Ran the OTL, but after the reboot the icons for Internet Explorer were gone….had to figure out how to get it back, as it was not showing on the main menu (show all programs)…..it also made the quick launch for it become non functional. THat being said, here are the logs….
Alos, on the bottom right by the time, I have a little notification that is a waiving flag…when I hove it says "Solve PC Issues: 1 message". Is this legit? It's not my PC so I don't know if it was there before the infection….
Sean
-I might have misunderstood, but shoud I have 2 OTL logs? After it ran, it rebooted, then I ran a scan to generate the log….
OTL:
OTL logfile created on: 7/7/2011 1:53:28 PM - Run 2
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\Noel Brereton\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.97 Gb Total Physical Memory | 4.61 Gb Available Physical Memory | 77.33% Memory free
11.93 Gb Paging File | 10.45 Gb Available in Paging File | 87.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 868.98 Gb Free Space | 94.82% Space Free | Partition Type: NTFS
Computer Name: NOELBRERETON-PC | User Name: Noel Brereton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
========== Modules (SafeList) ==========
MOD - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:
64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:
64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:
64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/07 13:35:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/05 14:42:34 | 001,905,664 | —- | C] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:45 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/03 15:19:03 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/03 15:03:23 | 000,012,872 | —- | C] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:01:00 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2011/07/03 15:00:37 | 000,000,000 | —D | C] – C:\ProgramData\Hitman Pro
[2011/07/03 15:00:05 | 007,617,344 | —- | C] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/07/03 14:00:29 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\Desktop\tdsskiller
[2011/07/02 13:02:17 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Malwarebytes
[2011/07/02 13:02:15 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/02 13:02:12 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/07/02 13:02:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/22 04:27:04 | 000,257,024 | -H– | C] (Microsoft Corporation) – C:\Users\Noel Brereton\taskmgr.exe
[2011/06/17 08:39:40 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/17 08:39:40 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/17 08:39:40 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/17 08:39:40 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/17 08:39:40 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/17 08:39:40 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/17 08:39:40 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/17 08:39:40 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/17 08:39:40 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/17 08:39:40 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/17 08:39:39 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/17 08:39:39 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/17 08:39:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/17 08:39:39 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/17 08:39:35 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/17 08:39:35 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/17 08:39:35 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
========== Files - Modified Within 30 Days ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | M] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:38:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/07 13:38:21 | 509,456,383 | -HS- | M] () – C:\hiberfil.sys
[2011/07/07 13:37:29 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:45:08 | 000,000,512 | —- | M] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:42:44 | 001,905,664 | —- | M] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/05 14:28:46 | 001,008,041 | —- | M] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:11:39 | 000,012,872 | —- | M] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:09:15 | 000,023,112 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | M] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 15:00:07 | 007,617,344 | —- | M] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,003,011 | —- | M] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | M] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/29 04:30:23 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/06/22 04:37:26 | 000,000,336 | -H– | M] () – C:\ProgramData\36429560
[2011/06/19 03:09:34 | 000,739,906 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/19 03:09:34 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/19 03:09:34 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/17 10:50:54 | 000,425,400 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | C] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:37:29 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:44:31 | 000,000,512 | —- | C] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:28:44 | 001,008,041 | —- | C] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/07/03 15:19:09 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:01:19 | 000,023,112 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | C] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 14:38:20 | 000,003,011 | —- | C] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | C] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/22 04:37:26 | 000,000,336 | -H– | C] () – C:\ProgramData\36429560
[2010/08/25 20:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010/08/25 19:52:00 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 19:52:00 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/08/27 17:02:56 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
Malwarebytes:
OTL logfile created on: 7/7/2011 1:53:28 PM - Run 2
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\Noel Brereton\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.97 Gb Total Physical Memory | 4.61 Gb Available Physical Memory | 77.33% Memory free
11.93 Gb Paging File | 10.45 Gb Available in Paging File | 87.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 868.98 Gb Free Space | 94.82% Space Free | Partition Type: NTFS
Computer Name: NOELBRERETON-PC | User Name: Noel Brereton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
========== Modules (SafeList) ==========
MOD - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:
64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:
64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:
64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/07 13:35:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/05 14:42:34 | 001,905,664 | —- | C] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:45 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/03 15:19:03 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/03 15:03:23 | 000,012,872 | —- | C] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:01:00 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2011/07/03 15:00:37 | 000,000,000 | —D | C] – C:\ProgramData\Hitman Pro
[2011/07/03 15:00:05 | 007,617,344 | —- | C] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/07/03 14:00:29 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\Desktop\tdsskiller
[2011/07/02 13:02:17 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Malwarebytes
[2011/07/02 13:02:15 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/02 13:02:12 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/07/02 13:02:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/22 04:27:04 | 000,257,024 | -H– | C] (Microsoft Corporation) – C:\Users\Noel Brereton\taskmgr.exe
[2011/06/17 08:39:40 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/17 08:39:40 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/17 08:39:40 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/17 08:39:40 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/17 08:39:40 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/17 08:39:40 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/17 08:39:40 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/17 08:39:40 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/17 08:39:40 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/17 08:39:40 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/17 08:39:39 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/17 08:39:39 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/17 08:39:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/17 08:39:39 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/17 08:39:35 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/17 08:39:35 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/17 08:39:35 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
========== Files - Modified Within 30 Days ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | M] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:38:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/07 13:38:21 | 509,456,383 | -HS- | M] () – C:\hiberfil.sys
[2011/07/07 13:37:29 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:45:08 | 000,000,512 | —- | M] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:42:44 | 001,905,664 | —- | M] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/05 14:28:46 | 001,008,041 | —- | M] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:11:39 | 000,012,872 | —- | M] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:09:15 | 000,023,112 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | M] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 15:00:07 | 007,617,344 | —- | M] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,003,011 | —- | M] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | M] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/29 04:30:23 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/06/22 04:37:26 | 000,000,336 | -H– | M] () – C:\ProgramData\36429560
[2011/06/19 03:09:34 | 000,739,906 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/19 03:09:34 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/19 03:09:34 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/17 10:50:54 | 000,425,400 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | C] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:37:29 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:44:31 | 000,000,512 | —- | C] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:28:44 | 001,008,041 | —- | C] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/07/03 15:19:09 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:01:19 | 000,023,112 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | C] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 14:38:20 | 000,003,011 | —- | C] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | C] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/22 04:37:26 | 000,000,336 | -H– | C] () – C:\ProgramData\36429560
[2010/08/25 20:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010/08/25 19:52:00 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 19:52:00 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/08/27 17:02:56 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >
Tdskiller:
OTL logfile created on: 7/7/2011 1:53:28 PM - Run 2
OTL by OldTimer - Version 3.2.26.0 Folder = C:\Users\Noel Brereton\Desktop
64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7600.16385)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
5.97 Gb Total Physical Memory | 4.61 Gb Available Physical Memory | 77.33% Memory free
11.93 Gb Paging File | 10.45 Gb Available in Paging File | 87.56% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.41 Gb Total Space | 868.98 Gb Free Space | 94.82% Space Free | Partition Type: NTFS
Computer Name: NOELBRERETON-PC | User Name: Noel Brereton | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
PRC - C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe (Sun Microsystems, Inc.)
PRC - C:\Program Files (x86)\BillP Studios\WinPatrol\WinPatrol.exe (BillP Studios)
PRC - C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
PRC - C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
PRC - C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
========== Modules (SafeList) ==========
MOD - C:\Users\Noel Brereton\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:
64bit: - (Updater Service) – C:\Program Files\Gateway\Gateway Updater\UpdaterService.exe (Acer)
SRV - (Lavasoft Ad-Aware Service) – C:\Program Files (x86)\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NewTech Infosystems\Gateway MyBackup\IScheduleSvc.exe (NewTech Infosystems, Inc.)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira GmbH)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Greg_Service) – C:\Program Files (x86)\Gateway\Registration\GregHSRW.exe (Acer Incorporated)
SRV - (GameConsoleService) – C:\Program Files (x86)\Gateway Games\Gateway Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira GmbH)
========== Driver Services (SafeList) ==========
DRV:
64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:
64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:
64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:
64bit: - (Lbd) – C:\Windows\SysNative\drivers\Lbd.sys (Lavasoft AB)
DRV:
64bit: - (avgntflt) – C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH)
DRV:
64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:
64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:
64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:
64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:
64bit: - (e1yexpress) Intel® – C:\Windows\SysNative\drivers\e1y62x64.sys (Intel Corporation)
DRV:
64bit: - (Ntfs) – C:\Windows\SysNative\wbem\ntfs.mof ()
DRV:
64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:
64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:
64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:
64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:
64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:
64bit: - (IntcHdmiAddService) Intel® – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:
64bit: - (NTIDrvr) – C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:
64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (Lavasoft Kernexplorer) – C:\Program Files (x86)\Lavasoft\Ad-Aware\kernexplorer64.sys ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://homepage.gateway.com/rdr.aspx?b=ACG…25v165k4701r29q
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
http://www.google.com/
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8064.0206: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [CanonSolutionMenu] C:\Program Files (x86)\Canon\SolutionMenu\CNSLMAIN.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_23)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:
64bit: - Winlogon\Notify\igfxcui: DllName - Reg Error: Key error. - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O34 - HKLM BootExecute: (lsdelete) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
========== Files/Folders - Created Within 30 Days ==========
[2011/07/07 13:35:27 | 000,000,000 | —D | C] – C:\_OTL
[2011/07/05 14:42:34 | 001,905,664 | —- | C] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:45 | 000,580,608 | —- | C] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/03 15:19:03 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2011/07/03 15:03:23 | 000,012,872 | —- | C] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:01:00 | 000,000,000 | —D | C] – C:\Program Files\Hitman Pro 3.5
[2011/07/03 15:00:37 | 000,000,000 | —D | C] – C:\ProgramData\Hitman Pro
[2011/07/03 15:00:05 | 007,617,344 | —- | C] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2011/07/03 14:38:20 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2011/07/03 14:00:29 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\Desktop\tdsskiller
[2011/07/02 13:02:17 | 000,000,000 | —D | C] – C:\Users\Noel Brereton\AppData\Roaming\Malwarebytes
[2011/07/02 13:02:15 | 000,039,984 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2011/07/02 13:02:15 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2011/07/02 13:02:12 | 000,025,912 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2011/07/02 13:02:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2011/06/22 04:27:04 | 000,257,024 | -H– | C] (Microsoft Corporation) – C:\Users\Noel Brereton\taskmgr.exe
[2011/06/17 08:39:40 | 000,703,488 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/17 08:39:40 | 000,599,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/17 08:39:40 | 000,256,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/17 08:39:40 | 000,247,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/17 08:39:40 | 000,185,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/17 08:39:40 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/17 08:39:40 | 000,097,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/17 08:39:40 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/17 08:39:40 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/17 08:39:40 | 000,044,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/17 08:39:39 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/17 08:39:39 | 000,386,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/17 08:39:39 | 000,012,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/17 08:39:39 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/17 08:39:35 | 000,861,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/17 08:39:35 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d10_1.dll
[2011/06/17 08:39:35 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d10_1.dll
========== Files - Modified Within 30 Days ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | M] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:45:40 | 000,009,920 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2011/07/07 13:38:22 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/07/07 13:38:21 | 509,456,383 | -HS- | M] () – C:\hiberfil.sys
[2011/07/07 13:37:29 | 000,000,064 | —- | M] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | M] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:45:08 | 000,000,512 | —- | M] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:42:44 | 001,905,664 | —- | M] (AVAST Software) – C:\Users\Noel Brereton\Desktop\aswMBR.exe
[2011/07/05 14:31:47 | 000,580,608 | —- | M] (OldTimer Tools) – C:\Users\Noel Brereton\Desktop\OTL.exe
[2011/07/05 14:28:46 | 001,008,041 | —- | M] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,021 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:11:39 | 000,012,872 | —- | M] (SurfRight B.V.) – C:\Windows\SysNative\bootdelete.exe
[2011/07/03 15:09:15 | 000,023,112 | —- | M] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | M] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 15:00:07 | 007,617,344 | —- | M] (SurfRight B.V.) – C:\Users\Noel Brereton\Desktop\HitmanPro35_x64.exe
[2011/07/03 14:38:20 | 000,003,011 | —- | M] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | M] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/29 04:30:23 | 000,055,384 | —- | M] (Sunbelt Software) – C:\Windows\SysNative\drivers\SBREDrv.sys
[2011/06/22 04:37:26 | 000,000,336 | -H– | M] () – C:\ProgramData\36429560
[2011/06/19 03:09:34 | 000,739,906 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/19 03:09:34 | 000,623,940 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/19 03:09:34 | 000,106,316 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/17 10:50:54 | 000,425,400 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
========== Files Created - No Company Name ==========
[2011/07/07 13:50:01 | 000,001,478 | —- | C] () – C:\Users\Noel Brereton\Desktop\New Internet.lnk
[2011/07/07 13:37:29 | 000,000,064 | —- | C] () – C:\Windows\SysWow64\rp_stats.dat
[2011/07/07 13:37:29 | 000,000,044 | —- | C] () – C:\Windows\SysWow64\rp_rules.dat
[2011/07/05 14:44:31 | 000,000,512 | —- | C] () – C:\Users\Noel Brereton\Desktop\MBR.dat
[2011/07/05 14:28:44 | 001,008,041 | —- | C] () – C:\Users\Noel Brereton\Desktop\rkill.exe
[2011/07/03 15:19:09 | 000,002,441 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader 9.lnk
[2011/07/03 15:19:09 | 000,002,021 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2011/07/03 15:01:19 | 000,023,112 | —- | C] () – C:\Windows\SysNative\drivers\hitmanpro35.sys
[2011/07/03 15:01:00 | 000,001,985 | —- | C] () – C:\Users\Public\Desktop\Hitman Pro 3.5.lnk
[2011/07/03 14:38:20 | 000,003,011 | —- | C] () – C:\Users\Noel Brereton\Desktop\HiJackThis.lnk
[2011/07/02 13:02:15 | 000,001,144 | —- | C] () – C:\Users\Noel Brereton\Application Data\Microsoft\Internet Explorer\Quick Launch\Malwarebytes' Anti-Malware.lnk
[2011/07/02 13:02:15 | 000,001,120 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes' Anti-Malware.lnk
[2011/06/22 04:37:26 | 000,000,336 | -H– | C] () – C:\ProgramData\36429560
[2010/08/25 20:34:30 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2010/08/25 20:34:30 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2010/08/25 20:34:30 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2010/08/25 19:52:00 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/08/25 19:52:00 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
[2009/08/27 17:02:56 | 000,134,592 | —- | C] () – C:\Windows\SysWow64\igfcg500.bin
[2009/07/14 01:38:36 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2009/07/13 22:35:51 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 22:34:42 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2009/07/13 20:10:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2009/07/13 19:42:10 | 000,064,000 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 17:03:59 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 17:26:10 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
< End of report >