OK scans took a little bit of time to run, but they are complete.
1. No questions
2. OTL Fix log:
All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D70E6A20-7060-4829-B3D7-B6624A1DE7C6}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D70E6A20-7060-4829-B3D7-B6624A1DE7C6}\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C}
C:\WINDOWS\Downloaded Program Files\erma.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found.
Starting removal of ActiveX control {9F1C11AA-197B-4942-BA54-47A8489BB47F}
C:\WINDOWS\Downloaded Program Files\iuctl.inf moved successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9F1C11AA-197B-4942-BA54-47A8489BB47F}\ not found.
File oft XML Parser for Java file://C:\WINDOWS\Java\classes\xmldso.cab not found.
Starting removal of ActiveX control Microsoft XML Parser for Java
Registry error reading value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\DownloadInformation\\INF .
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\Microsoft XML Parser for Java\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\Microsoft XML Parser for Java\ not found.
Registry value HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Session Manager\AppCertDlls\\dwwionce:C:\WINDOWS\system32\cidadiag.dll deleted successfully.
C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\ujwgoufgd folder moved successfully.
C:\WINDOWS\System32\CONFIG.TMP deleted successfully.
C:\WINDOWS\System32\SET29.tmp deleted successfully.
C:\WINDOWS\System32\SET49.tmp deleted successfully.
C:\WINDOWS\System32\SET4C.tmp deleted successfully.
C:\WINDOWS\System32\SET5B.tmp deleted successfully.
C:\WINDOWS\002581_.tmp deleted successfully.
C:\WINDOWS\005747_.tmp deleted successfully.
C:\WINDOWS\SET20.tmp deleted successfully.
C:\WINDOWS\SET2C.tmp deleted successfully.
C:\WINDOWS\SET3E.tmp deleted successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k0 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k7 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k6 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k5 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k4 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k3 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k2 moved successfully.
C:\WINDOWS\SYSTEM32\DRIVERS\kmxcfg.u2k1 moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: All Users
User: Brandon Miles
->Temp folder emptied: 270508419 bytes
->Temporary Internet Files folder emptied: 101615822 bytes
->Java cache emptied: 65132124 bytes
->Flash cache emptied: 8737 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 66016 bytes
->Temporary Internet Files folder emptied: 31332497 bytes
->Flash cache emptied: 1639 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 29198434 bytes
->Flash cache emptied: 15225 bytes
User: Owner
->Temp folder emptied: 7282654 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: RBM
->Temp folder emptied: 835 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 26588950 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 31223450 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 594079 bytes
RecycleBin emptied: 179481913 bytes
Total Files Cleaned = 709.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Brandon Miles
->Flash cache emptied: 0 bytes
User: Default User
User: LocalService
->Flash cache emptied: 0 bytes
User: NetworkService
->Flash cache emptied: 0 bytes
User: Owner
User: RBM
Total Flash Files Cleaned = 0.00 mb
OTL by OldTimer - Version 3.2.5.2 log created on 06012010_211617
Files\Folders moved on Reboot…
Registry entries deleted on Reboot…
3. Malwarebyte Log:
Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4162
Windows 5.1.2600 Service Pack 3
Internet Explorer 7.0.5730.11
6/1/2010 10:01:53 PM
mbam-log-2010-06-01 (22-01-53).txt
Scan type: Quick scan
Objects scanned: 146642
Time elapsed: 26 minute(s), 24 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\wbazup (Trojan.Hiloti) -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\WINDOWS\mshidx80.dll (Trojan.Hiloti) -> Quarantined and deleted successfully.
C:\Program Files\AWS\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.
C:\WINDOWS\herjek.config (Malware.Trace) -> Quarantined and deleted successfully.
4. ESET log (interesting file name

):
C:\Documents and Settings\Brandon Miles\Shared\jaimee hammer cute girl has orgasm on webcam.mpg a variant of WMA/TrojanDownloader.GetCodec.gen trojan
C:\Program Files\Morpheus\morpheustoolbar.exe Win32/Toolbar.AskSBar application
5. OTL Scan Log:
OTL logfile created on: 6/2/2010 1:12:57 AM - Run 2
OTL by OldTimer - Version 3.2.5.2 Folder = C:\Documents and Settings\Brandon Miles\Desktop
Windows XP Home Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.11)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
767.00 Mb Total Physical Memory | 273.00 Mb Available Physical Memory | 36.00% Memory free
2.00 Gb Paging File | 1.00 Gb Available in Paging File | 77.00% Paging File free
Paging file location(s): c:\pagefile.sys 384 768 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 37.24 Gb Total Space | 12.30 Gb Free Space | 33.04% Space Free | Partition Type: NTFS
D: Drive not present or media not loaded
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: BRANDON
Current User Name: Brandon Miles
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Company Name Whitelist: Off
Skip Microsoft Files: Off
File Age = 30 Days
Output = Minimal
========== Processes (SafeList) ==========
PRC - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfsem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\cavrid.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
PRC - C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
PRC - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exe (CA, Inc.)
PRC - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
PRC - C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
PRC - C:\WINDOWS\SYSTEM32\ltmsg.exe (LUCENT TECHNOLOGIES)
========== Modules (SafeList) ==========
MOD - C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOEHook.dll (CA)
MOD - C:\WINDOWS\SYSTEM32\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV - (CaCCProvSP) – C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exe (CA, Inc.)
SRV - (VETMSGNT) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\vetmsg.exe (CA, Inc.)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft)
SRV - (UmxPol) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxPol.exe (CA)
SRV - (UmxAgent) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxAgent.exe (CA)
SRV - (UmxCfg) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxCfg.exe (CA)
SRV - (UmxFwHlp) – C:\Program Files\CA\SharedComponents\HIPSEngine\UmxFwHlp.exe (CA)
SRV - (CAISafe) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\isafe.exe (Computer Associates International, Inc.)
SRV - (PPCtlPriv) – C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exe (CA, Inc.)
SRV - (ITMRTSVC) – C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exe (CA, Inc.)
========== Driver Services (SafeList) ==========
DRV - (VETEFILE) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys (Computer Associates International, Inc.)
DRV - (VETEBOOT) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys (Computer Associates International, Inc.)
DRV - (VETMONNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys (Computer Associates International, Inc.)
DRV - (VET-FILT) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys (Computer Associates International, Inc.)
DRV - (VETFDDNT) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys (Computer Associates International, Inc.)
DRV - (VET-REC) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys (Computer Associates International, Inc.)
DRV - (Lbd) – C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB)
DRV - (ati2mtag) – C:\WINDOWS\SYSTEM32\DRIVERS\ati2mtag.sys (ATI Technologies Inc.)
DRV - (KmxStart) – C:\WINDOWS\System32\DRIVERS\kmxstart.sys (CA)
DRV - (KmxSbx) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxSbx.sys (CA)
DRV - (KmxFw) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFw.sys (CA)
DRV - (KmxFile) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxFile.sys (CA)
DRV - (KmxCF) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCF.sys (CA)
DRV - (KmxCfg) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxCfg.sys (CA)
DRV - (KmxAgent) – C:\WINDOWS\SYSTEM32\DRIVERS\KmxAgent.sys (CA)
DRV - (amdagp) – C:\WINDOWS\System32\DRIVERS\amdagp.sys (Advanced Micro Devices, Inc.)
DRV - (sisagp) – C:\WINDOWS\System32\DRIVERS\sisagp.sys (Silicon Integrated Systems Corporation)
DRV - (ASCTRM) – C:\WINDOWS\SYSTEM32\DRIVERS\asctrm.sys (Windows ® 2000 DDK provider)
DRV - (ltmodem5) – C:\WINDOWS\SYSTEM32\DRIVERS\ltmdmxp.sys (LT)
DRV - (rtl8139) – C:\WINDOWS\SYSTEM32\DRIVERS\RTL8139.sys (Realtek Semiconductor Corporation )
DRV - (nv4) – C:\WINDOWS\SYSTEM32\DRIVERS\nv4_mini.sys (NVIDIA Corporation)
DRV - (dac2w2k) – C:\WINDOWS\System32\DRIVERS\dac2w2k.sys (Mylex Corporation)
DRV - (ql1280) – C:\WINDOWS\System32\DRIVERS\ql1280.sys (QLogic Corporation)
DRV - (ql12160) – C:\WINDOWS\System32\DRIVERS\ql12160.sys (QLogic Corporation)
DRV - (ql1080) – C:\WINDOWS\System32\DRIVERS\ql1080.sys (QLogic Corporation)
DRV - (hpt3xx) – C:\WINDOWS\System32\DRIVERS\hpt3xx.sys (HighPoint Technologies, Inc.)
DRV - (ultra) – C:\WINDOWS\System32\DRIVERS\ultra.sys (Promise Technology, Inc.)
DRV - (symc8xx) – C:\WINDOWS\System32\DRIVERS\symc8xx.sys (LSI Logic)
DRV - (sym_u3) – C:\WINDOWS\System32\DRIVERS\sym_u3.sys (LSI Logic)
DRV - (sym_hi) – C:\WINDOWS\System32\DRIVERS\sym_hi.sys (LSI Logic)
DRV - (asc) – C:\WINDOWS\System32\DRIVERS\asc.sys (Advanced System Products, Inc.)
DRV - (Sparrow) – C:\WINDOWS\System32\DRIVERS\sparrow.sys (Adaptec, Inc.)
DRV - (mraid35x) – C:\WINDOWS\System32\DRIVERS\mraid35x.sys (American Megatrends Inc.)
DRV - (symc810) – C:\WINDOWS\System32\DRIVERS\symc810.sys (Symbios Logic Inc.)
DRV - (asc3550) – C:\WINDOWS\System32\DRIVERS\asc3550.sys (Advanced System Products, Inc.)
DRV - (CmdIde) – C:\WINDOWS\System32\DRIVERS\cmdide.sys (CMD Technology, Inc.)
DRV - (AliIde) – C:\WINDOWS\System32\DRIVERS\aliide.sys (Acer Laboratories Inc.)
DRV - (MODEMCSA) – C:\WINDOWS\SYSTEM32\DRIVERS\MODEMCSA.sys (Microsoft Corporation)
DRV - (bvrp_pci) – C:\WINDOWS\SYSTEM32\DRIVERS\bvrp_pci.sys ()
DRV - (OMCI) – C:\WINDOWS\SYSTEM32\DRIVERS\OMCI.SYS (Dell Computer Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
O1 HOSTS File: ([2010/05/28 13:10:57 | 000,396,219 | R— | M]) - C:\WINDOWS\SYSTEM32\DRIVERS\ETC\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 13702 more lines…
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: [cafwc] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\cafw.exe (CA, Inc.)
O4 - HKLM..\Run: [capfasem] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfasem.exe (CA, Inc.)
O4 - HKLM..\Run: [capfupgrade] C:\Program Files\CA\CA Internet Security Suite\CA Personal Firewall\capfupgrade.exe (CA, Inc.)
O4 - HKLM..\Run: [CAVRID] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe (CA, Inc.)
O4 - HKLM..\Run: [cctray] C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe (CA, Inc.)
O4 - HKLM..\Run: [Dell|Alert] C:\Program Files\Dell\Support\Alert\bin\DAMon.exe ()
O4 - HKLM..\Run: [LTWinModem1] C:\WINDOWS\System32\ltmsg.exe (LUCENT TECHNOLOGIES)
O4 - HKLM..\Run: [QOELOADER] C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spam\QSP-5.1.18.0\QOELoader.exe (CA)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\WINDOWS\System32\VetRedir.dll (Computer Associates International, Inc.)
O15 - HKCU\..Trusted Domains: microsoft.com ([windowsupdate] https in Trusted sites)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwa…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {233C1507-6A77-46A4-9443-F871F945D258}
http://fpdownload.macromedia.com/get/shock…director/sw.cab (Shockwave ActiveX Control)
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166}
http://cdn.scan.onecare.live.com/resource/…lscbase1140.cab (Windows Live Safety Center Base Module)
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
http://www.update.microsoft.com/microsoftu…b?1275412849031 (MUWebControl Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5}
http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.0…oUploader55.cab (Facebook Photo Uploader 5 Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}
http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_03)
O16 - DPF: {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_06)
O16 - DPF: {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.5.0/jinstall-…indows-i586.cab (Java Plug-in 1.5.0_09)
O16 - DPF: {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_05)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://active.macromedia.com/flash2/cabs/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147}
http://gfx2.hotmail.com/mail/w4/pr01/photo…ol/MSNPUpld.cab (Windows Live Hotmail Photo Upload Tool)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O20 - Winlogon\Notify\AtiExtEvent: DllName - Ati2evxx.dll - C:\WINDOWS\System32\ati2evxx.dll (ATI Technologies Inc.)
O20 - Winlogon\Notify\PFW: DllName - UmxWnp.Dll - C:\WINDOWS\System32\UmxWNP.dll (CA)
O24 - Desktop WallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2001/11/15 08:31:14 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe ()
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs: 6to4 - File not found
NetSvcs: Ias - C:\WINDOWS\SYSTEM32\IAS [2003/01/23 18:41:05 | 000,000,000 | —D | M]
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: Wmi - C:\WINDOWS\SYSTEM32\wmi.dll (Microsoft Corporation)
NetSvcs: WmdmPmSp - File not found
CREATERESTOREPOINT
Restore point Set: OTL Restore Point (16902109354000384)
========== Files/Folders - Created Within 30 Days ==========
[2010/06/01 22:16:37 | 000,000,000 | —D | C] – C:\Program Files\ESET
[2010/06/01 21:31:46 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Application Data\Malwarebytes
[2010/06/01 21:31:16 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbamswissarmy.sys
[2010/06/01 21:31:14 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Malwarebytes
[2010/06/01 21:31:10 | 000,020,952 | —- | C] (Malwarebytes Corporation) – C:\WINDOWS\System32\drivers\mbam.sys
[2010/06/01 21:31:10 | 000,000,000 | —D | C] – C:\Program Files\Malwarebytes' Anti-Malware
[2010/06/01 21:29:49 | 006,153,352 | —- | C] (Malwarebytes Corporation ) – C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe
[2010/06/01 21:16:17 | 000,000,000 | —D | C] – C:\_OTL
[2010/06/01 18:07:05 | 000,571,392 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:28:01 | 000,000,000 | —D | C] – C:\Qoobox
[2010/06/01 17:25:43 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2010/06/01 09:56:17 | 000,739,696 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 09:56:17 | 000,133,520 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:31:48 | 000,099,592 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\isafeif.dll
[2010/06/01 09:31:48 | 000,079,424 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\vetredir.dll
[2010/06/01 09:31:48 | 000,075,016 | —- | C] (CA, Inc.) – C:\WINDOWS\System32\isafprod.dll
[2010/06/01 09:31:48 | 000,032,240 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:31:48 | 000,026,352 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:31:48 | 000,021,488 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:31:48 | 000,021,104 | —- | C] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 09:31:19 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Scanner
[2010/06/01 09:30:59 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\CA
[2010/06/01 09:30:57 | 000,000,000 | —D | C] – C:\Program Files\CA
[2010/06/01 07:32:11 | 045,145,784 | —- | C] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:10:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Application Data\GetRightToGo
[2010/05/29 08:36:46 | 000,000,000 | —D | C] – C:\Program Files\Trend Micro
[2010/05/29 08:05:45 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Macromedia
[2010/05/29 08:05:43 | 000,000,000 | —D | C] – C:\Documents and Settings\LocalService\Application Data\Adobe
[2010/05/29 07:14:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Sun
[2010/05/29 07:14:18 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Adobe
[2010/05/28 12:42:37 | 000,000,000 | —D | C] – C:\Program Files\File Scanner Library (Spybot - Search & Destroy)
[2010/05/28 09:14:55 | 000,064,288 | —- | C] (Lavasoft AB) – C:\WINDOWS\System32\drivers\Lbd.sys
[2010/05/28 09:14:54 | 000,000,000 | —D | C] – C:\WINDOWS\System32\DRVSTORE
[2010/05/28 09:14:37 | 000,095,024 | —- | C] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Program Files\Lavasoft
[2010/05/28 09:08:52 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Lavasoft
[2010/05/28 08:22:29 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Local Settings\Application Data\Apple Computer
[2010/05/27 15:42:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Brandon Miles\Desktop\VirusProt
[2010/05/27 14:42:12 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
[2010/05/27 09:27:14 | 000,026,368 | —- | C] (Microsoft Corporation) – C:\WINDOWS\System32\dllcache\usbstor.sys
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\TeaTimer (Spybot - Search & Destroy)
[2010/05/27 06:25:13 | 000,000,000 | —D | C] – C:\Program Files\SDHelper (Spybot - Search & Destroy)
[2010/05/26 18:04:50 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Macromedia
[2010/05/26 18:04:44 | 000,000,000 | —D | C] – C:\Documents and Settings\NetworkService\Application Data\Adobe
========== Files - Modified Within 30 Days ==========
[2010/06/01 22:07:48 | 000,011,564 | —- | M] () – C:\WINDOWS\System32\WPA.DBL
[2010/06/01 22:06:29 | 000,000,006 | -H– | M] () – C:\WINDOWS\tasks\SA.DAT
[2010/06/01 22:06:12 | 000,002,048 | –S- | M] () – C:\WINDOWS\BOOTSTAT.DAT
[2010/06/01 22:05:57 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2010/06/01 22:05:14 | 000,050,166 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 22:05:14 | 000,000,064 | —- | M] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 22:04:48 | 008,126,464 | —- | M] () – C:\Documents and Settings\Brandon Miles\ntuser.dat
[2010/06/01 22:04:48 | 000,000,178 | -HS- | M] () – C:\Documents and Settings\Brandon Miles\NTUSER.INI
[2010/06/01 22:04:37 | 001,983,752 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Local Settings\Application Data\IconCache.db
[2010/06/01 21:31:20 | 000,000,696 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:29:56 | 006,153,352 | —- | M] (Malwarebytes Corporation ) – C:\Documents and Settings\Brandon Miles\Desktop\mbam-setup-1.46.exe
[2010/06/01 18:07:05 | 000,571,392 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Brandon Miles\Desktop\OTL.exe
[2010/06/01 17:20:30 | 003,701,981 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:06:32 | 000,966,213 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 14:37:26 | 000,002,463 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/06/01 13:37:47 | 001,402,880 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:30 | 000,000,256 | —- | M] () – C:\WINDOWS\SYSTEM.INI
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2010/06/01 12:45:30 | 000,000,000 | —- | M] () – C:\WINDOWS\WIN.INI
[2010/06/01 11:33:45 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:34:36 | 000,000,530 | —- | M] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetefile.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\veteboot.sys
[2010/06/01 09:56:49 | 000,000,472 | —- | M] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetmonnt.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vetfddnt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\System32\drivers\vet-rec.sys
[2010/06/01 07:32:11 | 045,145,784 | —- | M] (CA) – C:\Documents and Settings\Brandon Miles\Desktop\iss_en_32.exe
[2010/05/29 10:11:02 | 000,001,152 | —- | M] () – C:\WINDOWS\System32\windrv.sys
[2010/05/28 15:57:17 | 000,052,224 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 13:10:57 | 000,396,219 | R— | M] () – C:\WINDOWS\System32\drivers\ETC\hosts
[2010/05/28 11:46:43 | 000,000,162 | -H– | M] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\System32\drivers\SBREDrv.sys
[2010/05/28 09:14:28 | 000,015,880 | —- | M] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:09:27 | 000,000,867 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/28 08:34:47 | 000,038,912 | —- | M] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/28 08:22:20 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/05/28 08:09:52 | 000,046,592 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:54:48 | 000,046,080 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 16:51:18 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/24 19:34:37 | 000,000,073 | —- | M] () – C:\WINDOWS\webica.ini
[2010/05/24 18:26:13 | 000,004,096 | —- | M] () – C:\WINDOWS\System32\crash
[2010/05/22 21:02:50 | 000,044,032 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:45 | 000,047,104 | —- | M] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/05/12 03:00:32 | 000,001,374 | —- | M] () – C:\WINDOWS\imsins.BAK
========== Files Created - No Company Name ==========
[2010/06/01 21:31:20 | 000,000,696 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Malwarebytes' Anti-Malware.lnk
[2010/06/01 21:21:38 | 000,050,166 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k0
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k7
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k6
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k5
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k4
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k3
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k2
[2010/06/01 21:21:38 | 000,000,064 | —- | C] () – C:\WINDOWS\System32\drivers\kmxcfg.u2k1
[2010/06/01 17:20:26 | 003,701,981 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\ComboFix.exe
[2010/06/01 17:06:26 | 000,966,213 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\tdsskiller.zip
[2010/06/01 13:37:45 | 001,402,880 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.msi
[2010/06/01 12:45:28 | 000,001,730 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
[2010/06/01 11:33:45 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\Desktop\~$lesResume.doc
[2010/06/01 10:16:18 | 804,114,432 | -HS- | C] () – C:\hiberfil.sys
[2010/06/01 09:31:28 | 000,000,530 | —- | C] () – C:\WINDOWS\tasks\CAAntiSpywareScan_Daily as Brandon Miles at 9 31 AM.job
[2010/05/29 10:11:02 | 000,001,152 | —- | C] () – C:\WINDOWS\System32\windrv.sys
[2010/05/29 08:36:46 | 000,002,463 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\HiJackThis.lnk
[2010/05/29 07:16:38 | 000,000,020 | —- | C] () – C:\Documents and Settings\NetworkService\Application Data\vqdlkr.dat
[2010/05/28 15:33:13 | 000,052,224 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\Boston_Company_List(1).xls
[2010/05/28 11:46:43 | 000,000,162 | -H– | C] () – C:\Documents and Settings\Brandon Miles\My Documents\~$lesResumeFormat.doc
[2010/05/28 10:12:23 | 000,015,880 | —- | C] () – C:\WINDOWS\System32\lsdelete.exe
[2010/05/28 09:16:35 | 000,000,472 | —- | C] () – C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job
[2010/05/28 09:09:27 | 000,000,867 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk
[2010/05/28 08:42:10 | 000,014,546 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.pdf
[2010/05/27 23:50:58 | 000,038,912 | —- | C] () – C:\Documents and Settings\Brandon Miles\My Documents\MilesResumeFormat.doc
[2010/05/27 15:56:05 | 000,046,592 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\MilesResume.doc
[2010/05/27 15:46:31 | 000,046,080 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-C.doc
[2010/05/26 16:51:18 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B[2][1].doc
[2010/05/21 23:19:58 | 000,044,032 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume-B.doc
[2010/05/21 23:07:44 | 000,047,104 | —- | C] () – C:\Documents and Settings\Brandon Miles\Desktop\RBM-resume.doc
[2010/05/16 07:06:21 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/05/16 07:06:21 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2008/04/07 00:43:21 | 000,000,010 | —- | C] () – C:\WINDOWS\WININIT.INI
[2007/09/21 23:13:10 | 000,043,520 | —- | C] () – C:\WINDOWS\System32\CmdLineExt03.dll
[2006/12/26 13:09:28 | 000,000,073 | —- | C] () – C:\WINDOWS\webica.ini
[2006/06/21 06:33:40 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\DivXWMPExtType.dll
[2006/03/21 17:11:51 | 000,010,240 | —- | C] () – C:\WINDOWS\System32\vidx16.dll
[2006/02/20 05:00:42 | 000,003,084 | —- | C] () – C:\WINDOWS\System32\MRT.INI
[2005/10/14 05:56:50 | 000,921,600 | —- | C] () – C:\WINDOWS\System32\VorbisEnc.dll
[2005/10/14 05:56:50 | 000,761,856 | —- | C] () – C:\WINDOWS\System32\xvidcore.dll
[2005/10/14 05:56:50 | 000,344,064 | —- | C] () – C:\WINDOWS\System32\xvid.dll
[2005/10/14 05:56:50 | 000,237,568 | —- | C] () – C:\WINDOWS\System32\OggDS.dll
[2005/10/14 05:56:50 | 000,188,416 | —- | C] () – C:\WINDOWS\System32\vorbis.dll
[2005/10/14 05:56:50 | 000,155,136 | —- | C] () – C:\WINDOWS\System32\unrar.dll
[2005/10/14 05:56:50 | 000,045,056 | —- | C] () – C:\WINDOWS\System32\ogg.dll
[2004/10/12 19:17:15 | 000,363,520 | —- | C] () – C:\WINDOWS\System32\psisdecd.dll
[2003/11/22 21:39:38 | 000,000,000 | —- | C] () – C:\WINDOWS\QTW.ini
[2003/02/23 20:11:47 | 000,021,840 | —- | C] () – C:\WINDOWS\System32\SIntfNT.dll
[2003/02/23 20:11:47 | 000,017,212 | —- | C] () – C:\WINDOWS\System32\SIntf32.dll
[2003/02/23 20:11:47 | 000,012,067 | —- | C] () – C:\WINDOWS\System32\SIntf16.dll
[2002/11/05 19:42:20 | 000,000,105 | —- | C] () – C:\WINDOWS\TheMatrix.ini
[2002/10/15 17:38:06 | 000,000,020 | —- | C] () – C:\WINDOWS\InfModM.ini
[2002/08/15 01:25:39 | 000,000,930 | —- | C] () – C:\WINDOWS\cdplayer.ini
[2002/06/20 18:31:44 | 000,001,095 | —- | C] () – C:\WINDOWS\ChemDraw.ini
[2002/06/20 09:43:36 | 000,000,002 | —- | C] () – C:\WINDOWS\msoffice.ini
[2002/06/13 02:02:41 | 000,000,061 | —- | C] () – C:\WINDOWS\smscfg.ini
[2002/06/13 01:57:12 | 000,000,029 | —- | C] () – C:\WINDOWS\wgedit.ini
[2002/06/13 01:57:10 | 000,057,344 | —- | C] () – C:\WINDOWS\uninstBVRP.dll
[2002/06/13 01:57:01 | 000,004,272 | —- | C] () – C:\WINDOWS\System32\drivers\bvrp_pci.sys
[2002/06/13 01:52:16 | 000,000,780 | —- | C] () – C:\WINDOWS\orun32.ini
[2002/06/13 00:32:40 | 000,000,480 | —- | C] () – C:\WINDOWS\System32\OEMINFO.INI
[2001/11/15 09:19:38 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[1999/01/22 22:46:58 | 000,065,536 | —- | C] () – C:\WINDOWS\System32\MSRTEDIT.DLL
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/06/01 22:05:54 | 000,007,615 | —- | M] () – C:\aaw7boot.log
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2010/06/01 12:45:30 | 000,000,211 | RHS- | M] () – C:\boot.ini
[2001/11/14 17:35:22 | 000,000,512 | -HS- | M] () – C:\BOOTSECT.DOS
[2010/06/01 09:31:50 | 000,034,844 | —- | M] () – C:\caavsetupLog.txt
[2010/06/01 10:17:28 | 000,027,094 | —- | M] () – C:\caisslog.txt
[2006/12/26 13:09:29 | 000,000,000 | —- | M] () – C:\COMLOG.txt
[2001/11/15 08:31:14 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2002/06/13 00:34:44 | 000,003,869 | RH– | M] () – C:\DELL.SDR
[2010/06/01 22:05:57 | 804,114,432 | -HS- | M] () – C:\hiberfil.sys
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\IO.SYS
[2002/06/13 02:00:05 | 000,000,314 | -H– | M] () – C:\IPH.PH
[2007/12/16 16:47:42 | 000,000,138 | —- | M] () – C:\moduleName.txt
[2001/11/15 08:31:14 | 000,000,000 | -H– | M] () – C:\MSDOS.SYS
[2003/12/09 01:08:47 | 000,509,624 | R— | M] () – C:\My Money Backup.mny.mbf
[2004/11/22 15:39:24 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2008/09/04 17:58:27 | 000,250,048 | RHS- | M] () – C:\ntldr
[2010/06/01 22:05:55 | 1206,067,200 | -HS- | M] () – C:\pagefile.sys
[2005/10/31 11:56:00 | 000,700,416 | —- | M] (LimeWire) – C:\StubInstaller.exe
[2010/06/01 17:10:32 | 000,045,352 | —- | M] () – C:\TDSSKiller.2.3.2.0_01.06.2010_17.09.06_log.txt
[2008/09/10 03:08:02 | 000,098,617 | —- | M] () – C:\YServer.txt
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
[2008/07/03 23:25:03 | 000,421,888 | —- | M] (Advanced Micro Devices, Inc.)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\ATIDEMGX.dll
[2010/03/11 08:38:51 | 000,347,136 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtmsft.dll
[2010/03/11 08:38:51 | 000,214,528 | —- | M] (Microsoft Corporation)
Unable to obtain MD5 – C:\WINDOWS\SYSTEM32\dxtrans.dll
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\System32\config\*.sav >
[2003/01/23 12:29:50 | 000,524,288 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\default.sav
[2003/01/23 18:22:57 | 000,262,144 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\security.sav
[2003/01/23 12:29:50 | 016,252,928 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\software.sav
[2003/01/23 12:29:51 | 004,194,304 | —- | M] () – C:\WINDOWS\SYSTEM32\CONFIG\system.sav
< %systemroot%\system32\drivers\*.sys /180 >
[2010/02/04 11:53:02 | 000,064,288 | —- | M] (Lavasoft AB) – C:\WINDOWS\SYSTEM32\DRIVERS\Lbd.sys
[2010/04/29 15:39:26 | 000,020,952 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbam.sys
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mbamswissarmy.sys
[2010/02/24 09:11:07 | 000,455,680 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\mrxsmb.sys
[2010/06/01 17:12:06 | 000,003,328 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\pciide.sys
[2010/05/28 09:14:30 | 000,095,024 | —- | M] (Sunbelt Software) – C:\WINDOWS\SYSTEM32\DRIVERS\SBREDrv.sys
[2009/12/31 12:50:03 | 000,353,792 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\srv.sys
[2010/02/11 08:02:15 | 000,226,880 | —- | M] (Microsoft Corporation) – C:\WINDOWS\SYSTEM32\DRIVERS\tcpip6.sys
[2010/06/01 09:56:02 | 000,026,352 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-filt.sys
[2010/06/01 09:56:02 | 000,021,104 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vet-rec.sys
[2010/06/01 10:20:11 | 000,133,520 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\veteboot.sys
[2010/06/01 10:20:12 | 000,739,696 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetefile.sys
[2010/06/01 09:56:02 | 000,021,488 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetfddnt.sys
[2010/06/01 09:56:02 | 000,032,240 | —- | M] (Computer Associates International, Inc.) – C:\WINDOWS\SYSTEM32\DRIVERS\vetmonnt.sys
< C:\Users\Amanda\AppData\Roaming\Luzebu\*.* /s >
< C:\Users\Amanda\AppData\Roaming\Ogba\*.* /s >
< End of report >
6. The startup after reboot is a little slower than normal, but otherwise everything is working fine.