This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Virtumonde

19 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Im sure its easier than I think to get rid of this thing but It seems Daunting. I ran the hijack this, this is the log. I have spybot and Maleaware bytes, And Im pretty sure I have the most recent updates, but it isnt registering that I am infected, yet I can see a ton of its .dll 's and other bits of it on my system. Please help! thanks

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
C:\Program Files\Acer\Acer VCM\RS_Service.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
C:\WINDOWS\RTHDCPL.EXE
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\WINDOWS\system32\igfxext.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\iPod\bin\iPodService.exe
C:\DOCUME~1\New\LOCALS~1\Temp\RtkBtMnt.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Safari\Safari.exe
C:\DOCUME~1\New\LOCALS~1\Temp\tlsgap8l.tmp\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe
O4 - HKLM\..\Run: [snp2uvc] rundll32.exe C:\WINDOWS\system32\csnp2uvc.dll,ResetCIDS
O4 - HKLM\..\Run: [NotificationCenterLauncher] C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"
O4 - Startup: OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Startup: ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe
O4 - Global Startup: Acer VCM.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe

–
End of file - 8006 bytes
Hello Sanatarius and Posted Image

My name is patndoris. I will be glad to take a look at your log and help you with solving any malware problems. It will be very helpful if you follow these guidelines:
  • Malware logs are often lengthy and can take a lot of time to research and interpret. Please be patient while I review your logs.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Please make sure to carefully read any instruction that I give you. If you're not sure, or if something unexpected happens, do NOT continue! Stop and ask!
  • Please follow my instructions carefully and in the order they are posted. You may also find it helpful to print out the instructions you receive.
  • Please do not run any scans or install/uninstall any applications or delete anything without being directed to do so.
  • Remember, absence of symptoms does not mean the infection is all gone. Please stick with me till you're given the "all clear".
  • Please do not use the Attachment feature for any log file. Do a Copy/Paste of the entire contents of the log file and submit it inside your post.
  • Please reply within 3 days. If I do not hear back from you in that time frame, I will post a reminder for you. Topics with no reply in 4 days are closed!
Please be advised I am still in training, and all of my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice.
This may cause a delay in response time, but I will do my best to keep it as short as possible.

HijackThis has largely been replaced by other tools. Since being acquired by TrendMicro, HijackThis has not been regularly updated. Many infections are now able to hide partly, or completely from a HijackThis scan. OTL ncludes all the scan locations of HijackThis and more. It's not only a more comprehensive scan tool, but also offers more powerful removal features.

Download and Run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Under the Custom Scan box paste this in:

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    eventlog.dll
    scecli.dll
    netlogon.dll
    cngaudit.dll
    sceclt.dll
    ntelogon.dll
    logevent.dll
    iaStor.sys
    nvstor.sys
    atapi.sys
    IdeChnDr.sys
    viasraid.sys
    AGP440.sys
    vaxscsi.sys
    nvatabus.sys
    viamraid.sys
    nvata.sys
    nvgts.sys
    iastorv.sys
    ViPrt.sys
    eNetHook.dll
    ahcix86.sys
    KR10N.sys
    nvstor32.sys
    ahcix86s.sys
    nvrd32.sys
    symmpi.sys
    adp3132.sys
    mv61xx.sys
    /md5stop
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\system32\*.dll /lockedfiles
    %systemroot%\Tasks\*.job /lockedfiles
    %systemroot%\system32\drivers\*.sys /lockedfiles
    %systemroot%\system32\drivers\*.sys /90
    %systemroot%\System32\config\*.sav

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.

If you have CDEmulation drivers installed (such as Daemon Tools, Alcohol120) please follow the instructions below to run DeFogger prior to and after running GMER. If you do not have any CDEmulation drivers installed, you do not need to run DeFogger and you can go right to the instructions to run GMER.

Download DeFogger

Please download DeFogger to your desktop.

Double click DeFogger to run the tool.
  • The application window will appear
  • Click the Disable button to disable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_disable which will appear on your desktop.

Do not re-enable these drivers until otherwise instructed.

Download and Run GMER

[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
Extras

OTL logfile created on: 5/7/2010 9:32:49 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\New\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 85.26 Gb Free Space | 59.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JEREMY
Current User Name: New
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
PRC - [2010/05/07 21:06:01 | 000,119,808 | —- | M] (Atribune.org) – C:\Documents and Settings\New\Local Settings\Temp\sie19t5x.tmp\VundoFix.exe
PRC - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2010/03/24 20:31:00 | 002,145,000 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/04 03:33:50 | 001,795,880 | —- | M] (Apple Inc.) – C:\Program Files\Safari\Safari.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/01/16 20:41:00 | 000,212,992 | —- | M] (Realtek Semiconductor Corp.) – C:\Documents and Settings\New\Local Settings\Temp\RtkBtMnt.exe
PRC - [2008/12/30 03:09:52 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/27 21:00:10 | 000,170,520 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxext.exe


========== Modules (SafeList) ==========

MOD - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
MOD - [2008/04/14 08:00:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/03/24 20:39:48 | 000,033,560 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EHttpSrv)
SRV - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn)
SRV - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - [2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)
DRV - [2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)
DRV - [2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)
DRV - [2008/12/26 05:27:26 | 004,968,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/11/20 05:39:36 | 000,204,464 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2008/09/23 13:15:00 | 000,038,400 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/08/14 21:54:18 | 001,318,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2008/04/14 08:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2008/04/14 08:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/14 08:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2008/04/14 08:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2008/04/14 08:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2008/04/14 08:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2008/04/14 08:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2008/04/14 08:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2008/04/14 08:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2008/04/14 08:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2008/04/14 08:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2008/04/14 08:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2008/04/14 08:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2008/04/14 08:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2008/04/14 08:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2008/04/14 04:06:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/14 04:06:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/14 00:15:14 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/02/14 19:12:06 | 005,854,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2007/10/01 14:59:46 | 001,769,984 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\snp2uvc.sys – (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2006/11/02 09:27:34 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2004/12/08 02:10:00 | 000,016,896 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/05/07 20:42:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NotificationCenterLauncher] C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe (Acer)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.DLL ( )
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/16 19:34:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/01/16 19:33:41 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/07 21:31:13 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:28:06 | 000,000,000 | —D | C] – C:\VundoFix Backups
[2010/05/07 21:01:29 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop\undll
[2010/05/07 20:52:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:43:02 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/05/07 20:35:05 | 000,000,000 | —D | C] – C:\Program Files\Eset undll
[2010/05/05 19:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\WMTools Downloaded Files
[2010/05/05 19:31:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/05/03 22:58:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/03 22:57:49 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/03 22:57:32 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/02 23:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Malwarebytes
[2010/05/02 23:25:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/02 23:25:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/02 23:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AskToolbar
[2010/05/02 22:30:28 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/05/02 22:22:27 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/05/02 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/02 22:21:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\uTorrent
[2010/04/26 23:51:09 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2010/04/26 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\ZooskMessenger
[2010/04/26 23:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/04/25 23:35:55 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\OpenOffice.org
[2010/04/25 23:34:22 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/04/25 23:34:16 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/04/25 23:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/25 23:33:31 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Sun
[2010/04/25 23:15:07 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/04/25 23:15:07 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/04/24 10:54:19 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/04/24 10:54:17 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/04/24 10:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Mozilla
[2010/04/24 10:37:22 | 000,000,000 | —D | C] – C:\Program Files\TuneUpMedia
[2010/04/20 08:30:45 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/04/20 08:30:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/04/20 08:30:43 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/04/17 22:31:24 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/04/17 22:31:19 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/04/17 22:31:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/04/17 22:30:50 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/04/17 22:30:50 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/04/17 22:30:50 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/04/17 22:30:50 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/04/17 22:30:50 | 000,000,000 | —D | C] – C:\7deeaa03f7a0b712ef2491cca1fe
[2010/04/17 22:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Adobe
[2010/04/17 22:14:39 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2010/04/17 21:08:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2010/04/17 02:41:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/04/17 02:40:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/04/17 02:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/04/17 02:36:45 | 000,000,000 | —D | C] – C:\WINDOWS\BTW
[2010/04/17 02:34:34 | 000,286,720 | —- | C] (Sonix) – C:\WINDOWS\System32\vsnp2uvc.dll
[2010/04/17 02:34:34 | 000,196,608 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2010/04/17 02:34:34 | 000,094,208 | —- | C] (sonix) – C:\WINDOWS\PLFSetL.exe
[2010/04/17 02:34:31 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\WINDOWS\SUYIN NB Cam
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SNP2UVC
[2010/04/17 02:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Acer
[2010/04/17 02:33:24 | 000,000,000 | –SD | C] – C:\Documents and Settings\New\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\SendTo
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Recent
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Application Data
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Start Menu
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Pictures
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Music
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Favorites
[2010/04/17 02:33:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\New\Cookies
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Templates
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\PrintHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\NetHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Local Settings
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft Help
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Macromedia
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\InstallShield
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Identities
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Google
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Adobe
[2010/04/17 02:28:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/04/16 23:46:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\TuneUpMedia
[2010/04/16 23:46:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUpMedia
[2010/04/16 23:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Songs
[2010/04/16 23:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\School Notes & Classes
[2010/04/16 23:37:13 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Videos
[2010/04/16 23:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Research, Intellectual Growth
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Tabs
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Lyrics
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Downloads
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Bands
[2010/04/16 23:36:11 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/04/16 23:35:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AWC
[2010/04/16 23:35:07 | 000,671,744 | —- | C] (Steve Murphy Software) – C:\WINDOWS\System32\AWC_SS.scr
[2010/04/16 23:35:05 | 002,420,736 | —- | C] (FreeImage) – C:\WINDOWS\System32\FreeImage.dll
[2010/04/16 23:35:05 | 000,167,936 | —- | C] (Common Controls Replacement Project (CCRP)) – C:\WINDOWS\System32\ccrpftv6.ocx
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (Jeremy Adams, CCRP) – C:\WINDOWS\System32\ccrpUCW6.dll
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (CCRP) – C:\WINDOWS\System32\ccrpDtp6.ocx
[2010/04/16 23:35:05 | 000,090,112 | —- | C] (http://www.mvps.org/vb) – C:\WINDOWS\System32\ccrpTmr6.dll
[2010/04/16 23:35:05 | 000,086,016 | —- | C] (CCRP / ECX Programming) – C:\WINDOWS\System32\ccrpudn6.ocx
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\SSubTmr6.dll
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (The Lillypad) – C:\WINDOWS\System32\DLLDesktop.dll
[2010/04/16 23:35:05 | 000,036,864 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\AlphaImageCreator.dll
[2010/04/16 23:35:04 | 000,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TABCTL32.OCX
[2010/04/16 23:35:04 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\RICHTX32.OCX
[2010/04/16 23:35:04 | 000,000,000 | —D | C] – C:\Program Files\AWC
[2010/04/16 23:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\skypePM
[2010/04/16 23:27:32 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Skype
[2010/04/16 23:27:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/04/16 23:27:21 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/04/16 23:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/16 23:11:59 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/04/16 23:11:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/16 23:10:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/16 23:10:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/04/16 23:10:23 | 003,003,680 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/04/16 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple Computer
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Apple Computer
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/16 22:57:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/16 22:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple
[2010/04/16 22:56:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/16 22:44:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/16 22:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/01/16 19:19:00 | 000,049,152 | —- | C] ( ) – C:\WINDOWS\Interop.IWshRuntimeLibrary.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:27:36 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/05/07 21:01:27 | 001,835,008 | -H– | M] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/05/07 21:01:01 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/07 20:53:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:25:51 | 000,008,007 | —- | M] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/06 18:38:03 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 15:09:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/05 22:11:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 20:43:37 | 000,006,144 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/03 22:57:36 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:36 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:36 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/02 23:25:51 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 23:03:23 | 000,511,030 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 23:03:23 | 000,434,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 23:03:23 | 000,068,386 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 22:59:33 | 000,000,706 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/05/02 22:59:15 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/02 22:59:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/02 22:59:10 | 000,272,576 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/02 22:59:09 | 2136,940,544 | -HS- | M] () – C:\hiberfil.sys
[2010/05/02 22:58:34 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\New\ntuser.ini
[2010/05/02 22:22:14 | 000,000,634 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 11:02:08 | 000,066,056 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/26 09:42:12 | 000,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Works.lnk
[2010/04/25 23:55:37 | 000,059,844 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/25 23:36:25 | 000,000,868 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/21 14:59:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/18 16:45:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/17 02:36:47 | 000,002,001 | —- | M] () – C:\WINDOWS\CLEANUP.CMD
[2010/04/17 02:32:38 | 000,037,761 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/04/17 02:32:35 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:34 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/17 02:29:56 | 000,005,208 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2010/04/17 02:28:54 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/16 23:35:07 | 000,000,572 | —- | M] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:28:04 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:23:08 | 000,000,937 | —- | M] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:51:07 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/07 20:25:51 | 000,008,007 | —- | C] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/05 22:11:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 19:33:23 | 000,006,144 | —- | C] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/02 23:25:51 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 22:22:30 | 000,000,230 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/02 22:22:14 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/26 23:51:09 | 000,000,706 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/04/25 23:36:25 | 000,000,868 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/17 02:34:34 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/04/17 02:34:34 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2010/04/17 02:34:34 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2010/04/17 02:33:24 | 001,835,008 | -H– | C] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/04/17 02:33:24 | 000,020,480 | -H– | C] () – C:\Documents and Settings\New\ntuser.dat.LOG
[2010/04/17 02:33:24 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\New\ntuser.ini
[2010/04/17 02:32:35 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:35 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2010/04/17 02:28:54 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/17 02:27:40 | 2136,940,544 | -HS- | C] () – C:\hiberfil.sys
[2010/04/16 23:35:07 | 000,000,572 | —- | C] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:35:07 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\ndupoem.rst
[2010/04/16 23:28:04 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:27:25 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/16 23:23:08 | 000,000,937 | —- | C] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:12:01 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:57:49 | 000,059,844 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/16 22:57:35 | 000,002,187 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/16 22:57:02 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/16 21:24:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/16 20:27:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/01/16 19:37:00 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/01/16 19:31:35 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:AGP440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/04/15 05:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy64\IaStor.sys
[2008/04/15 21:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy32\IaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\OemDir\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\drivers\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\DRVSTORE\iaAHCI_E7EB69FF3449D216602D0D37A1D73969621673A9\iaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\eamon.sys
[2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\ehdrv.sys
[2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\epfwtdir.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys

< %systemroot%\System32\config\*.sav >
[2009/01/16 11:28:21 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/16 11:28:21 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/16 11:28:21 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
OTL logfile created on: 5/7/2010 9:32:49 PM - Run 1
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\New\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 85.26 Gb Free Space | 59.60% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JEREMY
Current User Name: New
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
PRC - [2010/05/07 21:06:01 | 000,119,808 | —- | M] (Atribune.org) – C:\Documents and Settings\New\Local Settings\Temp\sie19t5x.tmp\VundoFix.exe
PRC - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2010/03/24 20:31:00 | 002,145,000 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/04 03:33:50 | 001,795,880 | —- | M] (Apple Inc.) – C:\Program Files\Safari\Safari.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/01/16 20:41:00 | 000,212,992 | —- | M] (Realtek Semiconductor Corp.) – C:\Documents and Settings\New\Local Settings\Temp\RtkBtMnt.exe
PRC - [2008/12/30 03:09:52 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/27 21:00:10 | 000,170,520 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxext.exe


========== Modules (SafeList) ==========

MOD - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
MOD - [2008/04/14 08:00:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/03/24 20:39:48 | 000,033,560 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EHttpSrv)
SRV - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn)
SRV - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - [2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)
DRV - [2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)
DRV - [2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)
DRV - [2008/12/26 05:27:26 | 004,968,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/11/20 05:39:36 | 000,204,464 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2008/09/23 13:15:00 | 000,038,400 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/08/14 21:54:18 | 001,318,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2008/04/14 08:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2008/04/14 08:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/14 08:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2008/04/14 08:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2008/04/14 08:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2008/04/14 08:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2008/04/14 08:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2008/04/14 08:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2008/04/14 08:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2008/04/14 08:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2008/04/14 08:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2008/04/14 08:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2008/04/14 08:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2008/04/14 08:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2008/04/14 08:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2008/04/14 04:06:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/14 04:06:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/14 00:15:14 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/02/14 19:12:06 | 005,854,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2007/10/01 14:59:46 | 001,769,984 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\snp2uvc.sys – (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2006/11/02 09:27:34 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2004/12/08 02:10:00 | 000,016,896 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/05/07 20:42:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NotificationCenterLauncher] C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe (Acer)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.DLL ( )
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/16 19:34:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/01/16 19:33:41 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/07 21:31:13 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:28:06 | 000,000,000 | —D | C] – C:\VundoFix Backups
[2010/05/07 21:01:29 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop\undll
[2010/05/07 20:52:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:43:02 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/05/07 20:35:05 | 000,000,000 | —D | C] – C:\Program Files\Eset undll
[2010/05/05 19:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\WMTools Downloaded Files
[2010/05/05 19:31:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/05/03 22:58:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/03 22:57:49 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/03 22:57:32 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/02 23:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Malwarebytes
[2010/05/02 23:25:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/02 23:25:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/02 23:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AskToolbar
[2010/05/02 22:30:28 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/05/02 22:22:27 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/05/02 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/02 22:21:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\uTorrent
[2010/04/26 23:51:09 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2010/04/26 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\ZooskMessenger
[2010/04/26 23:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/04/25 23:35:55 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\OpenOffice.org
[2010/04/25 23:34:22 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/04/25 23:34:16 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/04/25 23:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/25 23:33:31 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Sun
[2010/04/25 23:15:07 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/04/25 23:15:07 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/04/24 10:54:19 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/04/24 10:54:17 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/04/24 10:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Mozilla
[2010/04/24 10:37:22 | 000,000,000 | —D | C] – C:\Program Files\TuneUpMedia
[2010/04/20 08:30:45 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/04/20 08:30:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/04/20 08:30:43 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/04/17 22:31:24 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/04/17 22:31:19 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/04/17 22:31:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/04/17 22:30:50 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/04/17 22:30:50 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/04/17 22:30:50 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/04/17 22:30:50 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/04/17 22:30:50 | 000,000,000 | —D | C] – C:\7deeaa03f7a0b712ef2491cca1fe
[2010/04/17 22:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Adobe
[2010/04/17 22:14:39 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2010/04/17 21:08:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2010/04/17 02:41:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/04/17 02:40:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/04/17 02:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/04/17 02:36:45 | 000,000,000 | —D | C] – C:\WINDOWS\BTW
[2010/04/17 02:34:34 | 000,286,720 | —- | C] (Sonix) – C:\WINDOWS\System32\vsnp2uvc.dll
[2010/04/17 02:34:34 | 000,196,608 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2010/04/17 02:34:34 | 000,094,208 | —- | C] (sonix) – C:\WINDOWS\PLFSetL.exe
[2010/04/17 02:34:31 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\WINDOWS\SUYIN NB Cam
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SNP2UVC
[2010/04/17 02:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Acer
[2010/04/17 02:33:24 | 000,000,000 | –SD | C] – C:\Documents and Settings\New\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\SendTo
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Recent
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Application Data
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Start Menu
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Pictures
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Music
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Favorites
[2010/04/17 02:33:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\New\Cookies
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Templates
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\PrintHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\NetHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Local Settings
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft Help
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Macromedia
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\InstallShield
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Identities
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Google
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Adobe
[2010/04/17 02:28:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/04/16 23:46:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\TuneUpMedia
[2010/04/16 23:46:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUpMedia
[2010/04/16 23:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Songs
[2010/04/16 23:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\School Notes & Classes
[2010/04/16 23:37:13 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Videos
[2010/04/16 23:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Research, Intellectual Growth
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Tabs
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Lyrics
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Downloads
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Bands
[2010/04/16 23:36:11 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/04/16 23:35:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AWC
[2010/04/16 23:35:07 | 000,671,744 | —- | C] (Steve Murphy Software) – C:\WINDOWS\System32\AWC_SS.scr
[2010/04/16 23:35:05 | 002,420,736 | —- | C] (FreeImage) – C:\WINDOWS\System32\FreeImage.dll
[2010/04/16 23:35:05 | 000,167,936 | —- | C] (Common Controls Replacement Project (CCRP)) – C:\WINDOWS\System32\ccrpftv6.ocx
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (Jeremy Adams, CCRP) – C:\WINDOWS\System32\ccrpUCW6.dll
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (CCRP) – C:\WINDOWS\System32\ccrpDtp6.ocx
[2010/04/16 23:35:05 | 000,090,112 | —- | C] (http://www.mvps.org/vb) – C:\WINDOWS\System32\ccrpTmr6.dll
[2010/04/16 23:35:05 | 000,086,016 | —- | C] (CCRP / ECX Programming) – C:\WINDOWS\System32\ccrpudn6.ocx
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\SSubTmr6.dll
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (The Lillypad) – C:\WINDOWS\System32\DLLDesktop.dll
[2010/04/16 23:35:05 | 000,036,864 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\AlphaImageCreator.dll
[2010/04/16 23:35:04 | 000,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TABCTL32.OCX
[2010/04/16 23:35:04 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\RICHTX32.OCX
[2010/04/16 23:35:04 | 000,000,000 | —D | C] – C:\Program Files\AWC
[2010/04/16 23:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\skypePM
[2010/04/16 23:27:32 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Skype
[2010/04/16 23:27:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/04/16 23:27:21 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/04/16 23:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/16 23:11:59 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/04/16 23:11:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/16 23:10:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/16 23:10:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/04/16 23:10:23 | 003,003,680 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/04/16 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple Computer
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Apple Computer
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/16 22:57:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/16 22:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple
[2010/04/16 22:56:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/16 22:44:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/16 22:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/01/16 19:19:00 | 000,049,152 | —- | C] ( ) – C:\WINDOWS\Interop.IWshRuntimeLibrary.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:27:36 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/05/07 21:01:27 | 001,835,008 | -H– | M] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/05/07 21:01:01 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/07 20:53:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:25:51 | 000,008,007 | —- | M] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/06 18:38:03 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 15:09:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/05 22:11:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 20:43:37 | 000,006,144 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/03 22:57:36 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:36 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:36 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/02 23:25:51 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 23:03:23 | 000,511,030 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 23:03:23 | 000,434,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 23:03:23 | 000,068,386 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 22:59:33 | 000,000,706 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/05/02 22:59:15 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/02 22:59:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/02 22:59:10 | 000,272,576 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/02 22:59:09 | 2136,940,544 | -HS- | M] () – C:\hiberfil.sys
[2010/05/02 22:58:34 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\New\ntuser.ini
[2010/05/02 22:22:14 | 000,000,634 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 11:02:08 | 000,066,056 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/26 09:42:12 | 000,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Works.lnk
[2010/04/25 23:55:37 | 000,059,844 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/25 23:36:25 | 000,000,868 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/21 14:59:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/18 16:45:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/17 02:36:47 | 000,002,001 | —- | M] () – C:\WINDOWS\CLEANUP.CMD
[2010/04/17 02:32:38 | 000,037,761 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/04/17 02:32:35 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:34 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/17 02:29:56 | 000,005,208 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2010/04/17 02:28:54 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/16 23:35:07 | 000,000,572 | —- | M] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:28:04 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:23:08 | 000,000,937 | —- | M] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:51:07 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/07 20:25:51 | 000,008,007 | —- | C] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/05 22:11:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 19:33:23 | 000,006,144 | —- | C] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/02 23:25:51 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 22:22:30 | 000,000,230 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/02 22:22:14 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/26 23:51:09 | 000,000,706 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/04/25 23:36:25 | 000,000,868 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/17 02:34:34 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/04/17 02:34:34 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2010/04/17 02:34:34 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2010/04/17 02:33:24 | 001,835,008 | -H– | C] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/04/17 02:33:24 | 000,020,480 | -H– | C] () – C:\Documents and Settings\New\ntuser.dat.LOG
[2010/04/17 02:33:24 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\New\ntuser.ini
[2010/04/17 02:32:35 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:35 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2010/04/17 02:28:54 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/17 02:27:40 | 2136,940,544 | -HS- | C] () – C:\hiberfil.sys
[2010/04/16 23:35:07 | 000,000,572 | —- | C] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:35:07 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\ndupoem.rst
[2010/04/16 23:28:04 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:27:25 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/16 23:23:08 | 000,000,937 | —- | C] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:12:01 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:57:49 | 000,059,844 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/16 22:57:35 | 000,002,187 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/16 22:57:02 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/16 21:24:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/16 20:27:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/01/16 19:37:00 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/01/16 19:31:35 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:AGP440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/04/15 05:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy64\IaStor.sys
[2008/04/15 21:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy32\IaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\OemDir\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\drivers\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\DRVSTORE\iaAHCI_E7EB69FF3449D216602D0D37A1D73969621673A9\iaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\eamon.sys
[2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\ehdrv.sys
[2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\epfwtdir.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys

< %systemroot%\System32\config\*.sav >
[2009/01/16 11:28:21 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/16 11:28:21 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/16 11:28:21 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
DRV - [2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)
DRV - [2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)
DRV - [2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)
DRV - [2008/12/26 05:27:26 | 004,968,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/11/20 05:39:36 | 000,204,464 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2008/09/23 13:15:00 | 000,038,400 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/08/14 21:54:18 | 001,318,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2008/04/14 08:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2008/04/14 08:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/14 08:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2008/04/14 08:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2008/04/14 08:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2008/04/14 08:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2008/04/14 08:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2008/04/14 08:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2008/04/14 08:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2008/04/14 08:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2008/04/14 08:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2008/04/14 08:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2008/04/14 08:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2008/04/14 08:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2008/04/14 08:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2008/04/14 04:06:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/14 04:06:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/14 00:15:14 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/02/14 19:12:06 | 005,854,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2007/10/01 14:59:46 | 001,769,984 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\snp2uvc.sys – (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2006/11/02 09:27:34 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2004/12/08 02:10:00 | 000,016,896 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/05/07 20:42:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NotificationCenterLauncher] C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe (Acer)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.DLL ( )
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - HKLM..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/16 19:34:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2010/05/07 21:31:13 | 000,570,880 | —- | C] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:28:06 | 000,000,000 | —D | C] – C:\VundoFix Backups
[2010/05/07 21:01:29 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop\undll
[2010/05/07 20:52:57 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:43:02 | 000,000,000 | —D | C] – C:\WINDOWS\LastGood
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/05/07 20:35:05 | 000,000,000 | —D | C] – C:\Program Files\Eset undll
[2010/05/05 19:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\WMTools Downloaded Files
[2010/05/05 19:31:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/05/03 22:58:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/03 22:57:49 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/03 22:57:32 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/02 23:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Malwarebytes
[2010/05/02 23:25:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/02 23:25:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/02 23:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AskToolbar
[2010/05/02 22:30:28 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/05/02 22:22:27 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/05/02 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/02 22:21:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\uTorrent
[2010/04/26 23:51:09 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2010/04/26 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\ZooskMessenger
[2010/04/26 23:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/04/25 23:35:55 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\OpenOffice.org
[2010/04/25 23:34:22 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/04/25 23:34:16 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/04/25 23:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/25 23:33:31 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Sun
[2010/04/25 23:15:07 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/04/25 23:15:07 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/04/24 10:54:19 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/04/24 10:54:17 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/04/24 10:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Mozilla
[2010/04/24 10:37:22 | 000,000,000 | —D | C] – C:\Program Files\TuneUpMedia
[2010/04/20 08:30:45 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/04/20 08:30:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/04/20 08:30:43 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/04/17 22:31:24 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/04/17 22:31:19 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/04/17 22:31:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/04/17 22:30:50 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/04/17 22:30:50 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/04/17 22:30:50 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/04/17 22:30:50 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/04/17 22:30:50 | 000,000,000 | —D | C] – C:\7deeaa03f7a0b712ef2491cca1fe
[2010/04/17 22:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Adobe
[2010/04/17 22:14:39 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2010/04/17 21:08:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2010/04/17 02:41:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/04/17 02:40:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/04/17 02:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/04/17 02:36:45 | 000,000,000 | —D | C] – C:\WINDOWS\BTW
[2010/04/17 02:34:34 | 000,286,720 | —- | C] (Sonix) – C:\WINDOWS\System32\vsnp2uvc.dll
[2010/04/17 02:34:34 | 000,196,608 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2010/04/17 02:34:34 | 000,094,208 | —- | C] (sonix) – C:\WINDOWS\PLFSetL.exe
[2010/04/17 02:34:31 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\WINDOWS\SUYIN NB Cam
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SNP2UVC
[2010/04/17 02:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Acer
[2010/04/17 02:33:24 | 000,000,000 | –SD | C] – C:\Documents and Settings\New\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\SendTo
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Recent
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Application Data
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Start Menu
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Pictures
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Music
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Favorites
[2010/04/17 02:33:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\New\Cookies
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Templates
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\PrintHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\NetHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Local Settings
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft Help
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Macromedia
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\InstallShield
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Identities
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Google
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Adobe
[2010/04/17 02:28:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/04/16 23:46:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\TuneUpMedia
[2010/04/16 23:46:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUpMedia
[2010/04/16 23:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Songs
[2010/04/16 23:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\School Notes & Classes
[2010/04/16 23:37:13 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Videos
[2010/04/16 23:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Research, Intellectual Growth
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Tabs
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Lyrics
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Downloads
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Bands
[2010/04/16 23:36:11 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/04/16 23:35:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AWC
[2010/04/16 23:35:07 | 000,671,744 | —- | C] (Steve Murphy Software) – C:\WINDOWS\System32\AWC_SS.scr
[2010/04/16 23:35:05 | 002,420,736 | —- | C] (FreeImage) – C:\WINDOWS\System32\FreeImage.dll
[2010/04/16 23:35:05 | 000,167,936 | —- | C] (Common Controls Replacement Project (CCRP)) – C:\WINDOWS\System32\ccrpftv6.ocx
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (Jeremy Adams, CCRP) – C:\WINDOWS\System32\ccrpUCW6.dll
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (CCRP) – C:\WINDOWS\System32\ccrpDtp6.ocx
[2010/04/16 23:35:05 | 000,090,112 | —- | C] (http://www.mvps.org/vb) – C:\WINDOWS\System32\ccrpTmr6.dll
[2010/04/16 23:35:05 | 000,086,016 | —- | C] (CCRP / ECX Programming) – C:\WINDOWS\System32\ccrpudn6.ocx
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\SSubTmr6.dll
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (The Lillypad) – C:\WINDOWS\System32\DLLDesktop.dll
[2010/04/16 23:35:05 | 000,036,864 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\AlphaImageCreator.dll
[2010/04/16 23:35:04 | 000,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TABCTL32.OCX
[2010/04/16 23:35:04 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\RICHTX32.OCX
[2010/04/16 23:35:04 | 000,000,000 | —D | C] – C:\Program Files\AWC
[2010/04/16 23:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\skypePM
[2010/04/16 23:27:32 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Skype
[2010/04/16 23:27:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/04/16 23:27:21 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/04/16 23:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/16 23:11:59 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/04/16 23:11:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/16 23:10:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/16 23:10:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/04/16 23:10:23 | 003,003,680 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/04/16 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple Computer
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Apple Computer
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/16 22:57:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/16 22:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple
[2010/04/16 22:56:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/16 22:44:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/16 22:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/01/16 19:19:00 | 000,049,152 | —- | C] ( ) – C:\WINDOWS\Interop.IWshRuntimeLibrary.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\OTL.exe
[2010/05/07 21:27:36 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/05/07 21:01:27 | 001,835,008 | -H– | M] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/05/07 21:01:01 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/07 20:53:19 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\New\Desktop\HiJackThis.exe
[2010/05/07 20:25:51 | 000,008,007 | —- | M] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/06 18:38:03 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/06 15:09:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/05 22:11:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 20:43:37 | 000,006,144 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/03 22:57:36 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:36 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:36 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/02 23:25:51 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 23:03:23 | 000,511,030 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/02 23:03:23 | 000,434,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/02 23:03:23 | 000,068,386 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/02 22:59:33 | 000,000,706 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/05/02 22:59:15 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/02 22:59:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/02 22:59:10 | 000,272,576 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/02 22:59:09 | 2136,940,544 | -HS- | M] () – C:\hiberfil.sys
[2010/05/02 22:58:34 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\New\ntuser.ini
[2010/05/02 22:22:14 | 000,000,634 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 11:02:08 | 000,066,056 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/26 09:42:12 | 000,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Works.lnk
[2010/04/25 23:55:37 | 000,059,844 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/25 23:36:25 | 000,000,868 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/21 14:59:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/18 16:45:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/17 02:36:47 | 000,002,001 | —- | M] () – C:\WINDOWS\CLEANUP.CMD
[2010/04/17 02:32:38 | 000,037,761 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/04/17 02:32:35 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:34 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/17 02:29:56 | 000,005,208 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2010/04/17 02:28:54 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/16 23:35:07 | 000,000,572 | —- | M] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:28:04 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:23:08 | 000,000,937 | —- | M] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:51:07 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/07 20:25:51 | 000,008,007 | —- | C] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/05 22:11:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 19:33:23 | 000,006,144 | —- | C] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/02 23:25:51 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 22:22:30 | 000,000,230 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/02 22:22:14 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/26 23:51:09 | 000,000,706 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/04/25 23:36:25 | 000,000,868 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/17 02:34:34 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/04/17 02:34:34 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2010/04/17 02:34:34 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2010/04/17 02:33:24 | 001,835,008 | -H– | C] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/04/17 02:33:24 | 000,001,024 | -H– | C] () – C:\Documents and Settings\New\ntuser.dat.LOG
[2010/04/17 02:33:24 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\New\ntuser.ini
[2010/04/17 02:32:35 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:35 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2010/04/17 02:28:54 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/17 02:27:40 | 2136,940,544 | -HS- | C] () – C:\hiberfil.sys
[2010/04/16 23:35:07 | 000,000,572 | —- | C] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:35:07 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\ndupoem.rst
[2010/04/16 23:28:04 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:27:25 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/16 23:23:08 | 000,000,937 | —- | C] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:12:01 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:57:49 | 000,059,844 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/16 22:57:35 | 000,002,187 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/16 22:57:02 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/16 21:24:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/16 20:27:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/01/16 19:37:00 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/01/16 19:31:35 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:AGP440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/04/15 05:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy64\IaStor.sys
[2008/04/15 21:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy32\IaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\OemDir\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\drivers\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\DRVSTORE\iaAHCI_E7EB69FF3449D216602D0D37A1D73969621673A9\iaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\eamon.sys
[2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\ehdrv.sys
[2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\epfwtdir.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys

< %systemroot%\System32\config\*.sav >
[2009/01/16 11:28:21 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/16 11:28:21 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/16 11:28:21 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< End of report >
After running defogger is said finished, but did not ask me to reboot. So I restarted anyway, to be on the safe side. some way through gmer a blue windows screen came up and forced a restart. Ill have to restart gmer and get you the log files. This is the note defogger left on my desktop defogger_disable by jpshortstuff (23.02.10.1) Log created at 00:18 on 08/05/2010 (New) Checking for autostart values… HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers… -=E.O.F=-
When you run GMER again, please be sure you have your ESET NOD32 anti-virus disabled during the scan.

Ideally, we'd like to run GMER in normal mode, but if it still won't run in normal mode please do the following:

Boot your computer in Safe Mode
  • Turn the computer on or Restart the computer
  • As soon as BIOS is loaded, start tapping the F8 key.
  • The Windows Advanced Options Menu appears.
    If you begin tapping the F8 key too soon, some computers display a "keyboard error" message. To resolve this, restart the computer and try again.
  • Use the arrow keys to select the Safe Mode menu option.
  • Press Enter.
  • The computer then begins to start in Safe mode.
  • Log into your usual account
Then try running GMER with just "sections" and the "c:\" drive checked, leave everything else blank. After running it, reboot into normal mode.

If you still can't get it to run, please let me know.

It appears you have posted the same OTL log twice. Please provide the results of the Extras log and the GMER log in your next reply.
Gmer results
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwAssignProcessToJobObject [0x98D52610]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDebugActiveProcess [0x98D52C10]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwDuplicateObject [0x98D52730]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenProcess [0x98D524B0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwOpenThread [0x98D52570]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwProtectVirtualMemory [0x98D526D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetContextThread [0x98D52690]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetInformationThread [0x98D52650]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSetSecurityObject [0x98D527D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendProcess [0x98D52510]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwSuspendThread [0x98D52590]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateProcess [0x98D524D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwTerminateThread [0x98D525D0]
SSDT \SystemRoot\system32\DRIVERS\ehdrv.sys (ESET Helper driver/ESET) ZwWriteVirtualMemory [0x98D52750]

—- User code sections - GMER 1.0.15 —-

.text C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe[1572] kernel32.dll!SetUnhandledExceptionFilter 7C84495D 4 Bytes [C2, 04, 00, 00]

—- Devices - GMER 1.0.15 —-

AttachedDevice \FileSystem\Ntfs \Ntfs eamon.sys (Amon monitor/ESET)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass0 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Kbdclass \Device\KeyboardClass1 wdf01000.sys (WDF Dynamic/Microsoft Corporation)
AttachedDevice \Driver\Tcpip \Device\Tcp epfwtdir.sys (ESET Antivirus Network Redirector/ESET)
OTL.Txt


OTL logfile created on: 5/8/2010 10:21:48 PM - Run 2
OTL by OldTimer - Version 3.2.4.1 Folder = C:\Documents and Settings\New\Desktop\Viral Help
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 65.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 87.00% Paging File free
Paging file location(s): C:\pagefile.sys 2046 4092 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 143.04 Gb Total Space | 85.13 Gb Free Space | 59.51% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded

Computer Name: JEREMY
Current User Name: New
Logged in as Administrator.

Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Standard

========== Processes (SafeList) ==========

PRC - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\Viral Help\OTL.exe
PRC - [2010/05/02 22:22:14 | 000,321,328 | —- | M] (BitTorrent, Inc.) – C:\Program Files\uTorrent\uTorrent.exe
PRC - [2010/04/26 23:50:53 | 000,095,232 | —- | M] () – C:\Program Files\ZooskMessenger\ZooskMessenger.exe
PRC - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe
PRC - [2010/03/24 20:31:00 | 002,145,000 | —- | M] (ESET) – C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe
PRC - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
PRC - [2010/03/04 03:33:50 | 001,795,880 | —- | M] (Apple Inc.) – C:\Program Files\Safari\Safari.exe
PRC - [2010/02/02 00:10:14 | 007,418,368 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.bin
PRC - [2010/02/02 00:10:10 | 007,424,000 | —- | M] (OpenOffice.org) – C:\Program Files\OpenOffice.org 3\program\soffice.exe
PRC - [2009/01/16 20:41:00 | 000,212,992 | —- | M] (Realtek Semiconductor Corp.) – C:\Documents and Settings\New\Local Settings\Temp\RtkBtMnt.exe
PRC - [2009/01/10 23:24:38 | 000,565,248 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\AcerVCM.exe
PRC - [2009/01/06 21:42:16 | 001,671,168 | —- | M] (Acer Incoporated) – C:\Program Files\Acer\Acer VCM\VC.exe
PRC - [2008/12/30 03:09:52 | 000,875,016 | —- | M] (Dritek System Inc.) – C:\Program Files\Launch Manager\LManager.exe
PRC - [2008/12/22 12:00:40 | 000,225,280 | —- | M] (Acer) – C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe
PRC - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) – C:\Program Files\Acer\Acer VCM\RS_Service.exe
PRC - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/04/15 21:54:40 | 000,178,712 | —- | M] (Intel Corporation) – C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/04/14 08:00:00 | 001,033,728 | —- | M] (Microsoft Corporation) – C:\WINDOWS\explorer.exe
PRC - [2008/02/27 21:00:10 | 000,170,520 | —- | M] (Intel Corporation) – C:\WINDOWS\system32\igfxext.exe


========== Modules (SafeList) ==========

MOD - [2010/05/07 21:31:38 | 000,570,880 | —- | M] (OldTimer Tools) – C:\Documents and Settings\New\Desktop\Viral Help\OTL.exe
MOD - [2008/04/14 08:00:00 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\msscript.ocx


========== Win32 Services (SafeList) ==========

SRV - [2010/03/24 20:39:48 | 000,033,560 | —- | M] (ESET) [On_Demand | Stopped] – C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe – (EhttpSrv)
SRV - [2010/03/24 20:31:50 | 000,810,120 | —- | M] (ESET) [Auto | Running] – C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe – (ekrn)
SRV - [2010/03/19 10:49:20 | 000,144,672 | —- | M] (Apple Inc.) [Auto | Running] – C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe – (Apple Mobile Device)
SRV - [2008/11/27 15:00:58 | 000,237,568 | —- | M] (Acer Incorporated) [Auto | Running] – C:\Program Files\Acer\Acer VCM\RS_Service.exe – (RS_Service)
SRV - [2008/04/15 21:54:42 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON) Intel®


========== Driver Services (SafeList) ==========

DRV - [2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\epfwtdir.sys – (epfwtdir)
DRV - [2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) [Kernel | System | Running] – C:\WINDOWS\system32\drivers\ehdrv.sys – (ehdrv)
DRV - [2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) [File_System | Auto | Running] – C:\WINDOWS\system32\drivers\eamon.sys – (eamon)
DRV - [2008/12/26 05:27:26 | 004,968,448 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\RtkHDAud.sys – (IntcAzAudAddService) Service for Realtek HD Audio (WDM)
DRV - [2008/11/20 05:39:36 | 000,204,464 | —- | M] (Synaptics, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\SynTP.sys – (SynTP)
DRV - [2008/09/23 13:15:00 | 000,038,400 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\l1e51x86.sys – (L1e)
DRV - [2008/08/14 21:54:18 | 001,318,464 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\athw.sys – (AR5416)
DRV - [2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\drivers\iaStor.sys – (iaStor)
DRV - [2008/04/14 08:00:00 | 000,179,584 | —- | M] (Mylex Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\dac2w2k.sys – (dac2w2k)
DRV - [2008/04/14 08:00:00 | 000,144,384 | —- | M] (Windows ® Server 2003 DDK provider) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\hdaudbus.sys – (HDAudBus)
DRV - [2008/04/14 08:00:00 | 000,049,024 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1280.sys – (ql1280)
DRV - [2008/04/14 08:00:00 | 000,045,312 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql12160.sys – (ql12160)
DRV - [2008/04/14 08:00:00 | 000,040,320 | —- | M] (QLogic Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ql1080.sys – (ql1080)
DRV - [2008/04/14 08:00:00 | 000,036,736 | —- | M] (Promise Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\ultra.sys – (ultra)
DRV - [2008/04/14 08:00:00 | 000,032,640 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc8xx.sys – (symc8xx)
DRV - [2008/04/14 08:00:00 | 000,030,688 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_u3.sys – (sym_u3)
DRV - [2008/04/14 08:00:00 | 000,028,384 | —- | M] (LSI Logic) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sym_hi.sys – (sym_hi)
DRV - [2008/04/14 08:00:00 | 000,026,496 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc.sys – (asc)
DRV - [2008/04/14 08:00:00 | 000,019,072 | —- | M] (Adaptec, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sparrow.sys – (Sparrow)
DRV - [2008/04/14 08:00:00 | 000,017,280 | —- | M] (American Megatrends Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\mraid35x.sys – (mraid35x)
DRV - [2008/04/14 08:00:00 | 000,016,256 | —- | M] (Symbios Logic Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\symc810.sys – (symc810)
DRV - [2008/04/14 08:00:00 | 000,014,848 | —- | M] (Advanced System Products, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\asc3550.sys – (asc3550)
DRV - [2008/04/14 08:00:00 | 000,006,656 | —- | M] (CMD Technology, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\cmdide.sys – (CmdIde)
DRV - [2008/04/14 08:00:00 | 000,005,248 | —- | M] (Acer Laboratories Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\aliide.sys – (AliIde)
DRV - [2008/04/14 04:06:40 | 000,043,008 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\amdagp.sys – (amdagp)
DRV - [2008/04/14 04:06:40 | 000,040,960 | —- | M] (Silicon Integrated Systems Corporation) [Kernel | Boot | Running] – C:\WINDOWS\system32\DRIVERS\sisagp.sys – (sisagp)
DRV - [2008/04/14 00:15:14 | 000,060,032 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\WINDOWS\system32\drivers\USBAUDIO.sys – (usbaudio) USB Audio Driver (WDM)
DRV - [2008/02/14 19:12:06 | 005,854,752 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\igxpmp32.sys – (ialm)
DRV - [2007/10/01 14:59:46 | 001,769,984 | —- | M] () [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\snp2uvc.sys – (SNP2UVC) USB2.0 PC Camera (SNP2UVC)
DRV - [2006/11/02 09:27:34 | 000,020,112 | —- | M] (Dritek System Inc.) [Kernel | System | Running] – C:\Program Files\Launch Manager\DPortIO.sys – (DritekPortIO)
DRV - [2004/12/08 02:10:00 | 000,016,896 | —- | M] (Dritek System Inc.) [Kernel | On_Demand | Running] – C:\WINDOWS\system32\drivers\DKbFltr.SYS – (DKbFltr)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a…mp;m=aspire_one
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

FF - HKLM\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET NOD32 Antivirus\Mozilla Thunderbird [2010/05/07 20:42:20 | 000,000,000 | —D | M]


O1 HOSTS File: ([2008/04/14 08:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask.com)
O4 - HKLM..\Run: [Alcmtr] C:\WINDOWS\ALCMTR.EXE (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [AzMixerSel] C:\Program Files\Realtek\Audio\Drivers\AzMixerSel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [egui] C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe (ESET)
O4 - HKLM..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
O4 - HKLM..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe (Dritek System Inc.)
O4 - HKLM..\Run: [MSPY2002] C:\WINDOWS\System32\IME\PINTLGNT\ImScInst.exe ()
O4 - HKLM..\Run: [NotificationCenterLauncher] C:\Program Files\Acer\Acer eRecovery Management\NotificationLauncher.exe (Acer)
O4 - HKLM..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE (Microsoft Corporation)
O4 - HKLM..\Run: [PLFSetL] C:\WINDOWS\PLFSetL.exe (sonix)
O4 - HKLM..\Run: [snp2uvc] C:\WINDOWS\System32\csnp2uvc.DLL ( )
O4 - HKCU..\Run: [uTorrent] C:\Program Files\uTorrent\uTorrent.exe (BitTorrent, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Acer VCM.lnk = C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated)
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O4 - Startup: C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk = C:\Program Files\ZooskMessenger\ZooskMessenger.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8 - Extra context menu item: E&xport to Microsoft Excel - C:\Program Files\Microsoft Office\Office12\EXCEL.EXE (Microsoft Corporation)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program Files\Microsoft Office\Office12\REFIEBAR.DLL (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8050.1202.dll (Microsoft Corporation)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O18 - Protocol\Filter\text/xml {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\igfxcui: DllName - igfxdev.dll - C:\WINDOWS\System32\igfxdev.dll (Intel Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\New\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/01/16 19:34:13 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\system32\ias [2009/01/16 19:33:41 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\system32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (17183584330711040)

========== Files/Folders - Created Within 30 Days ==========

[2010/05/07 21:28:06 | 000,000,000 | —D | C] – C:\VundoFix Backups
[2010/05/07 21:01:29 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop\Viral Help
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/05/07 20:42:17 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\ESET
[2010/05/07 20:35:05 | 000,000,000 | —D | C] – C:\Program Files\Eset undll
[2010/05/05 19:32:19 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\WMTools Downloaded Files
[2010/05/05 19:31:47 | 000,000,000 | R–D | C] – C:\Documents and Settings\All Users\Documents\My Videos
[2010/05/03 22:58:00 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Java
[2010/05/03 22:57:49 | 000,411,368 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:49 | 000,153,376 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:49 | 000,145,184 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:49 | 000,073,728 | —- | C] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/03 22:57:32 | 000,000,000 | —D | C] – C:\Program Files\Java
[2010/05/02 23:25:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Malwarebytes
[2010/05/02 23:25:48 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/05/02 23:25:46 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/05/02 23:25:46 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/05/02 23:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AskToolbar
[2010/05/02 22:30:28 | 000,000,000 | —D | C] – C:\WINDOWS\Sun
[2010/05/02 22:22:27 | 000,000,000 | —D | C] – C:\Program Files\Ask.com
[2010/05/02 22:22:14 | 000,000,000 | —D | C] – C:\Program Files\uTorrent
[2010/05/02 22:21:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\uTorrent
[2010/04/26 23:51:09 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\com.zoosk.Desktop.096E6A67431258A508A2446A847B240591D2C99B.1
[2010/04/26 23:50:59 | 000,000,000 | —D | C] – C:\Program Files\ZooskMessenger
[2010/04/26 23:50:56 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Adobe AIR
[2010/04/25 23:35:55 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\OpenOffice.org
[2010/04/25 23:34:22 | 000,000,000 | —D | C] – C:\Program Files\JRE
[2010/04/25 23:34:16 | 000,000,000 | —D | C] – C:\Program Files\OpenOffice.org 3
[2010/04/25 23:34:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Sun
[2010/04/25 23:33:31 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Sun
[2010/04/25 23:15:07 | 000,274,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll
[2010/04/25 23:15:07 | 000,016,736 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\mucltui.dll.mui
[2010/04/24 10:54:19 | 000,021,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidserv.dll
[2010/04/24 10:54:17 | 000,010,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\hidusb.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\drivers\USBAUDIO.sys
[2010/04/24 10:54:03 | 000,060,032 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbaudio.sys
[2010/04/24 10:37:41 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Mozilla
[2010/04/24 10:37:22 | 000,000,000 | —D | C] – C:\Program Files\TuneUpMedia
[2010/04/20 08:30:45 | 000,159,232 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusd.dll
[2010/04/20 08:30:45 | 000,005,632 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\ptpusb.dll
[2010/04/20 08:30:43 | 000,015,104 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbscan.sys
[2010/04/17 22:31:24 | 000,000,000 | —D | C] – C:\WINDOWS\System32\XPSViewer
[2010/04/17 22:31:19 | 000,000,000 | —D | C] – C:\Program Files\MSBuild
[2010/04/17 22:31:10 | 000,000,000 | —D | C] – C:\Program Files\Reference Assemblies
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\xpssvcs.dll
[2010/04/17 22:30:50 | 001,676,288 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpssvcs.dll
[2010/04/17 22:30:50 | 000,597,504 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\printfilterpipelinesvc.exe
[2010/04/17 22:30:50 | 000,575,488 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\xpsshhdr.dll
[2010/04/17 22:30:50 | 000,117,760 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\prntvpt.dll
[2010/04/17 22:30:50 | 000,089,088 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\filterpipelineprintproc.dll
[2010/04/17 22:30:50 | 000,000,000 | —D | C] – C:\7deeaa03f7a0b712ef2491cca1fe
[2010/04/17 22:26:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Adobe
[2010/04/17 22:14:39 | 000,000,000 | —D | C] – C:\WINDOWS\ie7updates
[2010/04/17 21:08:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\PreInstall
[2010/04/17 02:41:30 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/04/17 02:40:21 | 000,000,000 | —D | C] – C:\WINDOWS\System32\SoftwareDistribution
[2010/04/17 02:38:49 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Google
[2010/04/17 02:36:45 | 000,000,000 | —D | C] – C:\WINDOWS\BTW
[2010/04/17 02:34:34 | 000,286,720 | —- | C] (Sonix) – C:\WINDOWS\System32\vsnp2uvc.dll
[2010/04/17 02:34:34 | 000,196,608 | —- | C] ( ) – C:\WINDOWS\System32\csnp2uvc.dll
[2010/04/17 02:34:34 | 000,094,208 | —- | C] (sonix) – C:\WINDOWS\PLFSetL.exe
[2010/04/17 02:34:31 | 000,172,032 | —- | C] ( ) – C:\WINDOWS\System32\rsnp2uvc.dll
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\WINDOWS\SUYIN NB Cam
[2010/04/17 02:34:31 | 000,000,000 | —D | C] – C:\Program Files\Common Files\SNP2UVC
[2010/04/17 02:33:25 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Acer
[2010/04/17 02:33:24 | 000,000,000 | –SD | C] – C:\Documents and Settings\New\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\SendTo
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Recent
[2010/04/17 02:33:24 | 000,000,000 | RH-D | C] – C:\Documents and Settings\New\Application Data
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Start Menu
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Pictures
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Music
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents
[2010/04/17 02:33:24 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\Favorites
[2010/04/17 02:33:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings\New\Cookies
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Templates
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\PrintHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\NetHood
[2010/04/17 02:33:24 | 000,000,000 | -H-D | C] – C:\Documents and Settings\New\Local Settings
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft Help
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Microsoft
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Macromedia
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\InstallShield
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Identities
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Google
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Desktop
[2010/04/17 02:33:24 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Adobe
[2010/04/17 02:28:21 | 000,000,000 | -HSD | C] – C:\System Volume Information
[2010/04/16 23:46:51 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\TuneUpMedia
[2010/04/16 23:46:45 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\TuneUpMedia
[2010/04/16 23:37:15 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Songs
[2010/04/16 23:37:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\School Notes & Classes
[2010/04/16 23:37:13 | 000,000,000 | R–D | C] – C:\Documents and Settings\New\My Documents\My Videos
[2010/04/16 23:37:13 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Research, Intellectual Growth
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Tabs
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Lyrics
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Downloads
[2010/04/16 23:36:56 | 000,000,000 | —D | C] – C:\Documents and Settings\New\My Documents\Bands
[2010/04/16 23:36:11 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/04/16 23:35:14 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\AWC
[2010/04/16 23:35:07 | 000,671,744 | —- | C] (Steve Murphy Software) – C:\WINDOWS\System32\AWC_SS.scr
[2010/04/16 23:35:05 | 002,420,736 | —- | C] (FreeImage) – C:\WINDOWS\System32\FreeImage.dll
[2010/04/16 23:35:05 | 000,167,936 | —- | C] (Common Controls Replacement Project (CCRP)) – C:\WINDOWS\System32\ccrpftv6.ocx
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (Jeremy Adams, CCRP) – C:\WINDOWS\System32\ccrpUCW6.dll
[2010/04/16 23:35:05 | 000,098,304 | —- | C] (CCRP) – C:\WINDOWS\System32\ccrpDtp6.ocx
[2010/04/16 23:35:05 | 000,090,112 | —- | C] (http://www.mvps.org/vb) – C:\WINDOWS\System32\ccrpTmr6.dll
[2010/04/16 23:35:05 | 000,086,016 | —- | C] (CCRP / ECX Programming) – C:\WINDOWS\System32\ccrpudn6.ocx
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\SSubTmr6.dll
[2010/04/16 23:35:05 | 000,040,960 | —- | C] (The Lillypad) – C:\WINDOWS\System32\DLLDesktop.dll
[2010/04/16 23:35:05 | 000,036,864 | —- | C] (vbAccelerator) – C:\WINDOWS\System32\AlphaImageCreator.dll
[2010/04/16 23:35:04 | 000,209,608 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\TABCTL32.OCX
[2010/04/16 23:35:04 | 000,203,976 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\RICHTX32.OCX
[2010/04/16 23:35:04 | 000,000,000 | —D | C] – C:\Program Files\AWC
[2010/04/16 23:28:03 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\skypePM
[2010/04/16 23:27:32 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Skype
[2010/04/16 23:27:24 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Skype
[2010/04/16 23:27:21 | 000,000,000 | R–D | C] – C:\Program Files\Skype
[2010/04/16 23:27:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Skype
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy
[2010/04/16 23:23:01 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
[2010/04/16 23:11:59 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\WINDOWS\System32\GEARAspi.dll
[2010/04/16 23:11:30 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2010/04/16 23:11:26 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
[2010/04/16 23:10:48 | 000,000,000 | —D | C] – C:\Program Files\QuickTime
[2010/04/16 23:10:33 | 000,000,000 | —D | C] – C:\Program Files\Apple Software Update
[2010/04/16 23:10:23 | 003,003,680 | —- | C] (Apple, Inc.) – C:\WINDOWS\System32\usbaaplrc.dll
[2010/04/16 23:10:04 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple Computer
[2010/04/16 22:57:45 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Application Data\Apple Computer
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Program Files\Safari
[2010/04/16 22:57:30 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple Computer
[2010/04/16 22:57:14 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2010/04/16 22:57:02 | 000,000,000 | —D | C] – C:\Documents and Settings\New\Local Settings\Application Data\Apple
[2010/04/16 22:56:58 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Apple
[2010/04/16 22:44:16 | 000,000,000 | -HSD | C] – C:\RECYCLER
[2010/04/16 22:43:50 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2009/01/16 19:19:00 | 000,049,152 | —- | C] ( ) – C:\WINDOWS\Interop.IWshRuntimeLibrary.dll
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/05/08 22:19:16 | 000,002,187 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/05/08 22:19:03 | 000,000,706 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/05/08 22:18:44 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/05/08 22:18:41 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/05/08 22:18:39 | 2136,940,544 | -HS- | M] () – C:\hiberfil.sys
[2010/05/08 22:13:23 | 001,835,008 | -H– | M] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/05/08 22:01:01 | 000,000,230 | —- | M] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/08 14:17:29 | 000,002,137 | —- | M] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/05/07 22:24:59 | 000,434,266 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/05/07 22:24:48 | 000,068,386 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/05/07 22:23:09 | 000,511,030 | —- | M] () – C:\WINDOWS\System32\PerfStringBackup.INI
[2010/05/07 22:11:13 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\New\ntuser.ini
[2010/05/07 22:11:02 | 004,299,394 | -H– | M] () – C:\Documents and Settings\New\Local Settings\Application Data\IconCache.db
[2010/05/07 21:57:40 | 000,000,000 | —- | M] () – C:\Documents and Settings\New\defogger_reenable
[2010/05/07 20:25:51 | 000,008,007 | —- | M] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/06 15:09:02 | 000,000,284 | —- | M] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2010/05/05 22:11:50 | 000,000,790 | —- | M] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 20:43:37 | 000,006,144 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/03 22:57:36 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\deployJava1.dll
[2010/05/03 22:57:36 | 000,153,376 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaws.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javaw.exe
[2010/05/03 22:57:36 | 000,145,184 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\java.exe
[2010/05/03 22:57:36 | 000,073,728 | —- | M] (Sun Microsystems, Inc.) – C:\WINDOWS\System32\javacpl.cpl
[2010/05/02 23:25:51 | 000,000,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 22:59:10 | 000,272,576 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/05/02 22:22:14 | 000,000,634 | —- | M] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/04/26 11:02:08 | 000,066,056 | —- | M] () – C:\Documents and Settings\New\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
[2010/04/26 09:42:12 | 000,000,886 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Microsoft Works.lnk
[2010/04/25 23:55:37 | 000,059,844 | -H– | M] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/25 23:36:25 | 000,000,868 | —- | M] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | M] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | M] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | M] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/21 14:59:20 | 000,002,265 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/18 16:45:12 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
[2010/04/17 02:36:47 | 000,002,001 | —- | M] () – C:\WINDOWS\CLEANUP.CMD
[2010/04/17 02:32:38 | 000,037,761 | —- | M] () – C:\WINDOWS\System32\$winnt$.inf
[2010/04/17 02:32:35 | 000,262,144 | —- | M] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:34 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/04/17 02:29:56 | 000,005,208 | —- | M] () – C:\WINDOWS\System32\pid.PNF
[2010/04/17 02:28:54 | 000,008,192 | —- | M] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/16 23:35:07 | 000,000,572 | —- | M] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:28:04 | 000,000,056 | -H– | M] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:23:08 | 000,000,937 | —- | M] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | M] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:51:07 | 000,001,158 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/05/07 21:57:40 | 000,000,000 | —- | C] () – C:\Documents and Settings\New\defogger_reenable
[2010/05/07 20:25:51 | 000,008,007 | —- | C] () – C:\Documents and Settings\New\My Documents\hijackthis log
[2010/05/05 22:11:50 | 000,000,790 | —- | C] () – C:\Documents and Settings\New\Desktop\Windows Media Player.lnk
[2010/05/05 19:33:23 | 000,006,144 | —- | C] () – C:\Documents and Settings\New\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/02 23:25:51 | 000,000,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/05/02 22:22:30 | 000,000,230 | —- | C] () – C:\WINDOWS\tasks\Scheduled Update for Ask Toolbar.job
[2010/05/02 22:22:14 | 000,000,634 | —- | C] () – C:\Documents and Settings\All Users\Desktop\µTorrent.lnk
[2010/04/26 23:51:09 | 000,000,706 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\ZooskMessenger.lnk
[2010/04/25 23:36:25 | 000,000,868 | —- | C] () – C:\Documents and Settings\New\Start Menu\Programs\Startup\OpenOffice.org 3.2.lnk
[2010/04/25 23:35:12 | 000,000,905 | —- | C] () – C:\Documents and Settings\All Users\Desktop\OpenOffice.org 3.2.lnk
[2010/04/25 23:14:58 | 000,000,000 | —- | C] () – C:\Documents and Settings\New\Application Data\wklnhst.dat
[2010/04/24 10:37:38 | 000,000,712 | —- | C] () – C:\Documents and Settings\All Users\Desktop\TuneUp Companion.lnk
[2010/04/17 02:34:34 | 001,769,984 | —- | C] () – C:\WINDOWS\System32\drivers\snp2uvc.sys
[2010/04/17 02:34:34 | 000,028,160 | —- | C] () – C:\WINDOWS\System32\drivers\sncduvc.sys
[2010/04/17 02:34:34 | 000,000,036 | —- | C] () – C:\WINDOWS\PidList.ini
[2010/04/17 02:33:24 | 001,835,008 | -H– | C] () – C:\Documents and Settings\New\NTUSER.DAT
[2010/04/17 02:33:24 | 000,001,024 | -H– | C] () – C:\Documents and Settings\New\ntuser.dat.LOG
[2010/04/17 02:33:24 | 000,000,178 | -HS- | C] () – C:\Documents and Settings\New\ntuser.ini
[2010/04/17 02:32:35 | 000,262,144 | —- | C] () – C:\Documents and Settings\All Users\NTUSER.DAT
[2010/04/17 02:32:35 | 000,001,024 | -H– | C] () – C:\Documents and Settings\All Users\NTUSER.DAT.LOG
[2010/04/17 02:28:54 | 000,008,192 | —- | C] () – C:\WINDOWS\REGLOCS.OLD
[2010/04/17 02:27:40 | 2136,940,544 | -HS- | C] () – C:\hiberfil.sys
[2010/04/16 23:35:07 | 000,000,572 | —- | C] () – C:\Documents and Settings\New\Desktop\AWC.lnk
[2010/04/16 23:35:07 | 000,000,032 | —- | C] () – C:\WINDOWS\System32\ndupoem.rst
[2010/04/16 23:28:04 | 000,000,056 | -H– | C] () – C:\WINDOWS\System32\ezsidmv.dat
[2010/04/16 23:27:25 | 000,002,265 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Skype.lnk
[2010/04/16 23:23:08 | 000,000,937 | —- | C] () – C:\Documents and Settings\New\Desktop\Spybot - Search & Destroy.lnk
[2010/04/16 23:12:01 | 000,002,137 | —- | C] () – C:\Documents and Settings\All Users\Desktop\iTunes.lnk
[2010/04/16 23:10:57 | 000,001,608 | —- | C] () – C:\Documents and Settings\All Users\Desktop\QuickTime Player.lnk
[2010/04/16 22:57:49 | 000,059,844 | -H– | C] () – C:\WINDOWS\System32\mlfcache.dat
[2010/04/16 22:57:35 | 000,002,187 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Safari.lnk
[2010/04/16 22:57:02 | 000,000,284 | —- | C] () – C:\WINDOWS\tasks\AppleSoftwareUpdate.job
[2009/01/16 21:24:45 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2009/01/16 20:27:38 | 000,147,456 | —- | C] () – C:\WINDOWS\System32\igfxCoIn_v4926.dll
[2009/01/16 19:37:00 | 000,006,782 | —- | C] () – C:\WINDOWS\System32\oeminfo.ini
[2009/01/16 19:31:35 | 000,001,793 | —- | C] () – C:\WINDOWS\System32\fxsperf.ini

========== Custom Scans ==========


< %SYSTEMDRIVE%\*.exe >


< MD5 for: AGP440.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:AGP440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\dllcache\agp440.sys
[2008/04/14 04:06:40 | 000,042,368 | —- | M] (Microsoft Corporation) MD5=08FD04AA961BDC77FB983F328334E3D7 – C:\WINDOWS\system32\drivers\AGP440.SYS

< MD5 for: ATAPI.SYS >
[2008/04/14 08:00:00 | 020,056,462 | —- | M] () .cab file – C:\i386\sp3.cab:atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\dllcache\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\drivers\atapi.sys
[2008/04/14 08:00:00 | 000,096,512 | —- | M] (Microsoft Corporation) MD5=9F3A2F5AA6875C72BF062C712CFA2674 – C:\WINDOWS\system32\ReinstallBackups\0004\DriverFiles\i386\atapi.sys

< MD5 for: EVENTLOG.DLL >
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\dllcache\eventlog.dll
[2008/04/14 08:00:00 | 000,056,320 | —- | M] (Microsoft Corporation) MD5=6D4FEB43EE538FC5428CC7F0565AA656 – C:\WINDOWS\system32\eventlog.dll

< MD5 for: IASTOR.SYS >
[2008/04/15 05:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy64\IaStor.sys
[2008/04/15 21:54:16 | 000,388,120 | —- | M] (Intel Corporation) MD5=8D58627FEF3F8767665D9F4DC91CBD97 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver64\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\ACER\Preload\Autorun\DRV\Intel IMSM 945GSE\f6flpy32\IaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\Program Files\Intel\Intel Matrix Storage Manager\driver\IaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\OemDir\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\drivers\iaStor.sys
[2008/04/15 21:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\DRVSTORE\iaAHCI_E7EB69FF3449D216602D0D37A1D73969621673A9\iaStor.sys
[2008/04/15 05:53:44 | 000,312,344 | —- | M] (Intel Corporation) MD5=DB0CC620B27A928D968C1A1E9CD9CB87 – C:\WINDOWS\system32\ReinstallBackups\0010\DriverFiles\iaStor.sys

< MD5 for: NETLOGON.DLL >
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\dllcache\netlogon.dll
[2008/04/14 08:00:00 | 000,407,040 | —- | M] (Microsoft Corporation) MD5=1B7F071C51B77C272875C3A23E1E4550 – C:\WINDOWS\system32\netlogon.dll

< MD5 for: SCECLI.DLL >
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\dllcache\scecli.dll
[2008/04/14 08:00:00 | 000,181,248 | —- | M] (Microsoft Corporation) MD5=A86BB5E61BF3E39B62AB4C7E7085A084 – C:\WINDOWS\system32\scecli.dll

< %systemroot%\*. /mp /s >

< %systemroot%\system32\*.dll /lockedfiles >
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %systemroot%\Tasks\*.job /lockedfiles >

< %systemroot%\system32\drivers\*.sys /lockedfiles >

< %systemroot%\system32\drivers\*.sys /90 >
[2010/03/24 20:23:52 | 000,139,192 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\eamon.sys
[2010/03/24 20:31:06 | 000,114,984 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\ehdrv.sys
[2010/03/24 20:33:52 | 000,095,872 | —- | M] (ESET) – C:\WINDOWS\system32\drivers\epfwtdir.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\system32\drivers\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\mrxsmb.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\system32\drivers\tcpip6.sys

< %systemroot%\System32\config\*.sav >
[2009/01/16 11:28:21 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2009/01/16 11:28:21 | 001,064,960 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2009/01/16 11:28:21 | 000,901,120 | —- | M] () – C:\WINDOWS\system32\config\system.sav
< End of report >
It only opened one .txt file, the OTL.txt. and did not open the Extra.txt file. Im running it again to see if it will pop up again. I Figured Id post the OTL one again for safe measure. Im sorry! thanks for your patience Ive been following your directions to a Tee, my system has been difficult along the way. When it gives me the Extras Ill post them. Also It doesnt seem to be saving them anywhere, I did a whole system search for the text files. arg
Don't worry about the extras log - let's continue on.

I see you have Malwarebytes already on your machine. Please run it by double clicking the icon on the desktop.
  • Click on the tab labeled Update and then click on the button Check for updates. Allow it to check for and apply any updates.
  • Select the Scanner tab, and Perform Quick Scan
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Please post the log in your next reply.

Please do a scan with Kaspersky Online Scanner
  • Click on the Accept button and install any components it needs.
  • The program will install and then begin downloading the latest definition files.
  • After the files have been downloaded on the left side of the page in the Scan section select My Computer.
  • This will start the program and scan your system.
  • The scan will take a while, so be patient and let it run. (At times it may appear to stall)
  • Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
  • Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
  • Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
  • Once the scan is complete, click on View scan report To obtain the report:
  • Click on: Save Report As
  • Next, in the Save as prompt, Save in area, select: Desktop
  • In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select:
  • Text file [*.txt] Then, click: Save
Please post the Kaspersky Online Scanner Report in your reply.
Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4084 Windows 5.1.2600 Service Pack 3 Internet Explorer 7.0.5730.13 5/10/2010 12:17:00 AM mbam-log-2010-05-10 (00-17-00).txt Scan type: Quick scan Objects scanned: 115092 Time elapsed: 9 minute(s), 31 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected)
——————————————————————————– KASPERSKY ONLINE SCANNER 7.0: scan report Monday, May 10, 2010 Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Monday, May 10, 2010 18:57:02 Records in database: 4091672 ——————————————————————————– Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes Scan area - My Computer: C:\ Scan statistics: Objects scanned: 48497 Threats found: 3 Infected objects found: 10 Suspicious objects found: 0 Scan duration: 01:55:21 File name / Threat / Threats count C:\Documents and Settings\New\Local Settings\Temp\8fiybf0d.tmp Infected: Exploit.JS.Pdfka.cfq 1 C:\Documents and Settings\New\Local Settings\Temp\apm6et86.tmp Infected: Exploit.JS.Pdfka.cfq 1 C:\Documents and Settings\New\Local Settings\Temp\jar_cache1106782817671869001.tmp Infected: Exploit.Java.CVE-2009-3867.d 1 C:\Documents and Settings\New\Local Settings\Temp\jar_cache1591584491637935437.tmp Infected: Exploit.Java.CVE-2009-3867.d 1 C:\Documents and Settings\New\Local Settings\Temp\jar_cache1659686594168339463.tmp Infected: Exploit.Java.CVE-2009-3867.d 1 C:\Documents and Settings\New\Local Settings\Temp\jar_cache821227610119930762.tmp Infected: Exploit.Java.CVE-2009-3867.d 1 C:\Documents and Settings\New\Local Settings\Temp\txraeatl.tmp Infected: Exploit.JS.Pdfka.cex 1 C:\Documents and Settings\New\Local Settings\Temp\v00jun0c.tmp Infected: Exploit.JS.Pdfka.cex 1 C:\Documents and Settings\New\Local Settings\Temporary Internet Files\Content.IE5\3I5XB8NF\s002106201317r0409R575640d4Xefe58410Ya438581dZ0100f070[1].pdf Infected: Exploit.JS.Pdfka.cex 1 C:\Documents and Settings\New\Local Settings\Temporary Internet Files\Content.IE5\M1YGRN56\s002106201317r0409R3490edf6Xefe58411Ya438581dZ0100f070[1].pdf Infected: Exploit.JS.Pdfka.cex 1 Selected area has been scanned.
Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean
It's normal after running TFC cleaner that the PC will be slower to boot the first time.


Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

If you notice any remaining tools or files you can delete them by right clicking and choosing delete.


If you ran DeFogger

To re-enable your Emulation drivers, double click DeFogger to run the tool.
  • The application window will appear
  • Click the Re-enable button to re-enable your CD Emulation drivers
  • Click Yes to continue
  • A 'Finished!' message will appear
  • Click OK
  • DeFogger will now ask to reboot the machine - click OK
IMPORTANT! If you receive an error message while running DeFogger, please post the log defogger_enable which will appear on your desktop.

Your Emulation drivers are now re-enabled.

Update Adobe Reader
There have been updates to Adobe Reader to address security vulnerabilities. You can download the latest version from the Adobe website


Can you please let me know how your computer is running now?
It is running ok. No glitches. However, I was running spybot search and destroy to double check. At the bottom it has a file count, which goes up to 1296504. You can see all the file names as it scans, and I can see Virtumonde.dll file names flashing through as well as virtumonde.sci, virtumonde.sdn which takes up almost all of these. not sure if this is of any consequence. But all in all working better. Thanks for all the work so far. Also I emailed a friend, and he got a virtumonde. though it may be coincidence, I fear I may have given it to him
The file count in Spybot S&D is the number of items in the Spybot S&D database, not the file count on your machine. What you see flashing across the bottom is the names of the files the program looks for on your machine. It does not mean these files are actually on your computer.

Great job! Your logs appear to be malware free and you do not appear to be experiencing any malware related problems.
Please follow these simple steps in order to keep your computer malware free and secure:

Set a New Restore Point to prevent possible reinfection from an old one.
Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
* Go to Start > Programs > Accessories > System Tools
* Click "System Restore"
* Choose the radio button marked "Create a Restore Point" on the first screen then click "Next"
* Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
* Then go to Start > Run and type: Cleanmgr
* Click "OK"
* Click the "More Options" Tab.
* Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

Visit Microsoft's Windows Update Site Frequently
It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

Use and Update your ESET NOD32 AntiVirus Software
It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

Use a Firewall

Your log doesn't appear to show a third-party software firewall installed - if you have one, and I've missed it, please ignore this. I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this. Simply using a Firewall in its default configuration can lower your risk greatly.

If you are relying the firewall that comes with Service Pack 2, then you need to install one. While the SP2 firewall is better than nothing, it doesn't monitor outgoing traffic, so anything malicious on your computer can 'phone home' at will. If you are using a wireless router that comes with a NAT hardware firewall, this also doesn't monitor outgoing connections.

Below are links to some free options:
Sunbelt Kerio OutPost
PC Tools Firewall Plus
Online Armor Free

After installing one of these, confirm your Windows Firewall is disabled by doing the following:
  • Click Start, click Run, type Firewall.cpl, and then click OK.
  • On the General tab, click Off (not recommended)
  • Click OK.

For a tutorial on Firewalls and a listing of some other available ones see the link below:
Understanding and Using Firewalls

Make your Internet Explorer more secure
This can be done by following these simple instructions:

1. From within Internet Explorer click on the Tools menu and then click on Options.
2. Click once on the Security tab
3. Click once on the Internet icon so it becomes highlighted.
4. Click once on the Custom Level button.

1. Change the Download signed ActiveX controls to Prompt
2. Change theDownload unsigned ActiveX controls to Disable
3. Change the Initialise and script ActiveX controls not marked as safe to Disable
4. Change the Installation of desktop items to Prompt
5. Change the Launching programs and files in an IFRAME to Prompt
6. Change the Navigate sub-frames across different domains to Prompt
7. When all these settings have been made, click on the OK button.
8. If it prompts you as to whether or not you want to save the settings, press the Yes button.

Next press the Apply button and then the OK to exit the Internet Properties page.

You should update your version of the Adobe Flash to the newest version:
You should update your version of the Sun Java Platform (JRE) to the newest version:
  • Download and install the latest version of Java
  • Next, remove all older versions of the Sun Java Platform using the Control Panel's Add/Remove Program feature (as they may contain security vulnerabilities).
Install SpywareBlaster
SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

The download and tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware

Run Malwarebytes Anti-Malware
Update the definitions and scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with SuperAntiSpyware.

Install SUPERAntiSpyware Home Edition (free edition)
You should also scan your computer with this program on a regular basis just as you would an antivirus software in conjunction with Malwarebytes.

Perform an online virus scan
Every so often, also perform an online virus scan.
AntiVirus scanners use databases which are not identical, and one may find malware that another does not.

Some online scanners:
TrendMicro HouseCall: http://uk.trendmicro-europe.com/consumer/h…call_launch.php
Panda ActiveScan: http://www.pandasoftware.com/products/activescan.htm
Kaspersky Online Scanner (using Internet Explorer): http://www.kaspersky.com/virusscanner
BitDefender: http://www.bitdefender.com/scan8/

To simplify making sure you have the latest version of many of your security programs and applications, you may want to consider:
Secunia's Personal Software Inspector (PSI). It is a free utility that scans your computer for installed applications and checks to see if they have the latest security patches and updates. If it finds any applications with possible security issues, links and/or instructions are provided for the necessariy updates.

Filehippo's Update Checker. It is free utilitiy that scan your computer for installed software, checks the versions and then sends this information to see if there are any newer releases. Available software updates are displayed and you can decide which ones to download and install. Among many other types of programs, they includes a number of the Anti-Spyware, Firewall/Security and Anti-Virus programs that have been recommended (though not all of them). Note: Definition files should be updated from within the programs themselves. The Update Checker look for newer versions of the software program, not definition files.

Update all these programs regularly
Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Follow this list and your potential for being infected again will reduce dramatically.

Hopefully this should take care of your problems! Good luck & Happy surfing!

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI