporation) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
PRC - [2010/01/29 10:16:40 | 000,090,112 | ---- | M] () -- C:\Program Files\BigFix Enterprise\BES Client\PowerManagement\BFIdleTracker.exe
PRC - [2009/10/19 19:08:22 | 001,408,072 | ---- | M] (BigFix, Inc.) -- C:\Program Files\BigFix Enterprise\BES Client\BESClientUI.exe
PRC - [2009/10/19 19:08:20 | 002,370,632 | ---- | M] (BigFix Inc.) -- C:\Program Files\BigFix Enterprise\BES Client\BESClient.exe
PRC - [2009/09/22 17:00:00 | 000,136,512 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\UdaterUI.exe
PRC - [2009/09/22 17:00:00 | 000,091,456 | ---- | M] (McAfee, Inc.) -- C:\Program Files\McAfee\Common Framework\McTray.exe
PRC - [2008/06/11 22:43:26 | 000,640,376 | ---- | M] (Adobe Systems Inc.) -- C:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exe
PRC - [2008/04/14 06:42:20 | 001,033,728 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\explorer.exe
PRC - [2007/10/09 17:21:06 | 000,169,328 | ---- | M] (Maxtor Corporation) -- C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe
PRC - [2007/10/09 17:21:02 | 000,124,280 | ---- | M] (Seagate Technology LLC) -- C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe
PRC - [2007/07/20 17:55:46 | 001,228,800 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\quickset.exe
PRC - [2007/07/20 17:53:52 | 000,475,136 | ---- | M] (Dell Inc.) -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe
PRC - [2007/05/10 10:22:32 | 000,405,504 | ---- | M] (SigmaTel, Inc.) -- C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe
PRC - [2005/10/07 14:13:38 | 000,176,128 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\Apoint.exe
PRC - [2005/09/08 06:20:00 | 000,122,940 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\DLA\DLACTRLW.EXE
PRC - [2005/07/27 16:41:08 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\ApntEx.exe
PRC - [2004/06/28 23:56:12 | 000,045,056 | ---- | M] (Alps Electric Co., Ltd.) -- C:\Program Files\Apoint\hidfind.exe
========== Modules (SafeList) ==========
MOD - [2011/05/23 16:34:38 | 000,580,096 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Dioscuri\My Documents\Downloads\OTL.exe
MOD - [2010/08/23 09:12:02 | 001,054,208 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.6028_x-ww_61e65202\comctl32.dll
========== Win32 Services (SafeList) ==========
SRV - [2011/03/28 16:15:40 | 000,136,360 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\sched.exe -- (AntiVirSchedulerService)
SRV - [2011/03/28 16:15:30 | 000,269,480 | ---- | M] (Avira GmbH) [Auto | Running] -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe -- (AntiVirService)
SRV - [2010/07/15 08:39:56 | 000,651,720 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/05 10:01:46 | 000,862,480 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel®
SRV - [2010/03/05 09:54:20 | 000,954,368 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe -- (S24EventMonitor) Intel®
SRV - [2010/03/05 09:43:50 | 000,473,360 | ---- | M] (Intel® Corporation) [Auto | Running] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel®
SRV - [2009/10/19 19:08:20 | 002,370,632 | ---- | M] (BigFix Inc.) [Auto | Running] -- C:\Program Files\BigFix Enterprise\BES Client\BESClient.exe -- (BESClient)
SRV - [2009/09/22 17:00:00 | 000,103,744 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\McAfee\Common Framework\FrameworkService.exe -- (McAfeeFramework)
SRV - [2007/10/09 17:21:02 | 000,124,280 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files\Seagate\Basics\Service\SyncServicesBasics.exe -- (Basics Service)
SRV - [2007/07/20 17:53:52 | 000,475,136 | ---- | M] (Dell Inc.) [Auto | Running] -- C:\Program Files\Dell\QuickSet\NicConfigSvc.exe -- (NICCONFIGSVC)
========== Driver Services (SafeList) ==========
DRV - [2011/04/01 17:07:59 | 000,137,656 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb)
DRV - [2011/04/01 17:07:59 | 000,061,960 | ---- | M] (Avira GmbH) [File_System | Auto | Running] -- C:\WINDOWS\system32\drivers\avgntflt.sys -- (avgntflt)
DRV - [2010/10/19 11:54:41 | 000,691,696 | ---- | M] () [Kernel | Boot | Running] -- C:\WINDOWS\System32\Drivers\sptd.sys -- (sptd)
DRV - [2010/06/17 15:27:22 | 000,028,520 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv)
DRV - [2010/06/17 15:27:12 | 000,011,608 | ---- | M] (Avira GmbH) [Kernel | System | Running] -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys -- (avgio)
DRV - [2010/05/31 11:58:36 | 006,608,512 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\NETw5x32.sys -- (NETw5x32) Intel®
DRV - [2009/08/10 01:46:38 | 000,013,952 | ---- | M] (Intel Corporation) [Kernel | Auto | Running] -- C:\WINDOWS\system32\drivers\s24trans.sys -- (s24trans)
DRV - [2007/09/26 02:01:00 | 002,236,032 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\NETw4x32.sys -- (NETw4x32) Intel®
DRV - [2007/05/10 10:24:34 | 001,222,840 | ---- | M] (SigmaTel, Inc.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\sthda.sys -- (STHDA)
DRV - [2007/02/09 22:06:00 | 000,100,096 | ---- | M] (LSI Logic) [Kernel | Boot | Running] -- C:\WINDOWS\system32\drivers\symmpi.sys -- (symmpi)
DRV - [2006/05/02 19:45:45 | 000,028,672 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\usbccid.sys -- (USBCCID)
DRV - [2005/10/26 11:01:02 | 000,142,720 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\b57xp32.sys -- (b57w2k)
DRV - [2005/09/28 21:57:18 | 000,113,847 | ---- | M] (Alps Electric Co., Ltd.) [Kernel | On_Demand | Running] -- C:\WINDOWS\system32\drivers\Apfiltr.sys -- (ApfiltrService)
DRV - [2005/09/08 06:20:00 | 000,094,332 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDFAM.SYS -- (DLAUDFAM)
DRV - [2005/09/08 06:20:00 | 000,087,036 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAUDF_M.SYS -- (DLAUDF_M)
DRV - [2005/09/08 06:20:00 | 000,086,524 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAIFS_M.SYS -- (DLAIFS_M)
DRV - [2005/09/08 06:20:00 | 000,025,628 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLABOIOM.SYS -- (DLABOIOM)
DRV - [2005/09/08 06:20:00 | 000,014,684 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAOPIOM.SYS -- (DLAOPIOM)
DRV - [2005/09/08 06:20:00 | 000,006,364 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLAPoolM.SYS -- (DLAPoolM)
DRV - [2005/09/08 06:20:00 | 000,002,496 | ---- | M] (Sonic Solutions) [File_System | Auto | Running] -- C:\WINDOWS\system32\DLA\DLADResN.SYS -- (DLADResN)
DRV - [2005/08/25 13:16:52 | 000,005,628 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLACDBHM.SYS -- (DLACDBHM)
DRV - [2005/08/25 13:16:16 | 000,022,684 | ---- | M] (Sonic Solutions) [File_System | System | Running] -- C:\WINDOWS\system32\drivers\DLARTL_N.SYS -- (DLARTL_N)
DRV - [2005/08/12 18:50:46 | 000,016,128 | ---- | M] (Dell Inc) [Kernel | System | Running] -- C:\WINDOWS\SYSTEM32\DRIVERS\APPDRV.SYS -- (APPDRV)
DRV - [2005/02/11 05:52:36 | 000,157,056 | ---- | M] (Texas Instruments) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\tifm21.sys -- (tifm21)
DRV - [2004/08/03 15:29:28 | 000,701,440 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\ati2mtag.sys -- (ati2mtag)
DRV - [2004/06/15 16:06:20 | 000,251,578 | ---- | M] (Adaptec, Inc.) [Kernel | Boot | Running] -- C:\WINDOWS\system32\DRIVERS\a320raid.sys -- (a320raid)
DRV - [2001/08/17 10:11:06 | 000,066,591 | ---- | M] (3Com Corporation) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\el90xbc5.sys -- (EL90XBC)
DRV - [2001/08/17 10:10:28 | 000,035,913 | ---- | M] (SMC) [Kernel | On_Demand | Stopped] -- C:\WINDOWS\system32\drivers\smcirda.sys -- (SMCIRDA)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = \system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://my.seagate.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.c...rch/search.html
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:50545
========== FireFox ==========
FF - prefs.js..network.proxy.http: "127.0.0.1"
FF - prefs.js..network.proxy.http_port: 50545
FF - prefs.js..network.proxy.type: 1
[2011/05/09 10:02:36 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\Dioscuri\Application Data\Mozilla\Extensions
[2011/05/09 10:23:02 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
[2010/01/13 12:26:00 | 000,000,000 | ---D | M] (IE View) -- C:\Program Files\Mozilla Firefox\extensions\{6e84150a-d526-41f1-a480-a67d3fed910d}
[2010/01/12 14:35:24 | 000,000,000 | ---D | M] (Adblock Plus) -- C:\Program Files\Mozilla Firefox\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}
[2010/01/13 12:25:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}-trash
File not found (No name found) --
[2010/09/23 13:03:24 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF
[2010/09/26 03:16:42 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\WINDOWS\MICROSOFT.NET\FRAMEWORK\V3.5\WINDOWS PRESENTATION FOUNDATION\DOTNETASSISTANTEXTENSION
O1 HOSTS File: ([2010/06/16 16:43:22 | 000,000,734 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (DriveLetterAccess) - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\DLA\DLASHX_W.DLL (Sonic Solutions)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O2 - BHO: (SmartSelect Class) - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Acrobat Assistant 8.0] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe (Adobe Systems Inc.)
O4 - HKLM..\Run: [Adobe Acrobat Speed Launcher] C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe (Alps Electric Co., Ltd.)
O4 - HKLM..\Run: [Auto_Inventory] C:\WINDOWS\LD_Boot.exe ()
O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [basicsmssmenu] C:\Program Files\Seagate\Basics\Basics Status\MaxMenuMgrBasics.exe (Maxtor Corporation)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.cpl (Microsoft Corporation)
O4 - HKLM..\Run: [conhost] C:\Documents and Settings\Dioscuri\Application Data\Microsoft\conhost.exe ()
O4 - HKLM..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe (Dell Inc.)
O4 - HKLM..\Run: [DLA] C:\WINDOWS\system32\DLA\DLACTRLW.EXE (Sonic Solutions)
O4 - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4 - HKLM..\Run: [IntelZeroConfig] C:\Program Files\Intel\WiFi\bin\ZCfgSvc.exe (Intel® Corporation)
O4 - HKLM..\Run: [McAfeeUpdaterUI] C:\Program Files\McAfee\Common Framework\udaterui.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NvCplDaemon] C:\WINDOWS\System32\NvCpl.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NVHotkey] C:\WINDOWS\System32\nvhotkey.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\WINDOWS\System32\NvMcTray.dll (NVIDIA Corporation)
O4 - HKLM..\Run: [nwiz] C:\WINDOWS\System32\nwiz.exe ()
O4 - HKLM..\Run: [SigmatelSysTrayApp] C:\Program Files\Sigmatel\C-Major Audio\WDM\stsystra.exe (SigmaTel, Inc.)
O4 - HKLM..\RunOnce: [Spybot - Search & Destroy] C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe (Safer Networking Limited)
O4 - Startup: C:\Documents and Settings\Dioscuri\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE ()
F3 - HKCU WinNT: Load - (C:\DOCUME~1\Dioscuri\LOCALS~1\Temp\csrss.exe) - C:\Documents and Settings\Dioscuri\Local Settings\Temp\csrss.exe ()
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoCDBurning = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoSharedDocuments = 1
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\WINDOWS\System32\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {05D96F71-87C6-11D3-9BE4-00902742D6E0} https://quickr.seagate.com/qp2.cab (Lotus Quickr Class)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://www.pcpitstop...t/PCPitStop.CAB (PCPitstop Utility)
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} http://www.nvidia.co...sreqlab_nvd.cab (System Requirements Lab Class)
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} http://www.update.mi...b?1201641630687 (WUWebControl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {8CFCF42C-1C64-47D6-AEEC-F9D001832ED3} http://xserv.dell.co.../DellSystem.CAB (DellSystem.Scanner)
O16 - DPF: {9C855227-889B-4B50-A41E-4B97C2F1E6A5} https://seagate.soft.../SLMSViewer.cab (SLMSViewer Control)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell....lSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {C3CBFE35-9BE8-11D1-B31B-006008948294} http://ok-orgpub.okl...ins/OrgPubX.cab (OrgPublisher PluginX)
O16 - DPF: {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA} https://eet61.adp.co...dows-i586-p.exe (Java Plug-in)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://internationa...ent/ieatgpc.cab (Reg Error: Key error.)
O16 - DPF: {F27237D7-93C8-44C2-AC6E-D6057B9A918F} https://ssl-sv.seaga...SetupClient.cab (JuniperSetupClientControl Class)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: GinaDLL - (MSGINA.DLL) - C:\WINDOWS\System32\msgina.dll (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (C:\Documents and Settings\Dioscuri\Application Data\dwm.exe) - C:\Documents and Settings\Dioscuri\Application Data\dwm.exe ()
O24 - Desktop WallPaper: C:\Documents and Settings\Dioscuri\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Dioscuri\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2005/05/01 09:41:33 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ]
O32 - Unable to obtain root file information for disk F:\
O33 - MountPoints2\{33532d45-ce7e-11dc-a65b-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{33532d45-ce7e-11dc-a65b-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{33532d45-ce7e-11dc-a65b-806d6172696f}\Shell\AutoRun\command - "" = D:\Programs\nu2menu\nu2menu.exe
O33 - MountPoints2\{a47e1dc3-ba32-11d9-9e03-806d6172696f}\Shell - "" = AutoRun
O33 - MountPoints2\{a47e1dc3-ba32-11d9-9e03-806d6172696f}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{a47e1dc3-ba32-11d9-9e03-806d6172696f}\Shell\AutoRun\command - "" = D:\setup.exe
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/05/23 13:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\WhoCrashed
[2011/05/23 13:37:53 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\WhoCrashed
[2011/05/23 09:16:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy
[2011/05/23 09:16:40 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy
[2011/05/23 09:16:40 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2011/05/23 09:08:29 | 000,000,000 | ---D | C] -- C:\WINDOWS\ERDNT
[2011/05/23 09:07:44 | 000,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2011/05/23 09:07:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\ERUNT
[2011/05/20 11:48:12 | 000,000,000 | ---D | C] -- C:\WINDOWS\Minidump
[2011/05/20 01:51:07 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\NtmsData
[2011/05/19 22:56:09 | 000,000,000 | ---D | C] -- C:\Program Files\directx
[2011/05/19 19:20:33 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\Kernel Recovery for iPod(Demo)
[2011/05/19 19:08:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Fox Interactive
[2011/05/19 13:01:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\Avira
[2011/05/19 11:26:04 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira
[2011/05/19 11:25:46 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys
[2011/05/19 11:25:43 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys
[2011/05/19 11:25:43 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys
[2011/05/19 11:25:43 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys
[2011/05/19 11:25:43 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys
[2011/05/19 11:25:41 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2011/05/19 11:25:41 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira
[2011/05/18 11:00:24 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\WindSolutions
[2011/05/18 11:00:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2011/05/16 17:48:52 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Desktop\[bleep], man (movies)
[2011/05/16 17:00:45 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Desktop\[bleep], man
[2011/05/16 16:52:20 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Recuva
[2011/05/16 16:52:19 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2011/05/10 22:38:58 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Start Menu\Programs\DVD Decrypter
[2011/05/10 22:38:57 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Decrypter
[2011/05/10 22:38:39 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\DVD Shrink
[2011/05/10 22:38:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\DVD Shrink
[2011/05/10 22:38:37 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Shrink
[2011/05/10 22:33:44 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\PackageAware
[2011/05/10 22:21:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\dvdcss
[2011/05/09 17:08:24 | 000,000,000 | RH-D | C] -- C:\Documents and Settings\Dioscuri\Recent
[2011/05/09 13:13:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\My Documents\Red Kawa
[2011/05/09 13:13:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\Red Kawa
[2011/05/09 11:07:02 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\Geckofx
[2011/05/09 11:03:18 | 000,000,000 | ---D | C] -- C:\Program Files\AviSynth 2.5
[2011/05/09 11:02:45 | 000,000,000 | ---D | C] -- C:\Program Files\AnvSoft
[2011/05/09 11:02:34 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Red Kawa
[2011/05/09 11:02:26 | 000,000,000 | ---D | C] -- C:\Program Files\Red Kawa
[2011/05/09 10:02:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\Mozilla
[2011/05/06 11:44:49 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Local Settings\Application Data\Google
[2011/05/06 11:25:23 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\My Documents\Any Video Converter
[2011/05/06 11:24:59 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\AnvSoft
[2011/05/05 10:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\HandBrake
[2011/05/05 10:40:09 | 000,000,000 | ---D | C] -- C:\Documents and Settings\Dioscuri\Application Data\HandBrake
[2011/05/05 10:39:52 | 000,000,000 | ---D | C] -- C:\Program Files\Handbrake
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/05/23 16:28:00 | 000,000,990 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3983183778-1303381309-3793546208-1021UA.job
[2011/05/23 13:38:05 | 000,206,336 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\dwm.exe
[2011/05/23 13:31:43 | 000,232,669 | ---- | M] () -- C:\WINDOWS\System32\nvModes.001
[2011/05/23 13:31:33 | 000,189,259 | ---- | M] () -- C:\WINDOWS\System32\nvapps.xml
[2011/05/23 13:30:47 | 000,021,282 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\442A.6D6
[2011/05/23 11:38:33 | 000,000,245 | RHS- | M] () -- C:\boot.ini
[2011/05/23 10:03:57 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl
[2011/05/23 10:02:15 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat
[2011/05/23 10:02:11 | 2145,509,376 | -HS- | M] () -- C:\hiberfil.sys
[2011/05/23 09:55:53 | 000,000,241 | ---- | M] () -- C:\WINDOWS\wininit.ini
[2011/05/23 09:08:10 | 000,000,767 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/05/23 00:49:06 | 2145,435,648 | ---- | M] () -- C:\WINDOWS\MEMORY.DMP
[2011/05/22 00:28:00 | 000,000,938 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-3983183778-1303381309-3793546208-1021Core.job
[2011/05/21 21:45:26 | 000,232,669 | ---- | M] () -- C:\WINDOWS\System32\nvModes.dat
[2011/05/21 18:45:22 | 000,000,552 | ---- | M] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/05/21 13:25:24 | 000,002,533 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Word 2007.lnk
[2011/05/21 09:53:01 | 000,000,284 | ---- | M] () -- C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2011/05/19 11:21:28 | 000,002,577 | ---- | M] () -- C:\WINDOWS\System32\CONFIG.NT
[2011/05/16 23:41:16 | 000,026,624 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/15 00:53:05 | 000,442,884 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat
[2011/05/15 00:53:05 | 000,072,296 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat
[2011/05/14 10:28:51 | 000,002,287 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2011/05/14 10:28:50 | 000,002,309 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Desktop\Google Chrome.lnk
[2011/05/11 22:48:04 | 000,000,003 | ---- | M] () -- C:\WINDOWS\System32\SysCalls.dat
[2011/05/09 17:13:51 | 000,941,132 | ---- | M] () -- C:\cc_20110509_1712.reg
[2011/05/07 09:13:44 | 000,000,598 | ---- | M] () -- C:\Documents and Settings\Dioscuri\Application Data\Microsoft\Internet Explorer\Quick Launch\iTunes.lnk
[2011/05/06 01:50:20 | 000,000,664 | ---- | M] () -- C:\WINDOWS\System32\d3d9caps.dat
[6 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\drivers\*.tmp files -> C:\WINDOWS\System32\drivers\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/05/23 13:38:05 | 000,206,336 | ---- | C] () -- C:\Documents and Settings\Dioscuri\Application Data\dwm.exe
[2011/05/23 09:08:10 | 000,000,767 | ---- | C] () -- C:\Documents and Settings\Dioscuri\Start Menu\Programs\Startup\ERUNT AutoBackup.lnk
[2011/05/21 18:47:04 | 2145,509,376 | -HS- | C] () -- C:\hiberfil.sys
[2011/05/21 18:45:22 | 000,000,552 | ---- | C] () -- C:\WINDOWS\System32\d3d8caps.dat
[2011/05/19 19:19:50 | 000,021,282 | ---- | C] () -- C:\Documents and Settings\Dioscuri\Application Data\442A.6D6
[2011/05/09 17:13:18 | 000,941,132 | ---- | C] () -- C:\cc_20110509_1712.reg
[2011/05/06 08:53:59 | 001,660,416 | ---- | C] () -- C:\WINDOWS\PS_MatrixScreensaver.scr
[2011/05/06 01:50:20 | 000,000,664 | ---- | C] () -- C:\WINDOWS\System32\d3d9caps.dat
[2010/10/07 20:34:44 | 000,165,376 | ---- | C] () -- C:\WINDOWS\System32\unrar.dll
[2010/10/07 16:00:14 | 000,041,472 | ---- | C] () -- C:\WINDOWS\FreeAgentGo.dll
[2010/10/07 14:32:05 | 000,026,624 | ---- | C] () -- C:\Documents and Settings\Dioscuri\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/09/30 14:18:23 | 000,069,506 | ---- | C] () -- C:\WINDOWS\hpoins05.dat
[2010/09/30 14:18:23 | 000,019,696 | ---- | C] () -- C:\WINDOWS\hpomdl05.dat
[2010/09/29 11:54:43 | 006,814,952 | ---- | C] () -- C:\WINDOWS\System32\SpoonUninstall.exe
[2010/09/29 09:51:07 | 000,057,320 | -H-- | C] () -- C:\WINDOWS\System32\mlfcache.dat
[2010/09/26 00:22:32 | 000,000,262 | ---- | C] () -- C:\WINDOWS\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2010/05/03 11:02:53 | 000,232,669 | ---- | C] () -- C:\WINDOWS\System32\nvModes.dat
[2009/12/01 09:31:10 | 000,000,000 | ---- | C] () -- C:\WINDOWS\hpmnwun.ini
[2009/08/03 15:07:42 | 000,403,816 | ---- | C] () -- C:\WINDOWS\System32\OGACheckControl.dll
[2009/08/03 15:07:42 | 000,230,768 | ---- | C] () -- C:\WINDOWS\System32\OGAEXEC.exe
[2009/06/25 11:03:38 | 000,078,336 | ---- | C] () -- C:\WINDOWS\System32\DLLEX32.DLL
[2009/06/25 11:03:38 | 000,014,304 | ---- | C] () -- C:\WINDOWS\System32\HLPADDIN.DLL
[2009/06/25 11:03:38 | 000,000,008 | ---- | C] () -- C:\WINDOWS\SV.INI
[2009/06/25 11:00:54 | 000,000,057 | ---- | C] () -- C:\WINDOWS\SABRE.INI
[2008/12/02 17:43:46 | 000,000,228 | ---- | C] () -- C:\WINDOWS\hpbafd.ini
[2008/12/02 15:52:38 | 000,125,678 | ---- | C] () -- C:\WINDOWS\cleanup_remedy.exe
[2008/12/02 15:20:03 | 000,000,376 | ---- | C] () -- C:\WINDOWS\ODBC.INI
[2008/12/02 15:20:03 | 000,000,063 | ---- | C] () -- C:\WINDOWS\mdm.ini
[2008/12/02 15:19:58 | 000,000,000 | ---- | C] () -- C:\WINDOWS\NSREX.INI
[2008/12/02 15:19:00 | 000,120,839 | ---- | C] () -- C:\WINDOWS\cleanup_2ksp3.exe
[2008/11/14 17:38:27 | 000,000,241 | ---- | C] () -- C:\WINDOWS\wininit.ini
[2008/11/14 17:19:27 | 000,000,003 | ---- | C] () -- C:\WINDOWS\System32\SysCalls.dat
[2008/11/14 16:09:46 | 000,129,793 | ---- | C] () -- C:\WINDOWS\LD_Boot.exe
[2008/11/14 16:09:46 | 000,129,739 | ---- | C] () -- C:\WINDOWS\LD_Repair.exe
[2008/10/20 12:57:25 | 000,126,734 | ---- | C] () -- C:\WINDOWS\WSE_FixLDAgent.EXE
[2008/01/31 13:14:08 | 000,000,280 | ---- | C] () -- C:\WINDOWS\System32\epoPGPsdk.dll.sig
[2008/01/31 11:55:05 | 000,125,557 | ---- | C] () -- C:\WINDOWS\cleanup.exe
[2008/01/31 10:07:09 | 000,000,036 | ---- | C] () -- C:\WINDOWS\webica.ini
[2008/01/31 10:04:34 | 000,110,494 | ---- | C] () -- C:\WINDOWS\wzclean.exe
[2008/01/30 12:19:46 | 000,065,619 | ---- | C] () -- C:\WINDOWS\System32\setupw2k.dll
[2008/01/30 12:19:40 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\nwslog32.dll
[2008/01/29 12:31:01 | 000,204,800 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4833.dll
[2008/01/29 12:26:41 | 001,630,208 | ---- | C] () -- C:\WINDOWS\System32\nwiz.exe
[2008/01/29 12:26:39 | 001,019,904 | ---- | C] () -- C:\WINDOWS\System32\nvwimg.dll
[2008/01/29 12:26:38 | 001,703,936 | ---- | C] () -- C:\WINDOWS\System32\nvwdmcpl.dll
[2008/01/29 12:26:32 | 000,466,944 | ---- | C] () -- C:\WINDOWS\System32\nvshell.dll
[2008/01/29 12:26:23 | 001,486,848 | ---- | C] () -- C:\WINDOWS\System32\nview.dll
[2008/01/29 12:26:19 | 001,339,392 | ---- | C] () -- C:\WINDOWS\System32\nvdspsch.exe
[2008/01/29 12:25:56 | 000,442,368 | ---- | C] () -- C:\WINDOWS\System32\nvappbar.exe
[2008/01/29 12:25:49 | 000,425,984 | ---- | C] () -- C:\WINDOWS\System32\keystone.exe
[2005/11/18 11:47:26 | 000,000,000 | ---- | C] () -- C:\WINDOWS\System32\px.ini
[2005/05/01 10:12:27 | 000,000,061 | ---- | C] () -- C:\WINDOWS\smscfg.ini
[2005/05/01 09:45:03 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat
[2005/05/01 09:37:38 | 000,021,640 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat
[2005/05/01 04:19:06 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI
[2005/05/01 04:17:56 | 004,737,192 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT
[2005/01/21 13:02:28 | 000,013,312 | ---- | C] () -- C:\WINDOWS\System32\RMDevice.dll
[2004/08/04 05:00:00 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin
[2004/08/04 05:00:00 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat
[2004/08/04 05:00:00 | 000,442,884 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat
[2004/08/04 05:00:00 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat
[2004/08/04 05:00:00 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat
[2004/08/04 05:00:00 | 000,072,296 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat
[2004/08/04 05:00:00 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin
[2004/08/04 05:00:00 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat
[2004/08/04 05:00:00 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat
[2004/08/04 05:00:00 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat
[2004/08/04 05:00:00 | 000,001,804 | ---- | C] () -- C:\WINDOWS\System32\dcache.bin
[2004/08/04 05:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat
[2002/02/27 10:41:28 | 000,024,576 | ---- | C] () -- C:\WINDOWS\System32\nsldappr32v50.dll
[2002/02/27 10:41:26 | 000,139,264 | ---- | C] () -- C:\WINDOWS\System32\nsldap32v50.dll
[2002/02/27 10:41:26 | 000,040,960 | ---- | C] () -- C:\WINDOWS\System32\nsldapssl32v50.dll
[2001/07/30 20:17:12 | 000,094,274 | ---- | C] () -- C:\WINDOWS\System32\HPBHEALR.DLL
========== LOP Check ==========
[2008/12/12 11:04:38 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Applications
[2009/03/13 15:59:55 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AR System
[2011/05/19 11:21:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVAST Software
[2011/04/18 14:36:13 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\AVG10
[2010/01/29 09:41:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\BigFix
[2011/04/22 09:38:34 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Citrix
[2011/04/18 10:51:19 | 000,000,000 | -H-D | M] -- C:\Documents and Settings\All Users\Application Data\Common Files
[2010/10/19 11:53:42 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\DAEMON Tools Lite
[2009/06/02 13:25:30 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Juniper Networks
[2011/04/18 12:55:16 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\MFAData
[2008/12/04 16:34:47 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Seagate
[2010/02/18 15:33:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\vulScan
[2011/04/13 11:14:07 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\Wave Systems Corp
[2011/05/18 11:04:28 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\WindSolutions
[2010/09/23 14:43:56 | 000,000,000 | ---D | M] -- C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2011/05/06 11:24:59 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\AnvSoft
[2011/04/12 23:12:45 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\AR System
[2011/04/18 11:01:53 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\AVG10
[2011/04/14 13:11:22 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\DAEMON Tools Lite
[2010/09/29 12:22:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\dBpoweramp
[2011/05/05 10:49:32 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\HandBrake
[2008/01/31 10:07:09 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\ICAClient
[2011/04/12 22:59:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Juniper Networks
[2011/05/19 19:20:33 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Kernel Recovery for iPod(Demo)
[2010/11/10 00:49:52 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Mumble
[2011/05/09 13:13:26 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Red Kawa
[2010/09/27 00:11:15 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\SystemRequirementsLab
[2011/04/22 12:13:58 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Unity
[2011/05/21 16:30:24 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\uTorrent
[2011/04/13 11:11:51 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Wave Systems Corp
[2011/04/12 23:07:19 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\Webex
[2011/05/18 11:04:46 | 000,000,000 | ---D | M] -- C:\Documents and Settings\Dioscuri\Application Data\WindSolutions
========== Purity Check ==========
< End of report >