I'd also like to express my appreciation for taking the time to help me. Here is the 'OTL' OTL log:
OTL logfile created on: 3/4/2010 10:43:38 PM - Run 1
OTL by OldTimer - Version 3.1.34.0 Folder = C:\Users\Ryan\Downloads
Windows Vista Home Premium Edition Service Pack 1 (Version = 6.0.6001) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18865)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 56.00% Memory free
5.00 Gb Paging File | 4.00 Gb Available in Paging File | 80.00% Paging File free
Paging file location(s): c:\pagefile.sys 2875 2875 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 326.48 Gb Total Space | 145.87 Gb Free Space | 44.68% Space Free | Partition Type: NTFS
Drive D: | 8.87 Gb Total Space | 1.20 Gb Free Space | 13.58% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: RYAN-PC
Current User Name: Ryan
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 14 Days
Output = Standard
Quick Scan
========== Processes (SafeList) ==========
PRC - [2010/03/04 22:42:22 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Ryan\Downloads\OTL.exe
PRC - [2010/02/18 08:38:29 | 000,908,248 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2009/11/24 17:51:40 | 000,081,000 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashDisp.exe
PRC - [2009/11/24 17:51:35 | 000,138,680 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashServ.exe
PRC - [2009/11/24 17:51:21 | 000,254,040 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
PRC - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
PRC - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
PRC - [2009/08/30 12:44:38 | 002,927,104 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2009/04/10 11:29:08 | 000,037,888 | —- | M] () – C:\Program Files\Winamp\winampa.exe
PRC - [2008/06/10 04:27:04 | 000,054,672 | —- | M] (Sun Microsystems, Inc.) – C:\Windows\System32\jureg.exe
PRC - [2008/02/12 16:18:30 | 000,132,384 | —- | M] (Affinegy Inc) – C:\Program Files\Clearwire\InstaLAN\AffinegyService.exe
PRC - [2008/02/12 16:18:28 | 000,611,616 | —- | M] (Affinegy Inc) – C:\Program Files\Clearwire\InstaLAN\InstaLAN.exe
PRC - [2008/01/18 22:33:28 | 000,151,552 | —- | M] (Microsoft Corporation) – C:\Windows\System32\schtasks.exe
PRC - [2007/10/25 05:52:08 | 004,702,208 | —- | M] (Realtek Semiconductor) – C:\Windows\RtHDVCpl.exe
PRC - [2007/10/10 19:51:55 | 000,039,792 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
PRC - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) – C:\Program Files\Symantec\LiveUpdate\AluSchedulerSvc.exe
PRC - [2007/05/28 10:57:54 | 000,275,968 | —- | M] (Rocket Division Software) – C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe
========== Modules (SafeList) ==========
MOD - [2010/03/04 22:42:22 | 000,554,496 | —- | M] (OldTimer Tools) – C:\Users\Ryan\Downloads\OTL.exe
MOD - [2008/01/18 22:36:26 | 000,038,912 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sfc_os.dll
MOD - [2008/01/18 22:35:12 | 002,085,888 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msi.dll
MOD - [2008/01/18 22:26:36 | 001,684,480 | —- | M] (Microsoft Corporation) – C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\comctl32.dll
MOD - [2006/11/02 03:46:13 | 000,004,608 | —- | M] (Microsoft Corporation) – C:\Windows\System32\sfc.dll
MOD - [2006/11/02 03:46:07 | 000,015,872 | —- | M] (Microsoft Corporation) – C:\Windows\System32\msiltcfg.dll
========== Win32 Services (SafeList) ==========
SRV - [2009/11/24 17:51:35 | 000,138,680 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\ashServ.exe – (avast! Antivirus)
SRV - [2009/11/24 17:51:21 | 000,254,040 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe – (avast! Mail Scanner)
SRV - [2009/11/24 17:48:48 | 000,352,920 | —- | M] (ALWIL Software) [On_Demand | Running] – C:\Program Files\Alwil Software\Avast4\ashWebSv.exe – (avast! Web Scanner)
SRV - [2009/11/24 17:43:56 | 000,018,752 | —- | M] (ALWIL Software) [Auto | Running] – C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe – (aswUpdSv)
SRV - [2008/02/12 16:18:30 | 000,132,384 | —- | M] (Affinegy Inc) [Auto | Running] – C:\Program Files\Clearwire\InstaLAN\AffinegyService.exe – (AffinegyService)
SRV - [2008/01/18 22:38:26 | 000,272,952 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2007/09/12 18:27:24 | 002,999,664 | —- | M] (Symantec Corporation) [On_Demand | Stopped] – C:\Program Files\Symantec\LiveUpdate\LuComServer_3_2.EXE – (LiveUpdate)
SRV - [2007/09/12 18:27:24 | 000,554,352 | —- | M] (Symantec Corporation) [Auto | Running] – C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe – (Automatic LiveUpdate Scheduler)
SRV - [2007/05/28 10:57:54 | 000,275,968 | —- | M] (Rocket Division Software) [Auto | Running] – C:\Program Files\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe – (StarWindServiceAE)
SRV - [2007/01/19 11:54:14 | 000,097,136 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\MSN Messenger\usnsvc.exe – (usnjsvc)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://ie.redirect.hp.com/svs/rdr?TYPE=3&a…&pf=desktop
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "www.google.com"
FF - prefs.js..extensions.enabledItems: [removed]:1.19
FF - prefs.js..extensions.enabledItems: [removed]:4.5
FF - prefs.js..extensions.enabledItems: {66B3427F-D646-4C0E-818C-F467B25B255E}:1.9.1
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/01/26 13:32:04 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/02/18 08:38:32 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.8\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/02/18 08:38:32 | 000,000,000 | —D | M]
[2008/08/27 07:48:50 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Extensions
[2010/02/19 07:55:57 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions
[2009/09/02 17:40:45 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2007/12/25 22:11:55 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\extensions\[removed]
[2008/12/12 12:23:54 | 000,002,158 | —- | M] () – C:\Users\Ryan\AppData\Roaming\Mozilla\Firefox\Profiles\9quraduu.default\searchplugins\MySpace.xml
[2008/12/12 16:01:37 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2008/08/27 07:48:43 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions\[removed]
[2008/09/03 18:11:24 | 000,054,600 | —- | M] (BitTorrent, Inc.) – C:\Program Files\Mozilla Firefox\plugins\npbittorrent.dll
[2007/07/18 12:19:40 | 002,998,784 | —- | M] (Tamarack Software, Inc.) – C:\Program Files\Mozilla Firefox\plugins\nptgeqplugin.dll
O1 HOSTS File: ([2010/02/19 08:10:12 | 000,381,542 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.123topsearch.com
O1 - Hosts: 127.0.0.1 123topsearch.com
O1 - Hosts: 127.0.0.1 www.132.com
O1 - Hosts: 127.0.0.1 132.com
O1 - Hosts: 127.0.0.1 www.136136.net
O1 - Hosts: 127.0.0.1 136136.net
O1 - Hosts: 127.0.0.1 www.163ns.com
O1 - Hosts: 13145 more lines…
O2 - BHO: (HP Print Enhancer) - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (HP Smart BHO Class) - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [Adobe Reader Speed Launcher] C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [avast!] C:\Program Files\Alwil Software\Avast4\ashDisp.exe (ALWIL Software)
O4 - HKLM..\Run: [InstaLAN] C:\Program Files\Clearwire\InstaLAN\InstaLAN.exe (Affinegy Inc)
O4 - HKLM..\Run: [NvCplDaemon] C:\Windows\System32\NvCpl.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [NvMediaCenter] C:\Windows\System32\NvMcTray.DLL (NVIDIA Corporation)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [SunJavaUpdateReg] C:\Windows\System32\jureg.exe (Sun Microsystems, Inc.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe ()
O4 - HKCU..\Run: [AlcoholAutomount] C:\Program Files\Alcohol Soft\Alcohol 52\axcmd.exe (Alcohol Soft Development Team)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [Messenger (Yahoo!)] C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe (Yahoo! Inc.)
O4 - HKLM..\RunOnce: [Launcher] C:\Windows\SMINST\Launcher.exe (soft thinks)
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office10\EXCEL.EXE (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\npjpi160_07.dll (Sun Microsystems, Inc.)
O9 - Extra Button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: real.com ([rhap-app-4-0] https in Trusted sites)
O15 - HKCU\..Trusted Domains: real.com ([rhapreg] https in Trusted sites)
O15 - HKCU\..Trusted Ranges: Range1 ([http] in Local intranet)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\MSN Messenger\msgrapp.8.1.0178.00.dll (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Ryan\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/08/30 06:05:48 | 000,000,074 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{aea993e7-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993e7-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = J:\autorun.exe – File not found
O33 - MountPoints2\{aea993f5-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993f5-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = K:\autorun.exe – File not found
O33 - MountPoints2\{aea993f7-534f-11dd-bb50-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{aea993f7-534f-11dd-bb50-001bb9d72e9e}\Shell\AutoRun\command - "" = L:\autorun.exe – File not found
O33 - MountPoints2\{ecc06527-7c4a-11de-bc68-001bb9d72e9e}\Shell - "" = AutoRun
O33 - MountPoints2\{ecc06527-7c4a-11de-bc68-001bb9d72e9e}\Shell\AutoRun\command - "" = M:\autoplay.exe – File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - comfile [open] – "%1" %*
O35 - exefile [open] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2009/10/27 12:50:50 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
OTL cannot create restorepoints on Vista OSs!
========== Files/Folders - Created Within 14 Days ==========
[2010/03/04 21:09:27 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2010/03/04 21:09:04 | 000,000,000 | —D | C] – C:\Program Files\ERUNT
[2010/03/03 19:45:27 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Roaming\Malwarebytes
[2010/03/03 19:45:23 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/03/03 19:45:22 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/03/03 19:45:21 | 000,019,160 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/03/03 19:45:21 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/02/19 07:47:30 | 000,000,000 | —D | C] – C:\Users\Ryan\AppData\Local\{66B3427F-D646-4C0E-818C-F467B25B255E}
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files - Modified Within 14 Days ==========
[2010/03/04 22:46:05 | 006,029,312 | -HS- | M] () – C:\Users\Ryan\ntuser.dat
[2010/03/04 22:41:22 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/03/04 22:41:21 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/03/04 22:41:21 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/03/04 22:41:16 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/03/04 22:40:27 | 000,524,288 | -HS- | M] () – C:\Users\Ryan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TMContainer00000000000000000001.regtrans-ms
[2010/03/04 22:40:27 | 000,065,536 | -HS- | M] () – C:\Users\Ryan\NTUSER.DAT{3a539871-6a70-11db-887c-d362bd253390}.TM.blf
[2010/03/04 22:40:17 | 002,942,467 | -H– | M] () – C:\Users\Ryan\AppData\Local\IconCache.db
[2010/03/04 21:09:05 | 000,000,735 | —- | M] () – C:\Users\Ryan\Desktop\NTREGOPT.lnk
[2010/03/04 21:09:05 | 000,000,716 | —- | M] () – C:\Users\Ryan\Desktop\ERUNT.lnk
[2010/03/04 04:29:25 | 000,000,680 | —- | M] () – C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2010/03/03 19:45:26 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/03/02 15:17:34 | 000,002,990 | —- | M] () – C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2010/02/25 18:52:13 | 000,021,504 | —- | M] () – C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/02/21 09:14:30 | 000,184,921 | —- | M] () – C:\Users\Ryan\Documents\GED.xps
[2010/02/20 07:42:15 | 000,000,120 | —- | M] () – C:\Users\Ryan\AppData\Local\Gpozahi.dat
[2010/02/20 07:42:13 | 000,000,000 | —- | M] () – C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
[2010/02/19 08:10:12 | 000,381,542 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/02/19 07:44:06 | 000,000,024 | —- | M] () – C:\Users\Ryan\AppData\Roaming\cqfyto.dat
[5 C:\Windows\System32\*.tmp files -> C:\Windows\System32\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/03/04 21:09:05 | 000,000,735 | —- | C] () – C:\Users\Ryan\Desktop\NTREGOPT.lnk
[2010/03/04 21:09:05 | 000,000,716 | —- | C] () – C:\Users\Ryan\Desktop\ERUNT.lnk
[2010/03/03 19:45:26 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/02/21 09:14:28 | 000,184,921 | —- | C] () – C:\Users\Ryan\Documents\GED.xps
[2010/02/19 07:47:30 | 000,000,120 | —- | C] () – C:\Users\Ryan\AppData\Local\Gpozahi.dat
[2010/02/19 07:47:30 | 000,000,000 | —- | C] () – C:\Users\Ryan\AppData\Local\Oduvoyamuzage.bin
[2010/02/19 07:43:47 | 000,000,024 | —- | C] () – C:\Users\Ryan\AppData\Roaming\cqfyto.dat
[2010/01/07 21:48:54 | 000,040,960 | —- | C] () – C:\Windows\System32\B11gUSB.dll
[2009/12/08 16:52:36 | 000,000,376 | —- | C] () – C:\Windows\ODBC.INI
[2009/12/03 16:33:45 | 000,085,504 | —- | C] () – C:\Windows\System32\ff_vfw.dll
[2009/09/01 14:47:37 | 000,002,990 | —- | C] () – C:\Users\Ryan\AppData\Roaming\wklnhst.dat
[2008/09/11 21:49:37 | 000,765,952 | —- | C] () – C:\Windows\System32\xvidcore.dll
[2008/09/11 21:49:37 | 000,180,224 | —- | C] () – C:\Windows\System32\xvidvfw.dll
[2008/08/16 21:19:39 | 000,069,632 | —- | C] () – C:\Windows\System32\xmltok.dll
[2008/08/16 21:19:39 | 000,036,864 | —- | C] () – C:\Windows\System32\xmlparse.dll
[2008/07/16 09:54:28 | 000,721,904 | —- | C] () – C:\Windows\System32\drivers\sptd.sys
[2008/03/11 00:58:50 | 000,000,092 | —- | C] () – C:\Users\Ryan\AppData\Local\fusioncache.dat
[2008/01/12 14:35:32 | 000,021,504 | —- | C] () – C:\Users\Ryan\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2008/01/02 22:48:09 | 000,008,245 | —- | C] () – C:\ProgramData\LUUnInstall.LiveUpdate
[2007/12/27 09:31:20 | 000,000,680 | —- | C] () – C:\Users\Ryan\AppData\Local\d3d9caps.dat
[2007/08/30 05:56:00 | 000,002,085 | —- | C] () – C:\ProgramData\hpzinstall.log
[2007/08/30 05:40:05 | 000,102,400 | —- | C] () – C:\Windows\System32\pywintypes25.dll
[2007/08/30 05:40:04 | 000,327,680 | —- | C] () – C:\Windows\System32\pythoncom25.dll
[2007/07/19 09:07:52 | 000,000,000 | —- | C] () – C:\Windows\System32\px.ini
[2006/12/14 00:01:36 | 000,520,192 | —- | C] () – C:\Windows\System32\CddbPlaylist2Roxio.dll
[2006/12/14 00:01:36 | 000,204,800 | —- | C] () – C:\Windows\System32\CddbFileTaggerRoxio.dll
[2006/11/02 06:35:32 | 000,005,632 | —- | C] () – C:\Windows\System32\sysprepMCE.dll
[2006/11/02 01:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2010/03/02 15:25:36 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\BitTorrent
[2009/09/12 06:48:39 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\COWON
[2009/07/29 08:27:32 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\DAEMON Tools Lite
[2008/07/16 10:04:33 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Firaxis Games
[2010/02/04 09:19:23 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\FrostWire
[2008/03/11 00:58:55 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\GetRightToGo
[2009/01/26 21:34:49 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\LimeWire
[2009/12/03 16:36:45 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Media Control
[2008/12/12 15:38:41 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\ODF
[2008/12/12 16:04:03 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\OpenOffice.org
[2010/02/02 12:42:20 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\runic games
[2007/12/25 16:34:10 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Snapfish
[2009/09/01 14:47:38 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Template
[2008/03/11 00:58:57 | 000,000,000 | —D | M] – C:\Users\Ryan\AppData\Roaming\Turbine
[2010/03/04 22:40:20 | 000,032,584 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_f750e484\AGP440.sys
[2008/01/18 22:42:26 | 000,056,376 | —- | M] (Microsoft Corporation) MD5=13F9E33747E6B41A3FF305C37DB0D360 – C:\Windows\winsxs\x86_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_ba12ed3bbeb0d97a\AGP440.sys
[2006/11/02 03:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\drivers\AGP440.sys
[2006/11/02 03:49:52 | 000,053,864 | —- | M] (Microsoft Corporation) MD5=EF23439CDD587F64C2C1B8825CEAD7D8 – C:\Windows\System32\DriverStore\FileRepository\machine.inf_920a2c1f\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_ecc53ff9\atapi.sys
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=224505155EC3E36D7A1F36E446F04C2A – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.16584_none_daff695624a08568\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\drivers\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_cc18792d\atapi.sys
[2008/01/18 22:41:32 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=2D9C903DC76A66813D350A562DE40ED9 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_dd38281a2189ce9c\atapi.sys
[2006/11/02 03:49:36 | 000,019,048 | —- | M] (Microsoft Corporation) MD5=4F4FCB8B6EA06784FB6D475B7EC7300F – C:\Windows\System32\DriverStore\FileRepository\mshdc.inf_c6c2e699\atapi.sys
[2008/01/15 23:43:00 | 000,021,560 | —- | M] (Microsoft Corporation) MD5=BFD3DF48C9ED81934FE21E8E3CFC2496 – C:\Windows\winsxs\x86_mshdc.inf_31bf3856ad364e35_6.0.6000.20707_none_dbe288453d7a8ed6\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 03:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\System32\cngaudit.dll
[2006/11/02 03:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_c9df7691\iaStorV.sys
[2008/01/18 22:42:52 | 000,235,064 | —- | M] (Intel Corporation) MD5=54155EA1B0DF185878E0FC9EC3AC3A14 – C:\Windows\winsxs\x86_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_af11527887c7fa8f\iaStorV.sys
[2006/11/02 03:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\drivers\iaStorV.sys
[2006/11/02 03:51:25 | 000,232,040 | —- | M] (Intel Corporation) MD5=C957BF4B5D80B46C5017BF0101E6C906 – C:\Windows\System32\DriverStore\FileRepository\iastorv.inf_37cdafa4\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2006/11/02 03:46:11 | 000,559,616 | —- | M] (Microsoft Corporation) MD5=889A2C9F2AACCD8F64EF50AC0B3D553B – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6000.16386_none_fb80f5473b0ed783\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\System32\netlogon.dll
[2008/01/18 22:35:38 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\x86_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_fdb7b74337f9e857\netlogon.dll
< MD5 for: NVRD32.SYS >
[2007/10/26 18:51:26 | 000,131,616 | —- | M] (NVIDIA Corporation) MD5=049E81B6FB41C73619ED3FE4DF7D8638 – C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvrd32.sys
< MD5 for: NVSTOR.SYS >
[2006/11/02 03:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\drivers\nvstor.sys
[2006/11/02 03:50:13 | 000,040,040 | —- | M] (NVIDIA Corporation) MD5=9E0BA19A28C498A6D323D065DB76DFFC – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_733654ff\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\System32\DriverStore\FileRepository\nvraid.inf_31c3d71d\nvstor.sys
[2008/01/18 22:42:10 | 000,045,112 | —- | M] (NVIDIA Corporation) MD5=ABED0C09758D1D97DB0042DBB2688177 – C:\Windows\winsxs\x86_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_39dac327befea467\nvstor.sys
< MD5 for: NVSTOR32.SYS >
[2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\Windows\System32\drivers\nvstor32.sys
[2007/10/26 18:51:24 | 000,110,624 | —- | M] (NVIDIA Corporation) MD5=7EBA6C9A0A295B1559EFB9062E701218 – C:\Windows\System32\DriverStore\FileRepository\nvrd32.inf_0f6358b4\nvstor32.sys
[2007/07/02 11:37:08 | 000,110,112 | —- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D – C:\hp\DRIVERS\NVIDIA_Serial_ATA\nvstor32.sys
[2007/07/02 11:37:08 | 000,110,112 | —- | M] (NVIDIA Corporation) MD5=A1CE1A6FD74C046F029448FCFA5E386D – C:\Windows\System32\DriverStore\FileRepository\nvstor32.inf_6b03e392\nvstor32.sys
< MD5 for: SCECLI.DLL >
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\System32\scecli.dll
[2008/01/18 22:36:20 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_380de25bd91b6f12\scecli.dll
[2006/11/02 03:46:12 | 000,176,640 | —- | M] (Microsoft Corporation) MD5=80E2839D05CA5970A86D7BE2A08BFF61 – C:\Windows\winsxs\x86_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6000.16386_none_35d7205fdc305e3e\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/01/18 22:38:04 | 000,242,744 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2008/01/18 22:36:12 | 000,225,792 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\SLC.dll
[5 C:\Windows\system32\*.tmp files -> C:\Windows\system32\*.tmp -> ]
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
[2009/07/28 20:51:05 | 000,721,904 | —- | M] ()
Unable to obtain MD5 – C:\Windows\System32\drivers\sptd.sys
< %systemroot%\System32\config\*.sav >
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 04:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 04:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 04:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 04:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< End of report >