That might have done the trick. Though I know I ran Malwarebytes a half dozen times and it found nothing; i'm not sure why it found 8 on this pass. I'm not asking why, just happy it found anything at all…
The PC seems sluggish but its older than I'm used to. Otherwise, it stays on the internet without any redirecting. I want to tentatively say it now works.
Here's the log files:
Malwarebytes' Anti-Malware 1.39
Database version: 2435
Windows 5.1.2600 Service Pack 3
7/15/2009 4:22:32 PM
mbam-log-2009-07-15 (16-22-32).txt
Scan type: Quick Scan
Objects scanned: 85020
Time elapsed: 3 minute(s), 9 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 1
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a77d3539-581d-450c-9e44-a84c415a6172} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\Environment\avapp (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Environment\avuninst (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
C:\Program Files\Common Files\Uninstall\PersonalAV (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
Files Infected:
C:\WINDOWS\system32\msxmlm.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\program files\common files\uninstall\personalav\Uninstall.lnk (Rogue.PersonalAntiVirus) -> Quarantined and deleted successfully.
______________________________________
OTL logfile created on: 7/15/2009 4:26:14 PM - Run 1
OTL by OldTimer - Version 3.0.7.1 Folder = C:\Documents and Settings\ADMIN\Desktop
Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 6.0.2900.5512)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
1022.73 Mb Total Physical Memory | 509.17 Mb Available Physical Memory | 49.79% Memory free
2.41 Gb Paging File | 1.97 Gb Available in Paging File | 81.96% Paging File free
Paging file location(s): C:\pagefile.sys 1536 3072 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 63.85 Gb Free Space | 85.69% Space Free | Partition Type: NTFS
Drive D: | 0.31 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: NONE-NONE
Current User Name: ADMIN
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
PRC - C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
PRC - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
PRC - C:\WINDOWS\Explorer.EXE (Microsoft Corporation)
PRC - C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
PRC - C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
PRC - C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
PRC - C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
PRC - C:\Program Files\Symantec\Symantec Endpoint Protection\SmcGui.exe (Symantec Corporation)
PRC - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Advanced Micro Devices Inc.)
PRC - C:\Program Files\AIM6\aim6.exe (AOL LLC)
PRC - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
PRC - C:\WINDOWS\System32\wbem\wmiprvse.exe (Microsoft Corporation)
PRC - C:\Documents and Settings\ADMIN\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe (ATI Technologies Inc.)
PRC - C:\Program Files\AIM6\aolsoftware.exe (AOL LLC)
========== Win32 Services (SafeList) ==========
SRV - (aspnet_state [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (Microsoft Corporation)
SRV - (Ati HotKey Poller [Auto | Running]) – C:\WINDOWS\System32\Ati2evxx.exe (ATI Technologies Inc.)
SRV - (ATI Smart [Auto | Stopped]) – C:\WINDOWS\System32\ati2sgag.exe ()
SRV - (ccEvtMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (ccSetMgr [Auto | Running]) – C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (Symantec Corporation)
SRV - (clr_optimization_v2.0.50727_32 [On_Demand | Stopped]) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (getPlus® Helper [On_Demand | Stopped]) – C:\Program Files\NOS\bin\getPlus_HelperSvc.exe (NOS Microsystems Ltd.)
SRV - (helpsvc [Auto | Running]) – C:\WINDOWS\PCHealth\HelpCtr\Binaries\pchsvc.dll (Microsoft Corporation)
SRV - (JavaQuickStarterService [Auto | Running]) – C:\Program Files\Java\jre6\bin\jqs.exe (Sun Microsystems, Inc.)
SRV - (LiveUpdate [On_Demand | Stopped]) – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_3.EXE (Symantec Corporation)
SRV - (SmcService [Auto | Running]) – C:\Program Files\Symantec\Symantec Endpoint Protection\Smc.exe (Symantec Corporation)
SRV - (SNAC [On_Demand | Stopped]) – C:\Program Files\Symantec\Symantec Endpoint Protection\SNAC.EXE (Symantec Corporation)
SRV - (SoundMAX Agent Service (default) [Auto | Running]) – C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe (Analog Devices, Inc.)
SRV - (Symantec AntiVirus [Auto | Running]) – C:\Program Files\Symantec\Symantec Endpoint Protection\Rtvscan.exe (Symantec Corporation)
SRV - (Viewpoint Manager Service [Auto | Running]) – C:\Program Files\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV - (aeaudio [On_Demand | Running]) – C:\WINDOWS\System32\drivers\aeaudio.sys (Andrea Electronics Corporation)
DRV - (ati2mtag [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (COH_Mon [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\COH_Mon.sys (Symantec Corporation)
DRV - (eeCtrl [System | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys (Symantec Corporation)
DRV - (EL2000 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\EL2K_XP.sys (3Com Corporation)
DRV - (EraserUtilRebootDrv [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys (Symantec Corporation)
DRV - (MidiSyn [On_Demand | Stopped]) – C:\WINDOWS\System32\drivers\MidiSyn.sys (Analog Devices Inc)
DRV - (NAVENG [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090715.016\NAVENG.SYS (Symantec Corporation)
DRV - (NAVEX15 [On_Demand | Running]) – C:\Program Files\Common Files\Symantec Shared\VirusDefs\20090715.016\NAVEX15.SYS (Symantec Corporation)
DRV - (Ptilink [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\ptilink.sys (Parallel Technologies, Inc.)
DRV - (Secdrv [On_Demand | Stopped]) – C:\WINDOWS\System32\DRIVERS\secdrv.sys (Macrovision Corporation, Macrovision Europe Limited, and Macrovision Japan and Asia K.K.)
DRV - (smwdm [On_Demand | Running]) – C:\WINDOWS\System32\drivers\smwdm.sys (Analog Devices, Inc.)
DRV - (SPBBCDrv [System | Running]) – C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCDrv.sys (Symantec Corporation)
DRV - (SRTSP [System | Running]) – C:\WINDOWS\System32\Drivers\SRTSP.SYS (Symantec Corporation)
DRV - (SRTSPL [On_Demand | Stopped]) – C:\WINDOWS\System32\Drivers\SRTSPL.SYS (Symantec Corporation)
DRV - (SRTSPX [System | Running]) – C:\WINDOWS\System32\Drivers\SRTSPX.SYS (Symantec Corporation)
DRV - (SymEvent [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMEVENT.SYS (Symantec Corporation)
DRV - (SYMREDRV [On_Demand | Running]) – C:\WINDOWS\System32\Drivers\SYMREDRV.SYS (Symantec Corporation)
DRV - (SYMTDI [System | Running]) – C:\WINDOWS\System32\Drivers\SYMTDI.SYS (Symantec Corporation)
DRV - (SysPlant [Boot | Running]) – C:\WINDOWS\SYSTEM32\Drivers\SysPlant.sys (Symantec Corporation)
DRV - (Teefer2 [On_Demand | Running]) – C:\WINDOWS\System32\DRIVERS\teefer2.sys (Symantec Corporation)
DRV - (WPS [System | Running]) – C:\WINDOWS\System32\drivers\wpsdrvnt.sys (Symantec Corporation)
DRV - (WpsHelper [On_Demand | Running]) – C:\WINDOWS\System32\drivers\WpsHelper.sys (Symantec Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.microsoft.com/isapi/redir.dll?p…&ar=msnhome
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.microsoft.com/isapi/redir.dll?p…amp;ar=iesearch
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.microsoft.com/isapi/redir.dll?p…ER}&ar=home
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF - HKLM\software\mozilla\Firefox\extensions\\[removed]: C:\Program Files\Java\jre6\lib\deploy\jqs\ff [2009/05/09 19:47:08 | 00,000,000 | —D | M]
O1 HOSTS File: (734 bytes) - C:\WINDOWS\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Adobe PDF Link Helper) - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated)
O2 - BHO: (AIM Toolbar Loader) - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (JQSIEStartDetectorImpl Class) - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll (Sun Microsystems, Inc.)
O3 - HKLM\..\Toolbar: (AIM Toolbar) - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [BluetoothAuthenticationAgent] C:\WINDOWS\System32\bthprops.CPL (Microsoft Corporation)
O4 - HKLM..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe (Symantec Corporation)
O4 - HKLM..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\SoundMAX\SMax4PNP.exe (Analog Devices, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre6\bin\jusched.exe (Sun Microsystems, Inc.)
O4 - HKCU..\Run: [Aim6] C:\Program Files\AIM6\aim6.exe (AOL LLC)
O4 - HKCU..\Run: [MSMSGS] C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: dontdisplaylastusername = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticecaption =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: legalnoticetext =
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: shutdownwithoutlogon = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: undockwithoutlogon = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Search - Reg Error: Value error. File not found
O9 - Extra Button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files\AIM Toolbar\aimtb.dll (AOL LLC.)
O9 - Extra 'Tools' menuitem : @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe (Microsoft Corporation)
O9 - Extra Button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\System32\wshbth.dll (Microsoft Corporation)
O15 - HKLM\..Trusted Domains: 1 domain(s) and sub-domain(s) not assigned to a zone.
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_13)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\http\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\http\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\https\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\ipp - No CLSID value found
O18 - Protocol\Handler\ipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp - No CLSID value found
O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files\Common Files\System\Ole DB\msdaipp.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\Explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\Ati2evxx.dll (ATI Technologies Inc.)
O24 - Desktop Components:0 (My Current Home Page) - About:Home
O31 - SafeBoot: AlternateShell - cmd.exe
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/30 17:35:55 | 00,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck) - File not found
O34 - HKLM BootExecute: (autochk) - C:\WINDOWS\System32\autochk.exe (Microsoft Corporation)
O34 - HKLM BootExecute: (*) - File not found
========== Files/Folders - Created Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/07/15 16:14:09 | 00,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/15 16:14:06 | 00,038,160 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/15 16:14:04 | 00,019,096 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/15 16:14:04 | 00,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2009/07/15 16:08:44 | 00,513,536 | —- | C] (OldTimer Tools) – C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2009/07/15 16:08:44 | 00,050,688 | —- | C] (Atribune.org) – C:\Documents and Settings\ADMIN\Desktop\ATF_Cleaner.exe
[2009/07/12 17:05:28 | 00,001,734 | —- | C] () – C:\Documents and Settings\ADMIN\Desktop\HijackThis.lnk
[2009/07/12 17:05:28 | 00,000,000 | —D | C] – C:\Program Files\Trend Micro
[2009/07/12 17:05:05 | 00,812,344 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\ADMIN\Desktop\HJTInstall.exe
[2009/07/12 16:16:53 | 00,000,000 | —D | C] – C:\Program Files\HijackThis
[2009/07/01 22:11:23 | 10,724,84352 | -HS- | C] () – C:\hiberfil.sys
[2009/07/01 21:07:04 | 00,000,000 | —D | C] – C:\WINDOWS\System32\appmgmt
[2009/07/01 20:58:29 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Uninstall
[2009/06/28 18:16:13 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irmon.dll
[2009/06/28 18:16:13 | 00,028,160 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irmon.dll
[2009/06/28 18:16:13 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\wshirda.dll
[2009/06/28 18:16:13 | 00,008,192 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\wshirda.dll
[2009/06/28 18:16:10 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\irftp.exe
[2009/06/28 18:16:10 | 00,151,552 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\irftp.exe
[2009/06/28 10:23:35 | 00,000,000 | —D | C] – C:\Documents and Settings\ADMIN\Local Settings\Application Data\Identities
[2009/06/23 22:16:15 | 00,000,000 | —D | C] – C:\Documents and Settings\ADMIN\Local Settings\Application Data\AIM Toolbar
[2009/06/23 10:24:55 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Software Update Utility
[2009/06/23 10:24:45 | 00,000,000 | —D | C] – C:\Program Files\AIM Toolbar
[2009/06/23 10:24:45 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2009/06/23 10:24:31 | 00,001,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
[2009/06/23 10:24:08 | 00,000,000 | —D | C] – C:\Documents and Settings\ADMIN\Local Settings\Application Data\AOL
[2009/06/23 10:23:41 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\AOL Downloads
[2009/06/17 12:52:23 | 00,000,000 | —D | C] – C:\WINDOWS\Sun
[2009/06/17 11:55:30 | 00,000,000 | —D | C] – C:\Documents and Settings\ADMIN\Application Data\Google
[2009/06/17 11:54:30 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe
[2009/06/17 11:54:30 | 00,000,000 | —D | C] – C:\Program Files\Adobe
[2009/06/17 11:54:02 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Adobe
[2009/06/17 11:53:59 | 00,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2009/06/17 11:53:16 | 00,000,000 | —D | C] – C:\Program Files\Google
[2009/06/17 11:53:12 | 00,000,000 | —D | C] – C:\Documents and Settings\ADMIN\Local Settings\Application Data\Adobe
[2009/06/17 11:52:59 | 00,000,000 | —D | C] – C:\Program Files\NOS
[2009/06/17 11:52:59 | 00,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\NOS
[2004/08/04 08:00:00 | 00,000,477 | —- | C] () – C:\WINDOWS\win.ini
[2004/08/04 08:00:00 | 00,000,231 | —- | C] () – C:\WINDOWS\system.ini
========== Files - Modified Within 30 Days ==========
[1 C:\WINDOWS\System32\*.tmp files]
[7 C:\WINDOWS\*.tmp files]
[2009/07/15 16:25:39 | 00,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2009/07/15 16:25:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2009/07/15 16:24:58 | 00,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2009/07/15 16:24:50 | 10,724,84352 | -HS- | M] () – C:\hiberfil.sys
[2009/07/15 16:23:22 | 04,280,518 | -H– | M] () – C:\Documents and Settings\ADMIN\Local Settings\Application Data\IconCache.db
[2009/07/15 16:14:09 | 00,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2009/07/15 11:23:54 | 00,513,536 | —- | M] (OldTimer Tools) – C:\Documents and Settings\ADMIN\Desktop\OTL.exe
[2009/07/15 11:22:46 | 00,050,688 | —- | M] (Atribune.org) – C:\Documents and Settings\ADMIN\Desktop\ATF_Cleaner.exe
[2009/07/13 13:36:34 | 00,038,160 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2009/07/13 13:36:12 | 00,019,096 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2009/07/12 17:05:28 | 00,001,734 | —- | M] () – C:\Documents and Settings\ADMIN\Desktop\HijackThis.lnk
[2009/07/12 17:03:08 | 00,812,344 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\ADMIN\Desktop\HJTInstall.exe
[2009/06/28 18:21:06 | 00,458,340 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2009/06/28 18:21:06 | 00,392,296 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2009/06/28 18:21:06 | 00,058,596 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2009/06/23 10:25:00 | 00,000,853 | -H– | M] () – C:\IPH.PH
[2009/06/23 10:24:31 | 00,001,634 | —- | M] () – C:\Documents and Settings\All Users\Desktop\AIM 6.lnk
========== LOP Check ==========
[2009/06/27 22:25:52 | 00,000,000 | RH-D | M] – C:\Documents and Settings\ADMIN\Application Data
[2009/02/01 13:02:51 | 00,000,000 | —D | M] – C:\Documents and Settings\ADMIN\Application Data\acccore
[2009/06/11 20:59:28 | 00,000,000 | —D | M] – C:\Documents and Settings\ADMIN\Application Data\ATI
[2009/06/27 23:07:23 | 00,000,000 | —D | M] – C:\Documents and Settings\ADMIN\Application Data\LimeWire
[2009/07/01 21:06:30 | 00,000,000 | RH-D | M] – C:\Documents and Settings\All Users\Application Data
[2009/01/31 18:00:47 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\acccore
[2009/06/23 10:24:45 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\AIM Toolbar
[2009/06/11 20:59:28 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\ATI
[2009/06/23 10:24:36 | 00,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Viewpoint
[2004/08/04 08:00:00 | 00,000,065 | RH– | M] () – C:\WINDOWS\Tasks\desktop.ini
[2009/07/15 16:25:09 | 00,000,006 | -H– | M] () – C:\WINDOWS\Tasks\SA.DAT
========== Purity Check ==========
< End of report >