i did what you asked...during the scan the anti-virus picked up a couple more virus' here is the log: OTListIt logfile created on: 1/21/2009 4:18:49 PM - Run 2 OTListIt2 by OldTimer - Version 1.0.3.0 Folder = C:\Documents and Settings\Owner\Desktop Windows XP Home Edition Service Pack 1 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2800.1106) Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy 511.48 Mb Total Physical Memory | 313.06 Mb Available Physical Memory | 61.21% Memory free 864.19 Mb Paging File | 704.86 Mb Available in Paging File | 81.56% Paging File free Paging file location(s): C:\pagefile.sys 384 768; %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 38.33 Gb Total Space | 6.32 Gb Free Space | 16.48% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: ANDREW Current User Name: Owner Logged in as Administrator. Current Boot Mode: Normal Scan Mode: All users Output = Standard File Age = 30 Days Company Name Whitelist: On ========== Processes (SafeList) ========== [2008/10/15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008/10/15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2004/11/11 18:53:03 | 00,016,448 | ---- | M] (ewido networks) -- C:\Program Files\ewido\security suite\ewidoctrl.exe [2006/10/22 11:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe [2004/09/29 11:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MsPMSPSv.exe [2001/12/18 08:24:00 | 00,028,672 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\nwtray.exe [2004/09/13 14:49:00 | 00,049,152 | ---- | M] (Hewlett-Packard Company) -- C:\Program Files\HP\HP Software Update\hpwuSchd2.exe [2001/08/18 07:00:00 | 00,031,744 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\rundll32.exe [2008/06/12 13:28:45 | 00,266,497 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2002/06/12 14:27:38 | 02,315,264 | ---- | M] (MICRO-STAR INT'L CO., LTD) -- C:\Program Files\MSI\FuzzyLogic4\FuzzyLogic4.exe [2009/01/21 16:12:45 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe [2009/01/21 16:12:45 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe ========== (O23) Win32 Services (SafeList) ========== [2008/10/15 13:31:53 | 00,068,865 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe -- (AntiVirScheduler [Auto | Running]) [2008/10/15 13:30:02 | 00,151,297 | ---- | M] (Avira GmbH) -- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe -- (AntiVirService [Auto | Running]) [2005/09/23 06:28:32 | 00,029,896 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe -- (aspnet_state [On_Demand | Stopped]) [2005/09/23 06:28:56 | 00,066,240 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) File not found -- -- (DefWatch [Disabled | Stopped]) [2004/11/11 18:53:03 | 00,016,448 | ---- | M] (ewido networks) -- C:\Program Files\ewido\security suite\ewidoctrl.exe -- (ewido security suite control [Auto | Running]) [2003/09/10 18:11:46 | 00,049,152 | ---- | M] (GEAR Software) -- C:\WINDOWS\system32\gearsec.exe -- (GEARSecurity [Disabled | Stopped]) [2005/04/03 23:41:10 | 00,069,632 | ---- | M] (Macrovision Corporation) -- C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe -- (IDriverT [On_Demand | Stopped]) [2003/10/21 17:07:40 | 00,417,792 | ---- | M] (Apple Computer, Inc.) -- C:\Program Files\iPod\bin\iPodService.exe -- (iPodService [Disabled | Stopped]) [2001/02/23 09:07:30 | 00,270,336 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe -- (MDM [Disabled | Stopped]) File not found -- -- (Norton AntiVirus Server [On_Demand | Stopped]) [2006/10/22 11:22:00 | 00,159,810 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\nvsvc32.exe -- (NVSvc [Auto | Running]) [2001/08/17 22:36:54 | 00,086,016 | ---- | M] (PCtel, Inc.) -- C:\WINDOWS\system32\pctspk.exe -- (Pctspk [Disabled | Stopped]) [2004/09/29 11:14:36 | 00,069,632 | ---- | M] (HP) -- C:\WINDOWS\system32\HPZipm12.exe -- (Pml Driver HPZ12 [Auto | Running]) [2005/01/28 13:44:28 | 00,038,912 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\wdfmgr.exe -- (UMWdf [Auto | Running]) [2001/05/01 17:06:22 | 00,053,248 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\MsPMSPSv.exe -- (WMDM PMSP Service [Auto | Running]) ========== Driver Services (SafeList) ========== [2003/10/09 12:15:12 | 00,068,672 | R--- | M] (2Wire, Inc.) -- C:\WINDOWS\system32\drivers\2WirePCP.sys -- (2WIREPCP [On_Demand | Stopped]) [2002/08/02 17:10:44 | 00,659,228 | ---- | M] (Avance Logic, Inc.) -- C:\WINDOWS\system32\drivers\ALCXWDM.SYS -- (ALCXWDM [On_Demand | Running]) [2002/08/29 03:05:08 | 00,032,512 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\amdk7.sys -- (AmdK7 [system | Running]) [2002/08/29 00:59:12 | 00,036,224 | ---- | M] (ADMtek Incorporated.) -- C:\WINDOWS\system32\drivers\an983.sys -- (AN983 [On_Demand | Running]) [2008/05/09 12:15:51 | 00,045,376 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avgntdd.sys -- (avgntdd [system | Running]) [2008/01/21 17:11:28 | 00,022,336 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avgntmgr.sys -- (avgntmgr [boot | Running]) [2008/10/30 10:21:03 | 00,075,072 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\avipbb.sys -- (avipbb [system | Running]) [2002/08/29 03:32:44 | 00,009,856 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\gameenum.sys -- (gameenum [On_Demand | Running]) [2003/09/10 18:11:46 | 00,009,760 | ---- | M] (GEAR Software) -- C:\WINDOWS\system32\drivers\GEARAspiWDM.sys -- (GEARAspiWDM [On_Demand | Running]) [2004/12/14 11:07:44 | 00,051,120 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZid412.sys -- (HPZid412 [On_Demand | Stopped]) [2004/12/14 11:07:44 | 00,016,496 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZipr12.sys -- (HPZipr12 [On_Demand | Stopped]) [2004/12/14 11:07:44 | 00,021,744 | R--- | M] (HP) -- C:\WINDOWS\system32\drivers\HPZius12.sys -- (HPZius12 [On_Demand | Stopped]) [2002/02/23 16:31:08 | 00,016,768 | R--- | M] (First International Digital, Inc.) -- C:\WINDOWS\system32\drivers\IR500.sys -- (IR500 [On_Demand | Stopped]) [2002/04/10 20:03:16 | 00,011,776 | ---- | M] (Roxio) -- C:\WINDOWS\system32\drivers\MRFilter.sys -- (MrFilter [boot | Running]) [2004/10/04 22:12:36 | 00,015,340 | ---- | M] (NT Kernel Resources) -- C:\WINDOWS\system32\drivers\ndisrd.sys -- (ndisrd [system | Running]) [2002/01/30 05:40:00 | 00,367,536 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwfs.sys -- (NetwareWorkstation [Auto | Running]) [2002/02/06 12:34:00 | 00,011,984 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\drivers\nicm.sys -- (NICM [system | Running]) [2006/10/22 11:22:00 | 03,994,624 | ---- | M] (NVIDIA Corporation) -- C:\WINDOWS\system32\drivers\nv4_mini.sys -- (nv [On_Demand | Running]) [2001/10/23 05:11:00 | 00,015,648 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwdhcp.sys -- (NWDHCP [Auto | Running]) [2002/01/02 09:38:00 | 00,047,616 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwdns.sys -- (NWDNS [On_Demand | Running]) [2001/10/23 05:13:00 | 00,011,760 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwhost.sys -- (NWHOST [On_Demand | Running]) [2001/08/18 07:00:00 | 00,084,864 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnkipx.sys -- (NwlnkIpx [Auto | Running]) [2001/08/18 07:00:00 | 00,063,232 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnknb.sys -- (NwlnkNb [Auto | Running]) [2001/08/18 07:00:00 | 00,055,936 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\nwlnkspx.sys -- (NwlnkSpx [Auto | Running]) [2001/10/23 05:10:00 | 00,022,160 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwsap.sys -- (NWSAP [On_Demand | Stopped]) [2001/10/23 04:58:00 | 00,040,560 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\nwsipx32.sys -- (NWSIPX32 [Auto | Running]) [2001/10/23 05:12:00 | 00,021,120 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwslp.sys -- (NWSLP [On_Demand | Running]) [2001/10/23 05:09:00 | 00,005,984 | ---- | M] () -- C:\WINDOWS\system32\NetWare\nwsns.sys -- (NWSNS [On_Demand | Running]) [2002/04/15 09:55:28 | 00,043,212 | ---- | M] (MICRO-STAR INT'L CO., LTD.) -- C:\Program Files\MSI\FuzzyLogic4\Ntglm7x.sys -- (PCAlertDriver [On_Demand | Running]) [2002/01/16 15:51:18 | 00,018,560 | R--- | M] (Barom Technologies Co., Ltd.) -- C:\WINDOWS\system32\drivers\PortRst.sys -- (PortRst [On_Demand | Stopped]) [2001/08/18 07:00:00 | 00,017,792 | ---- | M] (Parallel Technologies, Inc.) -- C:\WINDOWS\system32\drivers\ptilink.sys -- (Ptilink [On_Demand | Running]) [2001/08/17 13:28:14 | 00,112,574 | ---- | M] (PCTEL, INC.) -- C:\WINDOWS\system32\drivers\ptserlp.sys -- (Ptserlp [On_Demand | Stopped]) [2003/10/28 05:02:00 | 00,020,016 | ---- | M] (Sonic Solutions) -- C:\WINDOWS\system32\drivers\pxhelp20.sys -- (PxHelp20 [boot | Running]) [2001/08/17 13:53:32 | 00,003,328 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\qv2kux.sys -- (QV2KUX [On_Demand | Stopped]) [2001/10/23 05:04:00 | 00,029,229 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\resmgr.sys -- (RESMGR [Auto | Running]) [2002/06/12 15:19:12 | 00,044,812 | ---- | M] (Vireo Software) -- C:\Program Files\MSI\FuzzyLogic4\RushTop.sys -- (RushTopDevice [On_Demand | Running]) [2005/12/25 17:35:37 | 00,163,644 | ---- | M] (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.) -- C:\WINDOWS\system32\drivers\secdrv.sys -- (Secdrv [Auto | Running]) [2001/08/17 13:56:16 | 00,007,552 | ---- | M] (Sony Corporation) -- C:\WINDOWS\system32\drivers\SONYPVU1.SYS -- (SONYPVU1 [On_Demand | Stopped]) [2001/11/29 09:35:00 | 00,124,176 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\NetWare\srvloc.sys -- (SRVLOC [Auto | Running]) [2007/03/01 09:34:22 | 00,028,352 | ---- | M] (Avira GmbH) -- C:\WINDOWS\system32\drivers\ssmdrv.sys -- (ssmdrv [system | Running]) [2002/08/29 03:32:32 | 00,056,832 | ---- | M] (Microsoft Corporation) -- C:\WINDOWS\system32\drivers\USBAUDIO.sys -- (usbaudio [On_Demand | Stopped]) [2001/12/18 13:45:04 | 00,003,279 | ---- | M] (VIA Technologies. Inc.) -- C:\WINDOWS\system32\drivers\VIAPFD.SYS -- (VIAPFD [system | Running]) [2001/08/17 13:28:14 | 00,604,253 | ---- | M] (PCTEL, INC.) -- C:\WINDOWS\system32\drivers\vmodem.sys -- (Vmodem [boot | Running]) [2001/08/17 13:28:16 | 00,397,502 | ---- | M] (PCtel, Inc.) -- C:\WINDOWS\system32\drivers\vpctcom.sys -- (Vpctcom [boot | Running]) [2001/08/17 13:28:16 | 00,064,605 | ---- | M] (PCtel, Inc.) -- C:\WINDOWS\system32\drivers\vvoice.sys -- (Vvoice [boot | Running]) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\.DEFAULT\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = about:blank HKU\S-1-5-18\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 HKU\S-1-5-19\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page_bak = http://www.microsoft.com/isapi/redir.dll?p...amp;ar=iesearch HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?p...&ar=msnhome HKU\S-1-5-21-1202660629-879983540-725345543-1003\S-1-5-21-1202660629-879983540-725345543-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 O1 HOSTS File: (27 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts O1 - Hosts: 127.0.0.1 localhost O3 - HKLM\..\Toolbar: (&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx () O3 - HKCU\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found O3 - HKU\S-1-5-21-1202660629-879983540-725345543-1003\..\Toolbar: (no name) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - Reg Error: Key does not exist or could not be opened. File not found O4 - HKLM..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min (Avira GmbH) O4 - HKLM..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" (Hewlett-Packard Company) O4 - HKLM..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup (NVIDIA Corporation) O4 - HKLM..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit (NVIDIA Corporation) O4 - HKLM..\Run: [nwiz] nwiz.exe /install () O4 - HKLM..\Run: [NWTRAY] NWTRAY.EXE (Novell, Inc.) O4 - HKLM..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime (Apple Computer, Inc.) O4 - HKCU..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl File not found O4 - HKU\S-1-5-21-1202660629-879983540-725345543-1003..\Run: [AIM] C:\Program Files\AIM95\aim.exe -cnetwait.odl File not found O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\FuzzyLogic4.lnk = C:\Program Files\MSI\FuzzyLogic4\FuzzyLogic4.exe (MICRO-STAR INT'L CO., LTD) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext = O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DisableRegistryTools = 0 O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-18\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-19\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-19_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1202660629-879983540-725345543-1003\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveAutoRun = 67108863 O7 - HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 323 O7 - HKU\S-1-5-21-1202660629-879983540-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0 O7 - HKU\S-1-5-21-1202660629-879983540-725345543-1003_Classes\Software\Policies\Microsoft\Internet Explorer\Control Panel present O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra Button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.) O9 - Extra 'Tools' menuitem : Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\Program Files\Yahoo!\Messenger\yhexbmes0521.dll (Yahoo! Inc.) O9 - Extra Button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe (America Online, Inc.) O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O9 - Extra 'Tools' menuitem : Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation) O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa...director/sw.cab (Shockwave ActiveX Control) O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} http://download.yahoo.com/dl/yinst/yinst_current.cab (YInstStarter Class) O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} http://download.microsoft.com/download/F/6...922/wmv9VCM.CAB (Reg Error: Key does not exist or could not be opened.) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/products/plugin/1.4/jinstall-14-win.cab (Java Plug-in 1.4.0) O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} http://v4.windowsupdate.microsoft.com/CAB/...7878.4508680556 (Reg Error: Key does not exist or could not be opened.) O16 - DPF: {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA} http://java.sun.com/products/plugin/1.4/jinstall-14-win.cab (Java Plug-in 1.4.0) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://download.macromedia.com/pub/shockwa...ash/swflash.cab (Shockwave Flash Object) O18 - Protocol\Handler: - ipp - No CLSID value found O18 - Protocol\Handler: - ipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler: - msdaipp - No CLSID value found O18 - Protocol\Handler: - msdaipp\0x00000001 - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler: - msdaipp\oledb - C:\Program Files\Common Files\System\Ole DB\MSDAIPP.DLL (Microsoft Corporation) O18 - Protocol\Handler: - vnd.ms.radio - C:\WINDOWS\system32\msdxm.ocx () O20 - See sections below for AppInitDlls and Winlogon settings ========== HKLM Winlogon Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "GinaDLL" = NWGINA.DLL >[2002/01/22 11:45:00 | 00,244,992 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\nwgina.dll ========== Winlogon Notify Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\] NavLogon: "DllName" = C:\WINDOWS\System32\NavLogon.dll -- C:\WINDOWS\system32\NavLogon.dll () ========== Shell Execute Hooks ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{54D9498B-CF93-414F-8984-8CE7FDE0D391}" (HKLM) -- C:\Program Files\ewido\security suite\shellhook.dll () [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{EDB0E980-90BD-11D4-8599-0008C7D3B6F8}" (HKLM) -- C:\Program Files\Qualcomm\Eudora2\EuShlExt.dll (Qualcomm Inc.) ========== LSA *Authentication Packages* ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "Authentication Packages" = msv1_0,nwv1_0, >[2000/02/17 01:54:00 | 00,008,480 | ---- | M] (Novell, Inc.) -- C:\WINDOWS\system32\nwv1_0.dll ========== Safeboot Options ========== "AlternateShell" = cmd.exe ========== CDRom AutoRun Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom] "AutoRun" = 1 ========== Files/Folders - Created Within 30 Days ========== [6 C:\WINDOWS\*.tmp files] [2009/01/21 16:12:40 | 00,419,328 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe [2009/01/15 07:24:51 | 00,000,000 | ---D | C] -- C:\rsit [2009/01/15 07:24:02 | 00,781,851 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\RSIT.exe [2009/01/14 16:55:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\AntiVir PersonalEdition Classic [2009/01/14 16:47:04 | 00,001,858 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\AntiVir PE Classic.lnk [2009/01/14 16:46:55 | 00,045,376 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys [2009/01/14 16:46:55 | 00,022,336 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys [2009/01/14 16:46:54 | 00,028,352 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys [2009/01/14 16:46:51 | 00,075,072 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2009/01/14 16:46:45 | 00,000,000 | ---D | C] -- C:\Program Files\Avira [2009/01/14 16:46:45 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira [2009/01/14 16:04:50 | 22,058,104 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\antivir_workstation_winu_en_h.exe [2009/01/14 07:46:38 | 00,000,000 | -HSD | C] -- C:\RECYCLER [2009/01/14 07:38:22 | 00,368,922 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dds.scr [2009/01/14 07:34:11 | 00,000,000 | ---D | C] -- C:\WINDOWS\temp [2009/01/14 07:09:52 | 02,914,743 | R--- | C] () -- C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe [2009/01/14 07:06:51 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\varestorepolicies [2009/01/13 00:52:34 | 00,001,565 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Cake Poker.lnk [2009/01/13 00:52:33 | 00,000,000 | ---D | C] -- C:\Program Files\Cake Poker [2009/01/13 00:51:02 | 14,321,744 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\FullcakeSetup.1.0.118.exe [2009/01/12 07:37:07 | 00,028,168 | ---- | C] () -- C:\WINDOWS\SIGVERIF.zip [2009/01/12 01:43:57 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\NortonInstaller [2009/01/12 01:42:32 | 02,428,928 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe [2009/01/12 01:38:35 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\LspFix [2009/01/12 01:38:06 | 00,201,030 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\lspfix.zip [2009/01/11 09:17:34 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\SmitfraudFix [2009/01/10 19:41:23 | 00,016,884 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\VirusVaultAVG1-10-09.csv [2009/01/10 19:26:17 | 00,000,000 | ---D | C] -- C:\WINDOWS\LastGood [2009/01/09 13:57:32 | 00,368,831 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\dds.com [2009/01/09 13:44:45 | 00,000,194 | ---- | C] () -- C:\Boot.bak [2009/01/09 13:44:42 | 00,245,920 | ---- | C] () -- C:\cmldr [2009/01/09 13:44:37 | 00,000,000 | RHSD | C] -- C:\cmdcons [2009/01/09 13:43:02 | 00,212,480 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWXCACLS.exe [2009/01/09 13:43:02 | 00,161,792 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWREG.exe [2009/01/09 13:43:02 | 00,136,704 | ---- | C] (SteelWerX) -- C:\WINDOWS\SWSC.exe [2009/01/09 13:43:02 | 00,098,816 | ---- | C] () -- C:\WINDOWS\sed.exe [2009/01/09 13:43:02 | 00,089,504 | ---- | C] (Smallfrogs Studio) -- C:\WINDOWS\fdsv.exe [2009/01/09 13:43:02 | 00,080,412 | ---- | C] () -- C:\WINDOWS\grep.exe [2009/01/09 13:43:02 | 00,068,096 | ---- | C] () -- C:\WINDOWS\zip.exe [2009/01/09 13:43:02 | 00,049,152 | ---- | C] () -- C:\WINDOWS\VFIND.exe [2009/01/09 13:43:02 | 00,028,672 | ---- | C] (NirSoft) -- C:\WINDOWS\NIRCMD.exe [2009/01/09 13:42:54 | 00,000,000 | ---D | C] -- C:\WINDOWS\ERDNT [2009/01/09 13:42:54 | 00,000,000 | ---D | C] -- C:\Qoobox [2009/01/09 13:39:53 | 00,000,570 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\VArestorepolicies.zip [2009/01/09 13:34:53 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\FixPolicies [2009/01/09 13:34:12 | 00,185,065 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\FixPolicies.exe [2009/01/09 13:27:12 | 00,196,267 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\fixacl.exe [2009/01/09 13:23:04 | 00,001,555 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\CCleaner.lnk [2009/01/09 13:23:04 | 00,000,000 | ---D | C] -- C:\Program Files\CCleaner [2009/01/09 13:21:39 | 03,165,824 | ---- | C] (Piriform Ltd) -- C:\Documents and Settings\Owner\Desktop\ccsetup215.exe [2009/01/08 23:19:08 | 00,003,728 | ---- | C] () -- C:\Documents and Settings\Owner\Desktop\yourname_gmer.zip [2009/01/08 07:50:05 | 00,000,000 | ---D | C] -- C:\is_en [2009/01/08 07:47:10 | 00,000,000 | ---D | C] -- C:\TempHold [2009/01/07 19:55:19 | 00,000,250 | ---- | C] () -- C:\WINDOWS\gmer.ini [2009/01/07 19:55:18 | 00,884,736 | ---- | C] () -- C:\WINDOWS\gmer.dll [2009/01/07 19:55:18 | 00,811,008 | ---- | C] () -- C:\WINDOWS\gmer.exe [2009/01/07 19:55:18 | 00,085,969 | ---- | C] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys [2009/01/07 19:55:18 | 00,000,080 | ---- | C] () -- C:\WINDOWS\gmer_uninstall.cmd [2009/01/07 19:37:17 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Application Data\Malwarebytes [2009/01/07 19:37:14 | 00,015,504 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys [2009/01/07 19:37:11 | 00,038,496 | ---- | C] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/01/07 19:37:10 | 00,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware [2009/01/07 19:37:10 | 00,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Malwarebytes [2009/01/07 19:36:40 | 00,000,000 | ---D | C] -- C:\Documents and Settings\Owner\Desktop\Spyware Removal [2009/01/07 19:34:47 | 00,000,000 | ---D | C] -- C:\Program Files\Trend Micro ========== Files - Modified Within 30 Days ========== [5 C:\WINDOWS\System32\*.tmp files] [6 C:\WINDOWS\*.tmp files] [2009/01/21 16:17:13 | 00,000,000 | ---- | M] () -- C:\WINDOWS\System32\NvApps.xml [2009/01/21 16:15:31 | 00,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2009/01/21 16:12:45 | 00,419,328 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\Owner\Desktop\OTListIt2.exe [2009/01/21 16:03:03 | 02,656,656 | -H-- | M] () -- C:\Documents and Settings\Owner\Local Settings\Application Data\IconCache.db [2009/01/21 16:02:05 | 00,001,374 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2009/01/15 07:24:16 | 00,781,851 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\RSIT.exe [2009/01/14 17:36:40 | 00,001,858 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\AntiVir PE Classic.lnk [2009/01/14 16:08:44 | 22,058,104 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\antivir_workstation_winu_en_h.exe [2009/01/14 07:38:24 | 00,368,922 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\dds.scr [2009/01/14 07:29:38 | 00,000,246 | ---- | M] () -- C:\WINDOWS\system.ini [2009/01/14 07:27:44 | 00,000,027 | ---- | M] () -- C:\WINDOWS\System32\drivers\etc\hosts [2009/01/14 07:10:21 | 02,914,743 | R--- | M] () -- C:\Documents and Settings\Owner\Desktop\Combo-Fix.exe [2009/01/14 07:02:05 | 00,134,072 | ---- | M] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009/01/13 00:52:34 | 00,001,565 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Cake Poker.lnk [2009/01/13 00:52:11 | 14,321,744 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\FullcakeSetup.1.0.118.exe [2009/01/12 07:37:07 | 00,028,168 | ---- | M] () -- C:\WINDOWS\SIGVERIF.zip [2009/01/12 01:43:13 | 02,428,928 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\Norton_Removal_Tool.exe [2009/01/12 01:38:16 | 00,201,030 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\lspfix.zip [2009/01/10 19:41:23 | 00,016,884 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\VirusVaultAVG1-10-09.csv [2009/01/10 08:45:35 | 00,009,522 | ---- | M] () -- C:\WINDOWS\Zapotec.bmp [2009/01/10 08:45:34 | 00,048,680 | ---- | M] () -- C:\WINDOWS\winnt256.bmp [2009/01/10 08:45:34 | 00,048,680 | ---- | M] () -- C:\WINDOWS\winnt.bmp [2009/01/10 08:45:34 | 00,001,125 | ---- | M] () -- C:\WINDOWS\winamp.ini [2009/01/10 08:45:34 | 00,000,036 | ---- | M] () -- C:\WINDOWS\wininit.ini [2009/01/10 08:45:34 | 00,000,000 | ---- | M] () -- C:\WINDOWS\VPC32.INI [2009/01/10 08:45:33 | 00,065,978 | ---- | M] () -- C:\WINDOWS\Soap Bubbles.bmp [2009/01/10 08:45:33 | 00,065,832 | ---- | M] () -- C:\WINDOWS\Santa Fe Stucco.bmp [2009/01/10 08:45:33 | 00,026,680 | ---- | M] () -- C:\WINDOWS\River Sumida.bmp [2009/01/10 08:45:33 | 00,008,192 | ---- | M] () -- C:\WINDOWS\REGLOCS.OLD [2009/01/10 08:45:33 | 00,000,037 | ---- | M] () -- C:\WINDOWS\vbaddin.ini [2009/01/10 08:45:33 | 00,000,036 | ---- | M] () -- C:\WINDOWS\vb.ini [2009/01/10 08:45:32 | 00,000,525 | ---- | M] () -- C:\WINDOWS\QIII.INI [2009/01/10 08:45:32 | 00,000,000 | ---- | M] () -- C:\WINDOWS\QuickInstall.INI [2009/01/10 08:45:31 | 00,000,059 | ---- | M] () -- C:\WINDOWS\pp.enc [2009/01/10 08:45:30 | 00,082,022 | ---- | M] () -- C:\WINDOWS\n_vfjwxf.dat [2009/01/10 08:45:30 | 00,082,022 | ---- | M] () -- C:\WINDOWS\n_tyxhbu.dat [2009/01/10 08:45:30 | 00,034,937 | ---- | M] () -- C:\WINDOWS\n_xcsotu.dat [2009/01/10 08:45:29 | 00,033,401 | ---- | M] () -- C:\WINDOWS\n_lmltrs.dat [2009/01/10 08:45:29 | 00,029,768 | ---- | M] () -- C:\WINDOWS\n_glohwz.dat [2009/01/10 08:45:28 | 00,026,582 | ---- | M] () -- C:\WINDOWS\Greenstone.bmp [2009/01/10 08:45:28 | 00,004,226 | ---- | M] () -- C:\WINDOWS\mozver.dat [2009/01/10 08:45:28 | 00,000,011 | ---- | M] () -- C:\WINDOWS\NetWare.INI [2009/01/10 08:45:27 | 00,082,944 | ---- | M] () -- C:\WINDOWS\clock.avi [2009/01/10 08:45:27 | 00,017,336 | ---- | M] () -- C:\WINDOWS\Gone Fishing.bmp [2009/01/10 08:45:27 | 00,017,062 | ---- | M] () -- C:\WINDOWS\Coffee Bean.bmp [2009/01/10 08:45:27 | 00,000,000 | ---- | M] () -- C:\WINDOWS\control.ini [2009/01/09 13:57:38 | 00,368,831 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\dds.com [2009/01/09 13:44:46 | 00,000,264 | RHS- | M] () -- C:\boot.ini [2009/01/09 13:39:51 | 00,000,570 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\VArestorepolicies.zip [2009/01/09 13:34:12 | 00,185,065 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\FixPolicies.exe [2009/01/09 13:27:15 | 00,196,267 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\fixacl.exe [2009/01/09 13:23:04 | 00,001,555 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\CCleaner.lnk [2009/01/09 13:21:49 | 03,165,824 | ---- | M] (Piriform Ltd) -- C:\Documents and Settings\Owner\Desktop\ccsetup215.exe [2009/01/08 23:19:08 | 00,003,728 | ---- | M] () -- C:\Documents and Settings\Owner\Desktop\yourname_gmer.zip [2009/01/08 22:59:00 | 00,000,250 | ---- | M] () -- C:\WINDOWS\gmer.ini [2009/01/07 19:55:18 | 00,884,736 | ---- | M] () -- C:\WINDOWS\gmer.dll [2009/01/07 19:55:18 | 00,085,969 | ---- | M] (GMER) -- C:\WINDOWS\System32\drivers\gmer.sys [2009/01/07 19:55:18 | 00,000,080 | ---- | M] () -- C:\WINDOWS\gmer_uninstall.cmd [2009/01/04 18:38:22 | 00,038,496 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbamswissarmy.sys [2009/01/04 18:38:18 | 00,015,504 | ---- | M] (Malwarebytes Corporation) -- C:\WINDOWS\System32\drivers\mbam.sys ========== Alternate Data Streams ========== @Alternate Data Stream - 84222 bytes -> %SystemRoot%\_default.pif:pwqlo @Alternate Data Stream - 7473 bytes -> %SystemRoot%\winnt256.bmp:njrtqj @Alternate Data Stream - 7473 bytes -> %SystemRoot%\Santa Fe Stucco.bmp:thmcis @Alternate Data Stream - 7473 bytes -> %SystemRoot%\ropht.txt:gqxgff @Alternate Data Stream - 7473 bytes -> %SystemRoot%\Q815021.log:ideoxc @Alternate Data Stream - 7473 bytes -> %SystemRoot%\n_drwoho.log:kmghoo @Alternate Data Stream - 7473 bytes -> %SystemRoot%\KB824146.log:zjwmrt @Alternate Data Stream - 7473 bytes -> %SystemRoot%\fxhqs.log:vienrp @Alternate Data Stream - 7473 bytes -> %SystemRoot%\bootstat.dat:kcjadn @Alternate Data Stream - 7473 bytes -> %SystemRoot%\_default.pif:tjygio @Alternate Data Stream - 7473 bytes -> %SystemRoot%\_default.pif:jbjptx @Alternate Data Stream - 7473 bytes -> %SystemRoot%\_default.pif:ejmzsy @Alternate Data Stream - 7423 bytes -> %SystemRoot%\Zapotec.bmp:fwshbe @Alternate Data Stream - 7423 bytes -> %SystemRoot%\KB825119.log:hhirgo @Alternate Data Stream - 7423 bytes -> %SystemRoot%\Directx.log:paugdy @Alternate Data Stream - 7423 bytes -> %SystemRoot%\_default.pif:sldwpe @Alternate Data Stream - 7423 bytes -> %SystemRoot%\_default.pif:nwvyho @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:xvkqur @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:vzccne @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:udmzps @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:ubxhpl @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:txyjud @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:trxsuq @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:trlueh @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:tiwlhg @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:tcymul @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:rwqorf @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:rmxolt @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:rieyml @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:qydrxz @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:plprol @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:ovymno @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:ofdsyc @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:nuodli @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:ntdfgj @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:nbbbcs @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:muolyk @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:lvnqui @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:lrbpfu @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:ktitrw @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:kbxlpi @Alternate Data Stream - 66560 bytes -> %SystemRoot%\_default.pif:jraqkx @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:yqxxoc @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:ypcudt @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:vyjeql @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:tyixuj @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:rctdmz @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:qrosip @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:qiwgfe @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:ocfdul @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:kxrrqr @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:kscoor @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:jpuprb @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:jauxsy @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:iqachm @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:idvqxq @Alternate Data Stream - 4870 bytes -> %SystemRoot%\_default.pif:ibkyyv @Alternate Data Stream - 4866 bytes -> %SystemRoot%\msdfmap.ini:mvrdln @Alternate Data Stream - 4866 bytes -> %SystemRoot%\_default.pif:tjagas @Alternate Data Stream - 4866 bytes -> %SystemRoot%\_default.pif:ipqwjh @Alternate Data Stream - 4866 bytes -> %SystemRoot%\_default.pif:ibvuyy @Alternate Data Stream - 4866 bytes -> %SystemRoot%\_default.pif:glmepy @Alternate Data Stream - 4866 bytes -> %SystemRoot%\_default.pif:dmaabp @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:zhttkb @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:yxlmdp @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:ylfjrj @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:ydyjpv @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:xkfemj @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:wmkfda @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:wlbhxa @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:vufyke @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:vtvqix @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:vsszez @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:vfbzom @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:vaiwih @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:sqiblr @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:samfng @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:rbyopm @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:qrhlqm @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:qquixv @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:nycjko @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:mztcot @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:mklucd @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:kvmiok @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:kmwcrh @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:ishxls @Alternate Data Stream - 3567 bytes -> %SystemRoot%\_default.pif:iigtho @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:zwwrui @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:zsstuo @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:yuyflx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:yngatr @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:yixnp @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:yasagw @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xwxfmx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xvmulu @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xvjfcu @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xsqloy @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xkclcx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:xfmery @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:wodxxd @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:vnrlfm @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:vjqzxg @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:vbcsbx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:uwccls @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:uquxul @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:uitzdn @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:txzhkp @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:txwfxj @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:tnbqcm @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:tdwpvx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:sytdk @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:swfqxi @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:svvodk @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:scgggg @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:rzpvan @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:rjqisu @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:qydrx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:qvxdlc @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:qjmwjh @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:qcnecq @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:pvwtau @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:pgwwmp @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:pcccju @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:ovgjnw @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:ofkfks @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nzaibz @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nrjart @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nklcmp @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nkjrxz @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nkgpfr @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:nghqfq @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:neivkh @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:mtjmcq @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:mrwyqa @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:mlciwv @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:mhbhjl @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:mbncsd @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:lzuuzh @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:lnqaci @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:lmffjx @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:kwafgt @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:kvtjvw @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:keyyiw @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:jyase @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:jiarev @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:jgifzv @Alternate Data Stream - 29256 bytes -> %SystemRoot%\_default.pif:jblblw @Alternate Data Stream - 21932 bytes -> %SystemRoot%\_default.pif:zafjvk @Alternate Data Stream - 21932 bytes -> %SystemRoot%\_default.pif:ihsblt @Alternate Data Stream - 13874 bytes -> %SystemRoot%\mitqw.log:crgosg @Alternate Data Stream - 124706 bytes -> %SystemRoot%\_default.pif:ukytk @Alternate Data Stream - 124706 bytes -> %SystemRoot%\_default.pif:meaua @Alternate Data Stream - 124706 bytes -> %SystemRoot%\_default.pif:ksqrv @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:zbjxsp @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:vkbqvw @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:vftkpn @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:vcvysi @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:ueltfd @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:tlhuhf @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:szhpim @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:rzbjyo @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:robcxr @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:rbqbrv @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:qppwfj @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:qgavjj @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:qbrswl @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:qacodn @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:pofrpw @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:pdcldg @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:mjuupo @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:lsyobn @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:kzfdmu @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:kssgud @Alternate Data Stream - 11736 bytes -> %SystemRoot%\_default.pif:keqhsz @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:zvmdvx @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:zifdxj @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:zhvnez @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:zabwiu @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:yywqxd @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ybvzzf @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:xvloyj @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:xufyrz @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:xitrof @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:xgmdhl @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:xbsxps @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:wuodkt @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:wqpiyt @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:whakqe @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:wesrqi @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:vtldcu @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:vknckg @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:vjukfr @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:veqqqf @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:uyhdzo @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:unuypm @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ujqldw @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ujbxkn @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ugjcpb @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ufollg @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:ubdxys @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:tycpff @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:tqetwp @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:tmfvaf @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:tkjdck @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:tarhag @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:swhaei @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:sdosgm @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:rvtnyy @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:rujetu @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:rnysfl @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:qiqljt @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:qherkv @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:qehadn @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:qdafvy @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:pxlrrp @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:pmgyy @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:oxsyyi @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:otjxpx @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:orhosd @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:nudixe @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:nhmut @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:nacnve @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:mbbrnv @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:kquifo @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:kqhphx @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:kjdwie @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jwjnxq @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jqujtn @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jktcjw @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jintgb @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jgwcdo @Alternate Data Stream - 11674 bytes -> %SystemRoot%\_default.pif:jegbie @Alternate Data Stream - 11336 bytes -> %SystemRoot%\_default.pif:vhpbby @Alternate Data Stream - 11336 bytes -> %SystemRoot%\_default.pif:stnahn @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:wxwghk @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:wlnte @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:wekzu @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:rasexi @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:qzigiw @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:oyhujn @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:olugm @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:ogijoo @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:lkrlky @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:lhiut @Alternate Data Stream - 0 bytes -> %SystemRoot%\_default.pif:jabtkh < End of report > As far as extras.txt goes, there is no copy of that on my pc! Thanks for your help, looking forward to getting this problem licked!