Hello SweetTech and thanks for taking the time to help. Your answers…
1. Any comments or questions you may have that you'd like for me to answer in my next post to you.
Nothing ATT, but once the culprit is found, advice on how to further shore up defenses.
2. The logs that were produced after running the OTL scans. (OTL.txt & Extras.txt)
Here is the first OTL.txt
OTL logfile created on: 6/1/2010 7:52:17 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 7.09 Gb Free Space | 11.00% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
========== Modules (SafeList) ==========
MOD - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (ENETHUSB) – C:\Windows\System32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (MaVctrl) – C:\Windows\System32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (maz500u) – C:\Windows\System32\drivers\maz500u.sys (Mobile Action Technology Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (maz500m) – C:\Windows\System32\drivers\maz500m.sys (Mobile Action Technology Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
http://www.google.com/ig/dell?hl=en&cl;…amp;ibd=4071026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "
http://bing.zugo.com/?cfg=2-77-0-X35c"
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: {f0178163-d454-7451-6914-3ddfbc0cdfe6}:[removed]
FF - prefs.js..extensions.enabledItems: {896642E4-C556-4ED3-85D1-9AC431603E7D}:1.0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..keyword.URL: "
http://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;="
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 12:54:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 12:54:00 | 000,000,000 | —D | M]
[2009/11/04 17:40:27 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Extensions
[2010/05/23 21:03:57 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions
[2009/12/10 23:35:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/11 17:16:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/26 20:21:56 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}
[2010/02/04 13:04:15 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]
[2010/04/26 20:21:57 | 000,000,737 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\searchplugins\bing-ff.xml
[2010/04/26 20:22:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}
O1 HOSTS File: ([2010/05/05 20:24:28 | 000,393,216 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 13579 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ABC] C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380}
http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://frontier.webex.com/client/T26L/support/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\AutoRun\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\install\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualEnglish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualFrench\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualSpanish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/10/01 03:13:09 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.SP54 - C:\Windows\System32\Sp5x_32.dll (Sunplus)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/06/01 19:50:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/05/31 12:34:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/31 10:41:12 | 000,998,736 | —- | C] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 09:53:07 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2010/05/31 09:53:03 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/05/29 08:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/25 17:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/15 23:52:11 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\assembly
[2010/05/15 23:50:58 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\IsolatedStorage
[2010/05/15 23:48:24 | 000,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/05/04 21:57:13 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2010/05/04 21:57:04 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/04 21:57:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 21:57:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/04 21:57:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/06/01 19:56:08 | 006,553,600 | -HS- | M] () – C:\Users\Home\ntuser.dat
[2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/06/01 19:50:39 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 16:33:40 | 000,000,236 | —- | M] () – C:\Users\Home\Desktop\DAN-gh..url
[2010/05/31 20:31:02 | 003,701,914 | —- | M] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 20:28:37 | 000,998,736 | —- | M] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 12:34:55 | 000,002,521 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:17 | 001,402,880 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:31:58 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 12:31:58 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/31 12:31:58 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/31 12:25:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/31 12:25:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2010/05/31 12:24:48 | 000,524,288 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 12:24:48 | 000,065,536 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TM.blf
[2010/05/31 11:21:19 | 000,001,087 | —- | M] () – C:\Users\Home\Desktop\Spybot - Search & Destroy.lnk
[2010/05/29 08:47:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/05/29 08:47:00 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:47 | 051,731,232 | —- | M] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/27 03:00:00 | 000,000,308 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/26 03:00:00 | 000,000,316 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/23 21:09:40 | 000,006,866 | —- | M] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:47 | 000,033,094 | —- | M] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/16 00:31:52 | 000,018,432 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:50:34 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/15 19:37:11 | 003,852,800 | —- | M] () – C:\Users\Home\Desktop\The Rodwell Line.wps
[2010/05/15 19:37:11 | 000,001,104 | —- | M] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/06 15:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/05 20:24:28 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/05/05 20:21:16 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202428.backup
[2010/05/05 20:18:35 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202116.backup
[2010/05/04 21:57:06 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/01 19:50:35 | 000,293,376 | —- | C] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/05/31 20:30:55 | 003,701,914 | —- | C] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 12:34:34 | 000,002,521 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:06 | 001,402,880 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | C] () – C:\hiberfil.sys
[2010/05/29 08:47:00 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:42 | 051,731,232 | —- | C] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/23 21:09:40 | 000,006,866 | —- | C] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:46 | 000,033,094 | —- | C] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/15 23:50:34 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/05 20:07:07 | 000,000,316 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/05 20:05:15 | 000,000,308 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/04 21:57:06 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/09/11 01:57:46 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/03/19 09:05:30 | 000,000,110 | —- | C] () – C:\Windows\TLCAPPS.INI
[2009/03/08 15:37:48 | 000,000,343 | —- | C] () – C:\Windows\WININIT.INI
[2009/03/08 15:37:28 | 000,000,068 | —- | C] () – C:\Windows\SLS.INI
[2008/09/19 16:57:34 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 16:54:18 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/27 00:15:08 | 000,001,325 | —- | C] () – C:\Windows\Remove.ini
[2008/05/26 21:32:40 | 000,000,000 | —- | C] () – C:\Windows\I531_109.INI
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2010/04/13 08:56:00 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/09 23:11:49 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\LimeWire
[2008/06/07 11:56:21 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\MobileAction
[2009/10/04 23:15:29 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Softplicity
[2007/12/26 23:18:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2007/12/22 19:05:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Wal-Mart
[2010/05/31 11:24:42 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/10/25 19:32:57 | 000,004,095 | RH– | M] () – C:\dell.sdr
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/05/31 12:25:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/22 20:39:20 | 000,008,947 | —- | M] () – C:\SSInst.log
[2010/05/31 20:33:35 | 000,054,618 | —- | M] () – C:\TDSSKiller.2.3.2.0_31.05.2010_20.33.14_log.txt
[2008/06/27 15:08:30 | 000,000,000 | —- | M] () – C:\wizard.txt
[2007/12/28 22:28:01 | 000,000,158 | —- | M] () – C:\YServer.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 06:31:42 | 000,348,160 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/03/08 06:31:37 | 000,216,064 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 06:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 06:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 06:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 06:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 06:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 09:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/12/08 12:26:18 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2010/02/18 06:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 777 bytes -> C:\Users\Home\Desktop\RE_ Rushton Family .eml:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Home\Desktop\More pictures.eml:OECustomProperty
< End of report >
I will split these logs up in separate posts, as they are a little long…
3OTL logfile created on: 6/1/2010 7:52:17 PM - Run 1
OTL by OldTimer - Version 3.2.5.3 Folder = C:\Users\Home\Desktop
Windows Vista Home Basic Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18904)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
2.00 Gb Total Physical Memory | 1.00 Gb Available Physical Memory | 54.00% Memory free
4.00 Gb Paging File | 3.00 Gb Available in Paging File | 69.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 64.46 Gb Total Space | 7.09 Gb Free Space | 11.00% Space Free | Partition Type: NTFS
Drive D: | 10.00 Gb Total Space | 7.00 Gb Free Space | 70.05% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: HOME-PC
Current User Name: Home
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
PRC - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
PRC - C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
PRC - C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
PRC - C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
PRC - C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
PRC - C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
PRC - C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
PRC - C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
PRC - C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
PRC - C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
========== Modules (SafeList) ==========
MOD - C:\Users\Home\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18005_none_5cb72f96088b0de0\comctl32.dll (Microsoft Corporation)
MOD - C:\Windows\System32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (ALWIL Software)
SRV - (Steam Client Service) – C:\Program Files\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (GoogleDesktopManager-110309-193829) – C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
SRV - (FontCache) – C:\Windows\System32\FntCache.dll (Microsoft Corporation)
SRV - (SBSDWSCService) – C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe (Safer Networking Ltd.)
SRV - (atashost) – C:\Windows\System32\atashost.exe (WebEx Communications, Inc.)
SRV - (YahooAUService) – C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
SRV - (sprtsvc_dellsupportcenter) SupportSoft Sprocket Service (dellsupportcenter) – C:\Program Files\Dell Support Center\bin\sprtsvc.exe (SupportSoft, Inc.)
SRV - (GoToAssist) – C:\Program Files\Citrix\GoToAssist\514\g2aservice.exe (Citrix Online, a division of Citrix Systems, Inc.)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AERTFilters) – C:\Windows\System32\AERTSrv.exe (Andrea Electronics Corporation)
SRV - (DSBrokerService) – C:\Program Files\DellSupport\brkrsvc.exe ()
========== Driver Services (SafeList) ==========
DRV - (aswTdi) – C:\Windows\System32\drivers\aswTdi.sys (ALWIL Software)
DRV - (aswSP) – C:\Windows\System32\drivers\aswSP.sys (ALWIL Software)
DRV - (aswRdr) – C:\Windows\System32\drivers\aswRdr.sys (ALWIL Software)
DRV - (aswMonFlt) – C:\Windows\System32\drivers\aswMonFlt.sys (ALWIL Software)
DRV - (aswFsBlk) – C:\Windows\System32\drivers\aswFsBlk.sys (ALWIL Software)
DRV - (nvlddmkm) – C:\Windows\System32\drivers\nvlddmkm.sys (NVIDIA Corporation)
DRV - (pavboot) – C:\Windows\system32\drivers\pavboot.sys (Panda Security, S.L.)
DRV - (IntcAzAudAddService) Service for Realtek HD Audio (WDM) – C:\Windows\System32\drivers\RTKVHDA.sys (Realtek Semiconductor Corp.)
DRV - (X4HSX32) – C:\Program Files\GameTap\bin\Release\X4HSX32.sys (Exent Technologies Ltd.)
DRV - (xnacc) – C:\Windows\System32\drivers\xnacc.sys (Microsoft Corporation)
DRV - (viaide) – C:\Windows\system32\drivers\viaide.sys (VIA Technologies, Inc.)
DRV - (cmdide) – C:\Windows\system32\drivers\cmdide.sys (CMD Technology, Inc.)
DRV - (aliide) – C:\Windows\system32\drivers\aliide.sys (Acer Laboratories Inc.)
DRV - (xusb21) – C:\Windows\System32\drivers\xusb21.sys (Microsoft Corporation)
DRV - (nvstor32) – C:\Windows\system32\DRIVERS\nvstor32.sys (NVIDIA Corporation)
DRV - (NVENETFD) – C:\Windows\System32\drivers\nvmfdx32.sys (NVIDIA Corporation)
DRV - (dsunidrv) – C:\Windows\System32\drivers\dsunidrv.sys (Gteko Ltd.)
DRV - (ENETHUSB) – C:\Windows\System32\drivers\enethusb.sys (Siemens Subscriber Networks, Inc.)
DRV - (MaVctrl) – C:\Windows\System32\drivers\MaVc2K.sys (Mobile Action Technology Inc.)
DRV - (nvstor) – C:\Windows\system32\drivers\nvstor.sys (NVIDIA Corporation)
DRV - (maz500u) – C:\Windows\System32\drivers\maz500u.sys (Mobile Action Technology Inc.)
DRV - (ql2300) – C:\Windows\system32\drivers\ql2300.sys (QLogic Corporation)
DRV - (adp94xx) – C:\Windows\system32\drivers\adp94xx.sys (Adaptec, Inc.)
DRV - (elxstor) – C:\Windows\system32\drivers\elxstor.sys (Emulex)
DRV - (adpahci) – C:\Windows\system32\drivers\adpahci.sys (Adaptec, Inc.)
DRV - (uliahci) – C:\Windows\system32\drivers\uliahci.sys (ULi Electronics Inc.)
DRV - (iaStorV) – C:\Windows\system32\drivers\iastorv.sys (Intel Corporation)
DRV - (adpu320) – C:\Windows\system32\drivers\adpu320.sys (Adaptec, Inc.)
DRV - (ulsata2) – C:\Windows\system32\drivers\ulsata2.sys (Promise Technology, Inc.)
DRV - (vsmraid) – C:\Windows\system32\drivers\vsmraid.sys (VIA Technologies Inc.,Ltd)
DRV - (ql40xx) – C:\Windows\system32\drivers\ql40xx.sys (QLogic Corporation)
DRV - (UlSata) – C:\Windows\system32\drivers\ulsata.sys (Promise Technology, Inc.)
DRV - (adpu160m) – C:\Windows\system32\drivers\adpu160m.sys (Adaptec, Inc.)
DRV - (nvraid) – C:\Windows\system32\drivers\nvraid.sys (NVIDIA Corporation)
DRV - (nfrd960) – C:\Windows\system32\drivers\nfrd960.sys (IBM Corporation)
DRV - (iirsp) – C:\Windows\system32\drivers\iirsp.sys (Intel Corp./ICP vortex GmbH)
DRV - (SiSRaid4) – C:\Windows\system32\drivers\sisraid4.sys (Silicon Integrated Systems)
DRV - (aic78xx) – C:\Windows\system32\drivers\djsvs.sys (Adaptec, Inc.)
DRV - (arcsas) – C:\Windows\system32\drivers\arcsas.sys (Adaptec, Inc.)
DRV - (LSI_SCSI) – C:\Windows\system32\drivers\lsi_scsi.sys (LSI Logic)
DRV - (SiSRaid2) – C:\Windows\system32\drivers\sisraid2.sys (Silicon Integrated Systems Corp.)
DRV - (HpCISSs) – C:\Windows\system32\drivers\hpcisss.sys (Hewlett-Packard Company)
DRV - (arc) – C:\Windows\system32\drivers\arc.sys (Adaptec, Inc.)
DRV - (iteraid) – C:\Windows\system32\drivers\iteraid.sys (Integrated Technology Express, Inc.)
DRV - (iteatapi) – C:\Windows\system32\drivers\iteatapi.sys (Integrated Technology Express, Inc.)
DRV - (LSI_SAS) – C:\Windows\system32\drivers\lsi_sas.sys (LSI Logic)
DRV - (Symc8xx) – C:\Windows\system32\drivers\symc8xx.sys (LSI Logic)
DRV - (LSI_FC) – C:\Windows\system32\drivers\lsi_fc.sys (LSI Logic)
DRV - (Sym_u3) – C:\Windows\system32\drivers\sym_u3.sys (LSI Logic)
DRV - (Mraid35x) – C:\Windows\system32\drivers\mraid35x.sys (LSI Logic Corporation)
DRV - (Sym_hi) – C:\Windows\system32\drivers\sym_hi.sys (LSI Logic)
DRV - (megasas) – C:\Windows\system32\drivers\megasas.sys (LSI Logic Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (Brserid) Brother MFC Serial Port Interface Driver (WDM) – C:\Windows\system32\drivers\brserid.sys (Brother Industries Ltd.)
DRV - (BrUsbSer) – C:\Windows\system32\drivers\brusbser.sys (Brother Industries Ltd.)
DRV - (BrFiltUp) – C:\Windows\system32\drivers\brfiltup.sys (Brother Industries, Ltd.)
DRV - (BrFiltLo) – C:\Windows\system32\drivers\brfiltlo.sys (Brother Industries, Ltd.)
DRV - (BrSerWdm) – C:\Windows\system32\drivers\brserwdm.sys (Brother Industries Ltd.)
DRV - (BrUsbMdm) – C:\Windows\system32\drivers\brusbmdm.sys (Brother Industries Ltd.)
DRV - (ntrigdigi) – C:\Windows\system32\drivers\ntrigdigi.sys (N-trig Innovative Technologies)
DRV - (R300) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (e1express) Intel® – C:\Windows\System32\drivers\e1e6032.sys (Intel Corporation)
DRV - (E1G60) Intel® – C:\Windows\System32\drivers\E1G60I32.sys (Intel Corporation)
DRV - (HSF_DPV) – C:\Windows\System32\drivers\HSX_DPV.sys (Conexant Systems, Inc.)
DRV - (HSXHWBS2) – C:\Windows\System32\drivers\HSXHWBS2.sys (Conexant Systems, Inc.)
DRV - (winachsf) – C:\Windows\System32\drivers\HSX_CNXT.sys (Conexant Systems, Inc.)
DRV - (DSproct) – C:\Program Files\DellSupport\GTAction\triggers\DSproct.sys (Gteko Ltd.)
DRV - (XAudio) – C:\Windows\System32\drivers\XAudio.sys (Conexant Systems, Inc.)
DRV - (sscdmdm) – C:\Windows\System32\drivers\sscdmdm.sys (MCCI)
DRV - (sscdmdfl) – C:\Windows\System32\drivers\sscdmdfl.sys (MCCI)
DRV - (sscdbus) SAMSUNG USB Composite Device driver (WDM) – C:\Windows\System32\drivers\sscdbus.sys (MCCI)
DRV - (maz500m) – C:\Windows\System32\drivers\maz500m.sys (Mobile Action Technology Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,CustomSearch = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page =
http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore =
http://www.google.com/ig/dell?hl=en&cl;…amp;ibd=4071026
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.selectedEngine: "Bing"
FF - prefs.js..browser.startup.homepage: "
http://bing.zugo.com/?cfg=2-77-0-X35c"
FF - prefs.js..extensions.enabledItems: [removed]:0.4.1.1
FF - prefs.js..extensions.enabledItems: {f0178163-d454-7451-6914-3ddfbc0cdfe6}:[removed]
FF - prefs.js..extensions.enabledItems: {896642E4-C556-4ED3-85D1-9AC431603E7D}:1.0.4
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.5.8.6
FF - prefs.js..keyword.URL: "
http://bing.zugotoolbar.com/s/?iesrc=IE-Address&site;=Bing&q;="
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2010/04/11 12:54:00 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.5.9\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2010/04/11 12:54:00 | 000,000,000 | —D | M]
[2009/11/04 17:40:27 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Extensions
[2010/05/23 21:03:57 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions
[2009/12/10 23:35:41 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/11 17:16:39 | 000,000,000 | —D | M] (Zynga Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2010/04/26 20:21:56 | 000,000,000 | —D | M] (Search Toolbar) – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\{896642E4-C556-4ED3-85D1-9AC431603E7D}
[2010/02/04 13:04:15 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\extensions\[removed]
[2010/04/26 20:21:57 | 000,000,737 | —- | M] () – C:\Users\Home\AppData\Roaming\Mozilla\Firefox\Profiles\jk59gxay.default\searchplugins\bing-ff.xml
[2010/04/26 20:22:13 | 000,000,000 | —D | M] – C:\Program Files\Mozilla Firefox\extensions
[2010/04/26 20:22:13 | 000,000,000 | —D | M] (LoudMo Contextual Ad Assistant) – C:\Program Files\Mozilla Firefox\extensions\{f0178163-d454-7451-6914-3ddfbc0cdfe6}
O1 HOSTS File: ([2010/05/05 20:24:28 | 000,393,216 | R— | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-domains-registrations.com
O1 - Hosts: 127.0.0.1 www.1-domains-registrations.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 13579 more lines…
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O2 - BHO: (Spybot-S&D; IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O2 - BHO: (WitBHO Class) - {75ED56AF-4DC9-4243-A30C-4EF4DD0CA28F} - C:\Program Files\ChameleonTom\wit4ie.dll File not found
O2 - BHO: (SSVHelper Class) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - c:\Program Files\Java\jre1.6.0\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O2 - BHO: (CBrowserHelperObject Object) - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\Dell\BAE\BAE.dll (Dell Inc.)
O2 - BHO: (TBSB05974 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKLM\..\Toolbar: (&Google;) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {0C8413C1-FAD1-446C-8584-BE50576F863E} - C:\Program Files\Search Toolbar\tbcore3.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (&Google;) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Program Files\Google\GoogleToolbar1.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\tbZyng.dll (Conduit Ltd.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (ALWIL Software)
O4 - HKLM..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKLM..\Run: [dscactivate] C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe ( )
O4 - HKLM..\Run: [ECenter] C:\DELL\E-Center\EULALauncher.exe ( )
O4 - HKLM..\Run: [Google Desktop Search] C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe (Google)
O4 - HKLM..\Run: [Malwarebytes Anti-Malware (reboot)] C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [PDVDDXSrv] C:\Program Files\CyberLink\PowerDVD DX\PDVDDXSrv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [RtHDVCpl] C:\Windows\RtHDVCpl.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKCU..\Run: [ABC] C:\Users\Home\AppData\Local\Temp\SoftwareProtection.exe (Microsoft Inc.)
O4 - HKCU..\Run: [DellSupport] C:\Program Files\DellSupport\DSAgnt.exe (Gteko Ltd.)
O4 - HKCU..\Run: [DellSupportCenter] C:\Program Files\Dell Support Center\bin\sprtcmd.exe (SupportSoft, Inc.)
O4 - HKCU..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe (Safer-Networking Ltd.)
O4 - HKCU..\RunOnce: [Shockwave Updater] C:\Windows\System32\Adobe\Shockwave 11\SwHelper_1151601.exe -Update -1151601 -Mozilla\4.0 (compatible; MSIE 7.0; Windows NT 6.0; Trident\4.0; File not found
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - c:\Program Files\Java\jre1.6.0\bin\npjpi160.dll (Sun Microsystems, Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Ranges: GD ([http] in Local intranet)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} http://appldnld.apple.com.edgesuite.net/co…ex/qtplugin.cab (QuickTime Object)
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} http://upload.facebook.com/controls/2008.1…toUploader5.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} http://lads.myspace.com/upload/MySpaceUploader1006.cab (MySpace Uploader Control)
O16 - DPF: {49312E18-AA92-4CC2-BB97-55DEA7BCADD6}
http://support.dell.com/systemprofiler/SysProExe.CAB (WMI Class)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913}
http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab (ActiveScan 2.0 Installer Class)
O16 - DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0)
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380}
http://www.instantaction.com/download/iaplayer.cab (InstantAction Game Launcher)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C}
https://frontier.webex.com/client/T26L/support/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - AppInit_DLLs: (C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLL) - C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll (Google)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\GoToAssist: DllName - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll - C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll File not found
O24 - Desktop WallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O24 - Desktop BackupWallPaper: C:\Users\Home\AppData\Roaming\Microsoft\Windows Photo Gallery\Windows Photo Gallery Wallpaper.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/18 16:43:36 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\AutoRun\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\install\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualEnglish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualFrench\command - "" = F:\rcaeasyrip_setup.exe – File not found
O33 - MountPoints2\{3163d020-eb73-11de-8a29-001aa05eef43}\Shell\usermanualSpanish\command - "" = F:\rcaeasyrip_setup.exe – File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias [2008/10/01 03:13:09 | 000,000,000 | —D | M]
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: Wmi - C:\Windows\System32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found
Drivers32: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\System32\DivX.dll (DivX, Inc.)
Drivers32: VIDC.SP54 - C:\Windows\System32\Sp5x_32.dll (Sunplus)
Drivers32: vidc.yv12 - C:\Windows\System32\DivX.dll (DivX, Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2010/06/01 19:50:36 | 000,571,904 | —- | C] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/05/31 12:34:34 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/31 10:41:12 | 000,998,736 | —- | C] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 09:53:07 | 000,028,552 | —- | C] (Panda Security, S.L.) – C:\Windows\System32\drivers\pavboot.sys
[2010/05/31 09:53:03 | 000,000,000 | —D | C] – C:\Program Files\Panda Security
[2010/05/29 08:45:29 | 000,000,000 | —D | C] – C:\ProgramData\Alwil Software
[2010/05/25 17:00:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\System32\tzres.dll
[2010/05/15 23:52:11 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\assembly
[2010/05/15 23:50:58 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Local\IsolatedStorage
[2010/05/15 23:48:24 | 000,000,000 | —D | C] – C:\Program Files\Virtual Earth 3D
[2010/05/04 21:57:13 | 000,000,000 | —D | C] – C:\Users\Home\AppData\Roaming\Malwarebytes
[2010/05/04 21:57:04 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/05/04 21:57:03 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/04 21:57:02 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/05/04 21:57:01 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2010/06/01 19:56:08 | 006,553,600 | -HS- | M] () – C:\Users\Home\ntuser.dat
[2010/06/01 19:50:45 | 000,293,376 | —- | M] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/06/01 19:50:39 | 000,571,904 | —- | M] (OldTimer Tools) – C:\Users\Home\Desktop\OTL.exe
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 18:25:41 | 000,003,568 | -H– | M] () – C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/01 16:33:40 | 000,000,236 | —- | M] () – C:\Users\Home\Desktop\DAN-gh..url
[2010/05/31 20:31:02 | 003,701,914 | —- | M] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 20:28:37 | 000,998,736 | —- | M] (Kaspersky Lab) – C:\Users\Home\Desktop\TDSSKiller.exe
[2010/05/31 12:34:55 | 000,002,521 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:17 | 001,402,880 | —- | M] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:31:58 | 000,690,960 | —- | M] () – C:\Windows\System32\PerfStringBackup.INI
[2010/05/31 12:31:58 | 000,595,446 | —- | M] () – C:\Windows\System32\perfh009.dat
[2010/05/31 12:31:58 | 000,101,144 | —- | M] () – C:\Windows\System32\perfc009.dat
[2010/05/31 12:25:45 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/05/31 12:25:34 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2010/05/31 12:24:48 | 000,524,288 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 12:24:48 | 000,065,536 | -HS- | M] () – C:\Users\Home\ntuser.dat{6ee29a04-1b3e-11de-b98e-001aa05eef43}.TM.blf
[2010/05/31 11:21:19 | 000,001,087 | —- | M] () – C:\Users\Home\Desktop\Spybot - Search & Destroy.lnk
[2010/05/29 08:47:00 | 000,002,577 | —- | M] () – C:\Windows\System32\config.nt
[2010/05/29 08:47:00 | 000,001,842 | —- | M] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:47 | 051,731,232 | —- | M] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/27 03:00:00 | 000,000,308 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/26 03:00:00 | 000,000,316 | —- | M] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/23 21:09:40 | 000,006,866 | —- | M] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:47 | 000,033,094 | —- | M] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/16 00:31:52 | 000,018,432 | —- | M] () – C:\Users\Home\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/05/15 23:50:34 | 000,001,891 | —- | M] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/15 19:37:11 | 003,852,800 | —- | M] () – C:\Users\Home\Desktop\The Rodwell Line.wps
[2010/05/15 19:37:11 | 000,001,104 | —- | M] () – C:\Users\Home\AppData\Roaming\wklnhst.dat
[2010/05/12 11:21:16 | 000,221,568 | —- | M] (Microsoft Corporation) – C:\Windows\System32\MpSigStub.exe
[2010/05/06 15:59:57 | 000,038,848 | —- | M] (ALWIL Software) – C:\Windows\System32\avastSS.scr
[2010/05/06 15:59:36 | 000,165,032 | —- | M] (ALWIL Software) – C:\Windows\System32\aswBoot.exe
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/05 20:24:28 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts
[2010/05/05 20:21:16 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202428.backup
[2010/05/05 20:18:35 | 000,393,216 | R— | M] () – C:\Windows\System32\drivers\etc\hosts.20100505-202116.backup
[2010/05/04 21:57:06 | 000,000,820 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/01 19:50:35 | 000,293,376 | —- | C] () – C:\Users\Home\Desktop\jn9ule5l.exe
[2010/05/31 20:30:55 | 003,701,914 | —- | C] () – C:\Users\Home\Desktop\ComboFix.exe
[2010/05/31 12:34:34 | 000,002,521 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.lnk
[2010/05/31 12:33:06 | 001,402,880 | —- | C] () – C:\Users\Home\Desktop\HiJackThis.msi
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | C] () – C:\hiberfil.sys
[2010/05/29 08:47:00 | 000,001,842 | —- | C] () – C:\Users\Public\Desktop\avast! Free Antivirus.lnk
[2010/05/29 08:43:42 | 051,731,232 | —- | C] () – C:\Users\Home\Desktop\setup_av_free.exe
[2010/05/23 21:09:40 | 000,006,866 | —- | C] () – C:\Users\Home\Desktop\Outer lines.rtf
[2010/05/22 19:40:46 | 000,033,094 | —- | C] () – C:\Users\Home\Desktop\DF-Spider_Sound.ogg
[2010/05/15 23:50:34 | 000,001,891 | —- | C] () – C:\Users\Public\Desktop\Bing Maps 3D.lnk
[2010/05/05 20:07:07 | 000,000,316 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy Updater - Scheduled Task.job
[2010/05/05 20:05:15 | 000,000,308 | —- | C] () – C:\Windows\tasks\Spybot - Search & Destroy - Scheduled Task.job
[2010/05/04 21:57:06 | 000,000,820 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/04/02 17:17:34 | 000,179,091 | —- | C] () – C:\Windows\System32\xlive.dll.cat
[2009/09/11 01:57:46 | 000,117,248 | —- | C] () – C:\Windows\System32\EhStorAuthn.dll
[2009/03/19 09:05:30 | 000,000,110 | —- | C] () – C:\Windows\TLCAPPS.INI
[2009/03/08 15:37:48 | 000,000,343 | —- | C] () – C:\Windows\WININIT.INI
[2009/03/08 15:37:28 | 000,000,068 | —- | C] () – C:\Windows\SLS.INI
[2008/09/19 16:57:34 | 003,596,288 | —- | C] () – C:\Windows\System32\qt-dx331.dll
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dtu100.dll.manifest
[2008/09/19 16:55:10 | 000,000,416 | —- | C] () – C:\Windows\System32\dpl100.dll.manifest
[2008/09/19 16:54:18 | 000,012,288 | —- | C] () – C:\Windows\System32\DivXWMPExtType.dll
[2008/05/27 00:15:08 | 000,001,325 | —- | C] () – C:\Windows\Remove.ini
[2008/05/26 21:32:40 | 000,000,000 | —- | C] () – C:\Windows\I531_109.INI
[2007/03/19 05:04:58 | 000,003,584 | —- | C] () – C:\Windows\System32\namResES.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResIT.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResFR.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResENG.dll
[2007/03/19 05:04:58 | 000,003,072 | —- | C] () – C:\Windows\System32\namResDE.dll
[2007/03/19 05:04:56 | 000,003,584 | —- | C] () – C:\Windows\System32\namResPTB.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHC.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResKO.dll
[2007/03/19 05:04:56 | 000,003,072 | —- | C] () – C:\Windows\System32\namResJA.dll
[2007/03/19 05:04:54 | 000,022,016 | —- | C] () – C:\Windows\System32\nam_page.dll
[2007/03/19 05:04:54 | 000,003,072 | —- | C] () – C:\Windows\System32\namResZHT.dll
[2006/11/02 05:25:44 | 000,159,744 | —- | C] () – C:\Windows\System32\atitmmxx.dll
[2006/11/02 02:40:29 | 000,013,750 | —- | C] () – C:\Windows\System32\pacerprf.ini
========== LOP Check ==========
[2010/04/13 08:56:00 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/02/09 23:11:49 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\LimeWire
[2008/06/07 11:56:21 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\MobileAction
[2009/10/04 23:15:29 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Softplicity
[2007/12/26 23:18:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Template
[2007/12/22 19:05:54 | 000,000,000 | —D | M] – C:\Users\Home\AppData\Roaming\Wal-Mart
[2010/05/31 11:24:42 | 000,032,590 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2006/09/18 16:43:36 | 000,000,024 | —- | M] () – C:\autoexec.bat
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2006/11/10 16:59:07 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2006/09/18 16:43:37 | 000,000,010 | —- | M] () – C:\config.sys
[2007/10/25 19:32:57 | 000,004,095 | RH– | M] () – C:\dell.sdr
[2010/05/31 12:25:30 | 2078,793,728 | -HS- | M] () – C:\hiberfil.sys
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2008/05/26 13:44:41 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2010/05/31 12:25:28 | 2392,596,480 | -HS- | M] () – C:\pagefile.sys
[2007/11/22 20:39:20 | 000,008,947 | —- | M] () – C:\SSInst.log
[2010/05/31 20:33:35 | 000,054,618 | —- | M] () – C:\TDSSKiller.2.3.2.0_31.05.2010_20.33.14_log.txt
[2008/06/27 15:08:30 | 000,000,000 | —- | M] () – C:\wizard.txt
[2007/12/28 22:28:01 | 000,000,158 | —- | M] () – C:\YServer.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2009/03/08 06:31:42 | 000,348,160 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\dxtmsft.dll
[2009/03/08 06:31:37 | 000,216,064 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\dxtrans.dll
[2009/04/11 01:27:47 | 000,241,128 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\rsaenh.dll
[2009/04/11 01:28:23 | 000,228,352 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\Windows\System32\SLC.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\COMPONENTS.SAV
[2006/11/02 05:34:05 | 000,020,480 | —- | M] () – C:\Windows\System32\config\DEFAULT.SAV
[2006/11/02 05:34:05 | 000,008,192 | —- | M] () – C:\Windows\System32\config\SECURITY.SAV
[2006/11/02 05:34:08 | 010,133,504 | —- | M] () – C:\Windows\System32\config\SOFTWARE.SAV
[2006/11/02 05:34:08 | 001,826,816 | —- | M] () – C:\Windows\System32\config\SYSTEM.SAV
< %systemroot%\system32\drivers\*.sys /180 >
[2010/05/06 15:33:47 | 000,019,024 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswFsBlk.sys
[2010/05/06 15:34:10 | 000,051,792 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswMonFlt.sys
[2010/05/06 15:34:27 | 000,023,376 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswRdr.sys
[2010/05/06 15:39:00 | 000,164,048 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswSP.sys
[2010/05/06 15:39:23 | 000,046,672 | —- | M] (ALWIL Software) – C:\Windows\System32\drivers\aswTdi.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\System32\drivers\mbamswissarmy.sys
[2010/02/23 06:10:13 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb.sys
[2010/02/23 06:10:19 | 000,212,992 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb10.sys
[2010/02/23 06:10:13 | 000,079,360 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\mrxsmb20.sys
[2009/12/11 06:43:30 | 000,302,080 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srv.sys
[2009/12/11 06:43:11 | 000,098,816 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\srvnet.sys
[2010/02/18 09:07:16 | 000,904,576 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpip.sys
[2009/12/08 12:26:18 | 000,030,720 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tcpipreg.sys
[2010/02/18 06:28:13 | 000,025,088 | —- | M] (Microsoft Corporation) – C:\Windows\System32\drivers\tunnel.sys
========== Alternate Data Streams ==========
@Alternate Data Stream - 777 bytes -> C:\Users\Home\Desktop\RE_ Rushton Family .eml:OECustomProperty
@Alternate Data Stream - 741 bytes -> C:\Users\Home\Desktop\More pictures.eml:OECustomProperty
< End of report >