Thanks;
I wanted to let you know that my computer adopted an annoying new system last night. Now when I turn it on it says that my antivirus is not working, yet when I go to antivirus, it is on. I thought at first that it was because it hadn't opened up yet (this antivirus prog is new to me); but I had never seen that happen before, and have not changed the settings on it.
By the way, just in case you are reading this, I intend to add the files to this post.
VirSCAN.org Scanned Report :
Scanned time : 2009/03/08 09:52:50 (CDT)
Scanner results: 8% Scanner(3/37) found malware!
File Name : sysguard.exe
File Size : 198788 byte
File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit
MD5 : 2051ca9e3bb6e45d76611ad25d0bbd08
SHA1 : 60befa3b7cd839f9c864a563472cf315949ddea2
Online report :
http://virscan.org/report/4a704391a090c ... 5fc1e.htmlScanner Engine Ver Sig Ver Sig Date Time Scan result
a-squared 4.0.0.32 20090308223224 2009-03-08 2.54 -
AhnLab V3 2009.03.07.01 2009.03.07 2009-03-07 1.13 -
AntiVir 7.9.0.105 7.1.2.135 2009-03-07 1.90 -
Antiy 2.0.18 20090308.2212560 2009-03-08 0.12 -
Authentium 5.1.1 200903071729 2009-03-07 1.18 -
AVAST! 3.0.1 090307-0 2009-03-07 0.90 -
AVG 7.5.52.442 270.11.9/1989 2009-03-07 1.98 -
BitDefender 7.81008.2770348 7.24049 2009-03-08 2.60 -
CA (VET) 9.0.0.143 31.6.6386 2009-03-07 5.34 -
ClamAV 0.94.2 9080 2009-03-07 0.15 -
Comodo 3.8 1037 2009-03-08 1.11 -
CP Secure 1.1.0.715 2009.03.08 2009-03-08 7.41 W32.IM.W.Sohanad.as
Dr.Web 4.44.0.9170 2009.03.08 2009-03-08 4.53 -
F-Prot 4.4.4.56 20090307 2009-03-07 1.16 -
F-Secure 5.51.6100 2009.03.08.01 2009-03-08 5.07 -
Fortinet 2.81-3.117 10.132 2009-03-07 0.24 -
GData 19.3745/19.252 20090308 2009-03-08 3.46 -
ViRobot 20090307 2009.03.07 2009-03-07 0.41 -
Ikarus T3.1.01.45 2009.03.08.72398 2009-03-08 4.52 -
JiangMin 11.0.706 2009.03.06 2009-03-06 1.59 -
Kaspersky 5.5.10 2009.03.08 2009-03-08 0.28 -
KingSoft 2009.2.5.15 2009.3.8.15 2009-03-08 0.70 -
McAfee 5.3.00 5546 2009-03-07 2.84 -
Microsoft 1.4405 2009.03.08 2009-03-08 4.84 -
mks_vir 2.01 2009.03.08 2009-03-08 2.93 -
Norman 6.00.06 6.00.00 2009-03-06 8.01 -
Panda 9.05.01 2009.03.07 2009-03-07 1.58 -
Trend Micro 8.700-1004 5.884.33 2009-03-08 0.08 -
Quick Heal 10.00 2009.03.07 2009-03-07 1.00 -
Rising 20.0 21.19.42.00 2009-03-06 0.40 Trojan.DL.Agent.gol
Sophos 2.84.1 4.39 2009-03-08 2.41 -
Sunbelt 5030 5030 2009-03-07 1.34 -
Symantec 1.3.0.24 20090307.003 2009-03-07 0.41 -
nProtect 20090307.01 3288711 2009-03-07 4.78 -
The Hacker 6.3.2.7 v00275 2009-03-07 0.58 W32/Sohanad.bb
VBA32 3.12.10.1 20090307.1637 2009-03-07 1.95 -
VirusBuster 4.5.11.10 10.102.2/968427 2009-03-07 1.57 -
Microsoft Windows XP Professional (5.1.2600) Service Pack 3
A:\ [Removable] (Total:0 Mo/Free:0 Mo)
C:\ [Fixed] - NTFS - (Total:76316 Mo/Free:2292 Mo)
D:\ [CD-Rom] (Total:0 Mo/Free:0 Mo)
Sun 03/08/2009|10:00
----------------------\\ Processes..
--Locked-- [System Process]
---------- System
---------- \SystemRoot\System32\smss.exe
---------- \??\C:\WINDOWS\system32\csrss.exe
---------- \??\C:\WINDOWS\system32\winlogon.exe
---------- C:\WINDOWS\system32\services.exe
---------- C:\WINDOWS\system32\lsass.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\system32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\System32\svchost.exe
---------- C:\WINDOWS\Explorer.EXE
---------- C:\WINDOWS\system32\spoolsv.exe
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
---------- C:\WINDOWS\LTMSG.exe
---------- C:\Program Files\Java\jre6\bin\jusched.exe
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
---------- C:\WINDOWS\system32\ctfmon.exe
---------- C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
---------- C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
---------- C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
---------- C:\Program Files\Java\jre6\bin\jqs.exe
---------- C:\WINDOWS\system32\msfeedssync.exe
---------- C:\WINDOWS\System32\alg.exe
---------- C:\DOCUME~1\judy\LOCALS~1\Temp\SSUPDATE.EXE
---------- C:\Program Files\Internet Explorer\IEXPLORE.EXE
---------- C:\WINDOWS\system32\notepad.exe
---------- C:\WINDOWS\system32\cmd.exe
---------- C:\Rooter$\RK.exe
----------------------\\ Search..
----------------------\\ ROOTKIT !!
1 - "C:\Rooter$\Rooter_1.txt" - Sun 03/08/2009|10:00
----------------------\\ Scan completed at 10:00
Logfile of random's system information tool 1.05 (written by random/random)
Run by judy at 2009-03-08 10:11:19
Microsoft Windows XP Professional Service Pack 3
System drive C: has 72 GB (94%) free of 76 GB
Total RAM: 239 MB (49% free)
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:11:29 AM, on 3/8/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\LTMSG.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\msfeedssync.exe
C:\DOCUME~1\judy\LOCALS~1\Temp\SSUPDATE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\system32\notepad.exe
C:\Documents and Settings\judy\Desktop\RSIT.exe
C:\Program Files\Trend Micro\HijackThis\judy.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.ca/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.guidingstar.co.uk/start/startca.htmO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [LTMSG] LTMSG.exe 7
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O8 - Extra context menu item: Mail to a Friend... -
http://client.alexa.com/holiday/script/ ... mailto.htmO9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://www.update.microsoft.com/microso ... 3837989077O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://www.update.microsoft.com/microso ... 3837976374O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/s ... wflash.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) -
https://signin3.valueactive.eu/Register ... lashax.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{9535DC02-ECC3-4712-A6CE-7620E7198714}: NameServer = 142.161.130.154 142.161.2.154
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dll
O23 - Service: Avira AntiVir Personal - Free Antivirus Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
--
End of file - 5663 bytes
======Scheduled tasks folder======
C:\WINDOWS\tasks\User_Feed_Synchronization-{2F596269-74BE-4162-88E1-E16F297CDF22}.job
======Registry dump======
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
AVG Safe Search - C:\Program Files\AVG\AVG8\avgssie.dll []
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AA58ED58-01DD-4d91-8333-CF10577473F7}]
Google Toolbar Helper - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-07 251504]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}]
Google Toolbar Notifier BHO - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll [2009-01-07 657904]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C84D72FE-E17D-4195-BB24-76C02E2E7C4E}]
Google Dictionary Compression sdch - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll [2009-01-07 522224]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}]
Java(tm) Plug-In 2 SSV Helper - C:\Program Files\Java\jre6\bin\jp2ssv.dll [2009-03-03 35840]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}]
JQSIEStartDetectorImpl Class - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-03 73728]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
{2318C2B1-4965-11d4-9B18-009027A5CD4F} - &Google Toolbar - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll [2009-01-07 251504]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
"LTMSG"=LTMSG.exe 7 []
"SunJavaUpdateSched"=C:\Program Files\Java\jre6\bin\jusched.exe [2009-03-03 148888]
"avgnt"=C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497]
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"=C:\WINDOWS\system32\ctfmon.exe [2008-04-13 15360]
"swg"=C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [2008-10-25 68856]
"SUPERAntiSpyware"=C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe [2009-02-17 1830128]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\!SASWinLogon]
C:\Program Files\SUPERAntiSpyware\SASWINLO.dll [2008-12-22 356352]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon]
C:\WINDOWS\system32\WgaLogon.dll [2008-09-05 241704]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks]
"{5AE067D3-9AFB-48E0-853A-EBB7F4A000DA}"=C:\Program Files\SUPERAntiSpyware\SASSEH.DLL [2008-05-13 77824]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr]
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System]
"dontdisplaylastusername"=0
"legalnoticecaption"=
"legalnoticetext"=
"shutdownwithoutlogon"=1
"undockwithoutlogon"=1
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"NoDriveTypeAutoRun"=145
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer]
"HonorAutoRunSetting"=
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\Program Files\Messenger\msmsgs.exe"="C:\Program Files\Messenger\msmsgs.exe:*:Enabled:Windows Messenger"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
======List of files/folders created in the last 3 months======
2009-03-08 10:00:54 ----A---- C:\Rooter.txt
2009-03-08 10:00:19 ----D---- C:\Rooter$
2009-03-06 17:38:11 ----D---- C:\Program Files\Stamina
2009-03-06 17:21:40 ----D---- C:\WINDOWS\system32\Adobe
2009-03-05 00:21:22 ----D---- C:\Documents and Settings\All Users\Application Data\SUPERAntiSpyware.com
2009-03-05 00:21:07 ----D---- C:\Program Files\SUPERAntiSpyware
2009-03-05 00:21:07 ----D---- C:\Documents and Settings\judy\Application Data\SUPERAntiSpyware.com
2009-03-04 22:31:08 ----D---- C:\Program Files\Avira
2009-03-04 22:31:08 ----D---- C:\Documents and Settings\All Users\Application Data\Avira
2009-03-04 19:39:04 ----D---- C:\Documents and Settings\judy\Application Data\Malwarebytes
2009-03-04 19:38:57 ----D---- C:\Program Files\Malwarebytes' Anti-Malware
2009-03-04 19:38:57 ----D---- C:\Documents and Settings\All Users\Application Data\Malwarebytes
2009-03-04 18:56:23 ----D---- C:\Program Files\Common Files\Wise Installation Wizard
2009-03-04 18:55:25 ----D---- C:\Program Files\Trend Micro
2009-03-04 17:54:23 ----D---- C:\Program Files\CCleaner
2009-03-03 11:42:37 ----A---- C:\WINDOWS\system32\javaws.exe
2009-03-03 11:42:36 ----A---- C:\WINDOWS\system32\javaw.exe
2009-03-03 11:42:36 ----A---- C:\WINDOWS\system32\java.exe
2009-03-03 11:42:11 ----D---- C:\Program Files\Java
2009-02-25 19:27:52 ----D---- C:\Program Files\Common Files\Adobe AIR
2009-02-18 16:37:22 ----D---- C:\Documents and Settings\judy\Application Data\gtk-2.0
2009-02-18 14:14:28 ----D---- C:\Program Files\Yahoo!
2009-02-10 10:06:26 ----A---- C:\WINDOWS\system32\sysguard.exe
2009-02-09 14:54:40 ----A---- C:\WINDOWS\WORDPAD.INI
2009-02-09 14:18:24 ----AD---- C:\Documents and Settings\All Users\Application Data\TEMP
2009-02-06 18:16:23 ----HD---- C:\$AVG8.VAULT$
2009-01-09 09:43:48 ----A---- C:\WINDOWS\system32\HSF_INST.dll
2009-01-08 21:20:23 ----A---- C:\WINDOWS\ModemLog_Agere Win Modem.txt
2009-01-04 09:49:55 ----D---- C:\rsit
2008-12-31 10:29:41 ----A---- C:\WINDOWS\ModemLog_PCI Soft Voice SoftRing Modem.txt
2008-12-12 10:31:34 ----A---- C:\WINDOWS\system32\deploytk.dll
2008-12-10 18:50:22 ----D---- C:\WINDOWS\system32\FlashAX
2008-12-10 18:49:44 ----D---- C:\Documents and Settings\All Users\Application Data\Microgaming
2008-12-10 18:49:44 ----D---- C:\Documents and Settings\All Users\Application Data\MGS
======List of files/folders modified in the last 3 months======
2009-03-08 10:00:33 ----D---- C:\WINDOWS\Prefetch
2009-03-08 09:44:05 ----D---- C:\WINDOWS\system32\CatRoot2
2009-03-08 09:21:41 ----D---- C:\WINDOWS\system32
2009-03-08 09:21:40 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI
2009-03-08 09:20:09 ----D---- C:\WINDOWS\Temp
2009-03-07 23:38:14 ----A---- C:\WINDOWS\SchedLgU.Txt
2009-03-07 20:44:58 ----D---- C:\WINDOWS
2009-03-06 17:38:11 ----RD---- C:\Program Files
2009-03-06 17:21:50 ----SD---- C:\WINDOWS\Downloaded Program Files
2009-03-05 00:21:14 ----SHD---- C:\WINDOWS\Installer
2009-03-04 22:31:11 ----D---- C:\WINDOWS\system32\drivers
2009-03-04 19:13:15 ----D---- C:\Documents and Settings\All Users\Application Data\avg8
2009-03-04 19:10:58 ----SD---- C:\Documents and Settings\judy\Application Data\Microsoft
2009-03-04 18:56:23 ----D---- C:\Program Files\Common Files
2009-03-04 17:57:02 ----D---- C:\WINDOWS\Minidump
2009-03-04 17:57:02 ----D---- C:\WINDOWS\Debug
2009-03-01 00:00:39 ----A---- C:\WINDOWS\win.ini
2009-02-26 10:31:10 ----D---- C:\Documents and Settings\All Users\Application Data\NOS
2009-02-25 19:34:10 ----D---- C:\Program Files\Adobe
2009-02-25 19:34:08 ----D---- C:\Documents and Settings\All Users\Application Data\Adobe
2009-02-25 11:30:09 ----HD---- C:\WINDOWS\inf
2009-02-25 11:29:56 ----RSHDC---- C:\WINDOWS\system32\dllcache
2009-02-25 10:57:51 ----HD---- C:\WINDOWS\$hf_mig$
2009-02-11 13:14:51 ----D---- C:\Program Files\Internet Explorer
2009-02-03 18:21:12 ----A---- C:\WINDOWS\system32\MRT.exe
2009-01-16 22:35:14 ----A---- C:\WINDOWS\system32\mshtml.dll
2009-01-08 21:22:05 ----D---- C:\WINDOWS\system32\CatRoot
2009-01-08 21:20:09 ----A---- C:\WINDOWS\ModemLog_Lucent Win Modem.txt
2009-01-08 21:20:05 ----D---- C:\WINDOWS\system32\ReinstallBackups
2009-01-07 13:35:42 ----D---- C:\Program Files\Google
2009-01-07 10:25:03 ----D---- C:\Documents and Settings\All Users\Application Data\Google
2008-12-28 19:15:03 ----SHD---- C:\System Volume Information
2008-12-28 19:15:03 ----D---- C:\WINDOWS\system32\Restore
2008-12-20 18:15:41 ----A---- C:\WINDOWS\system32\wininet.dll
2008-12-20 18:15:40 ----A---- C:\WINDOWS\system32\webcheck.dll
2008-12-20 18:15:40 ----A---- C:\WINDOWS\system32\urlmon.dll
2008-12-20 18:15:39 ----A---- C:\WINDOWS\system32\url.dll
2008-12-20 18:15:38 ----N---- C:\WINDOWS\system32\occache.dll
2008-12-20 18:15:38 ----A---- C:\WINDOWS\system32\pngfilt.dll
2008-12-20 18:15:32 ----N---- C:\WINDOWS\system32\mstime.dll
2008-12-20 18:15:31 ----N---- C:\WINDOWS\system32\msrating.dll
2008-12-20 18:15:30 ----A---- C:\WINDOWS\system32\mshtmled.dll
2008-12-20 18:15:24 ----A---- C:\WINDOWS\system32\msfeedsbs.dll
2008-12-20 18:15:23 ----N---- C:\WINDOWS\system32\jsproxy.dll
2008-12-20 18:15:23 ----A---- C:\WINDOWS\system32\msfeeds.dll
2008-12-20 18:15:22 ----A---- C:\WINDOWS\system32\iertutil.dll
2008-12-20 18:15:21 ----N---- C:\WINDOWS\system32\iernonce.dll
2008-12-20 18:15:21 ----A---- C:\WINDOWS\system32\ieframe.dll
2008-12-20 18:15:16 ----N---- C:\WINDOWS\system32\iedkcs32.dll
2008-12-20 18:15:15 ----A---- C:\WINDOWS\system32\ieapfltr.dll
2008-12-20 18:15:14 ----N---- C:\WINDOWS\system32\ieaksie.dll
2008-12-20 18:15:14 ----N---- C:\WINDOWS\system32\ieakeng.dll
2008-12-20 18:15:13 ----N---- C:\WINDOWS\system32\extmgr.dll
2008-12-20 18:15:13 ----A---- C:\WINDOWS\system32\icardie.dll
2008-12-20 18:15:13 ----A---- C:\WINDOWS\system32\dxtrans.dll
2008-12-20 18:15:12 ----A---- C:\WINDOWS\system32\dxtmsft.dll
2008-12-20 18:15:11 ----A---- C:\WINDOWS\system32\advpack.dll
2008-12-20 09:30:31 ----SD---- C:\WINDOWS\Tasks
2008-12-19 04:10:15 ----N---- C:\WINDOWS\system32\ie4uinit.exe
2008-12-19 04:10:15 ----A---- C:\WINDOWS\system32\ieudinit.exe
2008-12-19 00:23:56 ----N---- C:\WINDOWS\system32\ieakui.dll
2008-12-18 23:04:09 ----D---- C:\WINDOWS\ie7updates
======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R1 avgio;avgio; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys []
R1 avipbb;avipbb; C:\WINDOWS\system32\DRIVERS\avipbb.sys [2008-10-30 75072]
R1 intelppm;Intel Processor Driver; C:\WINDOWS\System32\DRIVERS\intelppm.sys [2008-04-13 36352]
R1 SASDIFSV;SASDIFSV; \??\C:\Program Files\SUPERAntiSpyware\SASDIFSV.SYS []
R1 SASKUTIL;SASKUTIL; \??\C:\Program Files\SUPERAntiSpyware\SASKUTIL.sys []
R1 ssmdrv;ssmdrv; C:\WINDOWS\system32\DRIVERS\ssmdrv.sys [2007-03-01 28352]
R2 Fallback;Fallback; C:\WINDOWS\system32\DRIVERS\HSF_FALL.sys [2001-08-17 289887]
R2 Fsks;Fsks; C:\WINDOWS\system32\DRIVERS\HSF_FSKS.sys [2001-08-17 115807]
R2 K56;K56; C:\WINDOWS\system32\DRIVERS\HSF_K56K.sys [2001-08-17 391199]
R2 SoftFax;SoftFax; C:\WINDOWS\system32\DRIVERS\HSF_FAXX.sys [2001-08-17 199711]
R2 Tones;Tones; C:\WINDOWS\system32\DRIVERS\HSF_TONE.sys [2001-08-17 50751]
R2 V124;V124; C:\WINDOWS\system32\DRIVERS\HSF_V124.sys [2001-08-17 488383]
R3 avgntflt;avgntflt; \??\C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys []
R3 ltmodem5;Agere Modem Driver; C:\WINDOWS\System32\DRIVERS\ltmdmnt.sys [2003-12-12 652689]
R3 SASENUM;SASENUM; \??\C:\Program Files\SUPERAntiSpyware\SASENUM.SYS []
R3 usbhub;USB2 Enabled Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2008-04-13 59520]
R3 usbuhci;Microsoft USB Universal Host Controller Miniport Driver; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2008-04-13 20608]
S2 mdmxsdk;mdmxsdk; C:\WINDOWS\system32\DRIVERS\mdmxsdk.sys []
S3 basic2;basic2; C:\WINDOWS\system32\DRIVERS\HSF_BSC2.sys [2001-08-17 67167]
S3 es1371;Creative AudioPCI (ES1371,ES1373) (WDM); C:\WINDOWS\system32\drivers\es1371mp.sys [2007-11-21 37376]
S3 hsf_msft;hsf_msft; C:\WINDOWS\system32\DRIVERS\HSF_MSFT.sys [2001-08-17 542879]
S3 MODEMCSA;Unimodem Streaming Filter Device; C:\WINDOWS\system32\drivers\MODEMCSA.sys [2001-08-17 16128]
S3 Rksample;Rksample; C:\WINDOWS\system32\DRIVERS\HSF_SAMP.sys [2001-08-17 57471]
S3 RTL8023xp;Realtek 10/100/1000 PCI NIC Family NDIS XP Driver; C:\WINDOWS\System32\DRIVERS\Rtnicxp.sys [2008-02-25 105088]
S3 rtl8139;Realtek RTL8139(A/B/C)-based PCI Fast Ethernet Adapter NT Driver; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2004-08-04 20992]
S3 USBSTOR;USB Mass Storage Driver; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-13 26368]
S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys []
======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)======
R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Scheduler; C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865]
R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297]
R2 JavaQuickStarterService;Java Quick Starter; C:\Program Files\Java\jre6\bin\jqs.exe [2009-03-03 152984]
S3 gusvc;Google Updater Service; C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe [2009-01-07 137200]
-----------------EOF-----------------