This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Infected with Virus

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

My computer will not allow me to access IE, and I cannot access Microsoft or windows websites, nor download any updates on my programs or hardware (Like .NET framework) It tries to tell me my internet isn't available though I can browse the web using chrome, but the Microsoft/Windows sites still won't show. I have tried researching this, it is most likely a virus, but I caused BSoD to my last computer by trying to be a superhero and delete the virus on my own. And I cannot afford to lose this computer, I need it for school. Anyways, OTL gave me this log:
OTL logfile created on: 10/31/2010 5:13:51 AM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

479.00 Mb Total Physical Memory | 218.00 Mb Available Physical Memory | 46.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 66.43 Gb Free Space | 89.14% Space Free | Partition Type: NTFS

Computer Name: E-MACHINE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Documents and Settings\Owner\Local Settings\Application Data\Google\Update\1.2.183.39\GoogleCrashHandler.exe (Google Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (CANON INC.)
PRC - C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\Airlink101\Airlink101 WLAN Monitor\WlanMon.exe ()
PRC - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Alpha Networks Inc.)
PRC - C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Alpha Networks Inc.)
PRC - C:\WINDOWS\system32\VTTimer.exe (S3 Graphics, Inc.)
PRC - C:\Program Files\HP\HP Software Update\hpwuSchd.exe (Hewlett-Packard)


========== Modules (SafeList) ==========

MOD - C:\Documents and Settings\Owner\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation)


========== Win32 Services (SafeList) ==========

SRV - (HidServ) – C:\WINDOWS\System32\hidserv.dll File not found
SRV - (AppMgmt) – C:\WINDOWS\System32\appmgmts.dll File not found
SRV - (avast! Web Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Mail Scanner) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV - (ANIWZCSdService) – C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exe (Alpha Networks Inc.)
SRV - (Pml Driver HPZ12) – C:\WINDOWS\system32\hpzipm12.exe (HP)


========== Driver Services (SafeList) ==========

DRV - (cmuda) – C:\WINDOWS\System32\drivers\cmuda.sys File not found
DRV - (aswTdi) – C:\WINDOWS\System32\drivers\aswTdi.sys (AVAST Software)
DRV - (aswSP) – C:\WINDOWS\System32\drivers\aswSP.sys (AVAST Software)
DRV - (aswRdr) – C:\WINDOWS\System32\drivers\aswRdr.sys (AVAST Software)
DRV - (aswMon2) – C:\WINDOWS\System32\drivers\aswmon2.sys (AVAST Software)
DRV - (aswFsBlk) – C:\WINDOWS\System32\drivers\aswFsBlk.sys (AVAST Software)
DRV - (Aavmker4) – C:\WINDOWS\System32\drivers\aavmker4.sys (AVAST Software)
DRV - (N5SG) – C:\WINDOWS\system32\drivers\N5SG.sys (Atheros Communications, Inc. )
DRV - (NwlnkIpx) – C:\WINDOWS\system32\drivers\nwlnkipx.sys (Microsoft Corporation)
DRV - (NwlnkNb) – C:\WINDOWS\system32\drivers\nwlnknb.sys (Microsoft Corporation)
DRV - (NwlnkSpx) – C:\WINDOWS\system32\drivers\nwlnkspx.sys (Microsoft Corporation)
DRV - (ANIO) – C:\WINDOWS\system32\ANIO.sys (Alpha Networks Inc.)
DRV - (BIOS) – C:\WINDOWS\system32\drivers\BIOS.sys (BIOSTAR Group)
DRV - (AFS2K) – C:\WINDOWS\System32\drivers\AFS2K.SYS (Oak Technology Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



O1 HOSTS File: ([2006/02/28 05:00:00 | 000,000,734 | —- | M]) - C:\WINDOWS\system32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (fdkowvbp) - {AAA5ED69-49AD-454A-AED3-0C23B8C4E202} - C:\WINDOWS\fdkowvbp.dll ()
O4 - HKLM..\Run: [Airlink101 WLAN Monitor] C:\Program Files\Airlink101\Airlink101 WLAN Monitor\WlanMon.exe ()
O4 - HKLM..\Run: [ANIWZCS2Service] C:\Program Files\ANI\ANIWZCS2 Service\WZCSLDR2.exe (Alpha Networks Inc.)
O4 - HKLM..\Run: [avast5] C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4 - HKLM..\Run: [DXDllRegExe] File not found
O4 - HKLM..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd.exe (Hewlett-Packard)
O4 - HKLM..\Run: [VTTimer] C:\WINDOWS\System32\VTTimer.exe (S3 Graphics, Inc.)
O4 - HKCU..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe (Adobe Systems Incorporated)
O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BDARemote.lnk = C:\Program Files\USB TV\EM28XX\BDARemote.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O10 - NameSpace_Catalog5\Catalog_Entries\000000000004 [] - C:\WINDOWS\system32\nwprovau.dll (Microsoft Corporation)
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed] [removed]
O18 - Protocol\Handler\cetihpz {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll (Hewlett-Packard Company)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O24 - Desktop BackupWallPaper: C:\Documents and Settings\Owner\Local Settings\Application Data\Microsoft\Wallpaper1.bmp
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2007/07/21 17:42:29 | 000,000,000 | —- | M] () - C:\AUTOEXEC.BAT – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*

NetSvcs: 6to4 - File not found
NetSvcs: AppMgmt - C:\WINDOWS\System32\appmgmts.dll File not found
NetSvcs: HidServ - C:\WINDOWS\System32\hidserv.dll File not found
NetSvcs: Ias - File not found
NetSvcs: Iprip - File not found
NetSvcs: Irmon - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: tbawvkos - C:\WINDOWS\system32\gdsaoann.dll ()
NetSvcs: gplprfwc - C:\WINDOWS\system32\gdsaoann.dll ()

Drivers32: msacm.iac2 - C:\WINDOWS\system32\iac25_32.ax (Intel Corporation)
Drivers32: msacm.l3acm - C:\WINDOWS\system32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.sl_anet - C:\WINDOWS\System32\sl_anet.acm (Sipro Lab Telecom Inc.)
Drivers32: msacm.trspch - C:\WINDOWS\System32\tssoft32.acm (DSP GROUP, INC.)
Drivers32: vidc.cvid - C:\WINDOWS\System32\iccvid.dll (Radius Inc.)
Drivers32: vidc.iv31 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv32 - C:\WINDOWS\System32\ir32_32.dll ()
Drivers32: vidc.iv41 - C:\WINDOWS\System32\ir41_32.ax (Intel Corporation)
Drivers32: vidc.iv50 - C:\WINDOWS\System32\ir50_32.dll (Intel Corporation)
Drivers32: vidc.LEAD - LCODCCMP.DLL File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point (54619756233228288)

========== Files/Folders - Created Within 30 Days ==========

[2010/10/31 05:09:01 | 000,388,608 | —- | C] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2010/10/31 05:08:30 | 000,575,488 | —- | C] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/10/31 04:41:47 | 000,000,000 | RH-D | C] – C:\Documents and Settings\Owner\Recent
[2010/10/31 04:19:16 | 002,959,376 | —- | C] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\dotnetfx35setup.exe
[2010/10/29 23:47:28 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\ROMS
[2010/10/28 23:57:42 | 000,017,744 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswFsBlk.sys
[2010/10/28 23:57:41 | 000,165,584 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswSP.sys
[2010/10/28 23:57:40 | 000,023,376 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswRdr.sys
[2010/10/28 23:57:39 | 000,046,672 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswTdi.sys
[2010/10/28 23:57:37 | 000,100,176 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon2.sys
[2010/10/28 23:57:37 | 000,094,544 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aswmon.sys
[2010/10/28 23:57:36 | 000,028,880 | —- | C] (AVAST Software) – C:\WINDOWS\System32\drivers\aavmker4.sys
[2010/10/28 23:57:11 | 000,038,848 | —- | C] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2010/10/28 23:57:10 | 000,167,592 | —- | C] (AVAST Software) – C:\WINDOWS\System32\aswBoot.exe
[2010/10/28 23:47:21 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2010/10/26 17:19:19 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Temp
[2010/10/16 20:37:02 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\SYSTEMAX Software Development
[2010/10/16 20:37:02 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\SYSTEMAX Software Development
[2010/10/16 20:36:23 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\Programs
[2010/10/14 22:23:51 | 000,000,000 | —D | C] – C:\WINDOWS\System32\LogFiles
[2010/10/13 21:53:41 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Contacts
[2010/10/13 21:53:30 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\My Documents\My Received Files
[2010/10/12 11:23:58 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/10/12 11:23:39 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Canon
[2010/10/12 11:18:43 | 001,310,720 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC250C.dll
[2010/10/12 11:18:43 | 000,303,104 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC250L.dll
[2010/10/12 11:18:43 | 000,110,592 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC250I.dll
[2010/10/12 11:18:43 | 000,106,496 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNC250U.dll
[2010/10/12 11:18:43 | 000,015,872 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNHMCA.dll
[2010/10/12 11:18:34 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2010/10/12 11:17:49 | 000,000,000 | -H-D | C] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/10/12 11:17:34 | 000,272,384 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMLM9W.DLL
[2010/10/12 11:17:31 | 000,000,000 | -H-D | C] – C:\WINDOWS\System32\CanonIJ Uninstaller Information
[2010/10/12 11:17:25 | 000,090,112 | —- | C] (Canon Inc.) – C:\WINDOWS\System32\CNC250O.dll
[2010/10/12 11:17:21 | 000,178,176 | —- | C] (CANON INC.) – C:\WINDOWS\System32\CNMIU9W.DLL
[2010/10/12 11:17:12 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2010/10/12 11:15:14 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2010/10/10 14:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\Help
[2010/10/10 14:47:27 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Help
[2010/10/10 03:01:55 | 000,000,000 | —D | C] – C:\WINDOWS\ServicePackFiles
[2010/10/09 09:55:40 | 000,000,000 | —D | C] – C:\WINDOWS\System32\CatRoot_bak
[2010/10/09 01:24:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\Sun
[2010/10/09 01:24:00 | 000,000,000 | —D | C] – C:\Program Files\Defraggler
[2010/10/09 01:20:41 | 000,000,000 | —D | C] – C:\Program Files\RocketDock
[2010/10/09 01:19:04 | 000,000,000 | —D | C] – C:\Program Files\Alwil Software
[2010/10/09 01:19:04 | 000,000,000 | —D | C] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/09 01:18:07 | 000,000,000 | —D | C] – C:\Program Files\Common Files\ATI Technologies
[2010/10/09 01:17:53 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2010/10/09 01:17:50 | 000,000,000 | —D | C] – C:\Program Files\USB TV
[2010/10/09 01:17:44 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\InstallShield
[2010/10/09 01:17:18 | 000,000,000 | —D | C] – C:\Program Files\ATI Technologies
[2010/10/09 01:17:11 | 000,000,000 | —D | C] – C:\Program Files\WinRAR
[2010/10/09 01:16:37 | 000,000,000 | —D | C] – C:\ATI
[2010/10/09 01:15:07 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2010/10/09 00:30:57 | 000,000,000 | —D | C] – C:\1fb6b60879a0a1b3a22fc861e10d80d6
[2010/10/09 00:29:59 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\IsolatedStorage
[2010/10/09 00:29:56 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\HP
[2010/10/09 00:29:37 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Application Data\alot
[2010/10/09 00:29:20 | 000,000,000 | —D | C] – C:\Documents and Settings\Owner\Local Settings\Application Data\ApplicationHistory
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2010/10/31 05:12:34 | 000,001,883 | —- | M] () – C:\Documents and Settings\Owner\My Documents\OTL file custom scan input.rtf
[2010/10/31 05:09:13 | 000,359,929 | —- | M] () – C:\Documents and Settings\Owner\Desktop\dds.download
[2010/10/31 05:08:54 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2010/10/31 05:08:26 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe
[2010/10/31 05:05:30 | 000,054,156 | -H– | M] () – C:\WINDOWS\QTFont.qfn
[2010/10/31 05:05:18 | 000,002,048 | –S- | M] () – C:\WINDOWS\bootstat.dat
[2010/10/31 04:24:02 | 000,000,978 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-651377827-1801674531-1003UA.job
[2010/10/31 04:19:12 | 002,959,376 | —- | M] (Microsoft Corporation) – C:\Documents and Settings\Owner\My Documents\dotnetfx35setup.exe
[2010/10/30 17:24:00 | 000,000,926 | —- | M] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-651377827-1801674531-1003Core.job
[2010/10/29 15:38:27 | 000,002,626 | —- | M] () – C:\WINDOWS\System32\CONFIG.NT
[2010/10/28 23:57:42 | 000,001,700 | —- | M] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/10/28 23:48:42 | 000,000,682 | —- | M] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/10/28 23:31:29 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/10/28 23:31:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/10/28 19:36:46 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/10/28 19:36:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/10/28 07:07:21 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/10/28 07:07:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/10/28 00:51:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/10/28 00:51:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/10/27 16:58:43 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/10/27 16:58:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/10/27 06:21:27 | 000,000,280 | -H– | M] () – C:\sqmdata13.sqm
[2010/10/27 06:21:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/10/26 20:06:27 | 000,000,815 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser (2).lnk
[2010/10/26 17:21:46 | 000,002,262 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/26 15:41:03 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/10/26 15:41:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/10/26 15:32:32 | 000,000,006 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME{6966061A-A3BE-4406-B125-0A3934D6BA30}
[2010/10/26 15:32:25 | 000,000,007 | —- | M] () – C:\WINDOWS\System32\ANIWZCSUSERNAME
[2010/10/26 13:04:29 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/10/26 13:04:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/10/25 23:35:44 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/10/25 23:35:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/10/25 23:00:36 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/10/25 23:00:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/10/25 19:18:28 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2010/10/25 19:18:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/10/25 16:53:47 | 000,000,754 | —- | M] () – C:\WINDOWS\WORDPAD.INI
[2010/10/24 21:39:13 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/10/24 21:39:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/10/24 10:04:04 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/10/24 10:04:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/10/23 18:17:01 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/10/23 18:17:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/10/22 21:58:01 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/10/22 21:58:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/10/22 19:21:04 | 000,013,646 | —- | M] () – C:\WINDOWS\System32\wpa.dbl
[2010/10/21 21:05:56 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/10/21 21:05:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/10/20 23:14:19 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/10/20 23:14:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/10/19 21:26:18 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/10/19 21:26:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/10/18 22:11:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/10/18 22:11:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/10/18 22:03:23 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/10/18 22:03:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm
[2010/10/16 20:37:26 | 000,000,808 | —- | M] () – C:\Documents and Settings\Owner\Desktop\SAI.lnk
[2010/10/15 20:13:10 | 000,001,409 | —- | M] () – C:\WINDOWS\QTFont.for
[2010/10/13 21:38:30 | 000,000,815 | —- | M] () – C:\Documents and Settings\Owner\Desktop\IE.lnk
[2010/10/12 11:18:25 | 000,001,736 | —- | M] () – C:\Documents and Settings\All Users\Desktop\Canon MP Navigator EX 3.0.lnk
[2010/10/10 03:28:10 | 000,380,350 | —- | M] () – C:\WINDOWS\System32\perfh009.dat
[2010/10/10 03:28:10 | 000,052,764 | —- | M] () – C:\WINDOWS\System32\perfc009.dat
[2010/10/10 03:22:42 | 000,108,600 | —- | M] () – C:\WINDOWS\System32\FNTCACHE.DAT
[2010/10/09 01:24:05 | 000,001,580 | —- | M] () – C:\Documents and Settings\Owner\Desktop\Defraggler.lnk
[2010/10/09 01:20:49 | 000,000,650 | —- | M] () – C:\Documents and Settings\Owner\Desktop\RocketDock.lnk
[2010/10/09 01:17:50 | 000,000,531 | —- | M] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BDARemote.lnk
[2010/10/09 01:17:50 | 000,000,519 | —- | M] () – C:\Documents and Settings\All Users\Desktop\BDARemote.lnk
[2010/10/09 01:15:53 | 000,004,212 | -H– | M] () – C:\WINDOWS\System32\zllictbl.dat
[2010/10/09 01:09:12 | 000,004,608 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/09 00:29:28 | 000,000,128 | —- | M] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]
[1 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ]

========== Files Created - No Company Name ==========

[2010/10/31 05:12:34 | 000,001,883 | —- | C] () – C:\Documents and Settings\Owner\My Documents\OTL file custom scan input.rtf
[2010/10/31 05:09:15 | 000,359,929 | —- | C] () – C:\Documents and Settings\Owner\Desktop\dds.download
[2010/10/28 23:57:42 | 000,001,700 | —- | C] () – C:\Documents and Settings\All Users\Desktop\avast! Free Antivirus.lnk
[2010/10/28 23:48:42 | 000,000,682 | —- | C] () – C:\Documents and Settings\All Users\Desktop\CCleaner.lnk
[2010/10/26 20:06:27 | 000,000,815 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser (2).lnk
[2010/10/26 17:21:46 | 000,002,262 | —- | C] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2010/10/26 17:19:08 | 000,000,978 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-651377827-1801674531-1003UA.job
[2010/10/26 17:19:06 | 000,000,926 | —- | C] () – C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-1708537768-651377827-1801674531-1003Core.job
[2010/10/25 16:53:36 | 000,000,754 | —- | C] () – C:\WINDOWS\WORDPAD.INI
[2010/10/18 22:03:23 | 000,000,268 | -H– | C] () – C:\sqmdata19.sqm
[2010/10/18 22:03:23 | 000,000,244 | -H– | C] () – C:\sqmnoopt19.sqm
[2010/10/17 22:26:09 | 000,000,268 | -H– | C] () – C:\sqmdata18.sqm
[2010/10/17 22:26:09 | 000,000,244 | -H– | C] () – C:\sqmnoopt18.sqm
[2010/10/17 18:13:04 | 000,000,268 | -H– | C] () – C:\sqmdata17.sqm
[2010/10/17 18:13:04 | 000,000,244 | -H– | C] () – C:\sqmnoopt17.sqm
[2010/10/17 12:19:44 | 000,000,268 | -H– | C] () – C:\sqmdata16.sqm
[2010/10/17 12:19:44 | 000,000,244 | -H– | C] () – C:\sqmnoopt16.sqm
[2010/10/16 23:33:05 | 000,000,268 | -H– | C] () – C:\sqmdata15.sqm
[2010/10/16 23:33:05 | 000,000,244 | -H– | C] () – C:\sqmnoopt15.sqm
[2010/10/16 20:37:14 | 000,000,808 | —- | C] () – C:\Documents and Settings\Owner\Desktop\SAI.lnk
[2010/10/16 17:52:49 | 000,000,268 | -H– | C] () – C:\sqmdata14.sqm
[2010/10/16 17:52:49 | 000,000,244 | -H– | C] () – C:\sqmnoopt14.sqm
[2010/10/15 20:14:15 | 000,000,280 | -H– | C] () – C:\sqmdata13.sqm
[2010/10/15 20:14:15 | 000,000,244 | -H– | C] () – C:\sqmnoopt13.sqm
[2010/10/15 20:13:10 | 000,054,156 | -H– | C] () – C:\WINDOWS\QTFont.qfn
[2010/10/15 20:13:10 | 000,001,409 | —- | C] () – C:\WINDOWS\QTFont.for
[2010/10/15 15:15:57 | 000,000,268 | -H– | C] () – C:\sqmdata12.sqm
[2010/10/15 15:15:57 | 000,000,244 | -H– | C] () – C:\sqmnoopt12.sqm
[2010/10/15 14:36:12 | 000,000,268 | -H– | C] () – C:\sqmdata11.sqm
[2010/10/15 14:36:12 | 000,000,244 | -H– | C] () – C:\sqmnoopt11.sqm
[2010/10/15 14:34:54 | 000,000,268 | -H– | C] () – C:\sqmdata10.sqm
[2010/10/15 14:34:54 | 000,000,244 | -H– | C] () – C:\sqmnoopt10.sqm
[2010/10/15 13:16:34 | 000,000,268 | -H– | C] () – C:\sqmdata09.sqm
[2010/10/15 13:16:34 | 000,000,244 | -H– | C] () – C:\sqmnoopt09.sqm
[2010/10/14 22:33:53 | 000,000,268 | -H– | C] () – C:\sqmdata08.sqm
[2010/10/14 22:33:53 | 000,000,244 | -H– | C] () – C:\sqmnoopt08.sqm
[2010/10/14 00:06:25 | 000,000,268 | -H– | C] () – C:\sqmdata07.sqm
[2010/10/14 00:06:25 | 000,000,244 | -H– | C] () – C:\sqmnoopt07.sqm
[2010/10/13 21:38:30 | 000,000,815 | —- | C] () – C:\Documents and Settings\Owner\Desktop\IE.lnk
[2010/10/12 11:18:43 | 000,012,288 | —- | C] () – C:\WINDOWS\System32\CNC173AD.TBL
[2010/10/12 11:18:25 | 000,001,736 | —- | C] () – C:\Documents and Settings\All Users\Desktop\Canon MP Navigator EX 3.0.lnk
[2010/10/09 01:24:05 | 000,001,580 | —- | C] () – C:\Documents and Settings\Owner\Desktop\Defraggler.lnk
[2010/10/09 01:20:49 | 000,000,650 | —- | C] () – C:\Documents and Settings\Owner\Desktop\RocketDock.lnk
[2010/10/09 01:17:50 | 000,000,531 | —- | C] () – C:\Documents and Settings\All Users\Start Menu\Programs\Startup\BDARemote.lnk
[2010/10/09 01:17:50 | 000,000,519 | —- | C] () – C:\Documents and Settings\All Users\Desktop\BDARemote.lnk
[2010/10/09 00:29:28 | 000,000,128 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\fusioncache.dat
[2008/07/26 15:49:35 | 000,204,800 | —- | C] () – C:\WINDOWS\fdkowvbp.dll
[2007/09/03 21:41:25 | 000,001,159 | —- | C] () – C:\Documents and Settings\All Users\Application Data\hpzinstall.log
[2007/09/03 21:36:46 | 000,565,248 | —- | C] () – C:\WINDOWS\System32\hpotscl.dll
[2007/08/20 15:44:35 | 000,000,794 | —- | C] () – C:\WINDOWS\lrun32.ini
[2007/08/20 15:44:06 | 000,000,000 | —- | C] () – C:\WINDOWS\AutoRun.INI
[2007/08/20 14:57:45 | 000,000,376 | —- | C] () – C:\WINDOWS\ODBC.INI
[2007/08/17 20:50:15 | 000,004,608 | —- | C] () – C:\Documents and Settings\Owner\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2007/08/02 14:11:58 | 000,049,152 | —- | C] () – C:\WINDOWS\System32\JJAKEn.dll
[2007/07/23 12:00:32 | 000,000,092 | —- | C] () – C:\WINDOWS\CMISETUP.INI
[2007/07/23 12:00:31 | 000,000,026 | —- | C] () – C:\WINDOWS\CMCDPLAY.INI
[2007/07/23 12:00:29 | 000,000,000 | —- | C] () – C:\WINDOWS\Wininit.ini
[2007/07/23 12:00:28 | 000,028,672 | —- | C] () – C:\WINDOWS\CMIRmDriver.dll
[2007/07/21 10:24:58 | 000,004,161 | —- | C] () – C:\WINDOWS\ODBCINST.INI
[2006/02/28 05:00:00 | 000,161,547 | RHS- | C] () – C:\WINDOWS\System32\gdsaoann.dll
[2004/09/17 17:37:42 | 000,061,440 | —- | C] () – C:\WINDOWS\System32\vuins32.dll

========== LOP Check ==========

[2010/10/28 23:57:04 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\Alwil Software
[2010/10/12 11:17:49 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonBJ
[2010/10/12 11:23:58 | 000,000,000 | -H-D | M] – C:\Documents and Settings\All Users\Application Data\CanonIJScan
[2010/10/16 20:37:02 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\SYSTEMAX Software Development
[2007/08/20 14:52:23 | 000,000,000 | —D | M] – C:\Documents and Settings\All Users\Application Data\WildTangent
[2010/10/09 00:29:37 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\alot
[2010/10/12 11:23:58 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Canon
[2010/10/28 23:47:21 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\MSNInstaller
[2007/07/21 18:16:45 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Simple Star
[2007/07/21 18:21:59 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\Snapfish
[2010/10/16 20:37:02 | 000,000,000 | —D | M] – C:\Documents and Settings\Owner\Application Data\SYSTEMAX Software Development

========== Purity Check ==========



========== Custom Scans ==========


< %SYSTEMDRIVE%\*.* >
[2007/07/21 17:42:29 | 000,000,000 | —- | M] () – C:\AUTOEXEC.BAT
[2007/07/21 17:35:16 | 000,000,211 | -HS- | M] () – C:\boot.ini
[2007/07/21 17:42:29 | 000,000,000 | —- | M] () – C:\CONFIG.SYS
[2008/07/20 08:07:20 | 000,000,144 | —- | M] () – C:\domains.dat
[2001/09/05 22:00:58 | 001,700,352 | —- | M] (Microsoft Corporation) – C:\gdiplus.dll
[2007/07/21 17:42:29 | 000,000,000 | RHS- | M] () – C:\IO.SYS
[2007/07/21 17:42:29 | 000,000,000 | RHS- | M] () – C:\MSDOS.SYS
[2008/08/13 09:53:07 | 000,029,696 | —- | M] () – C:\Normal.dot
[2006/02/28 05:00:00 | 000,047,564 | RHS- | M] () – C:\NTDETECT.COM
[2006/02/28 05:00:00 | 000,250,032 | RHS- | M] () – C:\ntldr
[2010/10/31 05:05:16 | 754,974,720 | -HS- | M] () – C:\pagefile.sys
[2008/08/13 10:01:04 | 000,000,337 | —- | M] () – C:\rollback.ini
[2008/05/18 12:44:10 | 000,000,512 | —- | M] () – C:\ScanSectorLog.dat
[2010/10/18 22:11:42 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2010/10/19 21:26:18 | 000,000,268 | -H– | M] () – C:\sqmdata01.sqm
[2010/10/20 23:14:19 | 000,000,268 | -H– | M] () – C:\sqmdata02.sqm
[2010/10/21 21:05:56 | 000,000,268 | -H– | M] () – C:\sqmdata03.sqm
[2010/10/22 21:58:01 | 000,000,268 | -H– | M] () – C:\sqmdata04.sqm
[2010/10/23 18:17:01 | 000,000,268 | -H– | M] () – C:\sqmdata05.sqm
[2010/10/24 10:04:04 | 000,000,268 | -H– | M] () – C:\sqmdata06.sqm
[2010/10/24 21:39:13 | 000,000,268 | -H– | M] () – C:\sqmdata07.sqm
[2010/10/25 19:18:28 | 000,000,268 | -H– | M] () – C:\sqmdata08.sqm
[2010/10/25 23:00:36 | 000,000,268 | -H– | M] () – C:\sqmdata09.sqm
[2010/10/25 23:35:44 | 000,000,268 | -H– | M] () – C:\sqmdata10.sqm
[2010/10/26 13:04:29 | 000,000,268 | -H– | M] () – C:\sqmdata11.sqm
[2010/10/26 15:41:03 | 000,000,268 | -H– | M] () – C:\sqmdata12.sqm
[2010/10/27 06:21:27 | 000,000,280 | -H– | M] () – C:\sqmdata13.sqm
[2010/10/27 16:58:43 | 000,000,268 | -H– | M] () – C:\sqmdata14.sqm
[2010/10/28 00:51:38 | 000,000,268 | -H– | M] () – C:\sqmdata15.sqm
[2010/10/28 07:07:21 | 000,000,268 | -H– | M] () – C:\sqmdata16.sqm
[2010/10/28 19:36:46 | 000,000,268 | -H– | M] () – C:\sqmdata17.sqm
[2010/10/28 23:31:29 | 000,000,268 | -H– | M] () – C:\sqmdata18.sqm
[2010/10/18 22:03:23 | 000,000,268 | -H– | M] () – C:\sqmdata19.sqm
[2010/10/18 22:11:42 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2010/10/19 21:26:18 | 000,000,244 | -H– | M] () – C:\sqmnoopt01.sqm
[2010/10/20 23:14:19 | 000,000,244 | -H– | M] () – C:\sqmnoopt02.sqm
[2010/10/21 21:05:56 | 000,000,244 | -H– | M] () – C:\sqmnoopt03.sqm
[2010/10/22 21:58:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt04.sqm
[2010/10/23 18:17:01 | 000,000,244 | -H– | M] () – C:\sqmnoopt05.sqm
[2010/10/24 10:04:04 | 000,000,244 | -H– | M] () – C:\sqmnoopt06.sqm
[2010/10/24 21:39:13 | 000,000,244 | -H– | M] () – C:\sqmnoopt07.sqm
[2010/10/25 19:18:28 | 000,000,244 | -H– | M] () – C:\sqmnoopt08.sqm
[2010/10/25 23:00:36 | 000,000,244 | -H– | M] () – C:\sqmnoopt09.sqm
[2010/10/25 23:35:44 | 000,000,244 | -H– | M] () – C:\sqmnoopt10.sqm
[2010/10/26 13:04:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt11.sqm
[2010/10/26 15:41:03 | 000,000,244 | -H– | M] () – C:\sqmnoopt12.sqm
[2010/10/27 06:21:27 | 000,000,244 | -H– | M] () – C:\sqmnoopt13.sqm
[2010/10/27 16:58:43 | 000,000,244 | -H– | M] () – C:\sqmnoopt14.sqm
[2010/10/28 00:51:37 | 000,000,244 | -H– | M] () – C:\sqmnoopt15.sqm
[2010/10/28 07:07:21 | 000,000,244 | -H– | M] () – C:\sqmnoopt16.sqm
[2010/10/28 19:36:46 | 000,000,244 | -H– | M] () – C:\sqmnoopt17.sqm
[2010/10/28 23:31:29 | 000,000,244 | -H– | M] () – C:\sqmnoopt18.sqm
[2010/10/18 22:03:23 | 000,000,244 | -H– | M] () – C:\sqmnoopt19.sqm

< %systemroot%\Fonts\*.com >

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2007/07/21 17:41:59 | 000,000,067 | -HS- | M] () – C:\WINDOWS\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
[2009/03/17 05:00:00 | 000,027,648 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPD9W.DLL
[2009/03/17 05:00:00 | 000,070,656 | —- | M] (CANON INC.) – C:\WINDOWS\system32\spool\prtprocs\w32x86\CNMPP9W.DLL

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2010/09/07 08:12:17 | 000,038,848 | —- | M] (AVAST Software) – C:\WINDOWS\avastSS.scr
[2004/11/17 14:24:24 | 000,421,888 | —- | M] () – C:\WINDOWS\Nero PhotoShow.scr
[4 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >
[2007/07/21 10:22:34 | 000,094,208 | —- | M] () – C:\WINDOWS\system32\config\default.sav
[2007/07/21 10:22:34 | 000,634,880 | —- | M] () – C:\WINDOWS\system32\config\software.sav
[2007/07/21 10:22:34 | 000,868,352 | —- | M] () – C:\WINDOWS\system32\config\system.sav

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
[2007/07/21 17:42:35 | 000,000,294 | -HS- | M] () – C:\Documents and Settings\All Users\Start Menu\desktop.ini

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >
[2010/10/22 19:41:42 | 000,005,120 | -HS- | M] () – C:\WINDOWS\system32\Thumbs.db
[1 C:\WINDOWS\system32\*.tmp files -> C:\WINDOWS\system32\*.tmp -> ]

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2007/07/21 17:59:58 | 000,000,119 | -HS- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\desktop.ini
[2007/07/21 17:59:57 | 000,000,079 | —- | M] () – C:\Documents and Settings\Owner\Application Data\Microsoft\Internet Explorer\Quick Launch\Show Desktop.scf

< %USERPROFILE%\Desktop\*.exe >
[2010/10/31 05:08:54 | 000,388,608 | —- | M] (Trend Micro Inc.) – C:\Documents and Settings\Owner\Desktop\HiJackThis.exe
[2010/10/31 05:08:26 | 000,575,488 | —- | M] (OldTimer Tools) – C:\Documents and Settings\Owner\Desktop\OTL.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install\\LastSuccessTime: 2010-10-10 10:06:54

< End of report >
OTL Extras logfile created on: 10/31/2010 5:13:51 AM - Run 1
OTL by OldTimer - Version 3.2.17.1 Folder = C:\Documents and Settings\Owner\Desktop
Windows XP Home Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation
Internet Explorer (Version = 7.0.5730.13)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

479.00 Mb Total Physical Memory | 218.00 Mb Available Physical Memory | 46.00% Memory free
1.00 Gb Paging File | 1.00 Gb Available in Paging File | 84.00% Paging File free
Paging file location(s): C:\pagefile.sys 720 1440 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files
Drive C: | 74.52 Gb Total Space | 66.43 Gb Free Space | 89.14% Space Free | Partition Type: NTFS

Computer Name: E-MACHINE | User Name: Owner | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
htmlfile – Reg Error: Key error.
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirstRunDisabled" = 1
"AntiVirusDisableNotify" = 0
"FirewallDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 1
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sr]
"Start" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SrService]
"Start" = 2

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
"1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007
"2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008
"139:TCP" = 139:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22004
"445:TCP" = 445:TCP:LocalSubNet:Disabled:@xpsp2res.dll,-22005
"137:UDP" = 137:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22001
"138:UDP" = 138:UDP:LocalSubNet:Disabled:@xpsp2res.dll,-22002
"8482:TCP" = 8482:TCP:*:Enabled:gdkmladn

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe" = C:\WINDOWS\system32\ZoneLabs\avsys\ScanningProcess.exe:*:Enabled:Kaspersky AV Scanner – File not found
"C:\Program Files\iTunes\iTunes.exe" = C:\Program Files\iTunes\iTunes.exe:*:Enabled:iTunes – (Apple Inc.)
"C:\Program Files\MSN Messenger\msnmsgr.exe" = C:\Program Files\MSN Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1 – File not found
"C:\Program Files\MSN Messenger\livecall.exe" = C:\Program Files\MSN Messenger\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone) – File not found
"C:\Documents and Settings\Rocky\Application Data\MySpace\IM\bin\MySpaceIM.exe" = C:\Documents and Settings\Rocky\Application Data\MySpace\IM\bin\MySpaceIM.exe:*:Enabled:MySpaceIM – File not found


========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP250_series" = Canon MP250 series MP Drivers
"{18E0918E-1060-48f3-925C-56C82E88551B}" = HP PSC & OfficeJet 3.5
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F7473D9-6C0B-4F5A-8FA4-AB8AD78CBE54}" = DocProc
"{22988B2A-374A-4A7B-B795-A1AFF2046BE9}" = PhotoGallery
"{257EC58E-03FD-472B-A9B6-93F23A3C4CB0}" = Scan
"{2758691A-2CDE-4942-A4AC-0E8F61FE2067}" = USB Video Driver
"{29B50D30-EAFC-4cea-9F76-3A0E3729E9B0}" = SkinsHP1
"{2B43252C-A1E3-4C47-927C-9F2C276D3515}" = S3GSetup
"{2E132061-C78A-48D4-A899-1D13B9D189FA}" = Memories Disc Creator 2.0
"{34957B51-9676-41CE-9E52-44AE91B73F1C}" = HP Software Update
"{350C97B0-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP
"{3CF78481-FB7B-4B51-99A2-D5E0CD0B3AAF}" = HPSystemDiagnostics
"{415B8A4E-0EA2-4C69-975C-EEE07B837FD7}" = Unload
"{47759129-8649-47D1-9EA5-4BB84D86DB97}" = WLAN Monitor
"{47C25360-AEBC-4B21-B233-87CE653B3369}" = AIOMinimal
"{48242276-DB89-42e8-9678-BD4280D7B99A}" = Copy
"{492724FC-3B26-46B4-824F-3CE2722D9AA0}" = Apple Software Update
"{4C590030-7469-453E-8589-D15DA9D03F52}" = ANIWZCS2 Service
"{57C7C46A-D35D-492d-A328-4F8C9B5B4B52}" = PrintScreen
"{5C709422-F782-4629-8EE3-E60B480C7327}" = 1300Trb
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD
"{6864A62D-3EF3-415F-9922-240EED34B4C0}" = Fax
"{723C033E-63EA-4227-BAB2-0AA8693C16EB}" = Director
"{745A92AF-53B4-41A7-91C3-9B026B1D5897}" = InstantShare
"{763E8D6C-0098-4FF4-801A-3F311D2D9D80}" = Apple Mobile Device Support
"{7B5CE976-C7A9-4E38-A7F3-6C8EF025DD8E}" = ANIO Service
"{81DD5688-695A-4c1d-AE7D-368BF857725A}" = TrayApp
"{8777AC6D-89F9-4793-8266-DE406F343E89}" = QFolder
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{8A62A068-3FD6-495A-9F66-26FE94F32EC9}" = Rhapsody Player Engine
"{95A890AA-B3B1-44B6-9C18-A8F7AB3EE7FC}" = QuickTime
"{974C05A0-C76C-4724-A9A2-11D5D1355729}" = iTunes
"{98E05456-E3A5-4F6B-823E-4D1883E4BD3D}" = 1300_Help
"{99D48FBB-2DEF-49A9-BCC9-C5AF63DD2643}" = AiOSoftware
"{9B03C535-3AEA-4ef2-B326-0A01A2207034}" = CreativeProjects
"{AA452BED-9370-44D5-970C-677DECDA7463}" = 1300
"{AC76BA86-7AD7-1033-7B44-A71000000002}" = Adobe Reader 7.1.0
"{AEC20FEC-47D8-4DEA-85D7-0B7E5D905D11}" = AiO_Scan
"{BC339BFD-F550-471a-8D26-4D08126C62F7}" = SkinsHP2
"{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1
"{CBE3E0AF-73BB-4c21-8B96-B09E003EDE7F}" = QuickProjects
"{D186329B-1B4D-408D-ABEC-EA5CE1F182C9}" = Overland
"{E443F067-3345-482C-BD7A-12675A53D292}" = Readme
"{F43CEA29-411E-4689-A075-566DC6394635}" = 1300Tour
"{FBBF532A-47AC-457d-AC06-0D3163D8911E}" = WebReg
"{FF102450-55AA-4AE1-ACE4-E271E2470C83}" = hpmdtab
"69083DC58646DE46A09847A522A1CC487F918039" = Windows Driver Package - eMPIA Technology Inc, (emAudio) MEDIA (08/31/2007 5.7.0831.0)
"9722CA1E8F72F362E93CBEC75A707FDABFC8D880" = Windows Driver Package - Advanced Micro Devices, Inc. (USB28xxBGA) Media (08/31/2007 5.7.0831.0)
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"All ATI Software" = ATI - Software Uninstall Utility
"avast5" = avast! Free Antivirus
"Canon MP250 series User Registration" = Canon MP250 series User Registration
"CanonMyPrinter" = Canon Utilities My Printer
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"HP Photo & Imaging" = HP Image Zone 3.5
"IDNMitigationAPIs" = Microsoft Internationalized Domain Names Mitigation APIs
"ie7" = Windows Internet Explorer 7
"InstallShield_{47759129-8649-47D1-9EA5-4BB84D86DB97}" = WLAN Monitor
"Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1
"Microsoft Press Interactive Training" = Microsoft Interactive Training
"MP Navigator EX 3.0" = Canon MP Navigator EX 3.0
"NLSDownlevelMapping" = Microsoft National Language Support Downlevel APIs
"RocketDock_is1" = RocketDock 1.3.5
"VIA/S3G UniChrome Family Win2K/XP Display" = VIA/S3G Display Driver
"VN_VUIns_Rhine_VIA" = VIA Rhine-Family Fast Ethernet Adapter
"WinRAR archiver" = WinRAR archiver

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome

========== Last 10 Event Log Errors ==========

[ Application Events ]
Error - 10/31/2010 5:45:18 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 5:45:48 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 5:46:25 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 5:46:44 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:04:48 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:04:48 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:04:48 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:05:14 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:05:15 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

Error - 10/31/2010 6:05:15 AM | Computer Name = E-MACHINE | Source = crypt32 | ID = 131080
Description = Failed auto update retrieval of third-party root list sequence number
from: <http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This network connection does not exist.

[ System Events ]
Error - 10/30/2010 8:37:07 PM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7023
Description = The Monitor Manager service terminated with the following error: %%1114

Error - 10/30/2010 8:37:07 PM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7018
Description = Detected circular dependencies auto-starting services.

Error - 10/31/2010 12:23:59 AM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7023
Description = The Center Universal service terminated with the following error:
%%1114

Error - 10/31/2010 12:23:59 AM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7023
Description = The Monitor Manager service terminated with the following error: %%1114

Error - 10/31/2010 7:22:11 AM | Computer Name = E-MACHINE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/31/2010 7:24:30 AM | Computer Name = E-MACHINE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/31/2010 7:25:36 AM | Computer Name = E-MACHINE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}

Error - 10/31/2010 8:07:01 AM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7023
Description = The Center Universal service terminated with the following error:
%%1114

Error - 10/31/2010 8:07:01 AM | Computer Name = E-MACHINE | Source = Service Control Manager | ID = 7023
Description = The Monitor Manager service terminated with the following error: %%1114

Error - 10/31/2010 8:07:05 AM | Computer Name = E-MACHINE | Source = DCOM | ID = 10005
Description = DCOM got error "%1058" attempting to start the service BITS with arguments
"" in order to run the server: {4991D34B-80A1-4291-83B6-3328366B9097}


< End of report >
Hi

Please do the following:

Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O2 - BHO: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (fdkowvbp) - {AAA5ED69-49AD-454A-AED3-0C23B8C4E202} - C:\WINDOWS\fdkowvbp.dll ()
    [2008/07/26 15:49:35 | 000,204,800 | —- | C] () – C:\WINDOWS\fdkowvbp.dll
    NetSvcs: tbawvkos - C:\WINDOWS\system32\gdsaoann.dll ()
    NetSvcs: gplprfwc - C:\WINDOWS\system32\gdsaoann.dll ()
    [2006/02/28 05:00:00 | 000,161,547 | RHS- | C] () – C:\WINDOWS\System32\gdsaoann.dll
    
    :Reg
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
    "8482:TCP"=-
    
    :Services
    tbawvkos 
    gplprfwc 
    
    :Commands
    [resethosts]
    [emptyflash]
    [purity]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then post the OTL log




NEXT




[external image: Posted Image]
Download GMER Rootkit Scanner from here or here.
  • Extract the contents of the zipped file to desktop.
  • Double click GMER.exe. If asked to allow gmer.sys driver to load, please consent .
  • If it gives you a warning about rootkit activity and asks if you want to run scan…click on NO.

    [external image: Posted Image]
    Click the image to enlarge it
  • In the right panel, you will see several boxes that have been checked. Uncheck the following …
    • IAT/EAT
    • Drives/Partition other than Systemdrive (typically C:\)
    • Show All (don't miss this one)
  • Then click the Scan button & wait for it to finish.
  • Once done click on the [Save..] button, and in the File name area, type in "Gmer.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop, and attach it in your reply.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<— ROOKIT" entries
[EMPTYFLASH] User: All Users User: Default User User: Guest User: LocalService User: NetworkService User: Owner ->Flash cache emptied: 3007 bytes Total Flash Files Cleaned = 0.00 mb [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Guest ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 2937389 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Owner ->Temp folder emptied: 303764 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Google Chrome cache emptied: 27814338 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2157287 bytes %systemroot%\System32 .tmp files removed: 2577 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 32.00 mb OTL by OldTimer - Version 3.2.17.1 log created on 11012010_155355 Files\Folders moved on Reboot… C:\WINDOWS\system32\gdsaoann.dll moved successfully. File move failed. C:\WINDOWS\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot…📎gmer.txt

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI