While web surfing my browser will suddenly stop, saying it's waiting for response from site. This happens with either IE or Firefox although more likely with IE. After this happens I have to reboot before I can get to any website again, and it takes a long time to log off. Also with IE when clicking on a link sometimes it will jump to some bogus "your computer is infected" site trying to look like a legitimate malware scan.
My log files:
Malwarebytes' Anti-Malware 1.41
Database version: 2804
Windows 6.0.6002 Service Pack 2
9/15/2009 7:51:46 PM
mbam-log-2009-09-15 (19-51-46).txt
Scan type: Quick Scan
Objects scanned: 80407
Time elapsed: 2 minute(s), 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
Rooter.exe (v1.0.2) by Eric_71
.
SeDebugPrivilege granted successfully ...
.
Windows Vista Home Edition (6.0.6002) Service Pack 2
[32_bits] - x86 Family 6 Model 15 Stepping 13, GenuineIntel
.
[wscsvc] (Security Center) RUNNING (state:4)
[MpsSvc] RUNNING (state:4)
Windows Firewall -> Disabled !
Windows Defender -> Enabled
User Account Control (UAC) -> Enabled
.
Internet Explorer 8.0.6001.18813
Mozilla Firefox 3.5.3 (en-US)
.
C:\ [Fixed-NTFS] .. ( Total:51 Go - Free:30 Go )
D:\ [Fixed-NTFS] .. ( Total:50 Go - Free:49 Go )
E:\ [CD_Rom]
.
Scan : 20:39.39
Path : C:\Users\Pat\Desktop\Rooter.exe
User : Pat ( Administrator -> YES )
.
----------------------\\ Processes
.
Locked [System Process] (0)
Locked System (4)
______ \SystemRoot\System32\smss.exe (456)
______ C:\Windows\system32\csrss.exe (588)
______ C:\Windows\system32\wininit.exe (632)
______ C:\Windows\system32\csrss.exe (640)
______ C:\Windows\system32\services.exe (676)
______ C:\Windows\system32\lsass.exe (688)
______ C:\Windows\system32\lsm.exe (700)
______ C:\Windows\system32\winlogon.exe (780)
______ C:\Windows\system32\svchost.exe (872)
______ C:\Windows\system32\svchost.exe (952)
______ C:\Windows\System32\svchost.exe (988)
______ C:\Windows\System32\svchost.exe (1044)
______ C:\Windows\System32\svchost.exe (1076)
______ C:\Windows\system32\svchost.exe (1116)
Locked audiodg.exe (1184)
______ C:\Windows\system32\svchost.exe (1204)
______ C:\Windows\system32\SLsvc.exe (1220)
______ C:\Windows\system32\svchost.exe (1256)
______ C:\Windows\system32\svchost.exe (1476)
Locked vsmon.exe (1572)
______ C:\Windows\system32\WLANExt.exe (1832)
______ D:\Program Files\Avast\aswUpdSv.exe (1980)
______ D:\Program Files\Avast\ashServ.exe (2000)
______ C:\Windows\System32\spoolsv.exe (936)
______ C:\Windows\system32\taskeng.exe (1176)
______ C:\Windows\system32\svchost.exe (1212)
______ C:\Windows\system32\taskeng.exe (1752)
______ C:\Windows\system32\agrsmsvc.exe (2168)
______ C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe (2184)
______ C:\Acer\Empowering Technology\eNet\eNet Service.exe (2292)
______ C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe (2360)
______ C:\Program Files\Common Files\LightScribe\LSSrvc.exe (2400)
______ C:\Windows\system32\lxdccoms.exe (2428)
______ C:\Acer\Mobility Center\MobilityService.exe (2448)
______ C:\Windows\system32\svchost.exe (2488)
______ C:\Program Files\CyberLink\Shared Files\RichVideo.exe (2540)
______ C:\Windows\System32\svchost.exe (2652)
______ C:\Windows\system32\SearchIndexer.exe (2684)
______ C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe (2732)
______ C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe (2796)
______ C:\Acer\Empowering Technology\ePower\ePowerSvc.exe (2840)
______ C:\Windows\system32\wbem\wmiprvse.exe (2976)
______ C:\Windows\system32\wbem\unsecapp.exe (3040)
______ D:\Program Files\Avast\ashMaiSv.exe (3208)
______ D:\Program Files\Avast\ashWebSv.exe (3240)
______ C:\Windows\system32\wbem\wmiprvse.exe (3268)
______ C:\Windows\system32\Dwm.exe (3556)
______ C:\Windows\Explorer.EXE (3616)
______ C:\Program Files\Windows Defender\MSASCui.exe (3700)
______ C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (3712)
______ C:\Windows\RtHDVCpl.exe (3748)
______ C:\Program Files\Synaptics\SynTP\SynTPStart.exe (3820)
______ C:\Acer\Empowering Technology\eAudio\eAudio.exe (3848)
______ C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (3868)
______ C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (2076)
______ C:\Program Files\Launch Manager\QtZgAcer.EXE (836)
______ C:\Windows\System32\igfxtray.exe (2304)
______ C:\Windows\System32\hkcmd.exe (2484)
______ C:\Windows\System32\igfxpers.exe (2632)
Locked zlclient.exe (2032)
______ D:\Program Files\Avast\ashDisp.exe (2828)
______ C:\Program Files\Windows Sidebar\sidebar.exe (900)
______ C:\Users\Pat\AppData\Local\Temp\RtkBtMnt.exe (2088)
______ C:\Windows\system32\igfxsrvc.exe (1384)
______ C:\Windows\system32\igfxext.exe (2096)
______ C:\Windows\system32\igfxsrvc.exe (3692)
______ D:\Program Files\Firefox\firefox.exe (5724)
______ C:\Windows\system32\NOTEPAD.EXE (4252)
______ C:\Windows\system32\DllHost.exe (3548)
______ C:\Windows\system32\DllHost.exe (2992)
______ C:\Users\Pat\Desktop\Rooter.exe (2604)
.
----------------------\\ Device\Harddisk0\
.
\Device\Harddisk0 [Sectors : 63 x 512 Bytes]
.
\Device\Harddisk0\Partition1 (Start_Offset:32256 | Length:10478974464)
\Device\Harddisk0\Partition2 --[ MBR ]-- (Start_Offset:10479468544 | Length:54914973696)
\Device\Harddisk0\Partition3 (Start_Offset:65394442240 | Length:54638149632)
.
----------------------\\ Scheduled Tasks
.
C:\Windows\Tasks\SA.DAT
C:\Windows\Tasks\SCHEDLGU.TXT
C:\Windows\Tasks\User_Feed_Synchronization-{417481A6-3546-42E2-8E2B-2320C2089556}.job
.
----------------------\\ Registry
.
.
----------------------\\ Files & Folders
.
----------------------\\ Scan completed at 20:39.40
.
C:\Rooter$\Rooter_4.txt - (15/09/2009 | 20:39.40)
ROOTREPEAL © AD, 2007-2009
==================================================
Scan Start Time: 2009/09/15 20:41
Program Version: Version 1.3.5.0
Windows Version: Windows Vista SP2
==================================================
Drivers
-------------------
Name: dump_atapi.sys
Image Path: C:\Windows\System32\Drivers\dump_atapi.sys
Address: 0x87FCF000 Size: 32768 File Visible: No Signed: -
Status: -
Name: dump_dumpata.sys
Image Path: C:\Windows\System32\Drivers\dump_dumpata.sys
Address: 0x8C800000 Size: 45056 File Visible: No Signed: -
Status: -
Name: rootrepeal.sys
Image Path: C:\Windows\system32\drivers\rootrepeal.sys
Address: 0xA971D000 Size: 49152 File Visible: No Signed: -
Status: -
Processes
-------------------
Path: System
PID: 4 Status: Locked to the Windows API!
Path: C:\Windows\System32\audiodg.exe
PID: 1184 Status: Locked to the Windows API!
SSDT
-------------------
#: 021 Function Name: NtAlpcConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f9880
#: 054 Function Name: NtConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f94e0
#: 060 Function Name: NtCreateFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f6828
#: 064 Function Name: NtCreateKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90cd9c
#: 071 Function Name: NtCreatePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f9c36
#: 072 Function Name: NtCreateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90aaf8
#: 073 Function Name: NtCreateProcessEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90ad12
#: 075 Function Name: NtCreateSection
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90e780
#: 115 Function Name: NtCreateWaitablePort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f9cde
#: 122 Function Name: NtDeleteFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f6d0a
#: 123 Function Name: NtDeleteKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90d698
#: 126 Function Name: NtDeleteValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90d414
#: 129 Function Name: NtDuplicateObject
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90a4f8
#: 166 Function Name: NtLoadKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90dbc6
#: 167 Function Name: NtLoadKey2
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90dc3e
#: 168 Function Name: NtLoadKeyEx
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90dd2e
#: 186 Function Name: NtOpenFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f6ba2
#: 194 Function Name: NtOpenProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90bf18
#: 267 Function Name: NtRenameKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90e370
#: 268 Function Name: NtReplaceKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90dda6
#: 276 Function Name: NtRequestWaitReplyPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f916a
#: 280 Function Name: NtRestoreKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90e1b0
#: 286 Function Name: NtSecureConnectPort
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f9680
#: 301 Function Name: NtSetInformationFile
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c8f6ef8
#: 324 Function Name: NtSetValueKey
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90d11a
#: 332 Function Name: NtSystemDebugControl
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90b486
#: 334 Function Name: NtTerminateProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90b362
#: 383 Function Name: NtCreateUserProcess
Status: Hooked by "C:\Windows\system32\DRIVERS\vsdatant.sys" at address 0x8c90af30
==EOF==
OTL logfile created on: 9/15/2009 8:43:07 PM - Run 2
OTL by OldTimer - Version 3.0.14.0 Folder = C:\Users\Pat\Desktop
Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18813)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1.99 Gb Total Physical Memory | 1.09 Gb Available Physical Memory | 54.56% Memory free
4.00 Gb Paging File | 3.02 Gb Available in Paging File | 75.46% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 51.14 Gb Total Space | 30.45 Gb Free Space | 59.53% Space Free | Partition Type: NTFS
Drive D: | 50.89 Gb Total Space | 49.46 Gb Free Space | 97.20% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: PAT-PC
Current User Name: Pat
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe
PRC - [2009/08/17 10:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\aswUpdSv.exe
PRC - [2009/08/17 11:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashServ.exe
PRC - [2006/10/05 14:10:12 | 00,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe
PRC - [2007/10/01 18:42:36 | 00,024,576 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
PRC - [2007/12/20 13:32:04 | 00,131,072 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe
PRC - [2007/10/03 17:45:02 | 00,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
PRC - [2007/01/17 13:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe
PRC - [2007/05/25 09:38:20 | 00,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxdccoms.exe
PRC - [2007/11/27 20:54:36 | 00,110,592 | ---- | M] () -- C:\Acer\Mobility Center\MobilityService.exe
PRC - [2007/12/04 13:58:12 | 00,266,343 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe
PRC - [2007/09/10 15:28:18 | 00,057,344 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe
PRC - [2007/12/19 20:09:22 | 00,024,576 | ---- | M] () -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe
PRC - [2007/09/20 15:57:28 | 00,167,936 | ---- | M] (acer) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe
PRC - [2009/04/11 01:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/04/11 01:28:08 | 00,037,888 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\unsecapp.exe
PRC - [2009/08/17 11:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashMaiSv.exe
PRC - [2009/08/17 11:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashWebSv.exe
PRC - [2009/04/11 01:28:15 | 00,247,296 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wbem\wmiprvse.exe
PRC - [2009/04/11 01:27:36 | 02,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\Explorer.EXE
PRC - [2008/01/20 21:23:32 | 01,008,184 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\MSASCui.exe
PRC - [2007/10/03 17:44:58 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2007/05/28 03:29:00 | 04,472,832 | ---- | M] (Realtek Semiconductor) -- C:\Windows\RtHDVCpl.exe
PRC - [2007/11/29 22:47:22 | 00,102,400 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPStart.exe
PRC - [2007/10/10 08:41:54 | 01,286,144 | ---- | M] (CyberLink) -- C:\Acer\Empowering Technology\eAudio\eAudio.exe
PRC - [2008/01/22 11:14:24 | 00,200,704 | ---- | M] (CyberLink Corp.) -- C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe
PRC - [2007/11/29 22:47:22 | 01,021,224 | ---- | M] (Synaptics, Inc.) -- C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
PRC - [2008/01/02 08:17:28 | 00,707,080 | ---- | M] (Dritek System Inc.) -- C:\Program Files\Launch Manager\QtZgAcer.EXE
PRC - [2008/12/23 11:02:54 | 00,150,040 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxtray.exe
PRC - [2008/12/23 11:02:22 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\hkcmd.exe
PRC - [2008/12/23 11:02:50 | 00,154,136 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxpers.exe
PRC - [2009/02/16 00:10:22 | 00,981,384 | ---- | M] (Check Point Software Technologies LTD) -- D:\Program Files\ZoneAlarm\zlclient.exe
PRC - [2009/08/17 11:07:23 | 00,081,000 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashDisp.exe
PRC - [2009/04/11 01:28:03 | 01,233,920 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Sidebar\sidebar.exe
PRC - [2009/09/15 19:44:50 | 00,208,896 | ---- | M] (Realtek Semiconductor Corp.) -- C:\Users\Pat\AppData\Local\Temp\RtkBtMnt.exe
PRC - [2008/12/23 11:02:52 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2008/12/23 11:02:40 | 00,178,712 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxext.exe
PRC - [2008/12/23 11:02:52 | 00,256,536 | ---- | M] (Intel Corporation) -- C:\Windows\System32\igfxsrvc.exe
PRC - [2009/08/24 15:15:03 | 00,908,280 | ---- | M] (Mozilla Corporation) -- D:\Program Files\Firefox\firefox.exe
PRC - [2009/09/15 13:16:20 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Users\Pat\Desktop\OTL.exe
========== Win32 Services (SafeList) ==========
SRV - [2006/10/05 14:10:12 | 00,009,216 | ---- | M] (Agere Systems) -- C:\Windows\System32\agrsmsvc.exe -- (AgereModemAudio [Auto | Running])
SRV - [2009/08/17 10:58:55 | 00,018,752 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\aswUpdSv.exe -- (aswUpdSv [Auto | Running])
SRV - [2009/08/17 11:07:17 | 00,138,680 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashServ.exe -- (avast! Antivirus [Auto | Running])
SRV - [2009/08/17 11:07:01 | 00,254,040 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashMaiSv.exe -- (avast! Mail Scanner [On_Demand | Running])
SRV - [2009/08/17 11:04:21 | 00,352,920 | ---- | M] (ALWIL Software) -- D:\Program Files\Avast\ashWebSv.exe -- (avast! Web Scanner [On_Demand | Running])
SRV - [2009/03/29 23:42:14 | 00,066,368 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped])
SRV - [2008/01/20 21:25:09 | 00,292,352 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehRecvr.exe -- (ehRecvr [On_Demand | Stopped])
SRV - [2006/11/02 07:35:29 | 00,131,072 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehsched.exe -- (ehSched [On_Demand | Stopped])
SRV - [2006/11/02 07:35:29 | 00,013,312 | ---- | M] (Microsoft Corporation) -- C:\Windows\ehome\ehstart.dll -- (ehstart [Auto | Stopped])
SRV - [2007/10/01 18:42:36 | 00,024,576 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe -- (eLockService [Auto | Running])
SRV - [2007/12/20 13:32:04 | 00,131,072 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eNet\eNet Service.exe -- (eNet Service [Auto | Running])
SRV - [2007/09/10 15:28:18 | 00,057,344 | ---- | M] (Acer Inc.) -- C:\Acer\Empowering Technology\eRecovery\eRecoveryService.exe -- (eRecoveryService [Auto | Running])
SRV - [2007/12/19 20:09:22 | 00,024,576 | ---- | M] () -- C:\Acer\Empowering Technology\eSettings\Service\capuserv.exe -- (eSettingsService [Auto | Running])
SRV - [2009/04/11 01:28:25 | 01,017,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\wevtsvc.dll -- (Eventlog [Auto | Running])
SRV - [2009/02/18 13:39:20 | 00,043,904 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe -- (FontCache3.0.0.0 [On_Demand | Stopped])
SRV - [2007/10/03 17:45:02 | 00,358,936 | ---- | M] (Intel Corporation) -- C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe -- (IAANTMON [Auto | Running])
SRV - [2009/02/18 13:38:42 | 00,879,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe -- (idsvc [Unknown | Stopped])
SRV - [2007/01/17 13:20:10 | 00,061,440 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\Common Files\LightScribe\LSSrvc.exe -- (LightScribeService [Auto | Running])
SRV - [2007/05/25 09:38:20 | 00,537,520 | ---- | M] ( ) -- C:\Windows\System32\lxdccoms.exe -- (lxdc_device [Auto | Running])
SRV - [2007/11/27 20:54:36 | 00,110,592 | ---- | M] () -- C:\Acer\Mobility Center\MobilityService.exe -- (MobilityService [Auto | Running])
SRV - [2009/02/18 13:38:43 | 00,129,880 | ---- | M] (Microsoft Corporation) -- C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe -- (NetTcpPortSharing [Disabled | Stopped])
SRV - [2007/12/04 13:58:12 | 00,266,343 | ---- | M] () -- C:\Program Files\CyberLink\Shared Files\RichVideo.exe -- (RichVideo [Auto | Running])
SRV - [2009/02/16 00:10:22 | 02,402,184 | ---- | M] (Check Point Software Technologies LTD) -- C:\Windows\System32\ZoneLabs\vsmon.exe -- (vsmon [Auto | Running])
SRV - [2008/01/20 21:23:32 | 00,272,952 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Defender\mpsvc.dll -- (WinDefend [Auto | Running])
SRV - [2007/09/20 15:57:28 | 00,167,936 | ---- | M] (acer) -- C:\Acer\Empowering Technology\ePower\ePowerSvc.exe -- (WMIService [Auto | Running])
SRV - [2008/01/20 21:25:33 | 00,896,512 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Windows Media Player\wmpnetwk.exe -- (WMPNetworkSvc [On_Demand | Stopped])
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Extensions Off Page = about:NoAdd-ons
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\System32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Security Risk Page = about:SecurityRisk
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://drudgereport.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://drudgereport.com/"
FF - prefs.js..extensions.enabledItems: {20a82645-c095-46ed-80e3-08825760534b}:1.1
FF - prefs.js..extensions.enabledItems: {972ce4c6-7e08-4474-a285-3208198ce6fd}:3.5.3
FF - HKLM\software\mozilla\Firefox\Extensions\\{20a82645-c095-46ed-80e3-08825760534b}: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ [2009/09/08 03:01:31 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Components: D:\Program Files\Firefox\components [2009/09/15 11:17:56 | 00,000,000 | ---D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.3\extensions\\Plugins: D:\Program Files\Firefox\plugins [2009/09/15 11:17:44 | 00,000,000 | ---D | M]
[2009/09/15 11:18:06 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\mozilla\Extensions
[2009/09/15 11:18:06 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
[2009/09/15 11:42:55 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\mozilla\Firefox\Profiles\y11hos43.default\extensions
[2009/09/15 11:42:55 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\mozilla\Firefox\Profiles\y11hos43.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
O1 HOSTS File: (761 bytes) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (&Yahoo! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\ShellBrowser: (no name) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - No CLSID value found.
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] D:\Program Files\Avast\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [eAudio] C:\Acer\Empowering Technology\eAudio\eAudio.exe (CyberLink)
O4 - HKLM..\Run: [eRecoveryService] File not found
O4 - HKLM..\Run: [HotKeysCmds] C:\Windows\System32\hkcmd.exe (Intel Corporation)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IgfxTray] C:\Windows\System32\igfxtray.exe (Intel Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\QtZgAcer.EXE (Dritek System Inc.)
O4 - HKLM..\Run: [Persistence] C:\Windows\System32\igfxpers.exe (Intel Corporation)
O4 - HKLM..\Run: [PlayMovie] C:\Program Files\Acer Arcade Deluxe\Play Movie\PMVService.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Skytel] C:\Windows\Skytel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe (Synaptics, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [ZoneAlarm Client] D:\Program Files\ZoneAlarm\zlclient.exe (Check Point Software Technologies LTD)
O4 - HKCU..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: BindDirectlyToPropertySetStorage = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableInstallerDetection = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableSecureUIAPaths = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableVirtualization = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ValidateAdminCodeSignatures = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: scforceoption = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: FilterAdministratorToken = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableUIADesktopToggle = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_TEXT = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_BITMAP = 2
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_OEMTEXT = 7
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIB = 8
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_PALETTE = 9
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_UNICODETEXT = 13
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\UIPI\Clipboard\ExceptionFormats: CF_DIBV5 = 17
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableTaskmgr = 0
O10 - NameSpace_Catalog5\Catalog_Entries\000000000001 [] - C:\Windows\System32\NLAapi.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000002 [] - C:\Windows\System32\napinsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000003 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Windows\System32\pnrpnsp.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 68.238.0.12
O18 - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\Windows\System32\igfxdev.dll (Intel Corporation)
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 00,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\Windows\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
NetSvcs: FastUserSwitchingCompatibility - Service key not found. File not found
NetSvcs: Ias - Service key not found. File not found
NetSvcs: Irmon - Service key not found. File not found
NetSvcs: Nla - Service key not found. File not found
NetSvcs: Ntmssvc - Service key not found. File not found
NetSvcs: NWCWorkstation - Service key not found. File not found
NetSvcs: Nwsapagent - Service key not found. File not found
NetSvcs: SRService - Service key not found. File not found
NetSvcs: Wmi - Service key not found. File not found
NetSvcs: WmdmPmSp - Service key not found. File not found
NetSvcs: LogonHours - Service key not found. File not found
NetSvcs: PCAudit - Service key not found. File not found
NetSvcs: helpsvc - Service key not found. File not found
NetSvcs: uploadmgr - Service key not found. File not found
========== Files/Folders - Created Within 14 Days ==========
[2009/09/15 19:33:25 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Seven Zip
[2009/09/15 13:16:18 | 00,514,560 | ---- | C] (OldTimer Tools) -- C:\Users\Pat\Desktop\OTL.exe
[2009/09/15 13:13:23 | 00,000,000 | ---- | C] () -- C:\Users\Pat\Desktop\settings.dat
[2009/09/15 13:09:35 | 00,000,000 | ---D | C] -- C:\Rooter$
[2009/09/15 13:08:24 | 00,173,119 | ---- | C] (Eric_71) -- C:\Users\Pat\Desktop\Rooter.exe
[2009/09/15 12:30:03 | 00,000,000 | ---D | C] -- C:\Windows\pss
[2009/09/15 12:21:23 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Malwarebytes
[2009/09/15 12:21:20 | 00,000,620 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/15 12:21:17 | 00,038,224 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/09/15 12:21:16 | 00,019,160 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/09/15 12:21:16 | 00,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2009/09/15 12:13:37 | 00,271,872 | ---- | C] (OldTimer Tools) -- C:\Users\Pat\Desktop\TFC.exe
[2009/09/15 12:12:32 | 00,000,000 | ---D | C] -- C:\Windows\ERDNT
[2009/09/15 12:12:12 | 00,000,737 | ---- | C] () -- C:\Users\Pat\Desktop\NTREGOPT.lnk
[2009/09/15 12:12:12 | 00,000,718 | ---- | C] () -- C:\Users\Pat\Desktop\ERUNT.lnk
[2009/09/15 12:12:12 | 00,000,000 | ---D | C] -- C:\Program Files\ERUNT
[2009/09/15 12:08:48 | 00,794,112 | ---- | C] () -- C:\Users\Pat\Desktop\The_Comedian.exe
[2009/09/15 11:48:40 | 00,000,712 | ---- | C] () -- C:\Users\Pat\Desktop\CCleaner.lnk
[2009/09/15 11:17:49 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Mozilla
[2009/09/15 11:17:49 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Mozilla
[2009/09/15 11:17:47 | 00,000,696 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/09/13 19:34:22 | 00,000,000 | ---D | C] -- C:\Windows\System32\eu-ES
[2009/09/13 19:34:22 | 00,000,000 | ---D | C] -- C:\Windows\System32\ca-ES
[2009/09/13 19:34:21 | 00,000,000 | ---D | C] -- C:\Windows\System32\vi-VN
[2009/09/13 19:22:03 | 00,000,000 | ---D | C] -- C:\Windows\System32\EventProviders
[2009/09/13 19:11:59 | 00,023,152 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswRdr.sys
[2009/09/13 19:11:59 | 00,000,687 | ---- | C] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/09/13 19:11:58 | 00,051,376 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswTdi.sys
[2009/09/13 19:11:57 | 00,097,480 | ---- | C] (ALWIL Software) -- C:\Windows\System32\AvastSS.scr
[2009/09/13 19:11:56 | 00,114,768 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswSP.sys
[2009/09/13 19:11:56 | 00,020,560 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswFsBlk.sys
[2009/09/13 19:11:41 | 00,053,328 | ---- | C] (ALWIL Software) -- C:\Windows\System32\drivers\aswMonFlt.sys
[2009/09/13 19:11:33 | 01,279,456 | ---- | C] (ALWIL Software) -- C:\Windows\System32\aswBoot.exe
[2009/09/13 19:11:33 | 00,380,928 | ---- | C] () -- C:\Windows\System32\actskin4.ocx
[2009/09/13 19:06:34 | 00,000,000 | ---D | C] -- C:\ProgramData\Lavasoft
[2009/09/13 18:46:06 | 00,006,080 | ---- | C] () -- C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/09/13 18:26:44 | 00,350,192 | -H-- | C] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/09/13 18:26:44 | 00,000,000 | ---D | C] -- C:\Windows\System32\ZoneLabs
[2009/09/13 18:25:17 | 00,000,000 | ---D | C] -- C:\ProgramData\CheckPoint
[2009/09/13 18:24:59 | 00,000,000 | ---D | C] -- C:\Windows\Internet Logs
[2009/09/12 20:45:46 | 01,676,869 | ---- | C] () -- D:\Documents\IL444-2378B.pdf
[2009/09/10 16:17:42 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Yahoo
[2009/09/10 03:29:32 | 00,130,008 | ---- | C] () -- C:\Windows\System32\systemsf.ebd
[2009/09/10 03:29:27 | 00,009,239 | ---- | C] () -- C:\Windows\System32\spcinstrumentation.man
[2009/09/10 03:29:07 | 00,442,788 | ---- | C] () -- C:\Windows\System32\dot3.tmf
[2009/09/10 03:29:03 | 00,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2009/09/10 03:29:02 | 00,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2009/09/10 03:28:58 | 03,662,128 | ---- | C] () -- C:\Windows\System32\locale.nls
[2009/09/10 03:28:57 | 00,392,170 | ---- | C] () -- C:\Windows\System32\onex.tmf
[2009/09/10 03:28:47 | 00,344,698 | ---- | C] () -- C:\Windows\System32\eaphost.tmf
[2009/09/10 03:28:17 | 00,208,966 | ---- | C] () -- C:\Windows\System32\WFP.TMF
[2009/09/10 03:28:12 | 00,092,918 | ---- | C] () -- C:\Windows\System32\slmgr.vbs
[2009/09/10 03:26:25 | 00,009,212 | ---- | C] () -- C:\Windows\System32\RacUR.xml
[2009/09/10 03:26:05 | 00,000,153 | ---- | C] () -- C:\Windows\System32\RacUREx.xml
[2009/09/09 18:34:33 | 00,000,754 | ---- | C] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2009/09/09 18:34:22 | 00,000,000 | ---D | C] -- C:\ProgramData\Yahoo!
[2009/09/09 15:31:56 | 00,001,891 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/09/09 15:31:40 | 00,000,000 | ---D | C] -- C:\Program Files\Adobe
[2009/09/09 15:20:32 | 00,000,000 | ---D | C] -- C:\Program Files\lx_Cats
[2009/09/09 13:57:31 | 00,000,000 | ---D | C] -- C:\logs
[2009/09/09 13:45:02 | 00,000,000 | ---D | C] -- C:\drivers
[2009/09/09 10:36:00 | 02,501,921 | ---- | C] () -- C:\Windows\System32\wlan.tmf
[2009/09/08 20:33:17 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Adobe
[2009/09/06 18:37:16 | 00,000,418 | -H-- | C] () -- C:\Windows\tasks\User_Feed_Synchronization-{417481A6-3546-42E2-8E2B-2320C2089556}.job
[2009/09/06 17:01:57 | 00,057,667 | ---- | C] () -- C:\Windows\System32\ieuinit.inf
[2009/09/06 15:24:02 | 00,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2009/09/06 15:23:44 | 11,967,524 | ---- | C] () -- C:\Windows\System32\korwbrkr.lex
[2009/09/06 15:22:18 | 00,000,003 | ---- | C] () -- C:\Windows\AFirst.cmd
[2009/09/06 15:22:17 | 17,730,504 | ---- | C] (Acer Incorporated) -- C:\Windows\eRy.exe
[2009/09/06 15:22:12 | 00,000,030 | ---- | C] () -- C:\Windows\SETPANEL.INI
[2009/09/06 15:22:11 | 00,004,398 | ---- | C] () -- C:\Windows\CLEANUP.CMD
[2009/09/06 15:22:11 | 00,000,294 | ---- | C] () -- C:\Windows\offline.reg
[2009/09/06 15:22:11 | 00,000,155 | ---- | C] () -- C:\Windows\IR.reg
[2009/09/06 15:22:11 | 00,000,092 | ---- | C] () -- C:\Windows\CLEANUP.INI
[2009/09/06 15:22:11 | 00,000,023 | ---- | C] () -- C:\Windows\System32\$Acer$.cmd
[2009/09/06 14:35:58 | 21,374,48448 | -HS- | C] () -- C:\hiberfil.sys
[2009/09/06 14:34:15 | 00,000,000 | ---D | C] -- C:\Windows\System32\Lang
[2009/09/06 14:33:09 | 00,613,940 | ---- | C] () -- C:\Windows\System32\oem16.inf
[2009/09/06 14:32:58 | 00,000,000 | ---D | C] -- C:\Windows\SoftwareDistribution
[2009/09/06 14:25:08 | 00,000,000 | ---D | C] -- C:\Program Files\MSXML 4.0
[2009/09/06 14:12:19 | 00,026,087 | ---- | C] () -- D:\Documents\FixMyAcer.htm
[2009/09/06 12:58:08 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Adobe
[2009/09/06 12:54:27 | 00,000,000 | ---D | C] -- C:\Program Files\Vic512WA
[2009/09/06 12:54:21 | 00,000,092 | ---- | C] () -- C:\Windows\GridV.UNI
[2009/09/06 12:53:41 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Leadertech
[2009/09/06 12:53:41 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Acer
[2009/09/06 12:53:30 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\PlayMovie
[2009/09/06 12:51:18 | 02,302,445 | -H-- | C] () -- C:\Users\Pat\AppData\Local\IconCache.db
[2009/09/06 12:49:45 | 00,327,680 | ---- | C] (Acer Inc.) -- C:\Windows\System32\Remove_eRecovery.exe
[2009/09/06 12:49:45 | 00,000,552 | ---- | C] () -- C:\Windows\System32\setup.iss
[2009/09/06 12:49:44 | 00,368,640 | ---- | C] (Acer Inc.) -- C:\Windows\System32\CheckD2DSystem.exe
[2009/09/06 12:49:44 | 00,016,384 | ---- | C] () -- C:\Windows\System32\LauncheRyAgentUser.exe
[2009/09/06 12:49:44 | 00,016,384 | ---- | C] ( ) -- C:\Windows\System32\ClearEvent.exe
[2009/09/06 12:49:16 | 00,000,000 | ---D | C] -- C:\Program Files\Acer
[2009/09/06 12:48:21 | 00,000,083 | ---- | C] () -- C:\Windows\QtZgAcer.UNI
[2009/09/06 12:48:19 | 00,000,000 | ---D | C] -- C:\Program Files\Launch Manager
[2009/09/06 12:48:04 | 00,040,960 | ---- | C] (Sysinternals - www.sysinternals.com) -- C:\junction.exe
[2009/09/06 12:45:45 | 00,050,752 | ---- | C] (Agere Systems) -- C:\Windows\System32\agrsmdel.exe
[2009/09/06 12:45:04 | 00,000,000 | ---D | C] -- C:\Windows\Options
[2009/09/06 12:44:26 | 00,000,000 | -H-D | C] -- C:\Users\Pat\AppData\Local\acer eNM
[2009/09/06 12:44:03 | 00,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2009/09/06 12:44:00 | 00,069,272 | ---- | C] () -- C:\Users\Pat\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/09/06 12:43:40 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Identities
[2009/09/06 12:43:11 | 83,554,304 | ---- | C] () -- C:\Windows\System32\acer.scr
[2009/09/06 12:43:11 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Macromedia
[2009/09/06 12:43:03 | 00,000,000 | ---D | C] -- C:\Program Files\Acer Inc
[2009/09/06 12:43:01 | 00,000,000 | ---D | C] -- C:\Windows\ACER
[2009/09/06 12:42:25 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\VirtualStore
[2009/09/06 12:42:18 | 00,016,070 | ---- | C] () -- C:\Windows\System32\results.xml
[2009/09/06 12:41:54 | 00,000,000 | -HSD | C] -- C:\Users\Pat\AppData\Local\Temporary Internet Files
[2009/09/06 12:41:54 | 00,000,000 | -HSD | C] -- C:\Users\Pat\AppData\Local\History
[2009/09/06 12:41:54 | 00,000,000 | -HSD | C] -- C:\Users\Pat\AppData\Local\Application Data
[2009/09/06 12:41:53 | 00,000,000 | --SD | C] -- C:\Users\Pat\AppData\Roaming\Microsoft
[2009/09/06 12:41:53 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Media Center Programs
[2009/09/06 12:41:53 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Roaming\Acer GameZone Console
[2009/09/06 12:41:53 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Temp
[2009/09/06 12:41:53 | 00,000,000 | ---D | C] -- C:\Users\Pat\AppData\Local\Microsoft
[2009/09/06 12:08:52 | 00,007,078 | ---- | C] () -- D:\Documents\bookmark.htm
[2009/09/01 22:13:14 | 00,000,000 | ---D | C] -- D:\Documents\Legacy Charts
[2009/09/01 21:40:29 | 00,000,000 | ---D | C] -- D:\Documents\MyHeritage
========== Files - Modified Within 14 Days ==========
[2009/09/15 19:49:21 | 00,690,960 | ---- | M] () -- C:\Windows\System32\PerfStringBackup.INI
[2009/09/15 19:49:21 | 00,595,684 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2009/09/15 19:49:21 | 00,101,350 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2009/09/15 19:44:31 | 00,000,006 | -H-- | M] () -- C:\Windows\tasks\SA.DAT
[2009/09/15 19:44:27 | 00,350,192 | -H-- | M] () -- C:\Windows\System32\drivers\vsconfig.xml
[2009/09/15 19:44:25 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2009/09/15 19:44:25 | 00,003,216 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2009/09/15 19:44:18 | 00,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2009/09/15 19:44:16 | 21,374,48448 | -HS- | M] () -- C:\hiberfil.sys
[2009/09/15 19:31:01 | 00,069,272 | ---- | M] () -- C:\Users\Pat\AppData\Local\GDIPFONTCACHEV1.DAT
[2009/09/15 19:30:00 | 00,294,096 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/09/15 19:28:47 | 02,302,445 | -H-- | M] () -- C:\Users\Pat\AppData\Local\IconCache.db
[2009/09/15 14:53:18 | 00,000,418 | -H-- | M] () -- C:\Windows\tasks\User_Feed_Synchronization-{417481A6-3546-42E2-8E2B-2320C2089556}.job
[2009/09/15 13:16:20 | 00,514,560 | ---- | M] (OldTimer Tools) -- C:\Users\Pat\Desktop\OTL.exe
[2009/09/15 13:13:23 | 00,000,000 | ---- | M] () -- C:\Users\Pat\Desktop\settings.dat
[2009/09/15 13:12:59 | 00,472,064 | ---- | M] ( ) -- C:\Users\Pat\Desktop\RootRepeal.exe
[2009/09/15 13:08:25 | 00,173,119 | ---- | M] (Eric_71) -- C:\Users\Pat\Desktop\Rooter.exe
[2009/09/15 12:21:20 | 00,000,620 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/09/15 12:13:38 | 00,271,872 | ---- | M] (OldTimer Tools) -- C:\Users\Pat\Desktop\TFC.exe
[2009/09/15 12:12:12 | 00,000,737 | ---- | M] () -- C:\Users\Pat\Desktop\NTREGOPT.lnk
[2009/09/15 12:12:12 | 00,000,718 | ---- | M] () -- C:\Users\Pat\Desktop\ERUNT.lnk
[2009/09/15 12:08:50 | 00,794,112 | ---- | M] () -- C:\Users\Pat\Desktop\The_Comedian.exe
[2009/09/15 11:48:40 | 00,000,712 | ---- | M] () -- C:\Users\Pat\Desktop\CCleaner.lnk
[2009/09/15 11:17:47 | 00,000,696 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2009/09/15 11:13:40 | 00,006,080 | ---- | M] () -- C:\Users\Pat\AppData\Local\d3d9caps.dat
[2009/09/13 19:11:59 | 00,000,687 | ---- | M] () -- C:\Users\Public\Desktop\avast! Antivirus.lnk
[2009/09/13 19:11:56 | 00,002,577 | ---- | M] () -- C:\Windows\System32\config.nt
[2009/09/12 20:45:46 | 01,676,869 | ---- | M] () -- D:\Documents\IL444-2378B.pdf
[2009/09/10 14:54:06 | 00,038,224 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbamswissarmy.sys
[2009/09/10 14:53:50 | 00,019,160 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2009/09/09 18:34:33 | 00,000,754 | ---- | M] () -- C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2009/09/09 15:31:56 | 00,001,891 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader 8.lnk
[2009/09/06 15:22:18 | 00,000,003 | ---- | M] () -- C:\Windows\AFirst.cmd
[2009/09/06 14:37:00 | 00,047,092 | ---- | M] () -- C:\Windows\System32\license.rtf
[2009/09/06 14:12:19 | 00,026,087 | ---- | M] () -- D:\Documents\FixMyAcer.htm
[2009/09/06 13:29:54 | 00,016,070 | ---- | M] () -- C:\Windows\System32\results.xml
[2009/09/06 12:54:40 | 00,000,122 | ---- | M] () -- C:\Windows\Alaunch.ini
[2009/09/06 12:54:21 | 00,000,092 | ---- | M] () -- C:\Windows\GridV.UNI
[2009/09/06 12:48:21 | 00,000,083 | ---- | M] () -- C:\Windows\QtZgAcer.UNI
[2009/09/06 12:42:23 | 00,004,398 | ---- | M] () -- C:\Windows\CLEANUP.CMD
[2009/09/06 12:08:52 | 00,007,078 | ---- | M] () -- D:\Documents\bookmark.htm
========== LOP Check ==========
[2009/09/15 12:21:23 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming
[2009/09/06 12:53:42 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\Acer
[2008/03/14 01:21:06 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\Acer GameZone Console
[2009/09/06 12:53:41 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\Leadertech
[2006/11/02 07:37:34 | 00,000,000 | ---D | M] -- C:\Users\Pat\AppData\Roaming\Media Center Programs
[2009/09/15 19:44:31 | 00,000,006 | -H-- | M] () -- C:\Windows\Tasks\SA.DAT
[2009/09/15 19:43:30 | 00,018,838 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2009/09/15 14:53:18 | 00,000,418 | -H-- | M] () -- C:\Windows\Tasks\User_Feed_Synchronization-{417481A6-3546-42E2-8E2B-2320C2089556}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
[2005/08/16 08:49:12 | 00,040,960 | ---- | M] (Sysinternals - www.sysinternals.com) -- C:\junction.exe
< End of report >